Govern, Map, Measure, Manage
The one-paragraph answer
The NIST AI RMF (National Institute of Standards and Technology Artificial Intelligence Risk Management Framework) is the US government's voluntary reference framework for identifying and managing risks in AI systems. It has four functions: Govern, Map, Measure, and Manage. It is not a law and no one is forced to adopt it, but every US regulator, insurance carrier, and enterprise buyer treats it as the baseline expectation for a serious AI program.
Every AI program hits the same wall around month six. Leadership has spent money. Tools are in place. Something is working, or seems to be. Then the audit committee asks a hard question: "How do we know the AI is not creating risks we cannot see?" The room goes quiet again. Nobody wrote down which risks were considered. Nobody measured whether the risks are getting better or worse. Nobody assigned who is responsible if something goes wrong.
This is the pain the NIST AI RMF was designed to end. Before it existed, companies were inventing their own risk taxonomies, borrowing pieces from cybersecurity frameworks, and hoping the result would hold up. Some did. Most did not. The NIST AI RMF gave everyone a common vocabulary and a common four-function structure so that an AI program can be described, measured, and improved.
The NIST AI RMF is a document (technically NIST AI 100-1) published by the National Institute of Standards and Technology in January 2023. NIST is a US federal agency inside the Department of Commerce. It writes technical standards for measurement and technology. Its cybersecurity framework became the most widely-used security framework in the world; the NIST AI RMF is on the same trajectory for AI.
The framework is voluntary. There is no law that forces adoption. But because NIST authored it, and because federal executive orders reference it, and because it is written in plain, actionable language, it has been adopted as the practical standard by regulators (FTC, EEOC, CFPB), by state AI laws that reference it explicitly (Colorado, Texas), by procurement teams at Fortune 500 companies, and by AI insurance underwriters.
NIST also published a Generative AI Profile in July 2024, which extends the core framework specifically to generative AI risks. Together with the AI RMF Playbook, the ecosystem covers most of what a mid-sized US company needs to build a defensible AI programme.
Three further NIST efforts are in flight as of mid-2026, and they are frequently confused with one another. They are different documents doing different jobs.
A preliminary draft was released December 16, 2025, with a comment period that closed January 30, 2026. Formally the Cybersecurity Framework Profile for Artificial Intelligence, it maps CSF 2.0 onto AI systems and is organised around securing AI systems, using AI to defend, and thwarting AI-enabled attacks. It is outcome-oriented: it tells you what good looks like, not which control to implement. Where the NIST AI RMF covers the full breadth of AI trustworthiness including bias and fairness, the Cyber AI Profile is the cybersecurity slice specifically.
The implementation-level companion to the Cyber AI Profile, developing control overlays against the SP 800-53 catalogue. It covers distinct AI use cases, including generative AI and LLMs, predictive AI, single-agent and multi-agent systems, and the secure AI development lifecycle. For most security teams this is the more immediately useful of the two, because it names the controls rather than the outcomes.
A separate effort, at concept stage with drafting expected through 2026 and 2027, translating AI RMF functions into system requirements for critical infrastructure, including operational technology and industrial control systems. Its practical significance is procurement: it is the profile most likely to end up as contract language for anyone with an OT footprint.
The NIST AI RMF is organized around four functions. Each function contains several categories, and each category contains specific actions. Here is what each function asks for, in plain language.
Build the AI governance foundation. Set an AI risk management policy. Assign accountability roles (who owns AI risk?). Establish executive oversight. Define how AI risks map to organizational risk. Set training and competence requirements for AI-relevant roles. This function is the "who is in charge" answer that every board eventually asks.
Understand the AI systems you have and the context they operate in. Categorize AI systems. Identify who is affected by them (users, employees, customers, third parties). Document the AI's intended use, foreseeable misuse, and impact on people and organizations. Cataloging the AI environment is what the NIST AI RMF calls the Map function.
Assess AI systems against the seven trustworthy characteristics the framework defines: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair with harmful bias managed. Measurement can be quantitative (accuracy, error rates, fairness metrics), qualitative (user feedback, expert review), or both.
Treat the risks you have measured. Prioritize which risks matter most. Allocate resources. Respond to incidents. Adapt when the system, the data, or the environment changes. Continuous improvement lives here. If the Map function is "what do we have," Manage is "what are we doing about it."
The NIST AI RMF defines what "trustworthy" means with unusual specificity. An AI system is trustworthy to the extent that it is: valid and reliable (does what it claims); safe (does not endanger life or property); secure and resilient (resists attack and failure); accountable and transparent (someone owns it, someone can explain it); explainable and interpretable (its reasoning is understandable to affected parties); privacy-enhanced (respects data subject rights); and fair with harmful bias managed. Every measurement exercise ties back to these seven.
Four groups are looking at your NIST AI RMF alignment right now. Boards ask for it because it is the accepted framework for demonstrating AI risk oversight under Caremark-style fiduciary duties. Regulators cite it in enforcement matters, particularly the FTC and EEOC, as evidence of what a reasonable AI risk program looks like. State legislators reference it directly (Colorado's AI Act, for example, treats NIST AI RMF alignment as a factor in enforcement). And enterprise buyers are asking for it in due diligence questionnaires, especially in regulated industries and government contracting.
The NIST AI RMF is not a certification. There is no certificate to hang on the wall. But being able to document your Govern-Map-Measure-Manage practices is the difference between a defensible AI program and an assertion that everything is fine.
The academic literature on NIST AI RMF is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.
“the understanding of how such principles can be operationalized in designing, executing, monitoring, and evaluating AI applications is limited”
That is the gap between having AI and governing it. The second finding is the one that tends to change the room.
“it remains challenging for practitioners to identify the harmful repercussions of their own systems prior to deployment”
Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about NIST AI RMF arrives from the board, the buyer, or the regulator.
This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.
Done in this order, NIST AI RMF becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.
No. It is voluntary. But adoption is now expected by regulators, buyers, and insurers as the baseline for a serious AI program. Voluntary in law does not mean optional in practice.
They complement each other. ISO/IEC 42001 is a management system standard: the operating structure. The NIST AI RMF is a risk framework: the substance you put inside the structure. Most mature AI programs use ISO/IEC 42001 as the management-system wrapper and the NIST AI RMF as the risk-identification and treatment method inside it.
Yes. In July 2024, NIST published the Generative AI Profile that extends the core NIST AI RMF to generative-AI-specific risks: hallucination, data leakage from prompts, prompt injection, model misuse, and content authenticity. Any organization using generative AI should apply the profile alongside the core framework.
The NIST AI RMF Playbook is companion guidance that gives suggested actions, documentation, and outcomes for each category and subcategory of the framework. It is where teams turn when they need concrete steps beyond the framework's high-level structure.
The NIST AI RMF is the risk backbone of Volume III, The AI Risk & Governance Review™. Appendix L (the AI Governance Framework Crosswalk™) maps every operating artifact in The Operating Discipline for AI Library™ to specific NIST AI RMF categories. The Accountability Matrix, the risk register templates, the dossier sections, and the review cadence in Volume III all trace back to specific NIST AI RMF practices.
The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning NIST AI RMF that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.
The AI Business Enablement Audit™ measures your organization against every framework in this library, including NIST AI Risk Management Framework, and delivers a defensible governance dossier. Start or finish your audit below.
Start or finish your AI Audit →