Almost every organization is now building, buying, or embedding AI, and most are doing it faster than their governance can keep up. The NIST AI Risk Management Framework (AI RMF) is the most widely referenced way to close that gap. It is voluntary, vendor-neutral, and built around outcomes rather than prescriptive controls, which is exactly why regulators, customers, and boards increasingly point to it as the baseline for responsible AI. This guide walks through what the AI RMF is, how it is organized, what the maturity tiers mean, how the Generative AI Profile extends it, and how to run your first assessment.
What Is the NIST AI Risk Management Framework?
The AI RMF (formally NIST AI 100-1) was released in January 2023, developed by the National Institute of Standards and Technology under the National AI Initiative Act of 2020. It is a voluntary framework that helps organizations manage the risks of designing, developing, deploying, evaluating, and using AI systems, and do it in a way that promotes trustworthy AI.
NIST defines trustworthy AI through seven characteristics that the framework keeps in view throughout: AI systems should be valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. The framework does not tell you to deploy a specific tool or hit a specific number. It describes the outcomes a mature AI risk program achieves and leaves the implementation to you.
The Four Functions: Govern, Map, Measure, Manage
The AI RMF organizes AI risk management into four functions. Three of them, Map, Measure, and Manage, run roughly in sequence across the AI lifecycle. The fourth, Govern, is cross-cutting: it informs and is informed by all the others, which is why it is the right place to start.
| Function | Categories | Subcategories | What it covers |
|---|---|---|---|
| Govern | 6 | 19 | Culture, policies, roles, accountability, workforce, and third-party / supply-chain risk. Cross-cutting. |
| Map | 5 | 18 | Establish context, categorize the AI system, and frame its risks and benefits. |
| Measure | 4 | 22 | Analyze, assess, benchmark, and monitor the identified risks with appropriate methods and metrics. |
| Manage | 4 | 13 | Prioritize and act on risks, allocate resources, and respond, recover, and communicate. |
Across the four functions, that is 19 categories and 72 subcategories in total. Each subcategory is an outcome (for example, "Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities"), not a control to be checked off. The practical work of an AI RMF assessment is deciding, for each of those 72 outcomes, how well your organization actually achieves it today and how well it needs to.
Outcomes, Not Controls: the Role of the Playbook
Because the AI RMF describes outcomes rather than controls, NIST publishes a companion AI RMF Playbook with suggested, voluntary actions for each subcategory. The Playbook is where the framework gets concrete: for an outcome about legal and regulatory awareness, it suggests maintaining awareness of laws specific to your sector and training staff on them; for one about AI inventory, it suggests resourcing and routinely updating that inventory. The Playbook is guidance, not a mandate, and you are meant to adopt the actions that fit your context.
This is also the right mental model for scoring. You are not asking "did we implement control X?" You are asking "to what degree do we achieve this outcome, and is that degree appropriate for our risk?"
Measuring Maturity: Where the AI RMF Stops and Practice Begins
Here is a nuance worth getting right. The AI RMF is deliberately outcome-based and use-case-agnostic. It does not prescribe a numbered tier model, maturity levels, or a required level of rigor, and the Playbook is explicit that it is "neither a checklist nor a set of steps to be followed." That flexibility is intentional, but it leaves a practical question: how do you score "to what degree" you achieve each outcome?
The common practitioner answer is a four-level maturity scale, using language most GRC teams already know from the NIST Cybersecurity Framework's Implementation Tiers:
- Partial: applied in an ad hoc, reactive way; awareness of the outcome is limited and practices are not formalized.
- Risk Informed: practices addressing the outcome are approved by management but may not be established as organization-wide policy.
- Repeatable: the outcome is addressed through formal, organization-wide policy that is regularly updated as risks and the mission change.
- Adaptive: practices are continuously improved from lessons learned and predictive indicators, and adapt to an evolving AI landscape.
It is also not a grade to maximize everywhere: a small team running a single low-risk model does not need the top level on every outcome. Set each subcategory's target to fit its risk to your organization, then measure the gap. In the Risk Posture AI RMF tool, you rate each subcategory on a current level and a target level, so the gap is the distance between the two. To make picking a level straightforward, every one of the 72 subcategories includes its own examples written for that specific outcome, plus the official Playbook actions and a crosswalk to related regulations.
How to Conduct an AI RMF Assessment
A first AI RMF assessment is more approachable than its 72 subcategories suggest. The work breaks into four steps:
- Set the context. Decide what you are assessing. The AI RMF is applied at the system level, so a customer-facing chatbot, a fraud model, and an HR screening tool each deserve their own assessment rather than one blended score. Record the system, your methodology, scope, and key assumptions so the result is defensible.
- Score the 72 subcategories. Work through Govern first, then Map, Measure, and Manage. For each outcome, set a current tier, a target tier, and a priority. You do not have to score everything in one sitting; coverage tells you how far along you are.
- Complete the Generative AI Profile if your system uses generative AI (more below).
- Review gaps and act. Roll the scores up into function-level maturity, a prioritized gap list, and a target-dated action plan, then route the gaps into your remediation and risk workflow.
A common first-assessment finding is a low average tier (an organization-wide 1.6 to 1.8 is typical for teams just starting), driven by the absence of an AI inventory, no AI-specific training, no documented bias evaluation for consequential systems, and no formal AI incident response. That is not a failing grade; it is a baseline and a roadmap.
The Generative AI Profile (NIST AI 600-1)
If your system uses or builds on generative AI, the Core functions alone do not capture everything. In July 2024, NIST released the Generative AI Profile (NIST AI 600-1), a companion to the AI RMF that names twelve categories of risk unique to, or amplified by, generative AI:
CBRN information or capabilities, confabulation (hallucinations), dangerous or violent or hateful content, data privacy, environmental impacts, harmful bias or homogenization, human-AI configuration, information integrity, information security (including prompt injection), intellectual property, obscene or abusive content, and value-chain and component integration.
The Profile does not replace the Govern / Map / Measure / Manage assessment; it supplements it for the systems where it applies. For each risk you decide whether it applies to your system, record your mitigations, and draw on the Profile's suggested actions. For organizations whose primary risk vector is a generative assistant, these often carry the highest near-term exposure, which is why surfacing them alongside the Core gaps matters.
The AI RMF and Regulation: EU AI Act, ISO/IEC 42001
The AI RMF is voluntary, but it does not exist in a vacuum. It is increasingly used to operationalize obligations that are not voluntary:
- EU AI Act. In force since August 2024, the Act applies in phases: its bans on unacceptable-risk AI since February 2025, its general-purpose AI model rules since August 2025, and its high-risk obligations from August 2026 and August 2027. It imposes risk management, data governance, transparency, human oversight, and accuracy and robustness obligations on high-risk AI. The AI RMF functions map cleanly onto many of these duties, which makes it a practical way to start building the evidence the Act will require.
- ISO/IEC 42001:2023 defines a certifiable AI management system. Organizations frequently pursue both: the AI RMF for the risk-by-risk substance and ISO 42001 for the management-system wrapper.
- Sectoral law. For consequential use cases like hiring, anti-discrimination law (EEOC and Title VII in the US, plus state automated-employment-decision laws such as NYC Local Law 144) makes bias evaluation a legal exposure, not just a best practice.
You do not need to be a lawyer to use the framework, but it helps to know which subcategory gaps carry regulatory weight. The Risk Posture AI RMF tool surfaces a per-subcategory crosswalk to these frameworks as reference, so the outcomes with compliance implications are visible while you assess.
Getting Started
The fastest way to understand the AI RMF is to work through it on a real system. Start with Govern, because culture and accountability underpin everything else, then move through Map, Measure, and Manage. Read each subcategory's tier examples before you rate it, use the priority and target-date fields to build a roadmap, and complete the Generative AI Profile if generative AI is in play. Treat the first pass as a baseline; the value compounds when you reassess and watch the trend move.
Frequently Asked Questions
What is the difference between the NIST AI RMF and the NIST RMF for information systems?
They share a name and a risk-based philosophy, but they are different frameworks. The AI RMF (AI 100-1) is purpose-built for the distinct risks of AI, such as data drift, emergent behavior, bias, explainability, and generative-AI-specific harms. The NIST Risk Management Framework for information systems (SP 800-37) is the seven-step authorization process. Don't confuse the two.
How is the NIST AI RMF organized?
The AI RMF organizes AI risk management into four functions: Govern, Map, Measure, and Manage. Map, Measure, and Manage run roughly in sequence across the AI lifecycle, while Govern is cross-cutting and informs all the others. Across the four functions there are 19 categories and 72 subcategories in total, and each subcategory is an outcome rather than a control to be checked off.
Does the NIST AI RMF define maturity tiers or levels?
No. The AI RMF is deliberately outcome-based and use-case-agnostic, and does not prescribe a numbered tier model, maturity levels, or a required level of rigor. The common four-level scale (Partial, Risk Informed, Repeatable, Adaptive) is a measurement overlay that originates in the NIST Cybersecurity Framework, not part of the AI RMF itself. Use it to track per-outcome progress, but don't present a rating like Repeatable as a NIST AI RMF requirement in a report.
When do I need the Generative AI Profile?
Complete the Generative AI Profile (NIST AI 600-1) if your system uses or builds on generative AI. It is a companion to the AI RMF that names twelve categories of risk unique to, or amplified by, generative AI. It does not replace the Govern, Map, Measure, and Manage assessment; it supplements it for the systems where it applies. For each risk you decide whether it applies to your system, record your mitigations, and draw on the Profile's suggested actions.
Related Reading
- How to Run a Free NIST CSF 2.0 Self-Assessment
- Tracking NIST CSF Maturity Over Time: The Benefits of a Trend, Not a Single Score
- RMF Simplified: How the Seven Steps Bring Clarity to System Authorization
- the free NIST AI RMF assessment tool
References
- NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0) (2023). doi.org/10.6028/NIST.AI.100-1
- NIST AI RMF Playbook and the AI Resource Center (the Core, all 72 subcategories, and suggested actions). airc.nist.gov
- NIST AI 600-1, AI RMF: Generative Artificial Intelligence Profile (2024). doi.org/10.6028/NIST.AI.600-1
- ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system. iso.org