What Is NIST AI RMF?

Summary

The NIST AI Risk Management Framework is a voluntary AI governance framework published by the U.S. National Institute of Standards and Technology to help organizations identify, assess, and manage AI risk throughout the AI lifecycle. This article explains the four NIST AI RMF functions — Govern, Map, Measure, and Manage — how the framework relates to ISO/IEC 42001, the EU AI Act, and traditional cybersecurity frameworks, and why organizations need continuous AI discovery and risk scoring to operationalize it.

Key Takeaways

NIST AI RMF stands for the NIST AI Risk Management Framework.

The framework was published by the U.S. National Institute of Standards and Technology and released in January 2023.

NIST AI RMF is voluntary guidance, not a regulation.

The framework is structured around four core functions: Govern, Map, Measure, and Manage.

Govern focuses on policies, procedures, accountability, culture, and organizational responsibility for AI risk.

Map focuses on identifying AI systems, understanding their context, and determining which risks are relevant to each use case.

Measure focuses on assessing and tracking AI risk using consistent methods and metrics.

Manage focuses on prioritizing and responding to the highest-impact AI risks.

NIST AI RMF is different from ISO/IEC 42001 because NIST is voluntary and has no certification path, while ISO/IEC 42001 is a certifiable AI management system standard.

NIST AI RMF is different from the EU AI Act because the EU AI Act is binding law for in-scope organizations, while NIST is guidance.

The framework does not automatically discover AI systems. Organizations still need an AI inventory, continuous visibility, and risk-scoring tools to make the framework operational.

What Is NIST AI RMF?

What Is NIST AI RMF?

The NIST AI Risk Management Framework (AI RMF) is a voluntary framework published by the US National Institute of Standards and Technology to help organizations identify, assess, and manage risks associated with AI systems throughout their lifecycle. Released in January 2023, it has become the most widely referenced AI governance standard in the United States, cited in vendor contracts, procurement requirements, and internal governance programs even though adopting it carries no legal obligation.

Key facts about NIST AI RMF:

  • Published by: US National Institute of Standards and Technology (NIST), part of the Department of Commerce
  • Released: January 2023, version 1.0
  • Status: voluntary, not a regulation
  • Structure: four core functions — Govern, Map, Measure, Manage
  • Update cycle: intended as a living document, with formal community review expected by 2028
  • Companion resource: the NIST Generative AI Profile, which applies the RMF specifically to generative AI risks

What are the four functions of NIST AI RMF?

Govern. Establishes the policies, procedures, accountability structures, and organizational culture needed to manage AI risk. This function is meant to run continuously and cross-cut the other three, embedding risk awareness into how AI decisions are made rather than treating it as a separate checklist step.

Map. Establishes context: what AI systems exist, what they're for, who they affect, and what risks are relevant to their specific use case. This is the inventory-and-classification function, and in practice it is the step most organizations underinvest in, since it requires knowing about AI systems that were never formally procured.

Measure. Applies methods and metrics to assess identified risks, testing AI systems for issues like bias, security vulnerabilities, and reliability, and tracking those measurements over time rather than as a one-time assessment.

Manage. Prioritizes and responds to risks based on what Measure surfaces, allocating resources to the highest-impact issues and defining how the organization responds when a risk materializes.

The four functions are not strictly sequential. Govern operates continuously across the other three, and organizations typically cycle through Map, Measure, and Manage repeatedly as AI systems and their usage evolve.

Who needs to use NIST AI RMF?

Nobody is legally required to. It was written for any organization designing, developing, deploying, or using AI systems. Its adoption has concentrated among a few groups: US federal contractors and agencies (where it increasingly appears in procurement language), organizations without an EU footprint that still want a defensible governance structure, and companies using it as a common reference point before layering a certifiable standard like ISO/IEC 42001 on top.

How does NIST AI RMF relate to other frameworks?

Vs. ISO/IEC 42001. NIST AI RMF is free and voluntary, with no certification path. ISO/IEC 42001 is a certifiable management system standard, auditable by a third party. Many organizations use NIST's four functions as an internal working structure, then pursue ISO certification when a customer or regulator specifically requires independent verification.

Vs. the EU AI Act. NIST AI RMF is guidance; the EU AI Act is binding law for in-scope organizations, with a risk-tier classification system (unacceptable, high, limited, minimal) that has no direct NIST equivalent. Organizations operating in both jurisdictions typically map NIST's Map function to the Act's classification requirement, since both start from the same question: what AI exists, and how risky is it.

Vs. traditional cybersecurity frameworks. NIST also publishes the Cybersecurity Framework (CSF), a separate and older standard for general information security. AI RMF was designed to complement CSF, not replace it; an organization typically runs both, since AI risk (bias, hallucination, model behavior) is distinct from the confidentiality/integrity/availability risks CSF addresses.

What does implementing NIST AI RMF actually involve?

  1. Establish governance structures first (Govern). Assign accountability for AI risk before assessing anything, so findings from Map and Measure have an owner.
  2. Build the AI inventory (Map). Identify every AI system in use, its purpose, and its context, including systems adopted outside formal procurement. This step depends entirely on visibility into actual AI use, not just approved deployments.
  3. Assess and track risk (Measure). Apply consistent metrics across identified systems: security posture, bias testing, reliability, and other risk dimensions relevant to each system's context.
  4. Prioritize and respond (Manage). Direct resources at the highest-risk findings, and define escalation paths for when a risk materializes in production.

The framework itself does not specify how organizations discover the AI systems Map requires, or automate the tracking Measure calls for. That operational gap is why most implementations pair the framework with continuous AI discovery and risk-scoring tooling rather than working entirely from manual documentation.

Does NIST AI RMF cover AI agents and generative AI specifically?

The core AI RMF is intentionally general, written to apply across AI system types. NIST has since published a Generative AI Profile that applies the four functions specifically to generative AI risks like hallucination, data memorization, and content provenance. Agentic AI and MCP-connected systems are not yet the subject of a dedicated NIST profile, so organizations governing agents currently apply the core RMF's general functions to that context, mapping agent-specific risks (standing credentials, autonomous action, identity confusion) into the same Govern-Map-Measure-Manage structure used for everything else.

FAQ

What does NIST AI RMF stand for? NIST AI Risk Management Framework, published by the US National Institute of Standards and Technology to help organizations manage risks associated with AI systems.

Is NIST AI RMF mandatory? No. It is voluntary guidance, though it increasingly appears as a reference point in vendor contracts, procurement requirements, and internal governance policies, especially for organizations working with the US federal government.

What are the four functions of NIST AI RMF? Govern, Map, Measure, and Manage. Govern establishes policy and accountability, Map identifies AI systems and their context, Measure assesses and tracks risk, and Manage prioritizes and responds to it.

Is NIST AI RMF the same as ISO 42001? No. NIST AI RMF is free, voluntary, and US-focused with no certification path. ISO/IEC 42001 is an international, certifiable management system standard. Organizations often use NIST's structure internally and pursue ISO certification separately when they need independent verification.

Does NIST AI RMF apply to AI agents? The core framework's four functions are general enough to apply to any AI system, including agents, but NIST has not yet released a dedicated profile for agentic AI, unlike the existing Generative AI Profile. Organizations currently map agent-specific risks into the same general structure.

See Your AI Attack Surface

Discover every AI tool, agent, and model running in your enterprise — before attackers do.
Request a Demo

Related Articles

No items found.