NIST AI Risk Management Framework (AI RMF 1.0)
Framework reference — controls, obligations, and mapping to US state AI laws.
Last verified July 16, 2026
Overview
The NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0) is a voluntary framework released by the U.S. National Institute of Standards and Technology on January 26, 2023, intended to help organizations design, develop, deploy, and use AI systems in a manner that manages risks to individuals, organizations, and society.
The framework is built around four core functions:
- GOVERN - establish a culture of risk management with policies, processes, accountability structures, and oversight
- MAP - identify the context, intended uses, stakeholders, and risks of an AI system
- MEASURE - assess, analyze, and track AI risks and impacts using qualitative and quantitative methods
- MANAGE - allocate risk resources and treat identified risks based on assessed impact
NIST also released the Generative AI Profile (NIST AI 600-1) in July 2024, which provides specific guidance for the unique risks of generative AI systems, including confabulation, harmful biases, intellectual property issues, and value chain risks.
The framework PDF is paired with the NIST AI RMF Playbook, an interactive companion resource hosted on the NIST AI Resource Center (AIRC) that supplies suggested actions, transparency-and-documentation prompts, and references for each subcategory across all four functions. The Playbook is not distributed as a PDF; it is maintained as a living web resource and is updated independently of the framework PDF itself. Teams translating GOVERN into committees, decision rights, and lifecycle gates can use the AI Governance guide as the operating-model companion to this framework reference. Related Atlas coverage: Utah AI Policy Act.
NIST AI RMF certification: what exists in 2026
There is no official NIST-issued AI RMF certification for organizations, products, or AI systems. The official NIST AI RMF page describes the framework as intended for voluntary use, and the NIST AI RMF FAQ says private and public sector organizations are not required to use it. Those official pages identify the framework PDF, Playbook, roadmap, crosswalk, profiles, and Resource Center; they do not identify a NIST accreditation program, certification body, or conformity-assessment route for AI RMF certification. Sources: NIST AI RMF and NIST AI RMF FAQ, retrieved 2026-05-17.
That distinction matters because the market uses "NIST AI RMF certification" in three different ways:
| Market phrase | What it usually means | Evidence value |
|---|---|---|
| Official NIST AI RMF certification | Not an official NIST program identified on the AI RMF or FAQ pages | Do not treat as a NIST-issued certificate |
| NIST AI RMF training certificate | A third-party course or individual credential | Useful workforce evidence, but not organizational certification |
| AI RMF-aligned program attestation | A consultant or vendor assessment against selected AI RMF functions | Potentially useful assurance evidence if scope, controls, tests, and exceptions are documented |
| ISO/IEC 42001 certification | Certification against a management-system standard through certification bodies | Stronger organizational assurance path when a formal certificate is needed |
NIST AI RMF vs ISO/IEC 42001 certification
For compliance teams that need an auditable certificate, ISO/IEC 42001 is the cleaner comparison point. ISO describes ISO/IEC 42001:2023 as an international standard that specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System. Source: ISO/IEC 42001:2023, retrieved 2026-05-17.
A practical procurement rule is to ask vendors which evidence they are offering:
- A dated AI RMF control map showing which GOVERN, MAP, MEASURE, and MANAGE outcomes were assessed.
- The artifacts reviewed for each outcome, such as inventory records, impact assessments, bias testing, monitoring logs, incident procedures, and vendor due-diligence files.
- Any third-party training credential held by individuals, with issuer and scope.
- Any organization-level ISO/IEC 42001 certificate, with certification body, certificate number, scope, and expiry date.
- The statutory overlay for state or sector law, because voluntary framework alignment does not replace binding obligations under Colorado, Texas, NYC Local Law 144, Illinois, Utah, California, HIPAA, FCRA, or similar regimes.
NIST Generative AI Profile (NIST AI 600-1)
The NIST Generative AI Profile — formally Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1 — is a cross-sectoral companion to the core AI RMF that NIST published on July 26, 2024 to help organizations identify and manage risks that are unique to, or exacerbated by, generative AI. Source: NIST AI 600-1 publication record, retrieved 2026-07-16.
The Profile centers on 12 risk categories — including confabulation ("hallucination"), a lowered barrier to entry for offensive cyber and CBRN capabilities, mis- and disinformation harms to information integrity, harmful bias, data privacy, intellectual-property exposure, dangerous or hateful content, and value-chain and component-integration risk — and pairs them with just over 200 suggested actions for the organizations that design, develop, deploy, and use generative AI. Source: Department of Commerce / NIST 270-day EO announcement, retrieved 2026-07-16.
Those suggested actions are organized around four primary considerations — Governance, Content Provenance, Pre-deployment Testing, and Incident Disclosure — and each action is mapped back to the GOVERN, MAP, MEASURE, and MANAGE functions of AI RMF 1.0. A generative-AI program can therefore be documented as an overlay on an existing AI RMF control map rather than a separate exercise. Like the core framework, the Profile is voluntary guidance; it is not a certification, an accreditation program, or a binding standard.
Frequently asked questions
Is there a NIST AI RMF certification?
No official NIST-issued AI RMF certification is identified on NIST's AI RMF page or FAQ as of the 2026-05-17 source review. The AI RMF is a voluntary risk-management framework. Organizations can document alignment, but they should not describe a vendor certificate as "NIST-issued" unless NIST itself identifies that program.
Can a company certify that it follows the NIST AI RMF?
A company can create an internal attestation or hire an assessor to review alignment against selected AI RMF functions, categories, and subcategories. The useful artifact is the control map and evidence file, not the label alone.
What should replace a NIST AI RMF certificate in procurement files?
Use an AI RMF control map for operational evidence and ISO/IEC 42001 certification when a formal management-system certificate is required. Keep state-law evidence separately because NIST alignment does not satisfy statutory duties automatically.
What is the NIST AI RMF Generative AI Profile (NIST AI 600-1)?
The Generative AI Profile is a companion document NIST published on July 26, 2024 that applies the AI RMF to generative AI. It names 12 GenAI risk categories — such as confabulation, information-integrity harms, CBRN and cyber-capability uplift, harmful bias, data privacy, and value-chain risk — and offers just over 200 suggested actions mapped to the GOVERN, MAP, MEASURE, and MANAGE functions. It is voluntary guidance, not a certification.
How does the Generative AI Profile relate to the core NIST AI RMF?
The Profile does not replace AI RMF 1.0; it layers generative-AI-specific risks and suggested actions onto the same four functions. Teams that already maintain an AI RMF control map can extend it with the Profile's Governance, Content Provenance, Pre-deployment Testing, and Incident Disclosure actions instead of standing up a separate program.
Governance operating model
For teams turning the GOVERN function into decision rights, committees, lifecycle gates, and escalation paths, pair this framework reference with the AI governance guide.
Core controls & obligations
Specific controls and obligations from NIST AI RMF, with section references where available.
- GovernanceRole: bothGOVERN 1-6
GOVERN function: establish policies, processes, structures, and accountability for AI risk management across the organization, including senior leadership oversight and a risk-based culture.
- Risk assessmentRole: bothMAP 1-5
MAP function: identify the context, intended uses, stakeholders, and risks of each AI system, including categorization of impacts on individuals, communities, and the organization.
- Risk assessmentRole: bothMEASURE 1-4
MEASURE function: assess, analyze, and monitor AI risks using both quantitative and qualitative methods, including bias evaluation, robustness testing, and explainability assessments.
- GovernanceRole: bothMANAGE 1-4
MANAGE function: prioritize and treat identified risks, allocate resources, and implement risk response strategies including mitigation, transfer, acceptance, or avoidance.
Mapped to US state laws
Common controls in NIST AI RMF that satisfy or overlap with US state AI law obligations. Mapping strength indicates how closely the framework control corresponds to the statutory requirement.
- Transparency in Frontier Artificial Intelligence Act (TFAIA)strong mapping
- California AI Transparency Actweak mapping
- Colorado Artificial Intelligence Actstrong mapping
- Illinois HB 3773 (AI in Employment Decisions)partial mapping
- NYC Local Law 144 (Automated Employment Decision Tools)partial mapping
- Texas Responsible Artificial Intelligence Governance Act (TRAIGA)partial mapping
Related comparisons
Use the side-by-side comparisons to place this framework against adjacent US AI laws and standards.
- Colorado AI Act vs NIST AI RMF
Compare the law and framework records using the same source-backed entity data.
- NIST AI RMF vs ISO/IEC 42001
Compare framework scope, evidence expectations, and implementation context.
Related compliance guides
Apply NIST AI RMF alongside these implementation guides that connect the framework to operating models and statutory obligations.
- AI compliance framework: the regulatory control map — map NIST AI RMF controls onto a reusable, multi-law control set.
- NIST AI RMF playbook: official guide, actions & PDF — the actionable companion to the NIST AI Risk Management Framework.
- AI governance: building an AI compliance program — turn framework functions into decision rights, committees, and lifecycle gates.
- Mapping NIST AI RMF functions to U.S. state AI laws — how GOVERN-MAP-MEASURE-MANAGE line up with Colorado, Texas TRAIGA, and NYC Local Law 144 obligations.
- California AI Transparency Act for healthcare — apply framework controls to the Act's healthcare content-provenance and disclosure workflow.
- Utah AI Policy Act for financial services — apply framework controls to high-risk generative-AI interactions involving financial data.
- Florida AI laws for hiring and HR — map framework role, governance, and evidence controls onto Florida hiring workflows.
Sources
Last reviewed July 16, 2026. Reviewed by the AI Compliance Atlas editorial process against primary sources. Source selection, retrieval dates, and update rules are documented in the Atlas methodology.
We may receive referral commissions from recommended compliance tools. Recommendations are based on product fit and not on commission size. Links marked “partner link” include a tracked redirect.