An AI governance team is implementing the NIST AI Risk Management Framework. They have identified a high-risk AI system and are in the 'Measure' function. Which activity is most appropriate for this function?
Bias and fairness impact assessments generate quantitative and qualitative evidence about model behaviour, which is exactly what the Measure function covers: analysing, benchmarking and monitoring identified risks. Mapping and framing belong to earlier functions, while this activity quantifies the high-risk system's performance.
Why this answer
In the NIST AI Risk Management Framework (AI RMF), the 'Measure' function focuses on assessing and analyzing risks associated with AI systems. For a high-risk AI system, conducting bias and fairness impact assessments is a core activity within this function, as it quantifies and evaluates potential harms related to fairness, accuracy, and transparency. This aligns with the framework's emphasis on quantitative and qualitative risk measurement before moving to risk treatment in the 'Manage' function.
Exam trap
The AI0-001 exam often tests the distinction between the NIST AI RMF functions (Map, Measure, Manage, Govern) by presenting risk mitigation actions (like implementing controls) as plausible activities for the 'Measure' function, when they actually belong to the 'Manage' function.
How to eliminate wrong answers
Option B is wrong because implementing technical controls to mitigate risks belongs to the 'Manage' function, which involves risk response and treatment, not the 'Measure' function that focuses on assessment and analysis. Option C is wrong because documenting the system's intended purpose and data sources is part of the 'Map' function, which establishes context and identifies risks, not the 'Measure' function that evaluates those risks. Option D is wrong because establishing an AI ethics board is a governance structure typically associated with the 'Govern' function, which sets policies and oversight, not the 'Measure' function's risk assessment activities.