United States / Global voluntary use · framework

NIST Artificial Intelligence Risk Management Framework 1.0

Voluntary framework for managing AI risks and incorporating trustworthiness considerations across design, development, deployment and use.

voluntaryU.S. National Institute of Standards and TechnologyVerified 23 Aug 2026

Applicability

Cross-sectoral voluntary framework that can be adapted to organisational context and risk tolerance.

Enforcement context

Not a standalone law; often used as a risk-management reference and assurance basis.

Regulatory timeline

Material dates and status changes.

26 Jan 2023

NIST AI RMF 1.0

Voluntary framework for managing AI risks and incorporating trustworthiness considerations across design, development, deployment and use.

Source for this event →

CRG implementation mapping

Operational obligations and evidence expectations.

RMF-GOV

Govern AI risk

Establish accountable governance, policies, roles and risk culture for AI.

Actor: all · Domain: governance

Evidence: Governance charter, roles, policy set and review records.

RMF-MANAGE

Manage prioritised risk

Prioritise, treat, monitor and communicate AI risks over the lifecycle.

Actor: all · Domain: risk management

Evidence: Risk register, treatment plan, residual-risk acceptance and monitoring.

RMF-MAP

Map context and risk

Document intended purpose, context, affected parties, dependencies and foreseeable risks.

Actor: all · Domain: risk classification

Evidence: Use-case dossier, stakeholder analysis and risk map.

RMF-MEASURE

Measure trustworthiness

Use fit-for-purpose measurements and evaluations to understand system performance and risk.

Actor: all · Domain: evaluation

Evidence: Evaluation plan, test evidence, thresholds and limitations.

Primary source

Verify the underlying instrument.

Cybatar's mapping is designed for AI governance and assurance work. Legal interpretation remains anchored to the current primary text and competent authority guidance.

Open NIST source