NIST AI RMF
NIST AI Risk Management Framework
A voluntary framework from the US National Institute of Standards and Technology (NIST) for managing AI risks through four functions: Govern, Map, Measure and Manage.
The NIST AI Risk Management Framework (AI RMF 1.0), document NIST AI 100-1, was released on 26 January 2023. It is not a law but a framework intended for voluntary use: it fines nobody and has no certificate. Because it gives everyone a shared vocabulary, it has become one of the most cited references for AI risk management, in the US and beyond.
The framework first defines the characteristics of trustworthy AI: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed.
Its Core has four functions: - GOVERN: risk culture, policies, roles, accountability, third- party risk. A cross-cutting function infused through the other three. 6 categories. - MAP: understand the context. What is the system for, who uses it, who does it affect, what assumptions does it rely on, what are the possible benefits and harms? 5 categories. - MEASURE: assess, test and monitor the mapped risks with quantitative and qualitative methods — accuracy, safety, fairness/ bias, privacy, environmental impact. 4 categories. - MANAGE: prioritise risks and act (mitigate, transfer, accept or don't deploy), respond to incidents, deactivate the system if needed. 4 categories.
Each category breaks down into numbered subcategories (e.g. MAP 1.1: intended purpose and context are documented; MEASURE 2.11: fairness and bias are evaluated; MANAGE 2.4: there are mechanisms to disengage systems with unexpected outcomes). These are outcomes, not a to-do list; the separately published Playbook suggests how to reach them.
Profiles adapt the framework to a sector or technology. The most important one is the Generative AI Profile (NIST AI 600-1), published on 26 July 2024. It defines 12 risks unique to or exacerbated by generative AI: CBRN information, confabulation (hallucination), dangerous/violent/hateful content, data privacy, environmental impacts, harmful bias and homogenisation, human-AI configuration, information integrity, information security, intellectual property, obscene/degrading/abusive content, and value chain and component integration. For each, it suggests concrete actions mapped to the four functions.
Status as of October 2026: the current version is still AI RMF 1.0. NIST states the framework is being revised as part of the White House AI Action Plan; no revised text has been published yet. In April 2026 NIST released a concept note for a critical infrastructure profile.
It does not replace binding law such as the EU AI Act, but it is a good skeleton for the risk management process such laws ask for.
Like a pilot's checklist culture. Before take-off you understand the route and weather (Map), you read the instruments (Measure), and when something goes wrong you run the procedure or decide to land (Manage). Above all of it sit the airline's rules on who the captain is, how crews are trained and how incidents get reported (Govern). The checklist doesn't fly the plane, but it catches the forgotten step.
An insurer builds a RAG assistant to answer policyholders' questions and uses the AI RMF as a guide:
1. Govern: the business owner is the customer service director. Risk appetite is written down: "The assistant informs, it never decides claims." The model vendor goes through a supplier assessment (GOVERN 6). 2. Map: users are policyholders; wrong coverage information can cause financial harm. From the GenAI Profile, confabulation, data privacy and information security (prompt injection) are picked as the top three risks. 3. Measure: a 300-question test set measures grounding against sources, personal data leakage and injection attempts. Threshold: unsupported claims below 2%. 4. Manage: a release that misses a threshold doesn't ship. In production, answers without a source are routed to a human; there is a kill switch and an incident response process for serious failures.
No regulator required this; but the audit committee's "how do we manage these risks?" now has a documented answer.
system: AI-031 policy assistant (RAG)
framework: NIST AI RMF 1.0 + GenAI Profile (NIST AI 600-1)
govern:
owner: customer-service-director
risk_appetite: "Informs, never decides"
third_party: vendor-assessment-2026-08.pdf # GOVERN 6
map:
intended_use: "Q&A about policy coverage" # MAP 1.1
affected: [policyholders, call centre]
genai_risks: # picked from the 12 risks in 600-1
- confabulation
- data_privacy
- information_security
measure:
eval_set: evals/policy-qa-v4.jsonl # 300 questions
metrics:
unsupported_claim_rate: { threshold: 0.02 }
pii_leak_rate: { threshold: 0.0 }
injection_success_rate: { threshold: 0.01 }
cadence: every release + monthly production sample
manage:
release_gate: "No deploy until every threshold passes"
fallback: "Answer without a source → human agent"
kill_switch: feature-flag/policy-assistant # MANAGE 2.4
incident_runbook: runbooks/ai-incident.md# MAP workshop — 60 minutes, product + legal + security + support
1. What exactly will the system do, and not do? (one sentence)
2. Who uses it, and who is affected without ever seeing the screen?
3. What is the worst realistic outcome of a wrong answer?
4. What data does it see? Any personal data?
5. What assumptions are we relying on? (e.g. "the docs are current")
6. Which of the GenAI Profile's 12 risks apply to us?
7. How will we measure them? What is the acceptance threshold?
8. Is not deploying an option? What's the alternative?
Output: risk register + measurement plan (input to MEASURE)- When building an AI risk management process from scratch and you need a shared vocabulary and skeleton
- When US customers, public bodies or investors ask 'are you aligned with the NIST AI RMF?'
- To decide systematically which risks to look at in generative AI projects (GenAI Profile)
- To raise maturity before tackling ISO/IEC 42001 or AI Act readiness
- If you need a certificate or proof of legal compliance — the AI RMF has no certification and does not substitute for AI Act compliance
- Filling in every subcategory like a checklist — the framework is meant to be tailored to context
- A full-scale implementation for a small, low-risk internal tool — the burden is disproportionate
Skipping Govern
Teams usually jump straight to Measure. But if ownership, risk appetite and decision rights are unclear, measurements become charts nobody acts on.
Claiming to manage without measuring
Every risk listed in Map needs a measurement and an acceptance threshold. Without thresholds, 'can this ship?' gets answered arbitrarily in Manage.
A one-off exercise
The framework is iterative. When the model, data or usage changes, run Map and Measure again; a once-a-year assessment won't catch drift in production.
Not tracking the version
AI RMF 1.0 is being revised. Record which version and which profile your internal documents rely on, and update the mapping when a new version ships. This page is informational.