Written and maintained by CASRAI Editorial Board
Last updated
NIST’s AI Risk Management Framework (AI RMF 1.0, document NIST AI 100-1, released January 26, 2023) organizes AI risk management into four functions: Govern, Map, Measure, and Manage. This guide walks through what each function actually covers and how to sequence them when you are building a framework from the ground up.
If you already have (or are about to write) the organizational layer — a governance council, risk tiers, and escalation paths — see our AI governance framework template, which covers that structure in detail but does not walk through GOVERN/MAP/MEASURE/MANAGE as a methodology. This guide is the complementary piece: the NIST functions as a build sequence, not an org chart.
What the AI RMF is, and isn’t
The AI RMF is voluntary and not sector-specific. NIST designed it to be adaptable across industries and risk tolerances rather than prescribing fixed controls. Two companion documents extend it:
- The NIST AI RMF Playbook, published alongside the framework with suggested actions for each subcategory, available through NIST’s AI Resource Center.
- The Generative AI Profile (NIST AI 600-1, released July 26, 2024), which identifies risks specific to generative AI and proposes actions for managing them on top of the base framework.
Neither the base framework nor the Generative AI Profile is a certification scheme or a checklist you complete once. Both are meant to be applied on an ongoing basis, per AI system, across its lifecycle.
The four functions at a glance
- Govern — the cross-cutting function. Policies, accountability structures, culture, and third-party oversight that apply across every AI system, not to any one of them.
- Map — establishes context for a specific AI system: its purpose, who’s affected, what category of system it is, and what risk tolerance applies.
- Measure — evaluates that system against trustworthiness characteristics (safety, security, fairness, privacy, and more) using defined methods and metrics.
- Manage — takes Map and Measure’s output and prioritizes, treats, and monitors the risks that were identified.
Govern runs continuously and organization-wide. Map, Measure, and Manage are typically applied per AI system or use case, and Govern is what makes that repeatable across systems.
Govern: build the cross-cutting foundation
Govern has six categories:
- Govern 1 — policies, processes, and practices for AI risk management are documented and implemented, including legal/regulatory requirements, a system inventory, and decommissioning procedures.
- Govern 2 — accountability structures: roles and responsibilities are documented (Govern 2.1), personnel are trained (2.2), and executive leadership takes responsibility for risk decisions (2.3).
- Govern 3 — diversity, equity, inclusion, and accessibility inform decision-making and human-AI oversight configurations.
- Govern 4 — organizational culture: safety-first design practices, risk communication, and mechanisms for testing and incident sharing.
- Govern 5 — engagement with external actors: processes to collect and incorporate outside feedback on system impacts.
- Govern 6 — third-party and supply chain risk: policies for vendor AI, data, and contingency planning when third-party systems fail.
This is the layer our governance framework template covers in operational detail — who sits on the council, how risk tiers map to review depth, and what triggers an escalation. Use that guide to design the structures; use Govern 1–6 above as the checklist for what those structures need to cover.
Map: establish context and categorize the system
Map has five categories, applied per AI system:
- Map 1 — context: intended purpose, deployment setting, user expectations, and organizational risk tolerance are documented before the system is built or procured.
- Map 2 — categorization: what kind of system it is (classifier, generative model, etc.), its known limits, and where human oversight applies.
- Map 3 — capabilities and benchmarks: expected benefits and costs are examined against the system’s actual scope and the operators’ proficiency.
- Map 4 — component-level risk mapping, including third-party software and data.
- Map 5 — impact characterization: likely effects on individuals, groups, and organizations, informed by ongoing stakeholder feedback.
Map is where a system-level risk register starts to fill in. If you’re tracking these outputs formally, our AI risk assessment framework and risk register guide covers how to structure that register in practice.
Measure: evaluate the system against trustworthiness criteria
Measure has four categories. Measure 2 is the largest — NIST lists thirteen separate evaluation areas, including test/evaluation documentation, human-subject evaluation, production monitoring, validity and reliability, safety, security and resilience, transparency, explainability, privacy, fairness and bias, and environmental impact.
- Measure 1 — select methods and metrics, starting with the most significant risks; document anything that can’t be measured.
- Measure 2 — evaluate the system against each trustworthiness characteristic (the thirteen areas above).
- Measure 3 — track identified risks over time, including a feedback channel for end users and affected communities to report problems.
- Measure 4 — assess whether the measurement approach itself is working, and adjust it based on domain-expert input and observed performance.
Measure produces the evidence Manage acts on. A system that hasn’t been measured against these criteria doesn’t have risk data to manage — it has assumptions.
Manage: prioritize, treat, and monitor
- Manage 1 — using Map and Measure’s output, decide whether the system should proceed, and prioritize risk treatment by impact and likelihood.
- Manage 2 — plan and implement strategies to maximize benefit and minimize harm, including a documented path to disengage or deactivate an underperforming system.
- Manage 3 — manage third-party AI risk on an ongoing basis, including monitoring pre-trained models you didn’t build.
- Manage 4 — document response, recovery, and communication plans, including post-deployment monitoring and incident tracking.
Manage 4’s incident tracking and response plans are the operational counterpart to the escalation paths described in the governance framework template — Manage defines what happens to a specific system’s risk; the escalation path defines who in the organization gets told and when.
Sequencing the four functions when you build from scratch
The functions aren’t a strict waterfall, but a practical build order looks like this:
- Stand up Govern first, as an ongoing structure rather than a one-time task — you need accountability and an inventory mechanism before you have anything consistent to Map.
- Run Map at intake, for every new AI system or use case, before it’s built, procured, or significantly changed.
- Run Measure against the criteria Map identified, both before deployment and on an ongoing basis once the system is live.
- Run Manage to prioritize and treat what Measure found, and to define incident response and decommissioning paths.
- Feed results back into Govern — Measure 4 and Govern 1.5 both call for periodic review, which is how the framework catches drift instead of being a one-time exercise.
In practice, Map, Measure, and Manage run per system while Govern runs continuously underneath all of them.
Frequently asked questions
Is the NIST AI RMF mandatory?
No. It’s voluntary and not sector-specific. Some sector or state requirements reference it or require similar practices, but the framework itself carries no compliance obligation on its own.
How is Govern different from Map, Measure, and Manage?
Govern is cross-cutting: policies, accountability, culture, and third-party oversight that apply across the organization and every AI system in it. Map, Measure, and Manage are typically run per AI system, at intake and throughout its lifecycle.
Do we need software to implement this?
No. The four functions are a methodology, not a tool requirement. Many organizations start with documents and a spreadsheet-based risk register and add tooling later if the volume of systems justifies it.
Where does generative AI fit into this?
NIST published a separate Generative AI Profile (NIST AI 600-1, July 2024) that applies on top of the base framework, identifying risks specific to generative AI and adding recommended actions within the same Govern/Map/Measure/Manage structure.
What’s the relationship between this guide and the governance framework template?
They cover different layers. The governance framework template covers the organizational structure — who decides, what triggers review, how risk tiers work. This guide covers the NIST methodology those decisions should be applied through. Use both together: the template for structure, this guide for what to run through that structure.
Sources
- NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1, released January 26, 2023 — nist.gov/itl/ai-risk-management-framework
- NIST AI Resource Center, AI RMF Core (function/category/subcategory detail) — airc.nist.gov/airmf-resources/airmf/5-sec-core
- NIST, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1, released July 26, 2024







