Back to Frameworks
Emerging

NIST AI RMF

The NIST AI Risk Management Framework (2023) gives organizations a structured, voluntary approach to identifying and managing risks specific to artificial intelligence systems.

It organizes activity into four functions — Govern, Map, Measure, Manage — covering everything from defining acceptable risk up front, to mapping context and use case, to measuring trustworthiness characteristics like fairness and reliability, to actively managing identified risks. Like NIST CSF, it is not a certification, but a shared structure that is rapidly becoming a reference point for AI governance programs and emerging AI regulation alike.

See how LumiGRC handles NIST AI RMF

Get a Demo
4

Govern, Map, Measure, Manage

0%
Typical certification profile
Audit Rigor48%
Time to Certify46%
Surveillance Burden51%
Issued & Enforced By

NIST

NIST AI Risk Management Framework (2023)

Key Points

  • Four functions: Govern, Map, Measure, Manage
  • Voluntary — a structure, not a certification
  • Addresses fairness, reliability, and trustworthiness of AI systems
  • A common reference point for AI governance programs