The NIST AI Risk Management Framework (AI RMF) is the U.S. framework for managing the risks of designing, developing, deploying, and using AI systems. Released by the National Institute of Standards and Technology in January 2023, it is voluntary, technology-neutral, and built to work for organizations of any size.
NIST has since added a Generative AI Profile (NIST AI 600-1) and is revising the framework under the White House AI Action Plan. It is not a certification: organizations align to it and demonstrate that alignment through documentation and independent assessment.
Why it matters
The framework U.S. buyers and regulators point to
Customer trust
Answer AI risk questions with a recognized framework Customers and partners increasingly ask how you manage AI risk. Mapping your program to the AI RMF gives them an answer they recognize.
A common language
Get leadership and engineering on the same page The AI RMF gives your board, legal, product, and engineering teams shared terms for AI risk and who owns it.
Regulatory readiness
Prepare for AI rules built on the same ideas Federal guidance and several state AI laws point to the AI RMF as a recognized framework, so aligning now prepares you for what comes next.
Path to certification
Build a foundation for ISO 42001 An AI RMF-aligned program covers much of the groundwork for ISO 42001 if your customers later ask for a certificate.
Inside the framework
Four functions. Seven traits of trustworthy AI
The AI RMF defines trustworthy AI as valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair, with harmful bias managed. Its four functions are how you get there.
Govern
Culture and accountability
Policies, roles, and oversight that make AI risk management part of how the organization works. It applies across the other three.
Map
Context and risk
Understand each AI system: its purpose, users, data, and the ways it could cause harm or fail.
Measure
Testing and tracking
Analyze, test, and monitor AI risks and trustworthiness with methods and metrics suited to each system.
Manage
Prioritize and respond
Treat the risks that matter most, respond to incidents, and keep improving as systems and threats change.
NIST AI RMF and ISO 42001
NIST AI RMF or ISO 42001: which do you need?
They work well together. The AI RMF tells you how to think about and manage AI risk; ISO 42001 gives you a certifiable management system to prove it.
Area
NIST AI RMF
ISO 42001
Type
Voluntary risk management framework
Certifiable management system standard
Published by
NIST, a U.S. federal agency
ISO and IEC, international standards bodies
Structure
Four functions: Govern, Map, Measure, Manage
Management system clauses plus 38 Annex A controls
Generative AI
Dedicated Generative AI Profile (NIST AI 600-1)
Covered through AI risk and impact assessments
How you prove it
Documented alignment and independent assessment
Certificate from an accredited certification body
Best fit for
Building a flexible, U.S.-recognized AI risk program
Giving customers certifiable proof of AI governance
Our AI RMF approach
Cybersecurity at our core. Compliance built on it
Compliance should validate good cybersecurity, not substitute for it.
InfoGuard brings 30+ years of cybersecurity leadership and deep experience with NIST frameworks to AI risk, so your program reflects how AI systems are actually built, attacked, and used.
AI security expertise
Risk management that covers how AI actually fails We address model, data, and pipeline risks such as poisoning, prompt injection, and data leakage alongside governance.
NIST framework depth
Practitioners who know NIST frameworks inside out Years of work with NIST SP 800-53, SP 800-171, and the Cybersecurity Framework mean we apply the AI RMF the way NIST intended.
Hands-on senior leadership
Senior experts on your engagement, start to finish Senior practitioners work alongside your product, data, and engineering teams, not a junior analyst running a checklist.
One effort, multiple frameworks
Do the work once, reuse it for ISO 42001 and more We build one program that maps to the AI RMF, ISO 42001, ISO 27001, and the 2026 SOC 2 AI requirements, sharing policies and evidence.
Your compliance investment should deliver more than checklists and documentation. It should improve your cybersecurity as well.
How we help
From AI inventory to an independent assessment, and beyond
01
AI Inventory & Context
We identify the AI systems you build, buy, or use, along with their purpose, data, users, and potential impacts.
02
Gap Assessment
We assess your current practices against the AI RMF functions and, where relevant, the Generative AI Profile, and document your current profile.
03
Target Profile & Roadmap
We define the target profile that fits your risk tolerance and business goals, with a prioritized roadmap to reach it.
04
Governance & Controls
We put in place the AI policy, roles, oversight, and technical safeguards your roadmap calls for, written to match how your teams work.
05
Measure & Test
We help you define metrics and testing for reliability, security, privacy, and bias, so AI risks are tracked rather than assumed.
06
Assess & Sustain
An independent assessment documents your alignment for customers and leadership, and ongoing reviews keep it current as systems change.
FAQ
NIST AI RMF questions, answered
The framework
Is the NIST AI RMF mandatory?
No. The AI RMF is voluntary. Its value comes from customers, partners, and regulators recognizing it as a sound way to manage AI risk, and from federal guidance and state laws that point to it.
Can we get certified to the NIST AI RMF?
No. There is no official AI RMF certification. You demonstrate alignment through documentation and an independent assessment. If customers need a certificate, ISO 42001 is the certifiable standard and builds on the same groundwork.
NIST is revising the AI RMF. Should we wait?
No. The core approach of governing, mapping, measuring, and managing AI risk is not going away, and the work you do now carries forward. We track the revision and update your program when it is published.
What is the Generative AI Profile?
NIST AI 600-1, published in July 2024, applies the AI RMF to risks specific to generative AI, such as confabulation, data privacy, information security, and harmful content, with suggested actions for each.
Scope, timing, and cost
Does it apply if we only use third-party AI tools?
Yes. The AI RMF covers AI you use as well as AI you build, including third-party models and AI features inside the software you buy.
Should we do the AI RMF, ISO 42001, or both?
Many organizations start with the AI RMF to build a flexible program, then pursue ISO 42001 when customers ask for a certificate. We plan the work once so it serves both.
How long does AI RMF alignment take?
It depends on how many AI systems are in scope and how mature your governance is today. Most organizations can reach a documented current and target profile in weeks, with implementation over the following months.
How much does it cost?
Cost depends on the number of AI systems, their risk, and how much needs to be built. There is no flat fee. We provide a firm quote after an initial gap assessment.
Cybersecurity first
A checkbox compliance provider won't cut it
You need real cybersecurity expertise to manage AI systems that can be attacked, misused, or fail in new ways, not just a policy that says you do.
Next step
Tell us where you stand
Tell us how you build or use AI. We’ll reply with next steps, whether that’s an AI inventory, an AI RMF gap assessment, or a plan that covers ISO 42001 as well.