The method · NIST AI RMF 1.0
The nine domains say where risk lives. NIST says how to govern it.
The framework maps the full territory of institutional AI — teaching, research, decisions about people, data and systems, vendors, and oversight. The NIST AI RMF supplies the repeatable practice applied inside each domain.
Its four functions are not a linear checklist. Govern is the culture that wraps everything; Map, Measure, and Manage run continuously across the AI lifecycle.
Why this matters
This is the practice your teams run for any AI use — the same four steps whether it's a chatbot or an admissions model. One method everyone follows is what makes oversight consistent instead of ad hoc.
How the four functions relate
Govern
The culture, policy & accountability that wraps and runs through the other three
↓
Map
Establish context & identify risk
→
Measure
Analyze, assess & monitor
→
Manage
Prioritize, respond & recover
↻Map · Measure · Manage run continuously across the AI lifecycle — not a one-time checklist
Govern
Cultivate a culture of AI risk management — the cross-cutting foundation
Policies, accountability structures, and review cycles that inform and run through Map, Measure, and Manage across the entire lifecycle. Here Govern is owned by Domain 9 and shared by every other domain.
Map
Establish context & identify risk
Categorize the AI system, its purpose, and who it affects. In practice: risk tiering, the system inventory, and impact assessments before deployment.
Measure
Analyze, assess & monitor
Assess risk with quantitative and qualitative methods. In practice: bias audits, explainability standards, validation, audit trails and logging.
Manage
Prioritize, respond & recover
Act on risk in proportion to impact. In practice: human-review pathways, appeals and redress, incident response, and vendor remediation.
How the Playbook works
New to NIST? For every outcome in the framework, the NIST AI RMF Playbook hands you four practical things — the same structure behind each domain's worked case study.
About
A plain-language explanation of the risk each outcome addresses.
Suggested actions
Concrete steps a team can take to reach the outcome.
Transparency & documentation
Questions to answer and record as evidence of your work.
References
Standards and sources to draw on for each action.
The bar each domain is measured against · 7 characteristics of trustworthy AI
Valid & reliable
Safe
Secure & resilient
Accountable & transparent
Explainable & interpretable
Privacy-enhanced
Fair — with harmful bias managed