The NIST AI Risk Management Framework (AI RMF 1.0) was published in January 2023 as a voluntary framework. Two years on, it is no longer optional in practice. Federal agencies, state legislators, procurement teams, and corporate boards treat it as the baseline for responsible AI governance. If your organisation deploys, develops, or procures AI systems, the NIST AI framework is the document you will be measured against.
This guide goes beyond a summary. It explains the four core functions in operational detail, demystifies NIST AI RMF profiles, maps the framework to the EU AI Act for organisations operating across both jurisdictions, and lays out a concrete implementation plan.
À retenir
- The NIST AI RMF organises AI risk management around four functions: Govern, Map, Measure, and Manage
- Profiles let organisations tailor the framework to their specific risk context, sector, and maturity level
- The framework aligns closely with the EU AI Act — implementing one accelerates compliance with the other
- Workforce AI competency (Govern function) is the most common gap and the fastest to close
Why the NIST AI framework matters now
The NIST AI framework is voluntary. But “voluntary” is misleading. In the US regulatory landscape, NIST frameworks have a long history of becoming the de facto standard that regulators, courts, and insurers use to define reasonable care. The Cybersecurity Framework followed the same trajectory — and the AI RMF is moving faster.
83%
of Fortune 500 companies now reference the NIST AI RMF in their AI governance documentation
Source : Accenture AI Governance Index, 2025
Three forces are accelerating adoption:
- State legislation. The Colorado AI Act (effective 2026) explicitly requires “reasonable care” in high-risk AI deployment — and cites NIST AI RMF concepts as the benchmark. Other states are following.
- Federal procurement. Executive Order 14110 directed federal agencies to adopt the NIST AI RMF. If you sell to the US government, compliance is a contractual expectation.
- Cross-border convergence. The EU AI Act is legally binding. Organisations that implement the NIST AI RMF find they have already completed a significant portion of their EU compliance work.
The four core functions explained
The NIST AI RMF is structured around four functions. They are not steps in a sequence — they operate concurrently and iteratively throughout the AI system lifecycle.
Govern: the organisational foundation
Govern is the only function that spans all the others. It establishes the policies, roles, culture, and competencies that make AI risk management possible.
What Govern requires in practice:
- AI governance structure. A designated committee or lead with authority over AI risk decisions. This is not a suggestion — without clear accountability, the other three functions collapse.
- Policy framework. A documented AI policy covering acceptable use, procurement, data handling, and incident response.
- Workforce competency. All staff interacting with AI systems need appropriate AI training. This is not limited to technical teams. The NIST framework explicitly calls out the need for organisation-wide AI literacy — the same requirement the EU AI Act mandates in Article 4.
- Third-party risk management. Your AI risk profile includes every vendor, SaaS tool, and API that uses AI. Govern requires you to identify and manage those dependencies.
- Stakeholder engagement. Affected communities and end users should have meaningful input into AI system design and deployment.
The Govern function is where most organisations stall. Not because governance is technically difficult, but because it requires executive sponsorship, cross-functional coordination, and cultural change. Start here — everything else depends on it.
Map: understanding your AI landscape
Before you can measure or manage risk, you need a complete picture of your AI exposure. The Map function builds that picture.
Key activities:
- AI inventory. Catalogue every AI system in your organisation — including tools embedded in SaaS platforms, browser extensions, and unofficial tools adopted by teams. Shadow AI is a real and growing risk that Map is designed to surface.
- Context documentation. For each system, document who uses it, what decisions it informs, what data it processes, and who is affected by its outputs.
- Risk identification. Identify potential harms across multiple dimensions: individual harm (discrimination, privacy violation), organisational harm (legal liability, reputational damage), and societal harm (systemic bias, environmental impact).
- Benefits mapping. Risk management is not risk elimination. Map also documents the benefits each AI system delivers, enabling proportionate responses.
Measure: quantifying AI risk
The Measure function turns qualitative risk identification into quantifiable, trackable metrics. This is where many AI risk assessment programmes differentiate themselves.
Core measurement areas:
- Validity and reliability. Does the AI system perform as intended, consistently, across the conditions it will encounter?
- Fairness and bias. Are outputs equitable across demographic groups? This requires structured testing, not assumptions.
- Transparency and explainability. Can you explain how the system reaches its outputs to the people affected by them?
- Security and resilience. How does the system respond to adversarial inputs, data poisoning, or infrastructure failures?
- Human oversight effectiveness. When a human is in the loop, are they actually capable of overriding or correcting the AI system? Or is oversight nominal?
61%
of organisations report they lack the metrics infrastructure to properly measure AI risk
Source : MIT Sloan AI Risk Report, 2025
Manage: closing the loop
Manage takes the risks identified in Map and quantified in Measure and applies controls, monitoring, and response mechanisms.
Operational requirements:
- Risk treatment plans. Each identified risk gets a documented mitigation — technical controls, procedural safeguards, or organisational measures.
- Continuous monitoring. AI systems drift. Data distributions shift. Models degrade. Manage requires ongoing monitoring with defined thresholds that trigger review.
- Incident response. Documented playbooks for AI failures, bias incidents, security breaches, and harmful outputs.
- Decommissioning. When an AI system no longer meets performance or risk standards, there must be a clear process for retiring it safely.
Understanding NIST AI RMF profiles
Profiles are one of the least understood — and most useful — elements of the NIST AI framework. A profile is a customised selection of framework outcomes tailored to a specific context.
NIST has published several use-case profiles, including:
- Generative AI profile (NIST AI 600-1). Addresses risks specific to large language models and generative systems, including hallucination, data provenance, and intellectual property concerns.
- AI RMF Playbook. Provides suggested actions and references for each subcategory of the framework.
Organisations create their own profiles by selecting the framework subcategories relevant to their risk context, regulatory obligations, and maturity level. A healthcare organisation deploying clinical decision support will have a very different profile from a retail company using AI for demand forecasting.
Think of it this way: the NIST AI RMF is the full menu. Your profile is your order — tailored to your appetite, dietary requirements, and budget.
Mapping NIST AI RMF to the EU AI Act
For organisations operating across jurisdictions, the alignment between the NIST AI framework and the EU AI Act is a significant advantage. Both frameworks share the same core logic: identify risks, implement proportionate controls, maintain oversight, and document everything.
| NIST AI RMF | EU AI Act | Practical overlap |
|---|---|---|
| Govern (workforce competency) | Article 4 (AI literacy) | AI competency programmes satisfy both |
| Map (risk identification) | Article 6 + Annex III (risk classification) | AI inventory and risk mapping align directly |
| Measure (bias testing, transparency) | Articles 9-10 (risk management, data governance) | Testing methodologies are interchangeable |
| Manage (monitoring, incident response) | Articles 13-14 (transparency, human oversight) | Monitoring infrastructure serves both |
The key difference remains enforcement. The EU AI Act carries penalties of up to 35 million euros or 7% of global turnover. The NIST AI RMF carries no direct penalties — but failing to follow it increasingly exposes organisations to liability claims based on negligence.
If you are already working towards EU AI Act compliance, map your existing controls to the NIST AI RMF subcategories. You will likely find you are 60-70% of the way there. The same logic applies in reverse. A dual-compliance approach saves significant time and budget.
How the NIST AI framework connects to other standards
The NIST AI RMF does not exist in isolation. It sits within a broader ecosystem of AI governance frameworks:
- ISO 42001 provides a certifiable AI management system. The NIST AI RMF provides the risk management methodology that fits inside it.
- Trustworthy AI frameworks (OECD, IEEE) define principles. The NIST AI RMF operationalises them.
- UK AI regulation follows a sector-specific, principles-based approach. The NIST AI RMF provides a structured way to demonstrate compliance with those principles.
- AI governance frameworks at the organisational level use the NIST AI RMF as their risk management backbone.
A practical implementation path
Here is how to get started, regardless of your organisation’s size or AI maturity.
Week 1-2: Executive alignment. Secure sponsorship. Define scope. Appoint a governance lead.
Week 3-4: AI inventory. Catalogue all AI systems. Include shadow AI. Prioritise by risk level.
Week 5-6: Gap assessment. Map your current controls against NIST AI RMF subcategories. Identify gaps.
Week 7-8: Profile creation. Build your organisation’s NIST AI RMF profile — the specific subcategories relevant to your context.
Week 9-12: Control implementation. Close priority gaps. Launch AI training for workforce competency. Establish monitoring.
Ongoing: Iterate. The NIST AI RMF is designed for continuous improvement. Review quarterly. Update as your AI portfolio evolves.
Build your NIST AI framework foundation with Brain
The NIST AI RMF’s Govern function makes workforce competency a governance requirement — not a nice-to-have. Brain delivers role-specific AI training that builds the AI literacy the framework demands. From AI awareness for all staff to governance-specific modules for compliance teams, every session is tracked and documented for audit purposes.
Whether you are implementing the NIST AI RMF, preparing for the EU AI Act, or building a comprehensive AI governance framework, workforce readiness is the foundation.
Related articles
AI Governance + Compliance: Unified Framework (GDPR, AI Act, NIST)
Integrate AI governance with GDPR and EU AI Act compliance in one framework. NIST AI RMF mapping, audit-ready checklist, real implementation playbook.
NIST AI Framework: Implementation Guide in 5 Steps
Implement the NIST AI Risk Management Framework step by step. 4 core functions, EU AI Act alignment and practical templates.
AI Governance Framework: 7-Step Checklist + ISO 42001 Template
Build your AI governance framework in 7 steps. Free checklist, ISO 42001 alignment, EU AI Act mapping, and the 4 governance principles that matter.