Skip to main content
Compliance & ATO

The NIST AI Risk Management Framework in practice

A contract says the vendor shall align with the NIST AI Risk Management Framework. There is no certificate to send back, no auditor who issues one, and no checklist NIST will score. Alignment is a claim carried entirely by documents, and this is the document set that makes it hold.

The sentence that starts the problem

One line arrives in a county contract, a state term-schedule amendment, a prime's subcontract flowdown, or a security questionnaire from a program office: the contractor shall align its AI practices with the NIST AI Risk Management Framework. Nobody on the buying side usually says what evidence would satisfy it, because in most cases nobody on the buying side knows either. The clause was copied from a policy document, and it sits there waiting for someone to answer it.

What follows is drawn from the framework itself, its companion profile and playbook, the two Office of Management and Budget memoranda that govern federal AI use and acquisition, and the enacted text of two state statutes. Every citation here can be checked by anyone willing to open the same documents.

The first thing to understand is that this is not a compliance regime in the sense that FedRAMP or CMMC are. There is no accreditation body. NIST does not certify conformance and no third party is authorized to certify it on NIST's behalf. So the question is never "are we certified." It is "what would a reasonable reviewer accept as evidence that we do the things the framework describes." Answering that well takes a few weeks of real work. Answering it badly takes an afternoon and produces a policy PDF that collapses the moment anyone asks a follow-up question.

The framework, stated exactly

The document is NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0), released January 26, 2023. It was produced under direction from the National Artificial Intelligence Initiative Act of 2020, Public Law 116-283. Its own scoping sentence is worth quoting because it settles several arguments at once: "The Framework is intended to be voluntary, rights-preserving, non-sector-specific, and use-case agnostic, providing flexibility to organizations of all sizes and in all sectors and throughout society to implement the approaches in the Framework."

The Core has four functions: GOVERN, MAP, MEASURE, and MANAGE. Under them sit 19 categories, and under those, 72 subcategories. The distribution matters more than the total. GOVERN carries 19 subcategories across six categories. MAP carries 18 across five. MEASURE carries 22 across four, of which 13 sit under a single category, MEASURE 2, on evaluating systems for trustworthy characteristics. MANAGE carries 13 across four.

Every subcategory is written as an outcome, not as a control. NIST SP 800-53 tells you to do a specific thing. The AI RMF tells you that a specific thing should be true. GOVERN 1.1, for example, states that legal and regulatory requirements involving AI are understood, managed, and documented. It does not say how. That is why alignment cannot be demonstrated by pointing at a configuration and why it can be demonstrated by pointing at a record.

The seven characteristics are where the work actually lands

The framework names the characteristics of trustworthy AI that the outcomes are meant to produce. They are the vocabulary a buyer will use in follow-up questions, so use them in the same words.

Valid and reliable. Named as the necessary condition of trustworthiness. If the system does not do what it claims, nothing else in the list rescues it.

Safe. The system does not, under defined conditions, endanger life, health, property, or the environment.

Secure and resilient. The system withstands adversarial events and unexpected conditions and returns to normal function.

Accountable and transparent. Information about the system is available to the people who need it, and someone owns the decisions. NIST relates this characteristic to all of the others.

Explainable and interpretable. The mechanism of an output can be described, and its meaning in context can be understood.

Privacy-enhanced. Anonymity, confidentiality, and control are preserved where they should be.

Fair, with harmful bias managed. Equality and equity concerns are addressed, and the systemic, computational, and human biases that produce harm are managed rather than assumed away.

MEASURE 2 being the largest category in the whole framework is not an accident. Producing defensible evidence on those seven characteristics for a specific deployed system is the hardest thing in the document, and it is the thing a serious buyer will probe first.

No certificate exists, and that is the design

The companion resource is the AI RMF Playbook, hosted at the NIST Trustworthy and Responsible AI Resource Center. It offers suggested actions aligned to each subcategory and is published in PDF, CSV, Excel and JSON so it can be pulled straight into whatever tracker an organization already runs. NIST is explicit about its status: the Playbook "is neither a checklist nor set of steps to be followed in its entirety," and its suggestions "are voluntary," to be borrowed as many or as few as apply. It is treated as a living resource with updates released roughly twice a year.

So the alignment claim is evidentiary. A reviewer who has to accept or reject it is looking for records that a named person produced on a known date about a specific system. The table below is the translation most teams are missing when they start.

What the alignment claim assertsWhat a reviewer can actually checkWhere it sits in the Core
We know what AI we runA dated inventory naming each system, its purpose, its owner, and whether its output drives a decision about a person.MAP 1, MAP 2
Someone is accountableNamed roles, a decision record showing who accepted the risk, and an escalation path that has been used at least once.GOVERN 2
We understand the contextDocumented intended use, expected users, people affected who are not users, and the limits the system is known to have.MAP 3, MAP 5
We measured itTest method, evaluation data, results, and a date, for the configuration actually deployed rather than the one demonstrated.MEASURE 1, MEASURE 2
We watch itMonitoring thresholds, a review cadence, and a written answer to what happens the day a threshold trips.MEASURE 3, MANAGE 4
We know our suppliersModel, data and component provenance with the terms attached, including anything a subcontractor brought in.GOVERN 6, MANAGE 3

The profile is the deliverable

The framework's own answer to "what do we hand over" is a profile. NIST describes three kinds and they compose rather than compete.

A use-case profile tailors the functions, categories and subcategories to one setting or application. A temporal profile comes in two states: a current profile describing how AI is being managed today and the risks that follow, and a target profile describing the outcomes needed to reach the intended state. Comparing the two produces the gap list, which becomes the action plan. A cross-sectoral profile covers risks that run across many use cases, such as those involving large language models, cloud services, or procurement itself.

NIST deliberately publishes no template for any of them. That is frustrating for a team that wants a form to fill out and it is the correct design, because a template would invite the exact failure the framework is trying to prevent: a document that describes a generic organization rather than a specific system. A profile that names the system, names the decision it influences, names the people it affects, and names the subcategories that were deliberately excluded and why, is worth more to a reviewer than a hundred pages that could have been written about anyone.

That last part carries weight. A target profile that claims all 72 subcategories are in scope and fully satisfied reads as unexamined. A target profile that says twelve subcategories are out of scope because the system produces no content, touches no biometric data, and makes no eligibility determination, reads as somebody who did the analysis.

Building the evidence set from a standing start

1
Inventory every AI system in scope, with owner, purpose, and whether its output drives a decision about a person
1–2 weeks
2
Set the target profile: choose the subcategories that apply to this use, and record why the others do not
1 week
3
Write the impact record: intended use, data fitness, affected people, known limits, accepted risk, named signer
2–3 weeks
4
Build the measurement plan and run it against the deployed configuration, not the demonstration one
3–6 weeks
5
Stand up monitoring with thresholds, a review cadence, and an escalation path with a name on it
2–4 weeks
6
Date it, version it, and schedule the reassessment before a buyer thinks to ask when it was last touched
ongoing

Anything with a language model in it inherits a second document

On July 26, 2024, NIST released AI 600-1, the Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile. It is a cross-sectoral profile and it is now the more frequently cited of the two documents in commercial and state contracting, because most of what buyers are worried about involves generated text.

It enumerates twelve risk categories that are unique to or exacerbated by generative AI: CBRN information or capabilities; confabulation; dangerous, violent, or hateful content; data privacy; environmental impacts; harmful bias and homogenization; human-AI configuration; information integrity; information security; intellectual property; obscene, degrading, or abusive content; and value chain and component integration.

The structure is what makes it usable. Suggested actions are organized by AI RMF subcategory and each carries an action ID keyed to that subcategory, so GV-1.1-001 is the first suggested action under GOVERN 1.1, MP is Map, MS is Measure, MG is Manage. Each action is tagged with the generative AI risks it addresses and the AI actor tasks it belongs to. NIST states plainly that not every subcategory appears, because the profile covers only the ones its working group addressed.

That numbering is the practical gift. A team that cites action IDs in its own risk register gives a reviewer something traceable to a published federal document line by line, which is a very different conversation from asserting alignment in prose.

What state and local buyers actually do with the phrase

Three patterns show up, and they carry different consequences.

As a contract term. The clause is in the terms and conditions, unnegotiated, and the buyer wants an answer during evaluation or at kickoff. This is the most common form and the easiest to satisfy, because a use-case profile plus measurement results plus a monitoring plan answers it directly.

As a questionnaire. A security or privacy office sends a spreadsheet, sometimes derived from the Playbook's own CSV. Answer per subcategory with a pointer to the artifact, not with a yes.

As a statutory defense. This is where the framework has real legal weight, and where the ground has moved twice in eighteen months.

Texas is the clean case. The Texas Responsible Artificial Intelligence Governance Act, House Bill 149 of the 89th Legislature, took effect January 1, 2026. Section 552.105(e) provides an affirmative defense where a defendant substantially complies with the most recent version of the NIST Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, or another nationally or internationally recognized AI risk management framework, together with an internal review process. A federal publication is named in a state statute as a route out of liability, which is about as concrete as voluntary guidance gets.

The same act places direct duties on government. Section 552.051(b) requires a governmental agency making an AI system available for interaction with consumers to disclose, before or at the time of interaction, that the person is interacting with an AI system, in a clear and conspicuous disclosure that avoids dark patterns. Section 552.053 bars governmental entities from AI that assigns social scores leading to detrimental or disproportionate treatment. Section 552.054(b) restricts government use of AI for unique identification through biometric data or images gathered from public sources without consent where that gathering would infringe a right. Chapter 553 creates a Department of Information Resources sandbox allowing tested systems to operate for up to 36 months, with the core protections still applying. Chapter 554 creates a seven-member Texas Artificial Intelligence Council.

Colorado is the cautionary case. Senate Bill 24-205, signed May 17, 2024, named the framework twice in enacted text: once as a measure of whether a deployer's risk management program is reasonable, alongside ISO/IEC 42001, and once inside the affirmative defense. Those obligations were set for February 1, 2026, then pushed to June 30, 2026 by SB 25B-004, signed August 28, 2025. Before that date arrived, Senate Bill 26-189 repealed and reenacted the act. It was signed May 14, 2026 and the new duties begin January 1, 2027. The published summary of the replacement is framed around automated decision-making technology, developer documentation, consumer notice and record retention rather than around a named framework, so anyone planning to rely on a framework-based defense in Colorado should read the enacted replacement text rather than the 2024 version that most vendor briefings still summarize.

A framework-based defense is only as durable as the statute that names it, and Colorado's original statute did not survive to its own start date.

The federal memoranda require the practices without naming the framework

Teams often assume federal AI policy mandates the AI RMF. It does not, and knowing that precisely is useful when a prime tells you otherwise.

Two OMB memoranda issued April 3, 2025 govern the current federal posture. M-25-21, Accelerating Federal Use of AI through Innovation, Governance, and Public Trust, replaces M-24-10. M-25-22, Driving Efficient Acquisition of Artificial Intelligence in Government, covers buying. Neither cites the NIST AI Risk Management Framework anywhere in its text.

What M-25-21 does instead is define a category and attach practices to it. High-impact AI is AI whose output serves as a principal basis for decisions or actions with legal, material, binding, or significant effect on civil rights, civil liberties or privacy; on access to education, housing, insurance, credit or employment; on access to critical government resources or services; on human health and safety; on critical infrastructure or public safety; or on strategic assets. The memo also lists categories presumed high-impact, including safety-critical infrastructure functions, medically relevant device functions and patient diagnosis, law enforcement risk assessments and biometric identification, control of access to government facilities, and adjudication of requests for critical federal benefits.

Seven minimum risk management practices attach to every high-impact use case, and they map cleanly onto the framework even though the framework is never mentioned.

M-25-21 minimum practiceWhat it producesNearest AI RMF outcome
Pre-deployment testingTest results and a mitigation plan before go-live; where source, model or data are unavailable, alternative methods such as querying the service or giving the vendor evaluation data.MEASURE 1, MEASURE 2
AI impact assessmentPurpose and expected benefit with metrics, data quality and fitness, potential privacy and civil rights impacts, reassessment schedule, cost analysis, independent internal review, and a signature accepting the risk.MAP 3, MAP 5, GOVERN 2
Ongoing monitoringPeriodic testing and human review after deployment, designed to catch changes to the system, the data, or the context of use.MEASURE 3
Human training and assessmentPeriodic training specific to the system being operated and how it is used.GOVERN 4
Human oversight and interventionAccountability suitable to the use, and where practicable a fail-safe that limits the risk of significant harm.MANAGE 1
Consistent remedies or appealsTimely human review and a route to appeal a negative outcome, built on an existing appeals process where one exists.MANAGE 4
End-user and public feedbackA channel that feeds real operating experience back into the risk record.MEASURE 4

M-25-22 works the acquisition side and is worth reading before a bid, not after. It pushes performance-based acquisition techniques for AI, and it directs attention to protections against vendor lock-in, including knowledge transfer and clear data and model rights. A vendor whose proposal already answers the lock-in question in writing is answering something the buyer's own guidance told them to ask.

The practical consequence for a state or local reader is a small change in wording that saves an argument. When a customer's own policy names the framework, cite the framework. When it does not, describe the practices and let the artifacts carry the claim. The evidence is the same either way, which is the point of building it once.

The framework is under revision, so cite the version

America's AI Action Plan, published July 2025, contains a recommended policy action directing that the Department of Commerce, through NIST, "revise the NIST AI Risk Management Framework to eliminate references to misinformation, Diversity, Equity, and Inclusion, and climate change." NIST's own framework page now states that the framework is being revised as part of that plan.

What that revision will change in the Core is not published, and predicting it would be guesswork. The consequence for a working team is procedural rather than substantive: date and version every artifact, keep the crosswalk between internal controls and subcategory identifiers in a form that can be reissued rather than rewritten, and avoid contract language that binds to "the most recent version" of a document whose next version is unknown, unless the statute in play already uses that phrase, as Texas does.

The framework family is still growing. On April 7, 2026 NIST released a concept note for an AI RMF profile on trustworthy AI in critical infrastructure. Teams working water, power, transit or emergency systems for a state or municipal customer should track that one directly, because a published sector profile becomes the reference a buyer reaches for.

Security is a separate document set, and buyers conflate them

The framework names secure and resilient as a characteristic and then, correctly, stops. It does not hand anyone a control baseline. Two other NIST efforts do that work.

In March 2025 NIST published AI 100-2e2025, Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations, which gives shared vocabulary for attack classes including data poisoning and evasion across both predictive and generative systems. And in July 2025 NIST created the Control Overlays for Securing AI Systems project, which builds overlays on SP 800-53 controls for specific AI system types. A concept paper went out for feedback on August 14, 2025 and an annotated outline covering predictive AI use cases followed on January 8, 2026, with an initial public draft anticipated after the February 2026 comment window.

That last one is worth watching closely, because it is the document that will let a buyer ask for AI security in the same control language their existing authorization already speaks. When it lands, the questionnaire changes.

What moves a reviewer, and what does not

Evidence is not equally persuasive. The ranking below reflects how far each artifact typically carries an alignment claim when someone has to accept it in writing and attach their name to that acceptance.

How far each artifact carries an alignment claim

Measurement results on the deployed configuration
92%
Current and target profile with a dated gap list
88%
Impact record signed by a named accountable owner
85%
Monitoring thresholds with a written escalation path
80%
Model, data and component provenance record
76%
A policy document asserting alignment
44%

Editorial ranking of evidentiary weight, drawn from the framework's own outcome language and published buyer guidance. Illustrative ordering, not a measured statistic.

The bottom row is the one worth staring at. A governance policy is necessary and it is the least persuasive thing in the folder, because it describes intent rather than practice. Teams build it first and stop there; the artifacts above it take longer and answer what the policy only restates.

Where this is genuinely unsettled

Three things are in motion and pretending otherwise would be dishonest.

The revision is unresolved. NIST has confirmed the framework is being revised under the AI Action Plan, but the resulting Core is not published, so no one can say today which subcategory identifiers survive intact. Crosswalks built now should be built to be reissued.

State law is churning faster than compliance programs can absorb. Colorado enacted, delayed, then repealed and reenacted its statute inside two years. Texas is operating. Others are moving. The stable strategy is to build the artifact set once, because every one of these regimes asks for documentation, notice, human review and records, and none of them asks for something the framework's outcomes do not already cover.

There is no conformity assessment scheme, and none has been announced. If a vendor offers a NIST AI RMF certificate, they are selling their own attestation with a federal logo near it. ISO/IEC 42001 is the certifiable instrument in this space, and it is a different animal.

Bottom line

Alignment with the AI RMF is not a status, a badge, or a purchase. It is a folder: an inventory, a use-case profile with current and target states, an impact record with a signature, measurement results on the system as deployed, a monitoring plan with thresholds and an escalation path, and a provenance record for what came from outside. Anything with a language model in it adds the generative AI profile's twelve risks and its action IDs. Build that once and it answers the state contract clause, the prime's flowdown, the federal high-impact practices, and the Texas affirmative defense from the same set of documents. Build only the policy and it answers none of them past the first follow-up question.

Frequently asked questions

Is there a NIST AI RMF certification?

No. The framework is voluntary by design and NIST does not certify conformance, nor is any body accredited to certify it. Any certificate offered is a vendor's own attestation. ISO/IEC 42001 is the certifiable AI management system standard if a certificate is what a buyer genuinely needs.

What do we actually send a buyer who asks for proof of alignment?

A use-case profile naming the system and the decision it influences, the current and target states with a dated gap list, an impact record with a named signer, measurement results for the deployed configuration, and a monitoring plan with thresholds and an escalation path. Where generative AI is involved, add the risk register keyed to AI 600-1 action IDs.

Does the framework apply if we only use a vendor's model rather than train our own?

Yes, and two parts of the Core exist for exactly that case. GOVERN 6 covers third-party software and data supply chain risk, and MANAGE 3 covers managing risks from third-party entities. M-25-21 also anticipates it directly, telling agencies to use alternative test methods such as querying the service or supplying the vendor with evaluation data when they lack access to the underlying model, code or data.

Does federal policy require the AI RMF?

Not by name. OMB M-25-21 and M-25-22, both issued April 3, 2025, govern federal AI use and acquisition, and neither cites the framework. M-25-21 defines high-impact AI and attaches seven minimum risk management practices to it. Those practices map onto AI RMF outcomes, so one evidence set satisfies both, but the citation a federal customer expects is the memorandum.

Which version should we cite while the framework is being revised?

Cite AI RMF 1.0, NIST AI 100-1, dated January 26, 2023, plus AI 600-1 dated July 2024 where generative AI is in scope, and date your own artifacts. NIST has confirmed a revision is underway under America's AI Action Plan but the revised Core is not published. Avoid contract language binding you to the most recent version of an unpublished document unless the governing statute already uses that phrasing.

1 business day response

Asked to show AI RMF alignment on a live procurement?

We build the evidence set that answers the clause: the use-case profile, the impact record, the measurement results on the system as deployed, and the monitoring plan behind them. Prime or subcontract, federal or state and local.

CapabilitiesMore insights →Start a conversation
UEI Y2JVCZXT9HP5CAGE 1AYQ0NAICS 541512SAM.GOV ACTIVE