NIST AI Risk Management Framework (AI RMF 1.0)
The NIST AI Risk Management Framework is a voluntary resource published by the U.S. National Institute of Standards and Technology to help organizations that design, develop, deploy, or use AI systems manage the many risks those systems can create. It is intended to help organizations build trustworthiness considerations into AI throughout its lifecycle. Because it is voluntary guidance rather than a law, it sets out practices to adopt rather than requirements that must be met.
The AI RMF 1.0 (published by NIST in 2023, document NIST AI 100-1) is a voluntary framework intended to improve organizations' ability to incorporate trustworthiness considerations into the design, development, deployment, and use of AI systems, and to help manage AI-related risks across the AI lifecycle. NIST states it is intended for voluntary use; as commonly understood, it is guidance rather than binding regulation, and its applicability and enforceability differ from that of a legal instrument. The framework uses a version-numbering system to track major and minor changes. This definition is scoped to the material in the evidence provided and does not detail the framework's internal core functions or profiles, which are not described in the cited sources.
Why it matters
The AI RMF matters because it offers organizations that design, develop, deploy, or use AI systems a structured, publicly available resource for managing the many risks AI can create, at a time when comprehensive binding AI regulation remains uneven across jurisdictions. As a NIST publication intended for voluntary use, it gives practitioners a common reference point and shared vocabulary for incorporating trustworthiness considerations into AI, which can support internal governance efforts even where no specific law compels a particular practice.
Who it's relevant to
Inside AI RMF
Common questions
Answers to the questions practitioners most commonly ask about AI RMF.