- Type
- Voluntary risk management framework
- Publisher
- National Institute of Standards and Technology (NIST), United States
- Published
- January 2023 (AI RMF 1.0); July 2024 (Generative AI Profile)
- Core functions
- Govern, Map, Measure, Manage
- Related
- EU AI Act, ISO/IEC 42001, Malaysia AIGE
- Type
- Voluntary risk management framework
- Publisher
- National Institute of Standards and Technology (NIST), United States
- Published
- January 2023 (AI RMF 1.0); July 2024 (Generative AI Profile)
- Core functions
- Govern, Map, Measure, Manage
- Related
- EU AI Act, ISO/IEC 42001, Malaysia AIGE
The NIST AI Risk Management Framework (AI RMF) is a voluntary, non-prescriptive framework published by the United States National Institute of Standards and Technology (NIST) to help organisations design, develop, deploy, and use artificial intelligence systems in ways that manage risk and promote trustworthy characteristics.[1] Released in January 2023 as NIST AI 100-1, it provides a common vocabulary, a set of outcome-focused functions, and a repeatable process for AI risk management without mandating specific tools or techniques.[2] A companion Generative AI Profile (NIST AI 600-1) was published in July 2024 to address risks specific to generative AI.[3]
History and Background
NIST was tasked with developing an AI risk management framework under the National Artificial Intelligence Initiative Act of 2020, and the AI RMF is one of the first national frameworks of its kind.[2] Development drew on broad stakeholder engagement, including workshops, a public request for information, and draft versions released for public comment through 2022.[1]
The framework's first volume, NIST AI 100-1, was published on 26 January 2023, designed to be voluntary and technology-agnostic and to treat risk management as a continuous process rather than a compliance checklist.[2] On 26 July 2024, pursuant to Section 4.1 of Executive Order 14110 on Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence, NIST released the Generative AI Profile (NIST AI 600-1), a cross-sectoral companion that applies the framework to generative AI.[3][4]
Key Concepts
The AI RMF is organised around four core functions: GOVERN, which establishes organisational policies, accountability, and oversight; MAP, which identifies the context and potential impacts of an AI system; MEASURE, which assesses and evaluates risks using quantitative and qualitative methods; and MANAGE, which prioritises and responds to identified risks.[2] These functions are supported by outcomes and subcategories that organisations can tailor to their own operations.
The framework identifies seven trustworthy characteristics — valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair with harmful bias managed.[1] It is designed to align with international standards: organisations commonly layer the AI RMF with ISO/IEC 42001, an internationally certifiable AI management system standard.[5]
The Generative AI Profile identifies 12 risk categories unique to or exacerbated by generative AI — including confabulation, dangerous or violent content, data privacy, harmful bias, information integrity, intellectual property, and value-chain risks — and maps more than 200 suggested actions onto the four core functions.[3][6]
Applications and Impact
The AI RMF has become a de facto governance vocabulary for AI risk management in the United States, with adoption across federal agencies, financial institutions, and technology companies.[6] Because the framework is voluntary, NIST does not certify organisations against it; private training certifications are not NIST-issued attestations.[5] Many organisations use the AI RMF as an internal risk-management operating model, often inside a certifiable ISO/IEC 42001 management system.[5]
Internationally, the framework is frequently cited in policy discussions alongside the European Union's AI Act, and NIST launched the Trustworthy and Responsible AI Resource Center in March 2023 to support implementation and international alignment.[4][7]
>See Also
References
Malaysian AI governance has developed along parallel tracks: the Ministry of Science, Technology and Innovation (MOSTI) launched the National Guidelines on AI Governance and Ethics (AIGE) on 20 September 2024 as a voluntary, non-binding framework built on seven core principles, and the National AI Office (NAIO) coordinates AI governance, strategy, and implementation under the Ministry of Digital.[8][9] Malaysian organisations adopting generative AI — including banks, healthcare providers, and government-linked companies — increasingly look to international frameworks such as the NIST AI RMF alongside the national AIGE guidelines and the forthcoming AI Act.[10] The NIST framework's voluntary, principles-based design is generally considered compatible with Malaysia's approach, which similarly emphasises human-centred, trustworthy AI without heavy-handed regulation.[8][9]
References
- ↑[NIST — AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework)
- ↑[Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1, January 2023](https://doi.org/10.6028/NIST.AI.100-1)
- ↑[Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1), July 2024 — NIST](https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence)
- ↑[Executive Order 14110 on Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence — The White House, October 2023](https://www.whitehouse.gov/briefing-room/presidential-actions/2023/10/30/executive-order-on-the-safe-secure-and-trustworthy-development-and-use-of-artificial-intelligence/)
- ↑[Implement NIST AI Risk Management Framework — Modulos](https://www.modulos.ai/nist-ai-rmf)
- ↑[NIST AI Risk Management Framework: Agentic Profile — Cloud Security Alliance](https://labs.cloudsecurityalliance.org/agentic/agentic-nist-ai-rmf-profile-v1)
- ↑[NIST releases its Generative Artificial Intelligence Profile — DLA Piper, 30 July 2024](https://www.dlapiper.com/en-us/insights/publications/ai-outlook/2024/nist-releases-its-generative-artificial-intelligence-profile)
- ↑[National Guidelines on AI Governance and Ethics (AIGE), Malaysia — Regulations.AI](https://regulations.ai/regulations/RAI-MY-NA-NGAGEXX-2024)
- ↑[Malaysia — UNESCO Global AI Ethics and Governance Observatory](https://www.unesco.org/ethics-ai/en/malaysia)
- ↑[Malaysia AI Governance Framework — AIWiki Malaysia](/wiki/malaysia-ai-governance-framework)