Glossary

NIST AI RMF

The NIST AI Risk Management Framework is voluntary guidance organised around Govern, Map, Measure and Manage. Govern is where most programmes are thin.

The NIST AI Risk Management Framework (AI RMF 1.0, published as NIST AI 100-1 in January 2023) is a voluntary framework for identifying, measuring and managing risk across the AI lifecycle. It is organised around four functions — Govern, Map, Measure and Manage — and is written to be adapted rather than certified against. NIST later published a Generative AI Profile (NIST AI 600-1) applying the framework to generative systems.

It has become procurement's common vocabulary. Because it is voluntary, sector-neutral and not a certification, it is the thing a security questionnaire can ask about without asserting a legal requirement — which is precisely why it appears in questionnaires so often.

Govern is where most programmes are thin. Map, Measure and Manage describe work that a capable team can do in a document. Govern asks who is accountable, what the policies are, and how they are enforced — and that answer is either a system or it is a claim. The framework does not say which tools to use, so the burden of proof falls on whatever the organisation can actually show.

How it differs from the EU AI Act. The AI RMF is voluntary guidance a firm chooses to adopt; the EU AI Act is binding law with classification tiers and obligations attached. They are frequently confused in procurement because both produce documentation. Only one of them carries penalties.

How it differs from model risk guidance. Model risk guidance is sector-specific supervisory expectation for regulated institutions. The AI RMF applies to anyone, and covers the lifecycle rather than the model.

AI agent governance guide

Ready to govern your AI infrastructure?

See how Smartflow gives regulated industries complete AI sovereignty.

Request a Demo View Documentation