NIST AI Risk Management Framework (AI RMF 1.0)
Framework reference — controls, obligations, and mapping to US state AI laws.
Last verified August 12, 2026
Overview
The NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0) is a voluntary framework released by the U.S. National Institute of Standards and Technology on January 26, 2023, intended to help organizations design, develop, deploy, and use AI systems in a manner that manages risks to individuals, organizations, and society.
The framework is built around four core functions:
- GOVERN - establish a culture of risk management with policies, processes, accountability structures, and oversight
- MAP - identify the context, intended uses, stakeholders, and risks of an AI system
- MEASURE - assess, analyze, and track AI risks and impacts using qualitative and quantitative methods
- MANAGE - allocate risk resources and treat identified risks based on assessed impact
NIST also released the Generative AI Profile (NIST AI 600-1) in July 2024, which provides specific guidance for the unique risks of generative AI systems, including confabulation, harmful biases, intellectual property issues, and value chain risks.
The framework PDF is paired with the NIST AI RMF Playbook, an interactive companion resource hosted on the NIST AI Resource Center (AIRC) that supplies suggested actions, transparency-and-documentation prompts, and references for each subcategory across all four functions. The Playbook is a living resource updated independently of the version-locked framework PDF, and NIST states that Playbook updates are released approximately twice per year. Alongside the browsable web version, NIST distributes it in four downloadable formats — PDF, Excel, CSV and JSON — all four retrieved and confirmed available on 2026-08-12 from the NIST AI Resource Center Playbook knowledge base. The NIST AI RMF Playbook guide sets out which export suits which compliance workflow. Teams translating GOVERN into committees, decision rights, and lifecycle gates can use the AI Governance guide as the operating-model companion to this framework reference. Related Atlas coverage: Utah AI Policy Act.
NIST AI RMF certification: what exists in 2026
There is no official NIST-issued AI RMF certification for organizations, products, or AI systems. The official NIST AI RMF page describes the framework as intended for voluntary use, and the NIST AI RMF FAQ says private and public sector organizations are not required to use it. Those official pages identify the framework PDF, Playbook, roadmap, crosswalk, profiles, and Resource Center; they do not identify a NIST accreditation program, certification body, or conformity-assessment route for AI RMF certification. Sources: NIST AI RMF and NIST AI RMF FAQ, retrieved 2026-05-17.
That distinction matters because the market uses "NIST AI RMF certification" in three different ways:
| Market phrase | What it usually means | Evidence value |
|---|---|---|
| Market phraseOfficial NIST AI RMF certification | What it usually meansNot an official NIST program identified on the AI RMF or FAQ pages | Evidence valueDo not treat as a NIST-issued certificate |
| Market phraseNIST AI RMF training certificate | What it usually meansA third-party course or individual credential | Evidence valueUseful workforce evidence, but not organizational certification |
| Market phraseAI RMF-aligned program attestation | What it usually meansA consultant or vendor assessment against selected AI RMF functions | Evidence valuePotentially useful assurance evidence if scope, controls, tests, and exceptions are documented |
| Market phraseISO/IEC 42001 certification | What it usually meansCertification against a management-system standard through certification bodies | Evidence valueStronger organizational assurance path when a formal certificate is needed |
NIST AI RMF vs ISO/IEC 42001 certification
For compliance teams that need an auditable certificate, ISO/IEC 42001 is the cleaner comparison point. ISO describes ISO/IEC 42001:2023 as an international standard that specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System. Source: ISO/IEC 42001:2023, retrieved 2026-05-17.
A practical procurement rule is to ask vendors which evidence they are offering:
- A dated AI RMF control map showing which GOVERN, MAP, MEASURE, and MANAGE outcomes were assessed.
- The artifacts reviewed for each outcome, such as inventory records, impact assessments, bias testing, monitoring logs, incident procedures, and vendor due-diligence files.
- Any third-party training credential held by individuals, with issuer and scope.
- Any organization-level ISO/IEC 42001 certificate, with certification body, certificate number, scope, and expiry date.
- The statutory overlay for state or sector law, because voluntary framework alignment does not replace binding obligations under Colorado, Texas, NYC Local Law 144, Illinois, Utah, California, HIPAA, FCRA, or similar regimes.
NIST Generative AI Profile (NIST AI 600-1)
The NIST Generative AI Profile — formally Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1 — is a cross-sectoral companion to the core AI RMF that NIST published on July 26, 2024 to help organizations identify and manage risks that are unique to, or exacerbated by, generative AI. Source: NIST AI 600-1 publication record, retrieved 2026-07-16.
The Profile centers on 12 risk categories — including confabulation ("hallucination"), a lowered barrier to entry for offensive cyber and CBRN capabilities, mis- and disinformation harms to information integrity, harmful bias, data privacy, intellectual-property exposure, dangerous or hateful content, and value-chain and component-integration risk — and pairs them with just over 200 suggested actions for the organizations that design, develop, deploy, and use generative AI. Source: Department of Commerce / NIST 270-day EO announcement, retrieved 2026-07-16.
Those suggested actions are organized around four primary considerations — Governance, Content Provenance, Pre-deployment Testing, and Incident Disclosure — and each action is mapped back to the GOVERN, MAP, MEASURE, and MANAGE functions of AI RMF 1.0. A generative-AI program can therefore be documented as an overlay on an existing AI RMF control map rather than a separate exercise. Like the core framework, the Profile is voluntary guidance; it is not a certification, an accreditation program, or a binding standard.
NIST AI RMF and intellectual property: which controls actually apply
As of July 30, 2026, NIST AI RMF 1.0 names intellectual property in exactly two of its Core subcategory outcomes — GOVERN 6.1 and MAP 4.1 — and both frame it as exposure to a third party's rights rather than as protection of the organization's own IP.
| Subcategory | Outcome text (AI RMF 1.0) |
|---|---|
| SubcategoryGOVERN 6.1 | Outcome text (AI RMF 1.0)"Policies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third-party's intellectual property or other rights." |
| SubcategoryMAP 4.1 | Outcome text (AI RMF 1.0)"Approaches for mapping AI technology and legal risks of its components - including the use of third-party data or software - are in place, followed, and documented, as are risks of infringement of a third party's intellectual property or other rights." |
A third mention sits outside the Core. The Secure and Resilient trustworthiness characteristic identifies "the exfiltration of models, training data, or other intellectual property through AI system endpoints" as a common security concern - an outbound IP-loss framing that belongs to the security control set, not to GOVERN 6.1 or MAP 4.1. A control map that treats "IP" as a single line item usually conflates these two directions. Source: NIST AI 100-1 (AI RMF 1.0), retrieved 2026-07-30.
What the Generative AI Profile adds (NIST AI 600-1 § 2.10)
The Generative AI Profile lists Intellectual Property as risk category 10 of its 12 and defines it as the "[e]ased production or replication of alleged copyrighted, trademarked, or licensed content without authorization (possibly in situations which do not fall under fair use); eased exposure of trade secrets; or plagiarism or illegal replication."
Section 2.10 narrows the mechanism. IP risk "may arise where the use of copyrighted works is not a fair use under the fair use doctrine," and where a GAI system's training data included copyrighted material, outputs that display training-data memorization "could infringe on copyright." NIST expressly declines to resolve the open question: the status of generated content that is similar to but does not strictly copy protected work "is currently being debated in legal fora," as is the use or emulation of personal identity, likeness, or voice without permission. The Profile maps the risk to three trustworthiness characteristics - Accountable and Transparent, Fair with Harmful Bias Managed, and Privacy Enhanced. Source: NIST AI 600-1 § 2.10, retrieved 2026-07-30.
Suggested actions carrying the Intellectual Property tag
Each suggested action in the Profile's Section 3 tables is tagged with the GAI risks it addresses. Under the two subcategories that name IP, the tagged actions are:
| Action ID | What the action asks the organization to do |
|---|---|
| Action IDMP-4.1-002 | What the action asks the organization to doImplement processes for responding to potential intellectual property infringement claims or other rights |
| Action IDMP-4.1-004 | What the action asks the organization to doDocument training-data curation policies, to the extent possible and according to applicable laws and policies |
| Action IDMP-4.1-005 | What the action asks the organization to doSet collection, retention, and minimum-quality data policies covering IP alongside CBRN, offensive-cyber, harmful-bias, and PII risks |
| Action IDMP-4.1-006 | What the action asks the organization to doDefine how third-party intellectual property and training data will be used, stored, and protected |
| Action IDMP-4.1-008 | What the action asks the organization to doRe-evaluate risks, IP included, when adapting a GAI model to a new domain |
| Action IDMP-4.1-010 | What the action asks the organization to doConduct diligence on training-data use to examine whether proprietary or sensitive training data is consistent with applicable laws |
| Action IDGV-6.1-004 | What the action asks the organization to doDraft contracts and SLAs specifying content ownership, usage rights, quality standards, security requirements, and provenance expectations |
| Action IDGV-6.1-005 | What the action asks the organization to doRun a use-case-based supplier risk assessment covering value-chain risk management and legal compliance |
| Action IDGV-6.1-008 | What the action asks the organization to doMaintain records of changes to content made by third parties, including sources, timestamps, and metadata |
| Action IDGV-6.1-009 | What the action asks the organization to doExtend GAI acquisition and procurement due diligence to intellectual property, data privacy, and security risks |
| Action IDGV-6.1-010 | What the action asks the organization to doUpdate GAI acceptable-use policies to address proprietary and open-source GAI technologies, data, and third-party personnel |
| Action IDGV-6.2-002 | What the action asks the organization to doDocument incidents involving third-party GAI data and systems, including open data and open-source software |
Further IP-tagged actions appear under GOVERN 1.2, GOVERN 1.6, MAP 2.1, MAP 2.3, and MANAGE 3.1, so an IP control map drawn only from MAP 4.1 will be incomplete. The AI actor tasks NIST names for MAP 4.1 are Governance and Oversight, Operation and Monitoring, Procurement, and Third-party entities - training-data IP diligence is placed with vendor management, not with legal alone. Source: NIST AI 600-1 § 3, retrieved 2026-07-30.
Where a voluntary action is already a statutory duty
MP-4.1-004 and MP-4.1-010 are suggested actions under a voluntary framework. For one class of organization they describe conduct that US law already compels. California AB 2013, the Generative AI Training Data Transparency Act codified at Civil Code §§ 3110-3111 and effective January 1, 2026, requires a developer of a generative AI system or service released on or after January 1, 2022 and made publicly available to Californians to post a public high-level summary of the datasets used in development. That summary must state whether the datasets include data protected by copyright, trademark, or patent or are entirely in the public domain, and whether the datasets were purchased or licensed. Source: Cal. Civ. Code Title 15.2, retrieved 2026-07-30.
The practical consequence for a compliance program is sequencing rather than duplication: the training-data curation record built for MP-4.1-004 supplies most of the § 3111 content, and the statute converts documenting it into publishing it. Framework alignment does not discharge the statutory duty, and the disclosure falls on the developer, not on a deployer that merely uses the system.
Frequently asked questions
Is there a NIST AI RMF certification?
No official NIST-issued AI RMF certification is identified on NIST's AI RMF page or FAQ as of the 2026-05-17 source review. The AI RMF is a voluntary risk-management framework. Organizations can document alignment, but they should not describe a vendor certificate as "NIST-issued" unless NIST itself identifies that program.
Can a company certify that it follows the NIST AI RMF?
A company can create an internal attestation or hire an assessor to review alignment against selected AI RMF functions, categories, and subcategories. The useful artifact is the control map and evidence file, not the label alone.
What should replace a NIST AI RMF certificate in procurement files?
Use an AI RMF control map for operational evidence and ISO/IEC 42001 certification when a formal management-system certificate is required. Keep state-law evidence separately because NIST alignment does not satisfy statutory duties automatically.
What is the NIST AI RMF Generative AI Profile (NIST AI 600-1)?
The Generative AI Profile is a companion document NIST published on July 26, 2024 that applies the AI RMF to generative AI. It names 12 GenAI risk categories — such as confabulation, information-integrity harms, CBRN and cyber-capability uplift, harmful bias, data privacy, and value-chain risk — and offers just over 200 suggested actions mapped to the GOVERN, MAP, MEASURE, and MANAGE functions. It is voluntary guidance, not a certification.
How does the Generative AI Profile relate to the core NIST AI RMF?
The Profile does not replace AI RMF 1.0; it layers generative-AI-specific risks and suggested actions onto the same four functions. Teams that already maintain an AI RMF control map can extend it with the Profile's Governance, Content Provenance, Pre-deployment Testing, and Incident Disclosure actions instead of standing up a separate program.
Does the NIST AI RMF cover intellectual property?
Yes, but narrowly. AI RMF 1.0 names intellectual property in two Core subcategory outcomes - GOVERN 6.1 and MAP 4.1 - and both are about the risk of infringing a third party's rights through third-party data, software, or model components. Loss of the organization's own IP is treated separately, under the Secure and Resilient trustworthiness characteristic, as exfiltration of models, training data, or other intellectual property through AI system endpoints. The Generative AI Profile (NIST AI 600-1) expands the topic as risk category 10 of 12 and supplies the tagged suggested actions.
What does NIST AI 600-1 say about AI training data and copyright?
NIST AI 600-1 § 2.10 states that intellectual property risks "may arise where the use of copyrighted works is not a fair use under the fair use doctrine," and that where training data included copyrighted material, outputs displaying training-data memorization "could infringe on copyright." NIST does not resolve whether generated content that is similar to but does not strictly copy a protected work is infringing, describing that question as "currently being debated in legal fora." The operative suggested actions are MP-4.1-004 (document training-data curation policies) and MP-4.1-010 (conduct diligence on training-data use to assess IP and privacy risks).
Governance operating model
For teams turning the GOVERN function into decision rights, committees, lifecycle gates, and escalation paths, pair this framework reference with the AI governance guide.
Core controls & obligations
Specific controls and obligations from NIST AI RMF, with section references where available.
- GovernanceRole: bothGOVERN 1-6
GOVERN function: establish policies, processes, structures, and accountability for AI risk management across the organization, including senior leadership oversight and a risk-based culture.
- Risk assessmentRole: bothMAP 1-5
MAP function: identify the context, intended uses, stakeholders, and risks of each AI system, including categorization of impacts on individuals, communities, and the organization.
- Risk assessmentRole: bothMEASURE 1-4
MEASURE function: assess, analyze, and monitor AI risks using both quantitative and qualitative methods, including bias evaluation, robustness testing, and explainability assessments.
- GovernanceRole: bothMANAGE 1-4
MANAGE function: prioritize and treat identified risks, allocate resources, and implement risk response strategies including mitigation, transfer, acceptance, or avoidance.
Mapped to US state laws
Common controls in NIST AI RMF that satisfy or overlap with US state AI law obligations. Mapping strength indicates how closely the framework control corresponds to the statutory requirement.
- Illinois HB 3773 (AI in Employment Decisions)partial mapping
- NYC Local Law 144 (Automated Employment Decision Tools)partial mapping
- Texas Responsible Artificial Intelligence Governance Act (TRAIGA)partial mapping
- Transparency in Frontier Artificial Intelligence Act (TFAIA)strong mapping
- California AI Transparency Actweak mapping
- Colorado Artificial Intelligence Actstrong mapping
Related comparisons
Use the side-by-side comparisons to place this framework against adjacent US AI laws and standards.
- Colorado AI Act vs NIST AI RMF
Compare the law and framework records using the same source-backed entity data.
- NIST AI RMF vs ISO/IEC 42001
Compare framework scope, evidence expectations, and implementation context.
Related compliance guides
Apply NIST AI RMF alongside these implementation guides that connect the framework to operating models and statutory obligations.
- 2026 US state AI laws overview — open the state-law calendar and statutory overlay for teams using NIST AI RMF as their control baseline.
- AI compliance framework: the regulatory control map — map NIST AI RMF controls onto a reusable, multi-law control set.
- NIST AI RMF playbook: official guide, actions & PDF — the actionable companion to the NIST AI Risk Management Framework.
- AI governance: building an AI compliance program — turn framework functions into decision rights, committees, and lifecycle gates.
- Mapping NIST AI RMF functions to U.S. state AI laws — how GOVERN-MAP-MEASURE-MANAGE line up with Colorado, Texas TRAIGA, and NYC Local Law 144 obligations.
- AI vendor due diligence questionnaire — generate the third-party evidence request behind GOVERN 6: "Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues" (NIST AI RMF Core, retrieved August 1, 2026).
- California AI Transparency Act for healthcare — apply framework controls to the Act's healthcare content-provenance and disclosure workflow.
- Utah AI Policy Act for financial services — apply framework controls to high-risk generative-AI interactions involving financial data.
- Florida AI laws for hiring and HR — map framework role, governance, and evidence controls onto Florida hiring workflows.
Sources
Last reviewed August 12, 2026. Reviewed by the AI Compliance Atlas editorial process against primary sources. Source selection, retrieval dates, and update rules are documented in the Atlas methodology.
We may receive referral commissions from recommended compliance tools. Recommendations are based on product fit and not on commission size. Links marked “partner link” include a tracked redirect.