NIST

NIST AI Risk Management Framework (AI RMF)

The voluntary framework US regulators and courts reference most often — free, technology-neutral, and increasingly the de facto standard for demonstrating reasonable AI risk management in the US.

Voluntary framework
Risk management team analyzing AI system risk factors in a meeting
Photo: Christina @ wocintechchat.com M via Unsplash
Governome Editorial Team2 min readHow we source and review this content.

The NIST AI Risk Management Framework is voluntary — there's no certifying body, no audit, no badge to put on your website. It matters anyway, for a specific practical reason: it's the framework US regulators, courts, and Colorado's statute specifically point to when asking what "reasonable" AI risk management looks like.

Why this framework carries more weight than "voluntary" implies

Colorado's AI Act creates an affirmative defense for developers and deployers who discover and cure a violation through internal testing consistent with a nationally or internationally recognized risk management framework — and the NIST AI RMF is the framework most commonly cited in that context. A voluntary framework that a state statute explicitly ties a legal defense to isn't really optional in practice, even though nothing compels you to adopt it.

The four core functions

The framework organizes AI risk management into four functions, meant to operate continuously rather than as a one-time checklist:

  • Govern — the cross-cutting function establishing the organizational structures, policies, and accountability that make the other three functions possible. This is the function most directly aligned with what we cover in our governance hub — NIST treats governance as foundational, not as one function among equals.
  • Map — establishing context: what is this system for, who does it affect, what could go wrong, and how does that map to the organization's actual risk tolerance.
  • Measure — analyzing, assessing, and tracking identified risks using appropriate quantitative, qualitative, or mixed methods.
  • Manage — allocating resources to the risks that matter most, based on the Map and Measure outputs, and monitoring how those risks change over time.

What using the framework actually looks like

The framework itself is deliberately abstract — it tells you what functions a risk management program needs, not the specific procedures to run. NIST's companion AI RMF Playbook fills that gap with more concrete suggested actions mapped to each function, and is the more directly actionable document for a team trying to operationalize the framework rather than just cite it.

How it relates to ISO/IEC 42001

The NIST AI RMF and ISO/IEC 42001 cover substantially overlapping ground — organizations that build a NIST AI RMF-aligned program are generally most of the way toward ISO/IEC 42001 readiness, since 42001's management-system structure asks for similar governance, risk assessment, and monitoring functions, just in a certifiable format. See our ISO/IEC 42001 coverage for that comparison in more depth.

Sources & references

  1. NIST AI Risk Management Framework (AI RMF 1.0)
  2. NIST AI RMF Playbook
Legal team reviewing duty-of-care obligations under Colorado's AI Act
Photo: Junior Verhelst via Unsplash

regulations us colorado

Colorado AI Act (SB 205)

Colorado's SB 205 imposes duties of reasonable care on both developers and deployers of high-risk AI systems, with impact assessment and consumer notice requirements tied to consequential decisions.
Governome Editorial Team · 2 min read
Compliance team meeting around a table to review an AI governance framework
Photo: Beatriz Cattel via Unsplash
Most AI governance frameworks fail for the same reason: they're written to look complete in a slide deck, not to survive contact with a real model deployment. Here's what to build first, in what order, and why the sequence matters more than the paperwork.
Governome Editorial Team · 4 min read