NIST AI Risk Management Framework, explained
6 min read · Certifyi research team · Updated July 2026
The NIST AI Risk Management Framework is a voluntary US framework organised around four functions: Govern, Map, Measure and Manage. It is not certifiable, which makes it useful as an internal operating model and as a common language with US enterprise buyers, but it will not produce a certificate.
The four functions
| Function | What it covers |
|---|---|
| Govern | Culture, accountability, policies and roles. Cuts across the other three. |
| Map | Establish context: intended purpose, stakeholders, and where the system could cause harm. |
| Measure | Assess and track AI risks using quantitative and qualitative methods. |
| Manage | Prioritise, respond to and monitor risks over the lifecycle. |
Why Govern comes first
Govern is not step one in a sequence, it is the layer the others sit on. Without named accountability and a policy for approving models into production, mapping and measuring produce documents nobody acts on.
NIST AI RMF versus ISO 42001
These are complementary, not competing.
| NIST AI RMF | ISO 42001 | |
|---|---|---|
| Type | Voluntary framework | Certifiable standard |
| Output | Internal capability | Third-party certificate |
| Origin | US (NIST) | International (ISO) |
| Best for | Structuring internal AI risk practice | Proving governance to buyers and regulators |
Making it operational
The framework is deliberately non-prescriptive, which is its strength and its trap. Teams read it, agree with it, and produce nothing testable.
- Name an accountable owner for each AI system
- Write a one-page context map per system: purpose, users, potential harms
- Define the measures you will actually track, and where they come from
- Set an approval gate before production and a review cadence after
- Record decisions so they can be evidenced later
Key takeaways
- Four functions: Govern, Map, Measure, Manage.
- Govern is the foundation, not the first step.
- Not certifiable, so pair with ISO 42001 if you need external proof.
- Force it into concrete artefacts or it stays theoretical.
Frequently asked questions
Can we get certified against NIST AI RMF?
No. It is a voluntary framework with no certification scheme. ISO 42001 is the certifiable option.
Is it required by law?
No, it is voluntary. Some US federal contexts and enterprise procurement standards reference it.
Can we use it alongside ISO 42001?
Yes, and many do. NIST provides the risk-thinking model, ISO 42001 provides the certifiable management system.
Where do most teams start?
With Map. Establishing context and intended purpose for each system usually surfaces the biggest gaps fastest.
Get audit-ready in 8 to 12 weeks
Certifyi pairs the platform with a named compliance lead, at published pricing from $8,000/year.
Book a 20-min deal readiness call