NIST
NIST AI Risk Management Framework (AI RMF)
The voluntary framework US regulators and courts reference most often — free, technology-neutral, and increasingly the de facto standard for demonstrating reasonable AI risk management in the US.
The NIST AI Risk Management Framework is voluntary — there's no certifying body, no audit, no badge to put on your website. It matters anyway, for a specific practical reason: it's the framework US regulators, courts, and Colorado's statute specifically point to when asking what "reasonable" AI risk management looks like.
Why this framework carries more weight than "voluntary" implies
Colorado's AI Act creates an affirmative defense for developers and deployers who discover and cure a violation through internal testing consistent with a nationally or internationally recognized risk management framework — and the NIST AI RMF is the framework most commonly cited in that context. A voluntary framework that a state statute explicitly ties a legal defense to isn't really optional in practice, even though nothing compels you to adopt it.
The four core functions
The framework organizes AI risk management into four functions, meant to operate continuously rather than as a one-time checklist:
- Govern — the cross-cutting function establishing the organizational structures, policies, and accountability that make the other three functions possible. This is the function most directly aligned with what we cover in our governance hub — NIST treats governance as foundational, not as one function among equals.
- Map — establishing context: what is this system for, who does it affect, what could go wrong, and how does that map to the organization's actual risk tolerance.
- Measure — analyzing, assessing, and tracking identified risks using appropriate quantitative, qualitative, or mixed methods.
- Manage — allocating resources to the risks that matter most, based on the Map and Measure outputs, and monitoring how those risks change over time.
What using the framework actually looks like
The framework itself is deliberately abstract — it tells you what functions a risk management program needs, not the specific procedures to run. NIST's companion AI RMF Playbook fills that gap with more concrete suggested actions mapped to each function, and is the more directly actionable document for a team trying to operationalize the framework rather than just cite it.
How it relates to ISO/IEC 42001
The NIST AI RMF and ISO/IEC 42001 cover substantially overlapping ground — organizations that build a NIST AI RMF-aligned program are generally most of the way toward ISO/IEC 42001 readiness, since 42001's management-system structure asks for similar governance, risk assessment, and monitoring functions, just in a certifiable format. See our ISO/IEC 42001 coverage for that comparison in more depth.
Sources & references
Suggested next reading
regulations us colorado