The NIST AI Risk Management Framework (AI RMF) is a voluntary framework for identifying, measuring, and managing the risks of artificial intelligence systems. Published by the U.S. National Institute of Standards and Technology as NIST AI 100-11 on January 26, 2023, it organizes AI risk management into four functions (GOVERN, MAP, MEASURE, and MANAGE) and defines seven characteristics that make an AI system trustworthy. As of mid-2026, version 1.0 remains the current release, with a revision in progress at NIST.2

That is the textbook answer. The more useful answer is that the AI RMF has quietly become the reference point American organizations reach for when someone in the room finally asks, "Who approved this model, and how do we know it works?"

Why a voluntary framework matters

Nothing in the AI RMF is legally binding. NIST developed it, at the direction of Congress,4 through an open consensus process involving more than 240 contributing organizations2, and it reads like the product of that process: careful, technology-neutral, and deliberately non-prescriptive. It tells you what outcomes a well-governed AI program achieves. It does not tell you which vendor to buy or which threshold to set.

Voluntary does not mean optional in practice. Regulators, examiners, customers, and cyber insurers increasingly frame their AI questions in the framework's vocabulary. When a bank examiner asks how model risk is governed, when a hospital's counsel asks how a clinical algorithm was validated, or when an enterprise customer sends a security questionnaire with an "AI governance" section, the AI RMF is the common language behind the question. Organizations that adopt it early answer those questions from documentation. Everyone else answers from memory.

There is a second reason the framework travels well: it was designed to plug into risk programs that already exist. If your organization runs NIST SP 800-53 controls, a SOC 2 program, or an ISO 27001 management system, AI RMF outcomes map into all of them. It behaves less like a new compliance regime and more like an AI-shaped lens on the risk discipline you already practice.

The architecture: one foundation, three moving parts

The framework's core is four functions. One is structural; three are operational.

GOVERN is the cross-cutting foundation. It covers policies, accountability structures, risk tolerance, workforce culture, AI inventories, and third-party oversight: the conditions under which every other activity happens. GOVERN is not a phase you complete; it is the load-bearing wall.

MAP establishes context. Before anyone measures anything, the organization documents what each AI system is for, who it affects, what data feeds it, where it sits in a business process, and what could plausibly go wrong. Many AI failures trace back to a mapping failure: a system used outside its intended context.

MEASURE turns mapped risks into evidence. It covers test, evaluation, validation, and verification (accuracy, yes, but also bias, robustness, security, and explainability) before deployment and continuously afterward.

MANAGE is where decisions get made. Risks identified in MAP and quantified in MEASURE are prioritized, treated, accepted, or escalated. Deployment gates, incident response, vendor monitoring, and decommissioning all live here.

The functions are a cycle, not a checklist. A model drifts, MEASURE catches it, MANAGE responds, MAP updates the context, and GOVERN adjusts the policy. Organizations that treat the framework as a one-time project miss its entire design.

The seven trustworthy AI characteristics

The framework defines trustworthy AI through seven characteristics: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair, with harmful bias managed.

Two things make this list more than a poster. First, NIST is explicit that the characteristics trade off against one another. A more interpretable model may be less accurate; a more privacy-preserving design may be harder to audit. The framework does not resolve those tensions; it requires you to document the tradeoff you chose and why. Second, the characteristics apply to the system, not just the model. Model safety is insufficient; system safety is the issue. The orchestration layer, the tools a model can call, the data pipelines, and the identity and access controls around it are all part of the attack surface and all in scope.

What the AI RMF is not

It is not a certification: there is no "AI RMF certified" seal, and any vendor claiming one is improvising. It is not a law, though U.S. federal guidance and a growing number of state requirements point to it. And it is not a generative-AI afterthought: NIST published a companion Generative AI Profile (AI 600-1)3 in July 2024 that maps GenAI-specific risks (confabulation, prompt injection, data leakage, harmful content) back into the same four functions, so LLM adoption does not require a separate framework.

Where to start

Start with an inventory. Organizations that begin this work often discover more AI in production than leadership believed, embedded in SaaS tools, purchased inside vendor platforms, or adopted team by team. You cannot govern what you have not enumerated. From there, build a profile: a statement of which framework outcomes matter for your context, where you stand today, and where you intend to be. The gap between those two positions becomes your roadmap.

The next four posts in this series take each function in turn: what it demands, where organizations stumble, and what the evidence of doing it well actually looks like.

Frequently asked questions

Is the NIST AI RMF mandatory? No. It is voluntary. But U.S. regulators, procurement offices, and enterprise customers increasingly use it as the benchmark for AI governance questions, which makes adoption a practical expectation in regulated industries.

Does the AI RMF cover generative AI and large language models? Yes. The Generative AI Profile (NIST AI 600-1, July 2024) extends the framework with GenAI-specific risks and actions, mapped to the same GOVERN, MAP, MEASURE, and MANAGE functions.

How does the AI RMF relate to ISO/IEC 42001? ISO/IEC 42001 defines a certifiable AI management system; the AI RMF defines risk-management outcomes. They are complementary; many organizations use the AI RMF as the operational layer and ISO 42001 as the certification wrapper.

References

  1. National Institute of Standards and Technology, "Artificial Intelligence Risk Management Framework (AI RMF 1.0)," NIST AI 100-1, January 2023. nvlpubs.nist.gov
  2. National Institute of Standards and Technology, "AI Risk Management Framework." nist.gov/itl/ai-risk-management-framework
  3. National Institute of Standards and Technology, "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile," NIST AI 600-1, July 2024. nvlpubs.nist.gov
  4. National Institute of Standards and Technology, "Artificial Intelligence Risk Management Framework (AI RMF 1.0)," publication record (developed as directed by the National Artificial Intelligence Initiative Act of 2020). nist.gov
Discuss this topic

DefenseLogix supports regulated and trust-sensitive organizations with this work. To discuss your organization's situation, start a conversation or review the AI Risk Management service.