The NIST AI Risk Management Framework is the most widely referenced AI risk document in the world and one of the least precisely understood. It is voluntary, it is not certifiable, and — despite a steady stream of blog posts claiming otherwise — there is still no AI RMF 2.0.
This is a walkthrough of what the framework actually asks you to do, function by function, and where the work usually stalls.
What it is, precisely
AI RMF 1.0 was published in January 2023. It organises AI risk management into four functions — Govern, Map, Measure, Manage — decomposed into categories and roughly 72 subcategories, each expressed as an outcome rather than a control. The companion Playbook suggests actions and documentation against each one.
Two properties matter more than the content:
It is outcome-based, not prescriptive. A subcategory says a thing should be true. It does not tell you how to make it true, which is why two organisations can both claim alignment and be doing very different work.
It is deliberately not certifiable. There is no NIST audit and no NIST certificate. Any vendor claiming to be “NIST AI RMF certified” is misrepresenting the framework, and that claim is a useful negative signal when assessing a supplier.
Govern
Govern is the only function that spans the organisation rather than a system. It covers policy, accountability, workforce competence, and the culture in which risk decisions get made — six categories and 19 subcategories.
It is placed first for a reason. Map, Measure, and Manage produce findings; Govern is what determines whether anyone acts on them. Programmes that skip it generate assessments that circulate and change nothing.
Where teams stall: accountability written as a department rather than a person. “The AI governance committee is accountable” means, in practice, that nobody is. The test is whether you can name the individual who would answer for a specific deployed system.
Map
Map establishes context: what the system is for, who it affects, what the intended use and the foreseeable misuse are, and where the boundaries sit.
This is where most of the value is, and it is mostly writing rather than testing. The central question — what is this system relied upon to do? — is one many organisations have never answered in writing, and the answer is rarely the one in the project brief. A system documented as flagging applications for human review is, if reviewers seldom overturn a flag, deciding them.
Where teams stall: mapping the system they designed rather than the one that is running. Scope creep after deployment is normal, and a Map artefact that reflects the original design is a description of history.
Measure
Measure is the technical core: analysing and tracking identified risks with quantitative and qualitative methods — four categories, 22 subcategories. It covers evaluation design, the limits of benchmarks, and the uncomfortable question of what evidence is sufficient for a given risk tier.
The framework is honest that some things are hard to measure and does not pretend otherwise. That honesty is what makes it more useful than a control checklist for the technical side of assurance.
Where teams stall: measuring what is easy rather than what matters. Accuracy on a held-out set is cheap to produce and often near-irrelevant to the deployment risk. Nobody’s Measure output should be a single number.
Manage
Manage is treatment: prioritising, allocating resources, documenting residual risk, responding to incidents, and monitoring after deployment.
Where teams stall: documenting residual risk instead of deciding about it. Manage asks for treatment decisions, and a residual risk with no named acceptor is not a decision — it is a description. Getting that acceptance recorded is step seven of a risk profile.
What changed in 2025–26
The framework itself has not been reissued, but the surrounding material has moved considerably. As of August 2026:
- AI RMF 1.0 remains the only finalised core framework. NIST states it is being revised. No 1.1 or 2.0 has been published, and content describing “AI RMF 2.0” as released is describing a rumour.
- The Generative AI Profile (NIST AI 600-1, July 2024) extends the framework to generative systems.
- A Cyber AI Profile has been folded into the Cybersecurity Framework, aligning AI risk work with security programmes that already exist.
- In April 2026, NIST released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure, targeting energy, water, healthcare, and financial services — explicitly aimed at contexts where AI-influenced decisions carry physical safety consequences.
That last item is the direction of travel worth watching. The generic framework is stabilising; the useful work is moving into sector profiles, which is where the questions an assurance practitioner actually faces get answered.
Using it with 42001
The RMF and ISO/IEC 42001 are not alternatives. 42001 gives you a certifiable management system and says almost nothing about how to evaluate a model. The RMF says a great deal about evaluation and produces no certificate. Mature programmes run both, which is covered in ISO/IEC 42001 vs NIST AI RMF.
A six-month test
Adopting the RMF is easy to fake, because nothing is audited. One question separates real adoption from a documentation exercise:
Has any deployment decision changed because of this work?
If nothing has been delayed, re-scoped, given additional monitoring, or rejected, the framework is decorative. That is not a failure of NIST; it is the predictable outcome of applying a voluntary framework without the governance function that makes findings consequential.
Applying the RMF to a live deployment, and defending the resulting judgement, is assessed directly in the Certified AI Assurance Financial Professional track.
Sources: NIST AI RMF · AI RMF Playbook · NIST AI 600-1, Generative AI Profile (July 2024) · NIST concept note, AI RMF Profile for Trustworthy AI in Critical Infrastructure (April 2026)