AI Turnpoint LogoAI Turnpoint logo alternative
  • Search
  • News
  • Strategy
  • Research
  • Tools
Subscribe
  1. Home
  2. Categories
  3. Strategy

NIST AI Risk Management Framework as a Working Operating System

Voluntary NIST AI 100-1 guidance (26 January 2023). Map GOVERN, MAP, MEASURE, and MANAGE to owners, evidence, and cadence.

Updated September 14, 202618 min read
Analytics dashboard used as featured image for the NIST AI Risk Management Framework guide

The NIST AI Risk Management Framework (AI RMF) is voluntary guidance, published 26 January 2023 as NIST AI 100-1, for incorporating trustworthiness into AI design, development, use, and evaluation. It is not SP 800-37, not CSF 2.0, and not a NIST-issued certification. This page is for product, engineering, and strategy teams who need named owners, control objectives, evidence artifacts, and a review cadence.

Private organizations are not required to use it. Read the rest as an operating join of the Core, the Playbook, and the Generative AI Profile, not as legal advice. If you sell into the EU or sit under an OMB memo, confirm extra-territorial and agency duties with counsel.

Key Takeaways

  • AI RMF 1.0 is NIST AI 100-1, released 26 January 2023. It is voluntary for private teams.
  • GOVERN, MAP, MEASURE, and MANAGE are outcome functions, not a checklist and not the seven steps of SP 800-37.
  • Inventory lives in GOVERN 1.6. Review frequency lives in GOVERN 1.5. Executive ownership lives in GOVERN 2.3. A kill switch lives in MANAGE 2.4.
  • Version 1.0 is being revised under the 23 July 2025 AI Action Plan. There is no published 2.0.
  • NIST does not certify you against the AI RMF. It is a voluntary framework, not a certification scheme. ISO/IEC 42001 is the certifiable AI management system; the EU AI Act is binding product law.

What It Is (and What It Is Not)

The AI RMF is consensus-driven guidance from NIST, a non-regulatory agency under Commerce, for managing risks across the AI lifecycle. Congress directed a voluntary framework in the National Artificial Intelligence Initiative Act of 2020 (P.L. 116-283).

Part 1 of 100-1 frames risk and seven trustworthy characteristics. Part 2 is the Core plus Profiles. Appendix D calls the document outcome-focused, non-prescriptive, and law- and regulation-agnostic.

The intended audience is OECD “AI actors”: those who play an active role in the AI system lifecycle, including organizations and individuals that deploy or operate AI.

The seven characteristics in AIRC §3 start with valid and reliable as the necessary base. The rest are safe; secure and resilient; accountable and transparent (cross-cutting); explainable and interpretable; privacy-enhanced; and fair, with harmful bias managed.

Tradeoffs are expected. Bias language points at NIST SP 1270 (systemic, computational/statistical, human-cognitive). Measurement language is TEVV: test, evaluation, verification, and validation.

Unqualified NIST RMF is SP 800-37, the seven-step federal authorization process (Prepare through Monitor) plus 800-53 controls. This page is the AI RMF.

CSF 2.0 (cyber outcomes), IR 8596 (Katerina Megas’s CSF-shaped Cyber AI Profile, draft 16 December 2025), ISO/IEC 42001, and the EU AI Act are adjacent documents. They are not this framework.

Secure and resilient in 100-1 points at the NIST Cybersecurity Framework and the NIST Risk Management Framework for confidentiality, integrity, and availability. That is a handoff, not a merge. Map and Measure have no clean CSF equivalent.

Appendix B of the AI RMF is the authority for what CSF does not cover: harmful bias, generative-AI risks, ML attacks, third-party AI, transfer learning, and off-label use.

Why It Matters in 2026

AI RMF 1.0 is still the published Core. NIST’s landing page and FAQs, both updated 13 August 2026, say 1.0 is being revised under the White House AI Action Plan of 23 July 2025.

The Plan’s instruction to Commerce/NIST is to revise the AI RMF to drop references to misinformation, Diversity, Equity, and Inclusion, and climate change. That is a revision task, not a shipped 2.0.

The AIRC (Trustworthy and Responsible AI Resource Center) launched 30 March 2023. Companion pieces on the hub are the Playbook, Roadmap, Crosswalk, and Perspectives.

NIST AI 600-1 (Generative AI Profile) landed 26 July 2024. A concept note for an AI RMF Profile on trustworthy AI in critical infrastructure went out 7 April 2026. That note is not a published profile and not version 2.0.

Federal agencies do not make the AI RMF “law.” M-25-21 and M-25-22, issued in April 2025, rescind and replace M-24-10 (28 March 2024) and the companion Biden-era acquisition memo.

EO 14110 is revoked. Current agency operating system is those OMB memos plus EO 13960 and EO 14179.

Rescinding 14110 does not unwind 100-1 or 600-1. They keep their own clocks.

Martin Stanley at NIST put the operator line in FedScoop on 10 October 2025: manage AI risk, do not try to avoid it. Use that as posture, not as a legal interpretation.

Claim you will hear

Status

AI RMF 1.0 / NIST AI 100-1

Current published Core (26 January 2023)

AI RMF 2.0

Not published

1.0 revision

Tasked by the 23 July 2025 AI Action Plan

M-24-10 / EO 14110

Historical. Replaced by M-25-21 / M-25-22

NIST AI RMF certification

NIST does not issue one

Critical Infrastructure Profile

Concept note 7 April 2026, not a finished profile

How the Four Functions Work

The Core is four functions: GOVERN, MAP, MEASURE, MANAGE. Actions in 100-1 do not constitute a checklist and are not necessarily an ordered set of steps.

GOVERN is cross-cutting and infused throughout. After you institute govern outcomes, most teams start with map and continue into measure or manage. You can run functions in any order across the lifecycle.

The work is continuous and multidisciplinary. Do not republish a 72-row subcategory table.

Vendor blogs disagree on the internal split. Use the load-bearing subcategory IDs below (from 100-1 Tables 1-4) as the operating spine.

ID

Official outcome

What you operationalize

GOVERN 1.5

Ongoing monitoring and periodic review planned; roles defined, including the frequency of periodic review

Cadence

GOVERN 1.6

Mechanisms to inventory AI systems, resourced to risk priorities

Inventory

GOVERN 1.7

Decommissioning and phasing out that does not increase risk or decrease trustworthiness

Decommission

GOVERN 2.1

Roles, responsibilities, and lines of communication for mapping, measuring, and managing AI risks are documented and clear

RACI

GOVERN 2.2

Personnel and partners receive AI risk-management training consistent with related policies

Training

GOVERN 2.3

Executive leadership takes responsibility for development and deployment risk decisions

Exec owner

MAP 1.1

Intended purposes, beneficial uses, context-specific laws and norms, and prospective settings understood and documented

Context before build

MEASURE 1.1

Metrics selected starting with the most significant AI risks; document what will not be measured

TEVV / evidence

MANAGE 1.1

Determination whether the system achieves intended purposes and whether development or deployment should proceed

Go / no-go

MANAGE 1.3

Responses to high-priority risks: mitigate, transfer, avoid, or accept

Treatment

MANAGE 2.4

Mechanisms to supersede, disengage, or deactivate systems whose performance or outcomes are inconsistent with intended use

Kill switch

Govern

Govern is culture plus ownership. If you skip it, Map and Measure become a slide deck.

Playbook suggestions under GOVERN 2.1 give you a role seed, not a vendor org chart. That seed includes boards, senior management, AI audit, product, project, design, and development. It also names human-AI interaction, testing and evaluation, acquisition, impact assessment, and oversight.

Separate development from testing so confirmation bias has somewhere to die. Fold the work into existing legal, compliance, and enterprise-risk channels instead of standing up a parallel AI GRC shop.

GOVERN 1.2 policy contents worth stealing from the Playbook PDF include terms and intended uses, existing governance, and data-governance alignment. Add experimental-design and training standards, mapping and measurement, model testing and validation, and legal and risk review.

Also write down frequency and detail for monitoring, auditing, and review. Add change management, stakeholder engagement, whistleblower paths, and incident-response plans that you actually test.

Evidence that would count: a one-page charter (purpose, scope, risk tolerance, escalation), a named executive owner per GOVERN 2.3, and a documented RACI per GOVERN 2.1. Add training records per GOVERN 2.2 and an inventory system per GOVERN 1.6.

Categories in the Core behave like control objectives. Subcategories behave like control activities. They are not the 20 families in SP 800-53.

Map

Write the context down before you train or buy. MAP 1.1 wants intended purposes, beneficial uses, applicable laws and norms, and prospective settings on paper first.

Face recognition unlocking a phone, clearing an airport lane, and feeding a law-enforcement case file are three different appetites. The Core does not pick your appetite. You do, in writing, with the exec owner from GOVERN 2.3 on the signature line.

If you cannot name the system, you cannot map it. Inventory (GOVERN 1.6) belongs before Map, including vendors, fine-tunes, agents, and the shadow tools your AI solutions stack already quietly bought.

An inventory row should carry purpose, data classes, owners, deployment venue, and residual-risk status. Evidence that would count: a context brief per system, a data-flow sketch, a third-party or model-card pointer, and a mapped list of which trustworthy characteristics are in scope versus explicitly out of scope.

Measure

Programs stall here. MEASURE 1.1 says you select metrics starting with the most significant AI risks, and you document what you will not measure. NIST does not publish pass/fail thresholds for you.

Playbook Measure language: document TEVV test sets, metrics, and tools. Track go/no-go and accountability roles.

Post-deployment TEVV covers validity, bias, privacy, and security, not a one-time eval spreadsheet. If you already run LLM observability (traces, quality scores, cost, drift), that instrumentation is the MEASURE runtime. The AI RMF does not replace it.

Evidence that would count: a TEVV plan, versioned test sets, a signed record of what was not measured, pre-deployment scores, and a monitoring spec with owners. Screenshots in a share folder are not a TEVV record.

Manage

Treatment without a kill switch is theater. MANAGE 1.1 is a documented determination of whether the system achieves its intended purposes and whether development or deployment should proceed. MANAGE 1.3 is mitigate, transfer, avoid, or accept.

MANAGE 2.4 is the kill switch: supersede, disengage, or deactivate when outcomes drift from intended use. GOVERN 1.7 covers decommissioning that does not raise residual risk.

Playbook Manage language adds post-deployment monitoring, incident response, and recovery. Cadence here is yours to set (GOVERN 1.5). NIST does not hand you a universal interval.

Evidence that would count: a go/no-go memo, residual-risk sign-off, an incident ticket that names the AI system, a tested rollback, and a decommission ticket. If nobody can deactivate the system on a named clock, you do not have MANAGE 2.4.

The Playbook: Suggested Actions, Not a Checklist

The NIST AI RMF Playbook is the how-to companion to Tables 1-4. Playbook FAQs (updated 18 March 2025) say it is not one-size-fits-all, and it is neither a checklist nor an ordered list of steps.

You are not expected to implement every suggestion. Comments are reviewed semi-annually.

Use the Playbook as suggested actions your team can turn into tickets. Do not retitle your internal wiki “the NIST playbook.”

Vendor “72-control self-assessments” and Notion templates are unofficial overlays. They can be useful as a prompt. They are not NIST.

Link the AIRC Playbook, not a PDF download. The PDF is a snapshot. NIST patches suggested actions in the HTML.

The Generative AI Overlay: NIST AI 600-1

Published 26 July 2024, NIST AI 600-1 is a cross-sectoral profile of AI RMF 1.0 for generative AI. A profile instantiates Core functions, categories, and subcategories for a setting or technology.

Not every 1.0 subcategory is included. Action IDs are GV, MP, MS, and MG. Do not cite the withdrawn initial public draft.

600-1 lists 12 GAI-exacerbated risks: CBRN information and capabilities; confabulation (NIST’s preferred term over “hallucination”); dangerous, violent, or hateful content; data privacy; environmental impacts; and harmful bias or homogenization.

The remaining six are human-AI configuration; information integrity; information security; intellectual property; obscene, degrading, or abusive content (including CSAM and NCII); and value-chain / component integration. Name the abusive-content category. Do not turn CSAM or NCII handling into product-runbook steps here.

If you ship LLMs, copilots, or content-generating features, layer 600-1 actions on the same four functions. It does not replace 1.0.

EO 14110 is why the profile exists. EO 14110 is not current federal AI policy.

600-1 restates GOVERN 1.5, GOVERN 1.6, GOVERN 2.1, and MEASURE 1.1 in GAI action tables. That is a second official witness of those sentences. It still does not cover autonomous tool-use and delegation well.

Agentic project management and MCP access-control design sit in that gap. Treat agents as identities with a named human owner and tighter least privilege than a person, then map them in GOVERN 1.6. Do not wait for a future “agent profile” before you inventory them.

Do not conflate 600-1 with the CSA Agentic Profile, NCCoE Cyber AI work, or IR 8596. Those are cyber-shaped. 600-1 is a GenAI overlay on the AI RMF.

Roles, Controls, Evidence, and Cadence

This is the hole the glossary pages leave. The Core tells you outcomes. You still have to name who does the work, what artifact would satisfy an auditor asking about a specific action, and how often you re-open the file.

The interval below is an operating example. It is not a NIST-mandated clock.

GOVERN 1.5 requires a defined frequency. The Playbook treats monitoring and audit frequency as a policy field. You pick the number and write it down.

  • Inventory (GOVERN 1.6) before Map. No row, no risk rating.
  • Charter plus executive owner (GOVERN 2.3) before any go/no-go.
  • Documented review frequency (GOVERN 1.5) in the policy, including who can change it.
  • Pre-deployment TEVV, then MANAGE 1.1 proceed or stop.
  • Post-deployment monitoring from the Playbook Manage actions, and deactivate authority (MANAGE 2.4 / GOVERN 1.7).
  • For generative systems, layer 600-1 actions on the same four functions. Retest after model updates, not on a calendar that ignores deploys.

On r/grc, the recurring failure is a policy PDF plus a vendor questionnaire, then silence when someone asks whether this agent was allowed to touch that dataset yesterday. Overlay the AI RMF on the register you already run (ISO 27001, CSF, internal ERM). Do not clone a second program that nobody staffs.

Artifact

Function hook

What it proves

System inventory row / AI-BOM

GOVERN 1.6

The system exists, with owner, purpose, data, venue

Charter (purpose, scope, tolerance, escalation)

GOVERN 2.3, MAP 1.1

Someone accepted the context

RACI plus training record

GOVERN 2.1, 2.2

Named humans, not a committee alias

TEVV plan and versioned test sets

MEASURE 1.1

What you measured, and what you refused to measure

Go/no-go memo

MANAGE 1.1

A decision, with a date and a signer

Residual-risk sign-off

MANAGE 1.3

Mitigate / transfer / avoid / accept, chosen in writing

Monitoring spec plus rollback

GOVERN 1.5, MANAGE 2.4

Cadence and a kill switch that has been tested

Decommission ticket

GOVERN 1.7

You can turn it off without raising residual risk

Build continuous evidence before an auditor asks. A pre-audit scramble that reconstructs intent from Slack is not GOVERN.

Dedicated GRC and CNAPP tools can automate inventory and evidence collection. They are not a substitute for the named owner and the written cadence.

Where It Sits Against ISO 42001, the EU AI Act, CSF, and OMB

On r/grc, questionnaires treat NIST AI RMF, ISO 42001, and the EU AI Act as interchangeable. They are not.

Instrument

What it is

What it is not

Who it binds

NIST AI RMF 1.0 (AI 100-1)

Voluntary US risk operating system

A law, a cert, a checklist, SP 800-37

Nobody, unless a contract says so

ISO/IEC 42001:2023

Certifiable AI management system (Edition 1, 18 December 2023)

A substitute for a legal regime

Organizations that choose certification

EU AI Act (Regulation 2024/1689)

Binding product law

A framework you “adopt”

Providers and deployers in scope of the Act

NIST CSF 2.0

Cybersecurity outcomes

Coverage of bias, GAI content risks, off-label ML

Cyber programs that adopt it

M-25-21 / M-25-22

Current OMB federal AI memos

“The AI RMF is mandatory for agencies”

US federal agencies (with stated exemptions)

ISO 42001 is Type A and jurisdiction-neutral. It does not replace laws. IAPP puts it plainly: it may not be a golden ticket for organizations that need to meet a specific legal regime.

An AIRC-hosted 42001 crosswalk PDF still carries an FDIS title. Treat it as a mapping aid. Do not treat it as a certification shortcut, and do not assume NIST authored every PDF sitting on AIRC.

The EU AI Act entered the OJ as Regulation 2024/1689 (13 June 2024; OJ 12.7.2024). Prohibitions, definitions, and AI-literacy duties applied from 2 February 2025. Governance, penalties, and GPAI-provider obligations applied from 2 August 2025.

Commission evaluation is due by 2 August 2028. Article 40 lets harmonised standards create a presumption of conformity for high-risk systems. ISO 42001 is not EU AI Act compliance.

US teams selling into the EU can reuse RMF evidence. That evidence is not conformity.

Contracts may still incorporate framework terms even when a state bill dies. Colorado’s 2024 AI Act was repealed before taking effect.

H.R. 6936 died with the 118th Congress (introduced, not enacted). Read the contract, not last year’s tracker.

Federal Agencies: Current OMB, Not a Renamed RMF

If you work in a US federal agency, your binding text is M-25-21 and M-25-22, not 100-1.

Hunton’s April 2025 decode is a useful companion to the PDFs. The memos put a Chief AI Officer on a 60-day clock and CFO Act AI Governance Boards on a 90-day clock. A barrier-removal strategy sits on a 180-day clock, plus an annual public inventory.

M-25-21 high-impact AI that is not performing must have a plan to discontinue until compliance. If mitigation is impossible, cease use. Independent review of high-impact use cases is required before risk acceptance, and agencies must track those cases centrally.

Each agency retains or designates a Chief AI Officer. CFO Act agencies convene an AI Governance Board.

Agencies publish an AI use-case inventory, adopt a Generative AI policy, implement minimum risk-management practices for high-impact uses, and report determinations and waivers. Sections 4(a)-(b) do not apply to Intelligence Community elements.

“Risks from the use of AI” in M-25-21 means efficacy, safety, fairness, transparency, accountability, appropriateness, or lawfulness of a decision or action. The memo explicitly does not include every AI risk. It carves out, for example, privacy, security, and confidentiality of training data and model inputs.

High-impact, in the memo, is output that serves as a principal basis for decisions or actions with legal, material, binding, or significant effect on rights, safety, critical services, or listed program access. Confirm the full definition and minimum-practice list against the PDF before you quote them as complete. National security systems are carved out.

M-25-22 governs acquisition. The memo applies to contracts awarded from solicitations issued on or after 180 days from its 3 April 2025 issuance, which is 1 October 2025.

M-25-21 does not require you to adopt the AI RMF as a mandatory operating system. The extracted memos do not name it that way.

The DNA overlap is real. The citation is the memo.

EO 14409 (2 June 2026) is about cyber defense of national security systems, not an AI RMF revision.

Common Implementation Mistakes to Avoid

Treating the AI RMF as the seven steps of SP 800-37

Search results still leak “7 steps of RMF” into AI-RMF queries. Those steps belong to SP 800-37.

If your implementation plan is Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor, you are running the classic RMF. Map it if you are a federal authorizer. It does not paste onto 100-1.

Collecting a certificate that NIST does not issue

“Is there a NIST AI RMF certification?” is the most repeated follow-up around this query. No. NIST does not operate a certification scheme against the AI RMF.

Third-party courses in a .gov catalog (including CISA NICCS listings) are training products, not a NIST credential. If a customer needs a certifiable AIMS, that is ISO/IEC 42001.

Writing policy and skipping inventory

On r/ciso, the recurring line is visibility first: you cannot classify risk on systems you have not listed. GOVERN 1.6 is the unglamorous first control.

Shadow LLM use is the new shadow IT. Blocking consumer domains without an official alternative just moves the work onto phones.

Publishing an “AI RMF 2.0” runbook

Some 2025 vendor posts claimed 2.0 shipped in February 2024. That date lines up with CSF 2.0, not the AI RMF.

As of the 13 August 2026 FAQ update, 1.0 is current and under revision. Do not date your controls to a version that does not exist.

Scoring unofficial 72-row checklists as if they were NIST

Vendor “72-control” self-assessments and Notion templates are unofficial overlays. The Core’s four functions and 19 categories are outcomes, not a scored control set. Useful as a prompt, fatal as “we are NIST-compliant.”

Swapping RMF, 42001, and the EU AI Act in a vendor questionnaire

One is voluntary guidance. One is a certifiable management system. One is legislation.

A completed 42001 audit does not control runtime behavior. An RMF profile does not create a presumption of conformity under Article 40.

Tags
Artificial Intelligence

Frequently Asked Questions

Keep thinking with

ChatGPTPerplexityGrokClaudeGoogle
Tomas Laurinavicius

Tomas Laurinavicius

AI & Growth Engineer, Partner at Craftled

Tomas builds AI-native software and media products at Craftled, including Bordfeed, Epigraph Media and Laupix, a fully autonomous zero-human company. He writes about AI from the builder's seat, not the sidelines.

TwitterLinkedInWebsite
View Profile

Contributors

Laupix
Laupix
Agent
5Views
Advertise here

Get the latest product news and behind the scenes updates.

Related Articles

Abstract light installation resembling a control plane of connected points
September 13, 2026

ChatGPT Enterprise Starts With the Control Plane

Buyer and implementation guide for ChatGPT Enterprise: controls, SSO/SCIM, residency, HIPAA boundary, and a 12-step rollout.

Tomas Laurinavicius
Tomas Laurinavicius
Read
Enterprise leaders around a conference table reviewing strategy
September 11, 2026

Why Does Enterprise AI Stall? A Portfolio Playbook

Run enterprise AI as a Fund, Defer, or Kill portfolio. Covers operating models, platform layers, shadow AI, and conflicting ROI numbers.

Tomas Laurinavicius
Tomas Laurinavicius
Read
Team reviewing strategy at a whiteboard during a working session
September 10, 2026

AI Governance Built on Owners, Inventory, Cadence

AI governance is named owners, written policy, risk-tiered approvals, a living inventory, and a review cadence that continues after go-live.

Tomas Laurinavicius
Tomas Laurinavicius
Read
AI Turnpoint LogoAI Turnpoint logo alternative

Discover the breakthroughs, tools, and ideas shaping the next era of artificial intelligence. Learn how AI agents, large language models, and automation are transforming how products are built, businesses operate, and individuals work.

LinkedIn
Resources
NewsletterBrand GuidelinesAboutContact
Explore
CategoriesAuthorsTags
Legal
Privacy PolicyTerms of Service

Get the latest product news and behind the scenes updates.

2026 © AI Turnpoint. AI, agents and the future of software. Standing on the shoulders of giants.Epigraph Media NetworkPart of the Epigraph Media Network