NIST PF ID.RA-P - Risk Assessment
Assess contextual factors, analytic bias, problematic data actions, their likelihood and impacts, and prioritize and implement privacy-risk responses.
Where this comes from
Provision: ID.RA-P - Risk Assessment
Instrument: NIST Privacy Framework Version 1.0
Citation: NIST Privacy Framework Version 1.0 (16 January 2020), Core, ID.RA-P1 through ID.RA-P5
Text version: NIST Privacy Framework 1.0 Core, 16 January 2020 (not PF 1.1)
Checked against the source: 6 September 2026
Who it applies to
It applies when all of these are true:
- NIST PF 1.0 Target Profile adopted: YES
- ID.RA-P: Which outcomes are selected in this project's Target Profile? is ID.RA-P1, ID.RA-P2, ID.RA-P3, ID.RA-P4 or ID.RA-P5
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Default profile visibility: private (not public)
- Default data sharing: off (opt-in, not opt-out)
- Default location tracking: off
- Default contact discoverability: off
- User can change any default via settings
Questions people ask
- Does NIST PF ID.RA-P - Risk Assessment apply to my service?
- It applies when NIST PF 1.0 Target Profile adopted: YES; ID.RA-P: Which outcomes are selected in this project's Target Profile? is ID.RA-P1, ID.RA-P2, ID.RA-P3, ID.RA-P4 or ID.RA-P5.
- From when does this apply?
- NIST PF ID.RA-P - Risk Assessment applies from 16 January 2020. Its current status is: in force.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.