Framework guide

NIST AI RMF in Operation

The NIST AI Risk Management Framework (AI RMF 1.0, published January 2023) defines four core functions for AI risk: Govern, Map, Measure, Manage. AI RMF is voluntary in the US but increasingly cited by federal agencies, state regulators, and contracts.

Publisher
NIST
Version
AI RMF 1.0, January 2023
Standing
Voluntary in the US, cited by agencies, regulators and contracts
In the check
Cited by 8 of the 16 questions
MAP
Understand the AI system, its context, and its potential impacts.
MEASURE
Assess AI risks using qualitative and quantitative methods.
MANAGE
Allocate resources to address identified risks proportionate to projected impact.
GOVERN Establish AI risk-management culture, accountability, and policy.
Figure 1. The four NIST AI RMF functions. Govern underpins the Map, Measure and Manage cycle.
Framework

The four core functions

What each function asks of the organization, and the control that proves it is in place.

FunctionWhat it asksControls that prove it
GovernEstablish AI risk-management culture, accountability, and policy.Named AI risk owner. Approved AI policy. Inventory of AI systems. Mapping to broader enterprise risk.
MapUnderstand the AI system, its context, and its potential impacts.AI system documentation. Stakeholder analysis. Risk and benefit analysis. Use-case classification.
MeasureAssess AI risks using qualitative and quantitative methods.Bias and fairness testing. Robustness testing. Performance metrics. Adversarial testing.
ManageAllocate resources to address identified risks proportionate to projected impact.Risk treatment plans. Incident response. Continuous monitoring. Documentation of decisions.
Posture Check

Where the check cites it

The AI Posture Check cites the NIST AI RMF’s Govern, Map, Measure and Manage functions when placing you at Crawl, Walk, Run or Sprint.

Question the check may askDimensionCitation
Which of these best describes AI in your organization today? Governance NIST AI RMF GOVERN-1.1, MAP-1.1
Is anyone evaluating or piloting AI tools right now, even informally? Governance NIST AI RMF GOVERN-1.5
Have you confirmed with your AI vendors that your data is not used to train their models? Vendor NIST AI RMF MAP-4.1
Are prompts and outputs logged, and is anyone alerted on unusual use? Runtime OWASP LLM10, NIST AI RMF MANAGE-2.2
Do you track which model versions are in use and have a way to retire one? Model OWASP LLM03, NIST AI RMF MEASURE-2.7
Has an AI-specific incident response plan been exercised in a tabletop? Runtime NIST AI RMF MANAGE-2.2
Do you know which AI coding agents and assistants are running on staff machines, and what they can reach? Governance OWASP LLM06 Excessive Agency, NIST AI RMF MAP-1.1
Do you know which AI coding agents and assistants run on staff machines, what they can reach, and how MCP servers and Skills are vetted before install? Governance OWASP LLM06 Excessive Agency, NIST AI RMF MAP-1.1
Ready when you are

Score yourself against this framework.

Five questions, each citing its source. You get your stage, your place on the chart and the one move that matters next.

  • A few minutes for most people
  • Free, from CWS
  • Your stage, the chart and the next move, by email or live with an engineer