The NIST AI Risk Management Framework (AI RMF 1.0), published by the US standards institute, is voluntary and not certifiable — unlike ISO 42001, which is. Its value isn't in a seal of approval, but in offering a common vocabulary and an operational process for managing AI risk that can run alongside the AI Act's legal obligations, without reinventing processes from scratch.

The framework's 4 functions

1. Govern

The cross-cutting function: organizational culture, policies, roles and responsibilities around AI. This is where you decide who's responsible for what — the same ground covered by a solid Data Governance RACI. Govern isn't a one-off step; it's the foundation the other three functions stand on.

2. Map

Consists of identifying context: what AI systems the organization has, what they're used for, who uses them, and what impact they could have if they fail. It's conceptually the same exercise the AI Act requires to classify systems as high-risk — if you've already done that inventory, most of the Map work is done.

3. Measure

Here, identified risks are evaluated with concrete metrics: accuracy, bias, robustness, explainability. It connects directly to everything we cover in data quality management — without measured data quality, there's no reliable way to measure the risk of the system consuming that data.

4. Manage

The action function: prioritizing risks, allocating resources, mitigating and documenting. This is where the framework turns into real decisions — which system gets paused, which gets fixed, which gets deployed anyway with additional controls.

NIST AI RMF vs the AI Act: do you have to choose?

No. The AI Act is a legal obligation in the EU; the NIST AI RMF is a voluntary risk management framework. Many European organizations with a US presence use the NIST AI RMF as an internal operational layer and the AI Act as the set of legal minimum requirements that layer must satisfy. In practice, the Govern and Map work of the NIST AI RMF overlaps heavily with the data governance already required by AI Act Art. 10.

Where to start if you have nothing in place: don't try to implement all 4 functions at once. Start with Govern (clear roles) and Map (system inventory) — without those, Measure and Manage have nothing to operate on.
Data Governance RACI Matrix Covers exactly the Govern function of the NIST AI RMF: clear roles and responsibilities per data domain. Aligned with AI Act Art. 10. €49 VAT incl.
Buy →

Common mistakes when adopting it

  • Treating it as a checklist instead of a continuous process — the 4 functions repeat in cycles, they aren't completed once.
  • Starting with Measure without having done Map: measuring the risk of systems that aren't even inventoried.
  • Confusing it with a certification: there's no such thing as "NIST AI RMF certification" — anyone selling that is selling smoke.

If you're deciding between investing time in the NIST AI RMF or ISO 42001, the full comparison is in ISO 42001 vs NIST AI RMF: how to choose your framework.