NIST AI Risk Management Framework

NIST AI Risk Management Framework

NIST AI Risk Management Framework

Released in January 2023 by the National Institute of Standards and Technology, the AI RMF provides a structure for identifying and managing AI risks across a system's lifecycle. Its four core functions are Govern, establishing culture and accountability, Map, establishing context and risks, Measure, assessing and tracking them, and Manage, prioritizing and responding.

It is voluntary, sector-agnostic, and designed to be adapted rather than certified against.

Alternative Names:

NIST AI RMF, AI RMF 1.0

Why it Matters?

The AI RMF has become the common vocabulary for AI governance conversations between legal technology vendors and enterprise buyers. Carriers and large firms increasingly ask vendors to map their controls to its functions during procurement, so alignment is a practical sales requirement even though no certification exists.

Frequently Confused with

Related terms

Frequently asked questions

Is NIST AI RMF compliance mandatory?

Is NIST AI RMF compliance mandatory?

No. It is a voluntary framework with no certification or enforcement, though procurement processes and underwriting questionnaires increasingly reference it.

How does it differ from ISO/IEC 42001?

How does it differ from ISO/IEC 42001?

The NIST framework is a flexible risk management structure. ISO/IEC 42001 is a certifiable management system standard with formal audit requirements.