Glossary · United States
NIST AI Risk Management Framework
Also known as: AI RMF, NIST AI RMF, AI RMF 1.0, NIST AI 600-1
The NIST AI Risk Management Framework (AI RMF 1.0, NIST AI 100-1) is a voluntary framework published by the US National Institute of Standards and Technology in January 2023 to help organizations manage the risks of AI systems throughout their lifecycle. It is organized in four functions — Govern, Map, Measure and Manage — and describes the characteristics of trustworthy AI.
- AI regulation
- USA
In one sentence
The NIST AI RMF is the voluntary US framework for managing AI risk, organized in four functions: Govern, Map, Measure and Manage.
Example
A US insurer documents its claims-triage model with a risk register organized by the Map, Measure and Manage functions and reports it to its board under the Govern function.
How it applies
- Structure: Four functions — Govern (culture, policies, accountability), Map (context and risks of a system), Measure (analysis, testing and tracking of risks) and Manage (prioritizing and treating risks). Seven characteristics of trustworthy AI: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair, with harmful bias managed.
- Profiles: The companion Playbook suggests actions for each function. The Generative AI Profile (NIST AI 600-1, July 2024) applies the framework to risks that generative AI creates or intensifies, such as confabulation and information integrity.
- Revision: America's AI Action Plan of July 2025 directed NIST to revise the framework, among other things to remove references to misinformation, diversity, equity and inclusion, and climate change. As of September 2026, no revised version has been published.
- Technical documentation: Although voluntary, the AI RMF is widely used as a documentation structure: risk registers, model cards and system documentation organized by the four functions. Texas' TRAIGA recognizes substantial compliance with a framework such as the AI RMF as a defense.
NIST AI RMF vs. the EU AI Act
The AI RMF tells organizations how to manage AI risk; the EU AI Act tells them which outcomes they must achieve, and enforces them. Both are compatible: the Map, Measure and Manage functions support the AI Act's risk management and technical documentation — but following the AI RMF alone does not demonstrate conformity with the AI Act.