NIST AI RMF — AI Risk Management Framework

The US voluntary framework for governing AI risk, structured around Govern, Map, Measure and Manage. The practical counterpart to ISO 42001.

National Institute of Standards and Technology (NIST), United States Department of Commerce. Voluntary framework — not a certification scheme.

What it is

The NIST Artificial Intelligence Risk Management Framework is voluntary guidance published by the US National Institute of Standards and Technology for managing risks arising from AI systems. It is organised around four functions:

  • Govern — the accountability, culture and processes that make AI risk management work, and the function that underpins the other three.
  • Map — establishing context and identifying AI systems, their intended use and their risks.
  • Measure — analysing and tracking those risks, including ones that are genuinely hard to quantify.
  • Manage — prioritising and acting on them.

It is not certifiable. There is no NIST AI RMF certificate and no assessment scheme. Its value is as a structure for doing the risk work well.

How it relates to ISO 42001

The most useful way to hold these two: the RMF is the risk framework and ISO/IEC 42001 is the certifiable management system. They cover much of the same ground with different purposes. The RMF is often the more practical guide to actually doing AI risk assessment; 42001 is what produces something a buyer or regulator can be shown.

Organisations frequently use both — the RMF to structure the work, 42001 to certify the result.

Who it's for

Organisations developing or deploying AI

Particularly where decisions affect individuals and the governance questions are real rather than theoretical.

Companies with US market exposure

Where the RMF is a recognised reference point and US counterparties expect familiarity with its language.

Organisations preparing for ISO 42001

The RMF's risk methodology feeds directly into a 42001 management system, so it is a sound way to start the substantive work before committing to certification.

Organisations that need governance rather than a certificate

Where the objective is genuinely managing AI risk rather than demonstrating it to a third party.

Why implement it

  • It is practically written. The RMF is more usable as a guide to doing AI risk assessment than most management system standards, which describe what must exist rather than how to arrive at it.
  • Govern comes first, deliberately. Putting accountability before technique is the correct sequence and the one organisations most often invert.
  • It feeds ISO 42001 directly. Work done here is not wasted if certification becomes necessary; it becomes the substance of the management system.
  • It is credible with US counterparties, where NIST frameworks carry real weight in procurement conversations.
  • It is honest about hard problems. Bias, explainability and robustness are difficult to measure, and the framework says so rather than offering false precision.

How implementation works

1. Establish governance

The GOVERN function comes first and underpins the rest: who is accountable for AI risk, how decisions are made and escalated, and what the organisation's risk tolerance actually is.

2. Map the AI landscape

Context, intended use, and an inventory of AI systems in use or development — including models embedded in third-party products. This step consistently surfaces more than expected.

3. Measure

Analyse and track risks, including the ones that resist measurement: bias, explainability, robustness. The framework is honest that some of these are difficult, which is more useful than pretending otherwise.

4. Manage

Prioritise and treat risks, with human oversight designed into consequential decisions rather than asserted after the fact.

5. Monitor

AI risk changes as models, data and usage change. Point-in-time assessment ages faster here than in almost any other domain.

6. Map to a certifiable system if needed

Where a buyer or regulator wants evidence, the RMF work feeds directly into an ISO 42001 management system.

How Soveriq helps

Soveriq uses the AI RMF as the practical structure for AI risk work — governance, inventory, impact assessment, oversight design — and then maps it into ISO 42001 where a certificate is needed. Doing them in that order means the risk work drives the management system rather than the other way round.

For organisations operating across Australian and US markets, one AI governance programme can answer both, and we scope it that way.

Being direct about what this is. There is no NIST AI RMF certificate. The framework's value is in the quality of the risk work, not in a credential. If what you need is something to show a buyer, we will say so and point you at 42001 rather than selling you a framework adoption you cannot evidence externally.

What the engagement looks like

  • Module 01 — Gap analysis against the four functions, including the AI system inventory.
  • Module 02 — Build. AI governance structure, risk and impact assessment method, provenance and oversight controls, monitoring.
  • Module 05 — Continuous compliance, because AI risk changes faster than an annual cycle.

Modules 03 and 04 do not apply in the certification sense. Where the work supports ISO 42001 certification, those modules apply to that programme.

Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.

Common questions

Can we be certified against the NIST AI RMF?

No. It is voluntary guidance with no certification scheme. If you need a certificate a buyer or regulator will recognise, that is ISO 42001.

NIST AI RMF or ISO 42001?

Both, usually, and in that order. Use the RMF to structure the risk work because it is more practically written; use 42001 to certify the resulting system. They are complementary rather than competing, and organisations that treat them as alternatives generally end up doing the work twice.

Does it satisfy the EU AI Act?

No. The EU AI Act is legislation. The RMF is voluntary guidance. There is overlap in what they ask for, so RMF work is a reasonable foundation, but neither the RMF nor any certificate constitutes legal compliance.

Is it useful for an Australian organisation?

Yes. The governance questions are not jurisdiction-specific. Where it particularly helps is with US counterparties, where the RMF is a recognised reference point and speaking its language shortens the conversation.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope