What is the NIST AI Risk Management Framework?
On This Page
- The framework is voluntary, and that is exactly what makes it usable
- Four functions carry the entire framework
- Seven characteristics define what NIST means by trustworthy
- Profiles adapt the framework to your context
- Enterprise buyers reach the framework before regulators do
- Some state AI laws point at the framework by name
- The framework is under revision, and your program should not wait
- The Playbook turns the framework into work you can assign
- The AI RMF, ISO 42001, and SOC 2 do three different jobs
- Adopting the framework works in three moves
- Three habits make adoption harder than it needs to be
- Frequently Asked Questions
The framework is voluntary, and that is exactly what makes it usable
NIST describes the AI RMF as voluntary, rights-preserving, non-sector-specific, and use-case agnostic. No agency certifies you against it, and no auditor issues an AI RMF report the way one issues a SOC 2 report. That sounds like a weakness until you are the one adopting it. A voluntary framework scales down honestly: a nine-person team can implement the parts that fit its risk profile and document the reasoning for the rest. NIST states plainly that the framework's actions "do not constitute a checklist, nor are they necessarily an ordered set of steps."
Four functions carry the entire framework
For a small team, govern is where the real work sits and where it is most often skipped. It means a named owner for AI risk, a documented path a new use case travels before it reaches customers, and a decision record when someone chooses speed over a control. None of that requires a committee. It requires that the answer to "who decided this, and on what basis" exists in writing before a buyer, an investor, or your own engineers need it eighteen months from now.
Seven characteristics define what NIST means by trustworthy
The AI RMF names seven characteristics of a trustworthy AI system: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. Validity and reliability sit first because nothing else matters in a system that does not work. The characteristics are deliberately in tension. Maximum explainability can cost accuracy, and aggressive privacy protection can constrain the data available for bias testing. NIST expects you to make those tradeoffs consciously and record why, rather than pretend all seven maximize together.
Profiles adapt the framework to your context
A profile is the AI RMF applied to a specific technology, sector, or use case. NIST published the Generative AI Profile, NIST AI 600-1, on July 26, 2024, identifying risks distinctive to generative systems and proposing actions against them. A profile for trustworthy AI in critical infrastructure entered development with a concept note on April 7, 2026. Profiles are where the framework stops being abstract. If you build generative features, the generative profile is the more practical starting point, and it maps back to the same four functions.
Enterprise buyers reach the framework before regulators do
The asymmetry is worth naming. The buyer's reviewer has a form to complete and limited patience for bespoke explanations. A vendor who answers in framework structure lets that reviewer close the item and move on. A vendor who answers in prose, however accurate, creates a follow-up call, then a second questionnaire, then a delay that nobody logs as a compliance problem because it shows up in the sales forecast instead. Structure is not bureaucracy here. It is throughput.
Some state AI laws point at the framework by name
Texas House Bill 149, the Texas Responsible Artificial Intelligence Governance Act, took effect January 1, 2026, and its text treats substantial compliance with the NIST AI Risk Management Framework, or a similar recognized framework, as an affirmative defense in enforcement actions brought by the state attorney general. Other state proposals have referenced it in comparable terms. This is general information about how one statute is drafted, not an assessment of whether it reaches your company. Whether any AI statute applies to your business is a question for your legal counsel, and we would recommend asking it early.
The framework is under revision, and your program should not wait
America's AI Action Plan, published in July 2025, directs the Department of Commerce through NIST to "revise the NIST AI Risk Management Framework to eliminate references to misinformation, Diversity, Equity, and Inclusion, and climate change." NIST confirms the revision is underway. As of September 2026, AI RMF 1.0 remains the published version. The structure that carries operational weight, the four functions and the lifecycle discipline underneath them, is not what is being edited. A program built on govern, map, measure, and manage will survive the revision intact.
The Playbook turns the framework into work you can assign
The framework itself states outcomes. The companion AI RMF Playbook, hosted at the NIST AI Resource Center, offers "suggested actions and documentation practices to help achieve the outcomes in the AI RMF." That distinction matters when you are staffing this. The framework tells you that AI risks are documented and monitored; the Playbook suggests what documenting and monitoring look like in practice. The Resource Center also publishes crosswalks to other governance frameworks and use case artifacts contributed by adopting organizations. NIST has said the Playbook will be updated once the revision to AI RMF 1.0 lands.
The AI RMF, ISO 42001, and SOC 2 do three different jobs
| Framework | What it gives you | Certificate at the end |
|---|---|---|
| NIST AI RMF | A risk method and a shared vocabulary for AI governance | No |
| ISO/IEC 42001 | A certifiable AI management system | Yes |
| SOC 2 | Security and availability controls, not model risk or output monitoring | Report, not a certificate |
Adopting the framework works in three moves
Sequence matters more than completeness. A team that inventories thoroughly and governs nothing has a spreadsheet. A team that writes an AI policy without knowing which systems are running has a document that will be wrong within a quarter. Inventory first, because everything downstream depends on knowing what exists, and revisit it on a schedule rather than when a questionnaire forces it.
Three habits make adoption harder than it needs to be
The first is treating the framework as a document to comply with rather than a method to run. It has no compliance state, so a binder proves nothing. The second is scoping to models your team built while ignoring the AI embedded in tools your team bought, which is where most real exposure now sits. The third is measuring what is convenient rather than what is risky: latency and uptime get monitored because they already were, while output quality, drift, and harmful bias go unmeasured because nobody owns them yet.
Frequently Asked Questions
Start with what your buyers can already see
The fastest way to understand what an AI governance posture looks like from the outside is to look at one. Our trust posture, subprocessors, and documentation are published rather than described. Visit the Aetos Trust Center.