Skip to main content
NIST AI 100-1, January 26, 2023

NIST AI Risk Management Framework: the complete guide

Every function, category and subcategory of AI RMF 1.0, in plain English, verified against the source document. 4 functions, 19 categories, 72 subcategories.

The NIST AI Risk Management Framework (AI RMF 1.0, published as NIST AI 100-1 on January 26, 2023) is the United States' voluntary national framework for managing AI risk. It organizes the work into four functions: GOVERN, MAP, MEASURE and MANAGE, broken into 19 categories and 72 subcategories, and defines seven characteristics of trustworthy AI. It is not law and carries no certification; it is the shared vocabulary most US organizations use to run AI risk work.

Last verified against NIST AI 100-1: August 25, 2026.

The instrument, in ten lines
Instrument
AI Risk Management Framework 1.0 (NIST AI 100-1)
Issued by
National Institute of Standards and Technology (NIST)
Issue date
January 26, 2023
Legal status
Voluntary guidance. No mandate, no certification scheme.
Structure
4 functions, 19 categories, 72 subcategories
Companion
AI RMF Playbook; Generative AI Profile (NIST-AI-600-1, July 26, 2024)
Last verified
August 25, 2026
The core of the framework

The four functions

The framework's entire method fits in four words. GOVERN builds the policies, people and culture. MAP establishes the context of each system. MEASURE tests the system against the risks. MANAGE acts on what was found. GOVERN wraps around the other three: it never finishes, because governance is the part that makes the rest happen at all.

What MEASURE measures

The seven characteristics of trustworthy AI

Section 3 of the framework defines what trustworthy AI even means, before the core tells you how to manage its risks. MEASURE 2 evaluates a system against every one of these, which is why that single category carries 13 of the framework's 72 subcategories.

Valid and reliable

The system does what it was built to do, and keeps doing it. NIST calls this the necessary condition: without it, the other six do not matter.

Safe

The system does not endanger human life, health, property or the environment, and it fails safely when pushed past its limits.

Secure and resilient

The system withstands attack and unexpected events, and recovers when they happen.

Accountable and transparent

What the system does and why can be explained to the people it affects, and someone answers for it.

Explainable and interpretable

How the system reaches its output can be described, and what that output means can be understood in context.

Privacy-enhanced

The system protects autonomy, identity and dignity, and handles data with the safeguards privacy requires.

Fair, with harmful bias managed

Bias is not assumed away; it is looked for, measured and managed across the lifecycle.

Section 6

Profiles: how the framework becomes your plan

The core is the same for everyone; a profile is where an organization makes it its own. The working pattern is a Current Profile (what is true today) against a Target Profile (what must be true). The gap between the two, prioritized by risk, is the implementation plan.

Use-case profiles

The framework applied to one setting: a hiring profile, a fair-housing profile. Same functions, tuned to one context's requirements and risk tolerance.

Temporal profiles

A Current Profile is where you are; a Target Profile is where you need to be. The gap between them is the work plan.

Cross-sectoral profiles

Risks that follow a technology everywhere it goes, like large language models or cloud services, governed once across sectors.

The question every buyer asks

Voluntary here, binding there

The AI RMF is voluntary: nothing in US federal law forces a private organization to use it, and NIST certifies no one against it. The EU AI Act is the opposite shape: binding law, hard deadlines, fines up to 35 million euros or 7 percent of global turnover for the worst violations. The two meet in practice: the Act tells you what you must achieve, and the RMF gives you a well-tested process for achieving it.

One warning that matters commercially: because there is no certification scheme, no organization is AI RMF certified. A vendor claiming certification is claiming something the framework does not offer. The honest claim is alignment shown as a Current Profile, a Target Profile, and a closing gap.

EU AI Act vs NIST AI RMF vs ISO 42001, side by side

Need a certificate an auditor accepts? Read the ISO/IEC 42001 guide

Two doors

Where to go from reading to running it

Practice

Run the decisions, not just the reading

The Global AI Governance Arena puts you in the regulator's chair across seven jurisdictions. Every GOVERN, MAP, MEASURE and MANAGE instinct shows up there as a decision with consequences.

Open the Arena
The program

Learn it end to end, with a credential

AI Governance: Applied Mastery walks the whole discipline: 88 topics, every one gated by a mastery assessment, ending in a signed credential an employer can verify. $399 for an individual.

See the program, $399
Eight answers

Frequently asked questions

Is the NIST AI RMF mandatory?

No. The framework is voluntary by design: the document describes itself as voluntary, rights-preserving, non-sector-specific and use-case agnostic. Congress directed NIST to build it under the National AI Initiative Act of 2020, but no law requires any organization to use it. Contrast with the EU AI Act, which is binding law with fines.

What are the four functions of the AI RMF?

GOVERN, MAP, MEASURE and MANAGE. GOVERN is cross-cutting: the policies, people and culture that make the rest real. MAP establishes context and frames the risks. MEASURE evaluates the system against the risks MAP found. MANAGE prioritizes, responds, recovers and communicates. The four break down into 19 categories and 72 subcategories.

Can my organization be NIST AI RMF certified?

No. NIST runs no certification scheme for the AI RMF, and no body is empowered to grant AI RMF certification. Any vendor selling one is selling something the framework does not contain. What organizations do instead is build a Current Profile, set a Target Profile, and show the gap closing.

How does the AI RMF relate to the EU AI Act?

They answer different questions. The AI RMF is a voluntary risk-management process: how to find, measure and treat AI risk inside an organization. The EU AI Act is binding law: what you must and must not do, with deadlines and fines. An organization selling into Europe needs the Act; the RMF is one well-regarded way to organize the work the Act demands. Our side-by-side guide walks the two together.

What is the Generative AI Profile?

NIST-AI-600-1, released July 26, 2024. It applies the AI RMF to generative AI specifically: twelve risks the base framework does not fully cover, from confabulation to data privacy to information integrity, each with suggested actions keyed back to the four functions.

What is the difference between a category and a subcategory?

A category is one outcome to achieve, like GOVERN 2: accountability structures in place. Its subcategories are the specific things that must be true for the outcome to hold, like GOVERN 2.3: executive leadership takes responsibility for AI risk decisions. Categories are the headings; subcategories are the checklist.

Who is the AI RMF for?

NIST addresses it to AI actors: everyone who plays an active role in the AI lifecycle, from the teams that design and build systems to the executives who answer for them. It is deliberately sector-agnostic: a hospital, a bank and a school district can each build their own profile from the same core.

Where do I start?

With a Current Profile: walk the categories, mark what is already true, and be honest about what is not. That gap, against a Target Profile, is your first quarter of work. GOVERN 1 and GOVERN 2 are where most organizations start, because nothing else holds without policies and named owners.

Know the framework. Then prove you can run it.

72 subcategories is a checklist, not a skill. The skill is making these calls under pressure, for a real organization, and leaving a record that survives an audit.

Primary only

Sources and verification

This guide paraphrases the framework in plain English and links the primary source throughout. It is not legal advice, and it is not affiliated with or endorsed by NIST. The structure (function, category and subcategory identifiers) follows NIST AI 100-1 exactly; the wording is ours. Last verified: August 25, 2026.