AAI Compliance Atlas
FrameworksState lawsIndustriesToolsNews
GuidesMap my obligations →
AAI Compliance Atlas

Structured, continuously verified reference for US AI compliance — federal frameworks, state laws, and the obligations that connect them.

Atlas

  • Frameworks
  • State laws
  • Industries
  • By role
  • Comparisons

Tools

  • Compliance Checker
  • Penalty Calculator
  • Impact Assessment
  • Vendor Questionnaire

Resources

  • Guides
  • News
  • Blog
  • Methodology

Company

  • About
  • Contact
  • Privacy
  • Terms
© 2026 AI Compliance Atlas. Informational only — not legal advice. Consult qualified counsel before making compliance decisions.Verified Jul 28, 2026
  1. Home/
  2. Frameworks/
  3. NIST AI RMF
voluntaryU.S. National Institute of Standards and Technologyv1.0

NIST AI Risk Management Framework (AI RMF 1.0)

Framework reference — controls, obligations, and mapping to US state AI laws.

Last verified July 16, 2026

Type
voluntary
Version
v1.0
Released
January 26, 2023
Certifiable
No

Overview

The NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0) is a voluntary framework released by the U.S. National Institute of Standards and Technology on January 26, 2023, intended to help organizations design, develop, deploy, and use AI systems in a manner that manages risks to individuals, organizations, and society.

The framework is built around four core functions:

  • GOVERN - establish a culture of risk management with policies, processes, accountability structures, and oversight
  • MAP - identify the context, intended uses, stakeholders, and risks of an AI system
  • MEASURE - assess, analyze, and track AI risks and impacts using qualitative and quantitative methods
  • MANAGE - allocate risk resources and treat identified risks based on assessed impact

NIST also released the Generative AI Profile (NIST AI 600-1) in July 2024, which provides specific guidance for the unique risks of generative AI systems, including confabulation, harmful biases, intellectual property issues, and value chain risks.

The framework PDF is paired with the NIST AI RMF Playbook, an interactive companion resource hosted on the NIST AI Resource Center (AIRC) that supplies suggested actions, transparency-and-documentation prompts, and references for each subcategory across all four functions. The Playbook is not distributed as a PDF; it is maintained as a living web resource and is updated independently of the framework PDF itself. Teams translating GOVERN into committees, decision rights, and lifecycle gates can use the AI Governance guide as the operating-model companion to this framework reference. Related Atlas coverage: Utah AI Policy Act.

NIST AI RMF certification: what exists in 2026

There is no official NIST-issued AI RMF certification for organizations, products, or AI systems. The official NIST AI RMF page describes the framework as intended for voluntary use, and the NIST AI RMF FAQ says private and public sector organizations are not required to use it. Those official pages identify the framework PDF, Playbook, roadmap, crosswalk, profiles, and Resource Center; they do not identify a NIST accreditation program, certification body, or conformity-assessment route for AI RMF certification. Sources: NIST AI RMF and NIST AI RMF FAQ, retrieved 2026-05-17.

That distinction matters because the market uses "NIST AI RMF certification" in three different ways:

Market phraseWhat it usually meansEvidence value
Official NIST AI RMF certificationNot an official NIST program identified on the AI RMF or FAQ pagesDo not treat as a NIST-issued certificate
NIST AI RMF training certificateA third-party course or individual credentialUseful workforce evidence, but not organizational certification
AI RMF-aligned program attestationA consultant or vendor assessment against selected AI RMF functionsPotentially useful assurance evidence if scope, controls, tests, and exceptions are documented
ISO/IEC 42001 certificationCertification against a management-system standard through certification bodiesStronger organizational assurance path when a formal certificate is needed

NIST AI RMF vs ISO/IEC 42001 certification

For compliance teams that need an auditable certificate, ISO/IEC 42001 is the cleaner comparison point. ISO describes ISO/IEC 42001:2023 as an international standard that specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System. Source: ISO/IEC 42001:2023, retrieved 2026-05-17.

A practical procurement rule is to ask vendors which evidence they are offering:

  1. A dated AI RMF control map showing which GOVERN, MAP, MEASURE, and MANAGE outcomes were assessed.
  2. The artifacts reviewed for each outcome, such as inventory records, impact assessments, bias testing, monitoring logs, incident procedures, and vendor due-diligence files.
  3. Any third-party training credential held by individuals, with issuer and scope.
  4. Any organization-level ISO/IEC 42001 certificate, with certification body, certificate number, scope, and expiry date.
  5. The statutory overlay for state or sector law, because voluntary framework alignment does not replace binding obligations under Colorado, Texas, NYC Local Law 144, Illinois, Utah, California, HIPAA, FCRA, or similar regimes.

NIST Generative AI Profile (NIST AI 600-1)

The NIST Generative AI Profile — formally Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1 — is a cross-sectoral companion to the core AI RMF that NIST published on July 26, 2024 to help organizations identify and manage risks that are unique to, or exacerbated by, generative AI. Source: NIST AI 600-1 publication record, retrieved 2026-07-16.

The Profile centers on 12 risk categories — including confabulation ("hallucination"), a lowered barrier to entry for offensive cyber and CBRN capabilities, mis- and disinformation harms to information integrity, harmful bias, data privacy, intellectual-property exposure, dangerous or hateful content, and value-chain and component-integration risk — and pairs them with just over 200 suggested actions for the organizations that design, develop, deploy, and use generative AI. Source: Department of Commerce / NIST 270-day EO announcement, retrieved 2026-07-16.

Those suggested actions are organized around four primary considerations — Governance, Content Provenance, Pre-deployment Testing, and Incident Disclosure — and each action is mapped back to the GOVERN, MAP, MEASURE, and MANAGE functions of AI RMF 1.0. A generative-AI program can therefore be documented as an overlay on an existing AI RMF control map rather than a separate exercise. Like the core framework, the Profile is voluntary guidance; it is not a certification, an accreditation program, or a binding standard.

Frequently asked questions

Is there a NIST AI RMF certification?

No official NIST-issued AI RMF certification is identified on NIST's AI RMF page or FAQ as of the 2026-05-17 source review. The AI RMF is a voluntary risk-management framework. Organizations can document alignment, but they should not describe a vendor certificate as "NIST-issued" unless NIST itself identifies that program.

Can a company certify that it follows the NIST AI RMF?

A company can create an internal attestation or hire an assessor to review alignment against selected AI RMF functions, categories, and subcategories. The useful artifact is the control map and evidence file, not the label alone.

What should replace a NIST AI RMF certificate in procurement files?

Use an AI RMF control map for operational evidence and ISO/IEC 42001 certification when a formal management-system certificate is required. Keep state-law evidence separately because NIST alignment does not satisfy statutory duties automatically.

What is the NIST AI RMF Generative AI Profile (NIST AI 600-1)?

The Generative AI Profile is a companion document NIST published on July 26, 2024 that applies the AI RMF to generative AI. It names 12 GenAI risk categories — such as confabulation, information-integrity harms, CBRN and cyber-capability uplift, harmful bias, data privacy, and value-chain risk — and offers just over 200 suggested actions mapped to the GOVERN, MAP, MEASURE, and MANAGE functions. It is voluntary guidance, not a certification.

How does the Generative AI Profile relate to the core NIST AI RMF?

The Profile does not replace AI RMF 1.0; it layers generative-AI-specific risks and suggested actions onto the same four functions. Teams that already maintain an AI RMF control map can extend it with the Profile's Governance, Content Provenance, Pre-deployment Testing, and Incident Disclosure actions instead of standing up a separate program.

Governance operating model

For teams turning the GOVERN function into decision rights, committees, lifecycle gates, and escalation paths, pair this framework reference with the AI governance guide.

Core controls & obligations

Specific controls and obligations from NIST AI RMF, with section references where available.

  • GovernanceRole: bothGOVERN 1-6

    GOVERN function: establish policies, processes, structures, and accountability for AI risk management across the organization, including senior leadership oversight and a risk-based culture.

  • Risk assessmentRole: bothMAP 1-5

    MAP function: identify the context, intended uses, stakeholders, and risks of each AI system, including categorization of impacts on individuals, communities, and the organization.

  • Risk assessmentRole: bothMEASURE 1-4

    MEASURE function: assess, analyze, and monitor AI risks using both quantitative and qualitative methods, including bias evaluation, robustness testing, and explainability assessments.

  • GovernanceRole: bothMANAGE 1-4

    MANAGE function: prioritize and treat identified risks, allocate resources, and implement risk response strategies including mitigation, transfer, acceptance, or avoidance.

Mapped to US state laws

Common controls in NIST AI RMF that satisfy or overlap with US state AI law obligations. Mapping strength indicates how closely the framework control corresponds to the statutory requirement.

  • Transparency in Frontier Artificial Intelligence Act (TFAIA)strong mapping
  • California AI Transparency Actweak mapping
  • Colorado Artificial Intelligence Actstrong mapping
  • Illinois HB 3773 (AI in Employment Decisions)partial mapping
  • NYC Local Law 144 (Automated Employment Decision Tools)partial mapping
  • Texas Responsible Artificial Intelligence Governance Act (TRAIGA)partial mapping

Related comparisons

Use the side-by-side comparisons to place this framework against adjacent US AI laws and standards.

  • Colorado AI Act vs NIST AI RMF

    Compare the law and framework records using the same source-backed entity data.

  • NIST AI RMF vs ISO/IEC 42001

    Compare framework scope, evidence expectations, and implementation context.

Automate AI governance with OneTrust

partner link

Manage AI inventory, risk assessments, and policy enforcement across your organization. Used by hundreds of regulated enterprises.

See OneTrust AI Governance →

Related compliance guides

Apply NIST AI RMF alongside these implementation guides that connect the framework to operating models and statutory obligations.

  • AI compliance framework: the regulatory control map — map NIST AI RMF controls onto a reusable, multi-law control set.
  • NIST AI RMF playbook: official guide, actions & PDF — the actionable companion to the NIST AI Risk Management Framework.
  • AI governance: building an AI compliance program — turn framework functions into decision rights, committees, and lifecycle gates.
  • Mapping NIST AI RMF functions to U.S. state AI laws — how GOVERN-MAP-MEASURE-MANAGE line up with Colorado, Texas TRAIGA, and NYC Local Law 144 obligations.
  • California AI Transparency Act for healthcare — apply framework controls to the Act's healthcare content-provenance and disclosure workflow.
  • Utah AI Policy Act for financial services — apply framework controls to high-risk generative-AI interactions involving financial data.
  • Florida AI laws for hiring and HR — map framework role, governance, and evidence controls onto Florida hiring workflows.

Sources

  • Officialwww.nist.gov

Last reviewed July 16, 2026. Reviewed by the AI Compliance Atlas editorial process against primary sources. Source selection, retrieval dates, and update rules are documented in the Atlas methodology.

Legal disclaimer

This content is informational only and does not constitute legal advice. Laws change frequently and vary by jurisdiction. Consult qualified legal counsel before making compliance decisions. Information accuracy not guaranteed as of any specific date.

We may receive referral commissions from recommended compliance tools. Recommendations are based on product fit and not on commission size. Links marked “partner link” include a tracked redirect.