Framework AI Governance & Privacy Frameworks
NIST AI RMF
The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary US framework, published in January 2023, for identifying and managing the risks that AI systems create for people, organizations, and society.
It is organized around four functions: Govern (policies, roles, and accountability for AI), Map (understanding the context and intended use of each system), Measure (testing and tracking trustworthiness characteristics such as validity, safety, fairness, and explainability), and Manage (prioritizing and treating the risks found).
A companion Playbook suggests concrete actions, and NIST AI 600-1, the Generative AI Profile published in July 2024, adds roughly two hundred actions across twelve risk categories specific to generative models.
The framework does not certify anything and no assessor exists for it. What it asks an organization to have in writing is an AI governance policy and risk tolerance statement, an inventory of AI systems with their intended use and context, documented roles for oversight, a measurement plan and test results for each system, incident and feedback channels, and records showing that risks were reviewed and treated over time.
Many companies adopt it as the internal structure behind an ISO/IEC 42001 management system or EU AI Act readiness program.
Who has to comply
Voluntary. Any organization that designs, develops, deploys, or uses AI systems. US federal agencies were directed to use it through OMB guidance and executive orders, and some state laws and procurement programs reference it as a recognized standard of care.
What the assessor asks to see
Where a customer or auditor asks for AI RMF alignment they generally want the AI governance policy and risk appetite; the AI system inventory with context and intended use; role assignments for oversight; risk assessments per system; testing and measurement results for trustworthiness characteristics; incident response and user feedback records; third-party model and data provenance documentation; and evidence that findings were acted on.
Where the requirement sits: AI RMF 1.0 Govern / Map / Measure / Manage
What AllyMatter does here
Organise AI governance policies against RMF categories.
AllyMatter publishes this site.
Assessors
Who assesses NIST AI RMF
None. There is no NIST certification or accredited assessor for the AI RMF; organizations self-attest or fold the framework into another audited scheme such as ISO/IEC 42001.
No firm has claimed a NIST AI RMF assessor listing yet. Claim yours →
Consultants
Who helps with NIST AI RMF
A broad consultancy and GRC vendor ecosystem. Consultants typically build the AI inventory, draft the governance policy, map systems to the Govern/Map/Measure/Manage subcategories, and set up testing and monitoring routines. Engagements run from a few weeks for a gap assessment to several months for a full program, often paired with ISO/IEC 42001 certification work.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a NIST AI RMF consultant listing yet. Claim yours →
Software
Tools for NIST AI RMF
Tools that name this framework in their own material.
Related reading
- Implementing the NIST AI RMFPractical read on turning Govern, Map, Measure and Manage into named owners, documented decisions and repeatable evidence.Cloud Security Alliance
- NIST's AI Risk Management Framework explainedShort orientation to the four functions and to why the framework is voluntary guidance rather than a certifiable standard.Cloud Security Alliance
- Architecting trust: a NIST-based security governance framework for AI agentsWorked example of mapping the AI RMF functions onto a live agent platform, showing what each function produces in practice.Microsoft
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for NIST AI RMF
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of NIST AI RMF in AllyMatter
Approve the policies NIST AI RMF asks for, keep every version, and record a named acknowledgment from each person who has to read them.