Skip to content
AIAC AI ASSURANCE COUNCIL

Framework

NIST AI RMF

The US reference for managing AI risk, organised into four functions. Voluntary, not certifiable, and the most widely used common vocabulary for what good AI risk management looks like in practice.

§ 1 — Orientation

How the framework is put together

The AI Risk Management Framework was published by the National Institute of Standards and Technology in January 2023. It is voluntary by design. There is no NIST audit, no NIST certificate and no conformity route, and that is a deliberate choice rather than a gap someone intends to close.

It organises the work into four functions. Govern establishes the culture and accountability the rest depends on, Map builds the understanding of context and of what a system is actually for, Measure decides what is assessed and how, and Manage acts on what the measurements show. Govern is drawn as running through the other three rather than sitting before them, because a measurement nobody is accountable for changes nothing.

What the RMF is unusually strong on is the part most instruments leave alone, which is what it means to measure a property like fairness or robustness at all. What it deliberately does not give you is an external signal. After a year of good RMF-aligned work an organisation has better practice and nothing a customer can verify, which is why mature programmes run it alongside a certifiable management system rather than instead of one.

§ 2 — Guides

Guides to this framework

Written about the instrument as a whole rather than provision by provision. Where an obligation page answers what one article requires, these answer what the thing is for and how it is adopted.

  • NIST AI RMF: a practical walkthrough

    What the four functions actually ask you to do, where teams stall, and what changed in 2025–26 — including why there is still no AI RMF 2.0.