← All frameworks
Voluntary

NIST AI RMF

US NIST · Gaithersburg, US · effective Jan 2023 (v1.0) + GenAI Profile 2024

The de-facto US risk-management baseline. Four functions — Govern, Map, Measure, Manage — plus the Generative AI Profile. Voluntary but referenced by US federal procurement and state law.

Who must comply
  • US federal agencies & contractors (de-facto)
  • Any org wanting a recognised US risk baseline
Penalties

No direct fines — but the baseline for federal contracts and a defensible standard in US litigation.

Key obligations
Govern
Culture, roles, accountability and policy for AI risk.
Map
Context, capabilities and impacts of each AI system.
Measure
Quantitative & qualitative evaluation of trustworthiness.
Manage
Prioritise, respond to and monitor risks over the lifecycle.
Sectors in scope
Federal / governmentDefenseFinanceHealthcareCritical infrastructure
Threats & cybersecurity it addresses
Model drift & degradationBias & disparate impactGenAI hallucination / misuseSupply-chain model risk
Crosswalks — comply once, cover many
EU AI Act →ISO 42001FedRAMP / OSCAL
CSOAI Layer 0 mapping

Charter Art. 11, 21, 24, 39

Governed MCP tools — open source, pip/npx install