10.1 NIST AI Risk Management Framework (AI RMF 1.0)

Key Takeaways

  • NIST AI RMF 1.0 is published as NIST AI 100-1; its Core organizes risk-management outcomes while Profiles and the Playbook support contextualization and implementation.
  • The Core consists of four cyclical, non-linear functions: GOVERN provides the cross-cutting organizational leadership and accountability umbrella, which directs and informs MAP (context and framing), MEASURE (quantitative and qualitative TEVV), and MANAGE (risk treatment and continuous monitoring).
  • The framework defines seven core characteristics of Trustworthy AI: Valid & Reliable, Safe, Secure & Resilient, Accountable & Transparent, Explainable & Interpretable, Privacy-Enhanced, and Fair with Harmful Biases Managed.
  • NIST AI 600-1 is the Generative AI Profile and identifies 12 risk categories, including confabulation, CBRN information or capabilities, privacy, information security, intellectual property, and value-chain integration.
  • Testing, Evaluation, Verification, and Validation (TEVV) serves as the technical engine of the MEASURE function, establishing empirical baselines to inform operational risk response and continuous assurance in MANAGE.
Last updated: September 2026

10.1 NIST AI Risk Management Framework (AI RMF 1.0)

The official identifier for AI RMF 1.0 is NIST AI 100-1, published in January 2023. It is not NIST SP 1270; SP 1270 is a different NIST publication about bias in AI. The AI RMF is voluntary, rights-preserving, non-sector-specific guidance. NIST has announced that an update is in progress, so production programs should version the framework; CY0-001 candidates should understand the published 1.0 Core specified by the blueprint. A law, regulator, contract, or organizational policy can require particular activities, but the framework itself does not impose fines.

Core and supporting resources

The AI RMF Core organizes outcomes at three levels: Functions, Categories, and Subcategories. The four functions are GOVERN, MAP, MEASURE, and MANAGE. They are not a one-time waterfall. GOVERN is cross-cutting, and information from operation can send an organization back to mapping, measurement, or treatment.

  • GOVERN establishes policies, culture, accountability, roles, competencies, legal and policy context, documentation, third-party oversight, and lifecycle review.
  • MAP establishes context: intended purpose, users, affected communities, data, deployment environment, dependencies, benefits, impacts, and risk tolerance.
  • MEASURE uses qualitative and quantitative methods to analyze trustworthiness, uncertainty, limitations, and risk. Testing, evaluation, verification, and validation (TEVV) belongs here.
  • MANAGE prioritizes risk, selects and monitors treatments, allocates resources, responds to incidents, and determines whether to deploy, restrict, redesign, or retire a system.

Profiles help an organization describe current and target application of Core outcomes for a context. The online Playbook offers suggested actions and references. Profiles and the Playbook are supporting resources; calling Core, Profiles, and Playbook official structural pillars obscures that the normative organizing structure of the Core is Functions, Categories, and Subcategories.

Trustworthy AI characteristics

AI RMF describes trustworthy AI as valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair with harmful bias managed. These characteristics interact and may conflict. More explanation can expose sensitive system detail. Privacy protection may reduce utility. A robust system can still be inaccurate for a particular population. The framework asks organizations to measure trade-offs in context, not to claim every trait is maximized.

TEVV should be independent enough for the impact and should use representative conditions. For a security classifier, evidence might include precision and recall by relevant scenario, calibration, false-negative analysis, adversarial robustness, latency, drift, data-quality checks, privacy tests, and recovery exercises. Metrics need documented datasets, versions, uncertainty, owners, and acceptance criteria. No single accuracy score proves trustworthiness.

NIST AI 600-1 Generative AI Profile

NIST AI 600-1, published in July 2024, applies AI RMF outcomes to generative AI. It identifies these 12 risk categories:

  1. CBRN information or capabilities
  2. Confabulation
  3. Dangerous, violent, or hateful content
  4. Data privacy
  5. Environmental impacts
  6. Human-AI configuration
  7. Information integrity
  8. Information security
  9. Intellectual property
  10. Obscene, degrading, and/or abusive content
  11. Value-chain and component integration
  12. Harmful bias and homogenization

Use the official names because several categories are broader than common shorthand. For example, information security covers attacks and vulnerabilities; human-AI configuration includes automation bias and inappropriate anthropomorphism; value-chain and component integration covers dependencies across data, models, plug-ins, suppliers, and deployers. Prompt injection is an important information-security scenario, not a separate thirteenth category.

The profile recommends actions rather than guaranteeing outcomes. Relevant measures can include groundedness and citation checks, dangerous-capability testing, privacy attacks, content evaluations, red-team exercises, provenance analysis, and human-factor tests. Automated evaluators also have error and bias, so high-impact claims need independent evidence and human expertise.

Applying the functions

Consider a SOC assistant that summarizes endpoint alerts and proposes containment:

  1. GOVERN: name the system and risk owners; define acceptable use, supplier requirements, escalation, records, approval authority, and retirement criteria.
  2. MAP: document the users, protected assets, telemetry classes, threat actors, integrations, possible false-positive and false-negative harm, and the fact that proposed commands could affect production.
  3. MEASURE: test on held-out and time-relevant alerts; measure evidence faithfulness, missed detections, false alarms, privacy leakage, injection resistance, tool-boundary enforcement, and performance across relevant environments.
  4. MANAGE: keep the model advisory, restrict retrieval and tools, validate outputs, require approval for containment, monitor drift and incidents, and maintain rollback. If residual risk exceeds tolerance, restrict or reject deployment.

A control belongs to more than one function when viewed from different responsibilities. The policy requiring human approval is governed; the scenario and affected operator are mapped; test evidence is measured; and the implemented gate is managed.

Exam distinctions

Do not confuse AI RMF with the NIST Cybersecurity Framework. CSF 2.0 organizes cybersecurity outcomes; AI RMF focuses on AI risks and trustworthy characteristics. They can be used together. Do not confuse a Profile with a model profile or model card. An AI RMF Profile expresses how Core outcomes apply to a context. Finally, remember that GOVERN is cross-cutting, MAP supplies context, MEASURE produces evidence, and MANAGE prioritizes and treats risk.

Loading diagram...
NIST AI RMF 1.0 Architecture and Trustworthy Characteristics
Test Your Knowledge

An enterprise risk management committee is establishing an AI governance program. The Chief Information Security Officer (CISO) emphasizes that the organization must define explicit leadership accountability, formalize AI acceptable use policies, determine organizational risk appetite, and establish third-party vendor review mechanisms before expanding model deployment. Under the NIST AI Risk Management Framework (AI RMF 1.0), which Core Function encompasses these activities?

A
B
C
D
Test Your Knowledge

A machine learning security team is preparing to deploy an automated network intrusion detection model. To validate the system prior to release, the team conducts adversarial perturbation testing using Projected Gradient Descent (PGD), calculates precision-recall curves across synthetic attack datasets, audits demographic parity metrics, and establishes baseline drift thresholds. Under NIST AI RMF 1.0, which technical process and Core Function do these activities represent?

A
B
C
D
Test Your Knowledge

A cybersecurity architect is reviewing NIST AI 600-1 (the Generative AI Profile) to evaluate risks associated with deploying a foundation model for automated threat analysis. Which choice names risks that the profile explicitly addresses?

A
B
C
D