United States - AI Risk Management Framework
Artificial Intelligence Risk Management Framework (AI RMF 1.0)
United States
RAI-US-NA-AIRMAXX-2023Voluntary NIST framework (AI RMF 1.0) for managing AI risk across govern, map, measure and manage functions. (nvlpubs.nist.gov)
Summary
NIST AI RMF 1.0 (published Jan 26, 2023) is voluntary, cross‑sector guidance that helps organizations govern, map, measure and manage risks from AI across the AI lifecycle to promote trustworthy, rights‑preserving AI aligned with standards and best practices. ([nvlpubs.nist.gov](https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf))
Full article
Read full text ↗Overview
The National Institute of Standards and Technology (NIST) published the Artificial Intelligence Risk Management Framework (AI RMF 1.0; NIST AI 100-1) on 2023-01-26 as voluntary, non‑sector specific guidance to help organizations that design, develop, deploy, procure, operate, evaluate, or acquire AI systems identify and manage harms and benefits across the AI lifecycle. The Framework was produced pursuant to the National Artificial Intelligence Initiative Act of 2020 and developed through public comment, workshops, and iterative drafts. NIST describes the AI RMF as a living document that will be reviewed periodically. The full Framework text is available from NIST: https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf.
Definitions
This section summarizes key terms and concepts as used in AI RMF 1.0. Where the Framework does not provide an exhaustive glossary, the following items capture central, operational definitions used throughout the Framework document and companion resources.
- AI RMF (Artificial Intelligence Risk Management Framework): Voluntary guidance published by NIST to support organizations in identifying, measuring, managing, and governing risks associated with AI systems across their lifecycle.
- Core functions: The Framework’s operational core is organized into four high‑level functions — GOVERN, MAP, MEASURE, and MANAGE — which represent categories of activities and outcomes intended to support systematic risk management across lifecycle stages.
- Trustworthiness characteristics: Attributes that the Framework identifies as desirable in AI systems, including being valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy‑enhanced; and fair with harmful bias managed. The Framework also addresses tradeoffs among these attributes.
- Profile: A context‑specific instantiation of the Framework functions, categories, and subcategories intended to help organizations tailor the RMF to particular use cases, sectors, or operational constraints.
- Playbook (AIRC Playbook): A companion implementation resource maintained by NIST’s Trustworthy & Responsible AI Resource Center (AIRC) that maps concrete implementation suggestions to Framework subcategories and provides tools, examples, and crosswalks.
Governance and Institutional Framework
NIST, an agency within the U.S. Department of Commerce, authored AI RMF 1.0 pursuant to congressional direction in the National Artificial Intelligence Initiative Act of 2020. The Framework itself is voluntary guidance rather than binding law or regulation, but NIST’s role is to support standards development, measurement research, and coordinated risk‑management approaches. The document was produced through a process of public engagement (requests for comment, workshops, and iterative drafts) and NIST commits to periodic review and versioning of the Framework. While the RMF imposes no direct statutory obligations, federal agencies, contractors, and private sector entities commonly reference or adopt NIST guidance when implementing policy, procurement requirements, grant terms, or rulemaking. Consequently, the institutional influence of NIST materials can translate into expectations that affect regulatory practice and contracting behavior.
Key Focus Areas
- Core functions (operational organization): GOVERN, MAP, MEASURE, and MANAGE are the Framework’s primary organizing functions; each is broken into categories, subcategories, and example activities to guide practical risk‑management outcomes across AI lifecycle stages. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
- Trustworthiness characteristics: The Framework defines and discusses attributes of trustworthy AI systems (valid & reliable; safe; secure & resilient; accountable & transparent; explainable & interpretable; privacy‑enhanced; fair with harmful bias managed) and explains how organizations should consider tradeoffs among them. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
- Implementation resources — Profiles and Playbook: NIST encourages the development of Profiles (context‑specific Framework instantiations) and provides a companion Playbook with implementation suggestions mapped to subcategories; NIST hosts the Playbook and an AI Resource Center (AIRC) with use cases, crosswalks, and tools to operationalize the Framework. https://airc.nist.gov/airmf-resources/playbook/
- Measurement and TEVV emphasis: The Framework emphasizes measurement, test, evaluation, verification and validation (TEVV) and socio‑technical methods to identify harms, verify outcomes, and support evaluation across lifecycle stages.
- Living framework and versioning: NIST commits to periodic updates and uses a two‑number major.minor versioning system (for example, 1.0, 1.1); NIST stated a formal community review is expected no later than 2028, and the Playbook will be updated more frequently. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
Implementation Framework
The Framework provides a structured approach to operationalize AI risk management through Profiles, Playbook guidance, and examples mapped to the four core functions. Organizations are encouraged to adopt or adapt Profiles that reflect specific mission, sector, use case, or operational constraints; to consult the AIRC Playbook for concrete implementation tactics; and to integrate practices for TEVV and socio‑technical assessment into testing, deployment, and monitoring processes. NIST’s Playbook and AIRC host tools, crosswalks to standards, use cases, and downloadable resources that organizations can apply to create measurable outcomes tied to GOVERN, MAP, MEASURE, and MANAGE activities. The Framework is intended to complement existing sectoral regulations and standards rather than replace them, and to be adaptable for organizations of varied size and maturity.
Monitoring and Evaluation
The AI RMF emphasizes continuous monitoring, measurement, and evaluation across lifecycle stages (planning, design, development, testing/evaluation, deployment, monitoring, and retirement). Key monitoring and evaluation elements in the Framework include: defining measurable risk outcomes; conducting TEVV (test, evaluation, verification and validation) to support claims about system behavior; using socio‑technical methods to detect harms and tradeoffs; and updating Profiles and operational practices in response to observed performance, incidents, or new evidence. NIST’s companion materials and Roadmap identify priorities for TEVV expansion and provide crosswalks linking RMF concepts to technical standards and evaluation methods.
Penalties, Liability, and Appeals
AI RMF 1.0 is voluntary guidance and does not itself create penalties, liability rules, or an appeals process. There are no enforcement mechanisms tied directly to the Framework. However, enforcement and binding requirements can arise indirectly where federal agencies or other authorities incorporate RMF concepts into legally binding documentation—such as procurement contracts, grant conditions, certification schemes, or regulatory requirements—and those instruments may include penalties, contract remedies, or administrative processes. Organizations should therefore be aware that voluntary adoption of RMF concepts can be incentivized or effectively required through procurement, funding conditions, or sectoral regulation that references NIST guidance. For primary legislative authority relevant to NIST’s role, see the National Artificial Intelligence Initiative Act of 2020 (Pub. L. No. 116-283). https://www.congress.gov/bill/116th-congress/house-bill/6216/text
Relationship to Other Instruments
The AI RMF is designed to complement, not replace, existing sectoral regulations, standards, and guidance. NIST has published crosswalks and a Roadmap to help align the Framework with international and sectoral standards and practices. Federal agencies, rulemaking efforts, procurement policies, and private sector governance programs have cited or relied on NIST AI RMF materials as authoritative sources for best practices; accordingly, organizations should expect that RMF concepts may be reflected in other legal or policy instruments. The Framework provides a coordination point between technical evaluation work, standards development, and policy implementation and encourages use of Profiles and Playbook resources to align organizational practices with applicable sectoral or statutory requirements. https://www.nist.gov/itl/ai-risk-management-framework/roadmap-nist-artificial-intelligence-risk-management-framework-ai
International Alignment
NIST has published companion resources and crosswalks intended to align the AI RMF with international standards and references (including ISO/IEC standards listed in NIST’s Roadmap). The Framework’s emphasis on measurement, TEVV, and socio‑technical evaluation supports interoperability with international evaluation efforts and standards development. NIST’s publications and Roadmap identify priorities for international collaboration and standardization to facilitate crosswalks between RMF concepts and existing international technical standards and normative documents.
Implementation Timeline
| Date | Event |
|---|---|
| 2023-01-26 | NIST publishes the Artificial Intelligence Risk Management Framework (AI RMF 1.0; NIST AI 100-1). https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf |
| 2023-03-30 | NIST releases the first complete AI RMF Playbook and launches the Trustworthy & Responsible AI Resource Center (AIRC). Playbook resources and downloads are available from the AIRC. https://airc.nist.gov/airmf-resources/playbook/ |
| 2024-07-26 | NIST publishes "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile" (NIST AI 600-1), a cross‑sector companion profile addressing generative AI risks. https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence |
| 2028 | NIST states a formal community review of AI RMF content is expected no later than 2028 (per the Framework’s update schedule and versioning commitments). https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf |
Sources and References
| Source | URL |
|---|---|
| NIST - Artificial Intelligence Risk Management Framework (AI RMF 1.0) (NIST AI 100-1, PDF) | https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf |
| NIST - AI Risk Management Framework (framework page and resources) | https://www.nist.gov/itl/ai-risk-management-framework |
| NIST - AI RMF Playbook (AIRC) — Playbook resources and downloads | https://airc.nist.gov/airmf-resources/playbook/ |
| NIST - Roadmap for the NIST AI Risk Management Framework (AI RMF 1.0) | https://www.nist.gov/itl/ai-risk-management-framework/roadmap-nist-artificial-intelligence-risk-management-framework-ai |
| NIST - Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1) | https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence |
| Congress.gov - Text of the National Artificial Intelligence Initiative Act of 2020 (Pub. L. No. 116-283) | https://www.congress.gov/bill/116th-congress/house-bill/6216/text |
| Federal Register / Government documents citing NIST AI RMF (example references in rulemaking and notices) | https://www.govinfo.gov/content/pkg/FR-2023-04-18/html/2023-07229.htm |
Requirements for a company
What an organisation has to do under United States - AI Risk Management Framework, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
7- Implement governance structures and accountability for AI risk management.Organizations designing, developing, deploying, or acquiring AI systems.
- Create or adopt a context-specific Framework Profile.Organizations designing, developing, deploying, or acquiring AI systems.
- Map AI system boundaries, identify potential harms, and document risk profiles.Organizations designing, developing, deploying, or acquiring AI systems.
- Consider trustworthiness characteristics like fairness, privacy, security, and transparency for AI systems.Organizations designing, developing, deploying, or acquiring AI systems.
- Develop and execute testing, evaluation, verification, and validation processes for AI systems.Organizations designing, developing, deploying, or acquiring AI systems.
- Continuously monitor deployed AI systems, investigate incidents, and update plans as needed.Organizations operating AI systems.
- +1 more in the table below
Must not do
0Nothing in this category.
Should do
1- Use the AIRC Playbook to operationalize controls, metrics, and assurance activities.Organizations implementing AI risk management.
Should not do
0Nothing in this category.
Who must do what
The obligations under United States - AI Risk Management Framework, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Organizations designing, developing, deploying, or acquiring AI systems. | Implement governance structures and accountability for AI risk management. “Implement governance structures and accountability mechanisms aligned with the GOVERN function to assign roles, responsibilities, and decision authorities.” | — | Compliance Checklist | Important |
| 2 | Organizations designing, developing, deploying, or acquiring AI systems. | Create or adopt a context-specific Framework Profile. “Create or adopt a context‑specific Profile that maps GOVERN, MAP, MEASURE, and MANAGE functions to organizational roles, assets, and use cases.” | — | Compliance Checklist | Important |
| 3 | Organizations designing, developing, deploying, or acquiring AI systems. | Map AI system boundaries, identify potential harms, and document risk profiles. “Map AI system boundaries, stakeholders, and potential harms; identify socio‑technical risk sources across lifecycle stages and document risk profiles.” | Before deploying AI systems | Compliance Checklist | Important |
| 4 | Organizations designing, developing, deploying, or acquiring AI systems. | Consider trustworthiness characteristics like fairness, privacy, security, and transparency for AI systems. “The Framework defines and discusses attributes of trustworthy AI systems... and explains how organizations should consider tradeoffs among them.” | Before deploying AI systems | Trustworthiness characteristics | Important |
| 5 | Organizations designing, developing, deploying, or acquiring AI systems. | Develop and execute testing, evaluation, verification, and validation processes for AI systems. “Develop and execute testing, evaluation, verification and validation (TEVV) processes to measure system behavior against defined outcomes and trustworthiness characteristics.” | Before deploying AI systems | Compliance Checklist | Important |
| 6 | Organizations operating AI systems. | Continuously monitor deployed AI systems, investigate incidents, and update plans as needed. “Continuously monitor deployed systems, collect telemetry and performance data, investigate incidents, and update Profiles, controls, and TEVV plans as needed.” | — | Compliance Checklist | Important |
| 7 | Organizations implementing AI risk management. | Maintain documentation of risk assessments, TEVV results, governance decisions, and mitigation actions. “Maintain documentation of risk assessments, TEVV results, governance decisions, and mitigation actions to support internal accountability.” | — | Compliance Checklist | Important |
| 8 | Organizations implementing AI risk management. | Use the AIRC Playbook to operationalize controls, metrics, and assurance activities. “Use AIRC Playbook implementation suggestions and tools mapped to subcategories to operationalize controls, metrics, and assurance activities.” | — | Compliance Checklist | Recommended |
Related Regulations
NIST AI RMF Profile for Trustworthy AI in Critical Infrastructure
United States96% similar
Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile
United States95% similar
Cybersecurity Framework Profile for Artificial Intelligence (NISTIR 8596)
United States94% similar
Executive Order: Ensuring National AI Policy Framework (December 2025)
United States93% similar
RAISE Act (Responsible AI Safety and Evaluation Act)
United States92% similar
© Regulations.AI · updated on 13-Jun-2026