NIST AI 100-1 | Version 1.0 | January 2023

The Complete Guide to NIST AI RMF

The US National Institute of Standards and Technology's AI Risk Management Framework. A voluntary, comprehensive approach to managing AI risks throughout the AI lifecycle. Learn the four core functions, seven trustworthy characteristics, and practical implementation.

You are interacting with an AI system.

The embedded 'Ask your Council assistant' panel (SovereignSpot) sends questions to the live Council chat endpoint (councilof.ai/api/gspc), where a model writes the answer. The Art 50(1) notice for this surface is registered here and being wired; until the component ships, this registry entry is the disclosure.

Disclosed under EU AI Act Article 50(1). Every surface and its classification

4
Core Functions
7
Trustworthy Characteristics
19
Categories
72+
Subcategories
Understanding the Framework

What is NIST AI RMF?

The NIST AI Risk Management Framework (AI RMF) is a voluntary framework published by the US National Institute of Standards and Technology in January 2023. It provides organizations with guidance for managing risks associated with AI systems throughout their lifecycle.

Unlike regulatory requirements, the AI RMF is designed to be flexible and adaptable, allowing organizations of all sizes and sectors to implement risk management practices appropriate to their context and risk tolerance.

The framework is built around four core functions (GOVERN, MAP, MEASURE, MANAGE) and seven characteristics of trustworthy AI, providing a comprehensive approach to responsible AI development and deployment.

Lifecycle-Based
End-to-End Coverage
Flexible
Adapt to Your Context

Key Objectives

  • Enable organizations to incorporate trustworthiness into AI systems
  • Provide flexible, scalable risk management guidance
  • Support ongoing improvement throughout AI lifecycle
  • Promote transparency and accountability in AI development
  • Address technical and sociotechnical AI risks
  • Complement existing organizational risk management practices
The Framework Structure

Four Core Functions

The AI RMF organizes risk management activities into four interconnected functions. GOVERN is a cross-cutting function that informs all others.

GOVERN

Cultivate a culture of AI risk management

Establish and maintain a culture of AI risk management across the organization. This cross-cutting function informs and is integrated into all other functions.

GV-1

Governance Policies

Policies, processes, procedures, and practices across the organization establish transparent AI governance.

GV-2

Accountability

Accountability structures are in place to ensure that AI activities comply with applicable regulations.

GV-3

Workforce

Workforce diversity, equity, inclusion, and accessibility processes are prioritized in AI governance.

GV-4

Organizational Context

Organizational mission and goals are reflected in AI design, development, deployment, and use.

GV-5

Risk Management Integration

AI risk management processes are integrated with broader enterprise risk management.

GV-6

Stakeholder Engagement

Stakeholder feedback is incorporated into AI governance processes.

Function Relationships

GOVERN
(Cross-cutting)
MAP
MEASURE
MANAGE

The functions are interconnected and iterative. GOVERN provides the foundation, while MAP, MEASURE, and MANAGE form a continuous cycle of risk identification, assessment, and treatment.

Foundation of Trustworthy AI

7 Trustworthy AI Characteristics

The AI RMF identifies seven characteristics that contribute to trustworthy AI. These characteristics may overlap and can sometimes be in tension with each other.

Valid and Reliable

AI systems perform as intended for defined operating conditions and produce consistent results.

Consistent outputs under similar conditions
Accuracy aligned with intended use
Documented performance benchmarks
Validated against ground truth

Safe

AI systems do not cause physical, psychological, financial, or environmental harm to humans or resources.

Fail-safe mechanisms
Bounded operating conditions
Emergency shutdown procedures
Harm prevention measures

Secure and Resilient

AI systems maintain confidentiality, integrity, availability, and can withstand adversarial attacks.

Adversarial robustness
Data protection
System availability
Recovery capabilities

Accountable and Transparent

Organizations and individuals are answerable for AI system decisions with clear disclosure of capabilities.

Clear ownership and responsibility
Disclosed capabilities and limitations
Decision audit trails
Stakeholder communication

Explainable and Interpretable

AI system outputs can be understood and explained in terms meaningful to stakeholders.

Human-understandable explanations
Model interpretability
Decision reasoning
Contextual explanations

Privacy-Enhanced

AI systems respect individual privacy rights and comply with applicable privacy regulations.

Data minimization
Consent management
Privacy by design
Data subject rights

Fair – with Harmful Bias Managed

AI systems are designed and deployed to minimize harmful bias and promote equitable outcomes.

Bias detection and mitigation
Equitable outcomes
Representative data
Inclusive design

Managing Tradeoffs

These characteristics may require balancing tradeoffs. For example, increasing explainability might reduce accuracy, or privacy protection might limit data availability. Organizations should prioritize based on their context, stakeholder needs, and risk tolerance.

New Release - December 2025

NIST AI RMF Cyber AI Profile

The NIST AI RMF Cyber AI Profile provides specific guidance for managing AI cybersecurity risks, bridging the AI RMF with the NIST Cybersecurity Framework.

Cross-Walk with CSF

Maps AI RMF subcategories to NIST Cybersecurity Framework functions

Threat Modeling

AI-specific threat identification and attack surface analysis

Supply Chain Security

Guidance for AI model and data supply chain risks

Incident Response

AI-specific incident detection and response procedures

Red Teaming

Framework for adversarial testing of AI systems

Secure Development

Secure AI development lifecycle practices

Cross-Framework Compatibility

Alignment with Other Frameworks

The NIST AI RMF is designed to complement and align with other AI governance frameworks and standards.

EU AI Act

High Alignment

NIST AI RMF's risk-based approach closely mirrors the EU AI Act's risk classification. Organizations can use the AI RMF to build compliance programs that satisfy EU requirements.

Key Mappings:

GOVERN aligns with EU governance requirements
MAP supports risk classification processes
MEASURE enables conformity assessment
MANAGE addresses ongoing compliance monitoring

ISO/IEC 42001

Very High Alignment

Both frameworks share foundational principles. ISO 42001's AIMS structure maps directly to AI RMF functions, enabling organizations to pursue certification while following AI RMF guidance.

Key Mappings:

Governance structures are equivalent
Risk assessment methodologies align
Continuous improvement cycles match
Documentation requirements are compatible

OECD AI Principles

Very High Alignment

The AI RMF was developed by NIST through an open, congressionally-directed process, and it aligns with and supports the OECD AI Principles through its trustworthy characteristics.

Key Mappings:

Human-centered values aligned
Transparency requirements match
Accountability principles equivalent
Robustness and security aligned
Getting Started

Implementation Roadmap

A practical approach to implementing the NIST AI RMF in your organization.

1

Frame the AI RMF

Understand your organization's context, values, and risk tolerance for AI systems.

Identify organizational objectives for AI
Establish risk tolerance levels
Define stakeholder groups
Document regulatory requirements
2

Scope Your AI Portfolio

Inventory and categorize all AI systems based on their purpose, deployment context, and potential impacts.

Create AI system inventory
Categorize by risk level
Identify critical AI systems
Document use cases and contexts
3

Establish Governance

Build the organizational structures, policies, and processes to manage AI risks effectively.

Designate AI governance roles
Develop AI policies and procedures
Integrate with enterprise risk management
Establish oversight mechanisms
4

Implement Functions

Operationalize the MAP, MEASURE, and MANAGE functions across your AI portfolio.

Deploy risk assessment processes
Implement measurement frameworks
Establish risk response procedures
Configure monitoring systems
5

Continuous Improvement

Monitor, evaluate, and refine your AI risk management practices over time.

Track metrics and KPIs
Conduct periodic reviews
Incorporate lessons learned
Update based on new guidance
Professional Development

Master the NIST AI RMF

Our comprehensive training program covers all aspects of the NIST AI RMF, from governance to implementation. Earn your certification and become an AI risk management expert.

All 4 Core Functions
Practical Exercises
Implementation Playbook
Got Questions?

Frequently Asked Questions

Common questions about the NIST AI RMF and its implementation.

Ready to Implement AI Risk Management?

Join organizations worldwide implementing the NIST AI RMF with CSOAI.

Ask the Council assistant — the NIST AI Risk Management Framework — Govern/Map/Measure/Manage
Governed answer · AI governance & cybersecurity only · signed to Layer 0
Open the full AI OS →