What is the NIST AI RMF?
The AI Risk Management Framework (AI RMF 1.0) was released by the U.S. National Institute of Standards and Technology in January 2023. It is voluntary and not a certification scheme. NIST publishes a companion Playbook and, since July 2024, a Generative AI Profile (NIST AI 600-1) that applies the framework to generative AI.
The framework describes characteristics of trustworthy AI: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair with harmful bias managed.
What are the four functions?
- Govern: the culture, policies, roles and accountability for AI risk across the organization. It applies to the other three.
- Map: understanding the context of each AI system, its intended use, its users and its potential impacts.
- Measure: assessing and tracking risks with tests, metrics and evaluation.
- Manage: prioritizing risks and acting on them, including responding to incidents and monitoring after deployment.
Which capabilities support each function?
- Govern: policy libraries, roles, approval workflows, regulatory intelligence. Credo AI's regulatory Knowledge Graph and forward-deployed experts sit here.
- Map: discovery, registers and impact assessments. Holistic AI and Credo AI lead our inventory criterion.
- Measure: adversarial testing, bias and hallucination tests, drift checks. Holistic AI lists bias, hallucination, prompt injection and drift tests; Alice, Pillar Security, SPLX and Lasso describe automated red teaming.
- Manage: runtime controls, remediation, retesting and logs. Alice's WonderFence and WonderCheck, Pillar's runtime guardrails and Lasso's closed-loop remediation sit here.
How should you use it with the other frameworks?
Many organizations use the NIST AI RMF as the internal structure for their program and map it to ISO/IEC 42001 for certification and to the EU AI Act for legal obligations. Holistic AI and Lasso name the NIST AI RMF on the pages we read; Alice and Credo AI name NIST. The next lesson shows how one control can serve all three.
What does the Generative AI Profile add?
NIST AI 600-1 applies the AI RMF to generative AI. It describes risks that are specific to generative AI or made worse by it, such as confabulation (confident but false output), information security, harmful content, data privacy and information integrity, and lists suggested actions under the four functions. For a customer-facing assistant, the profile works as a checklist of what to test under Measure and what to control under Manage.