30 Days Gen AI Risk Trial -Start Now
Skip to main content

NIST AI Risk Management Framework

A voluntary framework by the US National Institute of Standards and Technology for managing risks across the AI system lifecycle.

United States
Framework
Advisory
Framework published: 2023-01-26

NIST-AI-100-1-and-600-1Source checked: Resources ↗

Overview

The NIST AI Risk Management Framework (AI RMF 1.0), released on 26 January 2023, is a voluntary guidance document developed by the National Institute of Standards and Technology to help organisations design, develop, deploy, and use AI systems in a trustworthy and responsible manner. While not legally binding, the AI RMF has become a de facto standard for AI governance in the United States and is increasingly referenced in regulatory guidance worldwide.

The framework is structured around four core functions: Govern, Map, Measure, and Manage. These functions provide a flexible, structured approach to AI risk management that can be adapted to any organisation's size, sector, and risk tolerance.

The GOVERN function establishes and maintains the organisational structures, policies, and processes for AI risk management. It emphasises leadership accountability, stakeholder engagement, and the integration of AI risk management into broader enterprise risk management. This function recognises that effective AI governance requires cultural change, not just technical controls.

The MAP function is about understanding the context in which AI systems operate. It involves identifying and categorising AI systems, understanding their intended purposes and potential impacts, and recognising the broader societal context of AI deployment. Mapping also includes identifying relevant stakeholders and understanding the legal and regulatory landscape.

The MEASURE function focuses on employing quantitative and qualitative methods to analyse, assess, benchmark, and monitor AI risks and their related impacts. This includes developing metrics for trustworthiness characteristics such as accuracy, fairness, privacy, security, resilience, transparency, explainability, and accountability.

The MANAGE function involves allocating resources and implementing plans to respond to, recover from, and communicate about AI risks. It includes prioritising risks, implementing mitigation strategies, and establishing processes for ongoing monitoring and adjustment.

The companion document, the NIST AI RMF Playbook, provides suggested actions and references for each subcategory, making the framework highly practical for implementation. The Playbook is a living document that NIST updates as practices evolve.

The AI RMF was developed through an extensive multi-stakeholder process involving hundreds of organisations from industry, academia, civil society, and government. This collaborative development process has given the framework broad legitimacy and acceptance across sectors.

The AI RMF is voluntary guidance, not a statute or certification. EO 14110 referenced NIST work historically but was revoked on 20 January 2025. Any current procurement, contractual or sector-specific duty requires its own source and applicability check. The July 2024 Generative AI Profile complements AI RMF 1.0 rather than replacing it.

Review points

  1. GOVERN: Establish AI governance structures with clear roles, responsibilities, and accountability

  2. GOVERN: Develop organisational AI risk management policies and processes

  3. GOVERN: Foster a culture of responsible AI development and use

  4. MAP: Inventory and categorise all AI systems by context, purpose, and risk

  5. MAP: Identify intended and unintended impacts of AI systems on people and communities

  6. MAP: Understand legal, regulatory, and ethical requirements for each AI system

  7. MEASURE: Develop and apply metrics for AI trustworthiness characteristics

  8. MEASURE: Assess AI system performance, fairness, bias, and reliability

  9. MEASURE: Monitor AI systems for drift, degradation, and emerging risks

  10. MANAGE: Prioritise identified AI risks based on impact and likelihood

  11. MANAGE: Implement risk response strategies (mitigate, transfer, accept, avoid)

  12. MANAGE: Establish incident response and communication plans for AI failures

  13. Engage diverse stakeholders throughout the AI lifecycle

  14. Document and communicate AI risk management activities and decisions

Key Dates & Timeline

  1. NIST publishes Request for Information on AI RMF

  2. Initial draft AI RMF released for public comment

  3. Second draft released

  4. AI RMF 1.0 officially released

  5. Complete AI RMF Playbook published

  6. US Executive Order on AI references NIST AI RMF

  7. Draft Generative AI Profile released for consultation

  8. Final Generative AI Profile, NIST AI 600-1, released

  9. EO 14110 revoked; AI RMF remains a voluntary framework

Who It Affects

  • US federal agencies (referenced in Executive Order on AI)
  • AI developers and deployers seeking a governance framework
  • Organisations responding to US state-level AI legislation
  • Government contractors developing or procuring AI systems
  • Any organisation seeking to demonstrate responsible AI practices
  • International organisations looking for alignment with US AI governance expectations

Frequently Asked Questions

Is the NIST AI RMF legally mandatory?

The AI RMF itself is voluntary. It does not create a general legal mandate or certify compliance. Check any separate contract, procurement condition or sector rule that incorporates it. The revoked EO 14110 must not be treated as current authority.

How does the NIST AI RMF differ from the EU AI Act?

The NIST AI RMF is a voluntary risk management framework, while the EU AI Act is a binding law. The RMF provides flexible guidance for managing AI risks; the EU AI Act imposes specific legal obligations with penalties. Many organisations use both: the RMF for governance and the EU AI Act for legal compliance.

Does the NIST AI RMF address generative AI?

Yes. NIST released the final Generative AI Profile, NIST AI 600-1, on 26 July 2024 after an April draft. It is a companion to AI RMF 1.0 that addresses generative-AI risks and suggested actions.

Regulation Updates

Stay Ahead of AI Regulations

Receive AI regulatory updates to help prepare your next review.