It’s voluntary. You’re going to do the work anyway.
Whichever regime binds you — the EU AI Act, ISO 42001, a procurement questionnaire, a supervisor — the underlying work is the same: know what your systems do, test them, watch them, write it down. AI RMF is the vocabulary that makes that work count three times instead of once. It is free, it is readable, and nobody can certify you against it.
The same work, under three different names.
This is why AI RMF is not a third project. Every row is one piece of work; the columns are what each regime calls it.
| The work | NIST AI RMF | EU AI Act | ISO 42001 |
|---|---|---|---|
| Documented risk management across the lifecycle | GOVERN 1 · MANAGE 1 | Article 9 | Clause 6.1 |
| Data governance, provenance and quality | MAP 2 · MEASURE 2 | Article 10 | A.7 |
| Technical documentation of the system | MAP 1–3 | Article 11 · Annex IV | Clause 7.5 |
| Logging and record-keeping | MEASURE 3 · MANAGE 4 | Article 12 | A.6 |
| Information to the people running it | MAP 3 · GOVERN 5 | Article 13 | A.8 |
| Human oversight with real authority | GOVERN 2 · MANAGE 4 | Article 14 | A.9 |
| Accuracy, robustness and security | MEASURE 2 | Article 15 | A.6 |
| Impact on individuals and groups | MAP 5 | Article 27 | Clause 6.1.4 · A.5 |
| Third-party and supply-chain AI | GOVERN 6 · MANAGE 3 | Article 26 | A.10 |
| Post-deployment monitoring and incidents | MEASURE 3 · MANAGE 4 | Articles 72–73 | Clauses 9–10 |
This is iDharma’s working map, not NIST’s published crosswalk. NIST publishes its own crosswalk documents and those are the authority; ours is how we tag findings so one body of evidence answers three asks. Several rows are arguable, and where a mapping is genuinely contested the report says so rather than picking the tidy answer.
Run AI RMF properly and you have not “done NIST”. You have done most of the EU AI Act’s Articles 9–15 and most of ISO 42001’s clauses 6 and 8 — in a vocabulary both of those will accept as evidence.
What is the NIST AI RMF?
A framework for managing the risks of AI, published by the US National Institute of Standards and Technology. It is voluntary. It gives you a structure — four functions, nineteen categories, seven characteristics of trustworthy AI — and deliberately stops short of telling you what your risk tolerance should be, because that is not a question a standards body can answer for you.
- Status Voluntary No legal force of its own. Adopted by reference in contracts and procurement.
- Published January 2023 AI RMF 1.0, developed under the National AI Initiative Act of 2020.
- Companion Generative AI Profile NIST AI 600-1, July 2024 — the GenAI-specific overlay on the same Core.
Who needs it?
Nobody is legally required to adopt it. In practice it arrives through the terms — a contract clause, a vendor questionnaire, a supervisor asking which framework you run. These are the four places that ask comes from most often.
- Federal agencies and their suppliers US federal AI policy is written in NIST's vocabulary, and it reaches contractors through the terms rather than through a statute.
- Regulated industries Finance, health and insurance supervisors increasingly ask for a named risk framework. AI RMF is the one most often accepted by name.
- Global enterprises It maps cleanly onto the EU AI Act and ISO 42001, so one body of evidence can answer three different asks.
- AI developers and deployers The Core is written to be usable by whoever holds the risk — the roles it calls "AI actors" span the whole lifecycle.
How iDharma supports NIST AI RMF implementation
A verified auditor works the framework in its own structure, so the report reads against the functions you will be asked about rather than against ours.
| RMF function | What the assessment does |
|---|---|
| GOVERN | Governance review: policies, roles, risk tolerance and third-party terms read against GOVERN 1–6, with the gaps ranked. |
| MAP | System inventory and context capture — purpose, data, deployment setting and affected groups, documented per system. |
| MEASURE | Independent testing against the seven characteristics: accuracy, robustness, security, subgroup performance and explanation quality. |
| MANAGE | Treatment plan, ownership, monitoring cadence and incident path — written so it survives the person who wrote it. |
AI inventory and function mapping
Register every AI system with the metadata MAP asks for — purpose, data sources, deployment context and affected groups — and hold each entry against the categories it engages, so coverage is visible per system rather than in aggregate.
Addresses: MAP 1–5 context and categorisation, GOVERN 1 policies
Risk tolerance and governance records
Capture the risk tolerance the organisation has actually set, who set it and when it was last revisited. GOVERN asks for a documented position rather than an implied one, and an undocumented tolerance is the gap that shows up first.
Addresses: GOVERN 1 policies and tolerance, GOVERN 2 accountability
Measurement plan and metric registry
Fix the methods and metrics before the results exist. Each characteristic gets a named test, a threshold and an owner, so MEASURE produces a comparable series rather than a one-off report.
Addresses: MEASURE 1 methods and metrics, MEASURE 2 characteristics evaluated
Bias and subgroup performance testing
Test performance by subgroup rather than in aggregate, across the systemic, computational and human-cognitive bias the framework names. Results are recorded with the population definitions used, because a fairness number without them is unreadable later.
Addresses: MEASURE 2 harmful bias, MAP 5 impacts
Continuous monitoring and drift tracking
MEASURE 3 asks for mechanisms that keep tracking identified risks after deployment. Monitoring runs against the same metrics the assessment used, so a change in the series means a change in the system rather than a change in method.
Addresses: MEASURE 3 tracking, MANAGE 4 monitoring
Incident response and treatment records
Log incidents with severity and owner, track the treatment through to closure, and keep the decision trail. MANAGE 4 is about what happens after something goes wrong, and it is the part most programmes have least evidence for.
Addresses: MANAGE 1 prioritisation, MANAGE 4 response and recovery
Every activity is recorded with a timestamp, a named owner and the method used. That trail is what separates a governance programme from documentation assembled after someone asked for it — and it is the first thing an assessor looks for.
Complete NIST AI RMF categories coverage
All 19 categories across the 4 functions, with dedicated tooling behind each one.
- GOVERN The culture, policies and accountability the other three run inside.
- 6/6 categories covered
- MAP Establish the context, so risk is assessed against real use rather than intent.
- 5/5 categories covered
- MEASURE Analyse, benchmark and monitor — with methods chosen before the results are known.
- 4/4 categories covered
- MANAGE Act on what MEASURE found — prioritise, treat, monitor, and respond.
- 4/4 categories covered
Function-level scoring
Every finding lands on a named category, so the report reads in the framework's own structure.
GenAI Profile overlay
Generative systems are additionally read against NIST AI 600-1 rather than squeezed into the base Core.
Current-to-target profile
You get both profiles and the gap between them, which is the plan the framework is designed to produce.
Cross-framework mapping
Each finding is tagged to its EU AI Act article and ISO 42001 control, so one assessment answers three asks.
Four core functions
AI RMF organises risk management into four functions. GOVERN is cross-cutting; the other three run in order, and running them out of order is how programmes end up measuring systems nobody has described.
GOVERN
6 categoriesThe culture, policies and accountability the other three run inside.
- Policies, processes and procedures for AI risk
- Accountability structures and clear ownership
- Workforce competency, diversity and training
- Risk tolerance set and documented
- Engagement with affected people and AI actors
- Third-party and supply-chain AI risk
Cross-cutting — it applies to all stages, not to one.
MAP
5 categoriesEstablish the context, so risk is assessed against real use rather than intent.
- Context established and understood
- The AI system categorised and its purpose stated
- Capabilities, targeted usage, goals and expectations
- Risks and benefits mapped for all components
- Impacts to individuals, groups and communities
Done badly here, everything downstream measures the wrong thing.
MEASURE
4 categoriesAnalyse, benchmark and monitor — with methods chosen before the results are known.
- Appropriate methods and metrics identified
- Trustworthiness characteristics evaluated
- Mechanisms for tracking identified risks in place
- Feedback about efficacy gathered and assessed
This is where the seven trustworthiness characteristics get tested.
MANAGE
4 categoriesAct on what MEASURE found — prioritise, treat, monitor, and respond.
- Risks prioritised, acted on and resourced
- Strategies to maximise benefit and minimise harm
- Third-party risks and benefits managed
- Treatments documented, monitored and responded to
The function most often skipped, and the only one a regulator can see.
Functions → categories → subcategories. The 19 categories are not the working unit. Each breaks into subcategories, and the subcategory is what the AI RMF Playbook attaches suggested actions and references to. When somebody says they have “covered GOVERN 1”, the useful question is which subcategories, and with what evidence.
Seven trustworthiness characteristics
AI RMF defines what a trustworthy system looks like. These seven are what MEASURE tests against — and they trade off against each other, which is why the framework asks you to record the trade you made rather than pretend you made none.
Valid & reliable
The system does what it claims, on the data it will actually meet, repeatably.
Safe
It does not endanger life, health, property or the environment under foreseeable conditions.
Secure & resilient
It withstands adversarial input and unexpected conditions, and degrades gracefully.
Accountable & transparent
Who is answerable is known, and what the system is and does is disclosed to those affected.
Explainable & interpretable
Its mechanism can be described, and its output made meaningful in context.
Privacy-enhanced
Anonymity, confidentiality and control are preserved by design rather than by policy.
Fair – with harmful bias managed
Systemic, computational and human-cognitive bias are identified and managed, not merely disclaimed.
The base Core doesn’t reach generative systems.
NIST AI 600-1, July 2024, is a cross-sectoral overlay on the same four functions — not a replacement for them. It names the risks that are unique to generative AI, or made materially worse by it.
Confabulation
Confidently stated content with no basis in the source material.
Information integrity
Generated content that degrades the information environment it enters.
Information security
Prompt injection, model extraction and the attack surface a generative interface opens.
Data privacy
Training-data leakage, memorisation, and inference about people from outputs.
Intellectual property
Provenance of training data and of what the system produces.
Harmful bias or homogenization
Both skewed output and the flattening that comes from everyone using the same models.
Human-AI configuration
Over-reliance, misplaced trust, and unclear handoffs between person and system.
Dangerous, violent or hateful content
Generation of content that causes harm on release.
Obscene, degrading or abusive content
Including non-consensual imagery of real people.
CBRN information or capabilities
Lowering the barrier to chemical, biological, radiological or nuclear harm.
Environmental impacts
The compute cost of training and of serving at scale.
Value chain and component integration
Risk inherited from models, data and components you did not build.
If you run generative systems and your assessment stops at the base Core, everything on this list is unexamined — and confabulation and information integrity are the two that turn up in production first. The profile is a free PDF; it is linked in the sources below.
24-week implementation roadmap
A practical path to AI RMF adoption for an organisation starting without AI governance. The weeks are elapsed position, not effort — the phases overlap in practice.
-
GOVERN Weeks 1–4
Foundation
Stand up the governance the rest runs inside
- Assign AI risk ownership and escalation
- Set and document risk tolerance
- Adopt or adapt AI policies
- Inventory every AI system in use
- Establish third-party AI terms
-
MAP Weeks 5–10
Context and mapping
Establish what each system is actually for
- Document context and operating environment
- Categorise each system and state its purpose
- Record capabilities, limits and expectations
- Map risks and benefits per component
- Characterise impacts on affected groups
-
MEASURE Weeks 11–18
Measurement
Test the seven characteristics, not the demo
- Select methods and metrics per characteristic
- Test accuracy, robustness and security
- Run subgroup and disparate-impact testing
- Evaluate explanation quality in context
- Stand up risk-tracking mechanisms
- Gather and assess user feedback
-
MANAGE Weeks 19–24
Management
Treat, monitor and keep it current
- Prioritise and resource risk treatments
- Document treatment decisions and owners
- Manage third-party risk actively
- Stand up incident response and reporting
- Set the re-assessment cadence
Note: the framework has no deadline, so this schedule is ours rather than NIST’s. It is sized for a handful of systems; an enterprise programme with dozens of models runs longer, and a single high-stakes system can be assessed in weeks.
NIST AI RMF profiles
A profile is the Core applied to a specific setting. The framework’s output is not a score — it is the distance between where you are and where you intend to be.
AI RMF Core profile
The Core applied to one setting. A current profile records where you are, a target profile where you intend to be, and the distance between them is the programme — the framework is explicit that the gap, not the score, is the output.
Generative AI Profile
NIST AI 600-1, published July 2024. A cross-sectoral profile covering the risks unique to or amplified by generative AI — confabulation, harmful content, data leakage, provenance, and the human-AI configuration questions the base Core does not reach.
How NIST AI RMF compares
The three instruments most often confused with each other, and what actually separates them. They are not alternatives — most organisations end up touching all three.
| NIST AI RMF | EU AI Act | ISO/IEC 42001 | |
|---|---|---|---|
| Type | Voluntary framework | Binding regulation | Certifiable standard |
| Certification | None — nothing to certify against | Conformity assessment for high-risk | Third-party certification |
| Issued by | NIST (United States) | European Union | ISO / IEC |
| Applies to | Any AI, any sector, by choice | AI placed on or used in the EU market | Your AI management system |
| Structure | 4 functions, 19 categories | Risk tiers and articles | Clauses plus Annex A controls |
| Enforcement | Contractual, not statutory | Up to €35m or 7% of turnover | Certificate withdrawn |
| Best used for | Structuring the risk work itself | Meeting a legal obligation | Proving the system is managed |
So which one do you actually need?
- Your AI touches the EU market
- The Act is not optional and AI RMF is not a substitute for it. Run AI RMF as the engine; the Act is the obligation it feeds.
- Procurement or a customer is asking
- ISO 42001 is the only one of the three you can hand them a certificate for. AI RMF is what you do to be ready for that audit.
- Nobody is asking yet, but you are deploying AI
- Start here. It is free, it needs no auditor, and it is the only one of the three you can begin on Monday.
- All three are in play
- The ordinary case for a global enterprise — and the argument for one mapped assessment rather than three overlapping ones producing three incompatible reports.
Both of the others have their own page: the EU AI Act and ISO/IEC 42001.
Voluntary, and increasingly not optional
AI RMF carries no penalties of its own. What it carries is recognition — and once a buyer, a supervisor or an insurer names it in writing, it binds you through the contract rather than through the law.
Federal procurement
US public-sector AI policy is drafted in NIST's vocabulary, and it reaches suppliers through contract terms rather than through a statute.
Enterprise vendor review
Large buyers increasingly ask which AI risk framework you run. Naming one and evidencing it is what shortens the review.
Board and insurer diligence
Both want a named structure with owners and dates attached. AI RMF is the one most often recognised without explanation.
Complete AI governance policy repository
31 ready-to-use policy templates, grouped by the function they serve and mapped across to EU AI Act and ISO 42001 requirements.
Govern function
- AI Governance Policy
- AI Risk Tolerance Statement
- AI Roles & Accountability
- Responsible AI Principles
- AI Workforce Competency
- Third-Party AI Terms
+ 5 more policies
Map & measure functions
- AI System Context Record
- Impact Assessment Template
- Measurement Plan & Metrics
- Bias Testing Procedure
- Robustness & Security Testing
- Explainability Review
+ 4 more policies
Manage function
- Risk Treatment Register
- AI Incident Response Plan
- Continuous Monitoring Standard
- Model Change & Release
- Decommissioning Procedure
- Re-Assessment Cadence
+ 4 more policies
Official NIST resources
This page is a summary. These are the documents it summarises — every one of them NIST’s own, so nothing here has to be taken on our word.
The framework itself — the Core, the profiles, and the seven characteristics.
https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf AI RMF PlaybookSuggested actions and references for each subcategory, maintained in the Trustworthy AI Resource Center.
https://airc.nist.gov/AI_RMF_Knowledge_Base/Playbook Generative AI Profile (NIST AI 600-1)The cross-sectoral overlay for generative systems, July 2024.
https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf NIST AI Risk Management Framework hubThe programme page — updates, working groups and the current document set.
https://www.nist.gov/itl/ai-risk-management-frameworkOn this page. This is a summary of AI RMF 1.0 (NIST AI 100-1) and the Generative AI Profile (NIST AI 600-1). Both are free, both are linked above, and where this page and the framework disagree the framework wins.
The three-way map near the top is iDharma’s working crosswalk, not NIST’s published one. The category total of 19 and the generative-risk list are the figures we carry; they are the ones to confirm against the PDFs before quoting them onward.
Not legal advice. AI RMF is voluntary and carries no certification — we assess against it, and nobody certifies against it.
Frequently asked questions
The ones that come up in every NIST AI RMF scoping call.
If it is voluntary and there is no certificate, what do we get out of it?
A structure the other two regimes accept as evidence, in a vocabulary your auditors, customers and board already recognise. The underlying work — knowing what your systems do, testing them, watching them, writing it down — is not optional under any regime that might reach you. Only the label is. Running it under AI RMF is what stops you doing that work three times and producing three incompatible reports.
Is NIST AI RMF mandatory?
No. It is voluntary and carries no penalties of its own. What makes it feel mandatory is where it gets referenced — federal contract terms, enterprise vendor questionnaires and insurer diligence increasingly name it, and at that point it is binding on you contractually rather than legally.
What are the four functions?
GOVERN, MAP, MEASURE and MANAGE. GOVERN is cross-cutting — it is the culture, policy and accountability the other three operate inside. MAP establishes context, MEASURE analyses and tracks, MANAGE acts on what MEASURE found. Between them they hold 19 categories.
Do we have to implement all four functions?
The framework does not require anything, so strictly no. In practice GOVERN and MAP are load-bearing: measuring a system whose purpose and context were never written down produces numbers nobody can act on, and MANAGE without MEASURE is a plan with no evidence under it.
What is the Generative AI Profile?
NIST AI 600-1, published July 2024. It is a cross-sectoral profile — an overlay on the same Core — covering risks that are unique to generative AI or made worse by it, including confabulation, harmful content, data leakage and content provenance. If you run generative systems, the base Core alone will not reach them.
How does NIST AI RMF relate to the EU AI Act?
They answer different questions. The EU AI Act tells you what you must do if your AI touches the EU market; AI RMF tells you how to organise the work. The overlap in substance is large — risk management, data governance, testing, human oversight, monitoring — so a serious AI RMF programme covers much of the Act's Article 9–15 ground. It does not, on its own, make you compliant with it.
What is the difference between NIST AI RMF and ISO 42001?
Certifiability, mostly. ISO/IEC 42001 is a management-system standard you can be audited against and hold a certificate for. AI RMF has no certification scheme at all — nobody can certify you against it, and any vendor claiming to is selling something the framework does not define. AI RMF is better at structuring the risk work; ISO 42001 is better at proving to a third party that the system around it is managed.
Can we skip AI RMF and go straight to ISO 42001?
You can, and some do. But ISO 42001 asks you to have run a risk process and to be able to show the records it produced — and AI RMF is a well-specified, free, publicly readable description of that process. Skipping it usually means inventing a private one and then explaining it to a certification auditor, which is more work rather than less.
Can one assessment cover more than one framework?
Largely, yes, and it is usually the cheaper route. We tag each finding to its AI RMF category, its EU AI Act article and its ISO 42001 control, so one body of evidence answers three asks instead of three overlapping engagements producing three incompatible reports.
How long does implementation take?
The roadmap on this page runs 24 weeks for an organisation with a handful of systems and no existing AI governance. The weeks are elapsed position rather than effort, and the phases overlap. A single high-stakes system can be assessed in weeks; an enterprise-wide programme with dozens of models runs longer than 24.
How do we prioritise which systems to assess first?
By consequence, not by how interesting the model is. Systems that make or materially shape decisions about people — credit, hiring, access to services, clinical support — come first, then anything customer-facing that generates content, then internal tooling. MAP is what tells you which is which, which is why it runs before MEASURE.
What documentation does it actually require?
Nothing, strictly — it is voluntary. What it describes, and what anyone asking whether you follow it will look for, is: an AI inventory with context per system, a documented risk tolerance, named owners, a measurement plan with methods fixed in advance, results against the seven characteristics, treatment decisions, and monitoring with a cadence.
What does the Playbook add?
Suggested actions, references and documentation prompts, attached at the subcategory level rather than the category level. It is not normative and you do not have to follow it — but it is the fastest way to turn "we should cover MEASURE 2" into a list of things somebody can actually do this week. It is maintained in NIST's Trustworthy AI Resource Center rather than inside the framework PDF.
How does it apply to third-party and vendor AI?
Directly. GOVERN has a category for third-party risk and MANAGE has one for managing it, because buying a model in does not move the risk off you. In practice this is the weakest area in most programmes: the inventory stops at systems built in-house, and the ones bought in are the ones nobody has context for.
Can iDharma assess us against NIST AI RMF?
Yes — that is what this page is about. A verified auditor works through all four functions and the seven characteristics, produces a current profile and a target profile, and hands you the gap ranked by consequence. Scoping is agreed with you before anything is charged.
Ready to implement NIST AI RMF?
The framework is free and the PDFs are linked above — you can start without us. What we add is the independent read: all four functions, all 19 categories, the seven characteristics, and the GenAI Profile where it applies. Current profile against target, and the gap ranked by consequence — mapped to your EU AI Act and ISO 42001 obligations so it counts three times.
Scoped with you before you are charged. This page is guidance on how we scope an assessment, not legal advice.