Framework guide
NIST AI RMF in Operation
The NIST AI Risk Management Framework (AI RMF 1.0, published January 2023) defines four core functions for AI risk: Govern, Map, Measure, Manage. AI RMF is voluntary in the US but increasingly cited by federal agencies, state regulators, and contracts.
- Publisher
- NIST
- Version
- AI RMF 1.0, January 2023
- Standing
- Voluntary in the US, cited by agencies, regulators and contracts
- In the check
- Cited by 8 of the 16 questions
Framework
The four core functions
What each function asks of the organization, and the control that proves it is in place.
| Function | What it asks | Controls that prove it |
|---|---|---|
| Govern | Establish AI risk-management culture, accountability, and policy. | Named AI risk owner. Approved AI policy. Inventory of AI systems. Mapping to broader enterprise risk. |
| Map | Understand the AI system, its context, and its potential impacts. | AI system documentation. Stakeholder analysis. Risk and benefit analysis. Use-case classification. |
| Measure | Assess AI risks using qualitative and quantitative methods. | Bias and fairness testing. Robustness testing. Performance metrics. Adversarial testing. |
| Manage | Allocate resources to address identified risks proportionate to projected impact. | Risk treatment plans. Incident response. Continuous monitoring. Documentation of decisions. |
Posture Check
Where the check cites it
The AI Posture Check cites the NIST AI RMF’s Govern, Map, Measure and Manage functions when placing you at Crawl, Walk, Run or Sprint.
| Question the check may ask | Dimension | Citation |
|---|---|---|
| Which of these best describes AI in your organization today? | Governance | NIST AI RMF GOVERN-1.1, MAP-1.1 |
| Is anyone evaluating or piloting AI tools right now, even informally? | Governance | NIST AI RMF GOVERN-1.5 |
| Have you confirmed with your AI vendors that your data is not used to train their models? | Vendor | NIST AI RMF MAP-4.1 |
| Are prompts and outputs logged, and is anyone alerted on unusual use? | Runtime | OWASP LLM10, NIST AI RMF MANAGE-2.2 |
| Do you track which model versions are in use and have a way to retire one? | Model | OWASP LLM03, NIST AI RMF MEASURE-2.7 |
| Has an AI-specific incident response plan been exercised in a tabletop? | Runtime | NIST AI RMF MANAGE-2.2 |
| Do you know which AI coding agents and assistants are running on staff machines, and what they can reach? | Governance | OWASP LLM06 Excessive Agency, NIST AI RMF MAP-1.1 |
| Do you know which AI coding agents and assistants run on staff machines, what they can reach, and how MCP servers and Skills are vetted before install? | Governance | OWASP LLM06 Excessive Agency, NIST AI RMF MAP-1.1 |
Related
Other frameworks the check cites
Ready when you are
Score yourself against this framework.
Five questions, each citing its source. You get your stage, your place on the chart and the one move that matters next.
- A few minutes for most people
- Free, from CWS
- Your stage, the chart and the next move, by email or live with an engineer