NIST AI RMF Kit by Agent Trust Cloud Templates from $199

NIST AI RMF 1.0 explained: what the AI Risk Management Framework is and how it works

The NIST AI Risk Management Framework (AI RMF 1.0, published as NIST AI 100-1) is a free, voluntary US framework for managing the risks of designing, building, buying and using AI. It describes what trustworthy AI looks like and organises the work into four functions (Govern, Map, Measure, Manage), 19 categories and 72 subcategories. This page explains it in plain English, with the section of the framework each point comes from.

Want to know where you stand? The free maturity check rates your organisation on all 19 categories in a few minutes, in your browser.

The AI RMF at a glance

Full nameArtificial Intelligence Risk Management Framework (AI RMF 1.0)
PublicationNIST AI 100-1, released 26 January 2023
Published byThe National Institute of Standards and Technology (NIST), US Department of Commerce, as directed by the National Artificial Intelligence Initiative Act of 2020
StatusVoluntary. Current version 1.0; NIST says it is being revised (see AI RMF 2.0 status)
CostFree to download and use
StructurePart 1, foundational information; Part 2, the Core (4 functions, 19 categories, 72 subcategories) and profiles; four appendices
Companion resourcesThe AI RMF Playbook (suggested actions), a Roadmap, crosswalks to other standards, and profiles such as the Generative AI Profile (NIST AI 600-1, July 2024)

Source: NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023; NIST, AI Risk Management Framework (programme page); NIST AI 600-1, Generative Artificial Intelligence Profile, July 2024 (checked 1 October 2026).

Who it is for

NIST wrote the framework for any organisation that designs, develops, deploys or uses AI systems, of any size and in any sector. It is deliberately "non-sector-specific" and "use-case agnostic": the same outcomes apply to a bank's credit model, a hospital's triage tool and a software company's chatbot. The framework calls the people involved "AI actors" and expects them to come from across the AI lifecycle, from designers and data scientists to procurement, legal, operators, end users and the people affected by the system.

In practice three groups use it most: companies building AI products who need to show enterprise customers how they manage risk; organisations buying or deploying AI who need a structure for approving and monitoring it; and US public-sector bodies and their suppliers, for whom it is the reference NIST framework for AI risk.

It is not a law and not a certification. Nobody "passes" the AI RMF. What you can do is show, with evidence, how your practices meet its outcomes, and many security questionnaires and procurement reviews now ask exactly that.

Source: NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023 (checked 1 October 2026).

How the framework thinks about AI risk (Part 1)

Part 1 sets out the thinking behind the Core. Four ideas matter for day-to-day work:

Source: NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023 (checked 1 October 2026).

The seven characteristics of trustworthy AI

Section 3 of the framework defines what "trustworthy" means. NIST lists seven characteristics; your policies, tests and monitoring should address each one that applies to a system.

CharacteristicWhat it means in practiceWhere it is tested in the Core
Valid and reliableThe system does what it is meant to, accurately and consistently, in the conditions it is used in. NIST calls this a necessary condition for the other characteristics.MEASURE 2.5
SafeIt does not endanger human life, health, property or the environment, and fails safely when pushed beyond its limits.MEASURE 2.6
Secure and resilientIt withstands attacks and unexpected events, and recovers, with its confidentiality, integrity and availability protected.MEASURE 2.7
Accountable and transparentPeople can find out what the system is, how it was built and who is responsible for it. NIST says this relates to all the other characteristics.MEASURE 2.8
Explainable and interpretableUsers can understand how the system works and what an output means for them.MEASURE 2.9
Privacy-enhancedIt protects personal autonomy, identity and dignity, for example through data minimisation and privacy-enhancing techniques.MEASURE 2.10
Fair, with harmful bias managedHarmful bias of all three kinds NIST names (systemic, computational and statistical, and human-cognitive) is identified and managed.MEASURE 2.11

NIST stresses that the characteristics trade off against each other (privacy against accuracy, for instance, or interpretability against predictive power) and that addressing them one by one does not make a system trustworthy. Those trade-offs are decided in context and should be documented.

Source: NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023 (checked 1 October 2026).

The Core: four functions (Part 2)

The Core is the part most people mean when they say "the NIST AI RMF". It is a set of outcomes, grouped into four functions:

FunctionNIST's descriptionCategoriesSubcategoriesSuggested actions in the Playbook
GOVERNA culture of risk management is cultivated and present.619100
MAPContext is recognized and risks related to context are identified.518105
MEASUREIdentified risks are assessed, analyzed, or tracked.422179
MANAGERisks are prioritized and acted upon based on a projected impact.41375
Total1972459

GOVERN is organisation-wide and, in NIST's words, "a cross-cutting function to inform and be infused throughout the other three functions". MAP, MEASURE and MANAGE are applied to each AI system and at specific stages of its life. After GOVERN, NIST expects most users to start with MAP and continue to MEASURE or MANAGE, and the process should be iterative. Each function, its categories and what it produces are covered in detail in Govern, Map, Measure and Manage explained.

Two things the Core is not. It is not a checklist: NIST says the actions "do not constitute a checklist, nor are they necessarily an ordered set of steps". And it is not all-or-nothing: some organisations select the categories that fit; others apply all of them.

Source: NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023; NIST AIRC, AI RMF Core (Tables 1–4 of AI RMF 1.0) (checked 1 October 2026).

Profiles: tailoring the framework

Section 6 describes profiles, which are how you apply the framework to a particular setting. NIST names three kinds:

NIST does not prescribe a profile template, so any format that records each category, your current state, your target and the evidence will do.

Source: NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023; NIST AI 600-1, Generative Artificial Intelligence Profile, July 2024 (checked 1 October 2026).

Where to start: a first 90 days

  1. Weeks 1–2: inventory and owners. List every AI system you build, buy or use, including AI features inside SaaS tools, with a named owner for each (GOVERN 1.6, GOVERN 2.1).
  2. Weeks 2–4: Current Profile. Rate all 19 categories honestly with the maturity check. Note the evidence you already have.
  3. Weeks 3–6: policy and risk tolerance. Write or update an AI policy, the laws that apply (GOVERN 1.1) and how much risk you will accept (MAP 1.5).
  4. Weeks 5–10: map your highest-risk systems. For the two or three systems that matter most, document purpose, users, components and impacts (MAP 1 to MAP 5).
  5. Weeks 8–12: measure and decide. Pick metrics for the biggest risks, test, and record a go/no-go and treatment decision for each system (MEASURE 1, MANAGE 1).
  6. Every quarter: re-rate. The gap between your Current and Target Profile is your next plan. The Playbook guide lists NIST's suggested actions for each gap.

Templates to put AI RMF 1.0 into practice

The AI Governance Toolkit turns this into documents you can use: Starter ($199) has the AI policy, AI system inventory and risk register, and an AI risk assessment covering the AI RMF functions; Professional ($599) adds the NIST AI RMF mapping workbook for all 19 categories and the ISO/IEC 42001 gap assessment.

NIST AI RMF 1.0: questions

What is NIST AI RMF 1.0?

It is the Artificial Intelligence Risk Management Framework, published by NIST on 26 January 2023 as NIST AI 100-1. It is a voluntary framework for managing AI risks, organised into four functions (Govern, Map, Measure, Manage), 19 categories and 72 subcategories.

Is the NIST AI RMF mandatory?

No. NIST describes it as intended for voluntary use. It can become a requirement through a contract, a customer's procurement rules or a sector regulator that refers to it, so check what your customers and regulators ask for.

Can you be certified against the NIST AI RMF?

No. The AI RMF is not a certifiable standard and NIST does not certify organisations against it. If you need a certificate, ISO/IEC 42001 is the certifiable AI management system standard; the two overlap, and our Govern, Map, Measure and Manage page shows where by clause number.

What are the seven characteristics of trustworthy AI in the AI RMF?

Valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair, with harmful bias managed. NIST treats valid and reliable as a necessary condition for the others, and accountable and transparent as relating to all of them.

Is there an AI RMF 2.0?

Not yet. NIST says AI RMF 1.0 is being revised as part of the White House AI Action Plan, but as of 1 October 2026 it has not published a draft, a version number or a date. Our AI RMF 2.0 page tracks what NIST has said.