The NIST AI Risk Management Framework is a genuinely useful document that almost nobody reads, because the version most people meet is either the source material, which is written for organisations with a risk function, or a vendor summary that lists the four functions and stops. This page is the translation: what the framework actually asks, what a company of fifty people should honestly do about it, and which parts you can skip without pretending.
Two facts worth having before anything else. It was released on 26 January 2023, and it is voluntary. There is no NIST AI RMF certification, no auditor who signs you off, and nobody is coming to check. That is not a reason to ignore it. It is a reason to use it as a thinking tool rather than a compliance exercise, which is what it was built to be.
The four functions, in plain terms
Govern, Map, Measure, Manage. Every summary lists them. Very few explain that they are not four stages in a line.
Govern is who decides, who is accountable, and what the organisation has actually committed to in writing. It is drawn at the centre of the framework rather than as step one, because it runs continuously alongside the other three. In a small company this is not a committee. It is one named person, a policy people have signed, and a recurring review that actually happens.
Map is working out where AI is used here and in what context. Which tools, in which processes, touching which data, with what consequence if the output is wrong. Most companies discover during this step that the answer is broader than they assumed, because AI arrived inside software they already owned rather than through a decision.
Measure is how you would know if it were going wrong. This is the function small companies most often fake, because proper measurement of model behaviour is genuinely hard. The honest small-company version is narrower: track the handful of things you can actually observe, and be explicit that you are not measuring the rest.
Manage is what you do about it, prioritised. Not everything gets fixed. The framework expects you to rank risks and act on the ones that matter, which in practice means deciding what you are consciously accepting.
The mistake almost everyone makes with it
People start with Map, because inventorying tools feels like progress and produces a spreadsheet by Friday. Then the spreadsheet sits there, because nobody decided who owns it, what happens when something on it is wrong, or who can say no to the next tool.
Govern first. In a small company that is a genuinely small amount of work: name the owner, write the policy, put the review in the calendar. It is the cheapest of the four and it is the one that makes the other three mean anything, because Map without Govern is an inventory nobody acts on, and Measure without Govern is a metric with no consequence attached.
If you want the Govern function done properly and quickly, it is two documents and one decision: the acceptable use policy, signed, and the twenty decisions behind it. That is Govern, at the scale a fifty-person company actually needs.
The Generative AI Profile is probably the document you want
In July 2024 NIST published a companion, the Generative AI Profile, catalogued as NIST-AI-600-1. It identifies risks specific to generative AI and proposes actions for managing them.
For most companies reading this, that document is more immediately useful than the framework itself. The core framework is deliberately general, covering any AI system including ones you build. The Generative AI Profile addresses the situation nearly every small and mid-size business is actually in: staff using somebody else's model through a browser, with all the exposure sitting in what gets typed into it rather than in how a model was trained.
If you read one, read that one. If you read neither, the four questions above are the framework's substance anyway.
What a fifty-person company should honestly do
A proportionate version, which is the thing no vendor summary will give you because there is nothing to sell at the end of it.
Govern, roughly half a day. Name the owner with contact details. Write and circulate the policy. Get signatures. Put a quarterly review in the calendar attached to a meeting that already exists.
Map, roughly two days and no software. Ask people what they use. Check expense data for subscriptions. Check identity logs for work-email signups. Check DNS for AI destinations. Check the admin consoles of tools you already pay for, because that is where AI features get switched on without anyone deciding. Methods and their blind spots: shadow AI detection.
Measure, one page. Pick three things you can actually observe: which tools are in use, whether the approved list is current, and whether anything was reported. Write down explicitly what you are not measuring. A short honest measure section beats a long aspirational one, and it is the difference between a framework you use and one you perform.
Manage, one conversation a quarter. Look at what Map and Measure turned up, decide what to fix, and write down what you are choosing to accept. The written acceptance is the part people skip and the part that matters, because an unrecorded decision to do nothing is indistinguishable from not having noticed.
That is a week of work spread across a quarter. It is not a NIST implementation in the sense a consultancy would sell you, and it does not need to be, because the framework is voluntary and scaled to the organisation using it.
How it differs from ISO 42001
The question comes up constantly and the answer is short. NIST AI RMF is a voluntary framework for thinking about AI risk, with no certification attached. ISO 42001 is a certifiable management system standard, with an audit and a certificate at the end of it.
So the choice is usually decided by why you are asking. If you want to reason about your own risk, the framework is free, faster, and proportionate. If a customer or an insurer is asking for evidence, a framework you self-applied does not produce the artefact they want, and that is the conversation ISO 42001 is for. Most companies under a hundred people need the first and are being sold the second.
The supporting documents, and whether to bother
NIST publishes a Playbook with suggested actions against the framework's subcategories, a Roadmap, a set of Crosswalks mapping the framework to other standards, and a Trustworthy and Responsible AI Resource Center that has been running since March 2023.
The Crosswalks are worth knowing about if you already hold another certification, since they save you re-deriving overlapping controls. The Playbook is worth a skim if you are the person actually doing the work. The rest is reference material for organisations considerably larger than the ones this page is written for, and skipping it costs you nothing.
FAQ
Govern, Map, Measure and Manage. Govern covers accountability, ownership and written policy, and runs continuously rather than being a first step. Map identifies where AI is used and in what context. Measure asks how you would know if something were going wrong. Manage covers prioritising and acting on what the other functions surface, including explicitly recording risks you choose to accept.
No. NIST states it is intended for voluntary use. There is no NIST AI RMF certification and no auditor who signs an organisation off against it. It is designed as a reasoning tool that scales to the organisation applying it, which is why a small company can implement a proportionate version in about a week of work spread across a quarter.
The Generative AI Profile, published on 26 July 2024 as a companion to AI RMF 1.0. It identifies risks specific to generative AI and proposes actions for managing them. For most small and mid-size businesses it is the more directly useful document, because the core framework is general enough to cover systems you build yourself, while the profile addresses the common situation of staff using somebody else's model through a browser.
It depends on who is asking. The NIST framework is voluntary, free and proportionate, and suits an organisation reasoning about its own AI risk. ISO 42001 is a certifiable management system standard with an audit and a certificate, which is what produces evidence for a customer, insurer or auditor. A self-applied framework does not generate that artefact. Companies under about a hundred people usually need the former and are frequently sold the latter.
With Govern, not Map. Most organisations begin by inventorying AI tools because it produces a visible artefact quickly, then the inventory stalls because nobody owns it and no decision attaches to it. Govern is the cheapest of the four functions at small scale, a named owner, a signed policy and a recurring review, and it is what makes the other three consequential.