The NIST AI Risk Management Framework (AI RMF) is a voluntary, widely adopted US framework for managing AI risk. It's organized around four core functions — Govern, Map, Measure, and Manage — that help any organization identify, assess, and reduce the risks of its AI systems.
Where the EU AI Act is law, the NIST AI RMF is a practical playbook. It's not mandatory, but it's become a de facto standard for building an AI risk program, and it maps cleanly onto both regulation and day-to-day operations. Here's how it works.
The four core functions
Govern
The foundation: establishing the culture, policies, accountability, and processes for managing AI risk across the organization. Govern is cross-cutting — it informs the other three functions and is where your AI governance program and policy live. Without it, the other functions happen inconsistently or not at all.
Map
Establishing context and identifying risks: what the AI system is for, who it affects, where it's used, and what could go wrong. This is the framework's version of building an AI inventory and surfacing risks — closely related to the first steps of an AI risk assessment.
Measure
Analyzing and assessing the risks you mapped — using quantitative and qualitative methods to evaluate things like accuracy, bias, robustness, and security, and to track them over time. Measure turns "we think this is risky" into evidence.
Manage
Acting on the risks: prioritizing, allocating resources, applying mitigations, and monitoring. This is where remediation plans get executed and where residual risk is accepted, transferred, or reduced.
Why organizations adopt it
The AI RMF is popular because it's flexible, non-prescriptive, and works for any size organization and any AI use. It gives structure without forcing a specific tool or methodology, and because it's US-government-originated and widely referenced, aligning to it signals credibility to customers, partners, and regulators. It also pairs well with certifiable standards like ISO 42001 — the RMF gives you the risk logic, ISO 42001 gives you the management-system structure.
How it relates to regulation
The AI RMF isn't a law and doesn't make you compliant with the EU AI Act on its own. But its functions map closely to what regulation asks for — risk management, documentation, human oversight, monitoring — so building on the RMF puts you in a strong position to meet obligations as they arrive. Many organizations use the RMF as the operating framework and specific regulations as the requirements it helps them satisfy.
How to put it to work
Start with Govern (accountability and policy) and Map (inventory and risk identification), then layer in Measure and Manage. In practice, most teams run this as a recurring cycle rather than a one-time project, which is the essence of ongoing AI governance. If you want the framework operationalized for your company — including where AI shows up in marketing and data — that's what our AI risk assessment and compliance and policy services do.
Frequently asked questions
What is the NIST AI Risk Management Framework?
A voluntary US framework for managing AI risk, organized around four core functions — Govern, Map, Measure, and Manage — that help organizations identify, assess, and reduce the risks of their AI systems.
What are the four functions of the NIST AI RMF?
Govern (culture, policy, accountability), Map (context and risk identification), Measure (analyzing and assessing risks), and Manage (prioritizing, mitigating, and monitoring). Govern is cross-cutting and informs the others.
Is the NIST AI RMF mandatory?
No — it's voluntary. But it's become a de facto standard for building AI risk programs and aligns closely with regulatory expectations, so adopting it is a practical way to prepare for laws like the EU AI Act.
How does the NIST AI RMF relate to the EU AI Act?
The RMF is a framework, not a law; it doesn't make you EU AI Act-compliant by itself. But its functions map to what regulation asks for, so building on it positions you to meet obligations as they arrive.
How does the NIST AI RMF compare to ISO 42001?
They complement each other: the AI RMF provides the risk-management logic, while ISO 42001 provides a certifiable AI management-system structure. Many organizations use both together.