NIST AI RMF

What Is NIST AI RMF?

A plain-language introduction to the NIST AI Risk Management Framework 1.0 — what it is, where it came from, who it is for, and what adopting it actually means for an organisation. The framework is voluntary, non-certifiable, and structured around four functions. Our guide explains each of those features and what they imply in practice.

NIST AI RMF Implementation and Organisational Adoption

A practical guide to using the framework inside an organisation — how to scope adoption, assess current maturity, sequence implementation across the four functions, allocate ownership across teams, and document AI RMF use for external attestation.

Characteristics of Trustworthy AI

A reference guide to the seven characteristics the NIST AI RMF treats as the substantive goals of AI risk management — what each characteristic means, what it requires in practice, where tensions between them arise, and how the framework expects organisations to balance them in design and deployment decisions.

NIST AI RMF and the EU AI Act

How the voluntary US framework relates to the binding EU regulation — where the two align on substantive AI risk management, where they diverge in legal effect and scope, and how organisations operating in both jurisdictions use the AI RMF as substantive methodology alongside Act compliance work.

Using the AI RMF Playbook and Profiles

How the AI RMF’s supporting resources work in practice — what the Playbook provides for each subcategory of the four functions, what profiles add for specific use cases and sectors, and how organisations combine the two to convert the framework’s general guidance into context-specific operational practice.

NIST AI RMF Core Functions: Govern, Map, Measure, Manage

The NIST AI RMF is structured around four functions: Govern, Map, Measure, and Manage. Each function contains categories (numbered, for example, Govern 1 through Govern 6) and subcategories (Govern 1.1, Govern 1.2, and so on) that specify the outcomes the organisation seeks to achieve. “The AI RMF Core is composed of four functions: GOVERN, MAP, NIST AI RMF Core Functions: Govern, Map, Measure, Manage

NIST AI RMF and ISO/IEC 42001

How the voluntary US framework relates to the certifiable international management system standard — what each provides, where the substance overlaps, where the structures differ, and how organisations use the two together with the AI RMF as methodology source and ISO/IEC 42001 as the management system frame.

How Does the NIST AI RMF Apply to You?

Who the framework is intended for, how applicability is determined, and what AI RMF adoption looks like for organisations in different roles across the AI lifecycle. Because the framework is voluntary, the question of whether it applies is less about legal scope than about whether adoption serves the organisation’s purposes.

NIST AI RMF Quick Overview

A working introduction to the NIST AI Risk Management Framework — what it is, what it asks of organisations, and how to read it. Designed to be scanned in ten minutes and returned to as reference.