GLOSSARY · LEADERSHIP & GRC

NIST AI Risk Management Framework (AI RMF)

The NIST AI Risk Management Framework (AI RMF) is a voluntary United States framework, published in January 2023, that helps organizations identify, measure, and manage risks from AI systems.

It organizes work into four functions (Govern, Map, Measure, Manage) and defines characteristics of trustworthy AI. A companion profile published in 2024 addresses generative AI specifically.

The four functions are worth knowing in order, because they describe a sequence rather than a menu. Govern establishes the policies, roles, and accountability everything else depends on, and it runs continuously rather than once. Map builds context: what the system is for, who it affects, what could go wrong. Measure turns that context into testing and metrics, including the uncomfortable ones like bias and robustness that do not collapse into a single score. Manage allocates resources against the risks you found and decides what to accept, mitigate, or stop doing.

Its practical advantage over a certifiable standard is that it is free, voluntary, and outcome-based rather than prescriptive. NIST tells you what to reason about rather than which control to buy, which makes it usable at small scale and adaptable to use cases its authors never imagined. Its practical disadvantage is the same property viewed from the other side: nobody certifies you against it, so it does not close a procurement question the way ISO/IEC 42001 does.

For most organizations starting out, the AI RMF is the right first framework. It gives you a defensible vocabulary and structure quickly, its Generative AI Profile maps the specific failure modes of the systems people are actually deploying, and none of the work is wasted if you certify later. The frameworks complement rather than compete: RMF for framing, OWASP for anything your teams build, and the EU AI Act if you operate in or sell into Europe.