AI Governance, Risk & Red Teaming
Proficient · M22 · lesson 22 of 31 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
NIST AI RMF Profile Building - Sector and Use-Case Profiles
📖
now learning

NIST AI RMF Profile Building - Sector and Use-Case Profiles

15 min

The NIST AI RMF Core is general by design: four functions, 19 categories, written so a chemical-plant safety controller, a hospital triage model, an HR resume-ranker, and a customer-service chatbot can all map to the same framework. The operational guidance lives in the profiles. NIST AI 600-1 (the GenAI Profile, July 2024) translated the Core for generative AI. The Critical Infrastructure Profile concept note (April 7, 2026) extends the regime to grid operators, water utilities, hospitals, and financial-services infrastructure. The planned Q4 2026 AI Agent Interoperability Profile, coordinated with the CAISI Agent Standards Initiative (Feb 17, 2026), will extend it to agentic systems. An L3 practitioner does not wait for NIST. They build their own use-case profile for each material deployment and cross-walk it to the published profiles as those land. This lesson builds three worked examples, an HR-screening profile, a critical-infrastructure pre-cursor, and an agentic-deployment pre-cursor, and ships the methodology a practitioner reuses across the portfolio.

What a NIST AI RMF Profile Is - and Is Not

A NIST AI RMF profile is a sector-and-use-case-specific overlay on the AI RMF Core. The Core lists four functions (Govern, Map, Measure, Manage), 19 categories, and 70+ subcategories at a level of abstraction designed to fit any AI system in any sector. The profile takes those abstract categories and translates them into operational guidance for a specific deployment context: which subcategories matter most, which suggested actions to take, which metrics to track, which artifacts to produce, which cross-walks to maintain with adjacent frameworks (EU AI Act, ISO 42001, OWASP, MITRE ATLAS, sector-specific obligations).

A profile is not a replacement for the Core. It sits on top of it. A profile is not a compliance checklist, the AI RMF remains voluntary, and the profile inherits that posture (subject to the same federal-procurement / state-procurement / tort standard-of-care / customer-assurance practical-weight mechanics described in the previous lesson). A profile is not a one-time deliverable. It refreshes on a quarterly cadence and on trigger events (new system deployments, new vendor relationships, new regulatory developments, NIST profile releases, remediation completion).

The published profiles to track in May 2026:

  • NIST AI 600-1 GenAI Profile (July 2024). The first major profile. Names 12 risks: CBRN information; confabulation; dangerous, violent, or hateful content; data privacy; environmental impacts; human-AI configuration; information integrity; information security; intellectual property; obscene, degrading, or abusive content; value chain and component integration; harmful bias and homogenization. Distributes 200+ suggested actions across the Govern / Map / Measure / Manage functions. Operational guidance for any organization deploying or operating generative AI. Covered in detail in the next lesson.
  • NIST AI RMF Critical Infrastructure Profile (April 7, 2026 concept note). Concept note published; full profile expected 2026-2027. Targets critical-infrastructure operators across energy, water, transportation, financial services, and healthcare. Expected to cross-walk with EU AI Act Annex III §2 critical-infrastructure category, with the NIS 2 Directive for EU operators, and with sector-specific frameworks (NERC CIP for power, HIPAA Security Rule for healthcare, GLBA Safeguards Rule for financial services).
  • NIST AI Agent Interoperability Profile (planned Q4 2026). Addresses agentic AI: autonomy tiers, tool access, memory hygiene, identity, cross-agent communication, agent observability. Expected to align with the CAISI AI Agent Standards Initiative (launched Feb 17, 2026), the OWASP Agentic Top 10 (ASI01-ASI10), and the MITRE ATLAS agentic-systems techniques. For organizations with material agentic deployments, the profile will become the operational anchor for governance.

The framework's design intent: profiles proliferate. The first three are sector-and-deployment overlays. The next wave will cover sector-specific use cases (healthcare diagnostic AI, financial-services credit AI, education AI, defense AI). An L3 practitioner does not wait for NIST to publish. They build use-case profiles for material deployments now and update on the cross-walk as NIST profiles land.

The Profile-Building Methodology - Seven Steps

The methodology a practitioner applies when building a use-case profile or a sector profile:

  1. Define scope. Which AI systems are in scope? Which use cases? Which deployment contexts? Which user populations? Which jurisdictions? The scope statement is the boundary that determines applicability of every downstream decision.
  2. Map the AI RMF Core categories to the use-case context. Walk through the 19 categories and identify which Govern / Map / Measure / Manage categories apply most strongly. Not every category applies equally, Govern 3 (DEI in workforce) may matter more for a profile covering hiring AI; Measure 2.7 (red-team) may dominate a profile covering high-autonomy agentic deployments.
  3. Identify relevant existing profiles to incorporate. The GenAI Profile for generative components; the Critical Infrastructure Profile for critical-infrastructure deployments; the Agent Interoperability Profile (when published) for agentic deployments. A use-case profile inherits the guidance from applicable existing profiles, not duplicates it.
  4. Identify use-case-specific risks beyond the Core. The Core's categories are general. Add use-case-specific risks, disparate impact for HR-screening; grid-stability cascading failures for grid-load balancing; tool-misuse for agentic deployments. Use-case-specific risks may be drawn from sector frameworks (EEOC for employment, NERC CIP for power, OWASP Agentic Top 10 for agents).
  5. Document suggested actions per category. For each applicable category, document the suggested actions specific to the use case. Action format: action name; responsible party; frequency or trigger; evidence artifact; cross-walk citations to other frameworks where the action also satisfies obligations.
  6. Map to other frameworks. Build the cross-walk to EU AI Act articles, ISO 42001 controls, OWASP categories, MITRE ATLAS techniques, sector-specific frameworks. The cross-walk is the evidence-efficiency artifact, one action satisfies multiple framework windows.
  7. Publish, refresh, and refresh again. Publish the profile to the AI Governance Committee and the audit committee. Refresh quarterly. Refresh on trigger events. Integrate with the AI RMF gap heatmap and the L4 governance operating plan.

The output of the methodology is a use-case profile document, typically 5-15 pages, that translates the AI RMF Core into specific, actionable, evidence-producing guidance for the deployment in question. The document anchors operational governance work for the systems it covers and serves as the cross-walk artifact for audit and customer-assurance reviews.

Worked Example - HR-Screening Use-Case Profile

Scope: An EU multinational deploys an AI resume-ranker for high-volume sales-role hiring across operations in Ireland, Germany, France, the UK, and the U.S. (New York and California offices). The system ingests applicant resumes, ranks them on fit-for-role, and surfaces a shortlist to recruiters. Annex III §4 employment high-risk under the EU AI Act. NYC LL 144 automated employment decision tool. EEOC Title VII disparate-impact exposure. New York State AI hiring transparency. California SB 7 (when in force). The use-case profile covers this single deployment plus any future HR-screening systems in the portfolio.

Step 2 - Core category mapping. Govern 1 (policies including AI literacy under Article 4); Govern 3 (DEI in the recruiting and AI-development teams, directly relevant to hiring fairness); Govern 6 (third-party HR-tech vendor risk); Map 1 (context, the hiring pipeline, the candidate pool, the role-specific requirements); Map 2 (categorization, Annex III §4 employment high-risk, NYC LL 144 in scope, EEOC Title VII exposure); Map 5 (impacts on candidates, disparate impact, dignity, transparency); Measure 1 (metrics, selection rate, four-fifths-rule impact ratio, AUC, calibration); Measure 2 (fairness, accuracy, robustness); Measure 2.7 (red-team, adversarial resumes, prompt injection via resume, bias probing); Manage 1 (prioritization of identified bias and accuracy issues); Manage 4 (incident response, bias incident, accuracy incident, NYC LL 144 transparency-notice failure).

Step 3 - Incorporate existing profiles. The resume-ranker uses a fine-tuned LLM for resume scoring; the GenAI Profile applies (Risk 12 harmful bias and homogenization is directly relevant; Risk 4 data privacy applies to the candidate-data handling; Risk 11 value chain and component integration applies to the foundation-model dependency). The Critical Infrastructure Profile does not apply (HR-screening is not critical infrastructure under Annex III §2). The Agent Interoperability Profile does not apply (the resume-ranker is not an agent. It returns a ranked list, not autonomous actions).

Step 4. Use-case-specific risks beyond the Core. NYC LL 144 four-fifths-rule disparate-impact failure (regulator-published bias audit triggers enforcement); EEOC Title VII disparate-impact litigation exposure; New York State AI hiring transparency-notice failure; Article 27 FRIA inadequacy; Article 86 right-to-explanation request volume; candidate complaint to data-protection authority under GDPR Article 22 (automated individual decision-making); reputational risk from media coverage of a high-profile bias incident.

Step 5 - Suggested actions per category. Selected examples:

  • Govern 1 - AI literacy. Annual Article 4 AI literacy training for recruiters using the system; quarterly refresher; tracking via LMS; evidence artifact: training completion records.
  • Govern 6 - Vendor. SOC 2 + AI report from the HR-tech vendor; NYC LL 144 bias audit cooperation clause; Article 25 transfer analysis for any foundation-model fine-tune; ML-BoM under CycloneDX 1.7 CDXA; evidence artifact: vendor file with cited deliverables.
  • Map 5 - FRIA. Article 27 FRIA covering affected populations (candidates by protected class), impact severity, mitigation measures; published; refreshed annually plus on substantial modification; evidence artifact: signed FRIA.
  • Measure 1 - Metrics. Selection rate per protected class; four-fifths-rule impact ratio per protected class; AUC on a held-out evaluation set; calibration; evidence artifact: quarterly metrics dashboard.
  • Measure 2.7 - Red-team. Adversarial resume probes (synonyms, formatting variations, language patterns associated with protected classes); prompt injection via resume text; bias probing using a curated probe set; quarterly cadence; coverage by AI-VSS severity; evidence artifact: red-team report cross-walked to OWASP LLM Top 10 and EU AI Act Article 15.
  • Manage 4 - Incident response. Bias incident playbook (four-fifths-rule failure detected → suspend → investigate → mitigate → re-baseline → notify candidates if applicable); NYC LL 144 transparency-notice failure playbook; Article 73 reporting where the incident is a serious incident; evidence artifact: incident-response runbook.

Step 6 - Cross-walks. EU AI Act Annex III §4 (high-risk classification), Article 27 (FRIA), Article 86 (right to explanation), Article 15 (robustness), Article 73 (serious-incident reporting); NIST AI 600-1 Risk 12 (harmful bias); ISO 42001 A.7 (data governance), A.5 (impact assessment), A.10 (third-party); OWASP LLM Top 10 (LLM01 prompt injection, LLM09 misinformation); GDPR Article 22 (automated individual decision-making); NYC LL 144; New York State AI hiring transparency; California SB 7 (when in force); EEOC Title VII; UK Equality Act 2010.

Step 7 - Publish and refresh. Published to the AI Governance Committee; integrated with the AI RMF gap heatmap (rows for the in-scope categories, columns for the resume-ranker plus any future HR systems); quarterly refresh; trigger refresh on substantial modification, on regulator interpretive notes (NYC DCWP guidance on LL 144; New York DOL on AI hiring; EEOC AI guidance), on NIST profile updates affecting HR-relevant guidance. The profile document is the operational anchor: the recruiter onboarding references it, the vendor questionnaire responses cite it, the audit-committee briefing summarizes it.

Worked Example - Critical-Infrastructure Use-Case Profile Pre-Cursor

Scope: An EU energy company deploys an AI grid-load-balancing system for its transmission operations across Germany, France, and Ireland. The system ingests real-time load data, weather forecasts, generation availability, and market-clearing prices, and recommends load-shedding and generation-dispatch actions to grid operators. Annex III §2 critical-infrastructure high-risk under the EU AI Act. NIS 2 Directive in-scope (electricity sector essential entity). Sector-specific obligations under the EU Electricity Regulation and member-state grid codes. NERC CIP applies in the U.S. for any U.S.-operated assets (not relevant for this scope).

The Critical Infrastructure Profile is in concept-note phase (April 7, 2026); the full profile is expected 2026-2027. The practitioner cannot wait, operations continue, and the AI RMF gap heatmap requires a use-case profile now. The pre-cursor profile is built against the AI RMF Core, against the NIS 2 cybersecurity overlay, against EU AI Act Article 15 robustness obligations, and against published NERC CIP / sector best-practice references, and refreshed when NIST publishes the full Critical Infrastructure Profile.

Core category mapping with pre-cursor additions: Govern 1 (policies + NIS 2 cybersecurity policies + sector incident-response policies); Govern 6 (third-party vendor risk including the foundation-model provider for the optimization model + cloud infrastructure provider); Map 1 (context, the transmission system, the operator workflow, the regulatory regime); Map 2 (categorization, Annex III §2 critical infrastructure, NIS 2 essential entity); Map 4 (third-party components, foundation model, cloud, telemetry vendors, ML-BoM under CycloneDX 1.7 CDXA); Map 5 (impacts, cascading failure scenarios, blackout exposure, public-safety impacts); Measure 1 (metrics, accuracy, robustness under adversarial conditions, latency under stress, fail-safe behavior); Measure 2 (trustworthiness, robustness dominates; safety dominates; security and resilience dominates); Measure 2.7 (red-team, adversarial telemetry, model-extraction, prompt injection if the model has any natural-language interface, NIS 2-aligned cybersecurity testing); Measure 3 (continuous monitoring of drift, model performance, anomaly detection); Manage 1 (risk prioritization with safety-critical weighting); Manage 4 (incident response, Article 73 + NIS 2 24-hour early-warning + 72-hour incident notification + 1-month final report).

Pre-cursor profile additions specific to critical-infrastructure resilience: redundancy and failover requirements (always-available human-operator override; alternative dispatch path that does not depend on the AI); cybersecurity controls (NIS 2-aligned plus sector-specific NERC CIP-style controls where applicable); safety-case documentation (the system shall not recommend action X under condition Y; demonstrable fail-safe behavior); supply-chain attestation depth (foundation-model provider security posture, cloud provider security posture, telemetry-vendor security posture).

Cross-walks: EU AI Act Annex III §2, Article 15 (accuracy, robustness, cybersecurity), Article 27 (FRIA where applicable for affected populations), Article 73 (serious-incident reporting); NIS 2 Directive (Articles 21 cybersecurity measures, 23 incident reporting); NERC CIP (where U.S.-relevant); ISO 42001 A.5, A.7, A.8, A.10; OWASP LLM Top 10 (LLM01 prompt injection if natural-language interface, LLM10 model theft); MITRE ATLAS (relevant tactics for industrial-control AI); EU Electricity Regulation and grid codes.

The pre-cursor profile is refreshed when NIST publishes the full Critical Infrastructure Profile, anticipated late 2026 or 2027. The refresh integrates NIST's published guidance into the existing operational documentation, identifies any new suggested actions to add, and updates cross-walks. The pre-cursor work is not wasted, most of the operational documentation will transfer; the NIST profile becomes one more cross-walk citation.

Worked Example - Agentic Deployment Use-Case Profile Pre-Cursor

Scope: An EU multinational deploys the Acme.HelpdeskAgent v1.0 (from lesson 027) for internal IT-helpdesk operations across operations in Germany, France, Ireland, and the U.S. The agent receives natural-language requests from employees, queries a ticket system, queries an Active Directory, and can take a limited set of actions (password reset, software-license assignment, basic account-recovery flows). Autonomy Tier T2 (human-in-the-loop for any privileged action; autonomous for read-only operations). The use-case profile covers this agent plus any future agentic deployments in the IT-helpdesk class.

The Agent Interoperability Profile is planned for Q4 2026; the CAISI Agent Standards Initiative was launched Feb 17, 2026 and is expected to produce coordination output through 2026-2027. The pre-cursor profile is built against the AI RMF Core, against the OWASP Agentic Top 10 (ASI01-ASI10), against MITRE ATLAS agentic techniques, against the EU AI Act Article 14 human oversight obligations, and against Recital 110 systemic-risk taxonomy for agentic systems, and refreshed when NIST publishes the Agent Interoperability Profile.

Core category mapping with pre-cursor additions: Govern 1 (agent-specific policies on autonomy-tier governance, tool authorization, memory hygiene, identity); Govern 2 (accountability, agent owner, agent operator, agent risk owner, Chief AI Risk Officer ultimate accountability); Govern 6 (third-party, foundation-model provider, agent-orchestration vendor, tool-provider vendors, observability vendor); Map 1 (context, IT-helpdesk workflow, employee user population, action surface, tool inventory); Map 2 (categorization, internal-use agent, T2 autonomy, no high-risk Annex III classification but Article 50(1) interaction disclosure applies); Map 3 (capabilities, what the agent can and cannot do; out-of-scope actions named); Map 4 (third-party components, foundation model, orchestration framework, tools, memory store, observability); Map 5 (impacts, employee experience, security exposure if agent compromised, productivity impact); Measure 1 (metrics, task-completion rate, escalation rate, error rate, security-incident count, time-to-resolution); Measure 2.7 (red-team, OWASP Agentic Top 10 coverage, MITRE ATLAS agentic techniques coverage, autonomy-tier escalation testing, tool-misuse testing, memory-poisoning testing, identity-spoofing testing); Measure 3 (continuous monitoring of agent behavior, drift, tool-call volumes, escalation rates); Manage 1 (prioritization weighted by autonomy tier and action criticality); Manage 4 (incident response, agent rogue action (ASI10) playbook, memory-poisoning playbook, identity-spoofing playbook, tool-misuse playbook, Article 73 reporting where the incident is a serious incident).

Pre-cursor profile additions specific to autonomy-tier / tool-access / memory-hygiene controls: autonomy-tier policy (T0 read-only, T1 read-write low-impact, T2 read-write with human-in-the-loop for privileged actions, T3 fully autonomous: the helpdesk agent is T2); tool authorization gating (every tool call against an authorization policy, with logging and rate limits); memory hygiene policy (TTL on conversational memory, no PII in long-term memory, scrubbing on session end); identity policy (agent has a service-account identity with least-privilege scopes, distinct from any human user); observability requirements (every tool call logged with full input/output/decision, SIEM integration); kill-switch (operator can suspend the agent immediately on incident).

Cross-walks: EU AI Act Article 14 (human oversight, T2 autonomy with human-in-the-loop is the implementation), Article 50(1) (interaction disclosure, employees told they are interacting with an AI), Article 26(4) (deployer monitoring of agent behavior), Recital 110 (systemic-risk taxonomy for agentic systems where applicable), Article 73 (serious-incident reporting for rogue-action incidents); NIST AI RMF Core; OWASP Agentic Top 10 (ASI01-ASI10 with technique-by-technique coverage); MITRE ATLAS agentic-systems techniques; ISO 42001 A.5, A.7, A.8, A.10; CAISI Agent Standards (as they publish through 2026-2027); the planned Agent Interoperability Profile (refresh on publication).

The pre-cursor profile becomes the operational anchor for the helpdesk agent and for the next agentic deployments in the queue. When the Agent Interoperability Profile publishes in Q4 2026, the practitioner refreshes the use-case profile against NIST's guidance, identifies any new suggested actions, and updates the cross-walk to add the NIST profile citation alongside OWASP and MITRE ATLAS.

Multi-Profile Portfolio Operation

An enterprise with material AI deployments across multiple use-case classes operates multiple use-case profiles plus the Core plus any published NIST profiles that apply. The portfolio in the worked example so far: HR-screening profile (one profile covering the resume-ranker and any future HR systems); critical-infrastructure profile pre-cursor (one profile covering grid-load balancing and any future critical-infrastructure systems); agentic-deployment profile pre-cursor (one profile covering the helpdesk agent and any future agentic systems in the IT-helpdesk class). Plus the GenAI Profile (applies across all three use cases where generative components exist). Plus the AI RMF Core (always in play).

The multi-profile architecture: each profile inherits from the Core; profiles do not contradict each other but they emphasize different categories and suggested actions; the AI RMF gap heatmap aggregates status across all profiles (with profile-scoped columns); the L4 governance operating plan references the portfolio of profiles; the L5 board reporting summarizes profile maturity at the portfolio level.

When a new use case enters the portfolio, say, a customer-service chatbot, or a fraud-detection model in the financial services arm, or a clinical-decision-support model in the healthcare arm, the practitioner runs the seven-step methodology again. For some use cases, the existing profiles cover the deployment (a new HR-screening system fits the existing HR-screening profile). For others, a new profile is warranted (fraud-detection AI in financial services is its own use case with its own regulatory overlay: Federal Reserve SR 11-7, EU CRR/CRD, fair-lending obligations). The decision rule: a new profile is warranted when the use-case context has materially different regulatory exposure, materially different stakeholder population, materially different risk profile, or materially different operational guidance from existing profiles.

Profile Maintenance - Quarterly Cadence and Trigger Events

Profiles are living documents. The maintenance cadence:

  • Quarterly refresh. Each profile reviewed quarterly. Suggested actions still appropriate? Metrics still tracked? Cross-walks still current? Evidence artifacts still produced? Gap heatmap status updated? Remediation backlog burn-down on track?
  • Trigger refresh on regulatory developments. Omnibus VII (force majeure for general-purpose model providers); Commission interpretive notes; AI Office guidance; EDPB AI guidance; member-state national-authority guidance; sector-regulator AI guidance (EBA, ESMA, EIOPA, EEA for finance; EMA for healthcare; ENISA for cybersecurity).
  • Trigger refresh on NIST profile releases. Full Critical Infrastructure Profile (expected 2026-2027); Agent Interoperability Profile (Q4 2026); future profiles. On each release, refresh the affected use-case profile to integrate NIST's guidance and update cross-walks.
  • Trigger refresh on CAISI / AISIC / EU AI Office / UK AISI publications. CAISI Agent Standards Initiative deliverables; AISIC working-group outputs; EU AI Office Article 55 evaluation outputs; UK AISI evaluation outputs. Each may inform profile updates.
  • Trigger refresh on system changes. New foundation-model swap; new tool added to an agent; new use case added to a system; substantial modification under EU AI Act Article 43(4); change in autonomy tier.
  • Trigger refresh on incidents. Bias incident; security incident; near-miss; regulator inquiry. Incidents feed back into the profile through Manage 4 → Govern 1 cycle.
  • Trigger refresh on customer-assurance feedback. Vendor-questionnaire response gaps; customer audit findings; SOC 2 + AI report findings; ISO 42001 surveillance audit findings.

The profile refresh log itself becomes evidence: demonstrates active operation, supports audit-committee briefings, supports regulator inquiries on how the program adapts to developments.

Six Common Profile-Building Mistakes

Mistake 1 - Operating Against the Core Only

The AI RMF Core is general; the operational guidance lives in the profiles. A program that maps to the 19 categories without building any use-case profile has no operational anchor for the specific deployments it runs. The audit committee asks 'what does the HR-screening posture look like specifically?' and the answer is generic, 'we follow Map 5 and Measure 2.7.' That is not operational. Build the use-case profile.

Mistake 2 - Not Incorporating Existing NIST Profiles

The GenAI Profile applies to any generative-AI component. The Critical Infrastructure Profile (when finalized) applies to any critical-infrastructure deployment. The Agent Interoperability Profile (when published) applies to any agentic deployment. A use-case profile that ignores existing NIST profiles duplicates analysis NIST already did and risks contradicting NIST's published guidance, both unforced errors. Incorporate the existing profiles by reference and build on top.

Mistake 3 - Not Refreshing on Profile Updates

NIST publishes profile updates. CAISI publishes Agent Standards Initiative deliverables. AISIC publishes working-group outputs. EU AI Office publishes Article 55 evaluation results. UK AISI publishes evaluation results. A program that builds a profile once and never refreshes ends up with stale guidance. The trigger-refresh discipline is what keeps profiles operational.

Mistake 4 - Treating One Profile As Fitting All Use Cases

An HR-screening profile is not a fraud-detection profile is not a grid-load-balancing profile is not an agentic-helpdesk profile. Each has different regulatory exposure, different stakeholder populations, different risk profile, different operational guidance. A single 'enterprise AI profile' covering everything is too generic to be operational. Build separate use-case profiles per material deployment class.

Mistake 5 - Skipping the Cross-Walk to Non-NIST Frameworks

NIST AI RMF and its profiles are voluntary U.S. industry-consensus standards. EU AI Act is binding for EU-deployed systems. ISO 42001 is the certifiable management-system standard. OWASP and MITRE ATLAS are the operational red-team frameworks. Sector frameworks (NERC CIP, NIS 2, HIPAA, GLBA, EEOC, NYC LL 144) bring additional obligations. A profile that builds only against NIST and skips the cross-walks misses the evidence-efficiency benefit and risks producing artifacts that do not satisfy non-NIST obligations.

Mistake 6 - Treating the Profile as Static

Profiles refresh quarterly plus on trigger events. A static profile is a one-time deliverable that ages out and provides false assurance. The refresh discipline, quarterly plus triggers plus refresh-log evidence, is what makes a profile live operational guidance rather than a shelf document.

Key Takeaways

  • A NIST AI RMF profile is a sector-and-use-case overlay on the Core. The Core (four functions, 19 categories) is general; the profile translates it into operational guidance for a specific deployment context.
  • Published profiles to incorporate. NIST AI 600-1 GenAI Profile (July 2024, 12 risks, 200+ suggested actions); Critical Infrastructure Profile concept note (April 7, 2026, full profile 2026-2027); Agent Interoperability Profile (planned Q4 2026); CAISI Agent Standards Initiative (launched Feb 17, 2026).
  • Use-case profile methodology has seven steps. Define scope; map Core categories to context; incorporate existing profiles; identify use-case-specific risks; document suggested actions per category; cross-walk to other frameworks; publish and refresh.
  • Worked example, HR-screening profile. Annex III §4 employment high-risk; mapping across Govern 1/3/6, Map 1/2/5, Measure 1/2/2.7, Manage 1/4; additions for NYC LL 144 four-fifths-rule, EEOC Title VII, Article 27 FRIA, Article 86 right to explanation; cross-walks to GenAI Profile Risk 12, ISO 42001 A.7, OWASP LLM Top 10, GDPR Article 22.
  • Worked example, critical-infrastructure pre-cursor profile. Grid-load balancing under Annex III §2; mapping with anticipated Critical Infrastructure Profile + NIS 2 cybersecurity overlay + Article 15 robustness; additions for redundancy/failover, fail-safe behavior, supply-chain attestation depth; refresh on full profile release.
  • Worked example, agentic-deployment pre-cursor profile. IT-helpdesk agent at T2 autonomy; mapping with anticipated Agent Interoperability Profile + OWASP Agentic Top 10 + MITRE ATLAS + Article 14 human oversight; additions for autonomy-tier policy, tool authorization, memory hygiene, identity, observability, kill-switch; refresh on Agent Profile publication.
  • Multi-profile portfolio operation is the norm. Enterprise with material AI across HR + critical-infrastructure + agentic deployments runs three profiles plus the GenAI Profile plus the Core. AI RMF gap heatmap aggregates status across profiles.
  • Quarterly refresh plus trigger events. Quarterly cadence; refresh on regulatory developments, NIST profile releases, CAISI/AISIC/EU AI Office/UK AISI publications, system changes, incidents, customer-assurance feedback. Refresh log is evidence.
  • Six common mistakes. Operating against the Core only; not incorporating existing profiles; not refreshing on profile updates; treating one profile as fitting all use cases; skipping cross-walks to non-NIST frameworks; treating the profile as static.
  • Profiles are the operational anchor. Recruiter onboarding references the HR-screening profile; grid operators are trained against the critical-infrastructure profile; helpdesk-agent operators run the agentic profile. The profile is the live document, not a shelf deliverable.