NIST AI RMF · VOLUNTARY FRAMEWORK · GOVERN MAP MEASURE MANAGE

It’s voluntary. You’re going to do the work anyway.

Whichever regime binds you — the EU AI Act, ISO 42001, a procurement questionnaire, a supervisor — the underlying work is the same: know what your systems do, test them, watch them, write it down. AI RMF is the vocabulary that makes that work count three times instead of once. It is free, it is readable, and nobody can certify you against it.


An AI audit standard report on a desk under a brass lamp, open at a framework mapping table with a NIST AI RMF column ticked across governance, risk and transparency rows Illustrative materials
One assessment, mapped across frameworks
GOVERN MAP MEASURE MANAGE GenAI Profile
One assessment, three asks

The same work, under three different names.

This is why AI RMF is not a third project. Every row is one piece of work; the columns are what each regime calls it.

Common AI governance work mapped to NIST AI RMF categories, EU AI Act articles and ISO/IEC 42001 clauses and controls
The work NIST AI RMF EU AI Act ISO 42001
Documented risk management across the lifecycle GOVERN 1 · MANAGE 1 Article 9 Clause 6.1
Data governance, provenance and quality MAP 2 · MEASURE 2 Article 10 A.7
Technical documentation of the system MAP 1–3 Article 11 · Annex IV Clause 7.5
Logging and record-keeping MEASURE 3 · MANAGE 4 Article 12 A.6
Information to the people running it MAP 3 · GOVERN 5 Article 13 A.8
Human oversight with real authority GOVERN 2 · MANAGE 4 Article 14 A.9
Accuracy, robustness and security MEASURE 2 Article 15 A.6
Impact on individuals and groups MAP 5 Article 27 Clause 6.1.4 · A.5
Third-party and supply-chain AI GOVERN 6 · MANAGE 3 Article 26 A.10
Post-deployment monitoring and incidents MEASURE 3 · MANAGE 4 Articles 72–73 Clauses 9–10

This is iDharma’s working map, not NIST’s published crosswalk. NIST publishes its own crosswalk documents and those are the authority; ours is how we tag findings so one body of evidence answers three asks. Several rows are arguable, and where a mapping is genuinely contested the report says so rather than picking the tidy answer.

Run AI RMF properly and you have not “done NIST”. You have done most of the EU AI Act’s Articles 9–15 and most of ISO 42001’s clauses 6 and 8 — in a vocabulary both of those will accept as evidence.

What is the NIST AI RMF?

A framework for managing the risks of AI, published by the US National Institute of Standards and Technology. It is voluntary. It gives you a structure — four functions, nineteen categories, seven characteristics of trustworthy AI — and deliberately stops short of telling you what your risk tolerance should be, because that is not a question a standards body can answer for you.

  • Status Voluntary No legal force of its own. Adopted by reference in contracts and procurement.
  • Published January 2023 AI RMF 1.0, developed under the National AI Initiative Act of 2020.
  • Companion Generative AI Profile NIST AI 600-1, July 2024 — the GenAI-specific overlay on the same Core.

Who needs it?

Nobody is legally required to adopt it. In practice it arrives through the terms — a contract clause, a vendor questionnaire, a supervisor asking which framework you run. These are the four places that ask comes from most often.

  • Federal agencies and their suppliers US federal AI policy is written in NIST's vocabulary, and it reaches contractors through the terms rather than through a statute.
  • Regulated industries Finance, health and insurance supervisors increasingly ask for a named risk framework. AI RMF is the one most often accepted by name.
  • Global enterprises It maps cleanly onto the EU AI Act and ISO 42001, so one body of evidence can answer three different asks.
  • AI developers and deployers The Core is written to be usable by whoever holds the risk — the roles it calls "AI actors" span the whole lifecycle.
How we help

How iDharma supports NIST AI RMF implementation

A verified auditor works the framework in its own structure, so the report reads against the functions you will be asked about rather than against ours.

RMF functionWhat the assessment does
GOVERNGovernance review: policies, roles, risk tolerance and third-party terms read against GOVERN 1–6, with the gaps ranked.
MAPSystem inventory and context capture — purpose, data, deployment setting and affected groups, documented per system.
MEASUREIndependent testing against the seven characteristics: accuracy, robustness, security, subgroup performance and explanation quality.
MANAGETreatment plan, ownership, monitoring cadence and incident path — written so it survives the person who wrote it.

AI inventory and function mapping

Register every AI system with the metadata MAP asks for — purpose, data sources, deployment context and affected groups — and hold each entry against the categories it engages, so coverage is visible per system rather than in aggregate.

Addresses: MAP 1–5 context and categorisation, GOVERN 1 policies

Risk tolerance and governance records

Capture the risk tolerance the organisation has actually set, who set it and when it was last revisited. GOVERN asks for a documented position rather than an implied one, and an undocumented tolerance is the gap that shows up first.

Addresses: GOVERN 1 policies and tolerance, GOVERN 2 accountability

Measurement plan and metric registry

Fix the methods and metrics before the results exist. Each characteristic gets a named test, a threshold and an owner, so MEASURE produces a comparable series rather than a one-off report.

Addresses: MEASURE 1 methods and metrics, MEASURE 2 characteristics evaluated

Bias and subgroup performance testing

Test performance by subgroup rather than in aggregate, across the systemic, computational and human-cognitive bias the framework names. Results are recorded with the population definitions used, because a fairness number without them is unreadable later.

Addresses: MEASURE 2 harmful bias, MAP 5 impacts

Continuous monitoring and drift tracking

MEASURE 3 asks for mechanisms that keep tracking identified risks after deployment. Monitoring runs against the same metrics the assessment used, so a change in the series means a change in the system rather than a change in method.

Addresses: MEASURE 3 tracking, MANAGE 4 monitoring

Incident response and treatment records

Log incidents with severity and owner, track the treatment through to closure, and keep the decision trail. MANAGE 4 is about what happens after something goes wrong, and it is the part most programmes have least evidence for.

Addresses: MANAGE 1 prioritisation, MANAGE 4 response and recovery

Every activity is recorded with a timestamp, a named owner and the method used. That trail is what separates a governance programme from documentation assembled after someone asked for it — and it is the first thing an assessor looks for.

Coverage

Complete NIST AI RMF categories coverage

All 19 categories across the 4 functions, with dedicated tooling behind each one.

19
AI RMF categories
19
Categories with dedicated tooling
100%
Coverage across all four functions
GOVERN The culture, policies and accountability the other three run inside.
6/6 categories covered
MAP Establish the context, so risk is assessed against real use rather than intent.
5/5 categories covered
MEASURE Analyse, benchmark and monitor — with methods chosen before the results are known.
4/4 categories covered
MANAGE Act on what MEASURE found — prioritise, treat, monitor, and respond.
4/4 categories covered
Built for AI RMF from the ground up

Function-level scoring

Every finding lands on a named category, so the report reads in the framework's own structure.

GenAI Profile overlay

Generative systems are additionally read against NIST AI 600-1 rather than squeezed into the base Core.

Current-to-target profile

You get both profiles and the gap between them, which is the plan the framework is designed to produce.

Cross-framework mapping

Each finding is tagged to its EU AI Act article and ISO 42001 control, so one assessment answers three asks.

The core

Four core functions

AI RMF organises risk management into four functions. GOVERN is cross-cutting; the other three run in order, and running them out of order is how programmes end up measuring systems nobody has described.

GOVERN

6 categories

The culture, policies and accountability the other three run inside.

  • Policies, processes and procedures for AI risk
  • Accountability structures and clear ownership
  • Workforce competency, diversity and training
  • Risk tolerance set and documented
  • Engagement with affected people and AI actors
  • Third-party and supply-chain AI risk

Cross-cutting — it applies to all stages, not to one.

MAP

5 categories

Establish the context, so risk is assessed against real use rather than intent.

  • Context established and understood
  • The AI system categorised and its purpose stated
  • Capabilities, targeted usage, goals and expectations
  • Risks and benefits mapped for all components
  • Impacts to individuals, groups and communities

Done badly here, everything downstream measures the wrong thing.

MEASURE

4 categories

Analyse, benchmark and monitor — with methods chosen before the results are known.

  • Appropriate methods and metrics identified
  • Trustworthiness characteristics evaluated
  • Mechanisms for tracking identified risks in place
  • Feedback about efficacy gathered and assessed

This is where the seven trustworthiness characteristics get tested.

MANAGE

4 categories

Act on what MEASURE found — prioritise, treat, monitor, and respond.

  • Risks prioritised, acted on and resourced
  • Strategies to maximise benefit and minimise harm
  • Third-party risks and benefits managed
  • Treatments documented, monitored and responded to

The function most often skipped, and the only one a regulator can see.

Functions → categories → subcategories. The 19 categories are not the working unit. Each breaks into subcategories, and the subcategory is what the AI RMF Playbook attaches suggested actions and references to. When somebody says they have “covered GOVERN 1”, the useful question is which subcategories, and with what evidence.

Trustworthy AI

Seven trustworthiness characteristics

AI RMF defines what a trustworthy system looks like. These seven are what MEASURE tests against — and they trade off against each other, which is why the framework asks you to record the trade you made rather than pretend you made none.

Valid & reliable

The system does what it claims, on the data it will actually meet, repeatably.

How it is testedAccuracy, generalisation and drift testing

Safe

It does not endanger life, health, property or the environment under foreseeable conditions.

How it is testedFailure-mode analysis and safe-shutdown paths

Secure & resilient

It withstands adversarial input and unexpected conditions, and degrades gracefully.

How it is testedAdversarial and robustness testing

Accountable & transparent

Who is answerable is known, and what the system is and does is disclosed to those affected.

How it is testedOwnership records and disclosure review

Explainable & interpretable

Its mechanism can be described, and its output made meaningful in context.

How it is testedExplanation methods fit to the audience

Privacy-enhanced

Anonymity, confidentiality and control are preserved by design rather than by policy.

How it is testedData minimisation and re-identification risk

Fair – with harmful bias managed

Systemic, computational and human-cognitive bias are identified and managed, not merely disclaimed.

How it is testedSubgroup performance and disparate-impact testing
Generative AI

The base Core doesn’t reach generative systems.

NIST AI 600-1, July 2024, is a cross-sectoral overlay on the same four functions — not a replacement for them. It names the risks that are unique to generative AI, or made materially worse by it.

Confabulation

Confidently stated content with no basis in the source material.

Information integrity

Generated content that degrades the information environment it enters.

Information security

Prompt injection, model extraction and the attack surface a generative interface opens.

Data privacy

Training-data leakage, memorisation, and inference about people from outputs.

Intellectual property

Provenance of training data and of what the system produces.

Harmful bias or homogenization

Both skewed output and the flattening that comes from everyone using the same models.

Human-AI configuration

Over-reliance, misplaced trust, and unclear handoffs between person and system.

Dangerous, violent or hateful content

Generation of content that causes harm on release.

Obscene, degrading or abusive content

Including non-consensual imagery of real people.

CBRN information or capabilities

Lowering the barrier to chemical, biological, radiological or nuclear harm.

Environmental impacts

The compute cost of training and of serving at scale.

Value chain and component integration

Risk inherited from models, data and components you did not build.

If you run generative systems and your assessment stops at the base Core, everything on this list is unexamined — and confabulation and information integrity are the two that turn up in production first. The profile is a free PDF; it is linked in the sources below.

Getting there

24-week implementation roadmap

A practical path to AI RMF adoption for an organisation starting without AI governance. The weeks are elapsed position, not effort — the phases overlap in practice.

  1. GOVERN Weeks 1–4

    Foundation

    Stand up the governance the rest runs inside

    • Assign AI risk ownership and escalation
    • Set and document risk tolerance
    • Adopt or adapt AI policies
    • Inventory every AI system in use
    • Establish third-party AI terms
  2. MAP Weeks 5–10

    Context and mapping

    Establish what each system is actually for

    • Document context and operating environment
    • Categorise each system and state its purpose
    • Record capabilities, limits and expectations
    • Map risks and benefits per component
    • Characterise impacts on affected groups
  3. MEASURE Weeks 11–18

    Measurement

    Test the seven characteristics, not the demo

    • Select methods and metrics per characteristic
    • Test accuracy, robustness and security
    • Run subgroup and disparate-impact testing
    • Evaluate explanation quality in context
    • Stand up risk-tracking mechanisms
    • Gather and assess user feedback
  4. MANAGE Weeks 19–24

    Management

    Treat, monitor and keep it current

    • Prioritise and resource risk treatments
    • Document treatment decisions and owners
    • Manage third-party risk actively
    • Stand up incident response and reporting
    • Set the re-assessment cadence

Note: the framework has no deadline, so this schedule is ours rather than NIST’s. It is sized for a handful of systems; an enterprise programme with dozens of models runs longer, and a single high-stakes system can be assessed in weeks.

Profiles

NIST AI RMF profiles

A profile is the Core applied to a specific setting. The framework’s output is not a score — it is the distance between where you are and where you intend to be.

Use case

AI RMF Core profile

The Core applied to one setting. A current profile records where you are, a target profile where you intend to be, and the distance between them is the programme — the framework is explicit that the gap, not the score, is the output.

  • Current profile
  • Target profile
  • Gap as the plan
Overlay

Generative AI Profile

NIST AI 600-1, published July 2024. A cross-sectoral profile covering the risks unique to or amplified by generative AI — confabulation, harmful content, data leakage, provenance, and the human-AI configuration questions the base Core does not reach.

  • NIST AI 600-1
  • GenAI-specific risks
  • Suggested actions
In context

How NIST AI RMF compares

The three instruments most often confused with each other, and what actually separates them. They are not alternatives — most organisations end up touching all three.

  NIST AI RMF EU AI Act ISO/IEC 42001
Type Voluntary framework Binding regulation Certifiable standard
Certification None — nothing to certify against Conformity assessment for high-risk Third-party certification
Issued by NIST (United States) European Union ISO / IEC
Applies to Any AI, any sector, by choice AI placed on or used in the EU market Your AI management system
Structure 4 functions, 19 categories Risk tiers and articles Clauses plus Annex A controls
Enforcement Contractual, not statutory Up to €35m or 7% of turnover Certificate withdrawn
Best used for Structuring the risk work itself Meeting a legal obligation Proving the system is managed

So which one do you actually need?

Your AI touches the EU market
The Act is not optional and AI RMF is not a substitute for it. Run AI RMF as the engine; the Act is the obligation it feeds.
Procurement or a customer is asking
ISO 42001 is the only one of the three you can hand them a certificate for. AI RMF is what you do to be ready for that audit.
Nobody is asking yet, but you are deploying AI
Start here. It is free, it needs no auditor, and it is the only one of the three you can begin on Monday.
All three are in play
The ordinary case for a global enterprise — and the argument for one mapped assessment rather than three overlapping ones producing three incompatible reports.

Both of the others have their own page: the EU AI Act and ISO/IEC 42001.

Voluntary, and increasingly not optional

AI RMF carries no penalties of its own. What it carries is recognition — and once a buyer, a supervisor or an insurer names it in writing, it binds you through the contract rather than through the law.

Federal procurement

US public-sector AI policy is drafted in NIST's vocabulary, and it reaches suppliers through contract terms rather than through a statute.

Enterprise vendor review

Large buyers increasingly ask which AI risk framework you run. Naming one and evidencing it is what shortens the review.

Board and insurer diligence

Both want a named structure with owners and dates attached. AI RMF is the one most often recognised without explanation.

Start your NIST assessment
Policy templates

Complete AI governance policy repository

31 ready-to-use policy templates, grouped by the function they serve and mapped across to EU AI Act and ISO 42001 requirements.

Govern function

  • AI Governance Policy
  • AI Risk Tolerance Statement
  • AI Roles & Accountability
  • Responsible AI Principles
  • AI Workforce Competency
  • Third-Party AI Terms

+ 5 more policies

Map & measure functions

  • AI System Context Record
  • Impact Assessment Template
  • Measurement Plan & Metrics
  • Bias Testing Procedure
  • Robustness & Security Testing
  • Explainability Review

+ 4 more policies

Manage function

  • Risk Treatment Register
  • AI Incident Response Plan
  • Continuous Monitoring Standard
  • Model Change & Release
  • Decommissioning Procedure
  • Re-Assessment Cadence

+ 4 more policies

Primary sources

Official NIST resources

This page is a summary. These are the documents it summarises — every one of them NIST’s own, so nothing here has to be taken on our word.

On this page. This is a summary of AI RMF 1.0 (NIST AI 100-1) and the Generative AI Profile (NIST AI 600-1). Both are free, both are linked above, and where this page and the framework disagree the framework wins.

The three-way map near the top is iDharma’s working crosswalk, not NIST’s published one. The category total of 19 and the generative-risk list are the figures we carry; they are the ones to confirm against the PDFs before quoting them onward.

Not legal advice. AI RMF is voluntary and carries no certification — we assess against it, and nobody certifies against it.

Reading last verified 11 August 2026 Something here out of date? Tell us →

Questions

Frequently asked questions

The ones that come up in every NIST AI RMF scoping call.

1 What it is
If it is voluntary and there is no certificate, what do we get out of it?

A structure the other two regimes accept as evidence, in a vocabulary your auditors, customers and board already recognise. The underlying work — knowing what your systems do, testing them, watching them, writing it down — is not optional under any regime that might reach you. Only the label is. Running it under AI RMF is what stops you doing that work three times and producing three incompatible reports.

Is NIST AI RMF mandatory?

No. It is voluntary and carries no penalties of its own. What makes it feel mandatory is where it gets referenced — federal contract terms, enterprise vendor questionnaires and insurer diligence increasingly name it, and at that point it is binding on you contractually rather than legally.

What are the four functions?

GOVERN, MAP, MEASURE and MANAGE. GOVERN is cross-cutting — it is the culture, policy and accountability the other three operate inside. MAP establishes context, MEASURE analyses and tracks, MANAGE acts on what MEASURE found. Between them they hold 19 categories.

Do we have to implement all four functions?

The framework does not require anything, so strictly no. In practice GOVERN and MAP are load-bearing: measuring a system whose purpose and context were never written down produces numbers nobody can act on, and MANAGE without MEASURE is a plan with no evidence under it.

What is the Generative AI Profile?

NIST AI 600-1, published July 2024. It is a cross-sectoral profile — an overlay on the same Core — covering risks that are unique to generative AI or made worse by it, including confabulation, harmful content, data leakage and content provenance. If you run generative systems, the base Core alone will not reach them.

2 How it relates to other frameworks
How does NIST AI RMF relate to the EU AI Act?

They answer different questions. The EU AI Act tells you what you must do if your AI touches the EU market; AI RMF tells you how to organise the work. The overlap in substance is large — risk management, data governance, testing, human oversight, monitoring — so a serious AI RMF programme covers much of the Act's Article 9–15 ground. It does not, on its own, make you compliant with it.

What is the difference between NIST AI RMF and ISO 42001?

Certifiability, mostly. ISO/IEC 42001 is a management-system standard you can be audited against and hold a certificate for. AI RMF has no certification scheme at all — nobody can certify you against it, and any vendor claiming to is selling something the framework does not define. AI RMF is better at structuring the risk work; ISO 42001 is better at proving to a third party that the system around it is managed.

Can we skip AI RMF and go straight to ISO 42001?

You can, and some do. But ISO 42001 asks you to have run a risk process and to be able to show the records it produced — and AI RMF is a well-specified, free, publicly readable description of that process. Skipping it usually means inventing a private one and then explaining it to a certification auditor, which is more work rather than less.

Can one assessment cover more than one framework?

Largely, yes, and it is usually the cheaper route. We tag each finding to its AI RMF category, its EU AI Act article and its ISO 42001 control, so one body of evidence answers three asks instead of three overlapping engagements producing three incompatible reports.

3 Running it
How long does implementation take?

The roadmap on this page runs 24 weeks for an organisation with a handful of systems and no existing AI governance. The weeks are elapsed position rather than effort, and the phases overlap. A single high-stakes system can be assessed in weeks; an enterprise-wide programme with dozens of models runs longer than 24.

How do we prioritise which systems to assess first?

By consequence, not by how interesting the model is. Systems that make or materially shape decisions about people — credit, hiring, access to services, clinical support — come first, then anything customer-facing that generates content, then internal tooling. MAP is what tells you which is which, which is why it runs before MEASURE.

What documentation does it actually require?

Nothing, strictly — it is voluntary. What it describes, and what anyone asking whether you follow it will look for, is: an AI inventory with context per system, a documented risk tolerance, named owners, a measurement plan with methods fixed in advance, results against the seven characteristics, treatment decisions, and monitoring with a cadence.

What does the Playbook add?

Suggested actions, references and documentation prompts, attached at the subcategory level rather than the category level. It is not normative and you do not have to follow it — but it is the fastest way to turn "we should cover MEASURE 2" into a list of things somebody can actually do this week. It is maintained in NIST's Trustworthy AI Resource Center rather than inside the framework PDF.

How does it apply to third-party and vendor AI?

Directly. GOVERN has a category for third-party risk and MANAGE has one for managing it, because buying a model in does not move the risk off you. In practice this is the weakest area in most programmes: the inventory stops at systems built in-house, and the ones bought in are the ones nobody has context for.

Can iDharma assess us against NIST AI RMF?

Yes — that is what this page is about. A verified auditor works through all four functions and the seven characteristics, produces a current profile and a target profile, and hands you the gap ranked by consequence. Scoping is agreed with you before anything is charged.

Get started

Ready to implement NIST AI RMF?

The framework is free and the PDFs are linked above — you can start without us. What we add is the independent read: all four functions, all 19 categories, the seven characteristics, and the GenAI Profile where it applies. Current profile against target, and the gap ranked by consequence — mapped to your EU AI Act and ISO 42001 obligations so it counts three times.

Scoped with you before you are charged. This page is guidance on how we scope an assessment, not legal advice.