The NIST AI Risk Management Framework (AI RMF) is a voluntary framework from the US National Institute of Standards and Technology that helps organizations identify, assess and manage the risks of AI systems, whether they build them, buy them or simply use them. It is organized around four functions, Govern, Map, Measure and Manage, and describes what trustworthy AI looks like without prescribing specific tools or controls. It is a common reference point for AI governance programs in the US and beyond. This entry is an overview for buyers, not legal advice.
At a glance
- Published by NIST for voluntary use; version 1.0 was released in January 2023, and NIST has said it is revising the framework.
- Four core functions: Govern, Map, Measure and Manage.
- It is a framework of voluntary outcomes, not a certification: there are no levels, tiers, official certificates or conformity-assessment scheme.
- Companion resources include a Playbook of suggested actions and profiles, including one for generative AI.
- Customers, contracts and some public-sector programs may refer to it, so alignment can become an expectation even though the framework is voluntary.
What problem it solves
AI risks don’t fit neatly into existing security or privacy reviews. A model can be accurate in testing and unreliable in use, treat groups of people unfairly, leak data, be manipulated or produce convincing false output. Organizations adopting AI need a shared way to talk about those risks, decide who owns them and check whether they are under control.
The AI RMF gives that structure. It provides a common vocabulary for boards, technical teams, legal and procurement, and a set of outcomes to work toward, scaled to how the organization uses AI. For a mid-market company, it is often used as a checklist for building a proportionate AI governance program and for asking vendors consistent questions.
How it works
The framework describes trustworthy AI through seven characteristics: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair, with harmful bias managed. It recognizes that these involve trade-offs and depend on context.
Its core is organized into four functions, each broken into categories and subcategories of outcomes. Organizations choose which outcomes matter for their situation, often by building a profile that compares where they are with where they want to be. NIST’s Playbook suggests actions for each outcome, and use-case profiles apply the framework to particular settings, such as the Generative AI Profile published in 2024.
The framework is meant to be used throughout an AI system’s life, from planning and design through deployment, monitoring and retirement, and by anyone involved, including buyers of AI products.
Core functions
The AI RMF has no maturity levels, implementation tiers or certification. It defines voluntary outcomes and sets out no conformity-assessment scheme. Its closest structure is the four functions below, which are applied together rather than achieved in sequence. The last two columns are illustrative only: they show how a buyer might seek assurance from a vendor and are not prescribed by the framework.
| Function | What it covers | Ways a buyer can seek assurance (illustrative) | Typical evidence |
|---|---|---|---|
| Govern | Policies, accountability, roles, culture and oversight of AI risk, including third-party AI; applies across the other three | Vendor’s own description of its program; an independent review if one exists | AI policy, named owners, AI inventory, vendor review process |
| Map | Context of each AI system: purpose, users, affected people, data, limitations and potential impacts | Vendor’s documentation of intended use and limits | Use-case descriptions, impact or risk assessments |
| Measure | Methods and metrics to test and track risks and trustworthiness characteristics | Vendor’s test methods and results; independent testing if available | Test results, evaluation reports, monitoring metrics |
| Manage | Prioritizing and acting on risks, responding to incidents and deciding whether to deploy, change or retire a system | Vendor’s incident and change-notification commitments in the contract | Risk treatment decisions, incident records, monitoring logs |
When it matters for buyers
- When the board asks about AI risk. The four functions give a recognizable structure for reporting what is in place.
- When customers send AI questionnaires. Many questions map to AI RMF outcomes, and naming a framework helps answers hang together.
- When reviewing AI vendors. The framework’s third-party guidance supports consistent third-party risk management (TPRM) for AI products.
- When you also face the EU AI Act or sector rules. The AI RMF can organize the work, but legal obligations still need their own review.
Our governance, risk and compliance and artificial intelligence overviews cover providers that help build AI risk programs.
Questions to ask vendors
- Which AI frameworks or standards do you align with, and can you share how you map to the AI RMF functions?
- Has any of that alignment been independently assessed, and for which products?
- How do you test your AI features for accuracy, bias and security, and how often?
- What documentation do you provide about each AI feature’s intended use and limitations?
- How will you notify us of AI incidents or significant model changes?
- Do you use our data to train or improve models, and can we opt out by contract?
How it differs from the NIST Cybersecurity Framework
The NIST Cybersecurity Framework (NIST CSF) covers cybersecurity risk across the whole organization. The AI RMF focuses on risks specific to AI systems, including accuracy, fairness, explainability and harms to people, that a security framework does not fully address. They share a similar style, voluntary outcomes organized into functions, and many organizations use both, folding AI risk into an existing governance, risk and compliance (GRC) program and risk assessments. Unlike the EU AI Act, neither is a law in itself. For generative AI specifically, see generative AI.
