A customer's security questionnaire arrives with one new line: "Please describe your alignment with the NIST AI Risk Management Framework." You shipped an LLM-powered feature last quarter. Nobody on your team has opened the framework.
The NIST AI Risk Management Framework (AI RMF 1.0, published as NIST AI 100-1 on January 26, 2023) is a voluntary US framework for managing the risks of AI systems. It is organized into four functions, Govern, Map, Measure and Manage, which break down into 19 categories and 72 subcategories.
There is no certificate attached to it, which is the single biggest difference from ISO 42001. And as of September 2026, NIST says the framework is being revised as part of the White House AI Action Plan.
By the end of this guide, you will be able to answer that questionnaire line honestly, and know which parts of the framework are worth your time.
Here's what I'll cover:
- What the framework is, and what it is not (it is not NIST CSF or SP 800-53)
- Whether it is mandatory, and what has changed in the US since 2023
- How the framework is built, including the exact category and subcategory counts
- The four functions, translated into what a ten-person team actually does
- The Playbook, the crosswalks and the Generative AI Profile (NIST AI 600-1)
- How it compares to ISO 42001, and how it connects to your SOC 2 work
- A six-step starting path for a startup
What Is the NIST AI Risk Management Framework?
The NIST AI Risk Management Framework is a voluntary, non-sector-specific framework from the US National Institute of Standards and Technology that helps organizations design, develop, deploy and use AI systems more trustworthily. NIST released version 1.0 on January 26, 2023, as NIST AI 100-1, and the document describes itself as "voluntary, rights-preserving, non-sector-specific, and use-case agnostic."
Congress asked for it. The framework's own text says it was developed as directed by the National Artificial Intelligence Initiative Act of 2020.
Its audience is what NIST calls AI actors: anyone who plays an active role in the AI system lifecycle, from the team that trains a model to the company that deploys it inside a product. NIST says it should scale to organizations of all sizes, which includes a seed-stage SaaS company calling a third-party model API. You can read the framework directly on NIST's AI RMF page.
NIST AI Risk Management Framework vs NIST CSF and SP 800-53
Before going further, one disambiguation. This article is about the AI RMF only. It is not about the NIST Cybersecurity Framework (CSF 2.0), SP 800-171 or SP 800-53, which are a different family of documents that most "NIST compliance" searches actually mean. If that is what you are after, ComplyJet's NIST compliance guide is the better read.
| Document | What it is for | Who usually needs it |
|---|---|---|
| NIST AI RMF 1.0 (AI 100-1) | Managing risks of AI systems across their lifecycle | Anyone building or deploying AI |
| NIST CSF 2.0 | Organizing a cybersecurity program around six functions | Organizations building a security program, often US federal contractors |
| NIST SP 800-53 | Control catalog for federal information systems | Federal systems and their contractors |
| Cyber AI Profile (NIST IR 8596, draft) | A profile of CSF 2.0 for securing AI, using AI in defense and countering AI-enabled attacks | Security teams, as a CSF extension, not an AI RMF profile |
The last row trips people up. NIST's December 2025 preliminary draft of the Cyber AI Profile is an application of CSF 2.0, per NIST's announcement, so it sits beside this framework, not inside it.
Is the NIST AI Risk Management Framework Mandatory? Where It Stands in September 2026
No. NIST's own FAQ answers the question in two words: "No. NIST has produced the AI RMF as a voluntary Framework." Nothing in the framework creates a legal duty on its own, and nothing in NIST's materials describes a certification or attestation scheme for it. That is the honest starting point.
"Voluntary" is not the whole story, though. The policy ground around it has moved a lot since 2023, and a few of those moves affect how much weight you should put on it.
What has changed in US policy since the NIST AI Risk Management Framework was released
The framework's federal tailwind has shifted. Four dated facts matter:
- January 20, 2025: Executive Order 14110 (Safe, Secure, and Trustworthy Development and Use of AI), the order the Generative AI Profile was written under, was listed as rescinded in the White House's Initial Rescissions order.
- July 2025: America's AI Action Plan recommends that NIST "revise the NIST AI Risk Management Framework to eliminate references to misinformation, Diversity, Equity, and Inclusion, and climate change."
- Today: NIST's framework page states that "The AI RMF 1.0 is being revised as part of the White House AI Action Plan." I found no revised core text published there as of September 30, 2026.
- April 7, 2026: NIST released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure. It is a concept note, not a finished profile.
One detail is worth noticing. The current text's GOVERN 3 category is titled "Workforce diversity, equity, inclusion, and accessibility processes are prioritized," so the revision will presumably touch it. Nobody outside NIST knows the final wording yet.
State laws that point to the NIST AI Risk Management Framework
The framework has found a second life as a legal reference point, and the picture differs by state.
Texas is the live example. The Texas Responsible AI Governance Act (HB 149) took effect on January 1, 2026, and its enrolled text gives a defendant a defense where it substantially complies with the most recent version of NIST's "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile" or another nationally or internationally recognized AI risk management framework.
Colorado went the other way. SB 24-205 had an affirmative defense for NIST AI RMF or ISO 42001 alignment, but Colorado repealed and replaced that law with SB 26-189, signed May 14, 2026 and effective January 1, 2027, and VerifyWise's summary says the NIST and ISO affirmative defense was repealed along with the rest of that framework. Law-firm alerts, including Goodwin's, confirm the replacement and the removal of the old risk management program requirements.
That is not legal advice, and state AI law is moving quickly. The practical read: a defense tied to a named framework is worth having where it exists, but it is a reason to document your alignment, not a substitute for it.
How the NIST AI Risk Management Framework Is Structured: Core, Categories and Profiles
The framework has two parts. Part 1 covers how to frame AI risk and who the audience is. Part 2 is the Core, the part people actually mean when they say "implement the AI RMF."
The Core is four functions, each split into categories, then subcategories. I counted them straight from Tables 1 to 4 of NIST AI 100-1:
| Function | Categories | Subcategories |
|---|---|---|
| GOVERN | 6 | 19 |
| MAP | 5 | 18 |
| MEASURE | 4 | 22 |
| MANAGE | 4 | 13 |
| Total | 19 | 72 |
Some vendor pages give different numbers, such as "60 controls." NIST's own tables say 72 subcategories, so use that one. And "controls" is the wrong word anyway: these are outcomes, not tests a system passes or fails.
The seven characteristics of trustworthy AI
The Core exists to produce AI that is trustworthy, which NIST breaks into seven characteristics:
- Valid and reliable
- Safe
- Secure and resilient
- Accountable and transparent
- Explainable and interpretable
- Privacy-enhanced
- Fair, with harmful bias managed
NIST is explicit that you will not maximize all seven at once. Creating trustworthy AI requires balancing them based on the system's context of use, which is why the framework stays outcome-based and leaves the specifics to you.
Profiles: how the NIST AI Risk Management Framework becomes yours
A profile is an implementation of the functions, categories and subcategories for a specific setting, application or technology. The Generative AI Profile (covered below) is one. The critical infrastructure concept note is another in progress. The AI RMF has no maturity tiers, so you will not see anything like CSF's implementation tiers here.
The NIST AI RMF Core Functions: Govern, Map, Measure, Manage
The NIST AI RMF core functions are four, and GOVERN is the odd one out. NIST draws it as a cross-cutting function meant to inform, and be infused throughout, the other three, so the mental model is one ring of governance around a loop of Map, Measure and Manage.
The four functions below each follow the same pattern: what NIST asks for, what it looks like at a ten-person SaaS team, and a verdict.
Govern: who owns AI risk
GOVERN is the policies, accountability and culture layer. Its subcategories include understanding legal and regulatory requirements involving AI (GOVERN 1.1), keeping an inventory of AI systems (GOVERN 1.6), executive leadership taking responsibility for AI risk decisions (GOVERN 2.3) and handling risks from third-party software and data (the GOVERN 6 category).
At a small team, that is a one-page AI use policy, a spreadsheet of every AI feature and vendor model you use, and a named founder or CTO who signs off on new AI use.
Verdict: if you do only one function properly, do this one. An AI inventory you can hand to a customer is worth more than a long policy nobody reads.
Map: what the system is for and who it touches
MAP establishes context. MAP 1.1 asks that intended purposes, beneficial uses, relevant laws and the settings where the system will be deployed are understood and documented. Later categories characterize impacts on individuals, groups and society.
For a startup, this is a short intended-use statement per AI feature: what it does, what it must never be used for, who is affected when it is wrong, and which third-party models sit underneath.
Verdict: Map is where most "we use AI responsibly" claims either become specific or fall apart.
Measure: how you know it works
MEASURE is testing, evaluation, verification and validation, then tracking identified risks over time. It includes a notable independence requirement: MEASURE 1.3 asks that internal experts who did not serve as front-line developers, or independent assessors, take part in regular assessments.
For a small team, that means a written evaluation set for each AI feature, a rerun whenever the model or prompt changes, and someone other than the author reviewing the results.
Verdict: Measure is the function startups skip, and the one a sharp enterprise reviewer will probe.
Manage: what you do about it
MANAGE is acting on the risk. It covers prioritizing treatment by impact and likelihood (MANAGE 1.2), having mechanisms to supersede, disengage or deactivate a system that performs outside its intended use (MANAGE 2.4) and post-deployment monitoring including incident response, recovery and change management (MANAGE 4.1).
At ten people, that is a feature flag that can switch an AI feature off, production monitoring for output quality, and an incident path that already exists in your SOC 2 program.
Verdict: if you can switch an AI feature off in minutes and show how you would notice it misbehaving, you are ahead of most teams your size.
The NIST AI RMF Playbook, Crosswalks and Profiles
The framework tells you the outcomes. The NIST AI RMF Playbook suggests how to get there. It is organized around the four functions, with suggested actions aligned to subcategories, and NIST describes it as "neither a checklist nor set of steps to be followed in its entirety." Use as many or as few suggestions as apply.
NIST says it releases Playbook updates approximately twice a year, and that the Playbook will be updated after the AI RMF is revised.
NIST also hosts crosswalks that map the framework to other documents. The ISO ones are worth knowing about:
- ISO/IEC 23894 (AI risk management guidance): a revised crosswalk dated August 14, 2025, contributed by INCITS
- ISO/IEC 42005 (AI impact assessment): a crosswalk dated August 14, 2025, also from INCITS
- ISO/IEC 42001: a crosswalk listed on the page as contributed by Microsoft, with no date given
That last one deserves a caveat. The 42001 crosswalk is a third-party submission hosted by NIST, not a mapping NIST authored, so treat it as a useful starting point, not an official equivalence.
NIST AI 600-1: The Generative AI Profile for the NIST AI Risk Management Framework
NIST AI 600-1, the Generative AI Profile, is a companion to the AI RMF that NIST released on July 26, 2024. It defines risks that are novel to or exacerbated by generative AI and offers suggested actions organized by the framework's subcategories. NIST calls it a cross-sectoral profile, meaning it covers activities common across sectors, such as using large language models.
It was written pursuant to Executive Order 14110, which has since been rescinded. The profile itself was not withdrawn, and Texas's statute still names it. You can read the full text in NIST AI 600-1.
The profile names 12 risks. Here is all twelve, with my read on which a startup shipping an LLM feature should triage first:
| Risk (NIST's name) | Triage priority for a typical SaaS startup |
|---|---|
| Confabulation | High: wrong answers stated confidently, the most visible failure |
| Data Privacy | High: leakage of customer data into prompts, logs or training |
| Information Security | High: prompt injection and abuse of your AI endpoints |
| Value Chain and Component Integration | High: you inherit your model vendor's risks |
| Harmful Bias or Homogenization | Medium: depends on whether outputs affect people's opportunities |
| Intellectual Property | Medium: output and training-data provenance questions |
| Human-AI Configuration | Medium: over-reliance and automation bias in your own UX |
| Information Integrity | Medium: higher if you generate public-facing content |
| Dangerous, Violent, or Hateful Content | Lower for most B2B SaaS, higher if users can prompt freely |
| Obscene, Degrading, and/or Abusive Content | Lower for most B2B SaaS, higher if users can prompt freely |
| CBRN Information or Capabilities | Lower for most SaaS products that are not general-purpose models |
| Environmental Impacts | Lower as a day-to-day control, relevant to vendor choice |
The priority column is my judgment, not NIST's. NIST does not rank the risks for you, and your own context should override mine.
NIST AI RMF vs ISO 42001: Guidance You Align To, a Standard You Certify Against
Most comparison pages ask which one wins. The better question is what you need to be able to prove, and to whom.
The NIST AI Risk Management Framework is guidance. ISO 42001, published in December 2023, is a certifiable management system standard. If you need the long version of the standard itself, what is ISO 42001 covers the clauses and Annex A.
| Dimension | NIST AI RMF | ISO 42001 |
|---|---|---|
| Nature | Voluntary framework of outcomes | Management system standard with requirements |
| Publisher | US government (NIST) | ISO and IEC |
| Certifiable | No certification scheme in NIST's materials | Yes, through accredited certification bodies |
| Structure | 4 functions, 19 categories, 72 subcategories | 10 clauses, plus Annex A controls |
| Access | Free to download | Standard is purchased from ISO |
| What a customer can verify | Your own description of alignment | An auditor's certificate |
| Updates | Being revised; formal review by 2028 at the latest | Published December 2023 |
Verdict: NIST tells you which risks to think about. ISO 42001 gives you a system an auditor can test and a certificate a buyer can check.
Why "we align to the NIST AI RMF" is a weaker claim than a certificate
Nobody audits alignment. It is self-described, which is fine for an internal program and thin for a procurement team that has seen a hundred vague answers. The fair criticism of any voluntary framework is that it can degrade into paperwork.
Hacker News commenters said exactly that in April 2023, when the framework launched. One warned such frameworks risk becoming "a surface level, checklist ticking exercise" without a public feedback loop, and another dismissed it as having "no teeth" (see the launch thread). That is a launch-month take and partly dated, since the Playbook and Generative AI Profile have since added substance. The underlying worry, that nothing forces the work to be real, is still the gap an independent audit closes.
Using both without doubling the work
Here is how I would use them together. The NIST vocabulary (the four functions and the trustworthiness characteristics) is a good way to structure your risk work and explain it to a customer. ISO 42001 is what you pursue when a buyer wants a certificate, and the two overlap heavily because both come down to inventory, ownership, impact assessment, monitoring and improvement.
If certification is where you are heading, ISO 42001 certification cost breaks down the spend.
Where the NIST AI Risk Management Framework Meets Your SOC 2 Work
Your SOC 2 report already proves something about how you run a system, but it was never built to test whether an AI model is fair or safe. ComplyJet's guide to whether SOC 2 covers AI puts the boundary plainly: SOC 2 "was never built to test 'fairness, bias, responsible and ethical use, and safety.'"
That is exactly the ground the AI RMF covers, and it is why the two are complements. NIST publishes no official mapping between SOC 2 and the AI RMF, so the table below is my own reading of where your existing evidence feeds the framework, not an official crosswalk.
| Existing SOC 2 work (Trust Services Criteria area) | Where it plausibly supports the AI RMF |
|---|---|
| Risk assessment process (CC3) | GOVERN risk tolerance and MAP risk identification |
| Vendor and business partner risk management (CC9.2) | GOVERN 6 and MAP 4, third-party software and data |
| Monitoring and incident response (CC7) | MANAGE 4.1, post-deployment monitoring and incident response |
| Change management (CC8) | MANAGE 4.1 change management, re-evaluation after model or prompt changes |
| Access controls and logging | Evidence for MEASURE and MANAGE on who can change a model |
The practical upside for a startup is that you are not starting from zero. A team with a working vendor review, incident process and change log already has the operating habits that GOVERN and MANAGE assume. What is missing is usually the AI-specific layer: the inventory, the intended-use statements and the evaluation sets.
How a Startup Should Start With the NIST AI Risk Management Framework
The NIST AI RMF vs ISO 42001 question comes down to what you can prove, and a startup should not try to "implement" 72 subcategories to answer it. It should pick a small, defensible slice and keep it current.
- Inventory every AI system and model vendor (GOVERN 1.6). Include features, internal tools and any third-party model you call.
- Name one accountable owner (GOVERN 2.3). A person, not a committee.
- Write a one-page intended-use statement per system (MAP 1.1): purpose, out-of-scope uses, affected users, underlying models.
- Pick 10 to 15 subcategories and map your top generative AI risks from the table above to a concrete test for each.
- Add monitoring and a way to switch the feature off (MANAGE 2.4 and 4.1), and rehearse it once.
- Decide on ISO 42001 by one test: has a customer or partner asked for a certificate, or is one likely to?
So what should you choose?
- Align only if your customers ask for "alignment with NIST" and nobody has asked for a certificate. Steps 1 to 5 are enough, and they are cheap.
- Add ISO 42001 if enterprise buyers are putting "ISO 42001 certified or working toward it" in questionnaires, or your sales cycle keeps stalling on AI diligence.
- Otherwise, do steps 1 to 3 this week. They cost almost nothing and they are the first things anyone will ask for.
We support NIST AI RMF and ISO 42001 alongside SOC 2 on the ComplyJet platform, so the operating evidence you already collect for one does not get rebuilt for the next.
Common Misunderstandings About the NIST AI Risk Management Framework
These are the ones I see most often.
- "It's a checklist." NIST says the actions are not a checklist and not an ordered set of steps.
- "There is a NIST AI RMF certificate." NIST's materials describe no certification scheme. If a vendor sells you a "NIST AI RMF certification," ask who the accrediting body is.
- "It's the same as the NIST CSF." It is a separate framework with a different purpose and a different set of functions.
- "72 means 72 controls I must pass." The 72 subcategories are outcomes you choose among, not pass-fail tests.
- "The 2023 text is final." NIST states it is being revised, so version-name your claims.
- "The Generative AI Profile replaces the framework." It is a companion profile. It does not replace the Core.
FAQs
What is the NIST AI Risk Management Framework?
It is a voluntary framework from the US National Institute of Standards and Technology for managing AI risks, released as NIST AI 100-1 on January 26, 2023. It applies to any organization that designs, develops, deploys or uses AI, regardless of size or sector.
What are the four functions of the NIST AI RMF?
Govern, Map, Measure and Manage. Govern covers policies, accountability and culture across the other three. Map establishes context and impacts, Measure tests and tracks the risks, and Manage acts on them.
Is the NIST AI Risk Management Framework mandatory?
No. NIST's FAQ says it "has produced the AI RMF as a voluntary Framework." Some state laws and contracts may reference it, so check the terms you actually operate under.
Is the NIST AI Risk Management Framework a certification?
No. NIST's materials describe no certification or attestation scheme for it. If you need an auditable certificate for AI governance, ISO 42001 is the certifiable standard.
How many categories and subcategories does the NIST AI RMF have?
19 categories and 72 subcategories, split across Govern (6 and 19), Map (5 and 18), Measure (4 and 22) and Manage (4 and 13), based on the tables in NIST AI 100-1.
What is NIST AI 600-1?
It is the Generative AI Profile, released July 26, 2024. It defines 12 risks novel to or exacerbated by generative AI and offers suggested actions mapped to AI RMF subcategories.
How does the NIST AI Risk Management Framework compare to ISO 42001?
The AI RMF is voluntary guidance you align to and self-assess. ISO 42001 is a management system standard you can be certified against by an accredited body. Many teams use the NIST vocabulary to structure risk work and ISO 42001 when a customer wants a certificate.
Does a startup need the NIST AI RMF?
Not as a legal matter in most cases, but it is a useful, free structure for answering customer AI questions. A startup that ships an AI feature benefits most from the inventory, intended-use and monitoring steps.
Is the NIST AI RMF being updated?
Yes. NIST's page says AI RMF 1.0 is being revised as part of the White House AI Action Plan, and the Playbook will be updated after the revision. As of September 30, 2026, I found no revised core text published.
Related Reading
- What is ISO 42001: the certifiable standard that pairs with this framework
- ISO 42001 certification cost: what the certification path costs
- Does SOC 2 cover AI?: where your SOC 2 report stops on AI risk
- NIST compliance guide: NIST CSF 2.0, SP 800-171 and SP 800-53, the other family of NIST frameworks
- AI governance policy: how to write the policy document itself
- ISO 27001 and AI compliance: where AI governance meets an existing ISMS





