USUnited States (federal)VoluntaryNIST AI RMF

How to apply the NIST AI RMF to your AI systems

NIST AI Risk Management Framework 1.0

Status
Voluntary
Binding
No
Object analysed
AI system
Requirements
72
Next milestone
Dec 2026

In short

The US reference voluntary framework: 4 functions (Govern, Map, Measure, Manage), 72 subcategories. Cited as a safe harbour by Colorado and Texas.

Steps to compliance

  1. Qualify each AI systemAxes to decide: Internal risk tier (organisation-defined).
  2. Determine your roleDuties vary by role: AI actor.
  3. Apply the 72 requirementsThey focus on: Governance & accountability, Risk management, Accuracy & robustness and Post-deployment monitoring.
  4. Prove it with checks49 checks to document, 31 of which also serve ISO 42001, AI Act and US federal.
  5. Track the deadlinesNext milestone: Dec 2026, Expected RMF revision (potential).

Scope and penalties

Kind
Voluntary framework
Scope
Any organisation designing, deploying or using AI.
Territorial reach
No territorial scope; de facto reference for US public buyers.
Penalties
None (voluntary). Leverage: safe harbour in state laws.
Jurisdiction
United States (federal)

Timeline

Jan 26, 2023AI RMF 1.0
Jul 26, 2024Generative AI Profile (NIST AI 600-1)
Jul 23, 2025AI Action Plan asks for a revision of the framework
Release
Dec 2026Expected RMF revisionPotential
PastSet in the textPotentialTo verify

Qualifying a system

Classification axes and possible verdicts

Internal risk tier (organisation-defined)

HighMediumLow

Requirements

72 requirements

CodeArticleRequirementApplies toChecks
GOVERN-1.1GOVERNLegal and regulatory requirements involving AI are understood, managed, and documented.
Detail

AI systems may be subject to specific applicable legal and regulatory requirements. Some legal requirements can mandate (e.g., nondiscrimination, data privacy and security controls) documentation, disclosure, and increased AI system transparency. These requirements are complex and may not be applicable or differ across applications and contexts.

All
GOVERN-1.2GOVERNThe characteristics of trustworthy AI are integrated into organizational policies, processes, procedures, and practices.
Detail

Policies, processes, and procedures are central components of effective AI risk management and fundamental to individual and organizational accountability. All stakeholders benefit from policies, processes, and procedures which require preventing harm by design and default.

All
GOVERN-1.3GOVERNProcesses, procedures, and practices are in place to determine the needed level of risk management activities based on the organization's risk tolerance.
Detail

Risk management resources are finite in any organization. Adequate AI governance policies delineate the mapping, measurement, and prioritization of risks to allocate resources toward the most material issues for an AI system to ensure effective risk management. Policies may specify systematic processes for assigning mapped and measured risks to standardized risk scales.

All
GOVERN-1.4GOVERNThe risk management process and its outcomes are established through transparent policies, procedures, and other controls based on organizational risk priorities.
Detail

Clear policies and procedures relating to documentation and transparency facilitate and enhance efforts to communicate roles and responsibilities for the Map, Measure and Manage functions across the AI lifecycle. Standardized documentation can help organizations systematically integrate AI risk management processes and enhance accountability efforts. For example, by adding their contact information to a work product document, AI actors can improve communication, increase ownership of work products, and potentially enhance consideration of product quality. Documentation may generate downstream benefits related to improved system replicability and robustness. Proper documentation storage and access procedures allow for quick retrieval of critical information during a negative incident. Explainable machine learning efforts (models and explanatory methods) may bolster technical documentation practices by introducing additional information for review and interpretation by AI Actors.

All
GOVERN-1.5GOVERNOngoing monitoring and periodic review of the risk management process and its outcomes are planned and organizational roles and responsibilities clearly defined, including determining the frequency of periodic review.
Detail

AI systems are dynamic and may perform in unexpected ways once deployed or after deployment. Continuous monitoring is a risk management process for tracking unexpected issues and performance changes, in real-time or at a specific frequency, across the AI system lifecycle.

All
GOVERN-1.6GOVERNMechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities.
Detail

An AI system inventory is an organized database of artifacts relating to an AI system or model. It may include system documentation, incident response plans, data dictionaries, links to implementation software or source code, names and contact information for relevant AI actors, or other information that may be helpful for model or system maintenance and incident response purposes. AI system inventories also enable a holistic view of organizational AI assets. A serviceable AI system inventory may allow for the quick resolution of:

All
GOVERN-1.7GOVERNProcesses and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization's trustworthiness.
Detail

Irregular or indiscriminate termination or deletion of models or AI systems may be inappropriate and increase organizational risk. For example, AI systems may be subject to regulatory requirements or implicated in future security or legal investigations. To maintain trust, organizations may consider establishing policies and processes for the systematic and deliberate decommissioning of AI systems. Typically, such policies consider user and community concerns, risks in dependent and linked systems, and security, legal or regulatory concerns. Decommissioned models or systems may be stored in a model inventory along with active models, for an established length of time.

All
GOVERN-2.1GOVERNRoles and responsibilities and lines of communication related to mapping, measuring, and managing AI risks are documented and are clear to individuals and teams throughout the organization.
Detail

The development of a risk-aware organizational culture starts with defining responsibilities. For example, under some risk management structures, professionals carrying out test and evaluation tasks are independent from AI system developers and report through risk management functions or directly to executives. This kind of structure may help counter implicit biases such as groupthink or sunk cost fallacy and bolster risk management functions, so efforts are not easily bypassed or ignored.

All
GOVERN-2.2GOVERNThe organization's personnel and partners receive AI risk management training to enable them to perform their duties and responsibilities consistent with related policies, procedures, and agreements.
Detail

To enhance AI risk management adoption and effectiveness, organizations are encouraged to identify and integrate appropriate training curricula into enterprise learning requirements. Through regular training, AI actors can maintain awareness of:

All
GOVERN-2.3GOVERNExecutive leadership of the organization takes responsibility for decisions about risks associated with AI system development and deployment.
Detail

Senior leadership and members of the C-Suite in organizations that maintain an AI portfolio, should maintain awareness of AI risks, affirm the organizational appetite for such risks, and be responsible for managing those risks..

All
GOVERN-3.1GOVERNDecision-making related to mapping, measuring, and managing AI risks throughout the lifecycle is informed by a diverse team (e.g., diversity of demographics, disciplines, experience, expertise, and backgrounds).
Detail

A diverse team that includes AI actors with diversity of experience, disciplines, and backgrounds to enhance organizational capacity and capability for anticipating risks is better equipped to carry out risk management. Consultation with external personnel may be necessary when internal teams lack a diverse range of lived experiences or disciplinary expertise.

All
GOVERN-3.2GOVERNPolicies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems.
Detail

Identifying and managing AI risks and impacts are enhanced when a broad set of perspectives and actors across the AI lifecycle, including technical, legal, compliance, social science, and human factors expertise is engaged. AI actors include those who operate, use, or interact with AI systems for downstream tasks, or monitor AI system performance. Effective risk management efforts include:

All
GOVERN-4.1GOVERNOrganizational policies and practices are in place to foster a critical thinking and safety-first mindset in the design, development, deployment, and uses of AI systems to minimize potential negative impacts.
Detail

A risk culture and accompanying practices can help organizations effectively triage the most critical risks. Organizations in some industries implement three (or more) “lines of defense,” where separate teams are held accountable for different aspects of the system lifecycle, such as development, risk management, and auditing. While a traditional three- lines approach may be impractical for smaller organizations, leadership can commit to cultivating a strong risk culture through other means. For example, “effective challenge,” is a culture- based practice that encourages critical thinking and questioning of important design and implementation decisions by experts with the authority and stature to make such changes.

All
GOVERN-4.2GOVERNOrganizational teams document the risks and potential impacts of the AI technology they design, develop, deploy, evaluate, and use, and they communicate about the impacts more broadly.
Detail

Impact assessments are one approach for driving responsible technology development practices. And, within a specific use case, these assessments can provide a high-level structure for organizations to frame risks of a given algorithm or deployment. Impact assessments can also serve as a mechanism for organizations to articulate risks and generate documentation for managing and oversight activities when harms do arise.

All
GOVERN-4.3GOVERNOrganizational practices are in place to enable AI testing, identification of incidents, and information sharing.
Detail

Identifying AI system limitations, detecting and tracking negative impacts and incidents, and sharing information about these issues with appropriate AI actors will improve risk management. Issues such as concept drift, AI bias and discrimination, shortcut learning or underspecification are difficult to identify using current standard AI testing processes. Organizations can institute in-house use and testing policies and procedures to identify and manage such issues. Efforts can take the form of pre-alpha or pre-beta testing, or deploying internally developed systems or products within the organization. Testing may entail limited and controlled in-house, or publicly available, AI system testbeds, and accessibility of AI system interfaces and outputs.

All
GOVERN-5.1GOVERNOrganizational policies and practices are in place to collect, consider, prioritize, and integrate feedback from those external to the team that developed or deployed the AI system regarding the potential individual and societal impacts related to AI risks.
Detail

Beyond internal and laboratory-based system testing, organizational policies and practices may consider AI system fitness-for-purpose related to the intended context of use.

All
GOVERN-5.2GOVERNMechanisms are established to enable the team that developed or deployed AI systems to regularly incorporate adjudicated feedback from relevant AI actors into system design and implementation.
Detail

Organizational policies and procedures that equip AI actors with the processes, knowledge, and expertise needed to inform collaborative decisions about system deployment improve risk management. These decisions are closely tied to AI systems and organizational risk tolerance.

All
GOVERN-6.1GOVERNPolicies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third-party's intellectual property or other rights.
Detail

Risk measurement and management can be complicated by how customers use or integrate third-party data or systems into AI products or services, particularly without sufficient internal governance structures and technical safeguards.

All
GOVERN-6.2GOVERNContingency processes are in place to handle failures or incidents in third-party data or AI systems deemed to be high-risk.
Detail

To mitigate the potential harms of third-party system failures, organizations may implement policies and procedures that include redundancies for covering third-party functions.

All
MAP-1.1MAPIntended purposes, potentially beneficial uses, context-specific laws, norms and expectations, and prospective settings in which the AI system will be deployed are understood and documented. Considerations include: the specific set or types of users along with their expectations; potential positive and negative impacts of system uses to individuals, communities, organizations, society, and the planet; assumptions and related limitations about AI system purposes, uses, and risks across the development or product AI lifecycle; and related TEVV and system metrics.
Detail

Highly accurate and optimized systems can cause harm. Relatedly, organizations should expect broadly deployed AI tools to be reused, repurposed, and potentially misused regardless of intentions.

All
MAP-1.2MAPInterdisciplinary AI actors, competencies, skills, and capacities for establishing context reflect demographic diversity and broad domain and user experience expertise, and their participation is documented. Opportunities for interdisciplinary collaboration are prioritized.
Detail

Successfully mapping context requires a team of AI actors with a diversity of experience, expertise, abilities and backgrounds, and with the resources and independence to engage in critical inquiry.

All
MAP-1.3MAPThe organization's mission and relevant goals for AI technology are understood and documented.
Detail

Defining and documenting the specific business purpose of an AI system in a broader context of societal values helps teams to evaluate risks and increases the clarity of “go/no- go” decisions about whether to deploy.

All
MAP-1.4MAPThe business value or context of business use has been clearly defined or - in the case of assessing existing AI systems - re-evaluated.
Detail

Socio-technical AI risks emerge from the interplay between technical development decisions and how a system is used, who operates it, and the social context into which it is deployed. Addressing these risks is complex and requires a commitment to understanding how contextual factors may interact with AI lifecycle actions. One such contextual factor is how organizational mission and identified system purpose create incentives within AI system design, development, and deployment tasks that may result in positive and negative impacts. By establishing comprehensive and explicit enumeration of AI systems’ context of of business use and expectations, organizations can identify and manage these types of risks.

All
MAP-1.5MAPOrganizational risk tolerances are determined and documented.
Detail

Risk tolerance reflects the level and type of risk the organization is willing to accept while conducting its mission and carrying out its strategy.

All
MAP-1.6MAPSystem requirements (e.g., 'the system shall respect the privacy of its users') are elicited from and understood by relevant AI actors. Design decisions take socio-technical implications into account to address AI risks.
Detail

AI system development requirements may outpace documentation processes for traditional software. When written requirements are unavailable or incomplete, AI actors may inadvertently overlook business and stakeholder needs, over-rely on implicit human biases such as confirmation bias and groupthink, and maintain exclusive focus on computational requirements.

All
MAP-2.1MAPThe specific tasks and methods used to implement the tasks that the AI system will support are defined (e.g., classifiers, generative models, recommenders).
Detail

AI actors define the technical learning or decision-making task(s) an AI system is designed to accomplish, or the benefits that the system will provide. The clearer and narrower the task definition, the easier it is to map its benefits and risks, leading to more fulsome risk management.

All
MAP-2.2MAPInformation about the AI system's knowledge limits and how system output may be utilized and overseen by humans is documented. Documentation provides sufficient information to assist relevant AI actors when making decisions and taking subsequent actions.
Detail

An AI lifecycle consists of many interdependent activities involving a diverse set of actors that often do not have full visibility or control over other parts of the lifecycle and its associated contexts or risks. The interdependencies between these activities, and among the relevant AI actors and organizations, can make it difficult to reliably anticipate potential impacts of AI systems. For example, early decisions in identifying the purpose and objective of an AI system can alter its behavior and capabilities, and the dynamics of deployment setting (such as end users or impacted individuals) can shape the positive or negative impacts of AI system decisions. As a result, the best intentions within one dimension of the AI lifecycle can be undermined via interactions with decisions and conditions in other, later activities. This complexity and varying levels of visibility can introduce uncertainty. And, once deployed and in use, AI systems may sometimes perform poorly, manifest unanticipated negative impacts, or violate legal or ethical norms. These risks and incidents can result from a variety of factors. For example, downstream decisions can be influenced by end user over-trust or under-trust, and other complexities related to AI-supported decision-making.

All
MAP-2.3MAPScientific integrity and TEVV considerations are identified and documented, including those related to experimental design, data collection and selection (e.g., availability, representativeness, suitability), system trustworthiness, and construct validation.
Detail

Standard testing and evaluation protocols provide a basis to confirm assurance in a system that it is operating as designed and claimed. AI systems’ complexities create challenges for traditional testing and evaluation methodologies, which tend to be designed for static or isolated system performance. Opportunities for risk continue well beyond design and deployment, into system operation and application of system-enabled decisions. Testing and evaluation methodologies and metrics therefore address a continuum of activities. TEVV is enhanced when key metrics for performance, safety, and reliability are interpreted in a socio-technical context and not confined to the boundaries of the AI system pipeline.

All
MAP-3.1MAPPotential benefits of intended AI system functionality and performance are examined and documented.
Detail

AI systems have enormous potential to improve quality of life, enhance economic prosperity and security costs. Organizations are encouraged to define and document system purpose and utility, and its potential positive impacts and benefits beyond current known performance benchmarks.

All
MAP-3.2MAPPotential costs, including non-monetary costs, which result from expected or realized AI errors or system functionality and trustworthiness - as connected to organizational risk tolerance - are examined and documented.
Detail

Anticipating negative impacts of AI systems is a difficult task. Negative impacts can be due to many factors, such as system non-functionality or use outside of its operational limits, and may range from minor annoyance to serious injury, financial losses, or regulatory enforcement actions. AI actors can work with a broad set of stakeholders to improve their capacity for understanding systems’ potential impacts – and subsequently – systems’ risks.

All
MAP-3.3MAPTargeted application scope is specified and documented based on the system's capability, established context, and AI system categorization.
Detail

Systems that function in a narrow scope tend to enable better mapping, measurement, and management of risks in the learning or decision-making tasks and the system context. A narrow application scope also helps ease TEVV functions and related resources within an organization.

All
MAP-3.4MAPProcesses for operator and practitioner proficiency with AI system performance and trustworthiness - and relevant technical standards and certifications - are defined, assessed, and documented.
Detail

Human-AI configurations can span from fully autonomous to fully manual. AI systems can autonomously make decisions, defer decision-making to a human expert, or be used by a human decision-maker as an additional opinion. In some scenarios, professionals with expertise in a specific domain work in conjunction with an AI system towards a specific end goal—for example, a decision about another individual(s). Depending on the purpose of the system, the expert may interact with the AI system but is rarely part of the design or development of the system itself. These experts are not necessarily familiar with machine learning, data science, computer science, or other fields traditionally associated with AI design or development and - depending on the application - will likely not require such familiarity. For example, for AI systems that are deployed in health care delivery the experts are the physicians and bring their expertise about medicine—not data science, data modeling and engineering, or other computational factors. The challenge in these settings is not educating the end user about AI system capabilities, but rather leveraging, and not replacing, practitioner domain expertise.

All
MAP-3.5MAPProcesses for human oversight are defined, assessed, and documented in accordance with organizational policies from the govern function.
Detail

As AI systems have evolved in accuracy and precision, computational systems have moved from being used purely for decision support—or for explicit use by and under the control of a human operator—to automated decision making with limited input from humans. Computational decision support systems augment another, typically human, system in making decisions.These types of configurations increase the likelihood of outputs being produced with little human involvement.

All
MAP-4.1MAPApproaches for mapping AI technology and legal risks of its components - including the use of third-party data or software - are in place, followed, and documented, as are risks of infringement of a third party's intellectual property or other rights.
Detail

Technologies and personnel from third-parties are another potential sources of risk to consider during AI risk management activities. Such risks may be difficult to map since risk priorities or tolerances may not be the same as the deployer organization.

All
MAP-4.2MAPInternal risk controls for components of the AI system, including third-party AI technologies, are identified and documented.
Detail

In the course of their work, AI actors often utilize open-source, or otherwise freely available, third-party technologies – some of which may have privacy, bias, and security risks. Organizations may consider internal risk controls for these technology sources and build up practices for evaluating third-party material prior to deployment.

All
MAP-5.1MAPLikelihood and magnitude of each identified impact (both potentially beneficial and harmful) based on expected use, past uses of AI systems in similar contexts, public incident reports, feedback from those external to the team that developed or deployed the AI system, or other data are identified and documented.
Detail

AI actors can evaluate, document and triage the likelihood of AI system impacts identified in Map 5.1 Likelihood estimates may then be assessed and judged for go/no-go decisions about deploying an AI system. If an organization decides to proceed with deploying the system, the likelihood and magnitude estimates can be used to assign TEVV resources appropriate for the risk level.

All
MAP-5.2MAPPractices and personnel for supporting regular engagement with relevant AI actors and integrating feedback about positive, negative, and unanticipated impacts are in place and documented.
Detail

AI systems are socio-technical in nature and can have positive, neutral, or negative implications that extend beyond their stated purpose. Negative impacts can be wide- ranging and affect individuals, groups, communities, organizations, and society, as well as the environment and national security.

All
MEASURE-1.1MEASUREApproaches and metrics for measurement of AI risks enumerated during the map function are selected for implementation starting with the most significant AI risks. The risks or trustworthiness characteristics that will not - or cannot - be measured are properly documented.
Detail

The development and utility of trustworthy AI systems depends on reliable measurements and evaluations of underlying technologies and their use. Compared with traditional software systems, AI technologies bring new failure modes, inherent dependence on training data and methods which directly tie to data quality and representativeness. Additionally, AI systems are inherently socio-technical in nature, meaning they are influenced by societal dynamics and human behavior. AI risks – and benefits – can emerge from the interplay of technical aspects combined with societal factors related to how a system is used, its interactions with other AI systems, who operates it, and the social context in which it is deployed. In other words, What should be measured depends on the purpose, audience, and needs of the evaluations.

All
MEASURE-1.2MEASUREAppropriateness of AI metrics and effectiveness of existing controls are regularly assessed and updated, including reports of errors and potential impacts on affected communities.
Detail

Different AI tasks, such as neural networks or natural language processing, benefit from different evaluation techniques. Use-case and particular settings in which the AI system is used also affects appropriateness of the evaluation techniques. Changes in the operational settings, data drift, model drift are among factors that suggest regularly assessing and updating appropriateness of AI metrics and their effectiveness can enhance reliability of AI system measurements.

All
MEASURE-1.3MEASUREInternal experts who did not serve as front-line developers for the system and/or independent assessors are involved in regular assessments and updates. Domain experts, users, AI actors external to the team that developed or deployed the AI system, and affected communities are consulted in support of assessments as necessary per organizational risk tolerance.
Detail

The current AI systems are brittle, the failure modes are not well described, and the systems are dependent on the context in which they were developed and do not transfer well outside of the training environment. A reliance on local evaluations will be necessary along with a continuous monitoring of these systems. Measurements that extend beyond classical measures (which average across test cases) or expand to focus on pockets of failures where there are potentially significant costs can improve the reliability of risk management activities. Feedback from affected communities about how AI systems are being used can make AI evaluation purposeful. Involving internal experts who did not serve as front-line developers for the system and/or independent assessors regular assessments of AI systems helps a fulsome characterization of AI systems’ performance and trustworthiness .

All
MEASURE-2.1MEASURETest sets, metrics, and details about the tools used during TEVV are documented.
Detail

Documenting measurement approaches, test sets, metrics, processes and materials used, and associated details builds foundation upon which to build a valid, reliable measurement process. Documentation enables repeatability and consistency, and can enhance AI risk management decisions.

All
MEASURE-2.2MEASUREEvaluations involving human subjects meet applicable requirements (including human subject protection) and are representative of the relevant population.
Detail

Measurement and evaluation of AI systems often involves testing with human subjects or using data captured from human subjects. Protection of human subjects is required by law when carrying out federally funded research, and is a domain specific requirement for some disciplines. Standard human subjects protection procedures include protecting the welfare and interests of human subjects, designing evaluations to minimize risks to subjects, and completion of mandatory training regarding legal requirements and expectations.

All
MEASURE-2.3MEASUREAI system performance or assurance criteria are measured qualitatively or quantitatively and demonstrated for conditions similar to deployment setting(s). Measures are documented.
Detail

The current risk and impact environment suggests AI system performance estimates are insufficient and require a deeper understanding of deployment context of use. Computationally focused performance testing and evaluation schemes are restricted to test data sets and in silico techniques. These approaches do not directly evaluate risks and impacts in real world environments and can only predict what might create impact based on an approximation of expected AI use. To properly manage risks, more direct information is necessary to understand how and under what conditions deployed AI creates impacts, who is most likely to be impacted, and what that experience is like.

All
MEASURE-2.4MEASUREThe functionality and behavior of the AI system and its components - as identified in the map function - are monitored when in production.
Detail

AI systems may encounter new issues and risks while in production as the environment evolves over time. This effect, often referred to as “drift”, means AI systems no longer meet the assumptions and limitations of the original design. Regular monitoring allows AI Actors to monitor the functionality and behavior of the AI system and its components – as identified in the MAP function - and enhance the speed and efficacy of necessary system interventions.

All
MEASURE-2.5MEASUREThe AI system to be deployed is demonstrated to be valid and reliable. Limitations of the generalizability beyond the conditions under which the technology was developed are documented.
Detail

An AI system that is not validated or that fails validation may be inaccurate or unreliable or may generalize poorly to data and settings beyond its training, creating and increasing AI risks and reducing trustworthiness. AI Actors can improve system validity by creating processes for exploring and documenting system limitations. This includes broad consideration of purposes and uses for which the system was not designed.

All
MEASURE-2.6MEASUREThe AI system is evaluated regularly for safety risks - as identified in the map function. The AI system to be deployed is demonstrated to be safe, its residual negative risk does not exceed the risk tolerance, and it can fail safely, particularly if made to operate beyond its knowledge limits. Safety metrics reflect system reliability and robustness, real-time monitoring, and response times for AI system failures.
Detail

Many AI systems are being introduced into settings such as transportation, manufacturing or security, where failures may give rise to various physical or environmental harms. AI systems that may endanger human life, health, property or the environment are tested thoroughly prior to deployment, and are regularly evaluated to confirm the system is safe during normal operations, and in settings beyond its proposed use and knowledge limits.

All
MEASURE-2.7MEASUREAI system security and resilience - as identified in the map function - are evaluated and documented.
Detail

AI systems, as well as the ecosystems in which they are deployed, may be said to be resilient if they can withstand unexpected adverse events or unexpected changes in their environment or use – or if they can maintain their functions and structure in the face of internal and external change and degrade safely and gracefully when this is necessary. Common security concerns relate to adversarial examples, data poisoning, and the exfiltration of models, training data, or other intellectual property through AI system endpoints. AI systems that can maintain confidentiality, integrity, and availability through protection mechanisms that prevent unauthorized access and use may be said to be secure.

All
MEASURE-2.8MEASURERisks associated with transparency and accountability - as identified in the map function - are examined and documented.
Detail

Transparency enables meaningful visibility into entire AI pipelines, workflows, processes or organizations and decreases information asymmetry between AI developers and operators and other AI Actors and impacted communities. Transparency is a central element of effective AI risk management that enables insight into how an AI system is working, and the ability to address risks if and when they emerge. The ability for system users, individuals, or impacted communities to seek redress for incorrect or problematic AI system outcomes is one control for transparency and accountability. Higher level recourse processes are typically enabled by lower level implementation efforts directed at explainability and interpretability functionality. See Measure 2.9.

All
MEASURE-2.9MEASUREThe AI model is explained, validated, and documented, and AI system output is interpreted within its context - as identified in the map function - to inform responsible use and governance.
Detail

Explainability and interpretability assist those operating or overseeing an AI system, as well as users of an AI system, to gain deeper insights into the functionality and trustworthiness of the system, including its outputs.

All
MEASURE-2.10MEASUREPrivacy risk of the AI system - as identified in the map function - is examined and documented.
Detail

Privacy refers generally to the norms and practices that help to safeguard human autonomy, identity, and dignity. These norms and practices typically address freedom from intrusion, limiting observation, or individuals’ agency to consent to disclosure or control of facets of their identities (e.g., body, data, reputation).

All
MEASURE-2.11MEASUREFairness and bias - as identified in the map function - are evaluated and results are documented.
Detail

Fairness in AI includes concerns for equality and equity by addressing issues such as harmful bias and discrimination. Standards of fairness can be complex and difficult to define because perceptions of fairness differ among cultures and may shift depending on application. Organizations’ risk management efforts will be enhanced by recognizing and considering these differences. Systems in which harmful biases are mitigated are not necessarily fair. For example, systems in which predictions are somewhat balanced across demographic groups may still be inaccessible to individuals with disabilities or affected by the digital divide or may exacerbate existing disparities or systemic biases.

All
MEASURE-2.12MEASUREEnvironmental impact and sustainability of AI model training and management activities - as identified in the map function - are assessed and documented.
Detail

Large-scale, high-performance computational resources used by AI systems for training and operation can contribute to environmental impacts. Direct negative impacts to the environment from these processes are related to energy consumption, water consumption, and greenhouse gas (GHG) emissions. The OECD has identified metrics for each type of negative direct impact.

All
MEASURE-2.13MEASUREEffectiveness of the employed TEVV metrics and processes in the measure function are evaluated and documented.
Detail

The development of metrics is a process often considered to be objective but, as a human and organization driven endeavor, can reflect implicit and systemic biases, and may inadvertently reflect factors unrelated to the target function. Measurement approaches can be oversimplified, gamed, lack critical nuance, become used and relied upon in unexpected ways, fail to account for differences in affected groups and contexts.

All
MEASURE-3.1MEASUREApproaches, personnel, and documentation are in place to regularly identify and track existing, unanticipated, and emergent AI risks based on factors such as intended and actual performance in deployed contexts.
Detail

For trustworthy AI systems, regular system monitoring is carried out in accordance with organizational governance policies, AI actor roles and responsibilities, and within a culture of continual improvement. If and when emergent or complex risks arise, it may be necessary to adapt internal risk management procedures, such as regular monitoring, to stay on course. Documentation, resources, and training are part of an overall strategy to support AI actors as they investigate and respond to AI system errors, incidents or negative impacts.

All
MEASURE-3.2MEASURERisk tracking approaches are considered for settings where AI risks are difficult to assess using currently available measurement techniques or where metrics are not yet available.
Detail

Risks identified in the Map function may be complex, emerge over time, or difficult to measure. Systematic methods for risk tracking, including novel measurement approaches, can be established as part of regular monitoring and improvement processes.

All
MEASURE-3.3MEASUREFeedback processes for end users and impacted communities to report problems and appeal system outcomes are established and integrated into AI system evaluation metrics.
Detail

Assessing impact is a two-way effort. Many AI system outcomes and impacts may not be visible or recognizable to AI actors across the development and deployment dimensions of the AI lifecycle, and may require direct feedback about system outcomes from the perspective of end users and impacted groups.

All
MEASURE-4.1MEASUREMeasurement approaches for identifying AI risks are connected to deployment context(s) and informed through consultation with domain experts and other end users. Approaches are documented.
Detail

AI Actors carrying out TEVV tasks may have difficulty evaluating impacts within the system context of use. AI system risks and impacts are often best described by end users and others who may be affected by output and subsequent decisions. AI Actors can elicit feedback from impacted individuals and communities via participatory engagement processes established in Govern 5.1 and 5.2, and carried out in Map 1.6, 5.1, and 5.2.

All
MEASURE-4.2MEASUREMeasurement results regarding AI system trustworthiness in deployment context(s) and across the AI lifecycle are informed by input from domain experts and relevant AI actors to validate whether the system is performing consistently as intended. Results are documented.
Detail

Feedback captured from relevant AI Actors can be evaluated in combination with output from Measure 2.5 to 2.11 to determine if the AI system is performing within pre-defined operational limits for validity and reliability, safety, security and resilience, privacy, bias and fairness, explainability and interpretability, and transparency and accountability. This feedback provides an additional layer of insight about AI system performance, including potential misuse or reuse outside of intended settings.

All
MEASURE-4.3MEASUREMeasurable performance improvements or declines based on consultations with relevant AI actors, including affected communities, and field data about context-relevant risks and trustworthiness characteristics are identified and documented.
Detail

TEVV activities conducted throughout the AI system lifecycle can provide baseline quantitative measures for trustworthy characteristics. When combined with results from Measure 2.5 to 2.11 and Measure 4.1 and 4.2, TEVV actors can maintain a comprehensive view of system performance. These measures can be augmented through participatory engagement with potentially impacted communities or other forms of stakeholder elicitation about AI systems’ impacts. These sources of information can allow AI actors to explore potential adjustments to system components, adapt operating conditions, or institute performance improvements.

All
MANAGE-1.1MANAGEA determination is made as to whether the AI system achieves its intended purposes and stated objectives and whether its development or deployment should proceed.
Detail

AI systems may not necessarily be the right solution for a given business task or problem. A standard risk management practice is to formally weigh an AI system’s negative risks against its benefits, and to determine if the AI system is an appropriate solution. Tradeoffs among trustworthiness characteristics —such as deciding to deploy a system based on system performance vs system transparency–may require regular assessment throughout the AI lifecycle.

All
MANAGE-1.2MANAGETreatment of documented AI risks is prioritized based on impact, likelihood, and available resources or methods.
Detail

Risk refers to the composite measure of an event’s probability of occurring and the magnitude (or degree) of the consequences of the corresponding events. The impacts, or consequences, of AI systems can be positive, negative, or both and can result in opportunities or risks.

All
MANAGE-1.3MANAGEResponses to the AI risks deemed high priority, as identified by the map function, are developed, planned, and documented. Risk response options can include mitigating, transferring, avoiding, or accepting.
Detail

Outcomes from GOVERN-1, MAP-5 and MEASURE-2, can be used to address and document identified risks based on established risk tolerances. Organizations can follow existing regulations and guidelines for risk criteria, tolerances and responses established by organizational, domain, discipline, sector, or professional requirements. In lieu of such guidance, organizations can develop risk response plans based on strategies such as accepted model risk management, enterprise risk management, and information sharing and disclosure practices.

All
MANAGE-1.4MANAGENegative residual risks (defined as the sum of all unmitigated risks) to both downstream acquirers of AI systems and end users are documented.
Detail

Organizations may choose to accept or transfer some of the documented risks from MAP and MANAGE 1.3 and 2.1. Such risks, known as residual risk, may affect downstream AI actors such as those engaged in system procurement or use. Transparent monitoring and managing residual risks enables cost benefit analysis and the examination of potential values of AI systems versus its potential negative impacts.

All
MANAGE-2.1MANAGEResources required to manage AI risks are taken into account - along with viable non-AI alternative systems, approaches, or methods - to reduce the magnitude or likelihood of potential impacts.
Detail

Organizational risk response may entail identifying and analyzing alternative approaches, methods, processes or systems, and balancing tradeoffs between trustworthiness characteristics and how they relate to organizational principles and societal values. Analysis of these tradeoffs is informed by consulting with interdisciplinary organizational teams, independent domain experts, and engaging with individuals or community groups. These processes require sufficient resource allocation.

All
MANAGE-2.2MANAGEMechanisms are in place and applied to sustain the value of deployed AI systems.
Detail

System performance and trustworthiness may evolve and shift over time, once an AI system is deployed and put into operation. This phenomenon, generally known as drift, can degrade the value of the AI system to the organization and increase the likelihood of negative impacts. Regular monitoring of AI systems’ performance and trustworthiness enhances organizations’ ability to detect and respond to drift, and thus sustain an AI system’s value once deployed. Processes and mechanisms for regular monitoring address system functionality and behavior - as well as impacts and alignment with the values and norms within the specific context of use. For example, considerations regarding impacts on personal or public safety or privacy may include limiting high speeds when operating autonomous vehicles or restricting illicit content recommendations for minors.

All
MANAGE-2.3MANAGEProcedures are followed to respond to and recover from a previously unknown risk when it is identified.
Detail

AI systems – like any technology – can demonstrate non-functionality or failure or unexpected and unusual behavior. They also can be subject to attacks, incidents, or other misuse or abuse – which their sources are not always known apriori. Organizations can establish, document, communicate and maintain treatment procedures to recognize and counter, mitigate and manage risks that were not previously identified.

All
MANAGE-2.4MANAGEMechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use.
Detail

Performance inconsistent with intended use does not always increase risk or lead to negative impacts. Rigorous TEVV practices are useful for protecting against negative impacts regardless of intended use. When negative impacts do arise, superseding (bypassing), disengaging, or deactivating/decommissioning a model, AI system component(s), or the entire AI system may be necessary, such as when:

All
MANAGE-3.1MANAGEAI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented.
Detail

AI systems may depend on external resources and associated processes, including third- party data, software or hardware systems. Third parties’ supplying organizations with components and services, including tools, software, and expertise for AI system design, development, deployment or use can improve efficiency and scalability. It can also increase complexity and opacity, and, in-turn, risk. Documenting third-party technologies, personnel, and resources that were employed can help manage risks. Focusing first and foremost on risks involving physical safety, legal liabilities, regulatory compliance, and negative impacts on individuals, groups, or society is recommended.

All
MANAGE-3.2MANAGEPre-trained models which are used for development are monitored as part of AI system regular monitoring and maintenance.
Detail

A common approach in AI development is transfer learning, whereby an existing pre- trained model is adapted for use in a different, but related application. AI actors in development tasks often use pre-trained models from third-party entities for tasks such as image classification, language prediction, and entity recognition, because the resources to build such models may not be readily available to most organizations. Pre-trained models are typically trained to address various classification or prediction problems, using exceedingly large datasets and computationally intensive resources. The use of pre-trained models can make it difficult to anticipate negative system outcomes or impacts. Lack of documentation or transparency tools increases the difficulty and general complexity when deploying pre-trained models and hinders root cause analyses.

All
MANAGE-4.1MANAGEPost-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management.
Detail

AI system performance and trustworthiness can change due to a variety of factors. Regular AI system monitoring can help deployers identify performance degradations, adversarial attacks, unexpected and unusual behavior, near-misses, and impacts. Including pre- and post-deployment external feedback about AI system performance can enhance organizational awareness about positive and negative impacts, and reduce the time to respond to risks and harms.

All
MANAGE-4.2MANAGEMeasurable activities for continual improvements are integrated into AI system updates and include regular engagement with interested parties, including relevant AI actors.
Detail

Regular monitoring processes enable system updates to enhance performance and functionality in accordance with regulatory and legal frameworks, and organizational and contextual values and norms. These processes also facilitate analyses of root causes, system degradation, drift, near-misses, and failures, and incident response and documentation.

All
MANAGE-4.3MANAGEIncidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented.
Detail

Regularly documenting an accurate and transparent account of identified and reported errors can enhance AI risk management activities., Examples include:

All

Checks to document

Evidence collected for a check counts for every regulation that uses it.

CodeCheckScopeThemesAlso used by
CHK-POL-TRUSTTrustworthy-AI characteristics are embedded in organizational policies and a safety-first cultureOrganisation
CHK-POL-RISKAn AI risk-management policy and process are established through transparent, documented controlsOrganisation
CHK-RISK-TOLERANCERisk tolerances are defined and AI systems are assigned to risk levelsOrganisation
—
CHK-ROLES-CLARIFIEDRoles, responsibilities and delegated authorities are documented and clear to relevant stakeholdersOrganisation
CHK-REVIEW-PLANOngoing monitoring and periodic review of the risk-management process are planned, with defined roles and review frequencyOrganisation
VER-022-F-01Risk and incident response procedureOrganisation
VER-022-D-01Serious incident reporting procedureOrganisation
CHK-INVENTORYA mechanism to inventory AI systems is in place and resourcedOrganisation
CHK-DECOMMA documented process exists for safe decommissioning and phase-out of AI systemsOrganisation
—
CHK-TRAININGPersonnel and partners receive AI risk-management trainingOrganisation
CHK-EXEC-ACCOUNTExecutive leadership is accountable for AI risk decisions (board committee, risk appetite)Organisation
CHK-TEAM-DIVERSEA diverse, interdisciplinary team is involved and its participation documentedOrganisation
—
VER-008-03Competent overseers assigned to the systemSystem
VER-008-01Documented escalation and emergency stop procedureOrganisation
CHK-EFFECTIVE-CHALLENGEEffective-challenge, red-team or three-lines-of-defense practices are in placeOrganisation
—
CHK-IMPACT-ASSESSAn impact assessment is performed, documented and used in go/no-go and risk decisionsSystem
CHK-TESTING-ENABLEOrganizational practices enable AI testing and identification of limitationsOrganisation
—
CHK-STAKEHOLDER-FEEDBACKMechanisms collect, adjudicate and integrate external stakeholder / user feedbackOrganisation
CHK-THIRDPARTY-POLPolicies address third-party AI/data risks, incl. IP, transparency and testingOrganisation
CHK-THIRDPARTY-CONTINGENCYContingency/redundancy for high-risk third-party failures and ongoing third-party monitoringModel
CHK-USECASE-SCOPINGIntended purpose, context, applicable laws, business value and application scope are documentedSystem
—
CHK-REQ-SPECSystem requirements are elicited with socio-technical implications addressedSystem
—
CHK-CATEGORIZATIONAI system tasks and methods are categorized (classifier, generative, recommender)System
CHK-DOC-TECHTechnical documentation incl. knowledge limits, human oversight and usage instructions is maintainedSystem
—
CHK-TEVVTEVV plan, test sets, metrics and data considerations are documentedSystem
CHK-COMPETENCEOperator/practitioner proficiency processes and relevant standards are definedSystem
—
CHK-COMPONENTSLegal risks and internal controls for AI components, incl. third-party, are identifiedSystem
—
CHK-MEASURE-PLANMeasurement approaches and metrics are selected and connected to context; unmeasured risks documentedSystem
—
CHK-METRIC-REVIEWMetric appropriateness and control effectiveness are regularly assessed and updatedSystem
—
CHK-INDEP-ASSESSIndependent or internal-expert assessment involves domain experts and affected communitiesSystem
—
CHK-HUMAN-SUBJECTSHuman-subject evaluations meet protection requirements and are representativeSystem
—
VER-009-02Accuracy and robustness verified and documentedSystem
VER-021-F-01Operational monitoring planSystem
CHK-SAFETYSafety risks are evaluated and safe-failure demonstratedSystem
CHK-SECURITYSecurity and resilience are evaluated and documentedSystem
CHK-TRANSPARENCYTransparency and accountability risks are examined and documentedSystem
CHK-MODEL-CARDThe model is explained, validated and documented (model card)Model
—
VER-019-D-01Need for a DPIA assessedSystem
CHK-BIASFairness and bias are evaluated and results documentedSystem
CHK-ENVEnvironmental impact and sustainability of model training are assessedModel
VER-003-01Documented and up-to-date risk registerSystem
VER-AUTO-05Accuracy monitoring in operationSystem
CHK-GO-NOGOA go/no-go determination on system deployment is made and documentedSystem
—
CHK-RISK-RESPONSERisk treatment is prioritized and high-priority responses are planned and documentedSystem
CHK-ALTRequired resources and viable non-AI alternatives are consideredSystem
—
VER-008-02System designed to allow human oversight (stop button, override)System
CHK-MODEL-MONITORINGPre-trained models used in development are monitored and maintainedModel
—
CHK-CONTINUAL-IMPROVEContinual-improvement activities are integrated with stakeholder engagementSystem

Themes covered

Frequently asked questions

Who is in scope of NIST AI RMF?

Any organisation designing, deploying or using AI. No territorial scope; de facto reference for US public buyers.

What penalties does NIST AI RMF carry?

None (voluntary). Leverage: safe harbour in state laws.

When do the NIST AI RMF obligations apply?

Jul 26, 2024: Generative AI Profile (NIST AI 600-1); Jul 23, 2025: AI Action Plan asks for a revision of the framework; Dec 2026: Expected RMF revision.

Is NIST AI RMF binding?

No. Kind: voluntary framework. Status: voluntary.

How does NIST AI RMF relate to other regulations?

The same checks serve several texts. Shared checks: ISO 42001 (16), AI Act (9) and US federal (8).

Related regulations

Official sources

Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo