Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » NIST » NIST AI Risk Management Framework (AI RMF)

NIST AI Risk Management Framework (AI RMF)

The Artificial Intelligence Risk Management Framework (AI RMF) is designed in collaboration with private and public sectors. It is a practical guide to enable individuals and organizations to manage risks posed by generative AI in a way that aligns with their goals and objectives. 

NIST AI RMF is a voluntary framework developed to help users ensure transparency and trustworthiness into the end to end process of AI usage that includes its designing, developing, and evaluation. It aims to facilitate the use of AI in a way that emphasizes human centricity, social responsibility, and sustainability. 

The framework covers these areas:

  1. Framing risk: Understanding and addressing the impacts, challenges, and harms caused by risks.
  2. Audience: Involves the perspectives and impacts from a broad perspective of actors throughout its lifecycle. 
  3. AI risks and trustworthiness: Ensure that AI systems are trustworthy by being responsive to all interested parties.
  4. Effectiveness: Describes how users can benefit from the framework.
  5. RMF core: Outlines the actions and outcomes to promote the collaboration, understanding, and other activities that help to develop trustworthy AI systems though these functions – govern, map, measure, and manage. 
  6. Profiles: These are implementation of functions, categories, and subcategories for applications based on the specific requirement, risk tolerance level, and resources of the user.

Additional reading

A Quick Guide to PHI Disclosure

TL,DR: PHI disclosure is transmitting Protected Health Information outside the covered entity or between healthcare and non-healthcare components within a hybrid entity. PHI includes 18 identifiers linked to health information HIPAA permits disclosure without patient authorization for treatment, payment, and healthcare operations. All other disclosures require explicit written authorization and must follow the minimum necessary…

HIPAA for Healthcare Professionals: A Complete Guide

In 2024, the healthcare sector experienced a staggering 566 data breaches, exposing over 170 million patient records—a dramatic rise from just 6 million in 2010. While the numbers for 2025 aren’t yet fully known, the trend is clear: patient data is increasingly at risk, and the stakes for healthcare organizations have never been higher. For companies…

The rise of social engineering attacks and how to beat them

TL,DR: 90% of phishing attacks incorporate social engineering (Microsoft), and 95% of security breaches stem from human error. Instead of hacking systems, attackers manipulate people by exploiting trust, authority, urgency, and reciprocity Common techniques include impersonating authority figures (CEO fraud), creating artificial urgency to bypass critical thinking, offering fake favors to solicit sensitive information (reciprocity),…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.