Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →NIST AI Risk Management Framework (AI RMF 1.0) and Playbook
Issued by
National Institute of Standards and Technology (NIST), U.S. Department of Commerce
- September 30, 2026 · Substantive update — Broadened the Playbook entry to cover NIST AI RMF 1.0 and the Playbook. Removed an unsupported claim of a June 2026 Playbook update; checked against nist.gov. (Cody Maxwell)
The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary US framework for managing the risks of AI systems. It organizes the work into four functions: Govern, Map, Measure, and Manage. Its companion Playbook suggests concrete actions for each part. Any organization that builds or uses AI can adopt it, and some laws and contracts point to it.
Applies To
Overview
NIST released AI RMF 1.0 (NIST AI 100-1) on 26 January 2023. It is voluntary and does not favor any technology or sector. It helps organizations identify, assess, and reduce the risks AI systems pose to people, organizations, and society. It describes trustworthy AI through seven characteristics: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. The framework's core has four functions. Govern sets the policies, roles, and culture for AI risk management across the organization. Map establishes each system's context, intended use, and potential impacts. Measure analyzes and tracks the risks that mapping identifies. Manage decides how to treat those risks and how to respond to incidents. Each function breaks down into categories and subcategories that describe outcomes rather than required steps. The AI RMF Playbook is NIST's companion resource. For each subcategory it offers suggested actions, documentation to keep, and references. NIST also publishes profiles that adapt the framework to a specific use. The Generative AI Profile (NIST AI 600-1, July 2024) covers risks specific to generative AI. A concept note for a critical infrastructure profile followed in April 2026. NIST is revising AI RMF 1.0 under the July 2025 AI Action Plan. The plan directed NIST to remove references to misinformation, diversity, equity, and inclusion, and climate change. NIST has said the Playbook will be updated after the framework revision. Until then, version 1.0 and the current Playbook remain the published versions. The framework carries no penalties. It still matters for compliance, because other rules point to it. Colorado's AI Act ties an affirmative defense to compliance with a recognized framework such as the AI RMF. NIST also publishes crosswalks that map the framework to ISO/IEC 42001 and other standards.
Key Requirements
- •Govern: set AI risk policies, assign roles and accountability, and build a culture that treats AI risk seriously.
- •Map: document each AI system's purpose, context, users, and potential impacts before deciding to build or deploy it.
- •Measure: choose methods and metrics for each identified risk, and test systems against the trustworthy characteristics before and after deployment.
- •Manage: prioritize risks, decide whether to reduce, transfer, avoid, or accept each one, and plan for incidents and retirement.
- •Cover third-party AI, including vendor models and data, in the same risk process as systems built in-house.
- •Use profiles, such as the Generative AI Profile, to tailor the outcomes to a technology or sector.
- •Adoption is voluntary and carries no penalties, but contracts and laws that reference the framework can create obligations.
What Your Organization Must Do
- →Assign an owner for each of the four functions, and record which subcategory outcomes you meet, partly meet, or have deferred.
- →Build or update your AI inventory with the context the Map function asks for: purpose, users, data, and affected groups.
- →Use the Playbook's suggested actions as a checklist for policies, testing, and documentation.
- →Apply the Generative AI Profile to any generative AI in use, alongside the core framework.
- →Keep a crosswalk to ISO/IEC 42001 and the EU AI Act so that one control set serves all three.
- →Watch for the revised framework, since NIST will update the Playbook once the revision is published.
Playbook Guidance
Step-by-step implementation guidance for compliance teams.
Governance Controls
Operational controls that implement requirements from this regulation.
Frequently Asked Questions
- Is the NIST AI RMF mandatory?
- No, the AI RMF is voluntary for private organizations. It can become an obligation through a contract, a federal agency requirement, or a law that references it. Colorado's AI Act, for example, ties an affirmative defense to following a recognized framework such as the AI RMF.
- What are the four functions of the AI RMF?
- The functions are Govern, Map, Measure, and Manage. Govern applies across the whole organization, while Map, Measure, and Manage apply to each AI system throughout its life cycle.
- What is the AI RMF Playbook?
- The Playbook is NIST's companion resource to the framework. For each subcategory it suggests actions, documentation, and references. Like the framework, it is voluntary, and you can use the parts that fit.
- How does the AI RMF relate to NIST AI 600-1?
- NIST AI 600-1 is the Generative AI Profile of the AI RMF, published in July 2024. It applies the four functions to risks specific to generative AI, such as confabulation and information integrity. Use it alongside the core framework, not instead of it.
- Is NIST revising the AI RMF?
- Yes, NIST is revising AI RMF 1.0 under the July 2025 AI Action Plan. The plan directed NIST to remove references to misinformation, diversity, equity, and inclusion, and climate change. The Playbook will be updated after the revised framework is published.
- How does the AI RMF compare with ISO/IEC 42001?
- ISO/IEC 42001 is a certifiable management system standard, while the AI RMF is a voluntary framework without certification. The two overlap heavily, and NIST publishes a crosswalk between them. Many organizations use the AI RMF for risk practice and ISO/IEC 42001 for certification.
