Skip to main content
—
Framework library
Framework module · nist-ai-rmf-1-0

NIST AI Risk Management Framework

NIST's voluntary, cross-sector reference for governing AI risk, structured as Govern, Map, Measure, and Manage. NIST AI 600-1 is a companion profile for generative AI, not a replacement version or certification.

AI RMF 1.0 · NIST AI Risk Management Framework · published 2023-01-26

Standing today
Directory entry

00Answer

from the registry record
What is NIST AI Risk Management Framework?
NIST's voluntary, cross-sector reference for governing AI risk, structured as Govern, Map, Measure, and Manage. NIST AI 600-1 is a companion profile for generative AI, not a replacement version or certification.
Who does NIST AI Risk Management Framework apply to?
NIST AI Risk Management Framework applies to AI, technology, federal, US, global, per NIST AI Risk Management Framework.
What is the current version of NIST AI Risk Management Framework?
The current edition is AI RMF 1.0, issued by NIST AI Risk Management Framework and published 2023-01-26. Source: https://www.nist.gov/itl/ai-risk-management-framework.
What does an assessment under NIST AI Risk Management Framework require?
No control catalog has been ingested for NIST AI Risk Management Framework yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

NIST AI Risk Management Framework is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Named and tracked only; functions not ingested as a control catalog.

02Registry record

checked 2026-09-06
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Govern · Map · Measure · Manage
Applies to
AI · technology · federal · US · global
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-09-06
Pending change
NIST states that AI RMF 1.0 is being revised. The July 2025 White House 'America's AI Action Plan' directs NIST to revise the RMF to remove references to misinformation, Diversity, Equity, and Inclusion, and climate change — that directive, not an independent NIST initiative, is the revision's driver. NIST AI 600-1, the Generative AI Profile published 2024-07-26, remains a companion profile rather than a successor version.Expected: No successor publication date announced

03Version ledger

1 edition
AI RMF 1.0Current edition2023-01-26

04Authority intelligence

reviewed 2026-08-30

Curated primary-source signals connected to this registry record. An authority change creates review work; it does not silently change tenant posture, evidence credit, or prior decisions.

  1. Draft guidance

    NIST publishes draft guidance for using AI in CSF analysis.

    The initial public draft of SP 1353 illustrates AI-assisted CSF analysis, planning, implementation, and monitoring while calling for precautions and continuous evaluation and improvement.

    Operating move

    Version the prompt, approved source set, generated profile or report, evaluation result, and named reviewer disposition as one governed work record.

06Related frameworks

scored from registry facts
  1. EU AI ActRegulation (EU) 2024/1689

    Also applies to AI · The EU's risk-tiered regime for AI systems — prohibited practices, high-risk obligations, general-purpose model duties, and transparency requirements.

  2. AIUC-1Q3 2026 (2026-07-15 release)

    Also applies to AI · A quarterly updated standard and certification program for AI agents covering data and privacy, security, safety, reliability, accountability, and societal risk. Only AIUC can issue its certificate; registry inclusion makes no certification claim.

  3. Also applies to AI · The Cloud Security Alliance's vendor-neutral control framework for cloud-based AI systems, with implementation and auditing guidance plus the companion AI-CAIQ. It is a control catalog, not by itself a certification or STAR for AI designation.

  4. Also applies to AI · International guidance for integrating AI-specific risk management into organizations that develop, provide, deploy, or use AI systems. It complements ISO/IEC 42001 and is guidance, not a standalone certification.

NIST AI Risk Management Framework | ControlFrame