What is the NIST AI Risk Management Framework?
The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary US framework for managing the risks of AI. Released in 2023, it is organized around four functions, Govern, Map, Measure, and Manage, to help organizations build trustworthy and responsible AI.
Definition
The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary framework published by the US National Institute of Standards and Technology to help organizations identify, assess, and manage risks across the AI lifecycle.
Background
Released in 2023, the AI RMF is voluntary and technology-neutral. Its core is organized into four functions: Govern (a culture of risk management that cuts across the others), Map (establish context and identify risks), Measure (analyze and track risks), and Manage (prioritize and act on them). These functions break down into categories, and NIST provides a companion Playbook and profiles, including one for generative AI, to help teams apply the framework.
Why it matters
The AI RMF gives organizations a common, flexible vocabulary and process for AI risk, which is useful whether or not a specific law applies. It pairs well with a management standard like ISO 42001 and with regulatory work such as EU AI Act readiness, because it focuses on identifying and reducing AI risk in practice.
Step by step
- Govern: set AI risk-management policies, roles, and accountability.
- Map: establish the context and identify the risks of each AI system.
- Measure: analyze, assess, and track those risks with appropriate methods.
- Manage: prioritize risks and act to reduce them across the lifecycle.
- Iterate as systems and their context change.
Examples
- A team uses the Map and Measure functions to document and assess risks in a new model before release.
- An organization adopts the AI RMF as its internal method and layers ISO 42001 on top for a certifiable management system.
Common mistakes
- Treating the AI RMF as mandatory; it is voluntary, though many organizations adopt it as good practice.
- Using it only once instead of continuously across the AI lifecycle.
- Assuming it certifies you; the AI RMF is a framework, not a certification like ISO 42001.
FAQ
Is the NIST AI RMF mandatory?
No. It is a voluntary framework. Some organizations adopt it as good practice or because customers or policies reference it, but it is not a law and does not certify you.
How does the NIST AI RMF relate to ISO 42001?
The AI RMF is a voluntary risk framework (functions and categories), while ISO/IEC 42001 is a certifiable management-system standard. They complement each other: many teams use the AI RMF as their method and ISO 42001 as the certifiable system around it.
Do this in Keel, not a spreadsheet
Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.
Start free