AI Governance
NIST AI RMF
NIST AI Risk Management Framework 1.0
By Clear Infosec · Last reviewed: August 2026
The NIST AI Risk Management Framework (AI RMF) 1.0 is a voluntary framework for managing risks in the design, development, and use of AI systems, organized around four functions: Govern, Map, Measure, and Manage.
What is NIST AI RMF?
The AI RMF helps organizations improve the trustworthiness of AI systems, considering characteristics such as validity, safety, security, accountability, transparency, and fairness.
It is voluntary and technology-neutral, and it is often paired with governance standards such as ISO 42001.
Who does NIST AI RMF apply to?
Any organization designing, developing, deploying, or using AI systems that wants a structured way to identify and manage AI risk.
Key security expectations
- Govern: culture, policies, and accountability for AI risk.
- Map: context, purpose, and risk framing for AI systems.
- Measure: analyze and track AI risks and trustworthiness characteristics.
- Manage: prioritize and act on AI risks over the lifecycle.
How an assessment works
- 1 Establish AI governance and risk context (Govern, Map).
- 2 Assess and measure AI system risks (Measure).
- 3 Prioritize and treat risks (Manage).
- 4 Iterate as systems and threats evolve.
Typical evidence
Testing and NIST AI RMF: AI and LLM penetration testing supports the Measure and Manage functions by producing evidence of technical AI risks and their mitigation.
How Clear Infosec helps with NIST AI RMF
Related Clear Infosec services that support NIST AI RMF:
Vulnerability Assessment & Penetration Testing
Find and prove real risk before attackers do.
IT GRC, TPRM & Audit Preparation
Govern risk, vendors, and audits in one place.
vCISO / CISO-as-a-Service
Senior security leadership, on demand.
Risk Assessment & Compliance Readiness
Know your risk. Be audit-ready.
Frequently asked questions
Is the NIST AI RMF mandatory?
No. The AI RMF is a voluntary framework. Organizations adopt it to structure how they identify, measure, and manage AI risk.
How does the AI RMF relate to ISO 42001?
The AI RMF is a risk framework and ISO 42001 is a certifiable management-system standard. They are complementary and often used together.
This page is general information, not legal or regulatory advice. Requirements are defined by the authoritative body linked above.
Preparing for NIST AI RMF?
Talk to Clear Infosec about a readiness assessment, gap analysis, or testing aligned to NIST AI RMF.
Contact us