Skip to content
Compliance Framework

NIST AI RMF

The NIST AI Risk Management Framework is voluntary guidance for managing AI risk across a system's lifecycle. Nobody certifies it, which is why the record you keep is the entirety of what you can show.

Compliance Guide
7 min read

What the AI RMF is

The NIST AI Risk Management Framework is voluntary guidance for managing risk across the lifecycle of an AI system. There is no certification, no auditor, and no legal obligation attached to it.

That is precisely why it gets used. It is the common vocabulary organizations reach for when they need to show they govern AI deliberately, and it is increasingly named in customer questionnaires, board reporting, and procurement standards as the reference an AI governance program should be built against.

Why organizations adopt it

Adoption is usually driven by something concrete rather than by an interest in the framework itself.

  • An enterprise customer asking how AI features are governed before renewing
  • A board or audit committee wanting assurance that AI risk is being managed
  • Preparation for binding regimes such as the EU AI Act, where the RMF gives you a running start
  • An internal need to decide consistently which AI use cases are acceptable and which are not

The four functions

The framework organizes its work into four functions. Govern is continuous and sits underneath the other three rather than preceding them.

  • Govern: a culture and structure for AI risk. Policies, accountability, roles, workforce competence, and the escalation path when something goes wrong.
  • Map: establish context. What the system is for, who it affects, what could go wrong, and what the organization is prepared to accept.
  • Measure: analyze and track. Test for the risks identified in Map, including fairness, robustness, security, privacy, and explainability, and record the results.
  • Manage: act on what was measured. Prioritize, treat, allocate resources, monitor in production, and respond to incidents.

Trustworthiness characteristics

Running through the framework is a set of characteristics a trustworthy AI system is expected to display. They function as the dimensions you assess against, and they routinely conflict with one another.

  • Valid and reliable, which the framework treats as a precondition for the rest
  • Safe, secure, and resilient
  • Accountable and transparent
  • Explainable and interpretable
  • Privacy-enhanced
  • Fair, with harmful bias managed

What the record has to show

Because nobody certifies the AI RMF, the record is the whole of what you have. It has to be able to answer a customer, a regulator, or a board without being reconstructed first.

  • An inventory of AI systems and use cases, which most organizations discover they do not actually have
  • A risk profile per system, tied to context, affected parties, and intended purpose
  • Test and evaluation results against the trustworthiness characteristics, with dates
  • Documented decisions: what was accepted, what was mitigated, what was declined, and who decided
  • Production monitoring records and an AI incident log

How Verdict helps

Verdict stands up the program: the system inventory, the governance structure, the risk profiles, and the test and evaluation record, sized to how your organization actually builds and buys AI.

We then run it, so the record stays current as models are retrained and use cases are added, and so the same evidence supports a binding regime like the EU AI Act or ISO/IEC 42001 when one arrives. Your team reviews all of it in a client portal.

NIST AI RMF is part of ai governance, the work that covers what an organization building or deploying AI has to be able to show about how those systems are governed. The same lane also covers EU AI Act, and ISO/IEC 42001. For the mechanics of an engagement, see how we work.

If you need to show how AI is governed in your organization, and you are starting from an incomplete picture of where it is being used, that is the work we would take on.

Talk to a Consultant