Organizations building or deploying AI
Any company that designs, develops, procures, or operates AI systems can use the AI RMF to structure how it governs those systems, from a single predictive model to an enterprise portfolio.
The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary framework published by the U.S. National Institute of Standards and Technology in January 2023. It helps organizations govern, map, measure, and manage the risks of artificial intelligence systems, and it defines seven characteristics of trustworthy AI.
The NIST AI Risk Management Framework is a voluntary set of guidance for identifying, assessing, and managing the risks of artificial intelligence. It was published by the U.S. National Institute of Standards and Technology as AI RMF 1.0, document number NIST AI 100-1, on January 26, 2023. Its purpose is to help organizations that design, develop, deploy, or use AI systems build and operate them in a trustworthy and responsible way.
The framework is deliberately non-prescriptive. It does not certify products, mandate specific tools, or apply only to one sector. Instead it describes outcomes an organization should aim for, and it leaves the how to each organization based on its own use cases, risk tolerance, and resources. Two structures carry the framework: four functions that describe the work of managing AI risk, and seven characteristics that describe what trustworthy AI looks like. The characteristics are the what; the functions are the how.
The AI RMF is a resource, not a regulation. NIST does not enforce it, though it is increasingly referenced as a baseline for responsible AI.
It focuses attention where the potential for harm is highest, proportionate to context, rather than treating every AI system the same.
It applies across the AI lifecycle, from design and data through development, deployment, and ongoing operation.
“The AI RMF is intended for voluntary use and to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems.”
AI is being deployed into decisions that affect people, money, and safety faster than governance can keep up. The AI RMF gives organizations a common language and a defensible structure for closing that gap before a regulator, a customer, or an incident forces the issue.
Because it was built through open consensus and is technology-neutral, the AI RMF has become the reference many US agencies, buyers, and standards bodies point to when they ask what responsible AI looks like.
AI regulation is arriving unevenly across jurisdictions. Adopting a recognized framework now lets an organization show diligence and adapt as specific rules land, rather than starting from zero later.
The AI RMF mirrors the risk-based, outcome-driven logic of the NIST Cybersecurity Framework, so risk and compliance teams can fold AI risk into the enterprise program they already run.
The heart of the AI RMF is four functions. Govern is a cross-cutting function that informs the other three. Map, Measure, and Manage then run in a cycle for each AI system: understand the risk, quantify it, and act on it.
Build a culture of AI risk management.
Govern is the cross-cutting function that runs through the other three. It establishes the policies, accountability structures, roles, and oversight that make AI risk management repeatable rather than ad hoc. It covers legal and regulatory alignment, workforce diversity and competency, third-party and supply-chain risk, and clear lines of responsibility for AI decisions. NIST positions Govern as the foundation that Map, Measure, and Manage all depend on.
Establish context and frame risk.
Map builds the context needed to identify risks for a specific AI system. It documents the intended purpose, the deployment setting, the people and communities affected, the assumptions behind the system, and the categories of potential harm. Because risks are easier to prevent than to fix after deployment, the Map function front-loads the work of understanding where an AI system can go wrong before it goes live.
Analyze, assess, and track AI risks.
Measure applies quantitative, qualitative, and mixed-method tools to analyze, benchmark, and monitor the risks framed during Map. It covers testing for trustworthiness characteristics such as validity, safety, security, bias, and explainability, and it tracks how those metrics change over time. The output feeds directly into the Manage function so that decisions are grounded in evidence rather than assumption.
Prioritize and act on risks.
Manage allocates resources to the risks that Measure surfaced, based on their projected impact and the organization's risk tolerance. It covers treating, transferring, or accepting risk, planning for incidents and recovery, documenting residual risk, and responding when an AI system behaves outside expected bounds. Manage keeps the response proportionate to the risk and traceable back to a decision owner.
The order matters less than the loop. NIST intends the functions to be iterative, not a one-time waterfall: as an AI system changes, as new risks are mapped, and as measurement produces new evidence, the organization returns to Manage and adjusts. Govern sits underneath all of it, keeping the accountability and policy in place that make the loop repeatable.
RiskWatch lets you assess AI systems against a framework, catalog them in a risk register, and cross-map the controls to the standards you already run. See it on your own AI use cases.
AI RMF 1.0 defines trustworthy AI through seven characteristics. They are not a checklist to maximize in isolation. NIST is explicit that they interact and sometimes trade off, and that validity and reliability are the foundation the rest depend on.
The system does what it is meant to do, accurately and consistently, and keeps doing so under the conditions it will actually face. NIST treats validity and reliability as the necessary base condition for all the other characteristics.
The system does not, under defined conditions, endanger human life, health, property, or the environment. Safety calls for responsible design, clear deployment limits, and the ability to shut down or hand off when something goes wrong.
The system can withstand adversarial attack and unexpected events, and it can recover or degrade gracefully rather than fail catastrophically. This covers confidentiality, integrity, and availability of the model and its data.
Information about the system is available to the people who need it, and clear responsibility exists for its outcomes. Transparency spans the AI lifecycle, from training data and design choices to deployment decisions and monitoring.
The mechanisms behind a system's output can be described (explainability) and the meaning of that output in context can be understood (interpretability). Together they let operators and affected people make sense of why a system did what it did.
The system safeguards human autonomy, identity, and dignity through practices such as data minimization, anonymization, and privacy-preserving design. Privacy values include anonymity, confidentiality, and control over personal data.
The system promotes equality and equity, and it actively manages harmful bias. NIST names three categories of bias to address: systemic, computational and statistical, and human-cognitive. Fairness is context-dependent and demands ongoing attention.
Because the characteristics can pull against each other, for example a more explainable model may be less accurate, NIST frames trustworthiness as a balancing act specific to context. The role of the Measure function is to make those trade-offs visible and deliberate rather than accidental.
NIST wrote the framework for any AI actor across the lifecycle, which in practice means three overlapping groups. The framework scales from a startup with one model to an enterprise with a portfolio of them.
Any company that designs, develops, procures, or operates AI systems can use the AI RMF to structure how it governs those systems, from a single predictive model to an enterprise portfolio.
U.S. federal agencies and the contractors that serve them increasingly reference the AI RMF as the common baseline for responsible AI, which pulls it into supply-chain and procurement requirements.
GRC, CISO, and internal audit functions use the framework to fold AI risk into an existing enterprise risk program instead of standing up a separate, disconnected process for it.
The framework describes outcomes, not a step-by-step project plan. This is a practical sequence most organizations follow to turn the four functions into a running program. The companion AI RMF Playbook offers suggested actions for each outcome.
Define who owns AI risk, write the policies that set your risk tolerance, and confirm the legal and regulatory obligations that apply. Governance comes first because every later step depends on clear accountability and documented appetite.
Build a catalog of every AI system in use, and for each one record its purpose, its deployment context, the people it affects, and the categories of harm it could cause. This is the AI equivalent of a risk register, and it becomes the source of truth for everything downstream.
Assess each system for validity, safety, security, bias, transparency, explainability, and privacy. Use quantitative metrics where you have them and structured qualitative review where you do not, and record the results so they can be tracked over time.
Rank the risks Measure surfaced by projected impact, decide whether to treat, transfer, or accept each one, and document residual risk. Set monitoring and incident-response plans so a system that drifts out of bounds triggers a response, not a surprise.
Link your AI controls to the frameworks you already run, such as ISO 27001, SOC 2, or the NIST Cybersecurity Framework, so one control satisfies many requirements. Then reassess whenever a model, its data, its use case, or the regulatory landscape changes.
On July 26, 2024, NIST released the Generative AI Profile, published as NIST AI 600-1. It is a companion resource, developed in response to a 2023 U.S. Executive Order on AI, that applies the AI RMF specifically to generative AI. It identifies the risks that are unique to or amplified by generative AI and maps suggested actions across the same Govern, Map, Measure, and Manage functions.
A profile, in NIST's terms, is an implementation of the AI RMF functions for a specific setting, application, or technology, based on an organization's requirements, risk tolerance, and resources. The Generative AI Profile organizes generative-AI risks into a set of categories, covering concerns such as confabulation (fabricated or false output), dangerous or harmful content, data privacy, harmful bias, information integrity, and intellectual property. It is a resource organizations draw from, not a certification they pass.
Alongside the framework, NIST maintains the AI RMF Playbook on its Trustworthy and Responsible AI Resource Center. The Playbook offers suggested actions, references, and documentation guidance for achieving the outcomes in each function. NIST states that the AI RMF and its Playbook already apply to managing generative-AI risks, and the Generative AI Profile builds on them.
RiskWatch is a framework-based assessment and GRC platform, in business since 1993. It is not an AI model-testing tool, and it does not replace the technical evaluation your data science team runs. What it does is give the governance side of the AI RMF a system of record, so the Govern, Map, and Manage work has somewhere to live and stay current.
Turn the AI RMF outcomes into a repeatable assessment. RiskWatch applies its framework-based assessment engine, the same one that supports 40+ regulatory frameworks, to score AI systems against Govern, Map, Measure, and Manage and produce a defensible record.
Inventory every AI system as the framework's Map function requires, with purpose, context, owner, and risk scoring, so your AI systems sit in the same enterprise risk register as the rest of your risk landscape.
Cross-mapping lets one AI control satisfy requirements in ISO 27001, SOC 2, the NIST Cybersecurity Framework, and more, so you build the evidence once and reuse it across obligations instead of duplicating the work.
An Audit Register tracks who did what and when, and role-based access keeps assessment data scoped to the right people. RiskWatch itself is SOC 2 and ISO 27001 aligned, and holds a 4.7 rating on G2.
The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary framework published by the U.S. National Institute of Standards and Technology in January 2023. It gives organizations a structured, flexible way to identify, assess, and manage the risks of artificial intelligence systems and to build AI that is trustworthy and responsible. It is organized around four functions (Govern, Map, Measure, and Manage) and seven characteristics of trustworthy AI.
NIST released AI RMF 1.0, documented as NIST AI 100-1, on January 26, 2023. NIST developed it through an open, consensus-driven process with input from industry, academia, civil society, and government. A companion Generative AI Profile, NIST AI 600-1, followed on July 26, 2024.
The four core functions are Govern, Map, Measure, and Manage. Govern establishes the culture, policies, and accountability for AI risk and runs across the other three. Map builds context and identifies risks for a specific system. Measure analyzes and tracks those risks using quantitative and qualitative methods. Manage prioritizes and acts on the risks based on impact and the organization's risk tolerance.
AI RMF 1.0 defines trustworthy AI through seven characteristics: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair with harmful bias managed. Validity and reliability are treated as the necessary foundation, and the remaining characteristics are balanced according to context.
No. The NIST AI RMF is voluntary. It is a resource organizations choose to adopt rather than a regulation. In practice, though, it is becoming a de facto baseline: federal agencies, procurement requirements, and other frameworks increasingly reference it, so many organizations treat conformance as an expectation even though NIST does not enforce it.
The Generative AI Profile, published as NIST AI 600-1 in July 2024, is a companion resource that applies the AI RMF to generative AI. It identifies risks that are unique to or amplified by generative AI, maps them across the Govern, Map, Measure, and Manage functions, and suggests actions organizations can take. It was developed in response to a 2023 U.S. Executive Order on AI.
The AI RMF Playbook is a companion resource, hosted on the NIST Trustworthy and Responsible AI Resource Center, that offers suggested actions, references, and documentation guidance for achieving the outcomes in each of the four functions. It is not a checklist to complete in order; organizations use the parts that fit their context, risk tolerance, and resources.
The AI RMF is designed to work alongside frameworks organizations already run. It shares the risk-based, outcome-driven approach of the NIST Cybersecurity Framework, and it complements management-system standards such as ISO/IEC 42001 for AI. Many controls you build for AI governance can be cross-mapped to ISO 27001, SOC 2, or the NIST CSF, so a single control effort can satisfy several obligations at once.
RiskWatch runs assessments against 40+ frameworks, catalogs your AI systems in a risk register, and cross-maps controls so one effort satisfies many obligations.
No credit card required · 30-day free trial · Cancel anytime