✨ Standpoint covers NIST AI RMF readiness free for 14 days. Start your free trial →
Standpointby AI Service Pro
Frameworks / NIST AI RMF
AI governance · Voluntary framework

NIST AI RMF

The NIST AI Risk Management Framework — usually shortened to the AI RMF — is a voluntary framework published by the U.S. National Institute of Standards and Technology to help organizations manage the risks of AI systems and build AI that people can trust. It isn't a law and it isn't a certification. If a customer, a board, or your own governance work is pushing you toward "the NIST AI framework," here's the plain-language version: what it is, its four core functions (Govern, Map, Measure, Manage), the characteristics of trustworthy AI, the Generative AI Profile, and how to get ready.

What
the NIST AI RMF 1.0 — "Artificial Intelligence Risk Management Framework," released January 2023 — a voluntary framework for managing AI risk.
Who
any organization that designs, develops, deploys, or uses AI systems — from startups shipping AI features to enterprises governing a…
How it's organized
four core functions — Govern, Map, Measure, Manage — each broken into categories and subcategories of outcomes.
Trustworthy AI
the framework centers on making AI valid, safe, secure, accountable, explainable, privacy-enhanced, and fair.
// What Standpoint gives you

NIST AI RMF checklist

A function-by-function readiness checklist.

Free readiness assessment

See your AI RMF gaps in minutes.

Map to other frameworks

How the AI RMF lines up with ISO 42001, the EU AI Act & ISO 42005.

// What the framework covers
GOVERNCross-cutting. Build the culture, policies, roles, and accountability for managing AI risk — the foundation that connects and sustains the other three functions.GAP
MAPEstablish the context and frame the risks: what the AI system is for, who it affects, and where things could go wrong across its lifecycle.PARTIAL
MEASUREAnalyze, assess, and track the identified risks using appropriate methods and metrics, including testing for the trustworthiness characteristics.DONE
MANAGEPrioritize and act on the risks — allocate resources, treat or accept them, plan responses, and monitor over time.GAP

Illustrative statuses. Your real assessment is generated from your answers in the app. Standpoint is a self-assessment aid, not legal advice.

// Go deeper

What is the NIST AI RMF?

The AI RMF is a framework, not a certification or a rulebook. It gives organizations a common structure and vocabulary for identifying, assessing, and managing the risks that AI systems create — risks to people, organizations, and society — throughout the AI lifecycle. NIST developed it in an open, consensus process at the direction of Congress, and released version 1.0 in January 2023 alongside a companion Playbook. Because it is outcome-based and voluntary, an organization adopts as much of it as fits its context: the goal is not to "pass" but to make AI risk visible and manageable, and to i…

Who should use the NIST AI RMF?

It's written to be useful to anyone in the AI lifecycle, whatever their sector or size. Teams typically turn to the AI RMF when: - they are building or shipping AI features and want a defensible way to govern the risk; - a customer, partner, or board asks how they manage AI risk and expects a recognized structure; - they need a foundation that lines up with emerging AI regulation such as the EU AI Act, or with ISO/IEC 42001; - they want a shared language so legal, product, data science, and security can govern AI together.

The four core functions: Govern, Map, Measure, Manage

The heart of the AI RMF is four functions. GOVERN is cross-cutting — it runs through and supports the other three, setting the culture, policies, and accountability that make the rest work. Map, Measure, and Manage are the working cycle you run for each AI system. Under each function, the framework defines categories and, beneath those, more specific subcategories — concrete outcomes and actions an organization can work toward. You don't have to implement every subcategory; you select those that fit your risk and context, much as you would tailor any risk framework.

The characteristics of trustworthy AI

The AI RMF frames "trustworthy AI" around a set of characteristics that risk management should balance. No single one is enough on its own, and they can involve trade-offs. They are: - Valid and reliable — the system does what it's meant to, accurately and consistently. - Safe — it doesn't endanger human life, health, property, or the environment. - Secure and resilient — it withstands attacks and adverse events and recovers from them. - Accountable and transparent — responsibility is clear and information about the system is available to those who need it. - Explainable and interpretable — how it works and why it produced an output can be understood. - Privacy-enhanced — it safeguards autonomy, identity, and personal data. - Fair, with harmful bias managed — it promotes equity and actively manages harmful bias.

The Generative AI Profile

In July 2024, NIST released the Generative AI Profile (NIST-AI-600-1) — a companion "profile" that tailors the AI RMF to the specific risks of generative AI. It maps a set of GenAI-specific risks (such as confabulation, harmful or dangerous content, data privacy and intellectual-property leakage, and information-integrity harms) onto the four functions, and suggests actions organizations can take to manage them. If you're deploying large language models or other generative systems, the profile is the practical companion to the core framework. NIST publications are in the public domain. We summarize the framework here in our own words; consult the official NIST AI RMF 1.0 and the Generative AI Profile (NIST-AI-600-1) for authoritative text.

NIST AI RMF vs. ISO 42001 vs. the EU AI Act

They complement each other. The NIST AI RMF is a voluntary framework — a structure for managing AI risk that you can adopt at your own pace, with nothing to "certify" against. ISO/IEC 42001 is a certifiable management-system standard for AI: it specifies requirements for an AI management system (AIMS) that an accredited body can audit and certify. The EU AI Act is a law — binding regulation that imposes obligations on certain AI systems placed on the EU market, with real penalties for non-compliance. In practice the AI RMF is an excellent foundation: the risk work it drives feeds directly into an ISO 42001 management system and into demonstrating diligence under the EU AI Act.

NIST AI RMF work counts elsewhere too

The crosswalk maps your NIST AI RMF evidence onto the frameworks it overlaps — so you move forward on several at once.

EU AI ActISO 42001

Get your NIST AI RMF readiness score.

Free to start. No card, no demo wall. You decide what leaves your device.

Run your free check →