What Is AI RMF (NIST AI Risk Management Framework)?

Also called: NIST AI RMF, AI Risk Management Framework

Related problems: Board asking how we manage AI risk and we have no structure to point to; Customers asking which AI framework we follow; Need a common way to assess AI tools before we buy or build them; Not sure what good AI risk management looks like for a company our size

The NIST AI Risk Management Framework (AI RMF) is a voluntary framework from the US National Institute of Standards and Technology that helps organizations identify, assess and manage the risks of AI systems, whether they build them, buy them or simply use them. It is organized around four functions, Govern, Map, Measure and Manage, and describes what trustworthy AI looks like without prescribing specific tools or controls. It is a common reference point for AI governance programs in the US and beyond. This entry is an overview for buyers, not legal advice.

At a glance

  • Published by NIST for voluntary use; version 1.0 was released in January 2023, and NIST has said it is revising the framework.
  • Four core functions: Govern, Map, Measure and Manage.
  • It is a framework of voluntary outcomes, not a certification: there are no levels, tiers, official certificates or conformity-assessment scheme.
  • Companion resources include a Playbook of suggested actions and profiles, including one for generative AI.
  • Customers, contracts and some public-sector programs may refer to it, so alignment can become an expectation even though the framework is voluntary.

What problem it solves

AI risks don’t fit neatly into existing security or privacy reviews. A model can be accurate in testing and unreliable in use, treat groups of people unfairly, leak data, be manipulated or produce convincing false output. Organizations adopting AI need a shared way to talk about those risks, decide who owns them and check whether they are under control.

The AI RMF gives that structure. It provides a common vocabulary for boards, technical teams, legal and procurement, and a set of outcomes to work toward, scaled to how the organization uses AI. For a mid-market company, it is often used as a checklist for building a proportionate AI governance program and for asking vendors consistent questions.

How it works

The framework describes trustworthy AI through seven characteristics: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair, with harmful bias managed. It recognizes that these involve trade-offs and depend on context.

Its core is organized into four functions, each broken into categories and subcategories of outcomes. Organizations choose which outcomes matter for their situation, often by building a profile that compares where they are with where they want to be. NIST’s Playbook suggests actions for each outcome, and use-case profiles apply the framework to particular settings, such as the Generative AI Profile published in 2024.

The framework is meant to be used throughout an AI system’s life, from planning and design through deployment, monitoring and retirement, and by anyone involved, including buyers of AI products.

Core functions

The AI RMF has no maturity levels, implementation tiers or certification. It defines voluntary outcomes and sets out no conformity-assessment scheme. Its closest structure is the four functions below, which are applied together rather than achieved in sequence. The last two columns are illustrative only: they show how a buyer might seek assurance from a vendor and are not prescribed by the framework.

Function What it covers Ways a buyer can seek assurance (illustrative) Typical evidence
Govern Policies, accountability, roles, culture and oversight of AI risk, including third-party AI; applies across the other three Vendor’s own description of its program; an independent review if one exists AI policy, named owners, AI inventory, vendor review process
Map Context of each AI system: purpose, users, affected people, data, limitations and potential impacts Vendor’s documentation of intended use and limits Use-case descriptions, impact or risk assessments
Measure Methods and metrics to test and track risks and trustworthiness characteristics Vendor’s test methods and results; independent testing if available Test results, evaluation reports, monitoring metrics
Manage Prioritizing and acting on risks, responding to incidents and deciding whether to deploy, change or retire a system Vendor’s incident and change-notification commitments in the contract Risk treatment decisions, incident records, monitoring logs

When it matters for buyers

  • When the board asks about AI risk. The four functions give a recognizable structure for reporting what is in place.
  • When customers send AI questionnaires. Many questions map to AI RMF outcomes, and naming a framework helps answers hang together.
  • When reviewing AI vendors. The framework’s third-party guidance supports consistent third-party risk management (TPRM) for AI products.
  • When you also face the EU AI Act or sector rules. The AI RMF can organize the work, but legal obligations still need their own review.

Our governance, risk and compliance and artificial intelligence overviews cover providers that help build AI risk programs.

Questions to ask vendors

  • Which AI frameworks or standards do you align with, and can you share how you map to the AI RMF functions?
  • Has any of that alignment been independently assessed, and for which products?
  • How do you test your AI features for accuracy, bias and security, and how often?
  • What documentation do you provide about each AI feature’s intended use and limitations?
  • How will you notify us of AI incidents or significant model changes?
  • Do you use our data to train or improve models, and can we opt out by contract?

How it differs from the NIST Cybersecurity Framework

The NIST Cybersecurity Framework (NIST CSF) covers cybersecurity risk across the whole organization. The AI RMF focuses on risks specific to AI systems, including accuracy, fairness, explainability and harms to people, that a security framework does not fully address. They share a similar style, voluntary outcomes organized into functions, and many organizations use both, folding AI risk into an existing governance, risk and compliance (GRC) program and risk assessments. Unlike the EU AI Act, neither is a law in itself. For generative AI specifically, see generative AI.

Frequently Asked Questions

Is the NIST AI RMF mandatory?
Not by itself. NIST publishes it for voluntary use. A customer contract, a government program or a sector regulator may ask you to align with it, so check your obligations with counsel. This is not legal advice.
Can a company be certified against the AI RMF?
No. NIST does not certify organizations against the AI RMF, and the framework has no levels, tiers or conformity-assessment scheme. A vendor can describe how it aligns with the framework or share an independent assessment, but there is no official AI RMF certificate. ISO/IEC 42001 is a separate, certifiable standard for AI management systems.
What are the four functions of the AI RMF?
Govern, Map, Measure and Manage. Govern sets the policies, roles and culture for AI risk and applies throughout; Map establishes context and identifies risks; Measure assesses and tracks them; Manage prioritizes and acts on them.
Does the AI RMF cover generative AI?
Yes. The framework applies to AI systems generally, and NIST has published a Generative AI Profile that applies it to risks specific to generative AI, such as confabulated output and misuse.
Does following the AI RMF satisfy the EU AI Act?
Not on its own. The two overlap in approach, but the EU AI Act is a law with specific obligations that depend on your role and how the AI is used. Alignment with the AI RMF can help structure that work; confirm specific EU obligations with counsel.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.