The NIST AI Risk Management Framework (AI RMF 1.0) is the de facto baseline for AI risk management in the United States — voluntary at the federal level, but cited as an affirmative defense in Colorado SB 24-205, mandated for federal agencies by OMB M-24-10, and increasingly referenced in state procurement. Use this guide to operationalize the four core functions — Govern, Map, Measure, Manage — apply the risk-tier framework, run a 30/60/90-day implementation roadmap, and align the same program with the EU AI Act and Colorado SB 205. Start with the free AI compliance assessment, or skim a sample compliance plan.
12 questions · 5 minutes · Instant score · No account required
In NIST AI RMF 1.0, Govern sits at the top of the function stack. It establishes the policies, processes, procedures, and organizational structures that direct every Map, Measure, and Manage activity downstream. Without a working Govern function, Map/Measure/Manage operate on an unowned problem — exactly the failure mode that produced 2023's consumer-AI incidents and 2024's enforcement actions.
The Govern function in NIST AI RMF 1.0 (NIST AI 100-1) organizes its subcategories across five operational categories:
The AI policies, processes, procedures and practices across the organization. Documented, accessible to staff, and version-controlled. Review cadence at least annually or on regulatory change.
Roles, responsibilities, and lines of communication related to AI risks documented and clear to individuals and teams throughout the organization. Accountability traced to a named executive.
AI-related legal and regulatory requirements understood and documented. Translated into operational obligations for the systems in scope.
A documented AI risk management strategy that connects AI risks to the organization's broader enterprise risk register, threat modeling, and decision-making hierarchy.
Practices and processes for AI risk-management are documented, stakeholder feedback is incorporated, and a culture of risk awareness and effective AI governance is cultivated across the organization.
Appropriate policies, processes, procedures and practices across the organization related to engaging with relevant AI actors. Demonstrable accountability to internal stakeholders and external parties.
Govern is not a one-time exercise. It is the standing operating system for everything else in the framework. Most AI compliance failures cited in FTC enforcement actions and Colorado AG investigations trace back to a missing or nominal Govern function — no named risk owner, no documented policy, no escalation path. A small but real Govern function beats a large but accountable-lacking Map/Measure/Manage investment. Start there.
Map is the context-building function. It produces the documentation that says this is what this AI system does, who it affects, how it can fail, and on what data it operates. Map is where you establish the AI system inventory, identify stakeholders, and frame risks before anything is tested, deployed, or measured.
Map outputs feed Measure (which tests whether the framed risks materialize) and Manage (which decides how to respond). A weak Map means the rest of the program is testing the wrong things. Spend the time here; the cost is much lower than redoing measurements on a poorly-framed use case.
Intended purposes, potentially beneficial uses, context-specific laws, norms and expectations, and prospective settings in which the AI system will be deployed.
AI system categorized relative to its intended purpose, scientific and engineering maturity, integrated with other systems, and the data it uses.
Processes for identifying and engaging with relevant AI actors, including AI impact assessments, consultations, and stakeholder feedback loops.
Risks and potential impacts — direct, indirect, downstream, individual, societal, environmental — are identified and documented across the AI lifecycle.
AI lifecycle stages, relevant actors, and their roles and responsibilities are defined and documented. Snapshot at every transition.
Measure is the function that quantifies and tracks the risks framed in Map. The NIH/NIST shorthand is TEVV: Test, Evaluation, Verification, and Validation. TEVV is not a pre-deployment event — it is a lifecycle-spanning practice, with recurrent measurement points at every Map artifact re-shape.
The Measure function is the one most often under-resourced at SMBs because it produces operational data rather than documents. The cost of skipping it shows up later as incidents that the framework was supposed to detect before deployment. Below are the Measure subcategories most often cited by enforcement authorities and AI procurement programs.
Test, evaluation, verification, and validation (TEVV) approaches are documented and applied across the AI lifecycle, with appropriate rigor matched to the risk profile.
Evaluations of trained AI model performance, fairness, and other dimensions are conducted on a regular cadence. Results logged with timestamp and dataset version.
AI systems are evaluated for bias, discrimination, and disparate impact against protected classes and historically marginalized groups throughout the lifecycle.
Systems evaluated for robustness against adversarial actions, including prompt injection, model inversion, data poisoning, and unauthorized access to model weights.
Approaches for interpreting model outputs and explaining system behavior are documented and applied. Traceable from input to decision where possible.
NIST AI 600-1 (July 2024) extends Measure with GenAI-specific actions: confabulation tests, training-data privacy leakage probes, copyrighted-material reproduction tests, and provenance / watermarking checks for AI-generated content. If your organization deploys GenAI in production (LLM-powered chat, content generation, code generation), AI 600-1 is the operational extension that the base AI RMF 1.0 references but does not specify.
Manage is where the framework converts measurement into action. Govern sets the policy, Map frames the context, Measure tracks the risks — Manage decides what to do about each known risk on an ongoing basis, and stands up the response when something goes wrong.
The Manage function is generally the most understaffed at SMBs because it is operational, ongoing, and benefits less from a one-time big push than from sustained process discipline. The Manage subcategories below are the ones most closely tied to FTC Section 5 enforcement, state AG actions, and sector regulators (OCR/HIPAA, CFPB).
Resources are allocated to mapped and measured risks on a regular basis and as defined by the Govern function. Prioritization is risk-based and defensible.
Plans and processes are in place to respond to AI system incidents, including AI system failures, security breaches, or unexpected outputs.
Third-party and vendor risks are identified, monitored, and managed across the AI lifecycle, including model providers, hosting, and data providers.
AI system change-management processes are documented, including version control, model rollback plans, and re-evaluation triggers on material change.
Documentation and records retention policies are in place to support compliance, audit, and ongoing governance activities.
NIST AI RMF 1.0 is intentionally tier-agnostic — it does not prescribe risk tiers the way the EU AI Act does. For SMBs, applying an internal tier taxonomy adapted from NIST AI 100-2 (Adversarial Machine Learning taxonomy) and the broader federal risk-tier frameworks makes the Map / Measure / Manage investment proportionate to each system.
The four tiers below work for SMB use cases; align them to internal risk taxonomy and adjust terminology as needed.
AI systems whose failure or misuse could cause severe harm to individuals, communities, or the organization. Examples: AI making consequential decisions about healthcare, employment, finance, justice, or safety. Maximum rigor required.
AI systems making decisions that materially affect customers or operations but without imminent harm. Examples: lead scoring, marketing personalization, fraud signals. Strong TEVV, ongoing monitoring.
AI systems that assist human decision-making rather than making decisions autonomously. Examples: customer support draft replies, internal research assistants, code completion. Moderate TEVV.
AI in clearly internal, non-decisional roles. Examples: code linting, search ranking, internal summaries. Light TEVV; volunteer best-practice codes encouraged.
NIST AI RMF 1.0 deliberately does not prescribe tiers because the framework is horizontal. SMBs that adopt explicit internal risk tiers get two benefits: (a) resources are spent proportionately — heavy TEVV on Critical systems, light on Low; and (b) the tier map becomes the document that aligns most cleanly to sector regulators. Colorado SB 26-189 treat Tier-1 systems as "high-risk AI systems" within its covered contexts; the EU AI Act maps its own Annex III categories onto roughly the same Tier-1 definition.
The roadmap below assumes a focus on a small in-scope AI system inventory (5–20 systems). Larger organizations scale the same artifacts across business units; smaller organizations may collapse day 1–30 into a single work week.
Deliverables: AI acceptable-use policy (one version, signed by accountable exec); AI system inventory (every AI tool in production today); named AI risk owner; documented escalation path; vendor procurement clause library; AI literacy training brief for staff who operate in-scope systems. Most of this is documentation work — but it unblocks every function downstream.
Deliverables: Per-system Map artifact capturing intended purpose, stakeholders, regulatory context, out-of-scope uses, data modalities, lifecycle stage, and risk identification. Bias and security risk enumerated per system. The Map artifacts feed directly into Measure and Manage, so they must be complete before day 60. For most SMBs this is 1–2 weeks of structured work per system.
Deliverables: TEVV plan per system; baseline accuracy / fairness / robustness metrics recorded; drift monitoring instrumentation enabled; output review cadence operational. Generative AI systems additionally run the AI 600-1 GenAI extensions (confabulation probes, IP / copyright reproduction tests, provenance / watermarking checks). Tier 3 and Tier 4 systems get a smoke-TEVV at deployment plus quarterly owner reviews.
Deliverables: Risk register with priority ranking tied to Map / Measure outputs; AI incident response plan with severity classification and notification templates; vendor risk register per procurement; documented change-trigger rules (typically 30-day re-assessment on vendor material update); records retention policy (3 years minimum for SB 26-189, longer for HIPAA). Govern function runs quarterly internal reviews against the AI RMF subcategories.
Quarterly inventory review (CCPA / SB 26-189 cadence). Annual impact assessment for Tier 1 and Tier 2 systems. Annual governance review by accountable executive. Internal post-incident learnings loop documented. AI literacy refreshers on regulatory change. Each refresh strengthens the rebuttable presumption under Colorado SB 24-205 and aligns closest to OMB M-24-10 expectations.
Colorado SB 24-205 (signed May 2024, Consumer Protection Act update) explicitly cites the NIST AI Risk Management Framework (and ISO/IEC 42001) as creating a rebuttable presumption of reasonable care when a developer or deployer of a high-risk AI system has implemented a risk-management program consistent with these frameworks. A documented AI RMF adoption record is therefore the single most concrete defense available to an SMB operating in Colorado.
The right column below maps SB 24-205's reasonable-care framework onto the four NIST AI RMF core functions. While the legislation and the framework are not a 1:1 alignment, the operational work delivered by an AI RMF adoption meets the substance of SB 24-205's reasonable-care inquiry.
| Dimension | NIST AI RMF Core Functions | Colorado SB 24-205 |
|---|---|---|
| Trigger | Voluntary adoption; OMB M-24-10 for federal agencies; procurement-driven for many state / federal buyers | High-risk AI system in a covered consequential-decision context within Colorado |
| Governance role | Govern — policies, roles, regulatory mapping, strategy, culture | Reasonable-care framework relies on documented governance + accountable executive |
| Risk identification | Map — context, categorization, stakeholders, risk identification, lifecycle | Obligation to identify and document risks before deployment of high-risk AI |
| Evaluation & monitoring | Measure — TEVV across lifecycle, bias testing, robustness, interpretability | Reasonable-care framework expects ongoing evaluation and consumer-disclosure record |
| Risk response | Manage — risk treatment, incident response, third-party, change management | Reasonable-care framework expects documented response and remediation capability |
| Affirmative defense | Framework adoption itself — documented AI RMF record is the affirmative posture | NIST AI RMF + ISO/IEC 42001 = rebuttable presumption of reasonable care |
| Generative AI | Generative AI Profile (NIST AI 600-1) extends each core function with GenAI-specific actions | SB 24-205 + SB 26-189 apply wherever generative AI operates in a covered context |
| Maximum penalty | No direct federal penalty — framework is voluntary | $20,000 per violation under Colorado Consumer Protection Act |
| Best compliance posture | Adopt all four core functions; integrate GenAI Profile; document; review quarterly | Demonstrate AI RMF / ISO 42001 adoption to invoke the rebuttable presumption |
Sources: NIST AI RMF 1.0 (NIST AI 100-1) — NIST; Colorado SB 24-205. See also SB 26-189 deep dive and SB 205 deep dive.
The EU AI Act (Reg. (EU) 2024/1689) and the NIST AI RMF are both risk-based frameworks, but they operate differently — the EU AI Act is mandatory and outcome-oriented; the AI RMF is voluntary and process-oriented. For SMBs serving EU residents, the same AI RMF adoption that addresses Colorado's affirmative defense covers most of the EU AI Act's substance — mapped function by function below.
| NIST AI RMF Core Function | EU AI Act provision(s) | What the AI RMF adoption delivers |
|---|---|---|
| Govern | Art. 4 AI literacy · Art. 17 Quality management system | Documented AI policies, role assignments, competency expectations, accountability chain — supplies the SMS-like artifact expected by Art. 17 and the staff literacy baseline of Art. 4. |
| Map | Art. 9 Risk management system · Art. 10 Data governance · Art. 11 Technical documentation | Per-system context, stakeholders, data modalities, lifecycle stage — substantively addresses Art. 9's risk-management requirements, Art. 10's data-governance expectations, and Art. 11's technical-documentation scope (Annex IV). |
| Measure | Art. 15 Accuracy, robustness, cybersecurity · Art. 72 Post-market monitoring · Art. 14 Human oversight | TEVV plan, baseline metrics, drift monitoring, bias / disparate-impact testing — the operational inputs to Art. 15's accuracy / robustness claim, Art. 72's post-market file, and Art. 14's human-oversight demonstration. |
| Manage | Art. 26 Deployer obligations · Art. 73 Serious-incident reporting · Art. 50 Transparency | Risk treatment, incident response plan, vendor management, change-management triggers — meet the deployer duty of Art. 26 to monitor operation, report incidents, and ensure input data relevance, plus Art. 50 disclosure language at the point of interaction. |
| Generative AI extension | Art. 51–55 GPAI obligations · Art. 50(4) Synthetic content marking | NIST AI 600-1 confabulation / privacy / IP / watermarking actions map to the GPAI documentation duty under Art. 53 and the synthetic-content marking duty under Art. 50(4). |
| Affirmative defense / penalty | No formal defense; €35M / 7% (Art. 5), €15M / 3% (other), €7.5M / 1% (info) | Adoption does not eliminate penalties; substantially reduces the operational work and produces the audit file competent authorities request. |
Sources: NIST AI RMF 1.0 — NIST; Regulation (EU) 2024/1689 — EUR-Lex. See also EU AI Act deep dive and EU AI Act SMB pillar.
The four core functions are reproduced below in operational checklist form for easy use. A standalone, print-friendly HTML version is also available for download — print it, walk it with your team, file it with your governance record.
A standalone, print-friendly version of this checklist is available at /checklists/nist-ai-rmf-checklist.html. It contains no JavaScript or analytics, and is sized for letter paper — drop it into your compliance binder or share with your accountability executive.
Reading the framework is the first step. Knowing exactly which of your AI systems map to each core function, where the gaps are in your Govern / Map / Measure / Manage practice, and getting a prioritized written action plan is the second. GovernIQ automates the gap analysis specifically for SMB resource budgets — without enterprise GRC overhead.
Covers AI tool inventory, data handling practices, employee training status, vendor procurement clauses, policy governance, and incident-response posture. Takes 5 minutes. Generates a 0–100 compliance score and up to 8 specific policy gaps — mapped to the four NIST AI RMF core functions with citations.
Take the Assessment →See a real example of the personalized Compliance Action Plan output for a fictional financial advisory firm facing a similar AI RMF / EU AI Act alignment challenge. Understand what you'll get before you purchase.
View Sample Plan →After a $299 one-time purchase, receive a full Compliance Action Plan specific to your company's AI stack, NIST AI RMF core-function gaps, EU AI Act risk classification, Colorado SB 24-205 / SB 26-189 obligations, and industry — with action items, governance templates, Map / Measure / TEVV templates, vendor clause language, and a 30/60/90-day roadmap.
See Pricing →The GovernIQ assessment maps each of your AI systems to the four NIST AI RMF core functions, identifies the specific Map / Measure / Manage gaps, and produces a prioritized 30/60/90-day action plan. Free. No account required. The output is the documented AI RMF adoption record that supports the Colorado SB 24-205 affirmative defense and substantially reduces the work to satisfy the EU AI Act for the same system.
Free assessment · Personalized Compliance Action Plan $299 · No subscription