Framework Overview
The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary, rights-preserving framework for managing AI risk across the lifecycle. It is organized around four functions — GOVERN, MAP, MEASURE, and MANAGE — and defines seven characteristics of trustworthy AI.
GOVERN cultivates a culture of risk management with policies, roles, accountability, and documentation. MAP establishes the context in which an AI system operates, including its intended use, stakeholders, and assumptions. MEASURE assesses and monitors the system against trustworthy characteristics. MANAGE prioritizes risks and allocates resources to mitigate them.
The trustworthy characteristics are: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed.
While voluntary, the framework is increasingly referenced in regulation and procurement. OMB Memorandum M-24-10 requires US federal agencies to implement the AI RMF for AI they design, develop, acquire, or use, and several state laws and enterprise RFPs point to it as the expected baseline.
Any organization designing, developing, acquiring, or using AI. Adoption is voluntary for most, but mandatory for US federal agencies under OMB M-24-10 and increasingly expected in regulated-industry procurement and enterprise contracts.
No direct fines — the framework is voluntary. Indirect exposure comes through referenced regulations, procurement disqualification, contractual obligations, and reputational harm when incidents occur.
Key Requirements Checklist
Use this checklist to scope your NIST AI RMF compliance program.
Establish GOVERN structures
Define AI policies, assign accountable roles (AI risk owner, accountable executive), map policies to laws and standards, and document decision-making authority.
Document context in MAP
Record the intended use, deployment setting, stakeholders, benefits, and assumptions for each AI system, and identify foreseeable misuses.
Identify risks and impacts
Surface risks to individuals, groups, communities, and society, including third-party and value-chain risks, and prioritize them.
MEASURE performance and trustworthiness
Test validity, reliability, safety, security, robustness, bias, explainability, privacy, and fairness against defined metrics.
Track trustworthy characteristics
Maintain evidence that each of the seven characteristics is being addressed for every system.
MANAGE mitigations and monitoring
Allocate resources to mitigate prioritized risks, implement monitoring, and establish incident response and third-party risk management.
Apply the Generative AI Profile (NIST AI 600)
Address generative-AI-specific risks such as harmful content, data provenance, intellectual property, and information integrity.
Maintain documentation and audit trails
Keep version-controlled records of decisions, tests, mitigations, and changes to support accountability and review.
Monitor and re-evaluate continuously
Re-run measurement and risk assessment on a schedule and when the context, data, or model changes.
How Aegis Oversight Automates NIST AI RMF Compliance
Pre-built controls, continuous checks, and audit-ready evidence — so you implement the checklist once and stay compliant automatically.
A pre-built control library organized by the four functions and their categories lets you assign and evidence each requirement without authoring controls from scratch.
Each AI model captures its intended use, stakeholders, and assumptions, then surfaces foreseeable misuse and value-chain risks for review.
Scheduled bias, fairness, and performance testing produces the MEASURE-function evidence for trustworthy characteristics automatically.
Real-time drift, anomaly, and security monitoring feed incident response and risk re-evaluation on a defined cadence.
Identify which categories and subcategories are unaddressed and prioritize remediation by risk, with AI-assisted recommendations.
Generate reports aligned to the four functions with traceable evidence, ready for internal review, federal reporting, or procurement diligence.
Frequently Asked Questions
It is voluntary for private organizations, but mandatory for US federal agencies under OMB Memorandum M-24-10 and increasingly required by state laws, enterprise procurement, and sector regulators as the expected baseline.
GOVERN (policies, roles, accountability), MAP (context, intended use, risks), MEASURE (assess and monitor trustworthy characteristics), and MANAGE (prioritize and mitigate risks, with monitoring and incident response).
Yes. NIST published the Generative AI Profile (NIST AI 600-1) in July 2024, adding specific risks and actions for generative AI on top of the base framework.
They are complementary. The NIST framework provides the operational risk-management practices; the EU AI Act provides the legal obligations. Organizations complying with both can satisfy NIST requirements while meeting EU AI Act high-risk obligations with overlapping controls.
Valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed.
Assign accountable roles, inventory your AI systems, document each system’s context under MAP, run MEASURE-function tests, and prioritize mitigations under MANAGE — with the control library doing the heavy lifting.
