Skip to main content
Case studyFortune 100: 80% less compliance workRead the Story
RiskWatch
AI governance · Pillar guide · Updated July 2026

NIST AI Risk Management Framework (AI RMF), explained

The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary framework published by the U.S. National Institute of Standards and Technology in January 2023. It helps organizations govern, map, measure, and manage the risks of artificial intelligence systems, and it defines seven characteristics of trustworthy AI.

Published
Jan 2023
Document
NIST AI 100-1
Functions
Govern · Map · Measure · Manage
Status
Voluntary
01 · Definition

What is the NIST AI Risk Management Framework?

The NIST AI Risk Management Framework is a voluntary set of guidance for identifying, assessing, and managing the risks of artificial intelligence. It was published by the U.S. National Institute of Standards and Technology as AI RMF 1.0, document number NIST AI 100-1, on January 26, 2023. Its purpose is to help organizations that design, develop, deploy, or use AI systems build and operate them in a trustworthy and responsible way.

The framework is deliberately non-prescriptive. It does not certify products, mandate specific tools, or apply only to one sector. Instead it describes outcomes an organization should aim for, and it leaves the how to each organization based on its own use cases, risk tolerance, and resources. Two structures carry the framework: four functions that describe the work of managing AI risk, and seven characteristics that describe what trustworthy AI looks like. The characteristics are the what; the functions are the how.

Voluntary

The AI RMF is a resource, not a regulation. NIST does not enforce it, though it is increasingly referenced as a baseline for responsible AI.

Risk-based

It focuses attention where the potential for harm is highest, proportionate to context, rather than treating every AI system the same.

Lifecycle-wide

It applies across the AI lifecycle, from design and data through development, deployment, and ongoing operation.

“The AI RMF is intended for voluntary use and to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems.”

02 · Why it matters

Why the AI RMF matters

AI is being deployed into decisions that affect people, money, and safety faster than governance can keep up. The AI RMF gives organizations a common language and a defensible structure for closing that gap before a regulator, a customer, or an incident forces the issue.

Common baseline
A shared reference point

Because it was built through open consensus and is technology-neutral, the AI RMF has become the reference many US agencies, buyers, and standards bodies point to when they ask what responsible AI looks like.

Regulatory momentum
Ahead of the rules

AI regulation is arriving unevenly across jurisdictions. Adopting a recognized framework now lets an organization show diligence and adapt as specific rules land, rather than starting from zero later.

Enterprise fit
It plugs into GRC

The AI RMF mirrors the risk-based, outcome-driven logic of the NIST Cybersecurity Framework, so risk and compliance teams can fold AI risk into the enterprise program they already run.

03 · The core

The 4 core functions: Govern, Map, Measure, Manage

The heart of the AI RMF is four functions. Govern is a cross-cutting function that informs the other three. Map, Measure, and Manage then run in a cycle for each AI system: understand the risk, quantify it, and act on it.

  1. GOVERN

    Govern

    Build a culture of AI risk management.

    Govern is the cross-cutting function that runs through the other three. It establishes the policies, accountability structures, roles, and oversight that make AI risk management repeatable rather than ad hoc. It covers legal and regulatory alignment, workforce diversity and competency, third-party and supply-chain risk, and clear lines of responsibility for AI decisions. NIST positions Govern as the foundation that Map, Measure, and Manage all depend on.

  2. MAP

    Map

    Establish context and frame risk.

    Map builds the context needed to identify risks for a specific AI system. It documents the intended purpose, the deployment setting, the people and communities affected, the assumptions behind the system, and the categories of potential harm. Because risks are easier to prevent than to fix after deployment, the Map function front-loads the work of understanding where an AI system can go wrong before it goes live.

  3. MEASURE

    Measure

    Analyze, assess, and track AI risks.

    Measure applies quantitative, qualitative, and mixed-method tools to analyze, benchmark, and monitor the risks framed during Map. It covers testing for trustworthiness characteristics such as validity, safety, security, bias, and explainability, and it tracks how those metrics change over time. The output feeds directly into the Manage function so that decisions are grounded in evidence rather than assumption.

  4. MANAGE

    Manage

    Prioritize and act on risks.

    Manage allocates resources to the risks that Measure surfaced, based on their projected impact and the organization's risk tolerance. It covers treating, transferring, or accepting risk, planning for incidents and recovery, documenting residual risk, and responding when an AI system behaves outside expected bounds. Manage keeps the response proportionate to the risk and traceable back to a decision owner.

The order matters less than the loop. NIST intends the functions to be iterative, not a one-time waterfall: as an AI system changes, as new risks are mapped, and as measurement produces new evidence, the organization returns to Manage and adjusts. Govern sits underneath all of it, keeping the accountability and policy in place that make the loop repeatable.

Turn the four functions into a running assessment

RiskWatch lets you assess AI systems against a framework, catalog them in a risk register, and cross-map the controls to the standards you already run. See it on your own AI use cases.

04 · Trustworthy AI

The 7 characteristics of trustworthy AI

AI RMF 1.0 defines trustworthy AI through seven characteristics. They are not a checklist to maximize in isolation. NIST is explicit that they interact and sometimes trade off, and that validity and reliability are the foundation the rest depend on.

  1. 01

    Valid and reliable

    The system does what it is meant to do, accurately and consistently, and keeps doing so under the conditions it will actually face. NIST treats validity and reliability as the necessary base condition for all the other characteristics.

  2. 02

    Safe

    The system does not, under defined conditions, endanger human life, health, property, or the environment. Safety calls for responsible design, clear deployment limits, and the ability to shut down or hand off when something goes wrong.

  3. 03

    Secure and resilient

    The system can withstand adversarial attack and unexpected events, and it can recover or degrade gracefully rather than fail catastrophically. This covers confidentiality, integrity, and availability of the model and its data.

  4. 04

    Accountable and transparent

    Information about the system is available to the people who need it, and clear responsibility exists for its outcomes. Transparency spans the AI lifecycle, from training data and design choices to deployment decisions and monitoring.

  5. 05

    Explainable and interpretable

    The mechanisms behind a system's output can be described (explainability) and the meaning of that output in context can be understood (interpretability). Together they let operators and affected people make sense of why a system did what it did.

  6. 06

    Privacy-enhanced

    The system safeguards human autonomy, identity, and dignity through practices such as data minimization, anonymization, and privacy-preserving design. Privacy values include anonymity, confidentiality, and control over personal data.

  7. 07

    Fair, with harmful bias managed

    The system promotes equality and equity, and it actively manages harmful bias. NIST names three categories of bias to address: systemic, computational and statistical, and human-cognitive. Fairness is context-dependent and demands ongoing attention.

Because the characteristics can pull against each other, for example a more explainable model may be less accurate, NIST frames trustworthiness as a balancing act specific to context. The role of the Measure function is to make those trade-offs visible and deliberate rather than accidental.

05 · Audience

Who should use the NIST AI RMF?

NIST wrote the framework for any AI actor across the lifecycle, which in practice means three overlapping groups. The framework scales from a startup with one model to an enterprise with a portfolio of them.

Organizations building or deploying AI

Any company that designs, develops, procures, or operates AI systems can use the AI RMF to structure how it governs those systems, from a single predictive model to an enterprise portfolio.

Federal agencies and their vendors

U.S. federal agencies and the contractors that serve them increasingly reference the AI RMF as the common baseline for responsible AI, which pulls it into supply-chain and procurement requirements.

Risk, compliance, and security teams

GRC, CISO, and internal audit functions use the framework to fold AI risk into an existing enterprise risk program instead of standing up a separate, disconnected process for it.

06 · Implementation

How to implement the NIST AI RMF

The framework describes outcomes, not a step-by-step project plan. This is a practical sequence most organizations follow to turn the four functions into a running program. The companion AI RMF Playbook offers suggested actions for each outcome.

  1. 01

    Stand up AI governance (Govern)

    Define who owns AI risk, write the policies that set your risk tolerance, and confirm the legal and regulatory obligations that apply. Governance comes first because every later step depends on clear accountability and documented appetite.

  2. 02

    Inventory and map your AI systems (Map)

    Build a catalog of every AI system in use, and for each one record its purpose, its deployment context, the people it affects, and the categories of harm it could cause. This is the AI equivalent of a risk register, and it becomes the source of truth for everything downstream.

  3. 03

    Test against the trustworthiness characteristics (Measure)

    Assess each system for validity, safety, security, bias, transparency, explainability, and privacy. Use quantitative metrics where you have them and structured qualitative review where you do not, and record the results so they can be tracked over time.

  4. 04

    Prioritize, treat, and monitor (Manage)

    Rank the risks Measure surfaced by projected impact, decide whether to treat, transfer, or accept each one, and document residual risk. Set monitoring and incident-response plans so a system that drifts out of bounds triggers a response, not a surprise.

  5. 05

    Cross-map to your other frameworks and reassess on change

    Link your AI controls to the frameworks you already run, such as ISO 27001, SOC 2, or the NIST Cybersecurity Framework, so one control satisfies many requirements. Then reassess whenever a model, its data, its use case, or the regulatory landscape changes.

07 · The companion profile

The Generative AI Profile

On July 26, 2024, NIST released the Generative AI Profile, published as NIST AI 600-1. It is a companion resource, developed in response to a 2023 U.S. Executive Order on AI, that applies the AI RMF specifically to generative AI. It identifies the risks that are unique to or amplified by generative AI and maps suggested actions across the same Govern, Map, Measure, and Manage functions.

A profile, in NIST's terms, is an implementation of the AI RMF functions for a specific setting, application, or technology, based on an organization's requirements, risk tolerance, and resources. The Generative AI Profile organizes generative-AI risks into a set of categories, covering concerns such as confabulation (fabricated or false output), dangerous or harmful content, data privacy, harmful bias, information integrity, and intellectual property. It is a resource organizations draw from, not a certification they pass.

Related companion: the AI RMF Playbook

Alongside the framework, NIST maintains the AI RMF Playbook on its Trustworthy and Responsible AI Resource Center. The Playbook offers suggested actions, references, and documentation guidance for achieving the outcomes in each function. NIST states that the AI RMF and its Playbook already apply to managing generative-AI risks, and the Generative AI Profile builds on them.

08 · Operationalizing it

How RiskWatch helps you operationalize the AI RMF

RiskWatch is a framework-based assessment and GRC platform, in business since 1993. It is not an AI model-testing tool, and it does not replace the technical evaluation your data science team runs. What it does is give the governance side of the AI RMF a system of record, so the Govern, Map, and Manage work has somewhere to live and stay current.

Run assessments against the framework

Turn the AI RMF outcomes into a repeatable assessment. RiskWatch applies its framework-based assessment engine, the same one that supports 40+ regulatory frameworks, to score AI systems against Govern, Map, Measure, and Manage and produce a defensible record.

Catalog AI systems in a risk register

Inventory every AI system as the framework's Map function requires, with purpose, context, owner, and risk scoring, so your AI systems sit in the same enterprise risk register as the rest of your risk landscape.

Cross-map AI controls to other frameworks

Cross-mapping lets one AI control satisfy requirements in ISO 27001, SOC 2, the NIST Cybersecurity Framework, and more, so you build the evidence once and reuse it across obligations instead of duplicating the work.

Keep it auditable and access-controlled

An Audit Register tracks who did what and when, and role-based access keeps assessment data scoped to the right people. RiskWatch itself is SOC 2 and ISO 27001 aligned, and holds a 4.7 rating on G2.

09 · FAQ

Frequently asked questions

What is the NIST AI Risk Management Framework?

The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary framework published by the U.S. National Institute of Standards and Technology in January 2023. It gives organizations a structured, flexible way to identify, assess, and manage the risks of artificial intelligence systems and to build AI that is trustworthy and responsible. It is organized around four functions (Govern, Map, Measure, and Manage) and seven characteristics of trustworthy AI.

When was the NIST AI RMF released?

NIST released AI RMF 1.0, documented as NIST AI 100-1, on January 26, 2023. NIST developed it through an open, consensus-driven process with input from industry, academia, civil society, and government. A companion Generative AI Profile, NIST AI 600-1, followed on July 26, 2024.

What are the four functions of the NIST AI RMF?

The four core functions are Govern, Map, Measure, and Manage. Govern establishes the culture, policies, and accountability for AI risk and runs across the other three. Map builds context and identifies risks for a specific system. Measure analyzes and tracks those risks using quantitative and qualitative methods. Manage prioritizes and acts on the risks based on impact and the organization's risk tolerance.

What are the seven characteristics of trustworthy AI?

AI RMF 1.0 defines trustworthy AI through seven characteristics: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair with harmful bias managed. Validity and reliability are treated as the necessary foundation, and the remaining characteristics are balanced according to context.

Is the NIST AI RMF mandatory?

No. The NIST AI RMF is voluntary. It is a resource organizations choose to adopt rather than a regulation. In practice, though, it is becoming a de facto baseline: federal agencies, procurement requirements, and other frameworks increasingly reference it, so many organizations treat conformance as an expectation even though NIST does not enforce it.

What is the NIST Generative AI Profile?

The Generative AI Profile, published as NIST AI 600-1 in July 2024, is a companion resource that applies the AI RMF to generative AI. It identifies risks that are unique to or amplified by generative AI, maps them across the Govern, Map, Measure, and Manage functions, and suggests actions organizations can take. It was developed in response to a 2023 U.S. Executive Order on AI.

What is the AI RMF Playbook?

The AI RMF Playbook is a companion resource, hosted on the NIST Trustworthy and Responsible AI Resource Center, that offers suggested actions, references, and documentation guidance for achieving the outcomes in each of the four functions. It is not a checklist to complete in order; organizations use the parts that fit their context, risk tolerance, and resources.

How does the NIST AI RMF relate to other frameworks?

The AI RMF is designed to work alongside frameworks organizations already run. It shares the risk-based, outcome-driven approach of the NIST Cybersecurity Framework, and it complements management-system standards such as ISO/IEC 42001 for AI. Many controls you build for AI governance can be cross-mapped to ISO 27001, SOC 2, or the NIST CSF, so a single control effort can satisfy several obligations at once.

From framework to running program

Operationalize the NIST AI RMF in one platform.

RiskWatch runs assessments against 40+ frameworks, catalogs your AI systems in a risk register, and cross-maps controls so one effort satisfies many obligations.

No credit card required · 30-day free trial · Cancel anytime

Request a Demo