NIST AI RMF
ASSURANCE
DATA
MODEL
External inputs and validation
Description
Measurement processes incorporate external perspectives, independent testing, and stakeholder feedback to validate AI system performance and impacts. Internal measurement is necessary but inherently limited by organizational blind spots and incentive structures.
Suggested Actions
1
Engage external auditors or independent researchers for validation of high-risk AI systems — algorithmic auditing firms, academic researchers, or consulting firms with AI ethics expertise2
Solicit structured feedback from end users and affected communities on system performance, fairness, and usability — not just satisfaction surveys, but targeted questions about specific system behaviors and impacts3
Benchmark against industry standards and peer system performance where available — absolute metrics without context are difficult to interpret4
Participate in external evaluations, certifications, or algorithmic audits (e.g., ISO 42001 certification, sector-specific AI audits, government-mandated assessments)5
Publish measurement results for high-risk systems (or at minimum share with regulators and affected stakeholders) — transparency drives accountability and enables external scrutiny6
Incorporate academic research on AI safety, fairness, and security into measurement methodologies — the field evolves rapidly and last year's best practices may be insufficient