Langprotect

NIST AI Risk Management Framework

Understand how the NIST AI Risk Management Framework helps organizations identify, assess, measure, and manage risks across the AI lifecycle while building more trustworthy AI systems.

Published: January 2023Type: Voluntary Risk Management FrameworkScope: AI Risk Management
NIST AI Risk Management Framework

What Is the NIST AI Risk Management Framework?

The NIST Artificial Intelligence Risk Management Framework (AI RMF) is a voluntary framework developed by the U.S. National Institute of Standards and Technology to help organizations manage risks associated with artificial intelligence and promote trustworthy and responsible AI.

AI RMF 1.0 is designed for organizations that design, develop, deploy, use, or evaluate AI systems. It is non-sector specific and use-case agnostic, allowing organizations of different sizes and industries to adapt its practices to their own risk profiles and needs.

Rather than prescribing a single set of technical controls, the framework provides a structured approach for understanding AI risks throughout the AI lifecycle. Its Core is organized around four functions: Govern, Map, Measure, and Manage.

NIST also provides a Generative AI Profile, NIST AI 600-1, which applies the AI RMF approach to risks associated with generative AI. It was published in July 2024.

What Does NIST AI RMF Cover?

The AI RMF Core organizes AI risk-management activities into four functions. These functions are intended to work together rather than as a fixed sequence, with Govern acting as a cross-cutting function across the AI risk-management process. NIST also emphasizes that the framework's actions are not a checklist.

GOVERN

AI Governance

Establish policies, processes, accountability structures, organizational culture, and risk-management practices for AI.

MAP

AI Context & Risk Mapping

Understand the AI system's purpose, context, stakeholders, potential impacts, benefits, limitations, and risks.

MEASURE

AI Risk Measurement

Apply appropriate methods and metrics to evaluate AI risks, system performance, and trustworthy AI characteristics.

MANAGE

AI Risk Management

Prioritize identified risks, develop responses, allocate resources, monitor outcomes, and manage residual risks.

GOVERN 1.6

AI System Inventory

Maintain mechanisms for inventorying AI systems according to organizational risk priorities.

GOVERN 6 / MANAGE 3

Third-Party AI Risk

Identify and manage risks associated with third-party software, data, models, and other AI components.

MEASURE 2.7

AI Security & Resilience

Evaluate and document the security and resilience of AI systems.

MEASURE 2.10

AI Privacy Risk

Examine and document privacy risks associated with AI systems.

MEASURE 3.1 / MANAGE 4

Ongoing Risk Monitoring

Track existing and emerging risks and maintain processes for post-deployment monitoring, response, and recovery.

NIST AI RMF at a Glance

Get a quick overview of NIST AI RMF, including its core functions, scope, and approach to AI risk management. See how Govern, Map, Measure, and Manage work together to support trustworthy AI across the lifecycle.

FRAMEWORKNIST AI Risk Management Framework
VERSIONAI RMF 1.0
PUBLISHEDJanuary 26, 2023
PUBLISHERNational Institute of Standards and Technology (NIST)
TYPEVoluntary Framework
CORE FUNCTIONSGovern, Map, Measure, Manage
PRIMARY FOCUSAI Risk Management & Trustworthy AI
APPLICATIONAI systems across their lifecycle

Four Core Functions: GOVERN (Establish the organizational structures and policies needed to manage AI risk), MAP (Understand the context, intended use, stakeholders, impacts, and risks associated with AI), MEASURE (Test, evaluate, monitor, and document AI risks and trustworthy AI characteristics), MANAGE (Prioritize risks and implement appropriate responses, mitigation, monitoring, and recovery processes).

Who Should Consider NIST AI RMF?

NIST AI RMF can be used by organizations across industries and throughout the AI lifecycle. It is designed for organizations involved in designing, developing, deploying, using, or evaluating AI systems.

AI Developers

AI Developers

Organizations building, training, testing, or integrating AI models and applications.

AI Deployers

AI Deployers

Organizations introducing AI into products, services, business processes, and internal workflows.

Enterprise AI Teams

Enterprise AI Teams

Organizations using third-party AI applications, copilots, agents, or AI-powered platforms across the business.

Security & Risk Teams

Security & Risk Teams

Security, privacy, compliance, legal, audit, and risk teams responsible for identifying and managing AI-related risks.

AI Governance Leaders

AI Governance Leaders

Organizations establishing policies, accountability structures, inventories, monitoring practices, and oversight for enterprise AI.

Organizations Using Generative AI

Organizations Using Generative AI

Organizations deploying LLMs, generative AI applications, AI agents, or other systems where generative AI introduces additional security, privacy, reliability, or information-integrity risks.

NIST AI RMF Readiness Checklist

Establish organizational AI risk-management policies
Define roles and responsibilities for AI risk management
Maintain an inventory of AI systems
Define the intended purpose and context of each AI system
Identify relevant stakeholders and potentially affected groups
Identify AI risks, benefits, limitations, and potential impacts
Establish organizational AI risk tolerance
Define appropriate risk metrics and measurement methods
Test and evaluate AI systems before deployment
Monitor AI systems and risks during operation
Evaluate AI security and resilience
Assess privacy and other trustworthy AI characteristics
Identify and manage third-party AI and supply-chain risks
Prioritize high-impact AI risks
Document risk responses and mitigation measures
Establish incident response and recovery processes
Review and update AI risk-management practices as systems and risks evolve

How NIST AI RMF fits into the AI compliance landscape

NIST AI RMF can complement regulations, standards, and other frameworks that address AI governance, security, privacy, and risk.

ISO/IEC 42001

ISO/IEC 42001

ISO/IEC 42001 establishes requirements for an Artificial Intelligence Management System. NIST AI RMF provides a flexible framework for identifying and managing AI risks through Govern, Map, Measure, and Manage. Organizations can use the two together to combine organizational AI governance with a structured AI risk-management approach.

ISO/IEC 23894

ISO/IEC 23894

ISO/IEC 23894 provides guidance for managing risks specifically associated with AI. It can complement NIST AI RMF by providing additional guidance for AI risk-management practices.

EU AI Act

EU AI Act

The EU AI Act establishes legally binding requirements for AI systems within its scope. NIST AI RMF is voluntary and can provide organizations with a risk-management structure that supports broader AI governance and compliance efforts.

SOC 2

SOC 2

SOC 2 focuses on controls relevant to areas such as security, availability, processing integrity, confidentiality, and privacy. NIST AI RMF addresses broader AI risks while also incorporating security, privacy, resilience, and monitoring considerations.

NIST Generative AI Profile

NIST Generative AI Profile

The NIST AI RMF Generative AI Profile (AI 600-1) extends the framework with guidance for generative AI risks. It identifies areas including data privacy, information security, information integrity, human-AI configuration, and value-chain and component-integration risks.

Frequently Asked Questions

Official NIST AI RMF Resources

For authoritative information about the NIST AI Risk Management Framework, refer to official NIST documentation: