Last updated: September 1, 2026
The NIST AI Risk Management Framework (AI RMF 1.0) is voluntary guidance published by the US National Institute of Standards and Technology in January 2023 to help organizations identify, measure and manage risks across the life of an AI system. It is built around four functions: Govern, Map, Measure and Manage. Unlike ISO 42001 it is not certifiable and unlike the EU AI Act it carries no penalties, but it has become the common vocabulary for AI risk in US enterprises and increasingly in vendor questionnaires.
This explainer is part of our AI governance guide.
Key takeaways
- AI RMF 1.0 is voluntary, free, and sector-agnostic. There is no certificate and no auditor.
- Four functions organize the work: Govern (cross-cutting), Map (context and risk identification), Measure (analysis and tracking), Manage (treatment and monitoring).
- Each function breaks into categories and subcategories, with a companion Playbook giving suggested actions and references.
- The Generative AI Profile, published in July 2024, extends the framework to generative systems with twelve risk areas and hundreds of suggested actions.
- It defines seven characteristics of trustworthy AI, which is where most of its practical value sits for risk teams.
- It pairs well with a certifiable management system: use AI RMF for how you think about risk, and ISO 42001 for the evidence a customer or auditor will accept.
What is the NIST AI RMF?
NIST developed the framework under a Congressional directive in the National Artificial Intelligence Initiative Act, through an open process with industry, academia and civil society. The result is a short core document plus a companion Playbook that expands each subcategory into suggested actions, transparency documentation and references.
Two design choices shape how it feels in practice. First, it is outcome-based rather than prescriptive: it tells you what good looks like and leaves the implementation to you. Second, it is explicitly socio-technical. It asks you to consider harms to people, to organizations and to ecosystems, not just model performance, and it expects you to involve people beyond the data science team.
What are the four core functions?
Govern
Govern is cross-cutting and sits above the other three. It covers the policies, accountability structures, workforce competence, culture, third-party arrangements and incident processes that make AI risk management repeatable rather than heroic. In most assessments Govern is where organizations score worst, usually because ownership of AI risk is unassigned or split ambiguously between security, legal and data science.
Map
Map establishes context for a specific AI system: what it is for, who it affects, what the intended and foreseeable misuses are, what the system boundaries and dependencies are, and what could go wrong. Map is where you decide whether the system should exist at all, which is a decision the framework explicitly says you are allowed to make. You cannot do Map well without an inventory of your AI systems, which is why the inventory is usually the first real deliverable.
Measure
Measure analyzes, benchmarks and tracks the risks Map identified, using quantitative and qualitative methods. This covers test, evaluation, verification and validation; metrics for the trustworthiness characteristics; and mechanisms for tracking risks that resist measurement. The honest constraint here is that many AI risks have no accepted metric, and the framework asks you to document that gap rather than paper over it.
Manage
Manage allocates resources to treat the risks: prioritize, decide whether to mitigate, transfer, avoid or accept, plan for incidents and recovery, monitor in production, and manage risk that arrives through third-party models and data. Manage closes the loop back into Govern through documented decisions and post-deployment monitoring.
What are the seven trustworthy AI characteristics?
The framework defines the properties a trustworthy AI system should show, and these are the most quoted part of the document:
- Valid and reliable
- Safe
- Secure and resilient
- Accountable and transparent
- Explainable and interpretable
- Privacy-enhanced
- Fair, with harmful bias managed
The framework is candid that these trade off against each other. Raising explainability can cost accuracy; strengthening privacy can weaken your ability to test for bias. Making those trade-offs explicit and documenting who decided is much of the point.
How does it compare to ISO 42001 and the EU AI Act?
| NIST AI RMF | ISO/IEC 42001 | EU AI Act | |
|---|---|---|---|
| Status | Voluntary guidance | Voluntary standard | Binding regulation |
| Certifiable | No | Yes, by an accredited body | Conformity assessment for high-risk systems |
| Structure | 4 functions, categories and subcategories | Clauses 4 to 10 plus 38 Annex A controls | Risk tiers and role-based obligations |
| Cost | Free to download and use | Standard purchase plus audit fees | Compliance cost scales with high-risk systems |
| Best for | Building a shared risk vocabulary and assessing maturity | Proving governance to customers and auditors | Legal access to the EU market |
They are complementary rather than competing. AI RMF gives you the thinking model, ISO 42001 turns it into a management system you can certify, and the AI Act imposes the legal floor if you touch the EU. Our comparison of the EU AI Act vs ISO 42001 covers the regulatory half of that picture, and what ISO 42001 is covers the standard itself.
What is the Generative AI Profile?
Published in July 2024 as NIST AI 600-1, the Generative AI Profile is a cross-sectoral companion that applies the four functions to generative systems. It names risk areas that traditional model risk work tends to miss: confabulation, dangerous or violent content, CBRN information, data privacy, environmental impact, harmful bias, human-AI configuration, information integrity, information security, intellectual property, obscene content, and value chain and component integration risk. For each it offers suggested actions mapped back to Govern, Map, Measure and Manage. If your AI exposure is mostly bought rather than built, the value chain and human-AI configuration sections are the ones to read first.
How do you start using it?
The framework is not something you implement end to end in one pass. A workable first ninety days looks like this:
- Build an AI system inventory covering built, bought and embedded AI, including features switched on inside existing SaaS tools.
- Assign an accountable owner per system and a single owner for the AI risk program. That is most of Govern.
- Run Map on the two or three highest-exposure systems rather than all of them.
- Pick a small set of metrics you can actually collect for Measure, and record honestly where no metric exists.
- Write down risk decisions and acceptance in the same register you already use for enterprise risk, so Manage is not a parallel process.
The most common failure is starting with Measure because it feels technical and tractable, and ending up with dashboards nobody can act on because Govern was never done.
Frequently asked questions
Can you get certified against the NIST AI RMF?
No. There is no certification scheme and no accredited auditor for AI RMF. You can self-assess, have a third party attest to your alignment, or use it as the design basis for a certifiable system such as ISO 42001. Vendors claiming NIST AI RMF certification are describing their own assessment, not an accredited one.
Is the NIST AI RMF mandatory for US federal contractors?
Not as a blanket rule. Federal AI policy has cited the framework in guidance and agency requirements, and individual solicitations increasingly reference it, so the practical answer depends on your contract vehicle. Read the specific clauses rather than assuming.
How is AI RMF different from the NIST Cybersecurity Framework?
The structure is familiar on purpose, but the risks are not the same. CSF addresses confidentiality, integrity and availability of information systems. AI RMF addresses risks that come from the AI itself: bias, drift, confabulation, opacity, and downstream harm to people. Many organizations run them side by side and share the governance layer.
Does using AI RMF help with EU AI Act compliance?
Indirectly. The risk management, documentation and monitoring practices map well onto the Act’s expectations for high-risk systems, but the framework does not classify systems, produce Annex IV documentation or handle conformity assessment. See our EU AI Act compliance checklist for what the law actually asks of you.
How long does it take to adopt?
Getting to a defensible baseline (inventory, ownership, Map on priority systems, a documented risk process) is typically one to two quarters for a mid-sized company. Full maturity across all four functions is a multi-year program, which is why most teams sequence by system exposure rather than by function.
Who should own it internally?
In practice, GRC or risk owns the framework and data science owns the technical evaluations, with legal advising on use restrictions. Handing the whole thing to the data science team is the pattern that most reliably stalls, because Govern requires authority they do not have.
Turning a framework into evidence
The gap most teams hit is not understanding AI RMF. It is proving they follow it when a customer, a board or a regulator asks. That means an inventory that stays current, risk decisions that are traceable, and controls that map across frameworks instead of being rebuilt for each one. Compyl connects your systems, keeps the AI inventory live, and maps AI RMF practices to ISO 42001 controls and other frameworks you already maintain, so one piece of evidence answers several questions. If you are standing up an AI risk program this year, we can show you what that mapping looks like against your environment.