The NIST AI RMF framework: Govern, Map, Measure and Manage
The core of the NIST AI Risk Management Framework is four functions. GOVERN sets up the organisation; MAP, MEASURE and MANAGE are run for each AI system. Together they hold 19 categories and 72 subcategories. Below: what each function is for, what it should produce, who usually owns it, how the four fit together, and where each category lands in ISO/IEC 42001.
See how your organisation scores on each function: the free maturity check rates all 19 categories and averages them by function.
The four functions in one table
| Function | NIST's description | Categories | Subcategories | Suggested actions in the Playbook |
|---|---|---|---|---|
| GOVERN | A culture of risk management is cultivated and present. | 6 | 19 | 100 |
| MAP | Context is recognized and risks related to context are identified. | 5 | 18 | 105 |
| MEASURE | Identified risks are assessed, analyzed, or tracked. | 4 | 22 | 179 |
| MANAGE | Risks are prioritized and acted upon based on a projected impact. | 4 | 13 | 75 |
| Total | 19 | 72 | 459 |
Counts are from AI RMF 1.0 (categories and subcategories) and the current NIST AI RMF Playbook (suggested actions). The Playbook guide lists every subcategory with its first suggested actions.
Source: NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023; NIST AIRC, AI RMF Core (Tables 1–4 of AI RMF 1.0); NIST AI RMF Playbook (AIRC) (checked 1 October 2026).
How the functions fit together
The four functions are not phases you finish one after another. NIST describes them this way:
- GOVERN runs through everything. It is designed to be "a cross-cutting function to inform and be infused throughout the other three functions". Policies, roles, risk tolerance and culture set in GOVERN are what MAP, MEASURE and MANAGE apply.
- MAP comes first for each system. After the GOVERN outcomes are in place, NIST says most users would start with MAP and continue to MEASURE or MANAGE. MAP outcomes "are the basis for the MEASURE and MANAGE functions".
- MEASURE feeds MANAGE. MEASURE uses what MAP identified and "informs the MANAGE function"; its results are used in MANAGE for monitoring and response.
- It loops. NIST says the process should be iterative, "with cross-referencing between functions as necessary", and that functions may be performed in any order once governance is in place. A new incident in MANAGE sends you back to MAP; a new law sends you back to GOVERN.
Source: NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023 (checked 1 October 2026).
| Moment | Function most in play | Typical question |
|---|---|---|
| Before any AI project | GOVERN | Do we have a policy, an inventory, owners and a risk tolerance? |
| Idea or purchase request | MAP | What is it for, who does it affect, what is it built from, should we use AI at all? |
| Build or vendor evaluation | MEASURE | Does it work, is it safe, secure, fair and explainable enough, by our metrics? |
| Go-live decision | MANAGE | Do we proceed, with which treatments, and who can switch it off? |
| In production | MEASURE and MANAGE | Is it drifting, what are users reporting, how do we respond to incidents? |
| Retirement | GOVERN and MANAGE | How do we decommission it without leaving risk behind? |
GOVERN: a culture of risk management
NIST's one-line description: “A culture of risk management is cultivated and present.”
Sets the rules, roles and culture that the other three functions run inside. It applies to the whole organisation rather than to one AI system, and NIST describes it as cross-cutting: it is never finished, and parts of it (compliance, evaluation) show up inside Map, Measure and Manage.
What it produces
- AI policy and risk-management procedure, approved by leadership
- AI system inventory with owners
- Named roles, training records and a review cycle
- Third-party AI rules in procurement and contracts
Usually owned by: Leadership, risk/compliance, legal and HR, with the AI governance lead coordinating.
GOVERN categories
| Category | Outcome (AI RMF 1.0) | Subcategories |
|---|---|---|
| GOVERN 1 | Policies, processes, procedures, and practices across the organization related to the mapping, measuring, and managing of AI risks are in place, transparent, and implemented effectively. | 1.1, 1.2, 1.3, 1.4, 1.5, 1.6, 1.7 |
| GOVERN 2 | Accountability structures are in place so that the appropriate teams and individuals are empowered, responsible, and trained for mapping, measuring, and managing AI risks. | 2.1, 2.2, 2.3 |
| GOVERN 3 | Workforce diversity, equity, inclusion, and accessibility processes are prioritized in the mapping, measuring, and managing of AI risks throughout the lifecycle. | 3.1, 3.2 |
| GOVERN 4 | Organizational teams are committed to a culture that considers and communicates AI risk. | 4.1, 4.2, 4.3 |
| GOVERN 5 | Processes are in place for robust engagement with relevant AI actors. | 5.1, 5.2 |
| GOVERN 6 | Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues. | 6.1, 6.2 |
MAP: know the context before you judge the risk
NIST's one-line description: “Context is recognized and risks related to context are identified.”
Runs per AI system. It establishes what the system is for, who it affects, what it is built from and what could go wrong. NIST says Map outcomes are the basis for Measure and Manage: without context, risks cannot be measured or treated sensibly.
What it produces
- Use-case record: purpose, users, setting, laws, limits
- System categorisation and component list (including third-party models and data)
- Benefit and cost analysis against risk tolerance
- Impact assessment covering people and groups affected
Usually owned by: The product or system owner, with domain experts, legal and people outside the build team.
MAP categories
| Category | Outcome (AI RMF 1.0) | Subcategories |
|---|---|---|
| MAP 1 | Context is established and understood. | 1.1, 1.2, 1.3, 1.4, 1.5, 1.6 |
| MAP 2 | Categorization of the AI system is performed. | 2.1, 2.2, 2.3 |
| MAP 3 | AI capabilities, targeted usage, goals, and expected benefits and costs compared with appropriate benchmarks are understood. | 3.1, 3.2, 3.3, 3.4, 3.5 |
| MAP 4 | Risks and benefits are mapped for all components of the AI system including third-party software and data. | 4.1, 4.2 |
| MAP 5 | Impacts to individuals, groups, communities, organizations, and society are characterized. | 5.1, 5.2 |
MEASURE: evidence, not assurances
NIST's one-line description: “Identified risks are assessed, analyzed, or tracked.”
Turns the mapped risks into evidence: tests, metrics and monitoring for each trustworthy characteristic, before deployment and while the system runs. Where characteristics trade off against each other, measurement gives a traceable basis for the decision.
What it produces
- Metric plan for the most significant mapped risks
- Test and evaluation (TEVV) results with test sets and tools documented
- Production monitoring and a way to track risks you can't yet measure
- User and community feedback channels feeding the metrics
Usually owned by: Engineering and data science for the tests, with independent reviewers who did not build the system.
MEASURE categories
| Category | Outcome (AI RMF 1.0) | Subcategories |
|---|---|---|
| MEASURE 1 | Appropriate methods and metrics are identified and applied. | 1.1, 1.2, 1.3 |
| MEASURE 2 | AI systems are evaluated for trustworthy characteristics. | 2.1, 2.2, 2.3, 2.4, 2.5, 2.6, 2.7, 2.8, 2.9, 2.10, 2.11, 2.12, 2.13 |
| MEASURE 3 | Mechanisms for tracking identified AI risks over time are in place. | 3.1, 3.2, 3.3 |
| MEASURE 4 | Feedback about efficacy of measurement is gathered and assessed. | 4.1, 4.2, 4.3 |
MANAGE: decide, treat, monitor, respond
NIST's one-line description: “Risks are prioritized and acted upon based on a projected impact.”
Allocates resources to the mapped and measured risks: decide whether to proceed, treat the risks in priority order, plan for incidents and recovery, watch third-party components, and keep improving after launch.
What it produces
- Go / no-go decision and a prioritised risk treatment plan
- Residual-risk statement for downstream users
- Override, disengage and decommission procedures
- Post-deployment monitoring, incident response and communication plans
Usually owned by: The system owner and the risk owner, with operations and incident response.
MANAGE categories
| Category | Outcome (AI RMF 1.0) | Subcategories |
|---|---|---|
| MANAGE 1 | AI risks based on assessments and other analytical output from the MAP and MEASURE functions are prioritized, responded to, and managed. | 1.1, 1.2, 1.3, 1.4 |
| MANAGE 2 | Strategies to maximize AI benefits and minimize negative impacts are planned, prepared, implemented, documented, and informed by input from relevant AI actors. | 2.1, 2.2, 2.3, 2.4 |
| MANAGE 3 | AI risks and benefits from third-party entities are managed. | 3.1, 3.2 |
| MANAGE 4 | Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored regularly. | 4.1, 4.2, 4.3 |
Source: NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023; NIST AIRC, AI RMF Core (Tables 1–4 of AI RMF 1.0) (checked 1 October 2026).
How the categories line up with ISO/IEC 42001
ISO/IEC 42001 is the international, certifiable standard for an AI management system. It covers much of the same ground as the AI RMF but is organised differently: management-system clauses 4 to 10 (context, leadership, planning, support, operation, performance evaluation, improvement) plus a set of AI controls in Annex A, with implementation guidance under the same numbers in Annex B. If you are working towards ISO/IEC 42001 certification, evidence you build for the AI RMF can usually be reused.
The table shows, for each AI RMF category, the ISO/IEC 42001 clauses and control areas that cover similar topics. It is a summary by topic of the NIST AI RMF to ISO/IEC 42001 crosswalk that NIST lists on its AI Resource Center (provided by Microsoft and prepared against the final draft of the standard). NIST notes that listing a crosswalk does not imply NIST endorsement of the resource it maps to, nor that either document fully covers the other. We give clause numbers only and do not reproduce ISO text; for the requirements themselves, use the standard.
| AI RMF category | ISO/IEC 42001 clauses (4–10) | Annex A/B control areas |
|---|---|---|
| GOVERN 1 | 4.1, 4.4, 5.2, 6.1, 6.2, 8.2, 8.3, 8.4 | A.2, A.4, A.6 |
| GOVERN 2 | 5.1, 5.2, 5.3, 7.1, 7.2, 7.3, 7.4, 9.1, 9.3 | A.3 |
| GOVERN 3 | 7.2 | A.3, A.4, A.5, A.6, A.9 |
| GOVERN 4 | 6.1.4, 7.4 | A.5, A.6, A.8, A.9, A.10 |
| GOVERN 5 | — | A.5, A.6, A.8, A.10 |
| GOVERN 6 | — | A.10 |
| MAP 1 | 4.1, 5.1, 5.2, 6.1.1, 6.1.4, 6.2, 7.2, 7.3, 7.4, 7.5 | A.4, A.5, A.6, A.9 |
| MAP 2 | — | A.4, A.6, A.7, A.8, A.9 |
| MAP 3 | 4.3, 7.2, 8.2, 8.3, 8.4 | A.4, A.5, A.6, A.8 |
| MAP 4 | 4.1 | A.2, A.6, A.8, A.9, A.10 |
| MAP 5 | 6.1.2 | A.5, A.6, A.8 |
| MEASURE 1 | 6.1.1, 6.1.2, 9.2 | A.5, A.6 |
| MEASURE 2 | 8.2, 9.1 | A.2, A.3, A.4, A.5, A.6, A.7, A.8, A.9 |
| MEASURE 3 | 4.4, 8.2, 8.4, 10.1 | A.6, A.8 |
| MEASURE 4 | 9.1, 9.2, 9.3 | A.5, A.6, A.8 |
| MANAGE 1 | 6.1.1, 6.1.2, 6.1.3, 6.1.4, 9.3 | A.5, A.6, A.9 |
| MANAGE 2 | 6.1.1, 6.1.2, 6.1.3, 7.1, 10.1, 10.2 | A.3, A.4, A.6, A.7, A.8, A.9 |
| MANAGE 3 | — | A.4, A.6, A.10 |
| MANAGE 4 | 9.2, 9.3 | A.6, A.8, A.10 |
Clauses, in our words: 4: context, scope and the management system itself; 5: leadership, AI policy and roles; 6: planning: risk assessment, risk treatment, impact assessment, objectives; 7: support: resources, competence, awareness, communication, documents; 8: operation: carrying out risk assessment, treatment and impact assessment; 9: performance evaluation: monitoring, internal audit, management review; 10: improvement and corrective action.
Control areas, in our words: A.2: AI policy; A.3: roles and raising concerns; A.4: resources: data, tools, computing, people; A.5: impact assessment; A.6: design, development, testing, deployment and monitoring; A.7: data quality and provenance; A.8: information for users and others, incident communication; A.9: responsible use; A.10: suppliers and customers.
Source: NIST AIRC, Crosswalk Documents; NIST AI RMF to ISO/IEC 42001 Crosswalk (provider: Microsoft; listed by NIST) (checked 1 October 2026).
Where a row shows "—" in the clauses column, the crosswalk maps that category only to Annex A/B controls. Four patterns stand out: GOVERN 1 and 2 line up with leadership, policy and support (clauses 5 and 7) and with the risk process itself (6.1, 8.2, 8.3); MAP and the impact parts of MEASURE line up with impact assessment (6.1.4, 8.4 and area A.5); MEASURE's testing and monitoring sit in the system life-cycle controls (A.6); and the third-party categories (GOVERN 6, MANAGE 3) map to supplier and customer controls (A.10).
Mapping workbook for all four functions
The Professional AI Governance Toolkit ($599) has the NIST AI RMF mapping workbook: all 19 categories with maturity scoring, evidence, owners and next steps, an indicative ISO/IEC 42001 crosswalk, and the ISO/IEC 42001 gap assessment. Starter ($199) has the AI policy, inventory, risk register and risk assessment.
Govern, Map, Measure, Manage: questions
What are the four functions of the NIST AI RMF?
GOVERN (a culture of risk management is cultivated and present), MAP (context is recognized and risks related to context are identified), MEASURE (identified risks are assessed, analyzed, or tracked) and MANAGE (risks are prioritized and acted upon based on a projected impact).
Do you have to do the functions in order?
No. NIST says that once governance is in place the functions may be performed in any order, and the process should be iterative. In practice most organisations set up GOVERN first and then run MAP, MEASURE and MANAGE for each AI system.
How many categories and subcategories are there?
19 categories and 72 subcategories: GOVERN has 6 categories and 19 subcategories; MAP has 5 categories and 18 subcategories; MEASURE has 4 categories and 22 subcategories; MANAGE has 4 categories and 13 subcategories.
Is the NIST AI RMF the same as ISO/IEC 42001?
No. ISO/IEC 42001 is a certifiable management-system standard; the NIST AI RMF is a voluntary framework that cannot be certified. They overlap heavily, and the crosswalk table on this page shows where each AI RMF category lands in ISO/IEC 42001 by clause number.
Which function should a small company start with?
GOVERN: an AI policy, an inventory of AI systems with owners, and a written risk tolerance. Then MAP your one or two highest-risk systems. Most of the rest builds on those documents.