The NIST AI Risk Management Framework (AI RMF) is a voluntary US framework, published by the National Institute of Standards and Technology in January 2023, that gives organizations a common method and vocabulary for managing AI risk. It is organized around four functions — Govern, Map, Measure, Manage — and it certifies nothing: there is no audit, no certificate, and no regulator enforcing it. What it gives executives is a shared structure for an AI governance program, one that maps cleanly onto ISO/IEC 42001 for organizations that also want a certifiable management system.
What is the NIST AI Risk Management Framework?
The NIST AI RMF is a voluntary framework, developed by the National Institute of Standards and Technology through a public, consensus-driven process, to help organizations manage the risks of designing, developing, deploying and using AI systems. NIST published version 1.0 (NIST AI 100-1) on January 26, 2023, following a mandate from the National AI Initiative Act of 2020.
It comes in two parts. The framework itself is a compact document, around 40 pages, laying out the four core functions and the principles behind them. The companion AI RMF Playbook is the operational half — over 140 pages of suggested actions, transparency questions and reference material mapped to every subcategory of the framework. Read the framework alone and you get the structure; the Playbook is where the actual to-do list lives.
NIST built the framework around seven characteristics of trustworthy AI: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. Every function and subcategory ties back to making an AI system stronger on one or more of these.
What are Govern, Map, Measure and Manage?
Govern sits apart from the other three: it is the cross-cutting function that has to be in place before the rest can work, not a step you finish and move past. Map, Measure and Manage then run as a continuous loop, repeated for every AI system or use case in the organization's portfolio.
Each function breaks into categories and subcategories with specific suggested actions in the Playbook. A few, as illustration: GOVERN 1.1 calls for an inventory of every AI system in use, including tools employees adopted on their own, not only sanctioned ones. MAP 2.2 asks the organization to identify potential harms to people and society before the system ships. MEASURE 2.1 calls for documenting test results, evaluation results and any vendor-supplied evaluation material. MANAGE 2.2 calls for documenting the risk-treatment decision and the reasoning behind accepting any residual risk.
Is NIST AI RMF mandatory?
No, not for the private sector. It is voluntary. No US law requires a private company to adopt it, no regulator audits against it, and there is no penalty for ignoring it.
The one place it functions closer to a requirement is inside the US federal government. OMB memorandum M-25-21, issued in 2025, directs federal agencies to manage risk from their own AI use in ways consistent with NIST's framework, particularly for AI uses classified as high-impact. That makes the AI RMF the reference practice for federal agencies specifically — it does not extend that requirement to private industry. Outside government, adoption is driven by expectation rather than law: enterprise customers, insurers and boards increasingly ask whether an AI program follows a recognized risk-management structure, and the AI RMF is the most common US answer to that question.
Who should use it?
NIST wrote the framework to be sector- and technology-agnostic on purpose, so it applies broadly rather than to one class of company.
- Any organization building AI systems — the Map and Measure functions are written from the perspective of someone designing and testing a system before it ships.
- Any organization deploying AI in its own operations — Govern and Manage apply just as directly to a company using a third-party model inside a business process.
- Any organization procuring AI from vendors — the framework gives a due-diligence vocabulary for questions to ask a vendor about how they manage risk on their side.
- US federal agencies, where OMB guidance makes it the reference practice rather than an optional one.
Because it is voluntary and non-certifiable, it has become the common backbone for enterprise AI governance conversations generally, in the US and increasingly outside it, precisely because it asks no one to prove anything to a third party — it just gives everyone the same four words to organize the work around.
The Generative AI Profile
NIST extends the core framework through "profiles" rather than new version numbers — the four functions themselves have not changed since 2023. The one that matters most right now is the Generative AI Profile (NIST AI 600-1), published July 26, 2024 in response to the 2023 Executive Order on Safe, Secure and Trustworthy AI. It applies Govern, Map, Measure and Manage specifically to large language models, text-to-image systems and other foundation-model-based applications, and it names twelve risk categories unique to or intensified by generative AI, including confabulation (what is commonly called hallucination), data privacy leakage, harmful bias and homogenization, and dual-use or malicious misuse.
For any organization deploying LLM chatbots, coding assistants, retrieval-augmented systems or agentic workflows, this profile — not just the core framework — is the relevant document. A separate concept note for a Trustworthy AI in Critical Infrastructure profile followed in April 2026, extending the same four functions to critical-infrastructure operators.
How NIST AI RMF differs from ISO/IEC 42001
These two get conflated constantly, and the confusion is understandable — they cover overlapping ground. The difference is what each one actually is.
| NIST AI RMF | ISO/IEC 42001 | |
|---|---|---|
| What it is | A voluntary risk-management method and shared vocabulary | A certifiable international management-system standard |
| Origin | US government (NIST), January 2023 | International (ISO/IEC JTC 1/SC 42), December 2023 |
| Certifiable? | No — self-attested only | Yes — audited by accredited certification bodies |
| Structure | 4 functions: Govern, Map, Measure, Manage | Clauses 4–10 plus 38 Annex A controls across 9 objectives |
| Best read as | An engineering and governance method | An auditable system, built on a similar underlying method |
In practice they are complementary rather than competing. NIST's four functions map closely enough onto ISO 42001's clauses and controls that risk-management work done for one carries directly into the other — an organization that has built a real AI RMF-based governance program has already done most of the substantive work an ISO 42001 auditor will look for. For the full breakdown of what ISO 42001 itself requires and how certification works, see ISO/IEC 42001 Explained.
How executives should implement it
The framework is deliberately abstract; turning it into a working program is where the executive judgment comes in. A workable sequence:
- Inventory every AI system in use — including tools teams adopted on their own, not just the ones IT sanctioned. You cannot govern what you cannot see.
- Set organizational risk tolerance before deployment, not after something goes wrong. This is a Govern-function decision, and it belongs with a named executive, not a committee that meets quarterly.
- Run Map on every system before it ships: context of use, intended users, the decisions the AI informs or makes, potential harms.
- Run Measure with real evidence — test results, evaluation results, vendor-supplied evaluation material — not a one-time checklist.
- Run Manage as an ongoing decision log: mitigate, transfer, avoid or accept, with the reasoning recorded, not just the outcome.
- Set a review cadence: incident log and risk register reviewed quarterly; tools, vendor assessments and training refreshed annually; senior leadership briefed on the risk profile on a fixed schedule, not only when something breaks.
Read the NIST AI RMF as an engineering method, not a compliance document. The four words are simple. Running them against every real initiative in the portfolio, on a cadence, is the actual work.
This is exactly the kind of governance design that belongs inside a real initiative, not next to it — which is why the AI Transformation Framework™ builds governance and risk directly into the same sequence as opportunity, business case and implementation, rather than treating it as a separate compliance track.
A 6-week accelerator. You bring one real business challenge; you leave with a governed AI initiative.
Explore the Chief AI Officer ProgramConsultants building this into client engagements — including the governance and risk design stage of an AI transformation — should see the Certified AI Consultant Program.
Frequently asked questions
Is there a NIST AI RMF 2.0?
No, as of 2026. NIST has said the framework is under revision, but the current version remains AI RMF 1.0 from January 2023. NIST extends the framework through profiles, such as the Generative AI Profile, rather than new version numbers — the four core functions have not changed.
Can we get certified against the NIST AI RMF?
No. It is explicitly non-certifiable; organizations can only self-attest alignment. ISO/IEC 42001 is the certifiable counterpart for organizations that need an audited claim.
Does the NIST AI RMF satisfy EU AI Act obligations?
No, not automatically. There is significant overlap between the two, and work done under the AI RMF supports EU AI Act compliance work, but the Act's obligations are separate binding legal requirements that still have to be satisfied on their own terms.
Do small companies need to bother with it?
There is no size threshold in the framework. A small company using a handful of third-party AI tools can apply a lightweight version of Govern, Map, Measure, Manage — an inventory, a stated risk tolerance, and a basic review cadence — without needing the full apparatus a large enterprise would build.
