The NIST AI Risk Management Framework (AI RMF 1.0), published by the US standards institute, is voluntary and not certifiable — unlike ISO 42001, which is. Its value isn't in a seal of approval, but in offering a common vocabulary and an operational process for managing AI risk that can run alongside the AI Act's legal obligations, without reinventing processes from scratch.
The framework's 4 functions
1. Govern
The cross-cutting function: organizational culture, policies, roles and responsibilities around AI. This is where you decide who's responsible for what — the same ground covered by a solid Data Governance RACI. Govern isn't a one-off step; it's the foundation the other three functions stand on.
2. Map
Consists of identifying context: what AI systems the organization has, what they're used for, who uses them, and what impact they could have if they fail. It's conceptually the same exercise the AI Act requires to classify systems as high-risk — if you've already done that inventory, most of the Map work is done.
3. Measure
Here, identified risks are evaluated with concrete metrics: accuracy, bias, robustness, explainability. It connects directly to everything we cover in data quality management — without measured data quality, there's no reliable way to measure the risk of the system consuming that data.
4. Manage
The action function: prioritizing risks, allocating resources, mitigating and documenting. This is where the framework turns into real decisions — which system gets paused, which gets fixed, which gets deployed anyway with additional controls.
NIST AI RMF vs the AI Act: do you have to choose?
No. The AI Act is a legal obligation in the EU; the NIST AI RMF is a voluntary risk management framework. Many European organizations with a US presence use the NIST AI RMF as an internal operational layer and the AI Act as the set of legal minimum requirements that layer must satisfy. In practice, the Govern and Map work of the NIST AI RMF overlaps heavily with the data governance already required by AI Act Art. 10.
Common mistakes when adopting it
- Treating it as a checklist instead of a continuous process — the 4 functions repeat in cycles, they aren't completed once.
- Starting with Measure without having done Map: measuring the risk of systems that aren't even inventoried.
- Confusing it with a certification: there's no such thing as "NIST AI RMF certification" — anyone selling that is selling smoke.
If you're deciding between investing time in the NIST AI RMF or ISO 42001, the full comparison is in ISO 42001 vs NIST AI RMF: how to choose your framework.