Framework
The NIST AI Risk Management Framework
Reviewed 25 August 2026
NIST AI RMF
The NIST AI Risk Management Framework is voluntary guidance for managing risk in artificial intelligence systems, published by the US National Institute of Standards and Technology in January 2023. It organises AI risk management into four functions - Govern, Map, Measure and Manage - and is not certifiable, having no audit or certificate attached.
Definition
What is NIST AI RMF?
The NIST AI RMF is a framework for thinking, not a control checklist. Its four functions are deliberately sequenced. Govern establishes the culture, policies and accountability that everything else depends on. Map builds context: what the system does, who it affects, what could go wrong. Measure assesses and tracks the risks Map identified. Manage allocates resources and acts on them.
The framework is organised around seven characteristics of trustworthy AI: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. These are the qualities the four functions are working towards, and the framework is explicit that they trade off against one another rather than all being maximised at once.
Because it is voluntary and non-certifiable, the NIST AI RMF is often used as the structuring layer beneath a certifiable standard. Organisations use it to work out what their AI risks actually are, then certify the resulting management system against ISO 42001.
Who NIST AI RMF applies to
- Organisations at the start of AI governance who need a way to structure the problem before committing to a certification path.
- Companies selling to US federal agencies or their suppliers, where NIST alignment is a common contractual expectation.
- Teams that need a shared vocabulary for AI risk across engineering, legal, product and risk functions.
- Organisations preparing for EU AI Act obligations who want to build the underlying risk practice first.
- Anyone who has been asked to explain AI risk to a board and found there was no agreed framing to use.
The path
How long does NIST AI RMF actually take?
Realistic elapsed durations for an organisation starting without a dedicated compliance function. Elapsed time, not effort - the two are routinely confused when this gets scoped.
- 013-6 weeks
Govern: accountability and policy
Establish who is accountable for AI risk, what the organisation's risk tolerance is, and how AI decisions get made and recorded. Govern is listed first because the other three functions produce findings that need somewhere to go. Skipping it produces analysis nobody acts on.
- 024-8 weeks
Map: context and inventory
Build the AI system inventory, establish what each system does, who is affected by it, and where harm could occur. Map is where shadow AI surfaces, and where organisations discover that vendor features have quietly become AI systems they now own the risk for.
- 036-10 weeks
Measure: assess and track
Define metrics for the trustworthiness characteristics that matter to each system, then test against them. This is the function most often skipped, because it requires deciding what good looks like in measurable terms rather than describing intent.
- 04Continuous
Manage: act and monitor
Prioritise the risks, allocate resources, implement treatments and monitor over time, including incident response for AI-specific failures. Manage is not a phase that completes - it is the steady state the first three functions exist to establish.
Cost and internal effort figures are being confirmed with the practice before publication: cost and effort figures · Q15
Failure points
Where NIST AI RMF programmes usually go wrong
Not the theory. The specific things that cause a delayed audit, a major non-conformity, or a certificate that does not survive its first surveillance visit.
Starting with Map instead of Govern
Inventorying AI systems is the satisfying part and teams reach for it first. Without Govern in place there is no owner, no risk tolerance and no decision path, so the inventory becomes a document rather than a control. The framework orders the functions deliberately.
Measuring what is easy rather than what matters
Model accuracy is easy to measure and rarely the risk. Fairness across affected groups, explainability to the person affected by a decision, and behaviour under adversarial input are harder to measure and are usually where the actual harm sits.
Treating it as a certification
There is no NIST AI RMF certificate and no accredited assessor. Claiming to be NIST AI RMF certified is inaccurate and will be noticed by anyone who knows the framework. The honest claim is alignment, supported by evidence of the four functions operating.
Applying it uniformly to every system
The framework is explicitly risk-based. A model that ranks internal search results and a model that screens job applicants do not warrant the same treatment. Applying identical rigour to both wastes effort on one and under-protects the other.
No route from Measure to Manage
Measurement that does not change what gets built or deployed is documentation. There has to be a defined point where a measured risk can stop or alter a release, and someone with the authority to make that call.
Ignoring the Generative AI Profile
NIST published a companion profile covering risks specific to generative AI, including confabulation, data leakage through prompts, and harmful content generation. Organisations deploying generative AI who work only from the core framework miss the risks most likely to affect them.
Dates that apply
The deadlines attached to NIST AI RMF
- Deferred · 14 months awayAnnex III standalone high-risk system obligations apply
- In force · since 2023Certifiable now
Verified 25 August 2026Full regulatory horizon ->
How we run it
NIST AI RMF, delivered in sprints
- 01Govern established first, with a named accountable owner and a written risk tolerance, so later findings have somewhere to land.
- 02Map run as active discovery including shadow AI, not a survey sent to team leads.
- 03Systems tiered by potential harm, so effort concentrates where a failure actually hurts someone.
- 04Measurement defined in terms your engineers can implement and your risk function can read.
- 05Findings delivered as a prioritised backlog with owners, in your tooling, rather than as a maturity report.
- 06Mapped forward to ISO 42001 and the EU AI Act, so the work counts towards certification rather than being a separate exercise.
Choosing between them
NIST AI RMF or ISO 42001?
The NIST AI RMF tells you how to think about AI risk; ISO 42001 gives you a management system you can be audited against. NIST AI RMF is voluntary, free to use, non-certifiable and strongest at helping an organisation work out what its AI risks actually are. ISO 42001 is a certifiable management system standard that produces a certificate an enterprise customer or a regulator will accept as evidence. They are complementary rather than alternatives, and the usual sequence is to use NIST AI RMF to structure the risk work, then certify the resulting system against ISO 42001 when somebody needs proof.
ISO 42001FAQ
NIST AI RMF: questions people actually ask
Can you get certified against the NIST AI Risk Management Framework?
What are the four functions of the NIST AI RMF?
Does the NIST AI RMF satisfy the EU AI Act?
Should we use NIST AI RMF or ISO 42001?
What is the NIST Generative AI Profile?
Start
Three ways in, depending on how close the deadline is.
- Book it
Book a discovery call
Thirty minutes, no deck. We work out whether there is a real engagement here, and say so if there is not.
- Go
Check the EU AI Act applies
Six questions, a dated list of the obligations that reach you, and a calendar file so the deadlines land somewhere you will see them again.
- Go
Request a roadmap
You know the obligation and the deadline. We scope the sprints, the deliverables and the dates.
Or just email a human: hello@cloudgap.ai
We reply within24 hours