NIST AI Risk Management Framework
Understand how the NIST AI Risk Management Framework helps organizations identify, assess, measure, and manage risks across the AI lifecycle while building more trustworthy AI systems.

What Is the NIST AI Risk Management Framework?
The NIST Artificial Intelligence Risk Management Framework (AI RMF) is a voluntary framework developed by the U.S. National Institute of Standards and Technology to help organizations manage risks associated with artificial intelligence and promote trustworthy and responsible AI.
AI RMF 1.0 is designed for organizations that design, develop, deploy, use, or evaluate AI systems. It is non-sector specific and use-case agnostic, allowing organizations of different sizes and industries to adapt its practices to their own risk profiles and needs.
Rather than prescribing a single set of technical controls, the framework provides a structured approach for understanding AI risks throughout the AI lifecycle. Its Core is organized around four functions: Govern, Map, Measure, and Manage.
NIST also provides a Generative AI Profile, NIST AI 600-1, which applies the AI RMF approach to risks associated with generative AI. It was published in July 2024.
What Does NIST AI RMF Cover?
The AI RMF Core organizes AI risk-management activities into four functions. These functions are intended to work together rather than as a fixed sequence, with Govern acting as a cross-cutting function across the AI risk-management process. NIST also emphasizes that the framework's actions are not a checklist.
AI Governance
Establish policies, processes, accountability structures, organizational culture, and risk-management practices for AI.
AI Context & Risk Mapping
Understand the AI system's purpose, context, stakeholders, potential impacts, benefits, limitations, and risks.
AI Risk Measurement
Apply appropriate methods and metrics to evaluate AI risks, system performance, and trustworthy AI characteristics.
AI Risk Management
Prioritize identified risks, develop responses, allocate resources, monitor outcomes, and manage residual risks.
AI System Inventory
Maintain mechanisms for inventorying AI systems according to organizational risk priorities.
Third-Party AI Risk
Identify and manage risks associated with third-party software, data, models, and other AI components.
AI Security & Resilience
Evaluate and document the security and resilience of AI systems.
AI Privacy Risk
Examine and document privacy risks associated with AI systems.
Ongoing Risk Monitoring
Track existing and emerging risks and maintain processes for post-deployment monitoring, response, and recovery.
NIST AI RMF at a Glance
Get a quick overview of NIST AI RMF, including its core functions, scope, and approach to AI risk management. See how Govern, Map, Measure, and Manage work together to support trustworthy AI across the lifecycle.
Four Core Functions: GOVERN (Establish the organizational structures and policies needed to manage AI risk), MAP (Understand the context, intended use, stakeholders, impacts, and risks associated with AI), MEASURE (Test, evaluate, monitor, and document AI risks and trustworthy AI characteristics), MANAGE (Prioritize risks and implement appropriate responses, mitigation, monitoring, and recovery processes).
Who Should Consider NIST AI RMF?
NIST AI RMF can be used by organizations across industries and throughout the AI lifecycle. It is designed for organizations involved in designing, developing, deploying, using, or evaluating AI systems.
AI Developers
Organizations building, training, testing, or integrating AI models and applications.
AI Deployers
Organizations introducing AI into products, services, business processes, and internal workflows.
Enterprise AI Teams
Organizations using third-party AI applications, copilots, agents, or AI-powered platforms across the business.
Security & Risk Teams
Security, privacy, compliance, legal, audit, and risk teams responsible for identifying and managing AI-related risks.
AI Governance Leaders
Organizations establishing policies, accountability structures, inventories, monitoring practices, and oversight for enterprise AI.
Organizations Using Generative AI
Organizations deploying LLMs, generative AI applications, AI agents, or other systems where generative AI introduces additional security, privacy, reliability, or information-integrity risks.
NIST AI RMF Readiness Checklist
How NIST AI RMF fits into the AI compliance landscape
NIST AI RMF can complement regulations, standards, and other frameworks that address AI governance, security, privacy, and risk.
ISO/IEC 42001
ISO/IEC 42001 establishes requirements for an Artificial Intelligence Management System. NIST AI RMF provides a flexible framework for identifying and managing AI risks through Govern, Map, Measure, and Manage. Organizations can use the two together to combine organizational AI governance with a structured AI risk-management approach.
ISO/IEC 23894
ISO/IEC 23894 provides guidance for managing risks specifically associated with AI. It can complement NIST AI RMF by providing additional guidance for AI risk-management practices.
EU AI Act
The EU AI Act establishes legally binding requirements for AI systems within its scope. NIST AI RMF is voluntary and can provide organizations with a risk-management structure that supports broader AI governance and compliance efforts.

SOC 2
SOC 2 focuses on controls relevant to areas such as security, availability, processing integrity, confidentiality, and privacy. NIST AI RMF addresses broader AI risks while also incorporating security, privacy, resilience, and monitoring considerations.

NIST Generative AI Profile
The NIST AI RMF Generative AI Profile (AI 600-1) extends the framework with guidance for generative AI risks. It identifies areas including data privacy, information security, information integrity, human-AI configuration, and value-chain and component-integration risks.
Frequently Asked Questions
Official NIST AI RMF Resources
For authoritative information about the NIST AI Risk Management Framework, refer to official NIST documentation: