Essex Junction, VT802-335-2662dkoran@davidkoran.com
DK
David Koran& Associates
AI Governance / NIST AI RMF

The NIST AI Risk Management Framework: what it asks, and why it has become the American baseline.

The NIST AI Risk Management Framework, published as AI RMF 1.0 in January 2023, is a voluntary framework for identifying, assessing, and managing the risks of artificial intelligence. In the absence of a comprehensive federal AI statute, it has become the de facto reference for AI governance in the United States: named in state law as a defense, asked about in procurement and due diligence, and crosswalked to ISO/IEC 42001 and the EU AI Act. This page explains the framework's four functions, the Generative AI Profile, the current NIST work program, and what alignment involves in practice.

The Framework at a Glance

NIST AI RMF 1.0

  • Published January 2023 as NIST AI 100-1
  • Four functions: Govern, Map, Measure, Manage
  • 19 categories and 72 subcategories
  • Generative AI Profile, NIST AI 600-1, July 2024
  • Voluntary, with a companion Playbook and crosswalks
  • A revision of AI RMF 1.0 is underway at NIST
Fundamentals

What the framework is and what it is for.

The AI RMF is a risk management framework, not a certification standard and not a checklist. It gives an organization a structured way to answer four questions about its use of artificial intelligence: is the use governed, is it understood in context, is it evaluated, and is it managed over time. The framework organizes those questions into four functions, Govern, Map, Measure, and Manage, elaborated through 19 categories and 72 subcategories that describe outcomes rather than prescribe methods. The organization decides how to achieve each outcome in proportion to its role, its systems, and the risks involved.

The framework's stated goal is trustworthy AI, which it defines through seven characteristics: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. These characteristics do the same work in AI governance that confidentiality, integrity, and availability do in information security. They convert an abstract aspiration into properties that can be examined, and an assessment against the framework is in large part an examination of whether the organization can support claims about those properties with evidence.

Because the framework is voluntary and outcome-based, its output is not a certificate. Its output is a working risk program and its records: an inventory of AI systems and their contexts, documented risk decisions, defined accountability, measurement appropriate to the organization's role, and treatment and monitoring that continue after deployment. Those records are what counterparties are actually asking for when they ask whether an organization follows the NIST AI RMF.

The Core

The four functions.

Govern is the cross-cutting function that makes the other three possible; Map, Measure, and Manage form the operating cycle applied to each AI system. The functions are continuous rather than sequential: mapping resumes when context changes, measurement resumes when systems change, and management continues for as long as the system runs.

Govern

Culture, policy, and accountability

The organizational function: AI policy, assigned roles and responsibilities, risk tolerance, workforce awareness, third-party oversight, and the processes that keep leadership informed. Govern is where the AI use inventory lives and where every other function gets its authority. In organizations that adopted AI tools before adopting governance, this is where the gaps concentrate.

Map

Context and risk identification

Establishing what each AI system is, what it is for, who it affects, and what could go wrong: intended use, foreseeable misuse, the data involved, the people and groups affected, and the risks specific to the context. Mapping is where an organization discovers that the boundary of its AI use is larger than it assumed, particularly where vendors have embedded AI into products already in service.

Measure

Analysis, testing, and metrics

Evaluating the risks that mapping identified, using quantitative and qualitative methods appropriate to the organization's role. For a developer that means testing models; for the deployer and user organizations this practice serves, it means evaluating vendor claims and documentation, examining outputs against intended use, and tracking the indicators that reveal when a system drifts from acceptable behavior.

Manage

Treatment, monitoring, and response

Acting on what measurement shows: prioritizing risks against tolerance, applying treatments, monitoring systems in operation, planning for incidents and failures, and deciding when a system should be changed, constrained, or retired. Manage is where AI risk management becomes an operating discipline with records rather than a one-time review.

The subcategories under these functions are the framework's working surface: 72 outcome statements that a gap analysis walks through one by one. An organization does not need all 72 at equal depth. It needs an honest determination of which apply to its role and systems, and evidence for the ones that do.
NIST AI 600-1

The Generative AI Profile.

In July 2024, NIST released the Generative AI Profile, NIST AI 600-1, as a companion to the framework. The profile identifies twelve risk categories that are unique to or amplified by generative AI, including confabulation, information security risks, data privacy, intellectual property, dangerous or violent content, and human-AI configuration, and maps suggested actions for each to the four functions. The profile is additive: it does not replace the base framework, it specializes it for organizations using large language models and other generative systems.

For most small and midsize organizations, the profile is not optional in practice, because generative AI is precisely the AI they use. The employee drafting with a chatbot, the AI assistant embedded in the office suite, and the generative features arriving in line-of-business software all sit inside the profile's subject matter. A gap analysis in this practice therefore applies the base framework and the Generative AI Profile together, with the profile's deployer-level actions carrying most of the weight.

The framework's ecosystem continues to grow around it, which is worth knowing because it signals where obligations are heading. NIST has stated that AI RMF 1.0 is being revised, released a preliminary draft Cyber AI Profile connecting AI risk to the Cybersecurity Framework in December 2025, published a concept note for a Critical Infrastructure profile in April 2026, and has SP 800-53 control overlays for securing AI systems in development. An organization aligned to the framework today inherits those extensions incrementally rather than starting over when they arrive.

Why a Voluntary Framework Carries Weight

Nobody mandates the AI RMF. Several instruments reference it.

The framework's force is referential. Texas made the clearest move: under TRAIGA, in effect since January 1, 2026, substantial compliance with the NIST AI RMF is recognized as a defense, which converts a voluntary framework into concrete legal value for any organization whose systems reach Texans. The counterexample proves the same point from the other side. Colorado's original 2024 AI Act contained a similar framework-based defense, and when Colorado repealed and replaced that law in 2026, the defense did not carry into the successor statute. Statutes churn; the framework has remained the stable reference underneath them, which is the core argument for governing to the framework rather than to any single statute, as developed on the AI governance overview.

The commercial references are quieter but broader. Enterprise procurement questionnaires and vendor due diligence increasingly ask whether an AI governance framework is in place and name the AI RMF as the expected answer. Cyber insurance applications have begun asking about AI use and its governance. Published crosswalks map the framework to ISO/IEC 42001 and to the EU AI Act, so work performed against the AI RMF transfers rather than duplicates: an organization can use the framework as its risk methodology and pursue the ISO/IEC 42001 management system when a certificate becomes commercially worthwhile.

The practical reading: the AI RMF is voluntary the way ISO 27001 was voluntary in 2010 and NIST SP 800-171 was obscure in 2015. The organizations that aligned early answered every later question from records they already held.
Alignment Work

What AI RMF alignment involves in this practice.

Alignment work translates the framework into an operating program sized to the organization's actual role, which for most clients of this practice is deployer and user rather than developer. The work begins where Govern begins, with the AI use inventory: what systems, embedded features, and tools are actually in use, established from the environment rather than from assumptions, as described on the AI governance overview. Mapping then documents context and risk for the systems that matter, measurement is scoped to what a deployer can genuinely evaluate, including vendor documentation, contract terms, and output monitoring, and management turns the results into treatments, monitoring, and response the organization can sustain. The gap analysis walks the subcategories, and the Generative AI Profile is applied wherever generative tools are in use.

The deliverable is the same across this practice: an evidence-based picture of where the organization stands, findings reported at the executive level, and a prioritized path with assigned ownership. This is independent advisory work; there is no certificate to sell and no software attached to the conclusion. What the organization holds at the end is a working program and the records that let it answer, accurately, when a statute, a customer, a carrier, or its own board asks how its AI is governed.

Common Questions

The NIST AI RMF, answered briefly.

What is the NIST AI RMF?

The NIST AI Risk Management Framework, published as AI RMF 1.0 in January 2023, is a voluntary framework for identifying, assessing, and managing AI risk. It organizes the work into four functions, Govern, Map, Measure, and Manage, elaborated through 19 categories and 72 subcategories, and it has become the de facto AI governance reference in the United States.

Is it mandatory?

No. The framework is voluntary. Its weight comes from the instruments that reference it: Texas recognizes substantial compliance as a defense under TRAIGA, procurement and due diligence questionnaires ask about it by name, and crosswalks connect it to ISO/IEC 42001 and the EU AI Act.

What is the Generative AI Profile?

NIST AI 600-1, released in July 2024, extends the framework to generative AI. It identifies twelve risk categories unique to or amplified by generative systems and maps suggested actions to the four functions. Organizations using large language models or generative features in their software apply the profile on top of the base framework.

How does it relate to ISO/IEC 42001?

They complement each other. The AI RMF structures risk thinking; ISO/IEC 42001 is a certifiable management system that institutionalizes governance. Published crosswalks map the two, so framework alignment builds directly toward the standard if certification later becomes worthwhile. The ISO/IEC 42001 page covers that standard in the same depth.

Does a small company that only uses AI tools need this?

The framework scales to role. A deployer and user organization does not need model testing laboratories; it needs the Govern and Map work, inventory, policy, accountability, and context, plus measurement and management proportionate to the tools it runs. That is a bounded program, and it is the version of the framework most small and midsize organizations are actually being asked about.

Get In Touch

Discuss NIST AI RMF Alignment

Inquiries may involve an AI RMF gap analysis, building the Govern function and the AI use inventory, applying the Generative AI Profile, or structuring alignment so it also serves ISO/IEC 42001, state law defenses, and the AI questions arriving in contracts and insurance applications. Call, email, or send a note. I respond personally to every inquiry, usually within one business day.

Address
Essex Junction, VT
Travel
I travel to client sites nationally.

Discuss an Assessment

Whether the question is where your organization stands against the framework, how to build the inventory and governance the Govern function requires, or how alignment serves the statutes and questionnaires now referencing the framework, the first conversation carries no commitment and no pitch.

Discuss an Assessment →