NIST AI RMF
The NIST AI Risk Management Framework (AI RMF 1.0, January 2023) is a voluntary U.S. framework for managing AI risks throughout the lifecycle, organized around four core functions — Govern, Map, Measure, Manage — and seven characteristics of trustworthy AI.
Full definition
The seven characteristics are: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; fair with harmful bias managed. The 2024 Generative AI Profile extends the framework to GenAI-specific risks (CBRN, confabulation, data privacy, IP, obscene content, harmful bias). NIST AI RMF is the de-facto reference framework for U.S. federal AI procurement and a common baseline for enterprise AI governance globally.
Why it matters
NIST AI RMF is voluntary but increasingly contractually required — federal contractors, regulated industries, and any enterprise selling into them face it directly. It also maps cleanly to the EU AI Act, making it the most efficient single framework to anchor a global program.
Example
A SaaS company adopts NIST AI RMF as its governance backbone, mapping each control to EU AI Act Article 9 obligations — single artifact set, two regulatory regimes covered.
Related terms
- AI Risk AssessmentAn AI risk assessment is a structured review of an AI system's potential harms — to individuals, groups, the organization, and society — covering likelihood, severity, affected populations, and mitigation controls across safety, fairness, security, privacy, and compliance dimensions.
- AI GovernanceAI governance is the framework of policies, roles, controls, and processes an organization uses to ensure its AI systems are lawful, safe, fair, accountable, and aligned with business intent — across the full lifecycle from problem framing to retirement.
- EU AI ActThe EU AI Act (Regulation (EU) 2024/1689) is the European Union's comprehensive, risk-tiered regulation of AI systems, the world's first horizontal AI law, with obligations phasing in from February 2025 and full general-purpose AI rules applying from August 2025.
- AI AuditAn AI audit is a structured, evidence-based examination of an AI system or AI program against defined criteria — covering training data, model, deployment context, monitoring, and governance — performed by an internal team, an external firm, or a regulator.
Source & further reading
Primary source: NIST — AI Risk Management Framework (AI RMF 1.0) (2023).
Citation policy: this entry is part of the AIDOLS AI Implementation Glossary and may be quoted for research, journalism, and education with attribution to aidolsgroup.com/no/glossary/nist-ai-rmf/.