NIST AI Risk Management Framework
The voluntary US framework for managing AI risks, organised around four core functions. Widely referenced internationally and increasingly cited by Australian organisations with US operations, US customers, or US-facing supply chains.
What it is
The AI Risk Management Framework (AI RMF) is a voluntary framework published by the US National Institute of Standards and Technology (NIST) in January 2023. Version 1.0 is the current published edition. It is supported by a companion AI RMF Playbook with practical implementation actions, and by the Generative AI Profile (NIST AI 600-1) published in July 2024 that adapts the framework for generative AI specifically. The framework is not law, has no certification track, and carries no formal mandate in Australia. Its weight comes from the depth of its content and the breadth of its adoption.
How it's structured
The AI RMF is built around four core functions, each broken down into categories and subcategories. The four functions are not sequential phases. They run in parallel through the life of an AI system.
- Govern: the organisational culture, structures, processes, and accountability for AI risk management. This is the foundational function and the framework treats it as the one that has to be working for the others to function.
- Map: the context of an AI system. What it does, who it affects, what assumptions it rests on, what categories of risk it carries.
- Measure: the analysis, assessment, benchmarking, and monitoring of identified AI risks. The function where the rubber meets the road on actually knowing what an AI system is doing in production.
- Manage: prioritising and acting on AI risks based on the organisation's risk tolerance. The function where decisions about deployment, modification, retirement, and resource allocation happen.
How it relates to other frameworks
The AI RMF is not directly comparable to ISO/IEC 42001, even though both address AI governance. ISO 42001 is a management system standard with a certifiable structure and prescribed clauses. The AI RMF is a risk management framework with functions, categories, and subcategories that organisations apply at the depth that suits them. The two are complementary rather than overlapping. Organisations with mature governance programs often use both, with ISO 42001 providing the management system spine and the AI RMF providing the operational vocabulary for risk work.
The Australian frameworks Aicura uses (the AI Ethics Principles, CSIRO AI6, and the NSW AI Assessment Framework) sit in a different register. The AI RMF is broader and more detailed, but the Australian frameworks are more specific to Australian regulatory expectations and concepts (the AIAF Level 1 to 4 risk taxonomy, the AI6 Essential Practices grounded in Australian sector context). For Australian organisations the practical pattern is to use the Australian frameworks as the primary reference and the AI RMF as a supplementary guidance source where its depth helps.
Why it matters for Australian organisations
Three reasons. First, US-facing supply chains. Many Australian organisations have US customers, US-headquartered vendors, US investors, or US regulators in their orbit. The AI RMF is increasingly the framework these counterparties reference when asking about AI risk management, and being able to speak its vocabulary matters in those conversations. Second, depth of content. The AI RMF Playbook contains practical actions at a level of detail that the higher-level Australian frameworks do not provide, which makes it a useful working reference even for organisations not directly subject to US guidance. Third, alignment with international expectations. As the EU AI Act, ISO 42001, the OECD AI Principles, and various sector-specific guidances converge around similar concepts, the AI RMF sits as one of the most fluent translations between them.
Common misreadings
"It is a US framework so it doesn't apply to us." The AI RMF is voluntary in the US too. Its application anywhere depends on the organisation choosing to use it. Australian organisations adopt it because the content is useful, not because they have to.
"It is just a checklist." The framework is deliberately not a checklist. The four functions are open-ended and the subcategories require the organisation to apply judgement about what is in scope and at what depth.
"It conflicts with ISO 42001." The two are designed to be compatible. An organisation pursuing ISO 42001 certification can use the AI RMF as the substantive content of its risk management processes.
How Aicura supports work against it
Aicura uses the AI RMF as a guidance source alongside Australian frameworks when reviewing AI risk assessment policies and producing per-system risk assessments. When you upload a risk assessment policy for review, the guidance Aicura returns is shaped by the AI RMF's four core functions and their subcategories where relevant, drawn alongside the Australian frameworks the policy primarily speaks to. Per-system risk assessments draw on the AI RMF's Measure function content when populating structured risk items, particularly for systems where benchmarking and monitoring are central to the risk position. Aicura does not certify or attest your work against the AI RMF. It uses the framework as part of the baseline against which guidance is produced.
A note on this page
This is Aicura's reading of the framework, written to help you understand what the product is wired into. It is not legal advice and it is not the framework itself. Read the primary source. Where Aicura's interpretation differs from yours or from your advisors', go with theirs.
For a more complete picture of what Aicura does and doesn't do for any framework, see the boundaries page.
Get started with Aicura.
Sign up and start the work. From your first session, you can catalogue your AI systems, run your privacy policy through Aicura's guidance and put your first risk assessments in place.