In this article
Introduction
A framework nobody can be audited against, with no certification, no badge, and no legal requirement to follow it, has still become the closest thing to a shared vocabulary for AI governance worldwide. That's the paradox of NIST's AI Risk Management Framework: entirely voluntary, and yet increasingly the reference point every other AI governance conversation gets measured against, including how ISO 42001 and the EU AI Act get discussed and implemented. This guide covers what the framework actually contains, how its four functions work together, where implementations commonly stall, and how it fits alongside the other major AI governance instruments organizations are weighing right now.
What NIST AI RMF Actually Is
The NIST AI Risk Management Framework, formally NIST AI 100-1, is voluntary guidance published on January 26, 2023, intended for any organization that designs, develops, deploys, or uses AI systems, a deliberately broad scope. It was developed under the National AI Initiative Act of 2020 through an open, consensus-driven process, drawing roughly 400 sets of formal comments from more than 240 organizations spanning industry, academia, civil society, and government, making it one of the more collaboratively built AI governance documents available. Unlike a certification standard, it's explicitly designed to be flexible: organizations adapt it to their own regulatory, operational, and technical context rather than following a single prescribed checklist.
The Four Functions
Govern, then the loop
Map
Framing the specific AI system and its context: intended use, potential impacts, and the environment it operates in.
→Measure
Assessing and benchmarking the risks identified in Map, using appropriate metrics and evaluation methods.
→Manage
Allocating resources to actually treat the risks that Measure surfaced, prioritizing responses and tracking outcomes.
Govern
The foundation that cuts across everything else: policies, accountability structures, culture, and leadership commitment that make the other three functions possible in practice.
Govern differs structurally from the other three: rather than being one step in a sequence, it's meant to run continuously underneath Map, Measure, and Manage, which themselves typically operate as a repeating cycle across an AI system's lifecycle rather than a one-time linear process.
Trustworthy AI: What the Framework Is Actually Optimizing For
Trustworthy AI characteristics
Valid and reliable
Performs as intended, consistently.
Safe
Doesn't create conditions leading to physical, psychological, or other harm.
Secure and resilient
Withstands adversarial manipulation and unexpected conditions.
Accountable and transparent
Clear ownership and visibility into how the system operates.
Explainable and interpretable
Decisions can be understood, not just observed.
Privacy-enhanced
Respects data protection principles by design.
Fair, with harmful bias managed
Actively addresses, rather than ignores, discriminatory outcomes.
These characteristics are the actual target the four functions are organized around; Govern, Map, Measure, and Manage are the process, and these characteristics are what that process is meant to produce evidence of.
The Generative AI Profile: When the Core Framework Wasn't Enough
Framework timeline
January 26, 2023
NIST AI RMF 1.0 (NIST AI 100-1) published, establishing the four core functions.
2023
AI RMF Playbook released as a companion resource, roughly 140 pages of suggested actions and reference material, considerably more operational detail than the roughly 40-page core framework itself.
July 2024
Generative AI Profile (NIST AI 600-1) published, developed in response to the 2023 Executive Order on Safe, Secure, and Trustworthy AI, applying the same four functions specifically to risks unique to or intensified by large language models and other foundation-model systems.
April 2026
A Trustworthy AI in Critical Infrastructure Profile concept note released, extending the framework's reach into a new sector context.
NIST extends the framework through these Profiles rather than new version numbers, which is worth knowing directly: there is no "AI RMF 2.0" as of 2026, and searches suggesting otherwise are usually referring to one of these companion Profiles rather than a genuine framework revision.
Where Implementations Commonly Stall
A pattern shows up often enough in practice to be worth naming directly: an organization adopts the framework, writes a governance policy under Govern, produces an AI inventory and some system-context documentation under Map, and then Measure quietly stalls, because building the actual data infrastructure needed to benchmark AI risk consistently is a meaningfully harder lift than writing policy or cataloging systems. Manage, in turn, has little to work with once Measure is incomplete. Recognizing this pattern in advance is more useful than discovering it a year into implementation: Measure is where real technical investment is required, not just governance documentation.
NIST AI RMF vs ISO 42001 vs the EU AI Act
Three frameworks, three different jobs
Worth noting concretely: Colorado's AI Act now makes demonstrated alignment with either NIST AI RMF or ISO 42001 an affirmative defense in litigation, a real, current example of a voluntary framework translating directly into legal consequence, not just internal best practice.
A Practical Adoption Path
Getting started with NIST AI RMF
Start with Govern, not Map: establish accountability and policy first, since Map and Measure activities lack real authority without it.
Build a genuine AI system inventory under Map, including systems acquired from vendors, not just internally built ones.
Invest in the data infrastructure Measure actually requires before assuming policy and inventory work alone constitute progress.
Use the AI RMF Playbook, not just the core framework document, for the operational detail most organizations actually need to implement each function.
If generative AI is in scope, apply the Generative AI Profile (NIST AI 600-1) alongside the core framework rather than treating it as optional add-on reading.
Treat NIST AI RMF and ISO 42001 as complementary rather than competing, using the former for internal method and the latter if third-party certifiable proof is needed.
Sources
- NIST, AI Risk Management Framework (AI RMF 1.0), NIST AI 100-1, January 26, 2023 (nist.gov)
- NIST, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1, July 2024
This article reflects publicly available NIST publications as of July 2026. NIST periodically issues new companion Profiles and guidance; verify current materials directly on nist.gov before finalizing an implementation plan.
Frequently Asked Questions
What is the NIST AI Risk Management Framework?+
Voluntary US guidance (NIST AI 100-1), published January 2023, for managing AI risk across the lifecycle, developed through a consensus process involving over 240 organizations.
Is NIST AI RMF certifiable?+
No, it's voluntary and non-certifiable, unlike ISO 42001, which organizations can be independently audited and certified against.
What are the four functions of NIST AI RMF?+
Govern, Map, Measure, and Manage. Govern is foundational and cuts across the others, while Map, Measure, and Manage typically operate as a repeating cycle.
What is the Generative AI Profile?+
NIST AI 600-1, published July 2024, applies the same four functions specifically to generative AI risks unique to large language models and foundation-model systems.
How does NIST AI RMF relate to ISO 42001?+
They're complementary: NIST AI RMF provides voluntary method and vocabulary, while ISO 42001 is the certifiable management system standard organizations can be audited against.
Is there a NIST AI RMF 2.0?+
No, AI RMF 1.0 remains current as of 2026. NIST extends the framework through companion Profiles rather than new version numbers.
