NIST AI RMF:
Govern, Map, Measure, Manage, explained.
What the NIST AI Risk Management Framework asks for, what each function contains, what the Generative AI Profile adds, and how it relates to ISO 42001 and the EU AI Act, for teams outside the US as much as inside it.
Last updated Published by TryTrustableNot legal advice
What is the NIST AI RMF?
The NIST AI Risk Management Framework, AI RMF 1.0, is voluntary guidance from the US National Institute of Standards and Technology, released in January 2023, for managing risks from AI systems. It is organised into four functions, Govern, Map, Measure and Manage, and is not a law, a standard or a certification.
The framework document is NIST AI 100-1, released on 26 January 2023, with a companion Playbook of suggested actions on NIST’s AI RMF page. Part 1 frames the problem: who the AI actors are, how AI risk differs from software risk, and seven characteristics of trustworthy AI. Part 2 is the core: the four functions, broken into categories and subcategories.
The seven characteristics are: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair, with harmful bias managed. They are the vocabulary the rest of the framework uses to describe what can go wrong.
What are the four functions of the NIST AI RMF?
The four NIST AI RMF functions are Govern, which sets culture, policy and accountability; Map, which establishes context and identifies risks for each AI system; Measure, which analyses and tracks those risks with tests and metrics; and Manage, which prioritises and acts on them. Govern applies across the other three.
The core has 19 categories and 72 subcategories. The functions are not a sequence; Map, Measure and Manage repeat across a system's life, and Govern sits across all three.
| Function | Categories | What it asks for | Evidence that shows it runs |
|---|---|---|---|
| Govern | 6 | Policies and processes for AI risk, accountability structures, workforce diversity and competence, a culture that surfaces risk, engagement with affected parties, third-party and supply chain risk | An approved AI policy, named owners, an inventory, supplier reviews |
| Map | 5 | Context and intended purpose, categorisation of the system, capabilities and limitations, risks and benefits of each component including third-party ones, impacts on individuals and society | A record per system: purpose, users, data, known limits, impacts assessed |
| Measure | 4 | Methods and metrics, evaluation against the trustworthiness characteristics, tracking risks over time, feedback on whether measurement works | Dated evaluation runs, bias and robustness results, drift tracked across runs |
| Manage | 4 | Prioritising and treating risks, maximising benefit and minimising harm, managing third-party risk, response, recovery and communication | Treatment decisions with owners, incident records, decommissioning decisions |
Category counts from AI RMF 1.0 (NIST AI 100-1). Descriptions paraphrased.
What is the NIST Generative AI Profile?
The Generative AI Profile, NIST AI 600-1, published in July 2024, applies the AI RMF to generative AI. It names twelve risks that generative AI creates or makes worse, such as confabulation, information integrity, information security and data privacy, and suggests more than two hundred actions mapped to the framework's functions.
NIST AI 600-1 was released on 26 July 2024. Its twelve risks are CBRN information or capabilities; confabulation; dangerous, violent or hateful content; data privacy; environmental impacts; harmful bias and homogenisation; human-AI configuration; information integrity; information security; intellectual property; obscene, degrading or abusive content; and value chain and component integration.
For a company building on a third-party foundation model, the value chain risk is the one to start with: the model, the prompt and the tools it can reach all change behaviour, and each is often owned by a different team or supplier.
How does the NIST AI RMF relate to ISO 42001 and the EU AI Act?
The NIST AI RMF is a voluntary risk method, ISO/IEC 42001 is a certifiable AI management system standard, and the EU AI Act is law regulating individual AI systems. They fit together: the RMF supplies the risk method, 42001 the auditable management system around it, and the Act the legal obligations and dates.
NIST publishes crosswalks from the RMF to other frameworks, including one to the final draft of ISO/IEC 42001. The side-by-side comparison is on ISO 42001 vs NIST AI RMF; the standard itself is explained in the ISO 42001 guide; the Act's tiers and dates are in the EU AI Act guide. Neither the RMF nor ISO/IEC 42001 gives a presumption of conformity under the AI Act.
For Indian companies, the RMF is also a practical way to operationalise the principles in India's AI governance guidelines, which are likewise voluntary.
How to start using the NIST AI RMF
Start with Govern and Map, because Measure and Manage have nothing to work on until you know which systems you run and what they are for.
| # | Step | Function | Done when |
|---|---|---|---|
| 1 | List every AI system in use: built, bought, and embedded in SaaS | Govern, Map | Each has an owner, purpose, provider and data sources |
| 2 | Write an AI policy and set risk tolerance | Govern | Approved by leadership |
| 3 | Map each system's context, users and impacts | Map | A record per system |
| 4 | Choose metrics and run evaluations against the characteristics that matter for that system | Measure | Dated results, repeated on change |
| 5 | Decide treatment for each material risk, including not deploying | Manage | Decisions with owners and dates |
| 6 | Add the Generative AI Profile's risks for generative systems | All four | Twelve risks considered, each accepted or treated |
Where the platform fits
The NIST AI RMF is on the coverage list with ISO 42001 and the EU AI Act. The AI governance engine registers models, prompts and MCP servers, runs judge-scored evaluations with stored transcripts, and tracks drift and bias across runs, which is the evidence Map and Measure ask for. Cross-framework mapping lets the same result answer an RMF subcategory, an ISO 42001 control and an AI Act requirement. The judgement in Govern and Manage stays with your people.
The things people ask us
What is the NIST AI RMF?
The NIST AI Risk Management Framework, AI RMF 1.0, is voluntary guidance from the US National Institute of Standards and Technology, released in January 2023, for managing risks from AI systems. It is organised into four functions, Govern, Map, Measure and Manage, and is not a law, a standard or a certification.
Is the NIST AI RMF mandatory?
No. NIST describes it as intended for voluntary use. It becomes binding only when something else makes it so, such as a customer contract, a US federal procurement requirement or an internal policy. Outside the US it is used as a well-documented method rather than a legal requirement.
What are the four functions of the NIST AI RMF?
The four NIST AI RMF functions are Govern, which sets culture, policy and accountability; Map, which establishes context and identifies risks for each AI system; Measure, which analyses and tracks those risks with tests and metrics; and Manage, which prioritises and acts on them. Govern applies across the other three.
What is the NIST Generative AI Profile?
The Generative AI Profile, NIST AI 600-1, published in July 2024, applies the AI RMF to generative AI. It names twelve risks that generative AI creates or makes worse, such as confabulation, information integrity, information security and data privacy, and suggests more than two hundred actions mapped to the framework's functions.
Can you be certified against the NIST AI RMF?
No. There is no NIST AI RMF certification scheme, and a vendor offering one is selling its own opinion. For a certificate, organisations use ISO/IEC 42001, which is certifiable by accredited bodies. Many use the NIST AI RMF as the risk method inside a 42001 management system.
Does the NIST AI RMF satisfy the EU AI Act?
No. The EU AI Act is law with its own classification, documentation and conformity assessment for each system. The NIST AI RMF can supply a risk method and much of the evidence, but it is not a harmonised standard under the Act and gives no presumption of conformity.
Is the NIST AI RMF being updated?
NIST says AI RMF 1.0 is being revised as part of the White House AI Action Plan. As of September 2026 version 1.0 remains current, alongside the Generative AI Profile and profiles in development, including a concept note for critical infrastructure published in April 2026. Check NIST's page for the current version.
See an AI system mapped to the RMF.
We register a real model, run a judged evaluation and show the result against NIST AI RMF Measure, ISO 42001 and the EU AI Act from one record.