NIST AI Risk Management Framework as a Working Operating System
Voluntary NIST AI 100-1 guidance (26 January 2023). Map GOVERN, MAP, MEASURE, and MANAGE to owners, evidence, and cadence.

Voluntary NIST AI 100-1 guidance (26 January 2023). Map GOVERN, MAP, MEASURE, and MANAGE to owners, evidence, and cadence.

The NIST AI Risk Management Framework (AI RMF) is voluntary guidance, published 26 January 2023 as NIST AI 100-1, for incorporating trustworthiness into AI design, development, use, and evaluation. It is not SP 800-37, not CSF 2.0, and not a NIST-issued certification. This page is for product, engineering, and strategy teams who need named owners, control objectives, evidence artifacts, and a review cadence.
Private organizations are not required to use it. Read the rest as an operating join of the Core, the Playbook, and the Generative AI Profile, not as legal advice. If you sell into the EU or sit under an OMB memo, confirm extra-territorial and agency duties with counsel.
The AI RMF is consensus-driven guidance from NIST, a non-regulatory agency under Commerce, for managing risks across the AI lifecycle. Congress directed a voluntary framework in the National Artificial Intelligence Initiative Act of 2020 (P.L. 116-283).
Part 1 of 100-1 frames risk and seven trustworthy characteristics. Part 2 is the Core plus Profiles. Appendix D calls the document outcome-focused, non-prescriptive, and law- and regulation-agnostic.
The intended audience is OECD “AI actors”: those who play an active role in the AI system lifecycle, including organizations and individuals that deploy or operate AI.
The seven characteristics in AIRC §3 start with valid and reliable as the necessary base. The rest are safe; secure and resilient; accountable and transparent (cross-cutting); explainable and interpretable; privacy-enhanced; and fair, with harmful bias managed.
Tradeoffs are expected. Bias language points at NIST SP 1270 (systemic, computational/statistical, human-cognitive). Measurement language is TEVV: test, evaluation, verification, and validation.
Unqualified NIST RMF is SP 800-37, the seven-step federal authorization process (Prepare through Monitor) plus 800-53 controls. This page is the AI RMF.
CSF 2.0 (cyber outcomes), IR 8596 (Katerina Megas’s CSF-shaped Cyber AI Profile, draft 16 December 2025), ISO/IEC 42001, and the EU AI Act are adjacent documents. They are not this framework.
Secure and resilient in 100-1 points at the NIST Cybersecurity Framework and the NIST Risk Management Framework for confidentiality, integrity, and availability. That is a handoff, not a merge. Map and Measure have no clean CSF equivalent.
Appendix B of the AI RMF is the authority for what CSF does not cover: harmful bias, generative-AI risks, ML attacks, third-party AI, transfer learning, and off-label use.
AI RMF 1.0 is still the published Core. NIST’s landing page and FAQs, both updated 13 August 2026, say 1.0 is being revised under the White House AI Action Plan of 23 July 2025.
The Plan’s instruction to Commerce/NIST is to revise the AI RMF to drop references to misinformation, Diversity, Equity, and Inclusion, and climate change. That is a revision task, not a shipped 2.0.
The AIRC (Trustworthy and Responsible AI Resource Center) launched 30 March 2023. Companion pieces on the hub are the Playbook, Roadmap, Crosswalk, and Perspectives.
NIST AI 600-1 (Generative AI Profile) landed 26 July 2024. A concept note for an AI RMF Profile on trustworthy AI in critical infrastructure went out 7 April 2026. That note is not a published profile and not version 2.0.
Federal agencies do not make the AI RMF “law.” M-25-21 and M-25-22, issued in April 2025, rescind and replace M-24-10 (28 March 2024) and the companion Biden-era acquisition memo.
EO 14110 is revoked. Current agency operating system is those OMB memos plus EO 13960 and EO 14179.
Rescinding 14110 does not unwind 100-1 or 600-1. They keep their own clocks.
Martin Stanley at NIST put the operator line in FedScoop on 10 October 2025: manage AI risk, do not try to avoid it. Use that as posture, not as a legal interpretation.
Claim you will hear | Status |
|---|---|
AI RMF 1.0 / NIST AI 100-1 | Current published Core (26 January 2023) |
AI RMF 2.0 | Not published |
1.0 revision | Tasked by the 23 July 2025 AI Action Plan |
M-24-10 / EO 14110 | Historical. Replaced by M-25-21 / M-25-22 |
NIST AI RMF certification | NIST does not issue one |
Critical Infrastructure Profile | Concept note 7 April 2026, not a finished profile |
The Core is four functions: GOVERN, MAP, MEASURE, MANAGE. Actions in 100-1 do not constitute a checklist and are not necessarily an ordered set of steps.
GOVERN is cross-cutting and infused throughout. After you institute govern outcomes, most teams start with map and continue into measure or manage. You can run functions in any order across the lifecycle.
The work is continuous and multidisciplinary. Do not republish a 72-row subcategory table.
Vendor blogs disagree on the internal split. Use the load-bearing subcategory IDs below (from 100-1 Tables 1-4) as the operating spine.
ID | Official outcome | What you operationalize |
|---|---|---|
GOVERN 1.5 | Ongoing monitoring and periodic review planned; roles defined, including the frequency of periodic review | Cadence |
GOVERN 1.6 | Mechanisms to inventory AI systems, resourced to risk priorities | Inventory |
GOVERN 1.7 | Decommissioning and phasing out that does not increase risk or decrease trustworthiness | Decommission |
GOVERN 2.1 | Roles, responsibilities, and lines of communication for mapping, measuring, and managing AI risks are documented and clear | RACI |
GOVERN 2.2 | Personnel and partners receive AI risk-management training consistent with related policies | Training |
GOVERN 2.3 | Executive leadership takes responsibility for development and deployment risk decisions | Exec owner |
MAP 1.1 | Intended purposes, beneficial uses, context-specific laws and norms, and prospective settings understood and documented | Context before build |
MEASURE 1.1 | Metrics selected starting with the most significant AI risks; document what will not be measured | TEVV / evidence |
MANAGE 1.1 | Determination whether the system achieves intended purposes and whether development or deployment should proceed | Go / no-go |
MANAGE 1.3 | Responses to high-priority risks: mitigate, transfer, avoid, or accept | Treatment |
MANAGE 2.4 | Mechanisms to supersede, disengage, or deactivate systems whose performance or outcomes are inconsistent with intended use | Kill switch |
Govern is culture plus ownership. If you skip it, Map and Measure become a slide deck.
Playbook suggestions under GOVERN 2.1 give you a role seed, not a vendor org chart. That seed includes boards, senior management, AI audit, product, project, design, and development. It also names human-AI interaction, testing and evaluation, acquisition, impact assessment, and oversight.
Separate development from testing so confirmation bias has somewhere to die. Fold the work into existing legal, compliance, and enterprise-risk channels instead of standing up a parallel AI GRC shop.
GOVERN 1.2 policy contents worth stealing from the Playbook PDF include terms and intended uses, existing governance, and data-governance alignment. Add experimental-design and training standards, mapping and measurement, model testing and validation, and legal and risk review.
Also write down frequency and detail for monitoring, auditing, and review. Add change management, stakeholder engagement, whistleblower paths, and incident-response plans that you actually test.
Evidence that would count: a one-page charter (purpose, scope, risk tolerance, escalation), a named executive owner per GOVERN 2.3, and a documented RACI per GOVERN 2.1. Add training records per GOVERN 2.2 and an inventory system per GOVERN 1.6.
Categories in the Core behave like control objectives. Subcategories behave like control activities. They are not the 20 families in SP 800-53.
Write the context down before you train or buy. MAP 1.1 wants intended purposes, beneficial uses, applicable laws and norms, and prospective settings on paper first.
Face recognition unlocking a phone, clearing an airport lane, and feeding a law-enforcement case file are three different appetites. The Core does not pick your appetite. You do, in writing, with the exec owner from GOVERN 2.3 on the signature line.
If you cannot name the system, you cannot map it. Inventory (GOVERN 1.6) belongs before Map, including vendors, fine-tunes, agents, and the shadow tools your AI solutions stack already quietly bought.
An inventory row should carry purpose, data classes, owners, deployment venue, and residual-risk status. Evidence that would count: a context brief per system, a data-flow sketch, a third-party or model-card pointer, and a mapped list of which trustworthy characteristics are in scope versus explicitly out of scope.
Programs stall here. MEASURE 1.1 says you select metrics starting with the most significant AI risks, and you document what you will not measure. NIST does not publish pass/fail thresholds for you.
Playbook Measure language: document TEVV test sets, metrics, and tools. Track go/no-go and accountability roles.
Post-deployment TEVV covers validity, bias, privacy, and security, not a one-time eval spreadsheet. If you already run LLM observability (traces, quality scores, cost, drift), that instrumentation is the MEASURE runtime. The AI RMF does not replace it.
Evidence that would count: a TEVV plan, versioned test sets, a signed record of what was not measured, pre-deployment scores, and a monitoring spec with owners. Screenshots in a share folder are not a TEVV record.
Treatment without a kill switch is theater. MANAGE 1.1 is a documented determination of whether the system achieves its intended purposes and whether development or deployment should proceed. MANAGE 1.3 is mitigate, transfer, avoid, or accept.
MANAGE 2.4 is the kill switch: supersede, disengage, or deactivate when outcomes drift from intended use. GOVERN 1.7 covers decommissioning that does not raise residual risk.
Playbook Manage language adds post-deployment monitoring, incident response, and recovery. Cadence here is yours to set (GOVERN 1.5). NIST does not hand you a universal interval.
Evidence that would count: a go/no-go memo, residual-risk sign-off, an incident ticket that names the AI system, a tested rollback, and a decommission ticket. If nobody can deactivate the system on a named clock, you do not have MANAGE 2.4.
The NIST AI RMF Playbook is the how-to companion to Tables 1-4. Playbook FAQs (updated 18 March 2025) say it is not one-size-fits-all, and it is neither a checklist nor an ordered list of steps.
You are not expected to implement every suggestion. Comments are reviewed semi-annually.
Use the Playbook as suggested actions your team can turn into tickets. Do not retitle your internal wiki “the NIST playbook.”
Vendor “72-control self-assessments” and Notion templates are unofficial overlays. They can be useful as a prompt. They are not NIST.
Link the AIRC Playbook, not a PDF download. The PDF is a snapshot. NIST patches suggested actions in the HTML.
Published 26 July 2024, NIST AI 600-1 is a cross-sectoral profile of AI RMF 1.0 for generative AI. A profile instantiates Core functions, categories, and subcategories for a setting or technology.
Not every 1.0 subcategory is included. Action IDs are GV, MP, MS, and MG. Do not cite the withdrawn initial public draft.
600-1 lists 12 GAI-exacerbated risks: CBRN information and capabilities; confabulation (NIST’s preferred term over “hallucination”); dangerous, violent, or hateful content; data privacy; environmental impacts; and harmful bias or homogenization.
The remaining six are human-AI configuration; information integrity; information security; intellectual property; obscene, degrading, or abusive content (including CSAM and NCII); and value-chain / component integration. Name the abusive-content category. Do not turn CSAM or NCII handling into product-runbook steps here.
If you ship LLMs, copilots, or content-generating features, layer 600-1 actions on the same four functions. It does not replace 1.0.
EO 14110 is why the profile exists. EO 14110 is not current federal AI policy.
600-1 restates GOVERN 1.5, GOVERN 1.6, GOVERN 2.1, and MEASURE 1.1 in GAI action tables. That is a second official witness of those sentences. It still does not cover autonomous tool-use and delegation well.
Agentic project management and MCP access-control design sit in that gap. Treat agents as identities with a named human owner and tighter least privilege than a person, then map them in GOVERN 1.6. Do not wait for a future “agent profile” before you inventory them.
Do not conflate 600-1 with the CSA Agentic Profile, NCCoE Cyber AI work, or IR 8596. Those are cyber-shaped. 600-1 is a GenAI overlay on the AI RMF.
This is the hole the glossary pages leave. The Core tells you outcomes. You still have to name who does the work, what artifact would satisfy an auditor asking about a specific action, and how often you re-open the file.
The interval below is an operating example. It is not a NIST-mandated clock.
GOVERN 1.5 requires a defined frequency. The Playbook treats monitoring and audit frequency as a policy field. You pick the number and write it down.
On r/grc, the recurring failure is a policy PDF plus a vendor questionnaire, then silence when someone asks whether this agent was allowed to touch that dataset yesterday. Overlay the AI RMF on the register you already run (ISO 27001, CSF, internal ERM). Do not clone a second program that nobody staffs.
Artifact | Function hook | What it proves |
|---|---|---|
System inventory row / AI-BOM | GOVERN 1.6 | The system exists, with owner, purpose, data, venue |
Charter (purpose, scope, tolerance, escalation) | GOVERN 2.3, MAP 1.1 | Someone accepted the context |
RACI plus training record | GOVERN 2.1, 2.2 | Named humans, not a committee alias |
TEVV plan and versioned test sets | MEASURE 1.1 | What you measured, and what you refused to measure |
Go/no-go memo | MANAGE 1.1 | A decision, with a date and a signer |
Residual-risk sign-off | MANAGE 1.3 | Mitigate / transfer / avoid / accept, chosen in writing |
Monitoring spec plus rollback | GOVERN 1.5, MANAGE 2.4 | Cadence and a kill switch that has been tested |
Decommission ticket | GOVERN 1.7 | You can turn it off without raising residual risk |
Build continuous evidence before an auditor asks. A pre-audit scramble that reconstructs intent from Slack is not GOVERN.
Dedicated GRC and CNAPP tools can automate inventory and evidence collection. They are not a substitute for the named owner and the written cadence.
On r/grc, questionnaires treat NIST AI RMF, ISO 42001, and the EU AI Act as interchangeable. They are not.
Instrument | What it is | What it is not | Who it binds |
|---|---|---|---|
NIST AI RMF 1.0 (AI 100-1) | Voluntary US risk operating system | A law, a cert, a checklist, SP 800-37 | Nobody, unless a contract says so |
Certifiable AI management system (Edition 1, 18 December 2023) | A substitute for a legal regime | Organizations that choose certification | |
EU AI Act (Regulation 2024/1689) | Binding product law | A framework you “adopt” | Providers and deployers in scope of the Act |
NIST CSF 2.0 | Cybersecurity outcomes | Coverage of bias, GAI content risks, off-label ML | Cyber programs that adopt it |
Current OMB federal AI memos | “The AI RMF is mandatory for agencies” | US federal agencies (with stated exemptions) |
ISO 42001 is Type A and jurisdiction-neutral. It does not replace laws. IAPP puts it plainly: it may not be a golden ticket for organizations that need to meet a specific legal regime.
An AIRC-hosted 42001 crosswalk PDF still carries an FDIS title. Treat it as a mapping aid. Do not treat it as a certification shortcut, and do not assume NIST authored every PDF sitting on AIRC.
The EU AI Act entered the OJ as Regulation 2024/1689 (13 June 2024; OJ 12.7.2024). Prohibitions, definitions, and AI-literacy duties applied from 2 February 2025. Governance, penalties, and GPAI-provider obligations applied from 2 August 2025.
Commission evaluation is due by 2 August 2028. Article 40 lets harmonised standards create a presumption of conformity for high-risk systems. ISO 42001 is not EU AI Act compliance.
US teams selling into the EU can reuse RMF evidence. That evidence is not conformity.
Contracts may still incorporate framework terms even when a state bill dies. Colorado’s 2024 AI Act was repealed before taking effect.
H.R. 6936 died with the 118th Congress (introduced, not enacted). Read the contract, not last year’s tracker.
If you work in a US federal agency, your binding text is M-25-21 and M-25-22, not 100-1.
Hunton’s April 2025 decode is a useful companion to the PDFs. The memos put a Chief AI Officer on a 60-day clock and CFO Act AI Governance Boards on a 90-day clock. A barrier-removal strategy sits on a 180-day clock, plus an annual public inventory.
M-25-21 high-impact AI that is not performing must have a plan to discontinue until compliance. If mitigation is impossible, cease use. Independent review of high-impact use cases is required before risk acceptance, and agencies must track those cases centrally.
Each agency retains or designates a Chief AI Officer. CFO Act agencies convene an AI Governance Board.
Agencies publish an AI use-case inventory, adopt a Generative AI policy, implement minimum risk-management practices for high-impact uses, and report determinations and waivers. Sections 4(a)-(b) do not apply to Intelligence Community elements.
“Risks from the use of AI” in M-25-21 means efficacy, safety, fairness, transparency, accountability, appropriateness, or lawfulness of a decision or action. The memo explicitly does not include every AI risk. It carves out, for example, privacy, security, and confidentiality of training data and model inputs.
High-impact, in the memo, is output that serves as a principal basis for decisions or actions with legal, material, binding, or significant effect on rights, safety, critical services, or listed program access. Confirm the full definition and minimum-practice list against the PDF before you quote them as complete. National security systems are carved out.
M-25-22 governs acquisition. The memo applies to contracts awarded from solicitations issued on or after 180 days from its 3 April 2025 issuance, which is 1 October 2025.
M-25-21 does not require you to adopt the AI RMF as a mandatory operating system. The extracted memos do not name it that way.
The DNA overlap is real. The citation is the memo.
EO 14409 (2 June 2026) is about cyber defense of national security systems, not an AI RMF revision.
Search results still leak “7 steps of RMF” into AI-RMF queries. Those steps belong to SP 800-37.
If your implementation plan is Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor, you are running the classic RMF. Map it if you are a federal authorizer. It does not paste onto 100-1.
“Is there a NIST AI RMF certification?” is the most repeated follow-up around this query. No. NIST does not operate a certification scheme against the AI RMF.
Third-party courses in a .gov catalog (including CISA NICCS listings) are training products, not a NIST credential. If a customer needs a certifiable AIMS, that is ISO/IEC 42001.
On r/ciso, the recurring line is visibility first: you cannot classify risk on systems you have not listed. GOVERN 1.6 is the unglamorous first control.
Shadow LLM use is the new shadow IT. Blocking consumer domains without an official alternative just moves the work onto phones.
Some 2025 vendor posts claimed 2.0 shipped in February 2024. That date lines up with CSF 2.0, not the AI RMF.
As of the 13 August 2026 FAQ update, 1.0 is current and under revision. Do not date your controls to a version that does not exist.
Vendor “72-control” self-assessments and Notion templates are unofficial overlays. The Core’s four functions and 19 categories are outcomes, not a scored control set. Useful as a prompt, fatal as “we are NIST-compliant.”
One is voluntary guidance. One is a certifiable management system. One is legislation.
A completed 42001 audit does not control runtime behavior. An RMF profile does not create a presumption of conformity under Article 40.

Buyer and implementation guide for ChatGPT Enterprise: controls, SSO/SCIM, residency, HIPAA boundary, and a 12-step rollout.

Run enterprise AI as a Fund, Defer, or Kill portfolio. Covers operating models, platform layers, shadow AI, and conflicting ROI numbers.

AI governance is named owners, written policy, risk-tiered approvals, a living inventory, and a review cadence that continues after go-live.