AI Governance Institute

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →
VoluntaryFrameworkUS

NIST AI Risk Management Framework (AI RMF 1.0) and Playbook

Issued by

National Institute of Standards and Technology (NIST), U.S. Department of Commerce

liveEffective 2023-01-26NIST AI RMFUpdated September 2026
Official document →

The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary US framework for managing the risks of AI systems. It organizes the work into four functions: Govern, Map, Measure, and Manage. Its companion Playbook suggests concrete actions for each part. Any organization that builds or uses AI can adopt it, and some laws and contracts point to it.

Applies To

Large enterpriseSMBPublic sectorAI developerAI deployer

Overview

NIST released AI RMF 1.0 (NIST AI 100-1) on 26 January 2023. It is voluntary and does not favor any technology or sector. It helps organizations identify, assess, and reduce the risks AI systems pose to people, organizations, and society. It describes trustworthy AI through seven characteristics: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. The framework's core has four functions. Govern sets the policies, roles, and culture for AI risk management across the organization. Map establishes each system's context, intended use, and potential impacts. Measure analyzes and tracks the risks that mapping identifies. Manage decides how to treat those risks and how to respond to incidents. Each function breaks down into categories and subcategories that describe outcomes rather than required steps. The AI RMF Playbook is NIST's companion resource. For each subcategory it offers suggested actions, documentation to keep, and references. NIST also publishes profiles that adapt the framework to a specific use. The Generative AI Profile (NIST AI 600-1, July 2024) covers risks specific to generative AI. A concept note for a critical infrastructure profile followed in April 2026. NIST is revising AI RMF 1.0 under the July 2025 AI Action Plan. The plan directed NIST to remove references to misinformation, diversity, equity, and inclusion, and climate change. NIST has said the Playbook will be updated after the framework revision. Until then, version 1.0 and the current Playbook remain the published versions. The framework carries no penalties. It still matters for compliance, because other rules point to it. Colorado's AI Act ties an affirmative defense to compliance with a recognized framework such as the AI RMF. NIST also publishes crosswalks that map the framework to ISO/IEC 42001 and other standards.

Key Requirements

  • •Govern: set AI risk policies, assign roles and accountability, and build a culture that treats AI risk seriously.
  • •Map: document each AI system's purpose, context, users, and potential impacts before deciding to build or deploy it.
  • •Measure: choose methods and metrics for each identified risk, and test systems against the trustworthy characteristics before and after deployment.
  • •Manage: prioritize risks, decide whether to reduce, transfer, avoid, or accept each one, and plan for incidents and retirement.
  • •Cover third-party AI, including vendor models and data, in the same risk process as systems built in-house.
  • •Use profiles, such as the Generative AI Profile, to tailor the outcomes to a technology or sector.
  • •Adoption is voluntary and carries no penalties, but contracts and laws that reference the framework can create obligations.

What Your Organization Must Do

  • →Assign an owner for each of the four functions, and record which subcategory outcomes you meet, partly meet, or have deferred.
  • →Build or update your AI inventory with the context the Map function asks for: purpose, users, data, and affected groups.
  • →Use the Playbook's suggested actions as a checklist for policies, testing, and documentation.
  • →Apply the Generative AI Profile to any generative AI in use, alongside the core framework.
  • →Keep a crosswalk to ISO/IEC 42001 and the EU AI Act so that one control set serves all three.
  • →Watch for the revised framework, since NIST will update the Playbook once the revision is published.

Playbook Guidance

Step-by-step implementation guidance for compliance teams.

01How do we inventory and classify AI systems by risk level?02Who owns AI governance within the organization?03How do we ensure third-party AI vendors meet our standards?05How do we detect and mitigate algorithmic bias?06What does meaningful human oversight look like for high-risk AI decisions?08How should employees be trained on acceptable AI use?09How do we maintain data privacy compliance when using AI?10How do we document AI decision-making for auditability?11How do we ensure human-in-the-loop review is actually effective?12Is our training data compliant with global privacy laws?13How do we measure and mitigate algorithmic bias?14What is our explainability standard for AI decisions?15How are we managing third-party AI risks?16Do we have a complete AI inventory?18What is our process for model drift monitoring?19How do we handle intellectual property and copyright in AI?20Is our AI red-teaming rigorous enough?21How do we govern AI agents that take autonomous actions?22How do we apply a three lines of defense model to AI risk?23How do we build and maintain an AI model registry?24What does audit-ready AI documentation look like in practice?26What does AI governance look like for a company with under 50 employees?27How do we perform an AI risk assessment?29How do we build an AI governance program from scratch?30What AI documentation do we actually need?31How do we audit an AI system for compliance?32How do we manage third-party AI vendors safely throughout the vendor lifecycle?33What do we do when an AI system causes harm or fails?34How do we prepare for AI regulation over the next 12 months?35How do we report AI risk to the board and audit committee?36How do we intake and govern open-weight and self-hosted AI models?37How do we map AI compliance obligations across multiple jurisdictions?38How do we govern AI models from preview release through retirement?39How do we monitor voluntary AI safety commitments and respond when they change?40How do we govern our AI supply chain and manage upstream model dependencies?41How do we disclose AI governance maturity to investors and regulators?42How do we build and maintain a multi-framework AI risk register?43How do we engage regulators and standards bodies proactively on AI governance?44How do we build director-level AI literacy for effective board oversight?45How do we comply with China's AI regulations?46How do we govern agentic coding assistants and AI developer tools?47How do we govern MCP servers and other agent tool connections?48What are the biggest AI governance challenges, and how do we address them?49Should we hire an AI governance consultant, or build the program in-house?50How do we audit our AI governance program, not just individual AI systems?51What does AI governance leadership look like at the board and executive level?52What are the AI governance best practices that actually hold up in practice?53What AI agent security controls do we need as agent autonomy expands?

Governance Controls

Operational controls that implement requirements from this regulation.

Frequently Asked Questions

Is the NIST AI RMF mandatory?
No, the AI RMF is voluntary for private organizations. It can become an obligation through a contract, a federal agency requirement, or a law that references it. Colorado's AI Act, for example, ties an affirmative defense to following a recognized framework such as the AI RMF.
What are the four functions of the AI RMF?
The functions are Govern, Map, Measure, and Manage. Govern applies across the whole organization, while Map, Measure, and Manage apply to each AI system throughout its life cycle.
What is the AI RMF Playbook?
The Playbook is NIST's companion resource to the framework. For each subcategory it suggests actions, documentation, and references. Like the framework, it is voluntary, and you can use the parts that fit.
How does the AI RMF relate to NIST AI 600-1?
NIST AI 600-1 is the Generative AI Profile of the AI RMF, published in July 2024. It applies the four functions to risks specific to generative AI, such as confabulation and information integrity. Use it alongside the core framework, not instead of it.
Is NIST revising the AI RMF?
Yes, NIST is revising AI RMF 1.0 under the July 2025 AI Action Plan. The plan directed NIST to remove references to misinformation, diversity, equity, and inclusion, and climate change. The Playbook will be updated after the revised framework is published.
How does the AI RMF compare with ISO/IEC 42001?
ISO/IEC 42001 is a certifiable management system standard, while the AI RMF is a voluntary framework without certification. The two overlap heavily, and NIST publishes a crosswalk between them. Many organizations use the AI RMF for risk practice and ISO/IEC 42001 for certification.