The NIST AI Risk Management Framework (AI RMF) is a voluntary, widely adopted framework from the US National Institute of Standards and Technology for…
See the framework's purpose and its voluntary, adaptable nature.
The NIST AI Risk Management Framework is a structured, voluntary guide for identifying and managing the risks of AI systems, published by the US National Institute of Standards and Technology. Unlike the EU AI Act, it is not a law — there is no enforcement — but it is widely adopted as a practical standard for building trustworthy AI.
Its aim is trustworthy AI: systems that are valid and reliable, safe, secure, accountable and transparent, explainable, privacy-enhanced, and fair. The framework gives organizations a common structure to reason about and reduce risk, adaptable to any sector or system size.
Learn the Govern, Map, Measure, Manage structure.
Govern is the foundation and runs throughout: it establishes the culture, policies, roles, and accountability for managing AI risk across the organization — without it, the other functions lack teeth.
Map builds context: identify where and how the AI system is used, who is affected, its intended purpose, and the risks and benefits in that setting. You cannot manage risks you have not first framed and identified.
Measure assesses and tracks the risks that Map identified, using quantitative and qualitative methods — testing, evaluation, and metrics for things like accuracy, robustness, bias, and security. It turns vague concerns into monitored quantities.
Manage acts on what Measure found: prioritize risks, apply mitigations, allocate resources, and respond to incidents. The four functions form an ongoing cycle, not a one-time pass — you revisit them as the system and its context change.
See how NIST extends the framework to generative systems.
The AI RMF is general, so NIST published a Generative AI Profile companion that pinpoints risks unique to or amplified by generative systems and maps concrete actions to the four functions. It gives teams building with LLMs a tailored starting point rather than a generic one.
The profile highlights risks such as confabulation (the framework's term for hallucination), generation of harmful or dangerous content, data privacy and training-data leakage, the ease of producing disinformation at scale, and challenges with intellectual property and provenance. For each, it suggests actions across Govern, Map, Measure, and Manage.
Put the framework to work and avoid treating it as paperwork.
Applied to a real system, the framework becomes a loop. Govern: set who owns AI risk and the policies. Map: document the use case, users, and context, and enumerate risks (using the GenAI Profile for LLM apps). Measure: define tests and metrics — red-teaming, evals, bias and security checks — and track them. Manage: mitigate, monitor in production, and respond to incidents.
Its value is a shared vocabulary and completeness: it makes teams ask about risks — governance, provenance, privacy — they might otherwise skip, and it composes with concrete controls like guardrails and evaluations.
Watch for: treating the RMF as documentation theater rather than driving real controls; doing Map and Measure once and never revisiting as the system changes; and skipping Govern, so no one actually owns the risk. The framework guides what to do — pair it with concrete measurement and mitigation, or it stays paperwork.
The NIST AI RMF is a voluntary framework for managing AI risk toward trustworthy AI, structured as four functions: Govern (culture and accountability), Map (context and risks), Measure (assess and track), and Manage (mitigate and respond) — run as an ongoing cycle. Its Generative AI Profile pinpoints risks like confabulation, harmful content, and data leakage and maps actions to each function. Apply it with real controls — guardrails, evals, monitoring — and clear ownership, or it stays paperwork.
You are deploying an LLM assistant for a bank. Walk one concrete action you would take under each of Govern, Map, Measure, and Manage, drawing a generative-AI-specific risk (like confabulation or data leakage) from the GenAI Profile into your Map step.
What is the NIST AI Risk Management Framework?
The AI RMF is a non-regulatory, adaptable guide toward trustworthy AI, structured around four core functions.
What are the four core functions of the AI RMF?
Govern sets culture and accountability throughout; Map frames context and risks; Measure assesses them; Manage mitigates and responds — as an ongoing cycle.
What does the Generative AI Profile add?
The profile tailors the general framework to generative systems, giving LLM teams a focused set of risks and suggested actions.
What is a common mistake when applying the AI RMF?
The framework guides what to do; without real measurement, mitigation, and clear ownership, it becomes paperwork rather than risk management.