NIST AI Risk Management Framework (AI RMF) Explained

Shubham S.
October 6, 2026
•
22
mins

A customer's security questionnaire arrives with one new line: "Please describe your alignment with the NIST AI Risk Management Framework." You shipped an LLM-powered feature last quarter. Nobody on your team has opened the framework.

The NIST AI Risk Management Framework (AI RMF 1.0, published as NIST AI 100-1 on January 26, 2023) is a voluntary US framework for managing the risks of AI systems. It is organized into four functions, Govern, Map, Measure and Manage, which break down into 19 categories and 72 subcategories.

There is no certificate attached to it, which is the single biggest difference from ISO 42001. And as of September 2026, NIST says the framework is being revised as part of the White House AI Action Plan.

Quick take If you are an early-stage SaaS team, treat the NIST AI RMF as the vocabulary for your AI risk work, not a badge to earn. Align to it, document what you do, and decide separately whether a customer is asking for ISO 42001, the standard you can actually be audited against.

By the end of this guide, you will be able to answer that questionnaire line honestly, and know which parts of the framework are worth your time.

Here's what I'll cover:

  • What the framework is, and what it is not (it is not NIST CSF or SP 800-53)
  • Whether it is mandatory, and what has changed in the US since 2023
  • How the framework is built, including the exact category and subcategory counts
  • The four functions, translated into what a ten-person team actually does
  • The Playbook, the crosswalks and the Generative AI Profile (NIST AI 600-1)
  • How it compares to ISO 42001, and how it connects to your SOC 2 work
  • A six-step starting path for a startup

What Is the NIST AI Risk Management Framework?

The NIST AI Risk Management Framework is a voluntary, non-sector-specific framework from the US National Institute of Standards and Technology that helps organizations design, develop, deploy and use AI systems more trustworthily. NIST released version 1.0 on January 26, 2023, as NIST AI 100-1, and the document describes itself as "voluntary, rights-preserving, non-sector-specific, and use-case agnostic."

Congress asked for it. The framework's own text says it was developed as directed by the National Artificial Intelligence Initiative Act of 2020.

Its audience is what NIST calls AI actors: anyone who plays an active role in the AI system lifecycle, from the team that trains a model to the company that deploys it inside a product. NIST says it should scale to organizations of all sizes, which includes a seed-stage SaaS company calling a third-party model API. You can read the framework directly on NIST's AI RMF page.

NIST AI Risk Management Framework vs NIST CSF and SP 800-53

Before going further, one disambiguation. This article is about the AI RMF only. It is not about the NIST Cybersecurity Framework (CSF 2.0), SP 800-171 or SP 800-53, which are a different family of documents that most "NIST compliance" searches actually mean. If that is what you are after, ComplyJet's NIST compliance guide is the better read.

Document What it is for Who usually needs it
NIST AI RMF 1.0 (AI 100-1) Managing risks of AI systems across their lifecycle Anyone building or deploying AI
NIST CSF 2.0 Organizing a cybersecurity program around six functions Organizations building a security program, often US federal contractors
NIST SP 800-53 Control catalog for federal information systems Federal systems and their contractors
Cyber AI Profile (NIST IR 8596, draft) A profile of CSF 2.0 for securing AI, using AI in defense and countering AI-enabled attacks Security teams, as a CSF extension, not an AI RMF profile

The last row trips people up. NIST's December 2025 preliminary draft of the Cyber AI Profile is an application of CSF 2.0, per NIST's announcement, so it sits beside this framework, not inside it.

Frameworks
NIST AI RMF, ISO 42001 and the EU AI Act on one platform
ComplyJet lists NIST AI RMF, ISO 42001 and the EU AI Act among its supported frameworks, alongside SOC 2, at flat per-company pricing.
See supported frameworks

Is the NIST AI Risk Management Framework Mandatory? Where It Stands in September 2026

No. NIST's own FAQ answers the question in two words: "No. NIST has produced the AI RMF as a voluntary Framework." Nothing in the framework creates a legal duty on its own, and nothing in NIST's materials describes a certification or attestation scheme for it. That is the honest starting point.

"Voluntary" is not the whole story, though. The policy ground around it has moved a lot since 2023, and a few of those moves affect how much weight you should put on it.

Timeline of the NIST AI Risk Management Framework: AI RMF 1.0 in January 2023, the Generative AI Profile in July 2024, Executive Order 14110 rescinded in January 2025, the AI Action Plan calling for a revision in July 2025, and a critical infrastructure profile concept note in April 2026.

What has changed in US policy since the NIST AI Risk Management Framework was released

The framework's federal tailwind has shifted. Four dated facts matter:

  • January 20, 2025: Executive Order 14110 (Safe, Secure, and Trustworthy Development and Use of AI), the order the Generative AI Profile was written under, was listed as rescinded in the White House's Initial Rescissions order.
  • July 2025: America's AI Action Plan recommends that NIST "revise the NIST AI Risk Management Framework to eliminate references to misinformation, Diversity, Equity, and Inclusion, and climate change."
  • Today: NIST's framework page states that "The AI RMF 1.0 is being revised as part of the White House AI Action Plan." I found no revised core text published there as of September 30, 2026.
  • April 7, 2026: NIST released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure. It is a concept note, not a finished profile.

One detail is worth noticing. The current text's GOVERN 3 category is titled "Workforce diversity, equity, inclusion, and accessibility processes are prioritized," so the revision will presumably touch it. Nobody outside NIST knows the final wording yet.

Watch out Do not write "compliant with the NIST AI RMF" into a customer contract or questionnaire answer without naming the version. "Aligned with AI RMF 1.0 (NIST AI 100-1, January 2023)" is accurate today and will still be accurate after a revision.

State laws that point to the NIST AI Risk Management Framework

The framework has found a second life as a legal reference point, and the picture differs by state.

Texas is the live example. The Texas Responsible AI Governance Act (HB 149) took effect on January 1, 2026, and its enrolled text gives a defendant a defense where it substantially complies with the most recent version of NIST's "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile" or another nationally or internationally recognized AI risk management framework.

Colorado went the other way. SB 24-205 had an affirmative defense for NIST AI RMF or ISO 42001 alignment, but Colorado repealed and replaced that law with SB 26-189, signed May 14, 2026 and effective January 1, 2027, and VerifyWise's summary says the NIST and ISO affirmative defense was repealed along with the rest of that framework. Law-firm alerts, including Goodwin's, confirm the replacement and the removal of the old risk management program requirements.

That is not legal advice, and state AI law is moving quickly. The practical read: a defense tied to a named framework is worth having where it exists, but it is a reason to document your alignment, not a substitute for it.

How the NIST AI Risk Management Framework Is Structured: Core, Categories and Profiles

The framework has two parts. Part 1 covers how to frame AI risk and who the audience is. Part 2 is the Core, the part people actually mean when they say "implement the AI RMF."

The Core is four functions, each split into categories, then subcategories. I counted them straight from Tables 1 to 4 of NIST AI 100-1:

Function Categories Subcategories
GOVERN 6 19
MAP 5 18
MEASURE 4 22
MANAGE 4 13
Total 19 72

Some vendor pages give different numbers, such as "60 controls." NIST's own tables say 72 subcategories, so use that one. And "controls" is the wrong word anyway: these are outcomes, not tests a system passes or fails.

Note NIST says the actions "do not constitute a checklist, nor are they necessarily an ordered set of steps." Organizations can pick the subcategories that fit their resources. After GOVERN is in place, NIST says most users would start with MAP and continue to MEASURE or MANAGE.

The seven characteristics of trustworthy AI

The Core exists to produce AI that is trustworthy, which NIST breaks into seven characteristics:

  1. Valid and reliable
  2. Safe
  3. Secure and resilient
  4. Accountable and transparent
  5. Explainable and interpretable
  6. Privacy-enhanced
  7. Fair, with harmful bias managed

NIST is explicit that you will not maximize all seven at once. Creating trustworthy AI requires balancing them based on the system's context of use, which is why the framework stays outcome-based and leaves the specifics to you.

Profiles: how the NIST AI Risk Management Framework becomes yours

A profile is an implementation of the functions, categories and subcategories for a specific setting, application or technology. The Generative AI Profile (covered below) is one. The critical infrastructure concept note is another in progress. The AI RMF has no maturity tiers, so you will not see anything like CSF's implementation tiers here.

The NIST AI RMF Core Functions: Govern, Map, Measure, Manage

The NIST AI RMF core functions are four, and GOVERN is the odd one out. NIST draws it as a cross-cutting function meant to inform, and be infused throughout, the other three, so the mental model is one ring of governance around a loop of Map, Measure and Manage.

Diagram of the four NIST AI RMF functions: Govern drawn as an outer ring around three connected steps, Map, Measure and Manage.

The four functions below each follow the same pattern: what NIST asks for, what it looks like at a ten-person SaaS team, and a verdict.

Govern: who owns AI risk

GOVERN is the policies, accountability and culture layer. Its subcategories include understanding legal and regulatory requirements involving AI (GOVERN 1.1), keeping an inventory of AI systems (GOVERN 1.6), executive leadership taking responsibility for AI risk decisions (GOVERN 2.3) and handling risks from third-party software and data (the GOVERN 6 category).

At a small team, that is a one-page AI use policy, a spreadsheet of every AI feature and vendor model you use, and a named founder or CTO who signs off on new AI use.

Verdict: if you do only one function properly, do this one. An AI inventory you can hand to a customer is worth more than a long policy nobody reads.

Map: what the system is for and who it touches

MAP establishes context. MAP 1.1 asks that intended purposes, beneficial uses, relevant laws and the settings where the system will be deployed are understood and documented. Later categories characterize impacts on individuals, groups and society.

For a startup, this is a short intended-use statement per AI feature: what it does, what it must never be used for, who is affected when it is wrong, and which third-party models sit underneath.

Verdict: Map is where most "we use AI responsibly" claims either become specific or fall apart.

Measure: how you know it works

MEASURE is testing, evaluation, verification and validation, then tracking identified risks over time. It includes a notable independence requirement: MEASURE 1.3 asks that internal experts who did not serve as front-line developers, or independent assessors, take part in regular assessments.

For a small team, that means a written evaluation set for each AI feature, a rerun whenever the model or prompt changes, and someone other than the author reviewing the results.

Verdict: Measure is the function startups skip, and the one a sharp enterprise reviewer will probe.

Manage: what you do about it

MANAGE is acting on the risk. It covers prioritizing treatment by impact and likelihood (MANAGE 1.2), having mechanisms to supersede, disengage or deactivate a system that performs outside its intended use (MANAGE 2.4) and post-deployment monitoring including incident response, recovery and change management (MANAGE 4.1).

At ten people, that is a feature flag that can switch an AI feature off, production monitoring for output quality, and an incident path that already exists in your SOC 2 program.

Verdict: if you can switch an AI feature off in minutes and show how you would notice it misbehaving, you are ahead of most teams your size.

The NIST AI RMF Playbook, Crosswalks and Profiles

The framework tells you the outcomes. The NIST AI RMF Playbook suggests how to get there. It is organized around the four functions, with suggested actions aligned to subcategories, and NIST describes it as "neither a checklist nor set of steps to be followed in its entirety." Use as many or as few suggestions as apply.

NIST says it releases Playbook updates approximately twice a year, and that the Playbook will be updated after the AI RMF is revised.

Try this yourself Open the Playbook entry for GOVERN 1.6 (the AI system inventory) and turn its suggested actions into a one-page template with columns for system, owner, vendor model, data touched and intended use. You will have built the most-asked-for AI artifact in under an hour.

NIST also hosts crosswalks that map the framework to other documents. The ISO ones are worth knowing about:

  • ISO/IEC 23894 (AI risk management guidance): a revised crosswalk dated August 14, 2025, contributed by INCITS
  • ISO/IEC 42005 (AI impact assessment): a crosswalk dated August 14, 2025, also from INCITS
  • ISO/IEC 42001: a crosswalk listed on the page as contributed by Microsoft, with no date given

That last one deserves a caveat. The 42001 crosswalk is a third-party submission hosted by NIST, not a mapping NIST authored, so treat it as a useful starting point, not an official equivalence.

NIST AI 600-1: The Generative AI Profile for the NIST AI Risk Management Framework

NIST AI 600-1, the Generative AI Profile, is a companion to the AI RMF that NIST released on July 26, 2024. It defines risks that are novel to or exacerbated by generative AI and offers suggested actions organized by the framework's subcategories. NIST calls it a cross-sectoral profile, meaning it covers activities common across sectors, such as using large language models.

It was written pursuant to Executive Order 14110, which has since been rescinded. The profile itself was not withdrawn, and Texas's statute still names it. You can read the full text in NIST AI 600-1.

The profile names 12 risks. Here is all twelve, with my read on which a startup shipping an LLM feature should triage first:

Risk (NIST's name) Triage priority for a typical SaaS startup
Confabulation High: wrong answers stated confidently, the most visible failure
Data Privacy High: leakage of customer data into prompts, logs or training
Information Security High: prompt injection and abuse of your AI endpoints
Value Chain and Component Integration High: you inherit your model vendor's risks
Harmful Bias or Homogenization Medium: depends on whether outputs affect people's opportunities
Intellectual Property Medium: output and training-data provenance questions
Human-AI Configuration Medium: over-reliance and automation bias in your own UX
Information Integrity Medium: higher if you generate public-facing content
Dangerous, Violent, or Hateful Content Lower for most B2B SaaS, higher if users can prompt freely
Obscene, Degrading, and/or Abusive Content Lower for most B2B SaaS, higher if users can prompt freely
CBRN Information or Capabilities Lower for most SaaS products that are not general-purpose models
Environmental Impacts Lower as a day-to-day control, relevant to vendor choice

The priority column is my judgment, not NIST's. NIST does not rank the risks for you, and your own context should override mine.

NIST AI RMF vs ISO 42001: Guidance You Align To, a Standard You Certify Against

Most comparison pages ask which one wins. The better question is what you need to be able to prove, and to whom.

The NIST AI Risk Management Framework is guidance. ISO 42001, published in December 2023, is a certifiable management system standard. If you need the long version of the standard itself, what is ISO 42001 covers the clauses and Annex A.

Two-lane comparison: the NIST AI RMF as voluntary guidance you align to and self-assess, and ISO 42001 as a certifiable standard audited by a third party.
Dimension NIST AI RMF ISO 42001
Nature Voluntary framework of outcomes Management system standard with requirements
Publisher US government (NIST) ISO and IEC
Certifiable No certification scheme in NIST's materials Yes, through accredited certification bodies
Structure 4 functions, 19 categories, 72 subcategories 10 clauses, plus Annex A controls
Access Free to download Standard is purchased from ISO
What a customer can verify Your own description of alignment An auditor's certificate
Updates Being revised; formal review by 2028 at the latest Published December 2023

Verdict: NIST tells you which risks to think about. ISO 42001 gives you a system an auditor can test and a certificate a buyer can check.

Why "we align to the NIST AI RMF" is a weaker claim than a certificate

Nobody audits alignment. It is self-described, which is fine for an internal program and thin for a procurement team that has seen a hundred vague answers. The fair criticism of any voluntary framework is that it can degrade into paperwork.

Hacker News commenters said exactly that in April 2023, when the framework launched. One warned such frameworks risk becoming "a surface level, checklist ticking exercise" without a public feedback loop, and another dismissed it as having "no teeth" (see the launch thread). That is a launch-month take and partly dated, since the Playbook and Generative AI Profile have since added substance. The underlying worry, that nothing forces the work to be real, is still the gap an independent audit closes.

Using both without doubling the work

Here is how I would use them together. The NIST vocabulary (the four functions and the trustworthiness characteristics) is a good way to structure your risk work and explain it to a customer. ISO 42001 is what you pursue when a buyer wants a certificate, and the two overlap heavily because both come down to inventory, ownership, impact assessment, monitoring and improvement.

If certification is where you are heading, ISO 42001 certification cost breaks down the spend.

ComplyJet customers
How an early-stage AI company runs compliance day to day
Raghuram Vadapally, Managing Director and Head of Software Engineering at Synexar AI, calls ComplyJet "an indispensable part of our compliance workflow." Read their SOC 2 and HIPAA story.
Read the Synexar AI story

Where the NIST AI Risk Management Framework Meets Your SOC 2 Work

Your SOC 2 report already proves something about how you run a system, but it was never built to test whether an AI model is fair or safe. ComplyJet's guide to whether SOC 2 covers AI puts the boundary plainly: SOC 2 "was never built to test 'fairness, bias, responsible and ethical use, and safety.'"

That is exactly the ground the AI RMF covers, and it is why the two are complements. NIST publishes no official mapping between SOC 2 and the AI RMF, so the table below is my own reading of where your existing evidence feeds the framework, not an official crosswalk.

Existing SOC 2 work (Trust Services Criteria area) Where it plausibly supports the AI RMF
Risk assessment process (CC3) GOVERN risk tolerance and MAP risk identification
Vendor and business partner risk management (CC9.2) GOVERN 6 and MAP 4, third-party software and data
Monitoring and incident response (CC7) MANAGE 4.1, post-deployment monitoring and incident response
Change management (CC8) MANAGE 4.1 change management, re-evaluation after model or prompt changes
Access controls and logging Evidence for MEASURE and MANAGE on who can change a model
Note The overlap is in how you operate, not in what you test. SOC 2 will not ask whether your summarization feature invents facts. MEASURE will. Build the evaluation evidence separately and keep it with the rest of your audit artifacts.

The practical upside for a startup is that you are not starting from zero. A team with a working vendor review, incident process and change log already has the operating habits that GOVERN and MANAGE assume. What is missing is usually the AI-specific layer: the inventory, the intended-use statements and the evaluation sets.

How a Startup Should Start With the NIST AI Risk Management Framework

The NIST AI RMF vs ISO 42001 question comes down to what you can prove, and a startup should not try to "implement" 72 subcategories to answer it. It should pick a small, defensible slice and keep it current.

Six-step path for a startup: inventory AI systems, name an owner, write intended-use statements, pick a risk slice, add monitoring and a kill switch, then decide on ISO 42001.
  1. Inventory every AI system and model vendor (GOVERN 1.6). Include features, internal tools and any third-party model you call.
  2. Name one accountable owner (GOVERN 2.3). A person, not a committee.
  3. Write a one-page intended-use statement per system (MAP 1.1): purpose, out-of-scope uses, affected users, underlying models.
  4. Pick 10 to 15 subcategories and map your top generative AI risks from the table above to a concrete test for each.
  5. Add monitoring and a way to switch the feature off (MANAGE 2.4 and 4.1), and rehearse it once.
  6. Decide on ISO 42001 by one test: has a customer or partner asked for a certificate, or is one likely to?
Pro tip Date every artifact and name the framework version in it. When NIST publishes the revision, you will know exactly which documents need a fresh look.

So what should you choose?

  • Align only if your customers ask for "alignment with NIST" and nobody has asked for a certificate. Steps 1 to 5 are enough, and they are cheap.
  • Add ISO 42001 if enterprise buyers are putting "ISO 42001 certified or working toward it" in questionnaires, or your sales cycle keeps stalling on AI diligence.
  • Otherwise, do steps 1 to 3 this week. They cost almost nothing and they are the first things anyone will ask for.

We support NIST AI RMF and ISO 42001 alongside SOC 2 on the ComplyJet platform, so the operating evidence you already collect for one does not get rebuilt for the next.

Common Misunderstandings About the NIST AI Risk Management Framework

These are the ones I see most often.

  • "It's a checklist." NIST says the actions are not a checklist and not an ordered set of steps.
  • "There is a NIST AI RMF certificate." NIST's materials describe no certification scheme. If a vendor sells you a "NIST AI RMF certification," ask who the accrediting body is.
  • "It's the same as the NIST CSF." It is a separate framework with a different purpose and a different set of functions.
  • "72 means 72 controls I must pass." The 72 subcategories are outcomes you choose among, not pass-fail tests.
  • "The 2023 text is final." NIST states it is being revised, so version-name your claims.
  • "The Generative AI Profile replaces the framework." It is a companion profile. It does not replace the Core.

FAQs

What is the NIST AI Risk Management Framework?

It is a voluntary framework from the US National Institute of Standards and Technology for managing AI risks, released as NIST AI 100-1 on January 26, 2023. It applies to any organization that designs, develops, deploys or uses AI, regardless of size or sector.

What are the four functions of the NIST AI RMF?

Govern, Map, Measure and Manage. Govern covers policies, accountability and culture across the other three. Map establishes context and impacts, Measure tests and tracks the risks, and Manage acts on them.

Is the NIST AI Risk Management Framework mandatory?

No. NIST's FAQ says it "has produced the AI RMF as a voluntary Framework." Some state laws and contracts may reference it, so check the terms you actually operate under.

Is the NIST AI Risk Management Framework a certification?

No. NIST's materials describe no certification or attestation scheme for it. If you need an auditable certificate for AI governance, ISO 42001 is the certifiable standard.

How many categories and subcategories does the NIST AI RMF have?

19 categories and 72 subcategories, split across Govern (6 and 19), Map (5 and 18), Measure (4 and 22) and Manage (4 and 13), based on the tables in NIST AI 100-1.

What is NIST AI 600-1?

It is the Generative AI Profile, released July 26, 2024. It defines 12 risks novel to or exacerbated by generative AI and offers suggested actions mapped to AI RMF subcategories.

How does the NIST AI Risk Management Framework compare to ISO 42001?

The AI RMF is voluntary guidance you align to and self-assess. ISO 42001 is a management system standard you can be certified against by an accredited body. Many teams use the NIST vocabulary to structure risk work and ISO 42001 when a customer wants a certificate.

Does a startup need the NIST AI RMF?

Not as a legal matter in most cases, but it is a useful, free structure for answering customer AI questions. A startup that ships an AI feature benefits most from the inventory, intended-use and monitoring steps.

Is the NIST AI RMF being updated?

Yes. NIST's page says AI RMF 1.0 is being revised as part of the White House AI Action Plan, and the Playbook will be updated after the revision. As of September 30, 2026, I found no revised core text published.

Book a demo
Sort out where your AI features sit today
Talk through your AI use, your existing SOC 2 work and whether ISO 42001 makes sense for a team your size.
Book a demo

Related Reading