AIWiki
Malaysia
Back to all articles
Ethics & Policynistai governancerisk management

NIST AI Risk Management Framework

5 min readUpdated September 2026
NIST AI Risk Management Framework
Type
Voluntary AI risk management framework
Developer
National Institute of Standards and Technology (USA)
First released
26 January 2023 (AI RMF 1.0)
Core functions
Govern, Map, Measure, Manage
Companion documents
Playbook, Roadmap, Crosswalks, Generative AI Profile
Status (2026)
Under revision as part of the White House AI Action Plan

The NIST AI Risk Management Framework (AI RMF) is a voluntary framework published by the United States National Institute of Standards and Technology for managing the risks that artificial intelligence systems pose to individuals, organisations and society. Released in January 2023, it is designed to be used across the lifecycle of an AI system — design, development, deployment and evaluation — and has become one of the most widely referenced governance baselines internationally, including by organisations that are not subject to United States regulation.[1]

History

NIST developed the framework under direction from the National AI Initiative Act of 2020, following an open process that included a public request for information, two draft releases and a series of workshops. AI RMF 1.0 was released on 26 January 2023 as publication NIST AI 100-1, alongside a companion Playbook of suggested actions and a roadmap for future work. In March 2023 NIST launched the Trustworthy and Responsible AI Resource Center to support adoption and international alignment. In July 2024 the institute published the Generative AI Profile (NIST AI 600-1), a companion document required by Executive Order 14110 that catalogues risks specific to generative AI — including confabulation, information integrity, harmful bias and over-reliance — and maps suggested actions to the core framework. NIST released a concept note for a further profile on trustworthy AI in critical infrastructure in April 2026, and has stated that AI RMF 1.0 is being revised as part of the White House AI Action Plan, the policy agenda issued in 2025. Translations have been published in Arabic and Japanese, and crosswalks map the framework to other standards including ISO/IEC 42001 and the EU AI Act.[1][2][3][4]

Key Concepts and Technology

The framework has two parts. The first sets out how organisations should frame AI risk, including the characteristics of trustworthy AI: systems that are valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. The second defines four core functions that structure risk management work: Govern (cultivating a risk culture, roles and policies), Map (establishing context and identifying risks), Measure (analysing and assessing risks with appropriate methods) and Manage (prioritising and responding to risks, including allocation of resources). The functions are iterative rather than sequential, and the framework deliberately avoids prescribing specific technologies or compliance checklists; instead, sector- and technology-specific profiles adapt the core for contexts such as generative AI or critical infrastructure. The companion Playbook provides example actions for each subcategory, and the crosswalks let organisations reconcile the AI RMF with ISO/IEC 42001, the EU AI Act and other instruments so that one governance programme can satisfy multiple regimes.[1][2][5]

Applications and Impact

Because the framework is voluntary, its influence comes through adoption rather than enforcement: United States federal agencies, state governments, standards bodies and multinational companies commonly cite it as a governance baseline, and it is frequently paired with ISO/IEC 42001 certification for organisations that want external assurance. The framework's vocabulary — govern, map, measure, manage, and the seven trustworthiness characteristics — has been absorbed into corporate AI policies, procurement questionnaires and audit practices well beyond the United States, making it a de facto international reference point alongside the OECD AI Principles and the EU AI Act. Its revision and the new profile work signal that AI risk guidance will continue to expand in scope through 2026 and beyond.[1][3][4]

>See Also

🇲🇾Malaysian Context

Malaysia's own governance architecture runs in parallel with the NIST approach. The AI Governance and Ethics Framework issued in 2024 articulates seven principles — fairness, reliability and safety, privacy and security, inclusiveness, transparency, accountability and pursuit of human benefit — that closely echo the trustworthiness characteristics of the AI RMF, and the National AI Office coordinates implementation alongside the National AI Action Plan 2026-2030 (branded AI Nation 2030), launched by the Prime Minister in July 2026. Regulated sectors bring additional expectations: Bank Negara Malaysia's risk-management policy requires financial institutions to govern AI and machine-learning models with validation and oversight, the Personal Data Protection Act 2010 and its 2024 amendments impose obligations around automated decision-making, and NACSA leads cybersecurity oversight of critical infrastructure. For Malaysian organisations selling into global markets — or serving multinational clients — mapping their AI governance to the AI RMF and ISO/IEC 42001 is increasingly a practical requirement rather than an optional exercise, and local consultancies and regulators routinely reference the framework in guidance for AI assurance.[6][7]

References

  1. ↑NIST. AI Risk Management Framework. https://www.nist.gov/itl/ai-risk-management-framework
  2. ↑NIST. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST.AI.100-1. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
  3. ↑NIST. (2024). Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST.AI.600-1. https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence
  4. ↑NIST. (2026). Concept Note: AI RMF Profile on Trustworthy AI in Critical Infrastructure. https://www.nist.gov/programs-projects/concept-note-ai-rmf-profile-trustworthy-ai-critical-infrastructure
  5. ↑NIST AI Resource Center. AI RMF Playbook. https://airc.nist.gov/airmf-resources/playbook/
  6. ↑National AI Office Malaysia. (2026). AI Nation 2030 — National AI Action Plan 2026-2030. https://ai.gov.my/
  7. ↑Ministry of Digital Malaysia. AI Malaysia — Driving the Journey Towards an AI Nation by 2030. https://www.digital.gov.my/en-GB/siaran/AI-Malaysia-Pemacu-Utama-Menuju-Negara-AI-2030