NIST AI RMF Kit by Agent Trust Cloud Templates from $199

The NIST AI RMF framework: Govern, Map, Measure and Manage

The core of the NIST AI Risk Management Framework is four functions. GOVERN sets up the organisation; MAP, MEASURE and MANAGE are run for each AI system. Together they hold 19 categories and 72 subcategories. Below: what each function is for, what it should produce, who usually owns it, how the four fit together, and where each category lands in ISO/IEC 42001.

See how your organisation scores on each function: the free maturity check rates all 19 categories and averages them by function.

The four functions in one table

FunctionNIST's descriptionCategoriesSubcategoriesSuggested actions in the Playbook
GOVERNA culture of risk management is cultivated and present.619100
MAPContext is recognized and risks related to context are identified.518105
MEASUREIdentified risks are assessed, analyzed, or tracked.422179
MANAGERisks are prioritized and acted upon based on a projected impact.41375
Total1972459

Counts are from AI RMF 1.0 (categories and subcategories) and the current NIST AI RMF Playbook (suggested actions). The Playbook guide lists every subcategory with its first suggested actions.

Source: NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023; NIST AIRC, AI RMF Core (Tables 1–4 of AI RMF 1.0); NIST AI RMF Playbook (AIRC) (checked 1 October 2026).

How the functions fit together

The four functions are not phases you finish one after another. NIST describes them this way:

Source: NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023 (checked 1 October 2026).

MomentFunction most in playTypical question
Before any AI projectGOVERNDo we have a policy, an inventory, owners and a risk tolerance?
Idea or purchase requestMAPWhat is it for, who does it affect, what is it built from, should we use AI at all?
Build or vendor evaluationMEASUREDoes it work, is it safe, secure, fair and explainable enough, by our metrics?
Go-live decisionMANAGEDo we proceed, with which treatments, and who can switch it off?
In productionMEASURE and MANAGEIs it drifting, what are users reporting, how do we respond to incidents?
RetirementGOVERN and MANAGEHow do we decommission it without leaving risk behind?

GOVERN: a culture of risk management

NIST's one-line description: “A culture of risk management is cultivated and present.”

Sets the rules, roles and culture that the other three functions run inside. It applies to the whole organisation rather than to one AI system, and NIST describes it as cross-cutting: it is never finished, and parts of it (compliance, evaluation) show up inside Map, Measure and Manage.

What it produces

Usually owned by: Leadership, risk/compliance, legal and HR, with the AI governance lead coordinating.

GOVERN categories

CategoryOutcome (AI RMF 1.0)Subcategories
GOVERN 1Policies, processes, procedures, and practices across the organization related to the mapping, measuring, and managing of AI risks are in place, transparent, and implemented effectively.1.1, 1.2, 1.3, 1.4, 1.5, 1.6, 1.7
GOVERN 2Accountability structures are in place so that the appropriate teams and individuals are empowered, responsible, and trained for mapping, measuring, and managing AI risks.2.1, 2.2, 2.3
GOVERN 3Workforce diversity, equity, inclusion, and accessibility processes are prioritized in the mapping, measuring, and managing of AI risks throughout the lifecycle.3.1, 3.2
GOVERN 4Organizational teams are committed to a culture that considers and communicates AI risk.4.1, 4.2, 4.3
GOVERN 5Processes are in place for robust engagement with relevant AI actors.5.1, 5.2
GOVERN 6Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues.6.1, 6.2

MAP: know the context before you judge the risk

NIST's one-line description: “Context is recognized and risks related to context are identified.”

Runs per AI system. It establishes what the system is for, who it affects, what it is built from and what could go wrong. NIST says Map outcomes are the basis for Measure and Manage: without context, risks cannot be measured or treated sensibly.

What it produces

Usually owned by: The product or system owner, with domain experts, legal and people outside the build team.

MAP categories

CategoryOutcome (AI RMF 1.0)Subcategories
MAP 1Context is established and understood.1.1, 1.2, 1.3, 1.4, 1.5, 1.6
MAP 2Categorization of the AI system is performed.2.1, 2.2, 2.3
MAP 3AI capabilities, targeted usage, goals, and expected benefits and costs compared with appropriate benchmarks are understood.3.1, 3.2, 3.3, 3.4, 3.5
MAP 4Risks and benefits are mapped for all components of the AI system including third-party software and data.4.1, 4.2
MAP 5Impacts to individuals, groups, communities, organizations, and society are characterized.5.1, 5.2

MEASURE: evidence, not assurances

NIST's one-line description: “Identified risks are assessed, analyzed, or tracked.”

Turns the mapped risks into evidence: tests, metrics and monitoring for each trustworthy characteristic, before deployment and while the system runs. Where characteristics trade off against each other, measurement gives a traceable basis for the decision.

What it produces

Usually owned by: Engineering and data science for the tests, with independent reviewers who did not build the system.

MEASURE categories

CategoryOutcome (AI RMF 1.0)Subcategories
MEASURE 1Appropriate methods and metrics are identified and applied.1.1, 1.2, 1.3
MEASURE 2AI systems are evaluated for trustworthy characteristics.2.1, 2.2, 2.3, 2.4, 2.5, 2.6, 2.7, 2.8, 2.9, 2.10, 2.11, 2.12, 2.13
MEASURE 3Mechanisms for tracking identified AI risks over time are in place.3.1, 3.2, 3.3
MEASURE 4Feedback about efficacy of measurement is gathered and assessed.4.1, 4.2, 4.3

MANAGE: decide, treat, monitor, respond

NIST's one-line description: “Risks are prioritized and acted upon based on a projected impact.”

Allocates resources to the mapped and measured risks: decide whether to proceed, treat the risks in priority order, plan for incidents and recovery, watch third-party components, and keep improving after launch.

What it produces

Usually owned by: The system owner and the risk owner, with operations and incident response.

MANAGE categories

CategoryOutcome (AI RMF 1.0)Subcategories
MANAGE 1AI risks based on assessments and other analytical output from the MAP and MEASURE functions are prioritized, responded to, and managed.1.1, 1.2, 1.3, 1.4
MANAGE 2Strategies to maximize AI benefits and minimize negative impacts are planned, prepared, implemented, documented, and informed by input from relevant AI actors.2.1, 2.2, 2.3, 2.4
MANAGE 3AI risks and benefits from third-party entities are managed.3.1, 3.2
MANAGE 4Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored regularly.4.1, 4.2, 4.3

Source: NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023; NIST AIRC, AI RMF Core (Tables 1–4 of AI RMF 1.0) (checked 1 October 2026).

How the categories line up with ISO/IEC 42001

ISO/IEC 42001 is the international, certifiable standard for an AI management system. It covers much of the same ground as the AI RMF but is organised differently: management-system clauses 4 to 10 (context, leadership, planning, support, operation, performance evaluation, improvement) plus a set of AI controls in Annex A, with implementation guidance under the same numbers in Annex B. If you are working towards ISO/IEC 42001 certification, evidence you build for the AI RMF can usually be reused.

The table shows, for each AI RMF category, the ISO/IEC 42001 clauses and control areas that cover similar topics. It is a summary by topic of the NIST AI RMF to ISO/IEC 42001 crosswalk that NIST lists on its AI Resource Center (provided by Microsoft and prepared against the final draft of the standard). NIST notes that listing a crosswalk does not imply NIST endorsement of the resource it maps to, nor that either document fully covers the other. We give clause numbers only and do not reproduce ISO text; for the requirements themselves, use the standard.

AI RMF categoryISO/IEC 42001 clauses (4–10)Annex A/B control areas
GOVERN 14.1, 4.4, 5.2, 6.1, 6.2, 8.2, 8.3, 8.4A.2, A.4, A.6
GOVERN 25.1, 5.2, 5.3, 7.1, 7.2, 7.3, 7.4, 9.1, 9.3A.3
GOVERN 37.2A.3, A.4, A.5, A.6, A.9
GOVERN 46.1.4, 7.4A.5, A.6, A.8, A.9, A.10
GOVERN 5—A.5, A.6, A.8, A.10
GOVERN 6—A.10
MAP 14.1, 5.1, 5.2, 6.1.1, 6.1.4, 6.2, 7.2, 7.3, 7.4, 7.5A.4, A.5, A.6, A.9
MAP 2—A.4, A.6, A.7, A.8, A.9
MAP 34.3, 7.2, 8.2, 8.3, 8.4A.4, A.5, A.6, A.8
MAP 44.1A.2, A.6, A.8, A.9, A.10
MAP 56.1.2A.5, A.6, A.8
MEASURE 16.1.1, 6.1.2, 9.2A.5, A.6
MEASURE 28.2, 9.1A.2, A.3, A.4, A.5, A.6, A.7, A.8, A.9
MEASURE 34.4, 8.2, 8.4, 10.1A.6, A.8
MEASURE 49.1, 9.2, 9.3A.5, A.6, A.8
MANAGE 16.1.1, 6.1.2, 6.1.3, 6.1.4, 9.3A.5, A.6, A.9
MANAGE 26.1.1, 6.1.2, 6.1.3, 7.1, 10.1, 10.2A.3, A.4, A.6, A.7, A.8, A.9
MANAGE 3—A.4, A.6, A.10
MANAGE 49.2, 9.3A.6, A.8, A.10

Clauses, in our words: 4: context, scope and the management system itself; 5: leadership, AI policy and roles; 6: planning: risk assessment, risk treatment, impact assessment, objectives; 7: support: resources, competence, awareness, communication, documents; 8: operation: carrying out risk assessment, treatment and impact assessment; 9: performance evaluation: monitoring, internal audit, management review; 10: improvement and corrective action.

Control areas, in our words: A.2: AI policy; A.3: roles and raising concerns; A.4: resources: data, tools, computing, people; A.5: impact assessment; A.6: design, development, testing, deployment and monitoring; A.7: data quality and provenance; A.8: information for users and others, incident communication; A.9: responsible use; A.10: suppliers and customers.

Source: NIST AIRC, Crosswalk Documents; NIST AI RMF to ISO/IEC 42001 Crosswalk (provider: Microsoft; listed by NIST) (checked 1 October 2026).

Where a row shows "—" in the clauses column, the crosswalk maps that category only to Annex A/B controls. Four patterns stand out: GOVERN 1 and 2 line up with leadership, policy and support (clauses 5 and 7) and with the risk process itself (6.1, 8.2, 8.3); MAP and the impact parts of MEASURE line up with impact assessment (6.1.4, 8.4 and area A.5); MEASURE's testing and monitoring sit in the system life-cycle controls (A.6); and the third-party categories (GOVERN 6, MANAGE 3) map to supplier and customer controls (A.10).

Mapping workbook for all four functions

The Professional AI Governance Toolkit ($599) has the NIST AI RMF mapping workbook: all 19 categories with maturity scoring, evidence, owners and next steps, an indicative ISO/IEC 42001 crosswalk, and the ISO/IEC 42001 gap assessment. Starter ($199) has the AI policy, inventory, risk register and risk assessment.

Govern, Map, Measure, Manage: questions

What are the four functions of the NIST AI RMF?

GOVERN (a culture of risk management is cultivated and present), MAP (context is recognized and risks related to context are identified), MEASURE (identified risks are assessed, analyzed, or tracked) and MANAGE (risks are prioritized and acted upon based on a projected impact).

Do you have to do the functions in order?

No. NIST says that once governance is in place the functions may be performed in any order, and the process should be iterative. In practice most organisations set up GOVERN first and then run MAP, MEASURE and MANAGE for each AI system.

How many categories and subcategories are there?

19 categories and 72 subcategories: GOVERN has 6 categories and 19 subcategories; MAP has 5 categories and 18 subcategories; MEASURE has 4 categories and 22 subcategories; MANAGE has 4 categories and 13 subcategories.

Is the NIST AI RMF the same as ISO/IEC 42001?

No. ISO/IEC 42001 is a certifiable management-system standard; the NIST AI RMF is a voluntary framework that cannot be certified. They overlap heavily, and the crosswalk table on this page shows where each AI RMF category lands in ISO/IEC 42001 by clause number.

Which function should a small company start with?

GOVERN: an AI policy, an inventory of AI systems with owners, and a written risk tolerance. Then MAP your one or two highest-risk systems. Most of the rest builds on those documents.