All resources
Playbook 7 min read

The 72 AI RMF Subcategories, without the overwhelm

C1The Compliance One team23 September 2026

The first time someone opens the NIST AI RMF Core and sees 72 Subcategories, the instinct is to close the tab. Do not. The 72 are not 72 unrelated tasks, they are outcomes clustered into 19 Categories under four Functions, and once you see the shape you can work them in a sensible order rather than all at once.

How the 72 break down

  • Govern (roughly a third of the outcomes): the standing work — policies, roles, accountability, risk tolerance, third-party and workforce considerations. You do this once for the organisation, not per system.
  • Map: framing a specific AI system — its context, purpose, categorisation, risks and impacts on people. This is where each new system starts.
  • Measure: the methods and metrics — assessing the system against the trustworthy-AI characteristics and tracking the results over time.
  • Manage: the decisions and actions — prioritising risks, responding, recovering and communicating.

Do Govern once, then run Map, Measure and Manage per AI system. That single mental model turns 72 outcomes from a wall into a workflow.

Work it one system at a time

You do not assess all 72 outcomes for your whole AI estate in one sitting. You stand up the Govern outcomes as your organisational baseline, then, for each AI system you build or buy, you run it through Map, Measure and Manage. A low-risk internal tool and a customer-facing generative model get very different levels of scrutiny, and the framework is built to flex that way.

In Compliance One the full 72-outcome library ships ready to use, so you assess each system against the same structured set, reuse the Govern baseline across all of them, and cross-map every outcome to your ISO 42001 controls. The 72 stop being a spreadsheet you dread and become a checklist you actually finish.

See it on your own frameworks

Book a 30-minute walkthrough and we'll map this to your environment.