AI risk frameworks

NIST AI Risk Management Framework: the four functions explained

A plain explanation of the NIST AI RMF itself, with dates, the four functions, the seven trustworthiness characteristics and a first 90 days.

The NIST AI Risk Management Framework (AI RMF 1.0, NIST AI 100-1) is a voluntary framework published on 26 January 2023. It organises AI risk work into four functions: Govern, Map, Measure and Manage. This page explains the framework and its companion documents as NIST publishes them. It is not a Swfte mapping: the separate NIST AI RMF and Swfte page holds that.

Last verified 2026-10-07. Sources are listed at the end of the page.

What is the NIST AI Risk Management Framework?

It is a framework from the US National Institute of Standards and Technology, published as NIST AI 100-1 on 26 January 2023. NIST describes it as intended to be "voluntary, rights-preserving, non-sector specific, and use-case agnostic". It is written for the people who design, develop, deploy or use AI systems, in any sector and at any size.

The framework has two parts. Part 1 frames AI risk and lists the characteristics of trustworthy AI. Part 2 is the Core: four functions broken into categories and subcategories. NIST states that the actions in the Core do not constitute a checklist, nor are they necessarily an ordered set of steps.

Nothing in it creates a legal duty by itself. A regulator, a customer contract or your own policy can make you follow part of it, but the framework does not.

What do Govern, Map, Measure and Manage do?

The purposes below paraphrase NIST AI 100-1, section 5. The example subcategories are quoted or shortened from its tables.

FunctionPurposeExample subcategory
GovernA cross-cutting function that builds a culture of risk management, with processes, documents and organisational structures. It applies at every stage and informs the other three.GOVERN 1.6: "Mechanisms are in place to inventory AI systems", resourced according to risk priorities.
MapEstablishes the context in which a system is used, so that risks can be framed. NIST says its outcomes are the basis for Measure and Manage.MAP 1.1: intended purposes, context-specific laws and norms, and the settings in which the system will be deployed are understood and documented.
MeasureUses quantitative, qualitative or mixed methods to analyse, assess, benchmark and monitor AI risk. NIST says systems should be tested before deployment and regularly while in operation.MEASURE 1.1: approaches and metrics for the risks found during Map are selected, starting with the most significant. What will not be measured is documented.
ManageAllocates risk resources to the risks that were mapped and measured, and plans responses to, recovery from and communication about incidents.MANAGE 1.3: responses to high-priority risks are developed, planned and documented. Options include mitigating, transferring, avoiding or accepting.

Source: NIST AI 100-1 (AI RMF 1.0), read on 2026-10-07.

What are the seven characteristics of trustworthy AI?

NIST lists these as the characteristics of trustworthy AI systems and says creating trustworthy AI requires balancing them according to the context of use.

  • Valid and reliable.
  • Safe.
  • Secure and resilient.
  • Accountable and transparent.
  • Explainable and interpretable.
  • Privacy-enhanced.
  • Fair, with harmful bias managed.

Which NIST documents and resources belong to the framework?

AI RMF 1.0 (NIST AI 100-1)

The framework text, dated 26 January 2023. NIST says it will review it regularly, with a review including formal input from the AI community expected no later than 2028.

AI RMF Playbook

Suggested actions for each subcategory across the four functions, in downloadable formats. NIST says the Playbook is neither a checklist nor a set of steps to be followed in its entirety.

Generative AI Profile (NIST AI 600-1)

A companion profile published on 26 July 2024. It defines twelve risks that are unique to or exacerbated by generative AI, including confabulation, data privacy, information security and value chain and component integration.

AI RMF Resource Centre

NIST launched the Trustworthy and Responsible AI Resource Centre on 30 March 2023. It hosts the framework, the Playbook and related material.

Is the NIST AI RMF being revised?

NIST says so. Its AI RMF page states that AI RMF 1.0 is being revised as part of the White House AI Action Plan, and the AI Resource Centre states "The AI RMF 1.0 is being updated. A revised version is in progress." The Playbook page adds that the Playbook will be updated after the framework is revised.

Neither page gives a release date or lists the changes, so this page does not state either. NIST also published a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure in April 2026, which NIST describes as an ongoing initiative. Check the NIST page before you cite a version in a policy: the text you read today may be replaced.

How does the AI RMF relate to the EU AI Act and ISO/IEC 42001?

They are different kinds of document. Using one does not substitute for another, and none of them is a statement about your legal position.

DocumentWhat kind of document it isWhat it means for you
NIST AI RMFA voluntary US framework of outcomes and suggested actions.A way to organise risk work and a shared vocabulary. It does not by itself satisfy any legal duty.
EU AI ActRegulation (EU) 2024/1689, binding law with risk tiers and dated obligations.Whether it applies depends on your role and use case. See the AI Act timeline and what changed.
ISO/IEC 42001:2023An international management system standard for AI.The European Commission says its goals and definitions are not aligned with the quality management system the AI Act requires. See ISO/IEC 42001.
Harmonised standardsStandards referenced in the Official Journal of the EU.The Commission says only these give a presumption of conformity. Neither the NIST framework nor ISO/IEC 42001 is presented as doing so.

What does a first 90 days with the AI RMF look like?

NIST does not prescribe an order or a timetable. This sequence is this page's suggestion, based on NIST saying that after Govern is in place most users start with Map and continue to Measure or Manage.

  1. Days 1 to 30: set up Govern

    Name an accountable owner, write down your risk tolerance, and start an inventory of AI systems (GOVERN 1.6). Document roles and lines of communication (GOVERN 2.1) and plan how often the risk process is reviewed (GOVERN 1.5). See AI inventory management and company AI policy.

  2. Days 31 to 60: map your highest-risk systems

    Pick the few systems that touch the most sensitive data or the most people. For each, record intended purpose, users, context and known limits (MAP 1.1), and who is affected if it fails.

  3. Days 61 to 90: measure and manage

    Choose metrics and tests for the risks you mapped, starting with the most significant (MEASURE 1.1). Decide a response for each high-priority risk: mitigate, transfer, avoid or accept (MANAGE 1.3), and write the incident path.

  4. Day 90: record what you chose not to do

    The Playbook is not a checklist, so skipping a subcategory is allowed. Write down which ones you skipped and why. That record is the most useful thing to show a customer or auditor later.

Who uses the NIST AI RMF?

NIST addresses it to organisations designing, developing, deploying or using AI systems, which it calls AI actors. The four groups below are this page's grouping, not NIST's.

  • Builders of AI products use it to structure testing, documentation and risk decisions across the lifecycle.
  • Buyers and deployers use it to ask suppliers consistent questions and to decide which uses need review.
  • Risk, security and compliance teams use the function names as headings for an AI risk register.
  • Public-sector and regulated teams may meet it where a regulator or contract points to it. Check the actual requirement rather than assuming.

Where Swfte fits

This page is an explainer of a NIST document. It does not say that Swfte meets, implements or is endorsed by the framework. The NIST AI RMF and Swfte page maps Swfte controls to the four functions and states what is built and what is not.

You do not need Swfte to use the framework. A shared document and a spreadsheet are enough to start Govern and Map. A platform becomes useful when you need runtime records such as audit events and approvals to back the Measure and Manage claims.

Swfte provides the technical controls, governance mechanisms and evidence you need to deploy AI within your applicable regulatory, security and policy requirements. The exact posture depends on your use case, jurisdiction, deployment and configuration.

Sources and last verified

Every dated or technical fact on this page was read from the pages below on 2026-10-07. Anything that could not be confirmed is left out or marked as not verified.

Frequently asked questions

When was the NIST AI RMF published?

NIST published AI RMF 1.0 (NIST AI 100-1) on 26 January 2023. The Generative AI Profile (NIST AI 600-1) followed on 26 July 2024. NIST also says AI RMF 1.0 is being revised, but its pages do not give a release date for the revised version.

Is the NIST AI RMF mandatory?

No. NIST describes the framework as intended for voluntary use, and says the Playbook is neither a checklist nor a set of steps to follow in full. A law, regulator or contract can still require you to follow part of it, so check the source of any specific obligation.

What are the four functions of the NIST AI RMF?

The four functions are Govern, Map, Measure and Manage. Govern is cross-cutting and sets culture, policies and accountability. Map frames context and risks. Measure analyses and monitors those risks with tests and metrics. Manage allocates resources to respond to, recover from and communicate about the risks.

What is the difference between the AI RMF and the AI RMF Playbook?

The framework states outcomes in categories and subcategories. The Playbook is an online companion with suggested actions for those subcategories, in downloadable formats. NIST says it is voluntary and that organisations can adopt only the suggestions that suit their industry and use case.

Does following the NIST AI RMF satisfy the EU AI Act?

No page we read says so. The European Commission states that a presumption of conformity comes from harmonised standards referenced in the Official Journal. The NIST framework is a voluntary US document, so treat it as a way to organise risk work, and take legal advice on your AI Act position.

What is the NIST Generative AI Profile?

It is NIST AI 600-1, a companion resource to AI RMF 1.0 for generative AI, published on 26 July 2024. It defines twelve risks that are unique to or exacerbated by generative AI and maps each to the trustworthiness characteristics in the framework.

Start with an inventory and an owner, then map your riskiest system

See what your agents are actually doing

Nexus gives you governance, observability and spend control across every agent you run.