Governance

What NIST’s AI RMF actually asks of you

← All InsightsBy Dr. Derek A. Smith6 min read

The NIST AI Risk Management Framework is the most cited document in AI governance and one of the most misread. Leaders treat “Govern, Map, Measure, Manage” as a compliance checklist to pass. It is not a checklist. It is an operating structure — and once you translate it out of framework language, each function points to concrete work you can start this quarter.

NIST released the AI RMF (AI 100-1) in January 2023, followed by a Generative AI Profile (AI 600-1) in July 2024. It is voluntary. But it has become the common language that regulators, customers, and boards expect you to speak — which makes adopting it a business decision as much as a security one.

The four functions, in plain terms

Govern — build the accountability first

Govern is the foundation the other three rest on. It asks: who owns AI risk here, what is your policy, and how do decisions get made? Practical first moves: name an accountable AI risk owner, stand up a lightweight AI policy, and start an inventory. Culture and structure before tooling.

Map — know what you actually have

Map is context. What AI systems are in use or in development, what is each one for, what data feeds it, and who could be affected if it fails? Most organizations cannot answer these, because AI arrived through a dozen doors at once. You cannot govern what you have not mapped, so an AI use-case inventory is the highest-leverage thing you can build.

Measure — assess before you trust

Measure is testing and metrics: accuracy, bias, security, robustness, and drift. It includes red-teaming generative systems and tracking how risks change over time. The point is to replace “the vendor says it works” with evidence you can show.

Manage — prioritize and act

Manage is where risk decisions get made: what to mitigate, what to monitor, what to accept, and what to stop. It closes the loop with response plans and clear go / no-go authority for putting AI into production.

The framework’s power isn’t the four words. It’s that they force the questions most organizations are avoiding.
A defensible first 90 days
  • Govern: name an AI risk owner and publish a one-page AI policy.
  • Map: build an AI use-case inventory with purpose, data, and impact.
  • Measure: pick your highest-impact system and test it properly.
  • Manage: stand up a simple intake and go / no-go decision point.

One caveat worth knowing: the 2025 OMB memos stepped back from explicitly mandating NIST for federal agencies. That does not lower the bar — the RMF remains the lingua franca everyone still measures you against. Adopt it because it is the language your regulators, customers, and board already speak.

Dr. Derek A. Smith is founder of DAS Advisory Group and author of The Defensible AI Program. He advises federal agencies and enterprises on governing and securing AI.

Want this applied to your organization?

A 30-minute conversation on where you are and what governing your AI actually takes.

Book a Consultation

Get new briefs in your inbox

Practical AI governance and security notes, sent when there's something worth reading. No spam.