Back to Frameworks
Frameworks

NIST AI Risk Management Framework (NIST AI RMF)

Framework Name

NIST AI Risk Management Framework (AI RMF), formally NIST AI 100-1

Type

Voluntary

Region / Jurisdiction

United States (widely referenced globally as a practical baseline, even outside the US)

Enforcing Body / Certifying Party

National Institute of Standards and Technology (NIST), part of the US Department of Commerce. There is no certifying body and no certification, organizations self-assess and self-attest to alignment

Penalty / Consequence of Non-Compliance

No direct penalty, and nothing to be certified against in the first place. The practical consequence is indirect: several US regulators, including the FTC, CFPB, FDA, and SEC, reference AI RMF principles in their enforcement guidance, and federal contractors face growing pressure to show alignment with it

What It Is & Why It Matters

The NIST AI Risk Management Framework helps organizations manage risk across the AI lifecycle using four functions: Govern, Map, Measure, and Manage. Unlike ISO 42001, it is not something you get audited or certified against. It is closer to a shared vocabulary and a structured way of thinking about AI risk than a checklist, supported by a much longer companion Playbook that offers suggested actions for each part of the framework.

It matters because it has become the default reference point for AI governance in the US, even though following it is entirely optional. Several federal regulators point to it in their own guidance, and it increasingly shows up in vendor contracts and government procurement expectations. Since it can't be certified, adopting it is really about building genuine internal practice rather than earning a badge, which makes it a natural complement to ISO 42001 for organizations that want both the substance and a certifiable proof point.

Who Needs It

  • You operate in the US and want a recognized reference point for structuring AI governance, without pursuing formal certification
  • You are a federal contractor or sell into government agencies where NIST alignment is increasingly expected
  • You want a practical foundation to build toward ISO 42001 certification later, since the two overlap conceptually
  • You are already tracking to the EU AI Act or ISO 42001 and want a US-anchored framework to cross-reference
Book A Demo