NIST AI 100-1 · AI 600-1 · AI RMF Playbook
NIST AI RMF. The risk methodology for AI.
The US standard that EU organizations increasingly use as the operational backbone for AI risk management — and the strongest crosswalk available to EU AI Act Art. 9 and Art. 72.
Published Jan 2023 · Generative AI Profile Jul 2024 · Voluntary but increasingly required in US procurement
Four Functions
Govern. Map. Measure. Manage.
GOVERN
Establish accountability
Policies, roles, and accountability for AI risk management. The cross-cutting, foundational function — without Govern, the other three drift.
MAP
Establish context
Identify and document AI system characteristics, intended uses, risks, and stakeholders. Inventory, classification, impact assessment.
MEASURE
Assess risks
Quantitative and qualitative methods to track identified risks. Testing, monitoring, evaluation against defined metrics.
MANAGE
Treat risks
Allocate resources, prioritize responses, track mitigation effectiveness. Continuous improvement loop.
Generative AI Profile
Twelve generative AI risks.
NIST AI 600-1 (July 2024) identifies these 12 generative-AI-specific risks for the Govern-Map-Measure-Manage cycle.
CBRN information
Chemical, biological, radiological, nuclear information uplift
Confabulation
Generation of false but plausible content (hallucination)
Dangerous content
Self-harm, violence, illegal activity instructions
Data privacy
Training data leakage, membership inference, re-identification
Environmental
Energy and resource costs of training and inference
Harmful bias
Systematic disadvantage to specific demographic groups
Human-AI configuration
Overreliance, automation bias, misaligned human-AI collaboration
Information integrity
Mis/disinformation amplification, deepfakes
IP
Copyright, trademark, trade secret infringement in training or outputs
Obscene content
CSAM, non-consensual intimate imagery, illegal content
Information security
Prompt injection, data exfiltration, model theft
Value chain
Third-party model risks, supply chain provenance, vendor lock-in
EU AI Act Bridge
NIST AI RMF maps to AI Act obligations.
How Matproof helps
NIST AI RMF operationalized.
FAQ
Frequently asked questions
What is the NIST AI Risk Management Framework?+
NIST AI RMF (AI 100-1) is a voluntary risk management framework for AI systems, published by the US National Institute of Standards and Technology in January 2023. It is structured around four functions — Govern, Map, Measure, Manage — and is sector-, technology-, and use-case-agnostic. The framework comes with a companion Playbook (AI RMF Playbook) containing actionable guidance and reference outcomes. NIST has also published profiles tailored to specific contexts, including the Generative AI Profile (AI 600-1) in July 2024.
Should European organizations use NIST AI RMF?+
Yes — even though it is US-origin, NIST AI RMF is highly useful for EU organizations for three reasons. (1) Methodological depth — the framework's risk taxonomy, trustworthy AI characteristics, and outcome statements are more granular and operational than EU AI Act text. (2) US market access — if you sell into US enterprises or US public sector, NIST AI RMF compliance is increasingly expected. (3) Crosswalk with EU AI Act — NIST has published mappings showing how AI RMF outcomes support AI Act obligations, particularly Art. 9 (risk management) and Art. 72 (post-market monitoring).
How do the four functions work?+
(1) Govern — establish the policies, roles, and accountability for AI risk management. This is the foundational, cross-cutting function. (2) Map — establish context, identify and document AI system characteristics, intended uses, and risks. Includes inventory, classification, and stakeholder identification. (3) Measure — assess and track identified risks using quantitative and qualitative methods. Includes testing, monitoring, and evaluation against defined metrics. (4) Manage — allocate resources to identified risks, prioritize risk responses, and track the effectiveness of risk mitigations. Each function has categories and subcategories with specific outcome statements.
What is the Generative AI Profile?+
NIST AI 600-1 (Generative AI Profile, July 2024) is a NIST AI RMF companion document specifically addressing risks from generative AI — large language models, image and video generation, and multimodal models. It identifies 12 generative-AI-specific risks (CBRN information, confabulation, dangerous content, data privacy, environmental, harmful bias, human-AI configuration, IP, obscene content, information integrity, information security, value chain) and maps each to actionable mitigations across the Govern, Map, Measure, Manage functions. Essential reading for any organization deploying GPAI under either NIST or EU AI Act regimes.
How does NIST AI RMF relate to EU AI Act?+
Complementary, not competitive. NIST AI RMF is voluntary, methodologically deep, and process-oriented. EU AI Act is binding, classification-driven, and outcome-oriented. Mappings: NIST 'Govern' broadly aligns with AI Act Art. 17 (quality management system); NIST 'Map' aligns with Art. 9 (risk management system); NIST 'Measure' aligns with Art. 15 (accuracy, robustness, cybersecurity) and Art. 72 (post-market monitoring); NIST 'Manage' aligns with the operational obligations across Art. 9, 14, 15, and 73. An organization with a mature NIST AI RMF implementation can repurpose ~70 percent of its evidence for AI Act conformity assessment.
How does NIST AI RMF relate to ISO 42001?+
Similar problem space, different shapes. ISO 42001 is a management system standard (Annex SL structure, designed for certification); NIST AI RMF is a risk framework (designed for self-assessment and continuous improvement). Many organizations operate both — ISO 42001 as the structural backbone, NIST AI RMF as the operational risk methodology within. The two are interoperable: AI RMF outcomes can be evidence for ISO 42001 controls (especially A.5 impact assessment and Clause 6 risk planning), and ISO 42001's PDCA cycle dovetails with NIST's continuous improvement orientation.
Is NIST AI RMF certifiable?+
No — NIST AI RMF is intentionally not a certification framework. It is a self-assessment tool with no formal accreditation body or certificate. Organizations can publicly attest to their use of the framework, and consultants offer NIST AI RMF readiness assessments, but no third-party 'NIST AI RMF certified' status exists. For certification, organizations typically combine NIST AI RMF methodology with ISO 42001 certification — getting both the depth of NIST's risk methodology and the certificate value of ISO.
Start
Run NIST AI RMF + EU AI Act from one platform.
30-minute demo. See how Matproof operationalizes all four NIST functions and feeds EU AI Act conformity assessment.