It speaks to the board
The Govern Function turns AI risk into a business-risk conversation leadership can actually own — culture, policy, roles and accountability, not just model metrics. It makes AI oversight legible to non-technical stakeholders.
The outcome-based baseline for managing AI risk.
The NIST AI Risk Management Framework 1.0 is a voluntary, outcome-based framework from the US National Institute of Standards and Technology (NIST AI 100-1, 2023). It organises AI risk management around four Functions — Govern, Map, Measure and Manage — broken into 19 Categories and 72 Subcategory outcomes, and helps any organisation build, deploy and use AI systems that are trustworthy across seven characteristics.
The standard
NIST AI Risk Management Framework 1.0 (NIST AI 100-1)
Who needs it
Any organisation that designs, develops, deploys, procures or uses AI systems and wants a common, board-readable way to understand and manage the risks — US companies whose customers or federal programmes reference NIST, and any team that wants a flexible framework to govern AI responsibly without committing to a formal certification.
72
Subcategory outcomes
The basics
The NIST AI RMF is not a checklist of technologies or a certification you pass. It is a taxonomy of outcomes for identifying, assessing and managing the risks of AI systems throughout their lifecycle — from design and development to deployment and decommissioning. It is designed to be rights-preserving and adaptable to any organisation, sector or AI use case, and it centres seven characteristics of trustworthy AI: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed.
You work the framework through its four Functions. Govern cultivates a culture of risk management and sets the policies, roles and accountability that steer everything else. Map establishes the context and frames the risks of a given AI system. Measure analyses, assesses and tracks those risks with quantitative and qualitative methods. Manage prioritises and acts on them. Because the Subcategories are outcomes rather than prescriptions, the framework crosswalks cleanly to ISO/IEC 42001:2023 and other standards you may already run, and the accompanying Generative AI Profile extends it to the specific risks of foundation models.
Why it matters
The Govern Function turns AI risk into a business-risk conversation leadership can actually own — culture, policy, roles and accountability, not just model metrics. It makes AI oversight legible to non-technical stakeholders.
The AI RMF is the reference point US buyers, insurers and regulators reach for when they ask how you manage AI risk. Being able to express your posture in its Functions and trustworthy-AI characteristics shortcuts a lot of AI-assurance back-and-forth.
It's a mapping, not a rebuild. The 72 outcomes crosswalk to ISO/IEC 42001:2023 and other frameworks, so the AI governance evidence you already collect can be pointed straight at the RMF.
Govern, Map, Measure and Manage — the top-level outcomes that organise the whole framework, with Govern cross-cutting the other three.
19 Categories break the Functions down into 72 Subcategory outcomes — the concrete, mappable statements of what good AI risk management looks like.
Seven characteristics — valid and reliable, safe, secure and resilient, accountable and transparent, explainable, privacy-enhanced, and fair — define what a trustworthy AI system looks like.
Use-case and cross-sectoral Profiles tailor the framework to your context, and the Generative AI Profile extends it to the specific risks of foundation models.
Done by hand, the AI RMF becomes a giant spreadsheet: 72 Subcategories assessed for each AI system, each cross-referenced to your real controls, models and evidence, then re-scored as models and use cases change. Keeping that mapping current across a growing fleet of AI systems — and turning it into a plan leadership can read — is exactly the repetitive work software should carry.
Do it once, reuse it everywhere. Evidence you collect for NIST AI RMF is automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.
See exactly how Compliance One maps NIST AI RMF to your environment in a 30-minute walkthrough — and how much of it we handle for you.