AIWiki
Malaysia
Back to all articles
Ethics & PolicyNISTAI risk managementAI governance

NIST AI Risk Management Framework

4 min readUpdated August 2026
NIST AI Risk Management Framework
Type
Voluntary risk management framework
Publisher
National Institute of Standards and Technology (NIST), United States
Published
January 2023 (AI RMF 1.0); July 2024 (Generative AI Profile)
Core functions
Govern, Map, Measure, Manage
Related
EU AI Act, ISO/IEC 42001, Malaysia AIGE

The NIST AI Risk Management Framework (AI RMF) is a voluntary, non-prescriptive framework published by the United States National Institute of Standards and Technology (NIST) to help organisations design, develop, deploy, and use artificial intelligence systems in ways that manage risk and promote trustworthy characteristics.[1] Released in January 2023 as NIST AI 100-1, it provides a common vocabulary, a set of outcome-focused functions, and a repeatable process for AI risk management without mandating specific tools or techniques.[2] A companion Generative AI Profile (NIST AI 600-1) was published in July 2024 to address risks specific to generative AI.[3]

History and Background

NIST was tasked with developing an AI risk management framework under the National Artificial Intelligence Initiative Act of 2020, and the AI RMF is one of the first national frameworks of its kind.[2] Development drew on broad stakeholder engagement, including workshops, a public request for information, and draft versions released for public comment through 2022.[1]

The framework's first volume, NIST AI 100-1, was published on 26 January 2023, designed to be voluntary and technology-agnostic and to treat risk management as a continuous process rather than a compliance checklist.[2] On 26 July 2024, pursuant to Section 4.1 of Executive Order 14110 on Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence, NIST released the Generative AI Profile (NIST AI 600-1), a cross-sectoral companion that applies the framework to generative AI.[3][4]

Key Concepts

The AI RMF is organised around four core functions: GOVERN, which establishes organisational policies, accountability, and oversight; MAP, which identifies the context and potential impacts of an AI system; MEASURE, which assesses and evaluates risks using quantitative and qualitative methods; and MANAGE, which prioritises and responds to identified risks.[2] These functions are supported by outcomes and subcategories that organisations can tailor to their own operations.

The framework identifies seven trustworthy characteristics — valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair with harmful bias managed.[1] It is designed to align with international standards: organisations commonly layer the AI RMF with ISO/IEC 42001, an internationally certifiable AI management system standard.[5]

The Generative AI Profile identifies 12 risk categories unique to or exacerbated by generative AI — including confabulation, dangerous or violent content, data privacy, harmful bias, information integrity, intellectual property, and value-chain risks — and maps more than 200 suggested actions onto the four core functions.[3][6]

Applications and Impact

The AI RMF has become a de facto governance vocabulary for AI risk management in the United States, with adoption across federal agencies, financial institutions, and technology companies.[6] Because the framework is voluntary, NIST does not certify organisations against it; private training certifications are not NIST-issued attestations.[5] Many organisations use the AI RMF as an internal risk-management operating model, often inside a certifiable ISO/IEC 42001 management system.[5]

Internationally, the framework is frequently cited in policy discussions alongside the European Union's AI Act, and NIST launched the Trustworthy and Responsible AI Resource Center in March 2023 to support implementation and international alignment.[4][7]

>See Also

References

🇲🇾Malaysian Context

Malaysian AI governance has developed along parallel tracks: the Ministry of Science, Technology and Innovation (MOSTI) launched the National Guidelines on AI Governance and Ethics (AIGE) on 20 September 2024 as a voluntary, non-binding framework built on seven core principles, and the National AI Office (NAIO) coordinates AI governance, strategy, and implementation under the Ministry of Digital.[8][9] Malaysian organisations adopting generative AI — including banks, healthcare providers, and government-linked companies — increasingly look to international frameworks such as the NIST AI RMF alongside the national AIGE guidelines and the forthcoming AI Act.[10] The NIST framework's voluntary, principles-based design is generally considered compatible with Malaysia's approach, which similarly emphasises human-centred, trustworthy AI without heavy-handed regulation.[8][9]

References

  1. [NIST — AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework)
  2. [Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1, January 2023](https://doi.org/10.6028/NIST.AI.100-1)
  3. [Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1), July 2024 — NIST](https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence)
  4. [Executive Order 14110 on Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence — The White House, October 2023](https://www.whitehouse.gov/briefing-room/presidential-actions/2023/10/30/executive-order-on-the-safe-secure-and-trustworthy-development-and-use-of-artificial-intelligence/)
  5. [Implement NIST AI Risk Management Framework — Modulos](https://www.modulos.ai/nist-ai-rmf)
  6. [NIST AI Risk Management Framework: Agentic Profile — Cloud Security Alliance](https://labs.cloudsecurityalliance.org/agentic/agentic-nist-ai-rmf-profile-v1)
  7. [NIST releases its Generative Artificial Intelligence Profile — DLA Piper, 30 July 2024](https://www.dlapiper.com/en-us/insights/publications/ai-outlook/2024/nist-releases-its-generative-artificial-intelligence-profile)
  8. [National Guidelines on AI Governance and Ethics (AIGE), Malaysia — Regulations.AI](https://regulations.ai/regulations/RAI-MY-NA-NGAGEXX-2024)
  9. [Malaysia — UNESCO Global AI Ethics and Governance Observatory](https://www.unesco.org/ethics-ai/en/malaysia)
  10. [Malaysia AI Governance Framework — AIWiki Malaysia](/wiki/malaysia-ai-governance-framework)