What is the NIST AI Risk Management Framework?
By Identra · Updated
The NIST AI Risk Management Framework (AI RMF) is voluntary guidance for managing the risks AI systems pose to people, organizations and society across their lifecycle. Its Govern, Map, Measure and Manage functions help organizations assign accountability, evaluate potential harm and make informed decisions about AI use.
What does the NIST AI RMF cover?
The National Institute of Standards and Technology wrote it for anyone who develops, buys, deploys or uses AI. It describes trustworthy AI through a set of characteristics: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. Attacks on models are one slice of that. Most of the framework is about what happens when AI is used in a specific setting. See the NIST framework overview.
For a CISO it is a shared vocabulary. Security, engineering and the business owner can agree on the intended use, the possible harm, the evidence needed and how much risk is left over. That ties AI governance to real calls. Launch it, widen its access or pull it.
How do Govern, Map, Measure and Manage work?
Govern sets accountability and runs underneath the other three. Map establishes context. Measure evaluates the risks. Manage decides what to do about them. Teams loop back through the functions as systems and their uses change, so this is not a one-time checklist before launch. The AI RMF 1.0 document explains how they fit together.
The evidence column below shows what a security team might keep. NIST does not prescribe these documents.
Govern
- Decision it supports
- Who is accountable, and how much risk is acceptable?
- Example evidence
- Named owner, use policy, escalation path
Map
- Decision it supports
- What could go wrong in this deployment?
- Example evidence
- Data flows, affected groups, access inventory, failure scenarios
Measure
- Decision it supports
- What do the evaluations show?
- Example evidence
- Test results, control checks, known limits of the testing
Manage
- Decision it supports
- Which risks get fixed and which get accepted?
- Example evidence
- Remediation records, approval decisions, monitoring plans
What does the NIST Generative AI Profile add?
NIST's Generative AI Profile, NIST AI 600-1, applies the framework to generative AI. Its risk list includes confabulation, which is NIST's term for confidently stated false output, along with data privacy, information integrity, information security, harmful bias and risks from third-party components in the value chain. Suggested actions sit under the same four functions.
Pick what fits. A document Q&A assistant needs tests for made-up answers and sensitive data disclosure. Claude Code with shell access needs its permissions and actions evaluated as well. When you test prompt injection, measure what a successful attack could do with the access the system really holds.
The companion NIST AI RMF Playbook has implementation suggestions to choose from. Neither document hands you a pass or fail grade.
What does applying the AI RMF look like in an enterprise?
Say a team proposes an assistant that reads customer tickets and drafts replies. The business wants faster handling. Security wants no cross-customer leaks and nothing sent without a person looking at it. Start by writing down which records it can read, whose identity it runs as and whether it can send on its own. Then walk the functions.
- Govern. Name an owner and set launch criteria.
- Map. Work through hostile ticket text that asks for another customer's records.
- Measure. Test customer separation, misleading instructions and unsupported answers on representative tickets.
- Manage. Restrict access, require review before send and fix failed tests before expanding use.
How should security teams get started with the AI RMF?
Apply least privilege to the account the assistant connects with. A line in the system prompt telling the model to respect customer boundaries is not an access control. And if the assistant later gets refund authority, run the assessment again because the stakes changed.
More broadly, pick one workflow that matters and has an owner willing to act on findings. Include shadow AI so the scope matches what people really use. Look at browser tools, endpoint apps and connected SaaS or cloud services wherever they touch that workflow. Run the work through your existing risk, change and incident processes rather than building new ones.
- Record purpose, owner, users, data sources, connected identities and permitted actions.
- Describe concrete harm, such as disclosure, a wrong decision or an unauthorized action.
- Pick a control for each scenario and define what passing and failing look like.
- Test the deployed configuration, integrations and permissions included, before approving wider use.
- Give every open issue an owner and record who accepts the remaining risk.
- Write down how to pause the system and revoke its access. Reassess after material changes to models, data, tools or permissions.
What evidence makes an AI RMF assessment useful?
A clean chain from scenario to control to test result to decision. Record the configuration you tested, what you expected, what happened and what is still uncertain. An AI audit trail helps later, as long as the records carry enough context to explain the outcome.
Policy evidence and operational evidence are different things. An approved access policy shows intent. A test proving the assistant cannot pull another customer's records supports a claim about that configuration on the day you ran it.
Keep the provider's material apart from your own. A model provider's system card says nothing about your data sources or your permissions. Note what each piece of evidence covers, which issues are open and what would trigger the next review.
How Identra thinks about it
Identra gives security teams visibility into AI apps, accounts and agents across the browser, endpoints and connected identity, SaaS and cloud providers. Teams can allow, redirect or block supported AI apps in the browser by signed-in account, check prompts on the device before they are sent, and review recorded AI agent runs with their allowed or blocked outcome as input to AI risk reviews.
Go deeper: AI security, built on identity
Frequently asked questions
Is the NIST AI RMF mandatory?
No. The framework is voluntary. Adopting it does not by itself show that an organization meets its legal or contractual requirements.
Are Govern, Map, Measure and Manage sequential steps?
No. Govern runs throughout the lifecycle. Teams return to the other functions as evaluations, deployment changes and operating experience turn up new information.
Does the framework apply to purchased AI tools?
Yes. If you use third-party AI you still assess your own use cases, data, integrations and permissions. Provider documentation feeds that assessment but does not replace it.
Is the Generative AI Profile a separate framework?
No. It is a companion resource that applies the AI RMF to generative AI risks and suggests actions under the same four functions.
Who should own an AI RMF assessment?
Someone with authority over the use case and its risk decisions. Security contributes alongside the business, engineering and other stakeholders because the assessment covers harm beyond cybersecurity.
Does completing an assessment prove an AI system is safe?
No. An assessment supports a decision within a defined scope and stated limits. Remaining risks need owners, and material changes should trigger another review.
