The NIST AI Risk Management Framework (AI RMF 1.0) is voluntary U.S. guidance published in January 2023, built around four functions: Govern, Map, Measure, and Manage. Unlike ISO 42001, it isn't a certifiable standard — there's no audit, no certificate, and no accrediting body checking your work. It's a structured way of thinking about AI risk that organizations choose to adopt.
This is the framework you've seen referenced across nearly every AI governance post on this site — in the EU AI Act comparisons, in the red teaming content, in the ISO 42001 explainer we published previously. It's foundational enough to the field that it's worth understanding properly on its own terms, not just as a name dropped inside other articles.
Part of the confusion around it comes from how often it gets described in the same breath as certifiable standards, when it fundamentally isn't one. Understanding that distinction early makes everything else about the framework easier to place correctly — including how it relates to ISO 42001, how it relates to binding law like the EU AI Act, and why AIGP candidates are expected to know the difference cold.
What Problem Does It Actually Solve?
NIST — the National Institute of Standards and Technology — published AI RMF 1.0 on January 26, 2023, after roughly two years of public workshops and draft consultation with both private and public sector stakeholders. The goal was straightforward: give organizations building, buying, or operating AI systems a structured, repeatable way to identify and manage the risks specific to AI, rather than forcing every company to improvise its own approach from scratch.
It's deliberately flexible rather than prescriptive. NIST doesn't tell you exactly which controls to implement the way ISO 42001's Annex A does — it gives you four interconnected functions and trusts you to apply them to your own context, risk appetite, and AI use cases. That flexibility is a feature for organizations with mature risk functions, and a genuine challenge for smaller teams looking for a checklist rather than a way of thinking.
The Four Functions, Explained
These aren't sequential steps you complete once and move past. They're meant to run iteratively, feeding into each other throughout an AI system's entire lifecycle.
Govern
The foundation. Establishes accountability, assigns roles and responsibilities, sets policy, and builds the risk-aware culture everything else depends on. Without Govern in place, the other three functions don't have organizational teeth.
Map
Establishes context. Identifies what a given AI system actually does, who it affects, and what could go wrong — technically, socially, and ethically. Map is where you frame the risk before you try to quantify it.
Measure
Risk assessment in practice — both quantitative and qualitative. This is where Testing, Evaluation, Verification, and Validation (TEVV) work lives, turning the context Map established into actual metrics and evidence.
Manage
Risk treatment and response — allocating resources to address the highest-priority risks Measure identified, monitoring for drift over time, and responding when something goes wrong in production.
In practice, most organizations start with Govern and Map together — you can't meaningfully measure or manage a risk you haven't first framed — then cycle through Measure and Manage continuously as AI systems evolve and new risks emerge.
What Implementing This Actually Looks Like Day to Day
The framework document itself is conceptual, which leaves a real gap between reading it and doing it. In practice, organizations that implement AI RMF well tend to follow a recognizable pattern regardless of size:
Inventory every AI system in use
Including shadow AI — tools individual teams adopted without formal procurement review. You can't Govern, Map, Measure, or Manage a system your risk function doesn't know exists.
Assign an accountable owner per system
Not a committee — a named individual responsible for that system's risk posture, consistent with the Govern function's emphasis on clear accountability.
Document context and potential harms per system
Who does this system affect, what happens if it fails or behaves unexpectedly, and what existing controls (if any) already mitigate that risk.
Define measurable indicators and monitor continuously
Accuracy drift, bias metrics, incident rates — whatever is relevant to that system — tracked on a recurring cadence, not just at initial deployment.
Beyond the Core: The Companion Resources
The four-function framework is just the foundation. NIST has built out a meaningful library of companion material since the original 2023 release:
- The AI RMF Playbook. Suggested actions and references for actually achieving each function's outcomes — the practical "how" layered on top of the conceptual "what."
- The AI RMF Roadmap. Identifies gaps and future research priorities NIST sees in the broader AI risk landscape.
- The Generative AI Profile (NIST-AI-600-1), released July 2024. A dedicated addendum addressing risks specific to generative AI — hallucination, synthetic content, prompt-based manipulation — that the original 2023 framework predates and doesn't fully cover on its own.
If your organization is working specifically with generative AI or large language models, the Generative AI Profile isn't optional reading — it's the part of NIST's guidance written for exactly that risk surface. It organizes generative AI risks into named categories — including confabulation (the technical term NIST uses in place of "hallucination"), toxic or harmful content generation, and information security risks like prompt injection — and maps each back to the original four functions, so it extends AI RMF rather than replacing it.
Voluntary on Paper, Increasingly Expected in Practice
"Voluntary" is the accurate legal description, but it undersells how much real-world weight this framework now carries. State-level AI laws frequently reference NIST's risk-based approach as a benchmark. Enterprise vendor contracts and cyber insurance underwriting increasingly ask whether an organization's AI risk program aligns with it. None of that requires a law forcing adoption — market and contractual pressure has done a lot of that work on its own.
In October 2023, Executive Order 14110 directed federal agencies to adopt NIST's AI risk guidance, effectively making it mandatory inside the federal government. That order was rescinded on January 20, 2025, replaced days later by Executive Order 14179, which took a different policy direction on AI. The NIST AI RMF itself wasn't withdrawn or changed by this — it's still published, still maintained, and still widely used. What changed was the federal mandate tied to it. If you're researching this for compliance purposes rather than general literacy, confirm the current federal posture directly with NIST or current guidance, since this is an area that has already shifted once and could again.
NIST AI RMF vs. ISO 42001 vs. the EU AI Act
We covered the ISO comparison from the other side in our ISO 42001 explainer, but it's worth laying all three side by side, since candidates and practitioners routinely conflate them.
| NIST AI RMF | ISO/IEC 42001 | EU AI Act | |
|---|---|---|---|
| Legal Status | Voluntary guidance | Voluntary standard | Binding law |
| Issuing Body | U.S. NIST | ISO / IEC | European Union |
| Can You Be Certified? | No | Yes, via accredited auditors | N/A — compliance is assessed, not certified |
| Core Structure | 4 functions (Govern, Map, Measure, Manage) | Management system + Annex A controls | Risk-tiered obligations (Provider/Deployer) |
| Enforcement | None directly; market and contractual pressure | None directly; audit-driven | Fines up to 7% of global turnover |
The practical relationship: NIST AI RMF gives you a way of thinking about AI risk. ISO 42001 gives you a certifiable system you can be independently audited against. The EU AI Act gives you a binding legal obligation with real penalties attached. Many organizations use all three together — NIST AI RMF to shape the substance of their AI risk program, ISO 42001 to formalize and certify the management system that results from it, and EU AI Act compliance as the non-negotiable legal floor if they operate in or serve that market. They're complementary layers, not competing choices.
Vendors and job postings sometimes describe a product or candidate as "NIST AI RMF certified." This isn't a real credential — NIST does not certify organizations or individuals against the framework. If you see this phrase, it typically means the organization has self-attested alignment, not that any accredited body reviewed and certified it. Treat the claim accordingly.
Why This Matters If You're Studying for AIGP
NIST AI RMF sits inside the AIGP Body of Knowledge as one of the core frameworks candidates are expected to recognize, alongside ISO 42001 and the EU AI Act's risk-tiered approach. Exam questions tend to test whether you can correctly distinguish a voluntary framework from a binding regulation, and whether you understand what each of the four functions is actually responsible for — not just that they exist. If you can explain, in one sentence each, what Govern, Map, Measure, and Manage do differently, you're already ahead of where most candidates start.
Common Mistakes Organizations Make Adopting It
Because the framework is conceptual rather than a checklist, most implementation failures aren't about misreading the four functions — they're about skipping the unglamorous groundwork underneath them.
- Treating Govern as a one-time policy document. Writing an AI governance policy and filing it away isn't Govern — the function is meant to operate continuously, with accountability that gets exercised, not just documented.
- Mapping only the AI systems procurement knows about. Shadow AI — tools individual teams adopt without formal review — routinely accounts for a significant share of an organization's actual AI exposure, and it's invisible to a Map exercise that only surveys officially sanctioned systems.
- Measuring once at launch and never again. AI systems drift as real-world data diverges from training data. A Measure exercise done only at deployment misses exactly the risks that emerge afterward.
- Confusing Manage with incident response alone. Manage covers proactive resource allocation to address known risks, not just reactive cleanup after something breaks. Organizations that only "manage" after an incident are running three of the four functions, not all four.
The through-line across all of these: AI RMF's flexibility is what makes it powerful for mature risk functions and what makes it easy to implement poorly for teams treating it as a one-time compliance exercise rather than an operating rhythm.
Frequently Asked Questions
Is NIST AI RMF mandatory for private companies?
No, it remains voluntary for private-sector organizations. It only carried a mandate for federal agencies under Executive Order 14110, and that mandate was rescinded in January 2025. Private companies adopt it by choice, usually for risk management quality, vendor requirements, or insurance underwriting reasons rather than legal compulsion.
Can a company be "NIST AI RMF certified"?
No. There is no certification program attached to the framework, and no accredited body issues certificates against it. Any claim of "NIST AI RMF certification" should be read as self-attestation, not third-party verification — a meaningful distinction if you're evaluating a vendor's claims.
How is the Generative AI Profile different from the base framework?
The base AI RMF (2023) covers AI risk broadly and predates the current wave of generative AI adoption. The Generative AI Profile (NIST-AI-600-1, July 2024) is a targeted addendum addressing risks specific to generative systems — confabulation, synthetic content misuse, and prompt-based manipulation — mapped back onto the same four functions.
Does adopting NIST AI RMF satisfy EU AI Act obligations?
Not on its own. The EU AI Act is binding law with its own specific documentation, risk-tiering, and conformity requirements. Aligning with NIST AI RMF can meaningfully strengthen the underlying risk management practice that supports EU AI Act compliance, but it doesn't substitute for the Act's specific legal obligations if your organization falls under its scope.
NIST AI RMF is the most widely referenced voluntary AI risk framework in the U.S., built on four interconnected functions rather than a rigid checklist. It carries no certification and no formal audit — but increasingly, market pressure does the enforcement that regulation doesn't. Understanding it on its own terms, distinct from certifiable standards like ISO 42001 and binding law like the EU AI Act, is foundational knowledge for anyone working in AI governance.
Related reading: What is ISO/IEC 42001?, the Generative AI Profile explained in depth, and how AIGP tests knowledge of all three major frameworks.