Skip to content

NIST AI Risk Management Framework: the four functions

By Sam Rivera, Founder, SentinelPanda · June 1, 2026 · 3 min read · AI Governance

NIST CSF for AI, with a twist. Same structural elegance, applied to an AI system you have actually scoped.

What the AI RMF actually is

The NIST AI Risk Management Framework (AI RMF 1.0, published January 2023, with the Generative AI Profile added July 2024) is a voluntary US framework for identifying and managing risks posed by AI systems. It was authored by NIST in response to direction from the National AI Initiative Act of 2020 and is now widely cited in US federal procurement, state AI laws, and enterprise vendor questionnaires.

It is structurally similar to the NIST Cybersecurity Framework — a small set of high-level functions organised into categories and subcategories — and is designed to be applied to a specific context: a defined AI system, programme, or use case. Applying it to "the organisation" wholesale misses the point; the framework expects you to scope first.

The four functions

Govern sets the organisational tone — policies, accountability, culture, oversight of the AI lifecycle, and how risk tolerance is decided. It is the only function that runs continuously across the others; the other three are applied to a specific system once it is in scope.

Map is where most of the analytical work happens. You characterise the AI system, its context of use, the affected populations, the legal and ethical considerations, and the categorisation of risk. Skip Map and the rest of the framework is theatre.

Measure assigns the methods, metrics, and tooling for tracking the risks identified in Map — performance, fairness, robustness, security, transparency. Manage acts on what Measure surfaces: prioritisation, response, ongoing monitoring, incident handling.

The Map step does the heavy lifting

In practice, the Map function is where the AI RMF differs from a generic risk programme. Subcategories require you to document the system's intended purpose, foreseeable misuse, the population it affects, the data lineage, and the third-party components in the pipeline. That documentation is exactly what the EU AI Act and ISO 42001 also want.

Treat the Map output as the master artefact for the AI system. Other standards re-use its content — ISO 42001's AI system impact assessment maps onto Map subcategories 1.1–1.6; the EU AI Act technical documentation requires substantially the same material in a different format.

Where it fits with ISO 42001 and the EU AI Act

ISO 42001 is a certifiable AIMS — a management system. NIST AI RMF is a voluntary risk-management playbook. They are complementary: build the AIMS scaffolding (clauses 4–10 of 42001) once, then plug the AI RMF artefacts into the AIMS as the operational records. The EU AI Act is the binding legal instrument that demands conformity evidence for high-risk systems; AI RMF documentation feeds the Act's technical documentation and post-market monitoring obligations.

For US-headquartered organisations selling into US enterprise, leading with the AI RMF is often the path of least resistance — buyers ask for it by name. For EU-market organisations, the AI Act sets the floor and 42001 is the structure that makes the Act easier to evidence. They reinforce each other.

Where to start

  • Pick one AI system to scope. The framework is designed per-context; you cannot Map "all your AI" in one pass.
  • Run the Map function end-to-end on that system: purpose, affected persons, data, components, foreseeable misuse, risk categorisation.
  • Choose three Measure metrics that are concretely testable for that system — not aspirational ones.
  • Document one Manage decision per identified risk (accept, mitigate, transfer, avoid) with the owner and review cadence.
  • Stand up the Govern function in parallel — it is organisation-wide, not per-system, and it gates everything else.
The NIST AI RMF Generative AI Profile, in practice ISO 42001 vs NIST AI RMF: a side-by-side ISO 42001 explained

Run your compliance program in one workspace.