United States Framework Voluntary standard Non-binding

NIST AI RMF: requirements, deadlines and compliance actions

NIST AI Risk Management Framework (AI RMF 1.0) and Generative AI Profile

What is the NIST AI RMF?

The NIST AI Risk Management Framework is a voluntary framework for managing risks to individuals, organisations and society from AI. It organises practices into four functions: Govern, Map, Measure and Manage, and describes characteristics of trustworthy AI such as validity, safety, security, accountability, explainability, privacy and fairness. The July 2024 Generative AI Profile (NIST AI 600-1) adds risks and suggested actions specific to generative AI. Many US procurement requirements and state laws reference the framework as a recognised approach.

Who does it apply to?

Voluntary and sector-agnostic; usable by any organisation designing, developing, deploying or evaluating AI systems. It creates no legal obligations, but Colorado SB 24-205 and federal procurement guidance treat conformity with the framework as evidence of reasonable care.

Any organisation that chooses to adopt it; referenced by regulators, state laws and customers.

When do the requirements apply?

AI RMF 1.0 released 26 January 2023; Generative AI Profile (NIST AI 600-1) released 26 July 2024.

What must organisations do?

Nothing is mandatory. Organisations adopting it typically establish governance (Govern), document context and impacts (Map), test and monitor (Measure), and prioritise and respond to risks (Manage), using the Playbook.

Voluntary Establish AI governance policies, roles and accountability (Govern) GOVERN function

Govern covers policies and procedures for AI risk, roles and responsibilities, workforce diversity and training, organisational culture, stakeholder engagement, and third-party risk management. It is the cross-cutting function that supports the other three.

Practical action: Adopt an AI policy, assign owners, and set a risk-tolerance statement approved by leadership.

Evidence examples: AI governance policy

Framework mapping (original, editorial): ISO/IEC 42001:2023 Clauses 4–5 and 7

Obligation page Source-linked

Voluntary Map context, intended use and potential impacts (Map) MAP function

Map establishes the context: intended purposes, users, deployment settings, legal requirements, risk categorisation, benefits and costs, and impacts on individuals, groups, communities and society.

Practical action: Produce a system card or context document before development starts.

Evidence examples: AI system context and impact document

Framework mapping (original, editorial): ISO/IEC 42001:2023 Clause 6.1.4 AI system impact assessment

Obligation page Source-linked

Voluntary Measure and test trustworthiness characteristics (Measure) MEASURE function

Measure covers selecting metrics and test methods, evaluating validity, safety, security, resilience, explainability, privacy, fairness and bias, and monitoring these over time, including through independent review and red-teaming for generative AI.

Practical action: Define a test plan with metrics for each trustworthiness characteristic and record results.

Evidence examples: Evaluation and red-team reports

Framework mapping (original, editorial): ISO/IEC 42001:2023 Clause 9 Performance evaluation; Annex A verification controls

Obligation page Source-linked

Voluntary Prioritise, respond to and monitor AI risks (Manage) MANAGE function

Manage allocates resources to mapped and measured risks, plans responses including decommissioning, manages third-party risks, and documents post-deployment monitoring, incident response and communication.

Practical action: Maintain a risk-treatment plan and an incident and monitoring log per system.

Evidence examples: Risk treatment and monitoring plan

Framework mapping (original, editorial): ISO/IEC 42001:2023 Clauses 8 and 10

Obligation page Source-linked

Penalties

None; voluntary.

Key sections and articles

Sections of NIST AI RMF
ReferenceTitleSummary
Part 1Foundational informationFraming AI risk, audiences, harms and trustworthiness characteristics.
Part 2: CoreGovern, Map, Measure, ManageThe four functions with categories and subcategories.
NIST AI 600-1Generative AI ProfileTwelve generative-AI risk areas and suggested actions.

Official sources

  1. Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1
    National Institute of Standards and Technology · 26 Jan 2023 · Tier 1 source
  2. AI RMF: Generative Artificial Intelligence Profile, NIST AI 600-1
    National Institute of Standards and Technology · 26 Jul 2024 · Tier 1 source
  3. AI RMF programme page and Playbook
    National Institute of Standards and Technology · Tier 1 source

Frequently asked questions

Is the NIST AI RMF mandatory?
No. It is voluntary. Some laws and procurement rules reference it, and Colorado's AI Act treats compliance with a recognised framework such as the AI RMF as relevant to the "reasonable care" defence.
How does the NIST AI RMF relate to ISO/IEC 42001?
Both are voluntary. The AI RMF is a risk-management framework with four functions; ISO/IEC 42001 is a certifiable management-system standard. Organisations often use the AI RMF as the practice catalogue inside an ISO/IEC 42001 management system.

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.