NIST AI Risk Management Framework (AI RMF 1.0)
What is NIST AI Risk Management Framework (AI RMF 1.0)?
The NIST AI Risk Management Framework (AI RMF 1.0), published January 2023, provides a voluntary framework for managing risks associated with AI systems throughout their lifecycle. It is organized around four core functions: Govern, Map, Measure, and Manage. It comprises 52 controls organised across 9 domains, published by NIST, and applies in the United States (NIST).
How NIST AI Risk Management Framework (AI RMF 1.0) maps to other frameworks
All 52 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 9 domains NIST AI Risk Management Framework (AI RMF 1.0) groups its controls into
Step-by-step implementation of NIST AI Risk Management Framework (AI RMF 1.0)
Where NIST AI Risk Management Framework (AI RMF 1.0) overlaps with the standards you already hold
What NIST AI Risk Management Framework (AI RMF 1.0) means in your sector
What NIST AI Risk Management Framework (AI RMF 1.0) means for your job
Questions people ask about NIST AI Risk Management Framework (AI RMF 1.0)
What is NIST AI Risk Management Framework?
How many controls does NIST AI Risk Management Framework have?
Where does NIST AI Risk Management Framework apply?
What frameworks does NIST AI Risk Management Framework map to?
How do I get started with NIST AI Risk Management Framework compliance?
Query NIST AI Risk Management Framework (AI RMF 1.0) programmatically
NIST AI Risk Management Framework (AI RMF 1.0), its 52 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
NIST AI Risk Management Framework (AI RMF 1.0) API reference and MCP config →What NIST AI Risk Management Framework (AI RMF 1.0) requires, control by control
Each page carries the requirement text for one NIST AI Risk Management Framework (AI RMF 1.0) control and what an assessor expects to see as evidence.
- AIRMF-GV-1-1 Legal and regulatory requirements involving AI are understood, managed, and documented
- AIRMF-GV-1-2 The characteristics of trustworthy AI are integrated into organizational policies, processes, and procedures
- AIRMF-GV-1-3 Processes and procedures are in place to determine the needed level of risk management activities based on the organization's risk tolerance
- AIRMF-GV-1-4 The risk management process and its outcomes are established through transparent policies, procedures, and other controls based on organizational risk priorities
- AIRMF-GV-1-5 Ongoing monitoring and periodic review of the risk management process and its outcomes are planned, organizational roles and responsibilities are clearly defined, including determining the frequency of periodic review
- AIRMF-GV-1-6 Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities
- AIRMF-GV-1-7 Processes and procedures are in place for decommissioning and phasing out of AI systems safely and in a manner that does not increase risks or decrease the organization's trustworthiness
- AIRMF-GV-2-1 Roles and responsibilities and lines of communication related to mapping, measuring, and managing AI risks are documented and are clear to individuals and teams throughout the organization
- AIRMF-GV-2-2 The organization's personnel and partners receive AI risk management training to enable them to perform their duties and responsibilities consistent with related policies, procedures, and agreements
- AIRMF-GV-2-3 Executive leadership of the organization takes responsibility for decisions about risks associated with AI system development and deployment
How much of another standard NIST AI Risk Management Framework (AI RMF 1.0) already covers
Each crosswalk is judged control by control, and the mappings that were rejected are kept alongside the ones that held.
How ready are you for NIST AI Risk Management Framework (AI RMF 1.0)?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.