GovCompass

The NIST AI RMF: a voluntary risk method, not a certification

By Michel Venniker· Last updated August 2026

The NIST AI Risk Management Framework is a voluntary framework for identifying, assessing, and treating AI risk, published by the US National Institute of Standards and Technology in January 2023. It organizes the work in four functions: govern, map, measure, and manage. It is a method, not a legal requirement and not a certifiable standard: no organization can be certified against it, and following it creates no presumption of conformity with the EU AI Act. Its value is the risk vocabulary and process it supplies inside a management system.

Status of time-bound facts in this article: 1 August 2026.

What the framework is

NIST released AI RMF 1.0 in January 2023 after a public, multi-round drafting process. Congress directed NIST to develop it, but use is voluntary for everyone, including US federal contractors, unless a contract or a sector rule says otherwise.

The framework has two parts. The first describes AI riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry → and the characteristics of trustworthy AItrustworthy AIAn umbrella term for AI that is lawful, ethical and robust, used by the OECD and EU; the responsible-AI pillars operationalize it.Open full entry → systems: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacyprivacyThe principle that personal data used by or produced through an AI system stays within the purpose and the legal basis it was collected for. Three routes cause most of the trouble: personal data in training material that was never intended for it, model output that reproduces what the model retained, and purpose creep, where a system built for one use drifts into another the original basis never covered. The GDPR governs this in full, and the EU AI Act adds data governance duties for high-risk systems (Article 10). See DPIA, purpose limitation, responsible AI.Open full entry →-enhanced, and fair with harmful biasbiasA systematic skew in data, model behavior, or outcomes that treats one group differently from another without justification. Bias usually enters through training data that reflects historical patterns. For high-risk AI systems, Article 10 of the EU AI Act requires examination of datasets for possible biases and measures to detect, prevent, and mitigate them. See fairness, proxy discrimination.Open full entry → managed. The second part is the core: four functions that organize risk work across the AI life cycleAI life cycleThe looped stages of an AI system: design → data/development → validation → deployment → operation & monitoring → retirement, each with native controls and gated transitions.Open full entry →.

Govern is the cross-cutting function. It covers the culture, policies, roles, and accountabilityaccountabilityThe principle that a named human or organization answers for an AI system's outcomes, through ownership, documentation, audit trails and redress; never the system itself. The EU AI Act attaches obligations to the role rather than the technology, with provider duties in Article 16 and deployer duties in Article 26, supported by technical documentation (Article 11) and record-keeping (Article 12). See provider, deployer, record-keeping, responsible AI.Open full entry → structures that make the other three functions possible. Map establishes context: what the system is, who it affects, and which risks are plausible. Measure analyzes and tracks the risks that map identified, with metrics where they exist and structured judgment where they do not. Manage treats the risks: prioritize, respond, and monitor.

Each function breaks down into categories and subcategories, and NIST maintains a companion playbook with suggested actions per subcategory. In July 2024 NIST added a generative AIgenerative AIAI systems that produce new content (text, images, audio, code) rather than only classifying or predicting. Large language models are the prominent example.Open full entry → profile that translates the framework for the risks specific to generative systems.

What the framework is not

Three misreadings are common, and each has a cost.

The framework is not a compliance instrument. It contains no obligations, no deadlines, and no penalties. An organization that "complies with NIST AI RMFNIST AI RMFThe AI Risk Management Framework of the US National Institute of Standards and Technology, published as version 1.0 in 2023. It is a voluntary framework built around four functions: govern, map, measure, and manage. In a layered setup, it serves as the risk method inside a management system such as ISO/IEC 42001. See ISO/IEC 42001, ISO/IEC 23894.Open full entry →" has made a category error in one sentence: there is nothing to comply with, only a method to apply.

It is not certifiable. NIST is not a certification body and has authorized no scheme. Training providersproviderThe actor who develops an AI system (or has it developed) and places it on the market or into service under its own name. It carries manufacturer-style duties: design controls, documentation, conformity.Open full entry → issue course certificates based on the framework, which record learning, not conformity. A supplier claiming to be "NIST AI RMF certified" is claiming something that does not exist.

It does not map one-to-one onto EU AI ActEU AI ActRegulation (EU) 2024/1689, the European Union's law on artificial intelligence. It takes a risk-based approach: prohibited practices, requirements for high-risk AI systems, transparency obligations for specific uses, and a separate regime for general-purpose AI models. Obligations are divided between providers and deployers. See general-purpose AI, conformity assessment.Open full entry → obligations. There is real overlap: the map function resembles the context-setting the Act expects, and measure and manage cover ground that Article 9 also covers. But the Act imposes specific, dated, enforceable obligations, and the framework offers none of that. Using the framework prepares an organization for the Act's risk management requirement; it does not satisfy it.

Where it fits in the stack

The layered frame is simple. The EU AI Act is the law and defines what you must do. ISO/IEC 42001ISO/IEC 42001The international requirements standard for AI management systems, published in 2023 and certifiable. It defines how an organization establishes, implements, maintains, and continually improves a management system for AI. Certification against ISO/IEC 42001 does not create a legal presumption of conformity with the EU AI Act. See AI management system, harmonized standard.Open full entry → is the certifiable management system standard that gives governancegovernanceThe system through which an organization steers itself: corporate governance, risk management, compliance, lines of accountability, risk appetite, and the operating model. It exists across everything the organization does, before and beyond AI. AI governance is this same system extended for AI. See AI governance, governance design, execution level.Open full entry → an auditable structure. The NIST AI RMF is the risk method that runs inside that structure.

The framework's practical strength is granularity. ISO/IEC 42001 requires risk assessment and treatment but stays at the level of requirements; the framework supplies the working method, category by category. Organizations that already run the framework find that its outputs, context maps, risk registersrisk registerThe living record of an AI system's identified risks, ratings, responses, owners and review dates, kept current from design through retirement.Open full entry →, and measurement plans, become the evidenceevidenceThe concrete proof that a control is designed, implemented, and working: a test report, an audit trail, an impact assessment, a monitoring log. Each link in the governance chain produces an artifact, and together they are what an organization hands to its own board, a regulator, a customer, or an affected person to show, not say, that a system is governed. Its absence is itself the failure: a risk register without test results, or a mitigation claimed without validation, is a governance gap, not a paperwork one. The closing link of the governance chain. See control, governance.Open full entry → an ISO/IEC 42001 audit asks for. Organizations that start from the standard borrow the framework to make clause 6 concrete.

The govern function deserves separate mention, because it is where the framework and the design-versus-operating distinction meet. Govern asks not only whether risk processes exist but whether accountability for them is assigned and functioning. A mapped and measured risk with no owner is a documented risk, not a managed one.

Using it without overclaiming

Say that you apply or align with the framework, and be ready to show which functions and categories your program covers. Do not say certified, compliant, or accredited, because none of those words has a referent here. In supplier questionnaires and procurement, ask the same precisionprecisionPrecision is the share of a model's positive calls that were correct: of everything the model flagged, how much was actually right. Low precision means false alarms and wasted work. Precision trades off against recall through the decision threshold. See recall.Open full entry → of others: a vendor that claims framework alignment should be able to show the mapping, not the logo.

Continue reading

Frequently asked questions

Is the NIST AI RMF mandatory?
No. It is voluntary for all organizations. A contract, a regulator, or a sector rule can make it binding for a specific relationship, but the framework itself imposes nothing.
Can you be certified against the NIST AI RMF?
No. There is no certification scheme. Course certificates based on the framework record training, not conformity.
Does following the NIST AI RMF satisfy the EU AI Act?
No. The framework overlaps with the Act's risk management requirement in substance, but the Act's obligations are specific and enforceable and the framework's guidance is voluntary. Alignment helps preparation; it does not create compliance or any presumption of conformity.
What are the four functions?
Govern, map, measure, and manage. Govern is cross-cutting and covers culture, roles, and accountability; map establishes context and identifies risk; measure analyzes and tracks it; manage prioritizes and treats it.
How does the framework relate to ISO/IEC 42001?
ISO/IEC 42001 defines the certifiable management system; the framework supplies the risk method inside it. They are complementary layers, not alternatives.
Legal referencesArt. 9
Continue withAccountability
Share Share on LinkedIn

More on Accountability

Agentic AI and governance: why autonomy sharpens the control question

Analysis

Agentic AI does not need a new kind of governance. Autonomy widens the gap between what a system does and who is accountable for it, which makes the existing governance chain, control tracing to risk and forward to evidence, more important, not less. The actions are real and sometimes irreversible, so the stakes on each control rise.

Agentic AI risk assessment: from architecture decisions to control objectives

Analysis

Assessing the risk of an AI agent does not need a separate method. The steps stay the same: recognize the risk, assess how likely and how severe it is for your system, and control it. What changes is the input. An agent runs the process through recorded architecture decisions, about the model, the instruction, retrieved knowledge, tools, orchestration, memory, and autonomy, and each of those decisions, alone or in combination, creates the possibility of harm. The output of the assessment is a set of risk scenarios with a control objective for each.

AI certification: what exists and what it proves

Analysis

AI certification is not one category. Three different objects are assessed, each by a different kind of assessor: a person, an organization's AI management system, and an AI system placed on the EU market. The first two can be certified. The third is subject to a legal conformity assessment, which produces a certificate on one of its two routes and none on the other. Identifying which object a credential covers is the first step to judging what it is worth.

AI governance and enterprise risk management: where they meet

Analysis

AI governance is not a parallel structure that sits beside enterprise risk management. It belongs inside it. The seven pillars of responsible AI are the control structure the organization uses to govern each AI system; enterprise risk management is the machine that carries the residual risk those controls leave behind into the board's risk appetite, the risk register, and the assurance plan. The practical question is not whether to build AI governance or ERM, but how to slot the first into the second so that one accountable structure, not two competing ones, owns AI risk.