NIST AI RMF
FRAMEWORK · NIST AI RMF

NIST AI RMF: four functions, one profile

The NIST AI Risk Management Framework is a voluntary framework from the US National Institute of Standards and Technology for managing the risks of AI systems across four functions — Govern, Map, Measure, Manage. Nobody is required to adopt it, no law in the EU refers to it, and no certification against it exists. Organisations use it because it is a common language for AI risk that customers, US federal buyers and boards recognise, and because its functions map cleanly onto the risk-management work the EU AI Act and ISO/IEC 42001 ask for anyway.

Last reviewed · against the consolidated text and Commission guidance

72
subcategories in the catalogue
12
programme steps, each producing a record
4
gate-locked phases
4
steps answered per AI system
Legal basis
NIST AI 100-1
Published by
US National Institute of Standards and Technology
Status
Voluntary · no certification exists
WHO IT APPLIES TO

Who adopts it

Nobody is required to. These are the organisations for which the standard answers a question someone is already asking.

Organisations selling into the US

Federal procurement and many enterprise buyers ask how AI risk is managed in NIST terms; a profile is the answer they recognise.

Teams that need a risk vocabulary

Before a management system, a shared way to name intended purpose, context, impacts and metrics — the Map and Measure functions give one.

Providers of high-risk AI in the EU

Art. 9 asks for a risk management system across the lifecycle; the framework organises it, and nothing in it substitutes for the Act's own duties.

KEY DATES · STATUS

The dates that matter

Nobody certifies the NIST AI RMF — no scheme exists, and Veritome never implies one. The output is a profile document.

DateEventWhat it means
26.01.2023AI RMF 1.0 releasedNIST AI 100-1, with the companion Playbook. Voluntary from the first page.
26.07.2024Generative AI ProfileNIST AI 600-1, a companion profile for generative AI risks — the same four functions, applied.
02.12.2027EU AI Act Annex IIIThe date most Annex III high-risk duties apply from. The framework organises Art. 9 risk management; it is not a harmonised standard and gives no presumption of conformity.
WHAT IT ASKS

72 requirements, in the shape the framework gives them

The Core is four functions broken into categories and subcategories: Govern sets policies, roles, culture and third-party handling; Map establishes context, purpose, capabilities and impacts; Measure defines metrics and evaluates trustworthiness; Manage prioritises, responds and learns. NIST publications are public domain, so Veritome's catalogue carries a one-line paraphrase of every subcategory and a step names the ranges it closes.

19
Govern subcategories
18
Map subcategories
22
Measure subcategories
13
Manage subcategories
  • GOVERN6 categories19
  • MAP5 categories18
  • MEASURE4 categories22
  • MANAGE4 categories13
HOW VERITOME RUNS IT

12 steps, 4 phases, one record each

4 phases, one per function — Govern · Map · Measure · Manage — gate-locked in that order, 12 steps in all. 4 of them — the Map steps and the trustworthiness evaluation — are answered per AI system and the rest once for the organisation, and they reuse what the EU AI Act journey already recorded about purpose, context and risk rather than asking again. The last step assembles the AI RMF profile — the document the framework itself describes as its output — as a generated PDF.

01

Govern

3 steps
  1. Policies, accountability and risk tolerance
  2. Roles, workforce and culture
  3. Third-party risk and stakeholder engagement
02

Map

3 steps
  1. Context and intended purpose
    Per system
  2. Categorisation, capabilities and benefits
    Per system
  3. Risks and impacts to individuals and society
    Per system
03

Measure

3 steps
  1. Metrics and evaluation approach
  2. Trustworthiness evaluation
    Per system
  3. Risk tracking and context-based performance feedback
04

Manage

3 steps
  1. Risk prioritisation and response
  2. Third-party risk management
  3. Incident response, learning and the AI RMF profile
NIST AI RMFNIST AI RMF programme
12 steps · 12 records · 0 shared
01Govern
3 steps · Complete
02Map
3 steps · In progress
03Measure
3 steps · Locked
04Manage
3 steps · Locked
Map · the steps
  1. 01Context and intended purposePer systemApproved
  2. 02Categorisation, capabilities and benefitsPer systemIn draft
  3. 03Risks and impacts to individuals and societyPer systemTo do
Phases and steps as the product generates them · progress shown is illustrative
WHERE IT OVERLAPS

Credited in both, or only related

No NIST step is credited against another framework: the framework is a set of outcomes, not clauses, and the owner's verified matrix relates rather than credits. Every step carries related links to the EU AI Act's risk-management, data-governance and monitoring articles and to ISO/IEC 42001's risk and impact clauses — shown in the drawer, never counted as coverage.

WithRecords credited in bothRelated only — shown, never creditedPage
EU AI Act021EU AI Act
GDPR04GDPR
ISO 42001023ISO 42001
ISO 2700107ISO 27001

12 of the 12 steps carry a related link to an EU AI Act article. A related link is a supporting candidate the owner's verified matrix did not check against source text; the product shows it beside the step and never counts it as coverage. The full matrix for all five frameworks is on the frameworks page; the EU AI Act itself, article by article, is at /eu-ai-act.

The coverage matrix in Veritome — one row per requirement, one column per framework, credited cells apart from related ones
QUESTIONS PEOPLE ASK

NIST AI RMF, answered plainly

The answers below are the ones the page marks up for search engines and AI assistants — the same text, nothing hidden.

What is the NIST AI RMF?

A voluntary framework published by the US National Institute of Standards and Technology in January 2023 for managing the risks of AI systems. Its Core has four functions — Govern, Map, Measure, Manage — with categories and subcategories describing outcomes, and a companion Playbook suggests how to reach them.

Is there a NIST AI RMF certification?

No. No certification scheme exists for the framework and NIST does not accredit one; anyone offering a 'NIST AI RMF certificate' is offering their own badge. The framework's own output is a profile: a description of how your organisation applies the functions to its AI. Veritome generates that profile and never calls it a certificate.

Does the NIST AI RMF satisfy the EU AI Act?

No. It is a voluntary US framework and the Act does not refer to it; it is not a harmonised standard and gives no presumption of conformity. The overlap is real — Art. 9's risk-management system, Art. 10's data governance and Art. 72's post-market monitoring cover the same ground as Map, Measure and Manage — and Veritome shows those as related links beside each step without crediting them.

What is an AI RMF profile?

A description of how an organisation implements the framework's functions for a given context — its current state, its target and the gap. NIST publishes companion profiles such as the Generative AI Profile (NIST AI 600-1). In Veritome the profile is the last step of the programme, assembled from the 12 records into a PDF.

How is the NIST AI RMF different from ISO/IEC 42001?

ISO/IEC 42001 is a certifiable management-system standard with auditable clauses; the NIST AI RMF is a voluntary framework of outcomes with no certification. Many organisations use the RMF's vocabulary inside an ISO/IEC 42001 system — the Map and Measure functions read naturally as the AI risk and impact assessments the standard requires.

How does Veritome run the NIST AI RMF?

As 12 steps across the four functions, 4 of them answered per AI system and the rest once for the organisation, closing all 72 subcategories. The programme ends in a generated profile PDF. Programmes come with a workspace; the free check shows which EU AI Act and GDPR duties a system carries first.

The other four