What does the NIST AI RMF ask for, and where do you start?

The NIST AI RMF is the U.S. government's voluntary framework for managing AI risk. The four functions, what GOVERN 1.6 and 6.1 say about inventory and third parties, and a five-step path.

Updated September 20, 2026 · 9 min read

What the NIST AI RMF is, in a paragraph

The NIST AI Risk Management Framework (AI RMF 1.0, document NIST AI 100-1) is a voluntary framework from the U.S. National Institute of Standards and Technology, published in January 2023, that helps organisations manage the risks of AI systems. It is organised around four functions — GOVERN, MAP, MEASURE and MANAGE — and is deliberately not tied to a sector or a technology.

In July 2024 NIST added the Generative AI Profile (NIST AI 600-1), which applies the same structure to generative AI. It identifies 13 risks that are unique to or amplified by generative AI, with more than 400 suggested actions.

The framework is widely used as a shared vocabulary for AI risk, and it has a property that makes it a practical starting point: it asks you to know what AI you are running before it asks you to measure anything. For most companies, that is where the trouble begins — because a large part of the AI in use was never registered anywhere.

The four functions in plain language

The four functions are not a sequence to complete once. GOVERN runs across the whole framework; MAP, MEASURE and MANAGE repeat for each AI system. The right-hand column is our reading of where employee use of AI tools lands in each one — it is not NIST text.

FunctionWhat it asks of youWhere employee AI tools show up (our reading)
GOVERNBuild the culture, accountability, policies and processes that make AI risk management possible. It is cross-cutting: it informs the other three.Who owns AI decisions, what the AI usage policy says, and whether an inventory of AI systems exists.
MAPEstablish the context of each AI system: what it is for, who it affects and what could go wrong.For each tool found in use: what it is used for, by whom, and with which category of data.
MEASUREAssess, analyse and track AI risks with defined methods and metrics.How often each tool is used, its risk level, and the trend over time.
MANAGEPrioritise the risks and act on them, including response and recovery planning.What happens when a prohibited tool is detected: an owner, a deadline and a record.

Two lines that matter most for Shadow AI

Two subcategories of the GOVERN function speak directly to the problem of tools your employees adopted on their own. The wording below is quoted from the AI RMF Playbook.

GOVERN 1.6: “Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities.”

GOVERN 6.1: “Policies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third party’s intellectual property or other rights.”

Read literally, the first cannot be satisfied while employees use AI tools that no one has recorded: an inventory that only lists what procurement approved is not an inventory of AI systems in use. The second treats every external AI service as a third party — including the free chat assistant an employee opened in a browser tab, which has no contract, no assessment and no policy behind it.

Why the inventory comes first

Policies, measurements and incident plans all need an object to act on. Without an inventory, each of them is written about a picture of the company that is already out of date. IBM’s 2025 breach study shows what that gap looks like from the other side of an incident.

63%

of the organisations that suffered a breach said they had no AI governance policies in place to manage AI or to prevent workers from using shadow AI.

IBM Security, Cost of a Data Breach Report 2025

USD 670,000

is what a high level of shadow AI added to the average breach cost, in the same study. Unapproved AI use appeared in 20% of the breaches analysed.

IBM Security, Cost of a Data Breach Report 2025

A starting path, in five steps

This is our reading of how to apply the framework to employee AI use, not NIST text. The order matters: programmes that start with the policy instead of the inventory tend to rewrite the policy.

  • 1. Inventory (GOVERN 1.6). Find out which AI tools are in use, on which machines and how often — including the ones nobody approved. See how to build an AI-BOM.
  • 2. Map the context (MAP). For each tool: what it is used for, by which team, with what kind of data. This is what turns a list into something a risk decision can be made from.
  • 3. Set the policy (GOVERN). Each tool becomes allowed, restricted or prohibited, with the reasoning recorded and a signed AI usage policy behind it. See the annotated policy template.
  • 4. Measure (MEASURE). Track usage and risk over time, so improvement is something you can show and not just something you assert.
  • 5. Respond (MANAGE). A prohibited tool detected becomes a task with an owner and a deadline, not a line in a report.

Tangerin AI includes the NIST AI RMF among its 24 frameworks and tracks your progress against it, mapping the same evidence to related frameworks such as ISO/IEC 42001 and SOC 2. It tracks; it does not certify — and, as explained below, nobody can certify you against the AI RMF.

What the AI RMF is not

It is not a law: use is voluntary. It is not certifiable either. If you need a certificate an auditor can issue, ISO/IEC 42001 is the AI management-system standard that is audited and certifiable, and the two work well together: the AI RMF gives you a risk-management structure and vocabulary, and ISO 42001 gives you a management system you can be audited against.

It is also not a substitute for knowing your own environment. To see which AI tools your employees are actually using, the AI tool catalog is public and free to browse, and the free assessment shows in a few minutes how your governance compares.

Frequently asked questions

What is the NIST AI RMF?

The NIST AI Risk Management Framework (AI RMF 1.0, NIST AI 100-1) is a voluntary framework from the U.S. National Institute of Standards and Technology, published in January 2023, to help organisations manage the risks of AI systems. It is organised around four functions: GOVERN, MAP, MEASURE and MANAGE.

Is the NIST AI RMF mandatory?

No. It is a voluntary framework, not a law. Organisations adopt it as a shared vocabulary and structure for AI risk management, and customers or partners may ask about it in due diligence.

Is there a NIST AI RMF certification?

No. Unlike ISO/IEC 42001, which is audited and certifiable, the AI RMF is not a certifiable standard: NIST does not certify organisations against it. Be wary of anyone selling a “NIST AI RMF certification”. What you can do is document how your practices map to its functions.

What does GOVERN 1.6 require?

GOVERN 1.6 reads: “Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities.” In practice, it means knowing which AI systems are in use — which is impossible while employees use tools nobody has recorded.

Does the NIST AI RMF cover generative AI?

Yes. In July 2024 NIST published the Generative AI Profile (NIST AI 600-1), which applies the AI RMF structure to generative AI. It identifies 13 risks that are unique to or amplified by generative AI and more than 400 suggested actions.

Sources

Found it useful? Share it

LinkedInX

Instagram does not open links from outside the app — we copy it for you to paste in a story or bio.

Where does your company stand today?

The free assessment is 9 questions, 5 minutes and no signup. It returns your maturity level per dimension and a prioritised action plan — enough to know where to start without buying anything.