What is the NIST AI Risk Management Framework?

The NIST AI Risk Management Framework, usually shortened to the AI RMF, is a voluntary framework published by the National Institute of Standards and Technology to help organizations identify, measure, and manage risk across the life of an AI system. NIST released AI RMF 1.0 on January 26, 2023, and built it around four functions: govern, map, measure, and manage. It is not a law, not a certification, and not a checklist. For a founder selling AI-enabled software into the enterprise, it has become something more immediately useful than any of those. It is the vocabulary your buyers are using when they ask how you control your models.

The framework is voluntary, and that is exactly what makes it usable

NIST describes the AI RMF as voluntary, rights-preserving, non-sector-specific, and use-case agnostic. No agency certifies you against it, and no auditor issues an AI RMF report the way one issues a SOC 2 report. That sounds like a weakness until you are the one adopting it. A voluntary framework scales down honestly: a nine-person team can implement the parts that fit its risk profile and document the reasoning for the rest. NIST states plainly that the framework's actions "do not constitute a checklist, nor are they necessarily an ordered set of steps."

Four functions carry the entire framework

Govern cultivates a culture of risk management across everything the organization designs, develops, deploys, evaluates, or acquires. Map establishes the context: what the system is for, who it touches, and what could go wrong. Measure applies quantitative, qualitative, or mixed-method techniques to analyze and monitor that risk. Manage allocates resources against the risks that map and measure surfaced. Govern runs continuously and sits underneath the other three. The other three attach to specific systems at specific points in the AI lifecycle, which is why the same framework works for one model and for forty.

For a small team, govern is where the real work sits and where it is most often skipped. It means a named owner for AI risk, a documented path a new use case travels before it reaches customers, and a decision record when someone chooses speed over a control. None of that requires a committee. It requires that the answer to "who decided this, and on what basis" exists in writing before a buyer, an investor, or your own engineers need it eighteen months from now.

Seven characteristics define what NIST means by trustworthy

The AI RMF names seven characteristics of a trustworthy AI system: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. Validity and reliability sit first because nothing else matters in a system that does not work. The characteristics are deliberately in tension. Maximum explainability can cost accuracy, and aggressive privacy protection can constrain the data available for bias testing. NIST expects you to make those tradeoffs consciously and record why, rather than pretend all seven maximize together.

Profiles adapt the framework to your context

A profile is the AI RMF applied to a specific technology, sector, or use case. NIST published the Generative AI Profile, NIST AI 600-1, on July 26, 2024, identifying risks distinctive to generative systems and proposing actions against them. A profile for trustworthy AI in critical infrastructure entered development with a concept note on April 7, 2026. Profiles are where the framework stops being abstract. If you build generative features, the generative profile is the more practical starting point, and it maps back to the same four functions.

Enterprise buyers reach the framework before regulators do

Procurement is the fastest-moving force here. Security questionnaires now carry dedicated AI governance sections, and the AI RMF is one of the frameworks those sections name. A buyer's third-party risk team is not asking whether you are certified, because no certification exists. They are asking whether you can describe your governance in a structure they recognize, produce an inventory of your models, and explain how you test them. Teams that answer in the framework's own language move through review faster, and security reviews are where deals quietly stall.

The asymmetry is worth naming. The buyer's reviewer has a form to complete and limited patience for bespoke explanations. A vendor who answers in framework structure lets that reviewer close the item and move on. A vendor who answers in prose, however accurate, creates a follow-up call, then a second questionnaire, then a delay that nobody logs as a compliance problem because it shows up in the sales forecast instead. Structure is not bureaucracy here. It is throughput.

Some state AI laws point at the framework by name

Texas House Bill 149, the Texas Responsible Artificial Intelligence Governance Act, took effect January 1, 2026, and its text treats substantial compliance with the NIST AI Risk Management Framework, or a similar recognized framework, as an affirmative defense in enforcement actions brought by the state attorney general. Other state proposals have referenced it in comparable terms. This is general information about how one statute is drafted, not an assessment of whether it reaches your company. Whether any AI statute applies to your business is a question for your legal counsel, and we would recommend asking it early.

The framework is under revision, and your program should not wait

America's AI Action Plan, published in July 2025, directs the Department of Commerce through NIST to "revise the NIST AI Risk Management Framework to eliminate references to misinformation, Diversity, Equity, and Inclusion, and climate change." NIST confirms the revision is underway. As of September 2026, AI RMF 1.0 remains the published version. The structure that carries operational weight, the four functions and the lifecycle discipline underneath them, is not what is being edited. A program built on govern, map, measure, and manage will survive the revision intact.

The Playbook turns the framework into work you can assign

The framework itself states outcomes. The companion AI RMF Playbook, hosted at the NIST AI Resource Center, offers "suggested actions and documentation practices to help achieve the outcomes in the AI RMF." That distinction matters when you are staffing this. The framework tells you that AI risks are documented and monitored; the Playbook suggests what documenting and monitoring look like in practice. The Resource Center also publishes crosswalks to other governance frameworks and use case artifacts contributed by adopting organizations. NIST has said the Playbook will be updated once the revision to AI RMF 1.0 lands.

The AI RMF, ISO 42001, and SOC 2 do three different jobs

They are complements, not competitors. The AI RMF gives you a risk method and a shared vocabulary, with no certificate at the end. ISO/IEC 42001 gives you a certifiable AI management system, which matters when a buyer wants third-party attestation specific to AI. SOC 2 addresses your security and availability controls, and it does not cover model risk, training data provenance, or output monitoring. A buyer who has read your SOC 2 report and still asks about AI governance is not being difficult. They are reading the scope correctly.
Framework What it gives you Certificate at the end
NIST AI RMF A risk method and a shared vocabulary for AI governance No
ISO/IEC 42001 A certifiable AI management system Yes
SOC 2 Security and availability controls, not model risk or output monitoring Report, not a certificate

Adopting the framework works in three moves

Assess, build, prove. Assess means inventorying every AI system in use, including the vendor tools your team adopted without telling anyone, then mapping context and potential harms for each. Build means standing up the governance layer: named owners, an approval path for new use cases, testing and monitoring appropriate to the risk, and documentation that a stranger could follow. Prove means packaging that evidence so a buyer's reviewer can verify it without a call. Most teams already do parts of this informally. The framework turns informal practice into evidence that moves through diligence.

Sequence matters more than completeness. A team that inventories thoroughly and governs nothing has a spreadsheet. A team that writes an AI policy without knowing which systems are running has a document that will be wrong within a quarter. Inventory first, because everything downstream depends on knowing what exists, and revisit it on a schedule rather than when a questionnaire forces it.

Three habits make adoption harder than it needs to be

The first is treating the framework as a document to comply with rather than a method to run. It has no compliance state, so a binder proves nothing. The second is scoping to models your team built while ignoring the AI embedded in tools your team bought, which is where most real exposure now sits. The third is measuring what is convenient rather than what is risky: latency and uptime get monitored because they already were, while output quality, drift, and harmful bias go unmeasured because nobody owns them yet.

Frequently Asked Questions

Is the NIST AI RMF mandatory?
No. NIST publishes it for voluntary use, and no federal agency certifies organizations against it. Some state AI statutes and federal procurement processes reference it, and enterprise buyers increasingly ask about it in vendor review. Whether any specific requirement reaches your business is a question for your legal counsel.
Can you get certified in the NIST AI RMF?
No certification exists for the AI RMF itself. Organizations that want a certificate specific to AI management typically pursue ISO/IEC 42001. You can, and should, document your alignment with the AI RMF and share that documentation with buyers directly.
How long does it take a startup to align with the AI RMF?
For a team with a handful of AI use cases and existing security practice, a defensible first pass usually takes eight to twelve weeks: inventory and context mapping, then governance structure, then evidence packaging. Teams with dozens of models or heavy vendor sprawl take longer.
What is the difference between the AI RMF and the Generative AI Profile?
The AI RMF is the general framework. The Generative AI Profile, NIST AI 600-1, applies that framework to generative systems specifically, naming risks such as data poisoning, prompt injection, and synthetic content. If your product uses generative AI, start with the profile and work back to the core.
Does a SOC 2 report cover AI governance?
Not on its own. SOC 2 addresses security, availability, and related trust services criteria. It does not speak to model inventory, training data provenance, evaluation methodology, or output monitoring, which is why buyers ask about AI governance separately.
Will the pending revision make our current work obsolete?
The published revision direction targets specific references, not the four-function architecture. Governance, context mapping, measurement, and management remain the operational core, so work grounded in that structure carries forward.

Start with what your buyers can already see

The fastest way to understand what an AI governance posture looks like from the outside is to look at one. Our trust posture, subprocessors, and documentation are published rather than described. Visit the Aetos Trust Center.

Read More On This Topic

Shayne Adler

Shayne Adler is the co-founder and Chief Executive Officer (CEO) of Aetos Data Consulting, specializing in cybersecurity due diligence and operationalizing regulatory and compliance frameworks for startups and small and midsize businesses (SMBs). With over 25 years of experience across nonprofit operations and strategic management, Shayne holds a Juris Doctor (JD) and a Master of Business Administration (MBA) and studied at Columbia University, the University of Michigan, and the University of California. Her work focuses on building scalable compliance and security governance programs that protect market value and satisfy investor and partner scrutiny.

Connect with Shayne on LinkedIn

https://www.aetos-data.com
Next
Next

How Can Businesses Demonstrate Compliance in AI Transactions?