Update cookies preferences

NIST AI Risk Management Framework

Updated:
 
August 12, 2026
Overview

The NIST AI Risk Management Framework, AI RMF 1.0, is a voluntary United States framework for managing risks in the design, development, deployment, and use of AI systems. It is structured around four functions – Govern, Map, Measure, and Manage – and NIST has since published a Generative AI Profile extending it to generative systems.

  • A voluntary US framework for managing AI risk across the lifecycle
  • Structured around four functions: Govern, Map, Measure, and Manage
  • The most widely referenced framework in US enterprise AI governance
  • The Generative AI Profile extends it to generative and agentic systems

Why is the NIST AI Risk Management Framework important?

The AI RMF matters because it is the most widely referenced framework in United States enterprise AI governance, and it is increasingly used outside the US as a vendor-neutral structure for AI risk management. Federal contractors and regulated industries cite it directly, which means it shows up in contracts and questionnaires whether or not an organization adopted it deliberately.

Its usefulness comes from being process-shaped rather than control-shaped. It does not tell you which product to deploy; it tells you which questions to be able to answer and in what order. That makes it durable as the technology changes, and it makes it a reasonable spine for a program that has to cover both conventional models and agents.

The Govern function is the part most directly relevant to security teams now. It covers the operational accountability questions enterprises are being asked – who owns an AI system, under what policy it operates, and how that policy is enforced and evidenced – which is precisely the ground agent deployments have made urgent.

What is the NIST AI Risk Management Framework?

The AI RMF is guidance published by the National Institute of Standards and Technology for identifying and managing risks across an AI system's lifecycle. It is voluntary, non-sector-specific, and designed to be adapted rather than adopted verbatim.

Four functions organize it. Govern establishes the culture, accountability structures, and policies that everything else depends on, and it runs continuously rather than as a first phase. Map establishes context: what the system is, what it is for, who it affects, and what could go wrong. Measure develops and applies methods for assessing the risks Map identified, including adversarial testing. Manage acts on what Measure produced – prioritizing, treating, and monitoring risk over time.

NIST has extended the framework with the Generative AI Profile, which addresses risks specific to generative systems including confabulation, data leakage through third-party tools, and information integrity. That profile is the more directly applicable document for anything involving language models or agents.

Types of NIST AI RMF functions

The four functions are the framework's structure, and each produces different artifacts.

Govern is the cross-cutting function. It defines roles, accountability, policy, and the culture that determines whether the other three happen honestly. Its outputs are ownership assignments, policies, and escalation paths.

Map is the context-setting function. It categorizes AI systems, establishes intended use and foreseeable misuse, and identifies affected parties. Its outputs are an inventory with classifications and documented assumptions – which is why discovery capability is a precondition rather than an optimization.

Measure is the assessment function. It selects metrics, tests systems including adversarially, and evaluates trustworthiness characteristics. Its outputs are test results, evaluations, and monitoring baselines.

Manage is the action function. It prioritizes risks, allocates resources, applies treatments, and monitors residual risk. Its outputs are decisions and the evidence they were carried out.

Profiles sit alongside the functions as use-case or sector-specific overlays, with the Generative AI Profile the most relevant here.

NIST AI RMF & Onyx

Onyx aligns explicitly to the Govern, Map, Measure, and Manage functions, with the platform producing the artifacts each one expects rather than leaving them to be assembled by hand.

Map is served by discovery and inventory across surfaces, with tagging that carries ownership and classification. Measure is served by posture scoring across exposure, privilege, data access, autonomy, and blast radius, alongside continuous adversarial testing. Manage is served by inline enforcement and the decision record that shows a treatment was applied to a specific request. Govern is served by policy authored in readable terms by the people accountable for it, which is what keeps the accountability structure the function describes intact. AI Governance is where that mapping is operated.

Frequently Asked Questions

Is the NIST AI RMF mandatory?
No, it is voluntary guidance. In practice it arrives through other routes such as federal contracting requirements and customer security questionnaires, so many organizations end up needing to demonstrate alignment without ever formally adopting it.
How does the AI RMF relate to the EU AI Act?
They are complementary. The AI RMF is voluntary process guidance; the EU AI Act is binding law with classifications and penalties. Running the AI RMF well produces much of the documentation and evidence the Act's high-risk obligations require.
What is the Generative AI Profile?
NIST AI 600-1, an overlay on the core framework addressing risks specific to generative systems, including confabulation, data leakage through third-party tools, and information integrity. For anything involving language models or agents it is the more applicable document.
Which function should an organization start with?
Map, in practice, because the other three depend on knowing what you have. Govern is described as cross-cutting and continuous, so it is not sequenced first so much as always running – but an inventory is what makes the rest actionable.
Does the framework address AI agents?
Not by that name in the core document, though the functions apply cleanly. Agent-specific concerns such as autonomy and action authority fit under Map and Measure, and the Generative AI Profile covers the closest named risks.
Related terms:
Table of Contents