NIST AI RMF: AI Risk Management Framework Guide
The NIST AI Risk Management Framework (AI RMF 1.0) provides a structured, voluntary approach to managing risks associated with AI systems throughout their lifecycle. Published in January 2023 and supplemented by the Generative AI Profile in 2024, the AI RMF has become the most widely referenced AI governance framework in the United States and is gaining international adoption as a practical complement to regulatory requirements like the EU AI Act.
What the NIST AI RMF Is and Who Issues It
NIST (the National Institute of Standards and Technology) is a non-regulatory agency within the US Department of Commerce with a long track record of producing practical, widely adopted cybersecurity and risk management frameworks — most notably the NIST Cybersecurity Framework (CSF). The AI RMF follows the same approach: voluntary, consensus-driven, and designed to be usable across sectors and organization sizes.
The framework was developed through an extensive multi-year process involving public workshops, comment periods, and collaboration with industry, academia, government, and civil society. It is not a regulation and NIST does not audit or certify organizations against it. However, it is referenced in US Executive Order 14110 on AI safety, incorporated into federal agency AI governance requirements, and cited by a growing number of state-level AI regulations and enterprise procurement requirements. The Generative AI Profile (NIST AI RMF GenAI 1.0, 2024) extends the framework with specific guidance for generative AI systems.
Who Should Use the AI RMF
The AI RMF is designed for any organization that develops, deploys, or uses AI systems. While voluntary, it provides substantive value in several scenarios:
- AI developers building models, datasets, or AI-powered products need a structured way to identify and address risks before deployment
- Enterprises deploying AI from third-party vendors need a framework to assess vendor risk, implement appropriate oversight, and monitor AI system performance in production
- Government agencies subject to federal AI governance requirements, including OMB Memorandum M-24-10, can use the RMF to demonstrate responsible AI use
- Organizations preparing for EU AI Act compliance can use the RMF's GOVERN and MAP functions to build the governance foundation that both US and EU requirements expect
- Smaller companies that find ISO 42001 certification premature can use the AI RMF as a practical, cost-effective starting point
The framework's flexibility makes it adaptable to startups with a handful of AI features and Fortune 500 enterprises with hundreds of AI systems in production.
The Four Core Functions in Depth
GOVERN — Establish the organizational context for AI risk management
GOVERN is the foundation. It establishes policies, processes, and accountability structures ensuring that AI risk management is embedded in organizational culture and operations. Key activities include defining the organization's risk tolerance for AI, establishing governance roles and responsibilities (including AI risk ownership), creating policies for AI system development and deployment, integrating AI risk management with enterprise risk management and existing management systems, and building organizational culture and incentives that support responsible AI.
The GOVERN function emphasizes that AI risk management cannot be siloed in a single team — it must involve executives, legal and compliance, technical teams, and domain experts who understand the business context of each AI application.
MAP — Identify and contextualize AI risks
MAP activities identify the organizational context, AI system characteristics, and stakeholders that determine which risks are most relevant. Organizations catalogue their AI systems, classify them by intended use and deployment context, identify all affected stakeholders (not just end users but also people indirectly affected by AI decisions), and surface potential negative impacts before they occur.
MAP includes understanding the supply chain: where training data originated, which third-party models or APIs are used, and what assumptions were embedded during development. The Generative AI Profile adds MAP activities specific to GPAI risks including confabulation (hallucination), intellectual property concerns, and homogenization of outputs across users.
MEASURE — Analyze and assess AI risks
MEASURE translates identified risks into quantitative and qualitative evaluations. This includes bias testing across protected characteristics and user populations, performance evaluation across diverse conditions, reliability and robustness testing, privacy risk assessment, security evaluation including adversarial testing, and impact assessment for affected communities. The function also covers metrics and methods for ongoing monitoring after deployment.
For generative AI, MEASURE addresses the unique challenges of evaluating systems whose outputs are probabilistic and context-dependent. This includes evaluation of factual accuracy rates, bias in generated content, vulnerability to adversarial prompts, and environmental impact of inference at scale.
MANAGE — Treat, monitor, and communicate AI risks
MANAGE translates risk assessment into action. Organizations implement risk treatments — mitigations, controls, or deployment constraints — based on MEASURE findings. They establish monitoring to detect performance degradation, bias drift, and unexpected behaviors in production. They develop incident response plans for AI-specific failures. They communicate risks to relevant stakeholders including deployers, affected communities, and regulators where required. They maintain records supporting accountability and post-incident analysis.
Critically, MANAGE includes deciding whether to deploy a system at all, or to restrict deployment to lower-risk contexts. The framework recognizes that some AI risks cannot be adequately mitigated and that the appropriate response may be not deploying the system in certain applications.
Trustworthy AI: Seven Properties
Underlying all four functions is the concept of Trustworthy AI, characterized by seven properties that the framework uses as a North Star:
- Valid and Reliable: The AI system performs accurately and consistently under expected conditions
- Safe: The system does not cause harm, particularly in high-stakes applications
- Secure and Resilient: The system resists adversarial attack and maintains function under stress
- Accountable and Transparent: Decisions can be explained and responsibility can be assigned
- Explainable and Interpretable: Stakeholders can understand how and why the system produces outputs
- Privacy-Enhanced: The system respects and protects personal information throughout its lifecycle
- Fair — with Harmful Bias Managed: The system does not discriminate in ways that cause harm to protected groups
These properties are not independent — they often involve trade-offs. Explainability may conflict with performance; privacy preservation may reduce accuracy. The AI RMF does not prescribe how to resolve these trade-offs but provides a structured way to identify and document them.
The Generative AI Profile
The Generative AI Profile (published 2024) identifies unique risks of generative AI systems not fully addressed in the core RMF: confabulation (generating plausible-sounding but false outputs), data provenance and copyright concerns, environmental and energy impact, homogenization (over-reliance on similar AI outputs across society), harmful content generation, privacy violations from training data memorization, information security risks unique to LLM architectures, and risks from value chain complexity when organizations chain multiple AI models.
The Profile maps these risks to specific GOVERN, MAP, MEASURE, and MANAGE activities, providing practical guidance for organizations building or deploying large language models, image generators, code assistants, and similar systems.
Costs and Timeline
| Activity | Typical Cost | Timeline |
|---|---|---|
| AI system inventory and classification | $5,000 – $20,000 | 2–4 weeks |
| GOVERN function setup (policies, roles) | $10,000 – $30,000 | 4–8 weeks |
| MAP function (risk identification) | $10,000 – $30,000 per AI system | 2–4 weeks per system |
| MEASURE function (bias, performance testing) | $10,000 – $50,000 per AI system | 4–8 weeks per system |
| MANAGE function (monitoring, incident response) | $15,000 – $60,000 | 2–3 months |
| Full program for 5–10 AI systems | $50,000 – $200,000 | 3–12 months |
The AI RMF itself is free. Costs are entirely implementation costs, scaled by the number and complexity of AI systems in scope.
Comparison with Related Frameworks
ISO 42001 (60% overlap): ISO 42001 and the NIST AI RMF are the most closely aligned pair in AI governance. Both address governance structures, risk assessment, AI lifecycle, and trustworthy AI properties. The RMF is the more flexible, process-oriented tool; ISO 42001 is certifiable and more prescriptive. Many organizations use the RMF for internal governance and ISO 42001 for external certification — the frameworks complement rather than duplicate each other. See our full ISO 42001 guide.
EU AI Act (55% overlap): The RMF provides the governance substance that EU AI Act compliance requires but does not prescribe. Mapping RMF GOVERN, MAP, MEASURE, and MANAGE activities to specific EU AI Act articles helps organizations bridge the voluntary framework to mandatory regulatory requirements. See the EU AI Act guide for detailed compliance requirements.
NIST CSF (35% overlap): The AI RMF was deliberately designed with structural similarity to the NIST Cybersecurity Framework (CSF) to ease adoption by organizations already familiar with CSF. The governance and measurement approaches are compatible, though the CSF addresses cybersecurity specifically while the AI RMF addresses AI risk broadly including safety, fairness, and societal impact.
For AI companies, our AI company compliance guide covers how to layer the NIST AI RMF with other compliance obligations.
How Automation Helps
Implementing the NIST AI RMF across an AI portfolio requires maintaining a live AI system inventory, tracking risk assessments per system, scheduling re-evaluations as models and data change, and documenting governance decisions in a way that supports accountability. Spreadsheet-based approaches quickly break down as the number of AI systems grows.
LowerPlane maps the NIST AI RMF across its 50+ framework library alongside related standards like ISO 42001 and the EU AI Act, enabling organizations to manage multi-framework AI compliance with shared evidence. Priced from $4,000 per year with a free tier, it holds a 9.4/10 satisfaction rating among AuditXYZ users. TruePrivacy's AI governance module complements the RMF's privacy-enhanced AI property with model-level data mapping and privacy impact assessment capabilities. Compare platform options at best compliance automation platforms.
Frequently Asked Questions
Is the NIST AI RMF legally required? No. The AI RMF is a voluntary framework. However, it is referenced in federal agency requirements under OMB M-24-10, and some government procurement contracts now require AI suppliers to demonstrate alignment. State-level AI legislation in the US increasingly references or builds on the RMF, and it is expected to influence future federal AI regulation.
How does the AI RMF relate to Executive Order 14110 on AI safety? Executive Order 14110 (October 2023) directed federal agencies to use the NIST AI RMF for managing AI risks in federal systems and directed NIST to develop additional AI safety tools and guidance. The Generative AI Profile was developed in part in response to EO 14110 requirements. The RMF is now embedded in federal AI governance as a baseline expectation.
What is the difference between AI risk and AI safety in the RMF context? The AI RMF uses "risk" broadly to encompass harms to individuals and society, not just organizational risks. "AI safety" in the US policy context increasingly refers specifically to catastrophic or irreversible risks from advanced AI systems. The RMF addresses the full spectrum from near-term risks (bias, privacy violations, reliability failures) to longer-term safety concerns.
How often should AI risk assessments be repeated? The RMF recommends treating AI risk management as a continuous process rather than a point-in-time exercise. Major re-assessment triggers include model updates or retraining, changes in deployment context, new evidence of bias or performance issues from monitoring, significant changes in the regulatory environment, and incidents or near-misses. At minimum, a structured annual review is recommended.
Can an organization get certified to the NIST AI RMF? NIST does not offer or recognize any AI RMF certification. Third-party organizations may offer independent assessments of AI RMF alignment, but these are not endorsed by NIST. ISO 42001 is the primary path to internationally recognized third-party certification for AI management systems.