NIST AI RMF
The four core functions
The AI RMF is organised around four core functions that structure how organisations should approach AI risk:
Govern — establishes the organisational context for AI risk management. This includes defining AI risk policies, assigning roles and responsibilities, building a culture of responsible AI, and aligning AI governance with enterprise risk management. Govern is the foundation — without organisational commitment, the other three functions cannot operate effectively.
Map — identifies and contextualises AI risks. This means understanding the AI system’s intended purpose, the data it uses, the stakeholders it affects, and the environment in which it operates. Map also covers identifying potential harms — to individuals, groups, organisations, and society — and documenting assumptions and limitations.
Measure — quantifies and tracks identified risks using appropriate metrics, testing methods, and benchmarks. This includes bias testing, performance evaluation, robustness checks, and ongoing monitoring of AI system behaviour in production. Measure is where technical testing meets organisational risk appetite.
Manage — prioritises and acts on measured risks. This covers risk treatment decisions (accept, mitigate, transfer, or avoid), incident response planning for AI failures, and communication of residual risks to stakeholders. Manage also addresses the decommissioning of AI systems that no longer meet acceptable risk thresholds.
NIST AI RMF vs ISO 42001 vs EU AI Act
These three instruments address AI governance from different angles:
| NIST AI RMF | ISO 42001 | EU AI Act | |
| Nature | Voluntary framework | International standard (certifiable) | Binding regulation |
| Origin | United States (NIST) | International (ISO/IEC) | European Union |
| Focus | Risk identification and management | AI management system (Plan-Do-Check-Act) | Risk classification and compliance obligations |
| Enforcement | None — voluntary adoption | Voluntary certification by accredited bodies | Fines up to 35 million euros or 7% of global turnover |
| Scope | All AI systems | All AI-related activities within an AIMS | AI systems placed on the EU market |
The three are complementary, not competing. An organisation can use the NIST AI RMF to structure its risk assessment process, implement ISO 42001 as its management system, and demonstrate compliance with the EU AI Act’s requirements for high-risk AI. Many multinationals are adopting all three in a layered approach.
Relevance for UK organisations
The UK government’s approach to AI regulation is sector-specific and principles-based, without a horizontal AI law equivalent to the EU AI Act. This makes voluntary frameworks more important, not less. Without a single regulatory standard to follow, UK organisations must demonstrate responsible AI governance through recognised frameworks.
The NIST AI RMF is particularly useful for UK organisations that supply AI systems to US customers or federal agencies, operate internationally and need a common risk language across jurisdictions, are preparing for future UK AI regulation and want a structured approach now, or need to complement their ISO 42001 implementation with a detailed risk assessment methodology.
The framework also aligns with the NCSC’s guidance on securing AI systems, providing a structured methodology for assessing risks that pure security testing — such as LLM security testing — can then validate technically.
Cyberfort and the NIST AI RMF
We help organisations apply the NIST AI RMF alongside ISO 42001 and EU AI Act compliance through our AI security and consultancy services. Our approach covers AI risk assessment against the four core functions, security testing of AI and ML systems, governance gap analysis, and alignment with international frameworks. Whether you are deploying large language models, computer vision systems, or decision-support AI, we provide the risk assessment and technical testing to ensure responsible deployment.
Related glossary terms
- ISO 42001 — the international standard for AI management systems, providing the certifiable management framework that the NIST AI RMF’s risk approach feeds into
- EU AI Act — the EU’s binding AI regulation, which the NIST AI RMF helps organisations prepare for through structured risk assessment
- LLM Security Testing — technical security assessment of large language models, addressing specific risks identified through the AI RMF’s Measure function
- Adversarial AI — attack techniques targeting AI systems, a key risk category within the AI RMF’s Map function
External references
- NIST AI RMF 1.0 (official publication) — full framework document and supporting resources
- Wikipedia: NIST — overview of the parent standards organisation
- NIST AI RMF Playbook — practical guidance for implementing each function and category
Frequently asked questions
Is the NIST AI RMF mandatory?
No. The NIST AI RMF is a voluntary framework. It is not legally binding in any jurisdiction. However, it is increasingly referenced in US federal procurement requirements and international best practice guidance. For UK organisations, it provides a structured methodology for AI risk management where no equivalent UK framework exists.
How does the NIST AI RMF relate to ISO 42001?
They are complementary. ISO 42001 establishes a management system for AI (policies, processes, controls, continual improvement), while the NIST AI RMF provides a detailed risk assessment methodology. Organisations commonly use the AI RMF’s Govern, Map, Measure, and Manage functions to feed into the risk assessment requirements of their ISO 42001 AI management system.
Does the NIST AI RMF cover cybersecurity risks?
Yes, but it is not a cybersecurity framework. The AI RMF addresses AI-specific risks including bias, fairness, transparency, accountability, robustness, and security. Cybersecurity is one dimension — covering adversarial attacks, data poisoning, model theft, and prompt injection — but the framework is broader than security alone. Organisations typically combine it with existing cybersecurity frameworks (such as NIST CSF or ISO 27001) for complete coverage.
Awards and Accreditations




















Contact Us
Cyberfort Ltd
Venture West,
Greenham Business Park, Thatcham,
Berkshire,
RG19 6HX
