What Is the NIST AI Risk Management Framework? A Plain-English Guide
The NIST AI Risk Management Framework (AI RMF) is a voluntary guide for managing the risks an AI system creates. The National Institute of Standards and Technology published it on January 26, 2023, as document NIST AI 100-1. It gives any organization a structure for spotting, judging, and managing the risks an AI system poses to people, to the business, and to the public.
NIST didn’t write it alone. That breadth is part of why so many businesses, auditors, and even insurers now treat it as a common reference point for “did you take AI risk seriously.”
Here’s the catch. The AI RMF is voluntary at the federal level, not a law. NIST does not certify anyone against it, so no company can accurately claim to be “NIST AI RMF certified.” But voluntary doesn’t mean optional in practice, and the next section explains why.
Who Has to Follow the NIST AI RMF?
Nobody is legally forced to adopt the NIST AI RMF itself. It’s written to apply to any organization, of any size, in any sector. It applies whether you:
- Build your own AI models or tools
- Buy an off-the-shelf AI product
- Deploy AI inside an existing workflow or app
The framework covers the whole AI lifecycle, from design through retirement, so it doesn’t matter which of those three describes your business. If AI touches your operation at all, the framework was written with you in mind.
Even though nobody has to follow it, it’s showing up in places that matter. Vendor contracts increasingly ask whether you follow a recognized AI risk framework. Cyber-insurance applications are starting to ask the same question. A “voluntary” framework that your insurer or your biggest client expects you to follow isn’t really optional.
Federal agencies got a harder push. OMB Memorandum M-24-10 requires every federal agency to name a Chief AI Officer. Agencies must also stand up an AI Governance Board. And they must apply minimum risk-management practices to any AI that affects someone’s rights or safety.
The AI RMF is not a law, and NIST doesn’t certify anyone against it. Its real influence comes from contracts, insurers, and state laws that point to it as the expected baseline.
The Four Functions: Govern, Map, Measure, Manage
The framework’s Core is organized into four functions: Govern, Map, Measure, and Manage. Each one answers a different question about your AI risk.
Govern: The Foundation Everything Else Sits On
Govern is the foundation. It covers your policies, who’s accountable, and how much risk your business is willing to accept. Say a business owner lets an employee use a free AI writing tool for client emails. Without a Govern function, nobody decided that was okay, nobody tracked that it was happening, and nobody owns the risk if the tool leaks client data. Govern is what would have caught that before it started.
Map: Understand the Risk Before You Act
Map comes before you build or measure anything. It asks what the AI system is actually for, where it will run, and what could go wrong. A landscaping company considering an AI scheduling tool would use Map to ask what customer data the tool sees, and what happens if it gets a job estimate wrong. Map turns those questions into an honest go or no-go decision, before the tool goes live.
Measure: Test the System Against What Matters
Measure is where you actually test the AI system. NIST lists trustworthiness characteristics to test against:
- Validity and reliability
- Safety
- Security and resilience
- Transparency and explainability
- Accountability
- Fairness and bias
- Privacy
- Environmental impact
A medical billing company using AI to flag insurance claims would measure how often it flags the wrong claim, not just whether it works most of the time. Testing doesn’t stop at launch, either. A system that passed a pre-launch test can still drift once it’s running in production.
Manage: Act on What You Found
Manage is where you act on what Map and Measure found. You prioritize risks by how likely they are and how much damage they’d cause. Then you pick a response: fix it, insure against it, avoid it, or accept it. Manage also covers what happens when something goes wrong, including incident response and recovery. And it feeds lessons back into Govern, so the next round is better than the last.
| Function | What It Does | Business Example |
|---|---|---|
| Govern | Sets policy, accountability, and risk tolerance | Deciding whether employees can use free AI tools with client data |
| Map | Builds context before you act | Checking what customer data a new AI scheduling tool touches |
| Measure | Tests the system against trustworthiness characteristics | Tracking how often an AI claims-review tool flags the wrong claim |
| Manage | Acts on what Map and Measure found | Choosing to fix, insure against, avoid, or accept a flagged risk |
How the Four Functions Work Together
Govern isn’t a separate step you finish and move past. NIST describes it as “infused throughout” the other three functions. Weak governance undermines Map, Measure, and Manage, no matter how well you execute each one on its own.
The four functions also aren’t a straight line. You don’t finish Govern, move to Map, and never look back. Most organizations cycle through Map, Measure, and Manage repeatedly, for every AI system and every stage of its life. A tool that passed Measure at launch may need to go through Measure again after a software update, or after employees start using it in a new way.
The Generative AI Profile: What Changed When ChatGPT-Style Tools Arrived
NIST published a companion document on July 26, 2024. It’s called the Generative AI Profile, or NIST AI 600-1.
The original AI RMF covers any kind of AI system. The Generative AI Profile applies the same four functions: Govern, Map, Measure, Manage. It focuses those functions on risks specific to generative tools, like chatbots and image generators. Those risks include:
- Confabulation, when a model states something false with total confidence (often called “hallucination”)
- Data privacy leakage through model outputs
- Harmful content generation
Does your business use a tool like ChatGPT, Copilot, or Gemini? The Generative AI Profile is the more directly relevant document for you. It doesn’t replace the core framework. It adds a lens on top of it.
Why “Voluntary” Doesn’t Mean Optional in Practice
We already covered OMB M-24-10’s push for federal agencies. But federal agencies aren’t the only ones feeling pressure to adopt the framework.

State legislatures have started writing NIST AI RMF references directly into law. Colorado’s original AI Act, SB 24-205, is a clear example of the pattern. It offered businesses an affirmative defense against state enforcement. That defense applied if they were following the NIST AI RMF or an equivalent framework.
That specific provision didn’t survive. Colorado repealed SB 24-205. The new law takes a narrower, disclosure-based approach. It also dropped the NIST-linked safe harbor.
But the underlying pattern hasn’t gone away. State lawmakers keep pointing to named frameworks like the AI RMF. It’s becoming their yardstick for whether a business took AI risk seriously.
Private businesses feel this pressure indirectly, through three channels:
- Regulators. The FTC can use its unfairness and deception authority against AI-related harms, even without a new AI law.
- Contracts. Larger clients and partners are starting to ask vendors to attest to an AI governance framework before signing.
- Insurance. Cyber-insurance underwriters are beginning to ask about AI governance, the same way they already ask about MFA and backups.
Since the AI RMF is voluntary, NIST doesn’t fine anyone for skipping it. The exposure is indirect. But it’s real.
The Governance Gap: Most Businesses Are Using AI Faster Than They’re Managing It
Adoption is outpacing governance almost everywhere. ISACA’s 2026 AI Pulse Poll surveyed more than 3,400 digital trust professionals worldwide in May 2026. It found a wide gap between AI use and AI policy.
| AI Policy Status | Share of Organizations |
|---|---|
| Formal, comprehensive AI policy | 38% |
90% of ISACA survey respondents believe employees at their organization are already using AI. Only 38% have a formal, comprehensive AI policy to govern that use.
That gap is exactly what the Govern function exists to close. Most businesses don’t lack the ability to write a policy. They lack a defined owner and a process for keeping the policy current as new tools show up.
What This Looks Like for a Small or Mid-Size Business
You don’t need a compliance department to start. Most small and mid-size businesses can make real progress with four practical moves.
- Find out what’s actually in use. Employees are usually already using more AI tools than leadership realizes.
- Write down who owns the decision. Someone needs to approve new AI tools before they touch client data.
- Put technical controls around the tools you keep. Access control, MFA, and encryption around anything that feeds data into an AI tool.
- Build a way to catch problems early. Logging and monitoring that flags unauthorized AI tool use on your network.
The first two moves are Govern and Map. The last two lean on Measure and Manage. That’s usually where an IT provider already has infrastructure in place:
- Access controls and encryption
- Monitoring for unusual activity
- Vendor risk review
- Incident response
Our AI governance checklist walks through all four functions in a step-by-step format. If you’d rather have someone handle the setup for you, that’s what LeadingIT’s AI governance services are for.
See Where You Stand
Want a faster way to see where your business stands? Answer a few plain-English questions about how you use AI today.
Take the free 2-minute NIST AI RMF risk check
No sign-up required to see your result.
Related Guides
Frequently Asked Questions
No. The NIST AI RMF is voluntary guidance, not a law or regulation. NIST does not fine or penalize a business for not adopting it. The pressure to follow it comes indirectly, through regulators, state laws, contracts, and insurers who point to it as a benchmark.
No. NIST does not offer, endorse, or accredit any certification for the AI RMF, and there is no NIST-issued “AI RMF certified” credential. Some private training companies sell courses and credentials built around the framework’s four functions. Those are vendor products, not government certifications, so verify any provider’s accreditation before you pay for one.
The Playbook is NIST’s free companion resource to the AI RMF. It lists suggested actions and references for meeting the outcomes under each of the four functions. It’s a self-service reference document, not a course or an exam.
Yes. The framework is written to apply to any organization, of any size, in any sector. It doesn’t matter whether you build AI, buy it, or just use a tool inside an existing workflow. A small business with one AI-powered app is still in scope.
It’s a companion document NIST published on July 26, 2024. It applies the same Govern, Map, Measure, Manage structure to risks specific to generative AI tools, like confabulation, data privacy leakage, and harmful content generation.
Not directly. But the surrounding ecosystem is extending to cover them. Agentic AI systems take multi-step actions largely on their own, raising risks a single-turn chatbot doesn’t have. NIST launched an AI Agent Standards Initiative in February 2026 for agent-specific standards. CISA and international partners followed in April 2026 with joint guidance on agentic AI risk.
NIST’s AI Resource Center, at airc.nist.gov, is the free public hub for AI RMF materials. It includes the framework text, the Playbook, a glossary of AI terms, and use-case specific profiles. Everything there is free and publicly available.
Talk to Someone Who Handles This Every Day
LeadingIT is a Chicagoland managed IT and cybersecurity provider, based in Woodstock and Manteno. AI governance work is becoming part of the same conversation as backups and firewalls.
We help clients put the Govern and Map work in writing. Then we build the access controls and monitoring that Measure and Manage require.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
