NIST AI Risk Management Framework, explained

Updated

The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary, sector-agnostic framework for identifying and managing the risks of AI systems. It is organized around four functions — Govern, Map, Measure, and Manage — and a set of trustworthiness characteristics a system should exhibit.

The framework is guidance, not a certification or a law. It gives organizations a shared vocabulary and a repeatable structure for governing AI: cultivating a risk culture (Govern), understanding context and identifying risks (Map), assessing and tracking them (Measure), and prioritizing and acting on them (Manage). NIST pairs it with a Playbook of suggested actions and with use-case profiles that adapt the core to specific settings.

What the NIST AI RMF is

The AI Risk Management Framework was published by the U.S. National Institute of Standards and Technology (NIST) in January 2023 as AI RMF 1.0, developed pursuant to the National Artificial Intelligence Initiative Act of 2020 through an open, consensus-driven process. It is intended to help organizations that design, develop, deploy, or use AI systems manage the associated risks and promote trustworthy and responsible AI.

Three properties define its character. It is voluntary — NIST does not certify or audit against it. It is rights-preserving and non-sector-specific, meaning it is written to apply across industries and use cases rather than to one regulated domain. And it is outcome-oriented rather than prescriptive: it describes what good AI risk management looks like and leaves the specific controls to the organization. That flexibility is why it is frequently referenced as a baseline by other frameworks, procurement requirements, and emerging regulation.

The four core functions: Govern, Map, Measure, Manage

The heart of the framework is four functions. Govern is cross-cutting — it applies across the other three rather than running in sequence — while Map, Measure, and Manage form an iterative cycle that repeats over a system's life. Each function is broken into categories and subcategories that describe concrete outcomes to work toward.

The four AI RMF functions and what each is responsible for
FunctionPurposeRepresentative outcomes
GovernCultivate and sustain a culture of AI risk management across the organization.Policies, accountability structures, roles, workforce diversity and competency, and oversight that apply across the whole lifecycle.
MapEstablish the context and identify risks related to that context.Intended purpose and setting, affected stakeholders, system capabilities and limitations, and the risks and benefits mapped before they are measured.
MeasureAssess, analyze, and track the risks that Map identified.Quantitative and qualitative methods, testing and evaluation, tracking of trustworthiness characteristics, and mechanisms to gather feedback.
ManagePrioritize and act on risks based on their projected impact.Risk treatment and prioritization, response and recovery plans, third-party and supply-chain risk handling, and documented decisions.

The trustworthiness characteristics

The framework organizes the properties of a trustworthy AI system into seven characteristics. They are meant to be balanced against one another in context — improving one can trade off against another — and no single characteristic on its own makes a system trustworthy. NIST treats validity and reliability as foundational: a system that is not valid and reliable cannot meaningfully claim the others.

  • Valid and reliable — the system performs as intended and produces accurate results under expected conditions (the foundational precondition).
  • Safe — it does not, under defined conditions, lead to a state that endangers human life, health, property, or the environment.
  • Secure and resilient — it withstands adversarial attack and unexpected conditions and can return to normal function.
  • Accountable and transparent — information about the system and its outputs is available to those who need it, and responsibility is clear.
  • Explainable and interpretable — the mechanisms behind an output, and the meaning of that output in context, can be understood.
  • Privacy-enhanced — it safeguards autonomy, identity, and dignity, applying privacy-preserving practices to data.
  • Fair with harmful bias managed — it addresses harmful bias and discrimination and promotes equity across systemic, computational, and human-cognitive sources.

Profiles and the Playbook

The core functions are deliberately generic, so NIST provides two ways to make them concrete. The AI RMF Playbook offers suggested actions, references, and documentation for each subcategory — an organization selects the parts relevant to its context rather than applying all of it. Profiles adapt the framework to a specific use case, sector, or technology by selecting the functions, categories, and subcategories that apply.

Profiles come in two shapes. A use-case or cross-sectoral profile tailors the framework to a setting — for example, hiring or a specific industry. A temporal profile describes a current state versus a target state, which lets an organization plan improvements as a gap between where its AI risk management is today and where it wants it to be. NIST has also published the Generative AI Profile (NIST AI 600-1, July 2024), a companion resource that identifies risks unique to or amplified by generative AI and suggested actions to manage them.

Why 'voluntary' still matters

Because the AI RMF is not a law or a certifiable standard, no regulator requires it by name and no body issues a certificate for it. That can make it easy to underestimate. In practice it has become a common reference point: buyers ask vendors to describe their AI risk management against it, and some emerging AI regulation points to recognized risk-management frameworks — the AI RMF among them — as evidence of reasonable care. Aligning to it does not by itself create legal compliance, but it can support the case that an organization managed risk responsibly.

It also pairs cleanly with certifiable regimes. A management-system standard such as ISO/IEC 42001 defines the auditable AI management system; the AI RMF supplies a detailed, outcome-oriented vocabulary for the risk work inside it. Many teams use the two together — the standard for the certificate, the framework for the substance.

How to operationalize the AI RMF

Turning the framework into practice means treating each function as ongoing work with evidence behind it, not a one-time document. The failure mode is a governance binder that describes intentions no one can show operating. Auditors, buyers, and regulators increasingly want to see the risk work happening — assessments dated to the systems they cover, measurements re-run as models change, and decisions recorded with who made them and when.

  • Start with Govern: assign accountability, write the policies, and decide who signs off on high-impact AI before you inventory systems.
  • Use Map to build an inventory of AI systems with their purpose, context, affected stakeholders, and known limitations — you cannot manage what you have not catalogued.
  • Make Measure repeatable: define how each system is tested and tracked against the trustworthiness characteristics, and re-run it when the model or data changes.
  • Close the loop with Manage: prioritize by projected impact, record the treatment decision, and keep the trail so the response can be reproduced later.
  • Adopt a profile rather than the whole core — select the subcategories that fit your use case, and treat a current-versus-target profile as your improvement roadmap.

Frequently asked questions

Is the NIST AI RMF mandatory?

No. The AI RMF is voluntary guidance. NIST does not certify or audit organizations against it, and no regulator requires it by name. It is widely referenced as a baseline, however, and aligning to it can support a case that an organization managed AI risk responsibly.

What are the four functions of the NIST AI RMF?

Govern, Map, Measure, and Manage. Govern is cross-cutting and establishes the risk culture and accountability; Map identifies context and risks; Measure assesses and tracks them; Manage prioritizes and acts on them. Map, Measure, and Manage form an iterative cycle over a system's life.

How does the NIST AI RMF relate to ISO/IEC 42001 and the EU AI Act?

They complement each other. ISO/IEC 42001 is a certifiable AI management-system standard; the AI RMF is a detailed, outcome-oriented risk vocabulary that fits inside it. The EU AI Act is binding law; the AI RMF is voluntary guidance that can help demonstrate sound risk management but does not by itself satisfy legal obligations.

What is an AI RMF profile?

A profile adapts the generic framework to a specific context. A use-case or cross-sectoral profile selects the functions and subcategories relevant to a setting; a temporal profile describes a current state versus a target state, which teams use as an improvement roadmap.

What is the Generative AI Profile?

It is a companion resource NIST published in July 2024 (NIST AI 600-1) that identifies risks unique to or amplified by generative AI and lists suggested actions to manage them, mapped back to the four core functions of the AI RMF.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.