Start a free trial
Menu

NIST AI RMF

NIST AI RMF, a framework for managing AI system risk

Organizations that design, develop, deploy or use AI systems and want a documented process for managing the risks those systems create

A voluntary US framework of four functions, Govern, Map, Measure and Manage, for organizations to manage AI system risk, with no certification scheme.

Edition
1.0
Published
2023-01

What it is

The AI Risk Management Framework, published by the US National Institute of Standards and Technology as NIST AI 100-1 in January 2023, gives organizations a structure for identifying and managing the risks their AI systems create. It was produced at the direction of the National Artificial Intelligence Initiative Act of 2020, and NIST describes it in its own terms: it "is intended to be voluntary, rights-preserving, non-sector-specific, and use-case agnostic, providing flexibility to organizations of all sizes and in all sectors." There is no certification, no accredited body, and no legal requirement attached to it anywhere in the document itself. What it offers instead is a common vocabulary and a repeatable process for a question every organization building or buying AI eventually has to answer for itself: what could go wrong, how would we know, and what do we do about it.

The four functions: Govern, Map, Measure, Manage

The Framework's substance sits in four functions, each broken into categories and subcategories of outcomes rather than pass/fail controls. NIST is explicit that these "do not constitute a checklist, nor are they necessarily an ordered set of steps."

Govern is cross-cutting and threads through the other three. It covers documenting the legal and regulatory requirements that touch an organization's AI use, setting and documenting risk tolerance, keeping an inventory of AI systems, decommissioning them safely when their use ends, defining roles and training staff, building demographic and disciplinary diversity into risk decisions, and managing risk that comes from third-party software, data and the wider supply chain.

Map establishes context before anything is tested: the intended purpose of a system, who will use it and what they expect, the organization's risk tolerance, and the system's own requirements. It also asks organizations to categorize what a system actually does (a classifier, a generative model, a recommender), document its known limits, and identify likely impacts on the people and communities a system touches, drawing on past incidents and feedback from outside the team that built it.

Measure is where the trustworthiness characteristics below get tested against evidence: documented test sets and methods, evaluation of performance and safety under conditions similar to actual deployment, ongoing production monitoring, and assessment of security, transparency, explainability, privacy risk, fairness, and even the environmental cost of training and running a model. Where a risk genuinely cannot be measured with a currently available method, the Framework asks that this be documented rather than quietly dropped, and recommends internal experts who were not the system's own developers, or independent assessors, take part in the review.

Manage turns the first three functions into action: prioritizing identified risks by impact and likelihood, deciding whether to mitigate, transfer, avoid or accept each one, and documenting the negative residual risk that reaches "both downstream acquirers of AI systems and end users." It also covers ongoing monitoring of third-party components and pre-trained models used in development, and post-deployment plans for monitoring, appeal and override mechanisms, decommissioning, and incident response.

Seven characteristics of trustworthy AI

Part 1 of the document sets out what "trustworthy" means in practical terms, as characteristics the Measure function tests against: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. The document draws its definition of risk itself from ISO 31000: "risk management refers to coordinated activities to direct and control an organization with regard to risk." NIST is careful to say these characteristics trade off against each other rather than all being maximized at once - a system tuned for interpretability can lose some predictive accuracy, for example - and that balancing them is a judgment call specific to how a system will actually be used, not something the Framework resolves for the reader.

Who it is written for, and how it takes hold

The Framework addresses what it calls "AI actors," a term it borrows from the OECD: anyone who plays an active role in the AI system lifecycle, including those who design, develop, deploy, operate, test, procure, or govern it, plus the third parties that supply data or models into a system, and the downstream acquirers and end users who receive it. No single one of these roles is singled out as the audience; the document states "all involved AI actors share responsibilities for designing, developing, and deploying a trustworthy AI system that is fit for purpose."

Nothing in the AI RMF makes it binding on anyone. It takes hold only where an organization chooses to adopt it, or where a customer, an internal policy, or a separate regulatory regime asks for it by name. NIST says it aims to be "useful to a wide range of perspectives, sectors, and technology domains" and "universally applicable to any AI technology," and separately that it should be "law- and regulation-agnostic" so it sits alongside whatever rules already apply to an organization rather than replacing them. The document originates from a US federal agency, but nothing confines its use to the United States or to any one sector.

What an assessor actually looks for

There is no certification, no notified body, and no third-party audit scheme described anywhere in the AI RMF. What the document describes instead is self-evaluation: it encourages organizations "to periodically evaluate whether the AI RMF has improved their ability to manage AI risks," looking at their own policies, processes, implementation plans and outcomes. NIST states its intent plainly in describing the Framework's own attributes: it aims to "provide a catalog of outcomes and approaches rather than prescribe one-size-fits-all requirements." Where an organization does have to show its work, it is to a customer, to a regulator applying a separate legal regime, or to its own leadership, using the documentation the four functions above produce: policies, a system inventory, risk registers, test and evaluation records, and residual-risk statements.

What it deliberately leaves open

Two gaps are worth knowing about before treating this as a complete rulebook. The Framework "can be used to prioritize risk," but does not itself set risk tolerance for anyone - that stays an organizational, and sometimes sector-specific, decision. And while Section 6 describes "AI RMF Profiles," tailored applications of the Core for a specific use case or sector, NIST is explicit that "this Framework does not prescribe profile templates, allowing for flexibility in implementation," so an organization builds its own.

Appendix B of the document is a useful checklist in its own right: it lists specific ways AI risk differs from ordinary software risk, including data that can drift after a model is trained, the opacity of large pre-trained models, harder-to-predict failure modes, heavier computational and environmental cost, and testing standards it describes as "underdeveloped" for AI-based practices compared with traditionally engineered software.

How we help

The AI RMF is a risk-management framework, not a technical specification a product either meets or fails, so the closest comparison is something like ISO 31000: it describes a process an organization runs, and ComplyTrain is the system that process runs in. The AI system inventory the Govern function calls for, the documented risk tolerance and policies behind it, the intended-use and context documentation the Map function asks for, and the test records, monitoring logs and residual-risk statements the Measure and Manage functions produce all sit as controlled, versioned records with an owner and a review history, rather than a document assembled from memory when a customer asks for it. Training records for staff with AI risk responsibilities, and the sign-offs behind a decision to proceed with or retire an AI system, are exactly the kind of evidence an internal reviewer or a customer's due-diligence questionnaire tends to ask for.

What ComplyTrain does not do: it does not build, test or operate an AI system, decide an organization's risk tolerance, carry out the technical risk measurement the Measure function describes, or substitute for the judgment the Framework places with senior leadership. This is guidance an organization applies to its own AI systems and its own risk appetite; ComplyTrain holds the evidence trail that shows the work happened, not the AI risk decisions themselves.

If AI risk management is something you are building or defending to an auditor, a board, or a customer, see what else sits alongside the AI RMF in the standards explorer, and talk to us about the evidence trail behind it.

Standards it references

Questions

Is the NIST AI RMF mandatory?

No. NIST describes the Framework as voluntary, and nothing in the document creates a legal obligation. It becomes relevant to a given organization only by choice, by a customer or partner asking for it, or because a separate law or contract points at it - the AI RMF itself does not.

Can an organization be certified to the NIST AI RMF?

No. The document names no accredited certification body and no conformity assessment scheme. It describes only self-evaluation: organizations are encouraged to periodically assess whether using the Framework has improved their own ability to manage AI risk.

What are the four functions of the NIST AI RMF?

Govern, Map, Measure and Manage. Govern is cross-cutting and covers policy, roles and oversight; Map establishes context and intended use before a system is tested; Measure evaluates a system against trustworthiness characteristics like safety, fairness and security; Manage turns the findings into prioritized action and ongoing monitoring.

What is the difference between the AI RMF and the AI RMF Playbook?

The AI RMF is the Framework itself: the functions, categories and subcategories of outcomes. The Playbook is a separate, equally voluntary companion resource published by NIST with suggested tactical actions for achieving those outcomes, which organizations can select from and tailor to their own context.

Does the NIST AI RMF apply outside the United States?

The document does not confine its use to any jurisdiction or sector. NIST states it aims to be usable by "organizations of all sizes and in all sectors" and "universally applicable to any AI technology," though it originates from a US federal agency and any separate legal obligations still depend on where an organization operates.