- The NIST AI Risk Management Framework (AI RMF 1.0) is voluntary guidance for identifying, measuring, and managing risk across the AI lifecycle, not a certification standard.
- It organizes AI risk work into four functions: Govern, Map, Measure, and Manage.
- NIST published AI RMF 1.0 in January 2023, following direction from Congress to develop a framework that balances AI innovation with accountability.
- Adoption is iterative: organizations typically start with an AI inventory and governance structure, then expand into risk mapping, measurement, and ongoing monitoring.
- The framework is technology neutral. It does not require specific tools, so most organizations pair it with technical controls for data discovery, classification, and monitoring.
What Is the NIST AI Risk Management Framework?
The NIST AI Risk Management Framework is voluntary guidance published by the National Institute of Standards and Technology that helps organizations identify, assess, and manage risks associated with artificial intelligence systems across their lifecycle. It is not a certification scheme or a checklist of required controls. Instead, it gives organizations a common structure, built around four functions, that they adapt to their own AI use cases, industry, and risk tolerance.
Security, legal, and product teams increasingly rely on this artificial intelligence risk management framework as a shared vocabulary when they talk about AI risk, since it gives auditors, executives, and engineers a consistent way to describe what has been assessed and what has not. Because the framework does not mandate specific tools or metrics, organizations typically pair it with existing programs such as ISO 27001, SOC 2, or the NIST Cybersecurity Framework rather than treating it as a standalone compliance regime.
How the NIST AI RMF Works: The Four Core Functions
The core of the AI RMF is organized around four functions that operate continuously rather than as a one-time sequence. Each function contains categories and subcategories that organizations tailor to their own systems and risk profile.
- Govern establishes the organizational culture, policies, and accountability structures that support AI risk management. This is where organizations decide who approves high-risk AI use cases, how third-party models enter the environment, and how a risk register is maintained and reviewed. A NIST AI RMF governance function risk register typically tracks each AI system's owner, intended use, risk classification, and outstanding mitigation items, giving the organization one place to answer "what AI do we have, and who is accountable for it."
- Map identifies the context around a given AI system: its intended use, stakeholders, data sources, and potential failure modes. Mapping happens before an organization defines success metrics, since a system that looks fine on a dashboard can still be missing the risks that matter most to the people it affects.
- Measure applies quantitative and qualitative methods to evaluate the risks identified during mapping. This can include offline evaluation datasets, drift monitoring, and testing for issues such as bias, unsafe outputs, or data exposure through prompts and retrieval pipelines.
- Manage prioritizes responses to measured risks, implements mitigations, and feeds lessons learned back into governance. This includes incident response for unsafe model behavior, vendor escalation when a third-party model changes, and rollback plans when a deployment fails validation.
| Function | Primary focus | Example activity |
|---|---|---|
| Govern | Culture, policy, accountability | Maintaining an AI risk register and approval process |
| Map | Context, stakeholders, failure modes | Documenting data sources and intended use for a system |
| Measure | Quantitative and qualitative evaluation | Testing for bias, drift, or prompt injection exposure |
| Manage | Response and continuous improvement | Running incident response for an unsafe model output |
NIST connects these functions to seven characteristics of trustworthy AI: validity and reliability, safety, security and resilience, accountability and transparency, explainability and interpretability, privacy-enhanced design, and fairness with harmful bias managed. Organizations map their own controls to whichever characteristics apply to a given system rather than treating all seven as equally relevant to every use case.
Why NIST Created the AI RMF
Congress directed NIST to develop the framework through the National Artificial Intelligence Initiative Act of 2020, in response to inconsistent AI risk practices across industries and growing concern about harms from poorly governed AI systems. NIST released AI RMF 1.0 on January 26, 2023, after public workshops and multiple rounds of draft feedback from industry, civil society, and academia.
The goal was not to slow AI adoption but to make AI risk management more legible to executives, auditors, and regulators who need a consistent way to ask how an organization identifies, measures, and responds to AI-related harm. NIST has since published companion materials, including a Generative AI Profile and an AI RMF Playbook, that map specific actions to each of the four functions. Because AI capabilities and measurement methods continue to change quickly, NIST treats the framework as a living baseline rather than a fixed standard, and it expects to revise it as practice matures.
Why the NIST AI RMF Matters for Data Security and Compliance
AI systems now touch data that used to sit safely inside a single application: training sets, prompts, retrieval indexes, and model outputs all carry sensitive information that can move in ways traditional security tooling was not built to track. A framework that only addresses model accuracy misses the data governance questions that boards and regulators actually ask, such as where training data came from, who can query a model, and what happens to sensitive data a user pastes into a prompt.
Regulatory pressure has made this more urgent. The EU AI Act introduced risk-based obligations for certain AI systems, and several US federal agencies now reference NIST frameworks when describing expectations for safe and trustworthy AI. State privacy laws continue to apply to personal data even when an AI system is doing the processing, which means data compliance work does not stop just because a workflow now runs through a model instead of a person.
For security teams specifically, the AI RMF gives a shared structure for conversations that used to happen ad hoc: which AI systems exist, what data they touch, and who signed off on that. That structure becomes the basis for showing auditors and boards how AI-related risk is tracked over time, rather than describing it system by system after the fact.
Common Challenges in Implementing the NIST AI RMF
Organizations that adopt the AI RMF tend to run into a similar set of obstacles:
- Incomplete AI inventory: Teams often underestimate how many AI systems and models are already in use, particularly when employees adopt agentic AI tools or third-party APIs without going through a formal approval process.
- Translating principles into controls: The framework describes outcomes, not specific technical controls, so teams with limited AI security experience can struggle to turn a category like "manage third-party risk" into a concrete test or policy.
- Measurement gaps: Bias testing, drift monitoring, and adversarial evaluation require tooling and expertise that many security teams have not needed before, and building that capability takes time.
- Fragmented ownership: Governance, security, legal, and data science teams each own a piece of AI risk, and without a shared risk register, the same system can end up reviewed by one team and invisible to the others.
- Shadow AI adoption: Employees frequently adopt new AI tools faster than governance processes can catch up, which is one reason shadow AI has become its own risk category inside AI governance programs.
How to Implement the NIST AI RMF: A Practical Adoption Path
Adopting the AI RMF is an incremental process, not a single project with a defined end date. Most organizations move through the following stages:
- Build an AI inventory
Identify every AI system, model, vendor, and dataset in use, including tools employees have adopted informally. - Establish governance
Assign owners, define an approval process for new AI use cases, and stand up a risk register that tracks each system's classification and status. - Map context and risk
For each system, document its intended use, data sources, stakeholders, and plausible failure modes before defining success metrics. - Measure against defined criteria
Apply testing appropriate to the system's risk level, from basic accuracy checks for low-risk internal tools to adversarial testing and bias evaluation for customer-facing systems. - Manage ongoing risk
Monitor for drift and unsafe behavior, maintain incident response procedures specific to AI systems, and feed findings back into governance so policy keeps pace with how the systems are actually used. - Expand and mature over time
Move from manual reviews and spreadsheets toward continuous monitoring and integrated reporting as the AI inventory grows.
Organizations already running a mature security program typically map existing controls to Govern and Manage first, since those functions overlap most with existing risk management practice, then add AI-specific work under Map and Measure.
NIST AI RMF vs. NIST Cybersecurity Framework (CSF): Key Differences
The NIST Cybersecurity Framework addresses cybersecurity risk broadly across infrastructure, identity, and incident response. The AI RMF focuses specifically on risks introduced by AI systems, including harmful bias, model drift, unsafe or unexplainable outputs, and AI supply chain risk.
Many organizations run both at once: the CSF as the enterprise security baseline, and the AI RMF as an overlay for the risks that are specific to building, buying, or operating AI. The two frameworks share structural similarities, which is intentional. NIST designed the AI RMF to align with its broader body of trustworthy AI and cybersecurity guidance so organizations already familiar with the CSF can extend existing governance rather than starting over.
How Cyberhaven Addresses NIST AI RMF Alignment
Cyberhaven's approach to Data Security for the Agentic Enterprise gives security teams the visibility the AI RMF assumes they already have: what data moves through which AI systems, who touches it, and where it goes next. Cyberhaven traces the full lifecycle of data as it moves into prompts, retrieval pipelines, and AI tools, then adapts protection to that changing context rather than relying on static rules that break the moment a workflow changes.
That lineage-based visibility supports the Map and Measure functions directly: security teams can see which AI systems actually touch sensitive data instead of relying on a self-reported inventory, and they can evaluate exposure using real usage patterns rather than assumptions. Cyberhaven's data loss prevention (DLP) and insider risk management (IRM) capabilities then support the Manage function by flagging risky data movement into AI tools as it happens, so incident response has evidence to act on rather than a policy document to point to after the fact.
Frequently Asked Questions
What is the NIST AI Risk Management Framework in simple terms?
It is voluntary guidance that helps organizations manage risks related to artificial intelligence, organized around four functions: Govern, Map, Measure, and Manage. It gives teams a shared structure for tracking AI risk instead of relying on ad hoc reviews.
Is the NIST AI RMF mandatory?
No. It is voluntary guidance, not a regulation or certification requirement. Some organizations reference it to support audit readiness or to align with emerging state and federal expectations, but adoption is not legally required in most contexts.
What is the purpose of the risk register in the NIST AI RMF governance function?
A risk register under the Govern function tracks each AI system's owner, intended use, risk classification, and open mitigation items. It gives an organization one place to see what AI is in use and who is accountable for managing its risk.
How is the NIST AI RMF different from the NIST Cybersecurity Framework?
The AI RMF addresses risks specific to AI systems, such as bias, drift, and unsafe outputs. The Cybersecurity Framework addresses broader security risk across infrastructure, identity, and data. Many organizations use both together.
Does the NIST AI RMF require specific security tools?
No. The framework is technology neutral and does not mandate specific vendors or products. Organizations typically combine it with technical controls for data discovery, monitoring, and access management to put it into practice.
How do organizations start adopting the NIST AI RMF?
Most start by building an inventory of AI systems, models, and vendors, then establish governance and a risk register before expanding into risk mapping, measurement, and ongoing monitoring.



.avif)
.avif)
