Skip to main content
v2026.11,610 entries · CC-BY 4.0
Dictionary termTrack CStablev2026.2

NIST AI RMF (Risk Management Framework)

The US National Institute of Standards and Technology's voluntary framework for managing risks associated with AI systems across the AI lifecycle, structured around the functions Govern, Map, Measure, and Manage.

ByCASRAI Editorial Board
· Last updated 22 Aug 2026

Ask about NIST AI RMF (Risk Management Framework)

Answers are drawn from this dictionary entry and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Examples

Worked examples

  • Is an instance

    A US federal contractor mapping its AI portfolio to the AI RMF Map function.

  • Is an instance

    An enterprise risk register structured around the AI RMF four functions.

Counter-examples

Looks similar, but isn't

  • Not an instance

    A single technical evaluation suite.

  • Not an instance

    An ISO 27001 information-security risk register.

Editorial commentary

The NIST AI Risk Management Framework (AI RMF 1.0, NIST AI 100-1, released January 2023) is a voluntary, process-oriented framework for identifying, assessing, and managing risks across an AI system’s lifecycle. It is organised around four core functions — Govern (culture and processes for managing AI risk across the organisation), Map (context and risk identification for a specific system), Measure (assessing and tracking identified risks, including through testing and metrics), and Manage (allocating resources to treat mapped and measured risks) — with a companion Playbook of concrete suggested actions published alongside it. A Generative AI Profile (NIST AI 600-1, 2024) extends the same four-function structure with risks specific to generative and foundation models (e.g. confabulation, data privacy, harmful bias, intellectual-property exposure).

Regulatory status, corrected here because it changes the framework’s practical weight: the RMF has always been voluntary — NIST has no statutory authority to mandate it — but Executive Order 14110 (October 2023) gave it real force by directing federal agencies to use RMF-aligned practices and requiring developers of the largest models to report certain safety test results, tied to a 10^26-FLOP compute-reporting threshold. EO 14110 was revoked on 20 January 2025 (EO 14148) and replaced 23 January 2025 by EO 14179, ‘Removing Barriers to American Leadership in Artificial Intelligence,’ which carries no equivalent reporting mandate. As of this writing, the AI RMF is voluntary guidance with no active US executive-order mandate behind it — any source stating that federal AI reporting obligations currently flow from EO 14110 is out of date.

How it relates to other frameworks

NIST has published a crosswalk mapping the RMF’s four functions to ISO/IEC 42001, the certifiable AI management-system standard published the same year (2023); together these are among the concrete mechanisms that make up the broader practice of AI assurance covered on this site as its own entry — the RMF is guidance without a certification mechanism, ISO/IEC 42001 is a management-system standard an organisation can be certified against. Neither framework itself specifies numeric compute or capability thresholds; the EU AI Act’s Article 51 systemic-risk presumption (10^25 FLOPs of cumulative training compute) is a separate, still-active regulatory line with no current US equivalent.

References

  • NIST AI 100-1, ‘Artificial Intelligence Risk Management Framework (AI RMF 1.0)’ (2023)
  • NIST AI 600-1, Generative AI Profile (2024)
  • Executive Order 14179 (23 January 2025)

Also known as

AI RMF · NIST AI Risk Management Framework

Machine-readable encodings

Use in your systems

JATS XML <role> element
xml
<role vocab="credit"
      vocab-identifier="https://casrai.org/dictionary/"
      vocab-term="NIST AI RMF (Risk Management Framework)"
      vocab-term-identifier="https://casrai.org/dictionary/term/nist-ai-rmf-risk-management-framework" />
Schema.org DefinedTerm (JSON-LD)
json
{
  "@context": "https://schema.org",
  "@type": "DefinedTerm",
  "@id": "https://casrai.org/dictionary/term/nist-ai-rmf-risk-management-framework",
  "name": "NIST AI RMF (Risk Management Framework)",
  "identifier": "https://casrai.org/dictionary/term/nist-ai-rmf-risk-management-framework",
  "description": "The US National Institute of Standards and Technology's voluntary framework for managing risks associated with AI systems across the AI lifecycle, structured around the functions Govern, Map, Measure, and Manage.",
  "inDefinedTermSet": "https://casrai.org/dictionary/domain/ai-ml-research-outputs#set",
  "url": "https://casrai.org/dictionary/term/nist-ai-rmf-risk-management-framework",
  "sameAs": [
    "AI RMF",
    "NIST AI Risk Management Framework"
  ],
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "publisher": {
    "@id": "https://casrai.org/#organization"
  },
  "dateModified": "2026-08-22T15:54:51",
  "inLanguage": "en"
}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →