We value your privacy

We use necessary cookies to run the site and, with your consent, analytics and marketing cookies to improve it. You can change your choice anytime. Privacy Policy

  • Security
  • Pricing
  • Blog
Book a scoping call
Back to glossary

NIST AI Risk Management Framework

The NIST AI Risk Management Framework (AI RMF) is a voluntary framework for managing AI risks and building trustworthy AI. Learn its four core functions and how to apply it.

The NIST AI Risk Management Framework (AI RMF) is a voluntary framework published by the U.S. National Institute of Standards and Technology to help organizations manage the risks of artificial intelligence and develop trustworthy, responsible AI systems. Released as AI RMF 1.0 in January 2023, it offers a structured, outcome-based approach — organized around four core functions — that any organization can adapt to its own context, regardless of sector, size, or AI maturity. It is guidance, not regulation, but it has become a common reference point for AI governance programs worldwide.

Why the AI RMF exists

AI systems introduce risks that traditional software risk management does not fully address: models can behave unpredictably, degrade over time, encode harmful bias, expose private data, or be manipulated through their inputs. These risks span the full lifecycle — from data collection and design through deployment and ongoing operation — and they affect not only the deploying organization but also individuals and society.

NIST developed the AI RMF in response to a Congressional directive, through an open, multi-stakeholder process. The goal was a practical, flexible resource that helps organizations identify and manage AI risks while improving their ability to build systems that are worthy of trust. Because it is voluntary and technology-neutral, it is designed to be used alongside — not in place of — existing risk, security, and privacy programs.

The four core functions

The heart of the framework is the AI RMF Core: four functions that organize the activities of managing AI risk. They are not strictly sequential. GOVERN is cross-cutting and informs the other three, which are applied iteratively throughout the AI lifecycle. Each function is broken down into categories and subcategories that describe specific outcomes to work toward.

FunctionRoleWhat it covers
GOVERNCross-cutting culture and accountabilityEstablishes the policies, processes, roles, and accountability structures for managing AI risk across the organization. Cultivates a risk-aware culture and connects technical work to organizational values, legal obligations, and oversight. Informs and is present throughout the other three functions.
MAPContext and risk identificationFrames the context in which an AI system operates and identifies the risks tied to that context — intended purpose, stakeholders, capabilities, limitations, and potential impacts. Establishes the understanding needed to decide whether to proceed and what to measure.
MEASUREAssessment, analysis, and trackingUses quantitative, qualitative, and mixed methods to analyze, assess, benchmark, and monitor the risks identified in MAP. Evaluates AI systems against the characteristics of trustworthy AI and tracks metrics over time.
MANAGEPrioritizing and acting on riskAllocates resources to the risks that have been mapped and measured, prioritizing them based on impact. Implements responses — mitigation, monitoring, or acceptance — and plans for recovery, incident response, and continuous improvement.

GOVERN as the foundation

GOVERN is treated separately because it underpins everything else. Without clear ownership, documented policies, and accountability, the work done in MAP, MEASURE, and MANAGE has no durable home. GOVERN is where an organization decides its risk tolerance, defines who is responsible for AI outcomes, and ensures that legal, ethical, and compliance considerations are built into the lifecycle rather than bolted on afterward.

The iterative loop

In practice, organizations cycle through MAP, MEASURE, and MANAGE continuously. New context emerges, measurements reveal previously unseen risks, and management responses change the system — which in turn requires remapping. The framework is explicitly designed to be revisited as systems and their environments evolve, not completed once.

The characteristics of trustworthy AI

The AI RMF defines risk management in service of a goal: trustworthy AI. It describes seven characteristics that trustworthy AI systems should exhibit. The framework notes that these characteristics can involve trade-offs, and that balancing them is a context-specific judgment rather than a fixed formula.

  • Valid and reliable — the system performs as intended, accurately and consistently, under expected conditions. NIST treats this as a baseline necessary condition for trustworthiness.
  • Safe — the system does not, under defined conditions, lead to states that endanger human life, health, property, or the environment.
  • Secure and resilient — the system can withstand adversarial attacks, unexpected inputs, and changes in its environment, and can recover or degrade gracefully.
  • Accountable and transparent — information about the system is available to the people who need it, and clear lines of responsibility exist for its outcomes.
  • Explainable and interpretable — the mechanisms behind a system's output and the meaning of that output in context can be understood by relevant stakeholders.
  • Privacy-enhanced — the system safeguards human autonomy, identity, and dignity, applying practices that protect personal data and limit intrusion.
  • Fair, with harmful bias managed — the system addresses concerns about equality and equity, and identifies and mitigates harmful bias across systemic, computational, and human dimensions.

No single characteristic is sufficient on its own, and pursuing one can constrain another — for example, increasing interpretability may affect performance, or maximizing accuracy may raise privacy concerns. The framework asks organizations to make these trade-offs deliberately and to document the reasoning.

Supporting resources and profiles

The AI RMF is accompanied by a companion Playbook, a practical resource that suggests concrete actions, references, and documentation for achieving the outcomes described in each function, category, and subcategory. The Playbook is advisory: organizations select the suggestions relevant to their context rather than implementing all of them.

NIST also publishes profiles — use-case or sector-specific implementations of the framework. Most notably, the Generative AI Profile (released in July 2024 as NIST AI 600-1) was developed in response to an Executive Order and identifies risks that are unique to or amplified by generative AI, along with actions, drawn from the Core, that organizations can take to manage them. Profiles let organizations tailor the general framework to a specific class of system without starting from scratch.

How the AI RMF relates to other frameworks

The AI RMF is intentionally compatible with existing governance and security efforts. Organizations already using risk frameworks such as the NIST Cybersecurity Framework or ISO management-system standards can map AI RMF outcomes onto those programs rather than running a parallel process. Because it focuses on outcomes rather than prescriptive controls, it also complements emerging AI regulation — including the EU AI Act — by giving teams a vocabulary and structure for the risk-management practices that such regulation increasingly expects.

Frequently asked questions

Frequently asked questions

No. The AI RMF is voluntary guidance, not law or regulation. NIST has no enforcement authority over its adoption. That said, many organizations adopt it because it provides a credible, widely recognized structure for AI governance, and because aligning to it helps prepare for regulatory expectations such as the EU AI Act. It is designed to be used alongside existing legal, security, and privacy obligations rather than to replace them.

No. Only the broad intent is sequential. GOVERN is cross-cutting and applies throughout — it informs the other three functions continuously. MAP, MEASURE, and MANAGE are meant to be applied iteratively across the AI lifecycle, revisited as the system, its context, and its measured risks change. The framework is a continuous loop, not a one-time checklist.

Yes, through a dedicated profile. The core framework is technology-neutral and applies to all AI systems, but NIST released the Generative AI Profile (AI 600-1) in July 2024 to address risks specific to or amplified by generative AI. It maps those risks to the four core functions and suggests concrete actions, so teams can apply the general framework to generative systems without reinventing it.

Qadar AI operationalizes the MANAGE and GOVERN functions at runtime. Where the framework calls for prioritizing and acting on AI risk, Qadar AI enforces policy on real AI usage and agent actions — inspecting prompts, completions, and tool calls across Shield Web, Shield Desktop, Shield Mobile, and Shield Control. It supports GOVERN with central, role-based policy management and a tamper-evident audit trail that records what was allowed, blocked, or approved across every AI surface. This turns documented governance intent into enforced, evidenced controls over how AI is actually used.

Natali Craig
Olivia Rhye
Drew Cano

Still have questions?

Can’t find the answer you’re looking for? Talk to our team and we’ll help you get started.

Get in touch

See how Qadar AI implements these concepts at runtime

Book a demo

A product specialist will reply within one business day

Subscribe to our newsletter

Product and governance updates — see our privacy policy.

AI security and control for every model your team uses.

Built in Dubai. Designed for teams operating across regions, models, and regulatory environments.

  • Product

    • Shield Web
    • Shield Control
    • Shield Desktop
    • Shield Mobile
    • Pricing
  • Solutions

    • For CISOs
    • For Operations
    • For AI Teams
  • Use Cases

    • AI Governance
    • AI Agent Security
    • LLM Access Control
    • Secure AI Deployment
    • Enterprise Operations
    • Financial Services
  • Resources

    • Blog
    • Guides
    • Glossary
    • AI Risk Calculator
    • Compare
    • FAQ
  • Company

    • About
    • Careers
    • Security & Trust
    • Contact
  • Legal

    • Legal
    • Privacy
    • Terms
    • GDPR / DPA

© 2026 Qadar AI. All rights reserved. EU data residency available for Enterprise customers.