Artificial Intelligence Risk Management Framework (AI RMF 1.0)
The NIST AI RMF provides voluntary guidance to help organizations that design, develop, deploy, or use AI systems manage risks to individuals, organizations, and society. It is intended for use across sectors, use cases, and organization sizes, and is not tied to any specific technology. The framework organizes AI risk management around four functions, Govern, Map, Measure, and Manage, oriented toward seven characteristics of trustworthy AI: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed.
The NIST AI Risk Management Framework (AI RMF) is voluntary U.S. guidance, published January 2023, that helps organizations manage AI risk through four functions: Govern, Map, Measure, and Manage. It has no certification mechanism and is not legally binding, but is widely referenced in U.S. AI governance programs and federal policy.
- Issuing body
- National Institute of Standards and Technology (NIST), U.S. Department of Commerce
- Official reference
- nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
What it covers
- Govern function: cultivates an organization-wide culture of AI risk management, including policies, processes, and accountability structures
- Map function: establishes context to identify AI risks tied to a specific system's intended use, requirements, and potential impacts
- Measure function: uses quantitative, qualitative, or mixed methods to analyze, assess, benchmark, and monitor AI risk and trustworthiness
- Manage function: allocates resources to treat mapped and measured risks, including response, recovery, and communication planning
- Defines seven characteristics of trustworthy AI: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed
- Accompanied by a non-binding NIST AI RMF Playbook that suggests actions mapped to each of the four functions
- Extended through use-case-specific profiles, including NIST AI 600-1, the Generative AI Profile published July 26, 2024
Adoption status
Published January 26, 2023 by NIST, a non-regulatory U.S. federal agency; adoption is voluntary and the framework carries no legal force on its own, though it is widely referenced in U.S. federal AI policy and by companies building AI governance programs. Use of the framework is informational only and does not constitute or guarantee compliance with any law or regulation.
Reference only. This page explains what NIST AI RMF covers; it is not a claim that Model Governance Index or any listed vendor satisfies it. Verify alignment directly against the issuing body's own current text before relying on it.
Sources. source 1 · source 2 · source 3. Data as of 2026-07-13. See methodology.