SEE MATPROOF ON YOUR STACK — BOOK A 30-MINUTE DEMO

NIST AI 100-1 · AI 600-1 · AI RMF Playbook

NIST AI RMF. The risk methodology for AI.

The US standard that EU organizations increasingly use as the operational backbone for AI risk management — and the strongest crosswalk available to EU AI Act Art. 9 and Art. 72.

Published Jan 2023 · Generative AI Profile Jul 2024 · Voluntary but increasingly required in US procurement

Four Functions

Govern. Map. Measure. Manage.

GOVERN

Establish accountability

Policies, roles, and accountability for AI risk management. The cross-cutting, foundational function — without Govern, the other three drift.

MAP

Establish context

Identify and document AI system characteristics, intended uses, risks, and stakeholders. Inventory, classification, impact assessment.

MEASURE

Assess risks

Quantitative and qualitative methods to track identified risks. Testing, monitoring, evaluation against defined metrics.

MANAGE

Treat risks

Allocate resources, prioritize responses, track mitigation effectiveness. Continuous improvement loop.

Generative AI Profile

Twelve generative AI risks.

NIST AI 600-1 (July 2024) identifies these 12 generative-AI-specific risks for the Govern-Map-Measure-Manage cycle.

CBRN information

Chemical, biological, radiological, nuclear information uplift

Confabulation

Generation of false but plausible content (hallucination)

Dangerous content

Self-harm, violence, illegal activity instructions

Data privacy

Training data leakage, membership inference, re-identification

Environmental

Energy and resource costs of training and inference

Harmful bias

Systematic disadvantage to specific demographic groups

Human-AI configuration

Overreliance, automation bias, misaligned human-AI collaboration

Information integrity

Mis/disinformation amplification, deepfakes

IP

Copyright, trademark, trade secret infringement in training or outputs

Obscene content

CSAM, non-consensual intimate imagery, illegal content

Information security

Prompt injection, data exfiltration, model theft

Value chain

Third-party model risks, supply chain provenance, vendor lock-in

EU AI Act Bridge

NIST AI RMF maps to AI Act obligations.

NIST AI RMF
EU AI Act
Govern (Policies, accountability)
Art. 17 — Quality management system
Map (Context, inventory)
Art. 9 — Risk management system + Art. 6 Classification
Map (Impact assessment)
Art. 27 — Fundamental rights impact assessment
Measure (Testing, evaluation)
Art. 15 — Accuracy, robustness, cybersecurity
Measure (Monitoring)
Art. 72 — Post-market monitoring
Manage (Resource allocation)
Art. 9 — Iterative risk management
Manage (Incidents)
Art. 73 — Serious incident reporting

How Matproof helps

NIST AI RMF operationalized.

Govern function templates — policy stack, RACI matrix, decision logs
Map function automation — AI inventory across OpenAI, Anthropic, Azure OpenAI, MLflow
Measure function — risk metrics dashboard with continuous evaluation
Manage function — incident handling, mitigation tracking, effectiveness review
Generative AI Profile mapping for the 12 specific risks
Cross-mapping: NIST AI RMF ↔ EU AI Act ↔ ISO 42001 in one platform

FAQ

Frequently asked questions

What is the NIST AI Risk Management Framework?+

NIST AI RMF (AI 100-1) is a voluntary risk management framework for AI systems, published by the US National Institute of Standards and Technology in January 2023. It is structured around four functions — Govern, Map, Measure, Manage — and is sector-, technology-, and use-case-agnostic. The framework comes with a companion Playbook (AI RMF Playbook) containing actionable guidance and reference outcomes. NIST has also published profiles tailored to specific contexts, including the Generative AI Profile (AI 600-1) in July 2024.

Should European organizations use NIST AI RMF?+

Yes — even though it is US-origin, NIST AI RMF is highly useful for EU organizations for three reasons. (1) Methodological depth — the framework's risk taxonomy, trustworthy AI characteristics, and outcome statements are more granular and operational than EU AI Act text. (2) US market access — if you sell into US enterprises or US public sector, NIST AI RMF compliance is increasingly expected. (3) Crosswalk with EU AI Act — NIST has published mappings showing how AI RMF outcomes support AI Act obligations, particularly Art. 9 (risk management) and Art. 72 (post-market monitoring).

How do the four functions work?+

(1) Govern — establish the policies, roles, and accountability for AI risk management. This is the foundational, cross-cutting function. (2) Map — establish context, identify and document AI system characteristics, intended uses, and risks. Includes inventory, classification, and stakeholder identification. (3) Measure — assess and track identified risks using quantitative and qualitative methods. Includes testing, monitoring, and evaluation against defined metrics. (4) Manage — allocate resources to identified risks, prioritize risk responses, and track the effectiveness of risk mitigations. Each function has categories and subcategories with specific outcome statements.

What is the Generative AI Profile?+

NIST AI 600-1 (Generative AI Profile, July 2024) is a NIST AI RMF companion document specifically addressing risks from generative AI — large language models, image and video generation, and multimodal models. It identifies 12 generative-AI-specific risks (CBRN information, confabulation, dangerous content, data privacy, environmental, harmful bias, human-AI configuration, IP, obscene content, information integrity, information security, value chain) and maps each to actionable mitigations across the Govern, Map, Measure, Manage functions. Essential reading for any organization deploying GPAI under either NIST or EU AI Act regimes.

How does NIST AI RMF relate to EU AI Act?+

Complementary, not competitive. NIST AI RMF is voluntary, methodologically deep, and process-oriented. EU AI Act is binding, classification-driven, and outcome-oriented. Mappings: NIST 'Govern' broadly aligns with AI Act Art. 17 (quality management system); NIST 'Map' aligns with Art. 9 (risk management system); NIST 'Measure' aligns with Art. 15 (accuracy, robustness, cybersecurity) and Art. 72 (post-market monitoring); NIST 'Manage' aligns with the operational obligations across Art. 9, 14, 15, and 73. An organization with a mature NIST AI RMF implementation can repurpose ~70 percent of its evidence for AI Act conformity assessment.

How does NIST AI RMF relate to ISO 42001?+

Similar problem space, different shapes. ISO 42001 is a management system standard (Annex SL structure, designed for certification); NIST AI RMF is a risk framework (designed for self-assessment and continuous improvement). Many organizations operate both — ISO 42001 as the structural backbone, NIST AI RMF as the operational risk methodology within. The two are interoperable: AI RMF outcomes can be evidence for ISO 42001 controls (especially A.5 impact assessment and Clause 6 risk planning), and ISO 42001's PDCA cycle dovetails with NIST's continuous improvement orientation.

Is NIST AI RMF certifiable?+

No — NIST AI RMF is intentionally not a certification framework. It is a self-assessment tool with no formal accreditation body or certificate. Organizations can publicly attest to their use of the framework, and consultants offer NIST AI RMF readiness assessments, but no third-party 'NIST AI RMF certified' status exists. For certification, organizations typically combine NIST AI RMF methodology with ISO 42001 certification — getting both the depth of NIST's risk methodology and the certificate value of ISO.

Start

Run NIST AI RMF + EU AI Act from one platform.

30-minute demo. See how Matproof operationalizes all four NIST functions and feeds EU AI Act conformity assessment.