NIST AI RMF starter profile
Nobody makes you adopt it and nobody certifies you against it. Your customers, your insurer and your enterprise procurement team will still ask you questions in its vocabulary.
“Most companies answer an AI governance question by writing a policy. The framework asks a harder question first, which is what you are actually running. Almost nobody can answer it, because the AI arrived inside software they had already bought.”
Tejas Dhabalia, Co-founder, DS Consulting
What you get
NIST calls a tailored application of the framework a Profile. This workbook is a starter profile. It turns the four functions into outcomes you can rate, own and evidence, without needing a risk function to run it.
The four functions broken into statements about your business rather than about AI in general. Seven on Govern, seven on Map, six on Measure, six on Manage.
Zero to three, with the steps defined. The gap between one and two is documentation. The gap between two and three is rhythm and evidence.
A rating with no owner is not operating and a rating with no evidence is an opinion. The summary counts both and tells you where they are missing.
Each function set against the EU AI Act, ISO/IEC 42001 and the DPDP Act, so you can see which document carries an actual obligation.
Right for you if
A customer, an insurer or an enterprise procurement team has sent you an AI questionnaire written in this vocabulary.
You have an AI policy and no way of telling whether anything changed on the ground after it was signed.
Somebody has offered to certify you against the NIST AI RMF and you want to know whether that is a real thing.
You are choosing between NIST AI RMF and ISO/IEC 42001 and nobody has explained why they are not alternatives.
What the framework is, and what it is not
Four things are worth knowing before you spend a day on it, and three of them are usually got wrong in the summaries.
Voluntary, and that is the design rather than a weakness.
NIST published AI RMF 1.0 in January 2023 under the National AI Initiative Act of 2020. It is voluntary, rights preserving, not sector specific and not tied to a use case. It describes outcomes to aim at rather than duties to discharge, which is why it travels across jurisdictions that have nothing else in common.
Nobody certifies you against it.
There is no NIST audit and no NIST certificate. Anyone offering to certify you against the AI RMF is selling ISO/IEC 42001 under another name, or selling nothing. Self attestation is the only status available, which is exactly why the evidence behind your claims matters.
It is two documents, and the useful half is the second one.
The framework itself is around forty pages of principle. The companion Playbook carries the suggested actions and documentation practices for each subcategory. Teams that read only the framework come away thinking it is too abstract to act on, which is a reading problem rather than a framework problem.
Version 1.0 is still current, and it is being revised.
NIST has stated that AI RMF 1.0 is under revision following the White House AI Action Plan of July 2025, and that the Playbook will be updated once the revision lands. There is no 2.0. The four functions have been stable since 2023 and are the part least likely to move, so build on those rather than on particular wording.
The four functions in plain terms
Govern runs across everything. Map, Measure and Manage apply to a specific system at a specific point in its life.
Govern: who answers for this.
Accountability, policy, risk tolerance, staff capability and the rules that cover third party AI. The test is not whether a policy exists. It is whether one named person answers for AI risk, and whether a member of staff who thinks an output is wrong has somewhere to take it that is not the person who deployed it.
Map: what are we actually running.
Context. What each use is for, who it affects including people who are not customers, and what a wrong output costs in business terms. This is the function almost nobody has completed, and everything downstream depends on it.
Measure: would we know if it stopped working.
Testing and monitoring on a stated rhythm, checked across the groups the system affects rather than only in aggregate. The uncomfortable version of the question is whether you would notice if your vendor changed the model underneath you, because they will and they will not ask.
Manage: what happens when it goes wrong.
Prioritising by consequence, a tested fallback, human review that is real, an incident path with a named owner, and risk acceptance that is written down. Manage is where a policy either becomes visible in how the business runs or stays a document.
Where mid-market companies come unstuck
These four patterns account for most of what we see. None of them is a failure of intent.
The policy arrives before the inventory.
A two page AI policy is quick to write and impossible to apply, because nobody has the list of systems it is meant to govern. Govern scores well, Map scores nothing, and the business runs exactly as it did before.
AI arrived through procurement rather than through technology.
The ERP shipped a copilot. The CRM added scoring. The marketing tool started generating copy. None of it went through an approval, so none of it is on a list. Expense reports and card statements usually find more of it than the asset register does.
Human oversight is recorded but is not real.
A reviewer with forty cases an hour, no context and no practical authority to overrule is providing a signature rather than a control. This is the row that fails first when a customer starts asking follow up questions.
Measurement stopped at go live.
The system was tested once, in the fortnight before launch, against data from before launch. Two model updates later nobody has looked again, and the first signal that quality moved is a complaint.
What proportionate looks like
The framework is written to be applied in varying degrees. A company of 300 people is not expected to build what a bank builds.
You do not need a model risk committee.
At two hundred to two thousand people the whole governance function is usually one accountable person, a maintained register, a quarterly review and a short list of uses that need sign off before output leaves the building. That is a legitimate answer and the framework supports it.
Depth should follow consequence.
A spam filter and a credit decisioning model do not deserve the same scrutiny. Rank the uses by what a wrong output costs, then spend the effort at the top of that list and accept a light touch at the bottom.
Start where you are weakest and most exposed.
Those are often two different functions. A low Map score usually matters more than a low Measure score, because measuring an estate you have not listed is not possible.
Write down what you have decided not to do.
Accepted risk is a legitimate position and the framework treats it as one. Unrecorded accepted risk turns into an argument about what everyone thought had been agreed, usually at the worst moment.
Why this matters
The commercial reason arrives before the regulatory one. Customer questionnaires, insurance renewals and enterprise procurement reviews have all started asking where AI touches a supplier's process, and a growing number of them borrow this vocabulary because it is the one available. A company that can answer in a week looks different from one that needs a month.
The framework is also the most portable thing in this space. The EU AI Act applies where it applies. The DPDP Act governs personal data. ISO/IEC 42001 costs money and takes an auditor. The four functions cost nothing, apply anywhere and give you a structure that still makes sense when the law you are subject to changes.
That is worth holding on to while NIST revises the framework. The wording will move. The questions of who answers for this, what are we running, would we know if it broke and what happens when it does are the same questions in every version, and they are the same questions your customers are asking.
Turning a completed profile into a working control set, with named owners, a review rhythm and a route into procurement, is AI governance and adoption work.
Frequently asked questions
Is the NIST AI RMF mandatory for us?
No. It is voluntary, it is issued by a United States agency, and no regulator anywhere requires it of a private company. It reaches most organisations commercially rather than legally, through customer questionnaires, insurance renewals and procurement reviews that borrow its vocabulary because there is no widely used alternative.
Is there a NIST AI RMF 2.0?
Not as at September 2026. AI RMF 1.0 from January 2023 is still the core framework, and NIST has said a revision is in progress. What confuses a search is that NIST extends the framework through Profiles rather than version numbers. The Generative AI Profile, NIST AI 600-1 from July 2024, is the document people usually mean when they ask about a newer version.
Should we do NIST AI RMF or ISO/IEC 42001?
They do different jobs. The AI RMF gives you a risk taxonomy and a shared vocabulary, costs nothing and produces no certificate. ISO/IEC 42001 is a certifiable management system standard, which is what you need when a customer wants proof rather than a statement. Organisations that have to demonstrate something to a third party usually end up with both, using NIST to work out what to do and ISO to prove they did it.
We operate in India. Does any of this apply to us?
Not as law. Your binding obligations on most AI uses come from the DPDP Act where personal data is involved, and from sector regulators where they have spoken. The framework still earns its place for two reasons. Questionnaires from European and American customers arrive written in this language, and the underlying work of knowing what you run and who owns it is identical whichever rulebook you end up answering to.
Sources
Everything on this page is drawn from documents published by NIST rather than from secondary summaries, which is deliberate. The framework is being revised, and summaries age faster than the source does.
- AI Risk Management Framework (AI RMF 1.0), NIST AI 100-1, January 2023
The framework itself. The four functions and the trustworthiness characteristics are here.
- NIST AI Risk Management Framework programme page
The page to check for current status, including the revision now in progress. Check this before quoting anything from the framework.
- AI RMF Playbook
Suggested actions and documentation practices for each subcategory. NIST has said it will be updated after the framework revision.
- AI RMF Core: the four functions and their categories
Where Govern, Map, Measure and Manage are broken down, and where the statement that Govern applies across all stages comes from.
- AI RMF Profiles
NIST's own description of what a Profile is. The workbook on this page is a starter profile in that sense.
- Generative AI Profile, NIST AI 600-1, July 2024
Applies the four functions to generative AI risk. The one to read if staff are using language models on real work.
- Crosswalk documents
NIST's formal mappings to other frameworks. Go here rather than to our crosswalk if you need a control level mapping.
- Executive summary and revision notice, AI RMF 1.0
Source for the framework being voluntary and use case agnostic, and for the revision following the White House AI Action Plan of 23 July 2025.
- Concept note: AI RMF Profile on Trustworthy AI in Critical Infrastructure, April 2026
Relevant if you operate in energy, water, healthcare, transport or financial infrastructure.
Get the workbook
Receive the NIST AI RMF starter profile with twenty six rateable outcomes across the four functions, an owner and evidence field on every row, a summary that finds the gaps, and a crosswalk to the EU AI Act, ISO/IEC 42001 and the DPDP Act.

Former IBM mainframe engineer turned operator across Tata and Tata-Tesco. Works at the seam between systems, governance and commercial execution.
LinkedIn profile →