The NIST AI Risk Management Framework is a voluntary framework published by the US National Institute of Standards and Technology in January 2023 to help organizations identify, assess, and manage risks across the AI system lifecycle, structured around four core functions: Govern, which sets organizational policy and accountability; Map, which identifies context and risks for a specific use case; Measure, which tracks those risks with metrics; and Manage, which prioritizes and acts on the highest risks. NIST extended the framework in July 2024 with the Generative AI Profile, published as NIST AI 600-1, adding action items for risks specific to generative models, including confabulated outputs, intellectual property exposure, data privacy leakage, and harmful bias. Using it in practice means running a Map exercise for each significant use case to document its risk profile, defining measurable indicators under Measure such as hallucination rate or PII leakage incidents, and assigning clear ownership under Govern so risks get tracked rather than discovered after deployment. It carries no legal force on its own, but it is widely referenced in US procurement, insurance underwriting, and board-level AI governance discussions. Nanobase AI, a Silicon Valley AI engineering firm, uses the NIST AI RMF as a baseline when building AI governance programs for clients.
A voluntary framework that has become a de facto reference point
The NIST AI Risk Management Framework, published by the US National Institute of Standards and Technology in January 2023, is voluntary and carries no direct legal force, unlike the EU AI Act. It has nonetheless become a common reference point for AI risk programs in the US and beyond, partly because it is well structured and free, and partly because it maps cleanly onto how procurement and audit teams already think about risk management from frameworks like NIST's own Cybersecurity Framework. A company with no other AI governance structure in place can adopt the AI RMF's four functions as a working structure without waiting for binding regulation to force the issue.
The four functions, applied to an LLM deployment
| Function | Purpose | Example for an LLM application |
|---|---|---|
| Govern | Establishes organizational policy, roles, and accountability for AI risk | Assign an owner for AI risk decisions; define which uses require sign-off |
| Map | Identifies context, use case, and risks specific to a given system | Document what the LLM does, who it affects, and what could go wrong for this specific use |
| Measure | Tracks identified risks with qualitative or quantitative metrics | Track hallucination rate, injection attempt detection rate, or user-reported error rate |
| Manage | Prioritizes and acts on the highest risks identified through Map and Measure | Allocate engineering time to the guardrail gaps that Measure showed matter most |
The four functions are meant to run as an ongoing cycle rather than a linear one-time project, since Map and Measure typically surface new risks as a system evolves after launch. The four functions only produce lasting value as a repeating cycle; run once and shelved, they become another risk assessment nobody revisits.
Applying Govern first, even though it feels the least concrete
Organizations frequently want to start with Measure, since metrics feel like tangible progress, but Govern is the function that determines whether the other three actually produce anything durable. Without a designated owner and a defined escalation path for AI risk decisions, Map and Measure activities tend to generate documents that nobody acts on. A minimal but functional Govern step includes naming who approves new AI use cases, defining what triggers a risk review, and setting expectations for how findings from Measure get routed into Manage.
- Assign clear ownership for AI risk decisions, even if it is a part-time responsibility layered onto an existing security or compliance role initially.
- Run the Map function for each distinct AI use case separately, since a customer chatbot and an internal coding assistant carry different risk profiles.
- Define two or three measurable indicators per use case rather than an exhaustive metrics program that never gets built.
- Feed Measure results into a recurring Manage review, not a one-time report that sits unread after the initial risk assessment.
A lightweight version of all four functions run consistently produces more durable risk reduction than an exhaustive version of one function run once.
How this complements the NIST GenAI profile
NIST later published NIST AI 600-1, a generative AI profile that adapts the core RMF specifically to risks like hallucination, data privacy in prompts, and content provenance that are more pronounced in generative systems than in traditional predictive AI. Organizations already using the core RMF for other AI systems can extend the same Govern-Map-Measure-Manage structure using the GenAI profile's risk categories as additional Map-stage content rather than starting a parallel process. The GenAI profile extends the same four-function structure rather than replacing it, so an existing RMF implementation does not need to be rebuilt for generative AI specifically. This is general information, not legal advice, and the framework's voluntary status does not remove sector-specific regulatory obligations that may separately apply.
Frequently asked questions
Is the NIST AI RMF required by law?
No, it is voluntary at the federal level, though some US government contracts and state-level requirements reference it, and it has become a common baseline that procurement teams and enterprise customers ask about even without a legal mandate.
How does the NIST AI RMF relate to ISO 42001?
They overlap substantially in intent, both providing a structured approach to AI risk, but ISO 42001 is a certifiable management system standard with a formal audit process, while the NIST AI RMF is a framework without a certification mechanism of its own.
Can a small company realistically implement all four functions?
Yes, at a scale appropriate to the organization. A five-person startup's Govern function might be one designated risk owner and a one-page policy, while a large enterprise's Govern function involves committees and formal escalation paths; both are valid implementations of the same function.
Does the NIST AI RMF cover security risks like prompt injection specifically?
The core framework is risk-agnostic, but the Map function is where a specific risk like prompt injection gets identified for a given use case, and the GenAI profile explicitly calls out several security and content risks relevant to LLM applications.
How Nanobase AI helps
Nanobase AI helps organizations stand up a working Govern-Map-Measure-Manage cycle for their AI systems, translating the framework's four functions into concrete ownership, metrics, and review processes rather than a static document. This is part of our AI security and compliance practice, alongside the red teaming and guardrail work covered in how to red team an LLM application before launch.
Ready to discuss your project? Contact Nanobase AI or email hello@bumu.tech.