The NIST AI Risk Management Framework (AI RMF) is a voluntary framework published by the U.S. National Institute of Standards and Technology to help organizations identify, assess, and manage risks from AI systems. It is organized around four core functions: Govern, Map, Measure, and Manage. This NIST AI RMF guide walks through what each function requires in practice, not just what it says on paper.
Most organizations that read the AI RMF nod along and then struggle to translate it into a Monday-morning workflow. The framework is deliberately non-prescriptive: it tells you what outcomes to achieve, not which tool or template to use. That flexibility is useful for an organization writing its first AI policy, but it leaves a gap between the document and the day-to-day work of a governance team. This piece closes that gap.
What Is the NIST AI RMF, and Why Does It Matter Now?
NIST released the AI RMF 1.0 in January 2023, developed with input from industry, academia, and civil society over an 18-month process. It is voluntary and sector-agnostic, meaning it applies whether an organization builds AI systems, buys them, or simply uses AI-enabled products from vendors.
Its relevance has grown because regulators keep pointing to it. The framework is increasingly cited as a reference point in U.S. federal guidance and by organizations preparing for other AI regulations, including the EU AI Act, because its four-function structure maps cleanly onto what regulators expect: governance, risk identification, measurement, and response. Understanding this NIST AI RMF guide is a reasonable starting point for any organization building an AI governance program from scratch.
Govern: Who Owns AI Risk in Your Organization?
Govern is the foundation function. It concerns the culture, policies, and accountability structures that make the other three functions possible. Without Govern in place, Map, Measure, and Manage tend to happen inconsistently, owned by whichever team happens to be closest to a given AI project.
In practice, Govern means naming who is accountable for AI risk decisions, not just who is responsible for AI projects. It means establishing policies for acceptable AI use, documenting roles across legal, technical, and business functions, and building a mechanism for escalation when an AI system's risk profile changes. It also means setting expectations for third-party AI tools and vendors, since most organizations use AI they did not build.
A working Govern function looks like a short list of named owners, a policy document that people actually reference, and a recurring review cadence, not an annual PDF nobody opens.
Govern also sets the organization's risk tolerance before any specific AI system is evaluated. Without a stated tolerance, every project ends up negotiating its own definition of "acceptable risk," which slows approvals and produces inconsistent decisions across teams. A clear tolerance statement, even a short one, gives every later function a shared reference point.
Map: What Are You Actually Building or Buying?
Map is where an organization catalogs its AI systems and understands the context each one operates in: who it affects, what decisions it influences, and what could go wrong. This function is where many organizations discover they have more AI in production than they realized, often embedded in vendor tools rather than built in-house.
Mapping requires answering concrete questions for each system: What is its intended purpose? Who are the affected stakeholders? What happens if it fails or behaves unexpectedly? Is it making or informing a decision that affects a person's access to a job, credit, housing, or similar opportunity? These questions determine how much scrutiny a given system needs later in Measure and Manage.
A practical Map exercise produces an inventory, not a narrative. Each entry should record the system's purpose, its data sources, the population it affects, and a first-pass risk category.
The inventory itself is a governance artifact, not a one-time exercise. New AI features ship inside existing software updates, sales teams adopt AI tools without a formal procurement process, and individual employees experiment with generative AI on their own accounts. A Map process that only runs at project kickoff will miss most of this activity. Building a recurring intake step, even something as simple as a quarterly prompt to department heads asking what AI tools their team has started using, keeps the inventory close to reality.
Measure: How Do You Know If an AI System Is Working as Intended?
Measure is the function most often skipped, because it requires technical testing rather than policy writing. It covers the metrics, testing methods, and monitoring processes that tell an organization whether an AI system performs as intended and where it falls short, including on accuracy, fairness, robustness, and security.
Measurement is not a one-time test before launch. NIST's framing treats it as an ongoing activity, because model behavior can drift as input data changes, as the system is used in new contexts, or as the underlying model is updated. A system measured as low-risk at launch can look different six months later.
Concrete Measure activities include testing for performance across different subgroups, red-teaming for adversarial inputs, tracking incidents and near-misses, and setting thresholds that trigger a review when a metric moves outside an acceptable range. The output of Measure feeds directly into Manage: without a measurement, there is nothing to manage against.
Measurement also has limits worth naming honestly. Some risks, including certain fairness and bias concerns, do not reduce cleanly to a single number, and quantitative metrics can create false confidence when they miss context that only qualitative review catches. NIST's own guidance acknowledges this tension: it recommends combining quantitative testing with structured human judgment rather than treating a passing metric as proof a system is safe.
Manage: What Happens When Something Goes Wrong?
Manage is the function that turns findings from Map and Measure into action. It covers prioritizing risks, allocating resources to address them, and deciding whether a given AI system's risk is acceptable, needs mitigation, or means the system should not be deployed at all.
This is also where response planning lives: what happens when a model underperforms in production, when a stakeholder complaint surfaces a fairness issue, or when a vendor changes an underlying model without notice. Manage requires a documented process for these scenarios before they happen, not improvisation after the fact.
Manage closes the loop back to Govern. Decisions made here, including which risks were accepted and why, should update the policies and accountability structures that Govern established, so the framework functions as a cycle rather than a one-time checklist.
Manage is also where an organization decides on residual risk, the risk that remains after mitigation. Not every issue Measure surfaces can be engineered away entirely. Documenting what was accepted, by whom, and under what conditions is what makes a Manage decision defensible later, whether to an internal audit committee, a customer, or a regulator.
Mapping the Four Functions to Practical Actions
| Function | Core Question | Practical Actions |
|---|---|---|
| Govern | Who owns AI risk decisions? | Name accountable owners; write an AI use policy; set vendor AI requirements; establish escalation paths |
| Map | What are we building or buying, and who does it affect? | Inventory all AI systems; document purpose, data, and affected stakeholders; assign initial risk categories |
| Measure | Is the system performing as intended? | Test for accuracy, fairness, robustness, and security; red-team for adversarial cases; monitor for drift over time |
| Manage | What do we do about the risks we found? | Prioritize risks by severity; allocate mitigation resources; document incident response; decide go/no-go on deployment |
How This NIST AI RMF Guide Applies to a Real AI Project
Consider a hypothetical customer-service AI tool that routes support tickets and drafts response suggestions. Govern would require naming the team accountable for its risk profile and confirming it falls under the organization's AI use policy. Map would document that it processes customer data, influences response prioritization, and affects both customers and support staff.
Measure would test whether ticket routing is consistent across customer segments and whether drafted responses meet accuracy and tone standards, then monitor those metrics after launch. Manage would define what happens if the tool misroutes a high-priority ticket: who is notified, how the issue is corrected, and whether the incident changes the system's risk category.
This same pattern, Govern setting the structure, Map defining the system, Measure testing it, Manage acting on findings, applies whether the AI system is a chatbot, a hiring screen, or a fraud detection model. The four functions do not run once in sequence and stop. NIST describes them as interrelated and iterative, which means an organization revisits all four as systems change, as new AI tools are adopted, and as the regulatory environment shifts.
Where the AI RMF Fits Alongside Other Standards
Organizations often ask whether the AI RMF replaces the need to look at the EU AI Act or ISO/IEC 42001. It does not. The AI RMF is a risk management framework, not a certifiable management system standard and not a binding regulation. ISO/IEC 42001 specifies requirements for an AI management system that an organization can be certified against. The EU AI Act is binding law for AI systems in scope of EU jurisdiction, with its own risk tiers and obligations.
In practice, many governance teams use the AI RMF as the conceptual backbone, since its four functions align well with what both ISO/IEC 42001 and the EU AI Act expect, then layer in the specific documentation and control requirements each standard or regulation demands. Treating the AI RMF as a common vocabulary across these frameworks reduces duplicated work.
Key Takeaways
- The NIST AI RMF is a voluntary, four-function framework, Govern, Map, Measure, Manage, not a checklist or a certification standard.
- Govern establishes accountability and policy; without it, the other three functions are inconsistently applied across an organization.
- Map requires a real inventory of AI systems in use, including vendor tools, with documented purpose and affected stakeholders.
- Measure is ongoing, not a one-time test: model behavior drifts, so metrics need continuous monitoring.
- Manage turns findings into action and feeds decisions back into Govern, making the framework a cycle rather than a linear process.
Organizations building AI governance capability from the ground up, including how to operationalize the NIST AI RMF alongside the EU AI Act and ISO/IEC 42001, can explore this in depth through AICA's Certified Chief AI Governance Officer (CCAIGO) credential.