NIST AI Risk Management Framework
Definition
NIST AI Risk Management Framework
The NIST AI Risk Management Framework, published January 26, 2023, is a voluntary U.S. guide that helps organizations across sectors identify, measure, and reduce AI risks over the full system lifecycle. It rests on four functions — Govern, Map, Measure, and Manage.
NIST developed the framework over 18 months, gathering roughly 400 comments from more than 240 organizations before publishing AI RMF 1.0. The document is sector-neutral, so a bank, hospital, or BPO can adopt the same shell without heavy adaptation.
A companion Generative AI Profile followed on July 26, 2024, extending the RMF to risks specific to large language models and image generators. Together, the two documents anchor most U.S. corporate AI governance programs, including those adopted by federal contractors.
The RMF is written in plain language on purpose. Rather than listing specific controls, it lists outcomes to achieve, letting each organization pick controls that fit its tools and risk appetite. Auditors welcome this because outcomes are testable.
Key takeaways
- The RMF defines four core functions: Govern, Map, Measure, and Manage.
- It is voluntary, not regulatory, but often cited in vendor contracts and audits.
- AI RMF 1.0 launched January 26, 2023; the Generative AI Profile followed in July 2024.
- The framework covers the AI lifecycle from design through decommissioning.
- It complements risk regimes like the EU AI Act rather than replacing them.
How it works
The framework organizes AI risk work into four interlocking functions. Each function contains categories that translate trustworthy AI principles — validity, safety, fairness, transparency — into controls teams can assign, evidence, and audit.
Govern sets the cultural and policy layer, defining who owns AI risk. Map builds shared context by inventorying systems, users, and expected impacts.
Measure applies quantitative and qualitative testing for bias, drift, and safety. Manage prioritizes findings, funds mitigations, and tracks residual risk over the AI system’s operating life.
Each function maps to specific outcomes NIST calls categories. Govern has six covering policy, roles, transparency, and impact monitoring. Map has five, Measure four, and Manage four. Teams pick categories that fit their use case rather than adopting all 19 at once.
| Function | Purpose | Typical outputs |
|---|---|---|
| Govern | Set accountability and policy | Board charter, AI policy, RACI |
| Map | Build context and inventory | AI register, impact assessments |
| Measure | Test and evaluate | Bias audits, performance metrics |
| Manage | Prioritize and mitigate | Risk register, treatment plans |
Adoption typically starts with Govern and Map because those two supply the inventory and policy scaffolding the other RMF functions depend on. Many teams pair the RMF with an internal risk management register already used for cyber or operational risk.
Others align the RMF with model risk practices already required in banking, insurance, or health payers, reducing duplicate assurance work when a single AI system serves multiple regulated business lines.
Enterprise buyers now routinely ask vendors for RMF-mapped attestations before signing multi-year contracts, especially when the AI system will handle regulated data. That market pressure has done as much to spread the RMF as its formal endorsement by federal agencies.
Examples
Regulators, federal agencies, and Fortune 500 firms have all publicly aligned to the RMF since its 2023 release. The examples below show how the same shell adapts to very different missions — from banking supervision to generative AI red teaming.
OMB Memorandum M-24-10 (March 2024). The U.S. Office of Management and Budget directed federal civilian agencies to align their AI governance programs with the NIST framework, effectively making a voluntary standard mandatory across the federal executive branch.
Generative AI Profile (July 2024). NIST released a dedicated profile covering risks unique to generative AI like confabulation, data provenance, and dangerous content, so LLM teams can bolt tailored guidance onto the base RMF.
EU AI Act crosswalks (2024–2025). Providers of high-risk AI in the EU AI Act frequently use the RMF as the internal control library that produces evidence for conformity assessments, avoiding duplicate documentation.
Enterprise adoption (2024). Major consulting firms have published RMF-mapped compliance playbooks, and enterprise buyers increasingly ask AI vendors for RMF-based attestations before signing contracts.
Federal AI Use Case Inventories (2024). Following Executive Order 14110 and subsequent OMB guidance, federal agencies publish RMF-aligned AI use case inventories, giving the public visibility into which government systems are being risk-managed.
Related terms
The RMF sits alongside a broader AI governance vocabulary. These terms show up in policy documents, vendor contracts, and audit workpapers, and mastering them makes RMF adoption faster, especially when handing work to outsourced KPO or QA teams.
- Artificial Intelligence: the parent category the RMF governs, spanning machine learning, rule-based systems, and generative models.
- Machine Learning: the statistical subset most RMF Measure controls target, since bias and drift live here.
- Generative AI: the class addressed by the July 2024 companion profile, distinct for its output-level risks.
- Risk Management: the broader enterprise discipline the RMF plugs into rather than replaces.
- Compliance: the audit-facing outcome many teams pursue when adopting the RMF against contracts.
- Quality Assurance: the testing muscle that operationalizes the Measure function day to day.
FAQ
Is the NIST AI Risk Management Framework mandatory?
No. The RMF is a voluntary framework issued by NIST. However, US federal agencies must align to it under OMB Memorandum M-24-10, and enterprise buyers increasingly require RMF-based attestations from vendors.
What are the four core functions of the RMF?
They are Govern, Map, Measure, and Manage. Govern sets policy and accountability; Map builds inventory and context; Measure applies testing; Manage tracks and mitigates residual risk.
How does the RMF relate to the EU AI Act?
The RMF is a voluntary U.S. framework, while the EU AI Act is a binding EU law. Multinationals often use the RMF’s controls to generate evidence needed for AI Act conformity assessments.
When was AI RMF 1.0 released?
NIST published AI RMF 1.0 on January 26, 2023, and released the Generative AI Profile on July 26, 2024.
Who should own RMF adoption inside a company?
Ownership usually sits with a cross-functional group covering legal, security, data science, and business leadership, because the Govern function requires enterprise authority to set and enforce policy.
Does the RMF apply to small businesses?
Yes, NIST designed the framework to scale down, so a small team can adopt the Govern and Map functions with a one-page policy and a lightweight AI inventory.
Ready to align your AI operations with the NIST framework? Explore Outsource Accelerator to find partners who can operationalize governance, testing, and quality assurance at scale.







Independent




