Skip to main content

AI GOVERNANCE

What Is NIST AI RMF?

DEFINITION

The NIST AI RMF is a voluntary framework from the U.S. National Institute of Standards and Technology for identifying, measuring, and managing risks from artificial intelligence systems. It organizes AI governance into four functions, Govern, Map, Measure, and Manage, and has become the de facto baseline for AI risk management programs in the United States.

The NIST AI Risk Management Framework, published by the U.S. National Institute of Standards and Technology in January 2023, is a voluntary framework for managing risk across the AI lifecycle. It defines four functions: Govern establishes policies, accountability, and culture; Map places AI systems in context and identifies their risks; Measure assesses and tracks those risks; and Manage prioritizes and responds to them. A companion Generative AI Profile addresses risks specific to generative models.

The framework applies to any organization that develops, procures, or deploys AI. In the absence of comprehensive federal AI regulation, it has become the default reference point for U.S. enterprise AI governance programs, customer due diligence questionnaires, and state legislation.

Its practical weight now extends beyond voluntary adoption. The Texas Responsible Artificial Intelligence Governance Act (TRAIGA), in force since January 1, 2026, gives documented compliance with the NIST AI RMF statutory safe-harbor value, which turns a voluntary framework into concrete legal protection. Mid-market companies can operationalize the framework through an AI governance assessment that maps actual AI use against its functions, supported by AI security services for the controls that follow.

Running a program that has to satisfy this?

A Z Cyber advisor can walk your current posture against the requirement and show you what a running program looks like on Glance.

Meet Your Security Team →