NIST AI RMF 1.0 - Govern, Map, Measure, Manage
If the EU AI Act is the binding regulation that determines who pays what penalty when, the NIST AI Risk Management Framework 1.0 is the U.S. industry-consensus standard that determines who gets hired, who wins federal contracts, who passes customer-assurance reviews, and who answers a plaintiff's lawyer arguing breach of duty. The framework is voluntary on paper and practically mandatory in operation. Its four functions, Govern, Map, Measure, Manage, and 19 categories operate continuously and reinforce each other. The April 7, 2026 Critical Infrastructure Profile concept note and the planned Q4 2026 AI Agent Interoperability Profile extend the regime to operators and agents. This lesson walks the framework function-by-function, builds the cross-walk against the EU AI Act and ISO 42001, and ships the AI RMF gap heatmap an AI Governance Lead carries into the Q3 AI Governance Committee.
Why NIST AI RMF Matters - Even Though It Is Voluntary
NIST AI RMF 1.0 was published in January 2023 by the U.S. National Institute of Standards and Technology in response to the National Artificial Intelligence Initiative Act of 2020. It is not law. It does not carry penalty exposure. It is also the document every U.S. federal agency, every responsible U.S. multinational, every U.S.-listed company's general counsel, and every U.S. AI vendor cites in their compliance documentation. Four reasons for the practical weight:
- Federal procurement. Executive Order 14110 (2023) and subsequent FY24-26 federal procurement guidance referenced NIST AI RMF as the framework federal agencies use to assess AI risk. Agencies expect contractors to demonstrate alignment. The U.S. General Services Administration's AI procurement guidance, the Federal CIO Council guidance, and Office of Management and Budget memos all cite NIST AI RMF.
- State procurement. States including California, New York, Texas, Illinois, and Washington have adopted NIST-aligned AI procurement language. A vendor selling AI services into state government in 2026 must demonstrate NIST AI RMF alignment to win the contract.
- Tort and securities standard of care. NIST publications carry significant weight in U.S. tort litigation as evidence of the standard of care a reasonable organization should follow. A defendant in an AI-failure tort case who cannot demonstrate NIST AI RMF alignment is in a weaker position than one who can. Securities litigation under the SEC's AI risk-disclosure expectations similarly cites NIST AI RMF as the framework public companies should reference.
- Customer assurance. Enterprise customers buying AI services in 2026 demand NIST AI RMF alignment in vendor questionnaires. The framework has become the de-facto common reference for B2B AI assurance reviews.
For a multinational with EU + U.S. operations, NIST AI RMF and the EU AI Act are complements, not alternatives. The EU AI Act is the binding regulation for EU-deployed systems and outputs used in the Union. NIST AI RMF is the operational framework for U.S. operations and the cross-walk evidence for ISO 42001 audits. Both must operate.
The Four Functions - Govern, Map, Measure, Manage
The NIST AI RMF Core has four functions. They are not sequential. They operate continuously and reinforce each other. The functions and their high-level intent:
- Govern: The organization-wide context for AI risk: policies, processes, accountability, resources, culture, governance committee structure, third-party AI risk, monitoring.
- Map: Categorization of the AI system, its context, capabilities, use case, intended deployment, affected populations, and contextual risk factors.
- Measure: Quantitative and qualitative assessment of the system's risk, performance, trustworthiness characteristics (validity and reliability; safety; security and resilience; accountability and transparency; explainability and interpretability; privacy enhancement; fairness with harmful bias managed).
- Manage: Treatment of identified risks: prioritization, response, monitoring, communication, decisions about whether to deploy, modify, or retire.
Each function decomposes into categories, each category into subcategories. NIST AI RMF 1.0 lists 19 categories distributed across the four functions. The categories are the operational units; the subcategories are the specific actions, controls, or evidence items.
Govern - The Organization-Wide Context
The Govern function has six categories (Govern 1 through Govern 6 conceptually). It is the foundation of the framework: without operating Govern, the other three functions float. The categories:
- Govern 1 - Policies, processes, and procedures. The AI risk-management process is in place; legal and regulatory requirements are addressed; risk-management activities are integrated into broader enterprise risk management; AI policies are reviewed and updated.
- Govern 2 - Accountability structures. Roles and responsibilities are documented; AI risk decisions are owned by individuals with the authority to make them; reporting lines support effective oversight.
- Govern 3 - Workforce diversity, equity, inclusion, and accessibility. Teams designing, developing, deploying, and managing AI are diverse; equitable practices are in place; bias in workforce composition is acknowledged as risk to system outcomes.
- Govern 4 - Culture, risk tolerance, and oversight. Organizational culture supports identification and management of AI risk; risk tolerance is articulated; oversight mechanisms are in place.
- Govern 5 - Engagement with stakeholders. AI actors engage with affected stakeholders and external parties (e.g., researchers, advocates, regulators) on AI risk management.
- Govern 6 - Third-party AI risk. Third-party risks (suppliers, vendors, customers, downstream users) are addressed; third-party AI policies are in place; third-party assurance is reviewed.
For the cross-walk: Govern 1 maps to ISO 42001 clauses 4-6 (context, leadership, planning) and to EU AI Act Article 17 QMS at the organizational level. Govern 2 maps to ISO 42001 Annex A.3 (internal organization) and to EU AI Act Article 47 personal-accountability for declaration signing. Govern 4 maps to ISO 42001 clause 5 (leadership commitment) and to the AI risk appetite statement at the board level. Govern 6 maps to ISO 42001 Annex A.10 (third-party relationships) and to the EU AI Act GPAI exposure map plus the procurement-contract clauses.
Map - Categorization of the AI System
The Map function has five categories (Map 1 through Map 5 conceptually). It is the discovery and contextualization phase. The categories:
- Map 1 - Context is established and understood. The AI system's purpose, use cases, intended deployment, operating environment, stakeholders, and affected populations are identified.
- Map 2 - Categorization of the AI system is performed. The AI system is classified by capability, use case, risk level, deployment scenario.
- Map 3 - AI capabilities, targeted usage, goals, and expected benefits and costs are understood. System capabilities are documented; intended use is specified; out-of-scope use is named; expected benefits and costs are calibrated.
- Map 4 - Risks and benefits are mapped for all components, including third-party software and data. Third-party AI components, data sources, and dependencies are identified and risk-assessed.
- Map 5 - Impacts to individuals, groups, communities, organizations, and society are characterized. Affected populations and communities are identified; potential impacts (positive and negative) are characterized; impact severity is calibrated.
For the cross-walk: Map 1 maps to ISO 42001 A.6.1.1 (AI impact assessment) and to the EU AI Act Article 3(1) scope memo. Map 2 maps to ISO 42001 A.6.2 (AI system impact criteria) and to the EU AI Act tiering memo. Map 4 maps to ISO 42001 A.10 (third-party relationships) and to the EU AI Act GPAI exposure map. Map 5 maps to ISO 42001 A.5 (AI impact assessment) and to the EU AI Act Article 27 FRIA.
Measure - Risk, Performance, and Trustworthiness Assessment
The Measure function has four categories (Measure 1 through Measure 4 conceptually). It is the quantification phase, both qualitative and quantitative. The categories:
- Measure 1 - Appropriate methods and metrics are identified and applied. Measurement methods and metrics are identified for each trustworthiness characteristic; methods are tracked over time.
- Measure 2 - AI systems are evaluated for trustworthiness characteristics. Validity and reliability, safety, security and resilience, accountability and transparency, explainability and interpretability, privacy enhancement, fairness with harmful bias managed, all evaluated with appropriate methods. Includes Measure 2.7 on red-team evaluations and adversarial testing.
- Measure 3 - Mechanisms for tracking identified risks over time are in place. Risk-tracking mechanisms are operational; change is monitored; new risks are identified.
- Measure 4 - Feedback about efficacy of measurement is gathered and assessed. Measurement effectiveness is assessed; methods are refined; feedback loops to Govern and Map are operational.
For the cross-walk: Measure 2.7 (red-team evaluations and adversarial testing) maps directly to EU AI Act Article 15 (accuracy, robustness, cybersecurity), Article 55(1)(a) (GPAI adversarial testing), ISO 42001 A.8 (information for users), OWASP LLM Top 10 / Agentic Top 10 coverage, and MITRE ATLAS technique-by-technique coverage. The red-team report is the cross-walk artifact for Measure 2.7. Measure 3 maps to ISO 42001 A.6.4 (post-deployment monitoring) and to the EU AI Act Article 72 (post-market monitoring).
Manage - Treatment of Identified Risks
The Manage function has four categories (Manage 1 through Manage 4 conceptually). It is the action phase. The categories:
- Manage 1 - AI risks are prioritized, responded to, and managed. Risk prioritization is in place; response decisions (accept, mitigate, transfer, avoid) are documented; risk owners are assigned.
- Manage 2 - Strategies to maximize AI benefits and minimize negative impacts are planned, prepared, implemented, documented, and informed by input from relevant AI actors. Mitigation strategies are in place; deployer-side controls are operational.
- Manage 3 - AI risks and benefits from third-party entities are managed. Third-party AI risks are managed; third-party AI benefits are realized; supplier relationships are managed.
- Manage 4 - Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored. Response and recovery procedures are in place; incident-response runbook is operational; communication plans are in place.
For the cross-walk: Manage 4 maps to ISO 42001 A.8.4 (incident response) and to the EU AI Act Article 73 (serious-incident reporting) plus Article 26(4) (deployer monitoring + provider notification). The Article 73 incident-response runbook is the cross-walk artifact for Manage 4.
The 2026 Profile Developments - Critical Infrastructure, Agents, and CAISI
NIST publishes profiles as sector-and-use-case-specific overlays on the AI RMF Core. The profiles are operational guidance documents that translate the Core's voluntary functions and categories into industry-specific obligations. The 2026 profile developments to track:
- NIST AI 600-1 GenAI Profile (July 2024). The first major profile, covering generative-AI risk management. Names 12 risks and 200+ suggested actions distributed across the Govern / Map / Measure / Manage functions. Already operational; refreshed periodically. Covered in detail in the next lesson.
- NIST AI RMF Critical Infrastructure Profile (April 7, 2026 concept note). Concept note published; full profile expected in 2026-2027. Addresses critical-infrastructure operators (energy, water, transportation, financial services, healthcare) deploying AI. Likely to cross-walk with EU AI Act Annex III §2 critical-infrastructure category and with the NIS 2 Directive for EU operators.
- NIST AI Agent Interoperability Profile (planned Q4 2026). Addresses agentic AI systems: autonomy, tool access, memory, identity, cross-agent communication. Will provide operational guidance on agent governance and is expected to align with the CAISI AI Agent Standards Initiative.
- CAISI AI Agent Standards Initiative (launched Feb 17, 2026). The Center for AI Standards and Innovation (formerly US AISI, renamed and expanded in late 2025) launched the Agent Standards Initiative to develop voluntary standards for agentic AI systems. Coordinates with NIST AI RMF Agent Interoperability Profile development, UK AISI work, and EU AI Office Article 55 evaluations.
- AISIC Consortium (280+ member organizations as of 2026). The AI Safety Institute Consortium continues to convene industry, academic, and government participants on AI risk-management practices. AISIC working groups inform NIST AI RMF refinements and profile development.
For the cross-walk: the Critical Infrastructure Profile concept note triggers a 2026 refresh of any Annex III §2 system's NIST alignment; the Agent Interoperability Profile triggers a Q4 2026 / Q1 2027 refresh of any agentic AI system's NIST alignment plus alignment with the EU AI Act Recital 110 systemic-risk taxonomy and Article 14 human oversight.
Building the AI RMF Gap Heatmap - The L1 Artifact
The L1 artifact for this lesson is an AI RMF gap heatmap: a matrix with rows for each of the 19 NIST AI RMF categories and columns for the organization's AI portfolio (high-risk, GPAI deployer, minimal-risk plus overlays, Annex I embedded). Each cell carries a status indicator (green / yellow / red) reflecting the organization's operational maturity on that category for that portfolio segment, plus a remediation note and a target completion date.
Walk an example for an EU multinational with U.S. operations in May 2026:
- Govern 1 (policies, processes), Green for the enterprise AI policy + GenAI policy + vendor-risk policy + incident-response policy stack; Yellow for the integration with broader enterprise risk management.
- Govern 2 (accountability), Green for AI Officer role + AI Governance Committee charter + Article 47 personal-accountability for declaration signing.
- Govern 4 (culture, risk tolerance, oversight), Yellow, AI risk appetite statement is in draft; not yet board-ratified.
- Govern 6 (third-party AI risk), Yellow, GPAI exposure map operational but contractual amendments still in progress for non-signatory vendors.
- Map 1 (context), Green for the Article 3(1) scope memo; Green for the AI inventory.
- Map 2 (categorization), Green for the EU AI Act tiering memo; Yellow for the U.S. state overlay completeness.
- Map 4 (third-party components), Yellow, GPAI exposure map operational but ML-BoM coverage gaps for some systems.
- Map 5 (impacts), Green for §5(b)/§5(c) FRIA capability; Yellow for broader Annex III FRIA backlog.
- Measure 1 (methods and metrics), Yellow, performance metrics defined for most high-risk systems; gaps on robustness and fairness metric methodology.
- Measure 2 (trustworthiness evaluation), Green for accuracy/reliability; Yellow for fairness; Red for adversarial testing coverage gaps on agentic systems.
- Measure 2.7 (red-team), Red, coverage gaps on Annex III §1 biometric and §4 employment systems; remediation in progress with Promptfoo + Garak + PyRIT deployment.
- Measure 3 (risk tracking over time), Yellow, post-deployment monitoring operational for some systems; drift-alert pipeline incomplete.
- Manage 1 (prioritization, response), Green for high-risk; Yellow for minimal-risk-with-overlays.
- Manage 3 (third-party risk management), Yellow, vendor remediation aging not yet on Q3 board pack.
- Manage 4 (response and recovery), Green for the Article 73 incident-response runbook; Green for the Article 26(4) deployer-monitoring runbook.
Fifteen cells; six green, seven yellow, two red. The remediation backlog is the gap-closure plan that anchors L2-L5 work. The heatmap is the artifact the AI Governance Committee uses to track progress quarterly.
CAISI, AISIC, and the 2026 Evaluations Convergence
The 2026 development worth understanding for an L1 audience: CAISI (formerly US AISI, renamed late 2025), UK AISI, and the EU AI Office are converging on a common evaluation scoreboard for frontier AI capabilities. CAISI's Feb 17, 2026 Agent Standards Initiative is the U.S. anchor. UK AISI's continuing dangerous-capability evaluation program is the UK anchor. The EU AI Office's Article 55 dialogue with GPAI-with-systemic-risk providers is the EU anchor. The three regimes share evaluation methodology, share findings, and increasingly publish coordinated guidance.
For an L1 audience, the practical implication: a U.S. multinational selling AI services into the EU faces NIST AI RMF + EU AI Act Article 55 (if GPAI-with-systemic-risk) + CAISI Agent Standards (if agentic) + UK AISI evaluation (if UK customers) as an integrated regime. The AI RMF gap heatmap is the artifact that anchors the convergence, gaps on Measure 2.7 are the gaps that show up at every regulator's door.
Common NIST AI RMF Mistakes
Mistake 1 - Treating NIST AI RMF as Purely Voluntary
The framework is voluntary on paper but practically mandatory through federal procurement, state procurement, tort standard of care, securities standard of care, and customer assurance. Programs that ignore NIST AI RMF in 2026 face procurement disqualification, weaker tort defense, and customer-assurance friction.
Mistake 2 - Treating the Four Functions as Sequential
Govern → Map → Measure → Manage is not a waterfall. The four functions operate continuously and reinforce each other. Govern shapes Map (policies inform categorization). Map shapes Measure (categorization determines metric selection). Measure feeds Manage (measurements drive response decisions). Manage feeds Govern (decisions inform policy updates). The cyclical operation is the framework's design.
Mistake 3 - Skipping the Profiles
The NIST AI RMF Core is general; the profiles are operational. A program that operates against the Core alone without referencing the GenAI Profile (for GenAI systems), the Critical Infrastructure Profile concept note (for critical-infrastructure operators), and the planned Agent Interoperability Profile (for agentic systems) misses the operational guidance.
Mistake 4 - Treating Measure 2.7 Red-Team as Optional
Measure 2.7 red-team evaluations and adversarial testing are the operational evidence for EU AI Act Article 15 robustness/cybersecurity and Article 55(1)(a) GPAI adversarial testing. Without operating Measure 2.7, the program has no evidence to point to when the auditor or regulator asks for robustness or adversarial-testing artifacts. The red-team report is the multi-framework cross-walk artifact.
Mistake 5 - Operating NIST AI RMF in Isolation From ISO 42001
NIST AI RMF and ISO 42001 are designed to complement each other. ISO 42001 provides the management-system structure (clauses 4-10 plus Annex A controls). NIST AI RMF provides the functional risk-management approach. A program operating both with a cross-walk produces evidence efficient at five-to-one (one artifact, multiple framework citations). A program operating them in silos produces duplicate work.
Mistake 6 - Treating the Gap Heatmap as a One-Time Deliverable
The AI RMF gap heatmap is a living document. Quarterly refresh plus triggered updates on new system deployments, new vendor relationships, new regulatory developments (Omnibus VII, Commission interpretive notes, NIST profile releases), and remediation completion. The heatmap supports the L4 governance operating plan and the L5 Chief AI Risk Officer board reporting.
Key Takeaways
- NIST AI RMF 1.0 is voluntary but practically mandatory. Federal procurement, state procurement, tort standard of care, securities standard of care, customer assurance all weight the framework heavily.
- Four functions operate continuously and reinforce each other. Govern (organization-wide context), Map (categorization), Measure (risk and trustworthiness), Manage (treatment).
- 19 categories distributed across the four functions. Govern 1-6 (policies, accountability, DEI, culture, stakeholders, third-party); Map 1-5 (context, categorization, capabilities, components, impacts); Measure 1-4 (methods, evaluation including 2.7 red-team, tracking, feedback); Manage 1-4 (prioritization, mitigation, third-party, response/recovery).
- Cross-walks to EU AI Act and ISO 42001 are extensive. Map 1 = Article 3(1) scope memo = ISO 42001 A.6.1.1. Map 2 = EU AI Act tiering memo = ISO 42001 A.6.2. Map 5 = EU AI Act Article 27 FRIA. Measure 2.7 = Article 15 + Article 55(1)(a) = OWASP/ATLAS red-team coverage. Manage 4 = Article 73 + Article 26(4).
- The 2026 profile developments matter. NIST AI 600-1 GenAI Profile (July 2024); NIST AI RMF Critical Infrastructure Profile concept note (April 7, 2026); NIST AI Agent Interoperability Profile (planned Q4 2026); CAISI Agent Standards Initiative (launched Feb 17, 2026); AISIC consortium (280+ members).
- CAISI + UK AISI + EU AI Office are converging. Common evaluation scoreboard for frontier AI capabilities; coordinated guidance; shared methodology. A U.S. multinational selling AI services into the EU faces NIST + EU + UK as an integrated regime.
- The L1 artifact is the AI RMF gap heatmap. Matrix with rows for the 19 categories and columns for portfolio segments. Green/yellow/red status with remediation notes and target dates.
- Measure 2.7 red-team is the multi-framework cross-walk artifact. Provides evidence for EU AI Act Article 15 + Article 55(1)(a), ISO 42001 A.8, OWASP/ATLAS coverage. Coverage gaps on agentic systems should be prioritized for remediation.
- The framework operates with ISO 42001, not in competition with it. ISO 42001 management-system structure + NIST AI RMF functional approach = one cross-walked evidence pack.
- The gap heatmap is a living document. Quarterly refresh plus triggered updates on new systems, vendors, regulatory developments, profile releases.
Skill.re