Resources 8 min read

NIST AI Risk Management Framework Explained

What the NIST AI Risk Management Framework is, its four functions, the Generative AI Profile, what it is not, and how to use it without adopting it wholesale.

Two professionals review a multi-lane organizational workflow diagram on a dual-screen laptop; with a customer journey map on the lower display.

The NIST AI Risk Management Framework is the reference most likely to come up when a board, a customer or an auditor asks how an organization manages AI risk. It is worth understanding what it is, and equally what it is not.

Framework referenced: NIST AI RMF 1.0, published 26 January 2023 as NIST AI 100-1. Status: NIST has stated that AI RMF 1.0 is being revised. Last reviewed by LABUSA: 19 August 2026. Check the framework page for the current position before relying on any version-specific detail below.

What it is, in one paragraph

The AI RMF is voluntary guidance for managing risks associated with artificial intelligence. It is not a regulation, not a certification, and not a checklist that produces a pass. It offers a structure for deciding what could go wrong with an AI system, working out how much that matters, and doing something proportionate about it, in a way that can be explained to somebody else afterwards.

NIST developed it in an open process with public comment, and publishes a companion Playbook of suggested actions alongside it.

The four functions

The framework's core is organized into four functions.

GOVERN. The organizational context: accountability, policy, culture, roles, and how risk decisions get made and recorded. GOVERN is cross-cutting rather than sequential. It applies across the other three rather than preceding them, and rendering it as step one of a linear process misrepresents the framework.

MAP. Establishing context: what the system is for, who is affected, what the intended and unintended uses are, and where it sits in a wider process. This is the function that corresponds most closely to what an organization does when it builds an inventory and works out what it actually has.

MEASURE. Analysing and tracking: what is assessed, against what, using what methods, and how the results are recorded.

MANAGE. Acting on what MAP and MEASURE established: allocating resources, applying controls, responding to incidents, and deciding what residual risk is acceptable.

NIST notes that MAP, MEASURE and MANAGE can be applied in AI system-specific contexts. In practice most organizations find MAP the hardest and the most valuable, because it is where the vague question of AI risk becomes a specific question about a specific use.

The characteristics of trustworthy AI

Alongside the functions, the framework describes characteristics of trustworthy AI systems: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair with harmful bias managed.

Two things about this list are easy to miss. It is a set of properties in tension rather than a scorecard: increasing explainability can reduce accuracy, and privacy measures can complicate fairness analysis. And NIST is explicit that trustworthiness is a property of a system in a context, not of a model in the abstract.

The Generative AI Profile

In July 2024 NIST published a companion resource, the Generative AI Profile, addressing risks unique to or exacerbated by generative AI and suggested actions for managing them.

It is a risk overlay rather than a second framework, and it does not have its own lifecycle. Where an organization is adopting generative tools, which is most of them, the Profile is the more directly applicable document and is where terms like confabulation are defined. Its risks are covered from a practitioner angle in AI risk assessment.

How the functions map onto work an organization already does

The four functions read as abstractions until they are set against the things a governance program produces, at which point most of them turn out to describe work that is either already happening or conspicuously absent.

GOVERN corresponds to naming an accountable owner, agreeing an escalation route and writing the short policy set. Organizations usually have some of this, held informally, and the framework's contribution is to ask whether it is written down and whether anyone could point at it.

MAP corresponds to the inventory and to establishing, per use case, what the system does, who it affects and what data reaches it. This is the function most often skipped, because it feels like preparation rather than progress, and skipping it is why policies get written for organizations nobody has described.

MEASURE corresponds to pre-deployment checks and to whatever tells you a system has stopped working as expected. In most organizations adopting third-party AI, this is the emptiest of the four: the system was evaluated once, by the person who wanted it, against an impression.

MANAGE corresponds to the controls, the human review thresholds, the incident route and the acceptance of what remains. It is the function that produces artifacts a reviewer can inspect.

Reading them this way is more useful than treating the framework as something to implement, because it turns four functions into four questions about work that is already underway.

What it is not

Four clarifications, because each of them is misstated somewhere in the market.

It is not law. Adopting the AI RMF does not make an organization compliant with any statute, regulation or contract. Where a legal obligation applies to you, it applies whether or not you use this framework.

There is no certification. No body certifies an organization against the AI RMF, and no product is NIST-approved. A supplier claiming either is describing something that does not exist. Certification against an AI management system is a different instrument entirely, covered in NIST AI RMF versus ISO/IEC 42001.

It is not a maturity model. There are no levels and no score.

It does not tell you what to do. It tells you what to decide. The specific controls remain yours to choose, which is a feature rather than a gap, and it is why the Playbook offers suggested actions rather than requirements.

Using it without adopting it wholesale

Most organizations do not implement the AI RMF as a programme. They use it in three narrower ways, and all three are legitimate.

As a structure for a conversation, because the four functions are a good agenda for a governance discussion that would otherwise wander.

As a gap check, reading the functions against what the organization already does and noting what nothing covers. This is usually where MEASURE turns out to be missing entirely.

As a reference point for a governing body. Saying that an approach is informed by the NIST AI RMF gives a board or a customer a recognized comparison, which is worth more than a bespoke framework nobody has heard of.

What none of those requires is mapping every subcategory to a control. That exercise has value at scale and is expensive; the three uses above are available to an organization of any size in an afternoon.

Version handling, and why it matters here

NIST maintains the framework and has signalled a revision. The White House AI Action Plan of 23 July 2025 tasked NIST with revising the AI RMF. NIST has separately indicated a two-number versioning scheme, with major revisions changing the first number, and has said a formal review with community input is expected no later than 2028.

In April 2026 NIST released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure. A concept note is not a published profile, and it should not be cited as one.

The practical consequence for an organization: reference the framework by name and version, record when you checked its status, and avoid writing internal policy that hard-codes a version number in a way that will require a rewrite. Our own review cadence for this page is three months, for the same reason.

Where it fits alongside the other references

The AI RMF is one of three documents that come up in almost every governance conversation, and they are different kinds of thing. The GAO AI Accountability Framework is oversight guidance organized around Governance, Data, Performance and Monitoring, addressed to federal agencies and other entities. ISO/IEC 42001:2023 specifies requirements for an AI management system, against which independent certification is possible.

Voluntary guidance, oversight guidance, and a certifiable management system. Treating them as interchangeable is the most common error in this area, and the comparison is worked through in NIST AI RMF versus ISO/IEC 42001.

Where to go next

For the domains a programme has to cover, see the AI governance framework. For the order to build them in, how to create an AI governance program. To establish where you stand today, the AI governance checklist.

LABUSA's approach is informed by the AI RMF and maps conceptually to its functions. We do not describe ourselves or our clients as NIST certified, approved or compliant, because no such status exists. If you want your programme reviewed against the framework as a reference point, our governance assessment work covers it, and a conversation is the place to start.

About LABUSA

LAB Information Technology Incorporated (LABUSA) is a trusted provider of managed IT solutions, empowering organizations with secure, efficient, and scalable technologies. With expertise spanning cybersecurity, cloud services, enterprise software, and data management, LABUSA helps clients modernize operations, strengthen compliance, and optimize performance. Our customer-focused approach ensures tailored solutions that align with organizational goals while maintaining the highest standards of reliability and security. Headquartered in Houston, Texas, LABUSA serves government agencies, corporations, and nonprofits across the United States and internationally.