Join our Newsletter — 33% off our NHI Course

Manage Function

The management phase of the NIST AI Risk Management Framework, where organisations act on AI risk through monitoring, remediation, enforcement, and reporting. It turns assessment into operational response, helping teams reduce harm, respond to incidents, and adapt controls as systems, threats, and regulations change.

Expanded Definition

Manage Function is the action-oriented part of the NIST AI Risk Management Framework that converts AI risk findings into ongoing operational control. It covers monitoring system behaviour, prioritising remediation, enforcing policy, escalating issues, and reporting outcomes so risk decisions do not remain static. In practice, the function sits after identification and assessment, and it is where governance becomes visible in day-to-day operations. For NHIMG, the most useful way to understand it is as the continuous feedback loop that keeps AI systems aligned with business objectives, safety expectations, and regulatory obligations.

It differs from one-time model review or pre-deployment testing because it assumes risk will change as data, prompts, integrations, and user behaviour evolve. That is especially important for agentic AI, where tool use and autonomous execution can expand impact after launch. The language in NIST NIST Cybersecurity Framework 2.0 is not AI-specific, but its govern, detect, respond, and recover concepts map well to operational follow-through.

The most common misapplication is treating Manage Function as a reporting exercise, which occurs when teams collect AI risk metrics without enforcing remediation or accountability.

Examples and Use Cases

Implementing Manage Function rigorously often introduces governance overhead, requiring organisations to weigh faster AI delivery against the cost of sustained oversight.

  • Flagging a high-risk model output pattern, assigning an owner, and tracking the remediation until the issue is closed.
  • Updating human review requirements when an AI system begins supporting decisions with direct business, safety, or compliance impact.
  • Restricting a model’s tool access after an incident shows that an agent can take actions beyond its original approval scope.
  • Producing recurring risk reports for security, legal, and operational leaders so changes in model behaviour are visible over time.
  • Adjusting controls after new regulations, internal policy changes, or supplier dependencies alter the risk profile of the AI system.

Used well, Manage Function is not just about monitoring drift. It also captures how organisations respond when controls fail, especially in environments where prompts, retrieval sources, and permissions can change quickly. Teams that already work with incident response playbooks will find the logic familiar, even though AI-specific controls may need tighter review of cybersecurity governance, escalation, and evidence handling.

Why It Matters for Security Teams

Security teams rely on Manage Function because AI risk is rarely static. Models can degrade, outputs can become unsafe, integrations can expand blast radius, and policy exceptions can accumulate unless someone actively manages them. The function gives organisations a structured way to move from detection to action, which is essential when AI is embedded in workflows that affect customers, employees, or regulated decisions. It also helps connect technical signals to governance decisions, so incidents, exceptions, and remediation status are visible to the right owners.

This matters even more where AI systems intersect with identity, access, and non-human execution. If an AI agent can call APIs, trigger workflows, or touch secrets, the control problem becomes operational and not just analytical. In that setting, Manage Function becomes the bridge between AI risk management and broader security operations, including monitoring, incident response, and privilege reduction. NIST’s framework approach to governance and response reinforces the same principle: risk only decreases when findings are acted on.

Organisations typically encounter the consequences only after a model incident, audit finding, or harmful automation event, at which point Manage Function becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 address the attack and risk surface, while NIST AI RMF, NIST AI 600-1, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST AI RMF MANAGE Defines the Manage function as the operational response side of AI risk management.
NIST AI 600-1 Provides GenAI risk guidance that relies on ongoing management after assessment.
NIST CSF 2.0 GV.RM, DE.CM, RS.RP CSF governance, monitoring, and response concepts align to operational risk handling.
OWASP Agentic AI Top 10 Agentic AI guidance highlights runtime control, oversight, and post-deployment response needs.
NIST Zero Trust (SP 800-207) Zero trust supports continuous verification when AI systems and agents access resources.

Tie AI risk actions to governance, detection, and response workflows with clear escalation.