What the AI RMF is, and why it exists
The NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0, publication NIST AI 100-1) was released in January 2023 in response to a Congressional direction to help organisations manage the risks of AI. Unlike the EU AI Act, it is voluntary, non-sector-specific, and rights-preserving — a resource, not a regulation. It has nonetheless become the reference baseline that US federal agencies, procurement teams, and enterprises point to when they ask a vendor to "manage AI risk."
Its purpose is to help organisations incorporate trustworthiness into the design, development, use, and evaluation of AI. It is designed to be practical, adaptable to any organisation's size and sector, and to be used across the full AI lifecycle by everyone from data scientists to executives.
The characteristics of trustworthy AI
The framework centres on seven characteristics that make an AI system trustworthy. Managing risk means balancing these — they can be in tension, and the right trade-off is context-dependent:
- Valid & reliable — accurate and robust across expected conditions (the foundation).
- Safe — does not endanger human life, health, property, or the environment.
- Secure & resilient — withstands adversarial attack and recovers from adverse events.
- Accountable & transparent — information is available across the lifecycle to appropriate actors.
- Explainable & interpretable — the "how" and the "meaning" of outputs can be understood.
- Privacy-enhanced — safeguards anonymity, confidentiality, and control over data.
- Fair, with harmful bias managed — addresses systemic, computational, and human-cognitive bias.
The four functions
The RMF Core organises the work into four functions. Govern is a cross-cutting culture-and-process function that runs through the other three; Map, Measure, and Manage form an iterative loop applied throughout the AI lifecycle. Each function breaks into categories and subcategories of concrete outcomes.
Govern
Cultivate a culture of risk management — the policies, accountability, and structures that make the other three functions work.
- Policies & processes for mapping, measuring, and managing AI risk.
- Accountability structures and clear roles/responsibilities.
- Workforce diversity, competence, and AI literacy.
- Third-party / supply-chain risk policies.
Map
Establish the context and frame the risks — you cannot manage what you have not identified.
- Context, intended purpose, and setting established.
- Capabilities, and the AI system inventory, catalogued.
- Risks and benefits mapped for all components, including third-party.
- Impacts to individuals, groups, and society characterised.
Measure
Analyse, assess, benchmark, and monitor AI risk using quantitative and qualitative methods.
- Appropriate metrics & methods identified and applied.
- Trustworthiness characteristics evaluated (safety, security, bias, etc.).
- Mechanisms for tracking risks over time.
- Feedback on measurement effectiveness gathered.
Manage
Prioritise and act on risks — allocate resources to treat, monitor, and respond.
- Risks prioritised and treated based on impact.
- Strategies to maximise benefit, minimise harm planned.
- Third-party risks managed; incidents responded to and recovered from.
- Ongoing monitoring & documented response.
The Generative AI Profile — NIST AI 600-1
In July 2024, in response to the US Executive Order on AI, NIST published a Generative AI Profile (NIST AI 600-1) — a cross-sectoral profile that applies the four functions specifically to generative AI. It identifies 12 risks that are unique to, or amplified by, generative AI, and then lists concrete actions aligned to the Govern/Map/Measure/Manage subcategories to address them.
The twelve risk categories include:
- CBRN information or capabilities — lowered barriers to chemical, biological, radiological, or nuclear weapons.
- Confabulation — confidently produced false or misleading "hallucinated" content.
- Dangerous, violent, or hateful content.
- Data privacy — leakage or inference of sensitive/personal data.
- Environmental impacts of training and operating large models.
- Harmful bias & homogenisation.
- Human-AI configuration — over-reliance, automation bias, misuse.
- Information integrity — disinformation, deepfakes at scale.
- Information security — expanded attack surface, prompt injection, model/data poisoning, exfiltration.
- Intellectual property — training-data and output IP exposure.
- Obscene, degrading, or abusive content (incl. CSAM/NCII).
- Value chain & component integration — third-party model and data supply-chain risk.
How the RMF maps to the EU AI Act
The frameworks are complementary: the RMF gives you the process to produce much of the evidence the EU AI Act legally requires. A single control effort can satisfy both.
| NIST AI RMF | Analogous EU AI Act obligation |
|---|---|
| Govern — policies, accountability, roles | Quality management system (Art. 17); AI literacy (Art. 4) |
| Map — context, inventory, impacts | Risk identification (Art. 9); classification & intended purpose |
| Measure — metrics, evaluation, testing | Testing & accuracy (Art. 9/15); data governance (Art. 10) |
| Manage — treat, monitor, respond | Risk controls (Art. 9); post-market monitoring (Art. 72) |
| GenAI Profile — adversarial testing, info-sec | GPAI evaluation & red-teaming (Art. 55) |
References
- NIST — AI Risk Management Framework (hub)Overview, resources, and the Roadmap.
- NIST AI 100-1 — AI RMF 1.0 (PDF)The core framework document (Jan 2023).
- NIST AI 600-1 — Generative AI Profile (PDF)Cross-sectoral GenAI profile (Jul 2024).
- NIST AI RMF Playbook (AIRC)Suggested actions per subcategory.
- NIST Trustworthy & Responsible AI Resource CenterKnowledge base and crosswalks.