Hael
Book a meeting
NIST AI RMF · Explained

NIST AI RMF Explained

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 7 min read
Key takeaways
  • The NIST AI Risk Management Framework is voluntary guidance published in January 2023. It is not a law and it cannot be certified against.
  • It has four functions, GOVERN, MAP, MEASURE and MANAGE, across 19 categories and 72 subcategories.
  • The Generative AI Profile, NIST AI 600-1, published in July 2024, adds twelve generative AI risks mapped to those functions.
  • Texas gives substantial compliance with the framework an enforcement safe harbour. Colorado's equivalent defence was repealed and did not survive.
  • NIST has confirmed that version 1.0 is being revised, and new profiles for cybersecurity, critical infrastructure and AI agents are in development.

The four functions

The NIST AI Risk Management Framework is a structured way of identifying and managing the risks that come with using artificial intelligence. It was published by the United States National Institute of Standards and Technology in January 2023, it is entirely voluntary, and it has become the reference point most American organisations use when they need to show they govern AI seriously.

It is guidance rather than regulation. Nobody enforces it directly, and no body certifies against it. What it does is give an organisation a common structure and a common vocabulary, which turns out to be what buyers, boards and increasingly regulators want to see.

The framework organises everything into four functions. They are not sequential stages; they run continuously and feed each other.

FunctionWhat it covers
GOVERNThe culture, policies, accountability and processes that sit across everything else. Who owns AI risk, how decisions get made, how third parties are managed
MAPEstablishing context. What the system does, who it affects, what the intended use is, what could go wrong, and what the organisation's risk tolerance is
MEASUREAnalysing, assessing and tracking the risks identified. Metrics, testing, evaluation, and monitoring over time
MANAGEActing on what was measured. Prioritising, responding, allocating resources, and recovering when something goes wrong

Beneath those sit 19 categories and 72 subcategories, which are the level at which the work actually happens. The companion Playbook offers suggested actions and references for each subcategory, which is where most implementation teams spend their time.

The trustworthy AI characteristics

The framework describes what it is aiming at: AI systems that are valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed.

Those characteristics are the point of the exercise. The functions and subcategories are the method for getting there. When a buyer asks whether your AI is trustworthy, that list is the vocabulary they are usually reaching for, even if they do not name it.

The Generative AI Profile

NIST published the Generative AI Profile, NIST AI 600-1, in July 2024. It is a companion rather than a replacement.

It catalogues twelve risks specific to or made worse by generative AI, including confabulation, information integrity, data privacy, harmful bias, information security and misuse, and maps mitigation actions onto the four core functions.

If your organisation uses large language models or other generative systems, you apply both: the base framework for the overall approach and the profile for the generative-specific risks. Federal agencies operating under OMB guidance use it as their reference for generative AI risk assessment, which is why it turns up in government contract requirements.

What is coming

NIST has confirmed that version 1.0 is being revised. Alongside that, several extensions are in development.

A draft Cyber AI Profile, connecting AI risk management to the Cybersecurity Framework 2.0. A concept note published in April 2026 for a profile covering trustworthy AI in critical infrastructure. Control overlays for securing AI systems under SP 800-53. And work through NIST's Center for AI Standards and Innovation on standards for AI agents, covering identity and authorisation, security, and monitoring and logging.

The practical implication is that an organisation implementing the framework now should expect to extend rather than rebuild. The four functions are stable; the profiles layer on top.

Why it matters commercially

Procurement. American enterprise buyers ask how you manage AI risk, and the framework is the answer they recognise. It gives a common structure to a conversation that otherwise has none.

Federal work. Agencies use it, and it flows into contract requirements for suppliers.

State law. Texas grants substantial compliance with the framework an enforcement safe harbour under its AI legislation, which took effect on 1 January 2026. Colorado's original AI Act contained a similar affirmative defence, but that statute was repealed and replaced in May 2026, and the defence did not survive into the successor. Outside Texas, the framework is recommended practice rather than a codified defence.

Other frameworks. NIST publishes crosswalks mapping the framework to ISO/IEC 42001 and the EU AI Act among others, so work done here transfers. See our ISO/IEC 42001 and EU AI Act service pages.

What it does not do

It does not certify you. There is no accredited body, no certificate and no audit. What that means in practice, and how organisations prove adoption to a buyer, is covered in What Is NIST AI RMF Compliance?

It does not make you compliant with any law. Outside the Texas safe harbour it creates no legal position at all.

It does not tell you what to do. It tells you what to consider. The subcategories are outcomes rather than controls, which makes the framework adaptable and also makes it harder to implement than a control list.

What to do next

Start with GOVERN and MAP. Knowing which AI systems you have, who owns each, and what each one affects is the prerequisite for everything in MEASURE and MANAGE.

Our free AI impact assessment gives a first view, and the NIST AI RMF service page sets out how an implementation runs.

References

FAQ

What is the NIST AI Risk Management Framework?

Voluntary guidance published in January 2023 for identifying and managing AI risk, organised into four functions across 19 categories and 72 subcategories.

Can you get certified in NIST AI RMF?

No. There is no certification, no accredited body and no audit. Organisations demonstrate adoption through documentation and, where a buyer needs assurance, an independent assessment.

Is it mandatory?

No. It is voluntary. Texas gives substantial compliance an enforcement safe harbour, and federal agencies use it, but there is no general legal obligation.

What is the Generative AI Profile?

NIST AI 600-1, published July 2024, cataloguing twelve generative AI risks and mapping mitigations onto the four core functions.

Is a new version coming?

NIST has confirmed AI RMF 1.0 is being revised, with additional profiles for cybersecurity, critical infrastructure and AI agents in development.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We take companies through the NIST AI Risk Management Framework, ISO/IEC 42001, the EU AI Act, SOC 2 and ISO 27001, and maintain the position afterwards. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on NIST AI RMF, free.

Answer a short set of questions and see what NIST AI RMF expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether NIST AI RMF applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to NIST AI RMF.

Or speak to us about your deadline. Book a meeting.