Complete Guide NIST AI RMF 1.0 ⚙ Generative AI Profile · AI 600-1

NIST AI RMF Compliance Guide for Small & Mid-Market Businesses

The NIST AI Risk Management Framework (AI RMF 1.0) is the de facto baseline for AI risk management in the United States — voluntary at the federal level, but cited as an affirmative defense in Colorado SB 24-205, mandated for federal agencies by OMB M-24-10, and increasingly referenced in state procurement. Use this guide to operationalize the four core functions — Govern, Map, Measure, Manage — apply the risk-tier framework, run a 30/60/90-day implementation roadmap, and align the same program with the EU AI Act and Colorado SB 205. Start with the free AI compliance assessment, or skim a sample compliance plan.

Create a workspace → Guided intake → See Sample Plan

12 questions · 5 minutes · Instant score · No account required

TL;DR — Three Things You Must Know
Contents
  1. § Govern — Policies, Roles, Accountability
  2. § Map — Context, Inventory, Stakeholders
  3. § Measure — TEVV & Ongoing Evaluation
  4. § Manage — Risk Treatment & Incident Response
  5. § AI Risk Tiers
  6. § 30/60/90-Day Implementation Roadmap
  7. § Alignment with Colorado SB 24-205
  8. § Alignment with the EU AI Act
  9. § Downloadable Compliance Checklist
  10. § Frequently Asked Questions
Core Function 01

Govern — the foundation for every other AI RMF function

In NIST AI RMF 1.0, Govern sits at the top of the function stack. It establishes the policies, processes, procedures, and organizational structures that direct every Map, Measure, and Manage activity downstream. Without a working Govern function, Map/Measure/Manage operate on an unowned problem — exactly the failure mode that produced 2023's consumer-AI incidents and 2024's enforcement actions.

The Govern function in NIST AI RMF 1.0 (NIST AI 100-1) organizes its subcategories across five operational categories:

📜

Govern 1: Policies & Processes

The AI policies, processes, procedures and practices across the organization. Documented, accessible to staff, and version-controlled. Review cadence at least annually or on regulatory change.

  • AI acceptable-use policy with scope and definitions
  • In-scope AI system inventory with ownership
  • Vendor AI management procedures
  • Consumer disclosure / transparency commitments
  • Documented change-management triggers
👥

Govern 2: Roles & Responsibilities

Roles, responsibilities, and lines of communication related to AI risks documented and clear to individuals and teams throughout the organization. Accountability traced to a named executive.

  • AI risk owner identified and documented
  • Roles for AI operators, model owners, vendor managers
  • Escalation path for AI-related incidents
  • Cross-functional review board (optional but valuable)
  • Reporting line to executive leadership
⚖️

Govern 3: Legal & Regulatory

AI-related legal and regulatory requirements understood and documented. Translated into operational obligations for the systems in scope.

  • Inventory of laws touching AI use (GDPR, HIPAA, FTC, EU AI Act, state AI laws)
  • Per-system compliance mapping maintained
  • Counsel review on AI-related disclosure language
  • Updates tracked when AI-related rules change
  • Procurement clause library for AI vendors
📈

Govern 4: Risk Management Strategy

A documented AI risk management strategy that connects AI risks to the organization's broader enterprise risk register, threat modeling, and decision-making hierarchy.

  • AI risks logged in enterprise risk register
  • Severity scoring aligned with overall risk taxonomy
  • Resource allocation tied to risk ranking
  • Quarterly review cadence defined
  • Trigger rules for emergency escalation
🛡️

Govern 5: Risk Culture & AI Literacy

Practices and processes for AI risk-management are documented, stakeholder feedback is incorporated, and a culture of risk awareness and effective AI governance is cultivated across the organization.

  • Mandatory AI literacy training for staff operating in-scope AI
  • Role-based competency expectations
  • Internal communication cadence on AI governance
  • External participation in standards bodies where relevant
  • Documented post-incident learnings loop
📥

Govern 6: Engagement & Accountability

Appropriate policies, processes, procedures and practices across the organization related to engaging with relevant AI actors. Demonstrable accountability to internal stakeholders and external parties.

  • Stakeholder register for each in-scope AI system
  • Affected-actor consultation where meaningful
  • Internal grievance channel with timely response
  • External disclosure where law or policy requires
  • Annual governance review by accountable executive

Why Govern gets the highest priority

Govern is not a one-time exercise. It is the standing operating system for everything else in the framework. Most AI compliance failures cited in FTC enforcement actions and Colorado AG investigations trace back to a missing or nominal Govern function — no named risk owner, no documented policy, no escalation path. A small but real Govern function beats a large but accountable-lacking Map/Measure/Manage investment. Start there.

Core Function 02

Map — establish the context for every AI system you run

Map is the context-building function. It produces the documentation that says this is what this AI system does, who it affects, how it can fail, and on what data it operates. Map is where you establish the AI system inventory, identify stakeholders, and frame risks before anything is tested, deployed, or measured.

Map outputs feed Measure (which tests whether the framed risks materialize) and Manage (which decides how to respond). A weak Map means the rest of the program is testing the wrong things. Spend the time here; the cost is much lower than redoing measurements on a poorly-framed use case.

📋

Map 1: Context Establishment

Intended purposes, potentially beneficial uses, context-specific laws, norms and expectations, and prospective settings in which the AI system will be deployed.

  • Documented intended purpose per system
  • Deployment surface: internal, B2B, B2C
  • Regulatory context mapped (HIPAA, GDPR, state)
  • Out-of-scope uses explicitly listed
  • Time horizon for the deployment
🧭

Map 2: AI System Categorization

AI system categorized relative to its intended purpose, scientific and engineering maturity, integrated with other systems, and the data it uses.

  • System capability inventory (NLP, vision, agents)
  • Data modalities: text, image, audio, tabular
  • Integration architecture documented
  • Build vs. buy decision recorded
  • Vendor dependencies and contracts listed
🤝

Map 3: Stakeholder Mapping

Processes for identifying and engaging with relevant AI actors, including AI impact assessments, consultations, and stakeholder feedback loops.

  • Internal stakeholders: users, operators, executives
  • External stakeholders: consumers, regulators, partners
  • Affected parties: those whose data or decisions are AI-touched
  • Feedback channels documented and staffed
  • Periodic stakeholder review scheduled
⚠️

Map 4: Risk Identification

Risks and potential impacts — direct, indirect, downstream, individual, societal, environmental — are identified and documented across the AI lifecycle.

  • Direct risk to consumer / operator
  • Disparate-impact risks by protected class
  • IP, copyright, and training-data provenance
  • Security attack surface (prompt injection, model theft)
  • Environmental / computational impact
📅

Map 5: Lifecycle Articulation

AI lifecycle stages, relevant actors, and their roles and responsibilities are defined and documented. Snapshot at every transition.

  • Plan + design with signed-off requirements
  • Develop / train with provenance record
  • Verify / validate pre-deployment gate
  • Deploy with monitoring enabled
  • Operate / monitor / retire with archive
Core Function 03

Measure — TEVV and continuous evaluation across the lifecycle

Measure is the function that quantifies and tracks the risks framed in Map. The NIH/NIST shorthand is TEVV: Test, Evaluation, Verification, and Validation. TEVV is not a pre-deployment event — it is a lifecycle-spanning practice, with recurrent measurement points at every Map artifact re-shape.

The Measure function is the one most often under-resourced at SMBs because it produces operational data rather than documents. The cost of skipping it shows up later as incidents that the framework was supposed to detect before deployment. Below are the Measure subcategories most often cited by enforcement authorities and AI procurement programs.

🧪

Measure 1: TEVV Methodology

Test, evaluation, verification, and validation (TEVV) approaches are documented and applied across the AI lifecycle, with appropriate rigor matched to the risk profile.

  • TEVV plan documented before deployment
  • Metrics matched to the system's task domain
  • Baseline performance recorded for drift comparison
  • Adversarial / red-team tests where appropriate
  • Test data held out from training (clean separation)
📊

Measure 2: Evaluation Suites

Evaluations of trained AI model performance, fairness, and other dimensions are conducted on a regular cadence. Results logged with timestamp and dataset version.

  • Latency + throughput benchmarks
  • Accuracy / F1 / calibration per task
  • Fairness metrics across protected classes
  • Robustness tests on adversarial inputs
  • Drift detection on production traffic
🩺

Measure 3: Bias & Disparate Impact

AI systems are evaluated for bias, discrimination, and disparate impact against protected classes and historically marginalized groups throughout the lifecycle.

  • Disparate-impact ratios computed at deployment
  • Re-evaluation on rolling 90-day cadence
  • Datasets audited for representation gaps
  • Mitigation actions tracked to completion
  • Counsel review on civil rights exposure
🛡️

Measure 4: Robustness & Security

Systems evaluated for robustness against adversarial actions, including prompt injection, model inversion, data poisoning, and unauthorized access to model weights.

  • Prompt-injection tests on chat surfaces
  • Output-filter tests for PII leakage
  • Supply-chain risk on model dependencies
  • Rate-limit and abuse monitoring
  • Vendor CVE / patch cadence tracked
📐

Measure 5: Model Interpretability

Approaches for interpreting model outputs and explaining system behavior are documented and applied. Traceable from input to decision where possible.

  • Output traceability in logs
  • Reasoning chains captured where available
  • Confidence / uncertainty surfaced
  • Human-readable explanations provided
  • Audit trail retained per policy

The Generative AI Profile (NIST AI 600-1) extension

NIST AI 600-1 (July 2024) extends Measure with GenAI-specific actions: confabulation tests, training-data privacy leakage probes, copyrighted-material reproduction tests, and provenance / watermarking checks for AI-generated content. If your organization deploys GenAI in production (LLM-powered chat, content generation, code generation), AI 600-1 is the operational extension that the base AI RMF 1.0 references but does not specify.

Core Function 04

Manage — risk treatment, incident response, third-party controls

Manage is where the framework converts measurement into action. Govern sets the policy, Map frames the context, Measure tracks the risks — Manage decides what to do about each known risk on an ongoing basis, and stands up the response when something goes wrong.

The Manage function is generally the most understaffed at SMBs because it is operational, ongoing, and benefits less from a one-time big push than from sustained process discipline. The Manage subcategories below are the ones most closely tied to FTC Section 5 enforcement, state AG actions, and sector regulators (OCR/HIPAA, CFPB).

🔧

Manage 1: Risk Treatment

Resources are allocated to mapped and measured risks on a regular basis and as defined by the Govern function. Prioritization is risk-based and defensible.

  • Risk register with priority ranking
  • Resource allocation tied to register
  • Plans-of-action-and-milestones tracked
  • Escalation rules defined and rehearsed
  • Quarterly risk-treatment review
🚨

Manage 2: Incident Response

Plans and processes are in place to respond to AI system incidents, including AI system failures, security breaches, or unexpected outputs.

  • AI incident response plan documented
  • Incident severity classification
  • Cross-functional incident response team
  • Customer / regulator notification templates
  • Post-incident review and remediation loop
🤝

Manage 3: Third-Party / Vendor Risk

Third-party and vendor risks are identified, monitored, and managed across the AI lifecycle, including model providers, hosting, and data providers.

  • Vendor risk register per AI system
  • Procurement clauses for AI assurance
  • Change-notice clauses (typically 30-day)
  • Vendor incident-reporting SLAs
  • Annual vendor compliance attestation
🔄

Manage 4: Change Management

AI system change-management processes are documented, including version control, model rollback plans, and re-evaluation triggers on material change.

  • Model and prompt version control
  • Rollback procedure tested annually
  • Trigger rules for Map / Measure re-run
  • Sign-off chain for material changes
  • Deployment gates before customer rollout
📚

Manage 5: Documentation & Records

Documentation and records retention policies are in place to support compliance, audit, and ongoing governance activities.

  • TEVV records retained per schedule
  • Risk register retained for ≥3 years (SB 26-189 standard)
  • Incident logs with protected-class tagging
  • Vendor records retained per procurement
  • Periodic defensibility review by counsel
Risk Tiers

Apply these four AI risk tiers to every system in your inventory

NIST AI RMF 1.0 is intentionally tier-agnostic — it does not prescribe risk tiers the way the EU AI Act does. For SMBs, applying an internal tier taxonomy adapted from NIST AI 100-2 (Adversarial Machine Learning taxonomy) and the broader federal risk-tier frameworks makes the Map / Measure / Manage investment proportionate to each system.

The four tiers below work for SMB use cases; align them to internal risk taxonomy and adjust terminology as needed.

🚨

Tier 1 — Critical

AI systems whose failure or misuse could cause severe harm to individuals, communities, or the organization. Examples: AI making consequential decisions about healthcare, employment, finance, justice, or safety. Maximum rigor required.

  • Full TEVV pre-deployment
  • Bias testing across protected classes
  • Adversarial robustness evaluation
  • Continuous monitoring in production
  • Executive accountability documented
⚠️

Tier 2 — High

AI systems making decisions that materially affect customers or operations but without imminent harm. Examples: lead scoring, marketing personalization, fraud signals. Strong TEVV, ongoing monitoring.

  • Standard TEVV pre-deployment
  • Periodic drift monitoring weekly+
  • Bias testing on rolling cadence
  • Vendor conformance documentation
  • 30-day change trigger rules
🟡

Tier 3 — Medium

AI systems that assist human decision-making rather than making decisions autonomously. Examples: customer support draft replies, internal research assistants, code completion. Moderate TEVV.

  • Smoke TEVV at deployment
  • Monthly drift checks
  • Human-in-the-loop enforced
  • Documented acceptable outputs
  • Quarterly review by owner
🟢

Tier 4 — Low / Minimal

AI in clearly internal, non-decisional roles. Examples: code linting, search ranking, internal summaries. Light TEVV; volunteer best-practice codes encouraged.

  • Output sanity checks at deployment
  • Quarterly owner confirmation
  • Documented use rationale
  • Track regulatory status changes
  • Re-evaluate if use case shifts

Why tier, when the framework itself is tier-agnostic?

NIST AI RMF 1.0 deliberately does not prescribe tiers because the framework is horizontal. SMBs that adopt explicit internal risk tiers get two benefits: (a) resources are spent proportionately — heavy TEVV on Critical systems, light on Low; and (b) the tier map becomes the document that aligns most cleanly to sector regulators. Colorado SB 26-189 treat Tier-1 systems as "high-risk AI systems" within its covered contexts; the EU AI Act maps its own Annex III categories onto roughly the same Tier-1 definition.

Implementation Roadmap

A 30/60/90-day implementation roadmap mapped to the four core functions

The roadmap below assumes a focus on a small in-scope AI system inventory (5–20 systems). Larger organizations scale the same artifacts across business units; smaller organizations may collapse day 1–30 into a single work week.

D1
Days 1–30 · GOVERN

Stand up the foundational governance artifacts

Deliverables: AI acceptable-use policy (one version, signed by accountable exec); AI system inventory (every AI tool in production today); named AI risk owner; documented escalation path; vendor procurement clause library; AI literacy training brief for staff who operate in-scope systems. Most of this is documentation work — but it unblocks every function downstream.

D31
Days 31–60 · MAP

Establish context for every in-scope AI system

Deliverables: Per-system Map artifact capturing intended purpose, stakeholders, regulatory context, out-of-scope uses, data modalities, lifecycle stage, and risk identification. Bias and security risk enumerated per system. The Map artifacts feed directly into Measure and Manage, so they must be complete before day 60. For most SMBs this is 1–2 weeks of structured work per system.

D61
Days 61–90 · MEASURE (TEVV baseline)

Run baseline TEVV on every Tier 1 and Tier 2 system

Deliverables: TEVV plan per system; baseline accuracy / fairness / robustness metrics recorded; drift monitoring instrumentation enabled; output review cadence operational. Generative AI systems additionally run the AI 600-1 GenAI extensions (confabulation probes, IP / copyright reproduction tests, provenance / watermarking checks). Tier 3 and Tier 4 systems get a smoke-TEVV at deployment plus quarterly owner reviews.

D91
Day 91+ · MANAGE (continuous)

Establish risk treatment, incident response, vendor management

Deliverables: Risk register with priority ranking tied to Map / Measure outputs; AI incident response plan with severity classification and notification templates; vendor risk register per procurement; documented change-trigger rules (typically 30-day re-assessment on vendor material update); records retention policy (3 years minimum for SB 26-189, longer for HIPAA). Govern function runs quarterly internal reviews against the AI RMF subcategories.

YR1
Year 1 · ANNUAL POSTURE

Work toward defensible annual posture

Quarterly inventory review (CCPA / SB 26-189 cadence). Annual impact assessment for Tier 1 and Tier 2 systems. Annual governance review by accountable executive. Internal post-incident learnings loop documented. AI literacy refreshers on regulatory change. Each refresh strengthens the rebuttable presumption under Colorado SB 24-205 and aligns closest to OMB M-24-10 expectations.

Regulatory Alignment

Alignment with Colorado SB 24-205 — NIST AI RMF as an affirmative defense

Colorado SB 24-205 (signed May 2024, Consumer Protection Act update) explicitly cites the NIST AI Risk Management Framework (and ISO/IEC 42001) as creating a rebuttable presumption of reasonable care when a developer or deployer of a high-risk AI system has implemented a risk-management program consistent with these frameworks. A documented AI RMF adoption record is therefore the single most concrete defense available to an SMB operating in Colorado.

The right column below maps SB 24-205's reasonable-care framework onto the four NIST AI RMF core functions. While the legislation and the framework are not a 1:1 alignment, the operational work delivered by an AI RMF adoption meets the substance of SB 24-205's reasonable-care inquiry.

Dimension NIST AI RMF Core Functions Colorado SB 24-205
Trigger Voluntary adoption; OMB M-24-10 for federal agencies; procurement-driven for many state / federal buyers High-risk AI system in a covered consequential-decision context within Colorado
Governance role Govern — policies, roles, regulatory mapping, strategy, culture Reasonable-care framework relies on documented governance + accountable executive
Risk identification Map — context, categorization, stakeholders, risk identification, lifecycle Obligation to identify and document risks before deployment of high-risk AI
Evaluation & monitoring Measure — TEVV across lifecycle, bias testing, robustness, interpretability Reasonable-care framework expects ongoing evaluation and consumer-disclosure record
Risk response Manage — risk treatment, incident response, third-party, change management Reasonable-care framework expects documented response and remediation capability
Affirmative defense Framework adoption itself — documented AI RMF record is the affirmative posture NIST AI RMF + ISO/IEC 42001 = rebuttable presumption of reasonable care
Generative AI Generative AI Profile (NIST AI 600-1) extends each core function with GenAI-specific actions SB 24-205 + SB 26-189 apply wherever generative AI operates in a covered context
Maximum penalty No direct federal penalty — framework is voluntary $20,000 per violation under Colorado Consumer Protection Act
Best compliance posture Adopt all four core functions; integrate GenAI Profile; document; review quarterly Demonstrate AI RMF / ISO 42001 adoption to invoke the rebuttable presumption

Sources: NIST AI RMF 1.0 (NIST AI 100-1) — NIST; Colorado SB 24-205. See also SB 26-189 deep dive and SB 205 deep dive.

Regulatory Alignment

Alignment with the EU AI Act — the AI RMF maps to specific Articles

The EU AI Act (Reg. (EU) 2024/1689) and the NIST AI RMF are both risk-based frameworks, but they operate differently — the EU AI Act is mandatory and outcome-oriented; the AI RMF is voluntary and process-oriented. For SMBs serving EU residents, the same AI RMF adoption that addresses Colorado's affirmative defense covers most of the EU AI Act's substance — mapped function by function below.

NIST AI RMF Core Function EU AI Act provision(s) What the AI RMF adoption delivers
Govern Art. 4 AI literacy · Art. 17 Quality management system Documented AI policies, role assignments, competency expectations, accountability chain — supplies the SMS-like artifact expected by Art. 17 and the staff literacy baseline of Art. 4.
Map Art. 9 Risk management system · Art. 10 Data governance · Art. 11 Technical documentation Per-system context, stakeholders, data modalities, lifecycle stage — substantively addresses Art. 9's risk-management requirements, Art. 10's data-governance expectations, and Art. 11's technical-documentation scope (Annex IV).
Measure Art. 15 Accuracy, robustness, cybersecurity · Art. 72 Post-market monitoring · Art. 14 Human oversight TEVV plan, baseline metrics, drift monitoring, bias / disparate-impact testing — the operational inputs to Art. 15's accuracy / robustness claim, Art. 72's post-market file, and Art. 14's human-oversight demonstration.
Manage Art. 26 Deployer obligations · Art. 73 Serious-incident reporting · Art. 50 Transparency Risk treatment, incident response plan, vendor management, change-management triggers — meet the deployer duty of Art. 26 to monitor operation, report incidents, and ensure input data relevance, plus Art. 50 disclosure language at the point of interaction.
Generative AI extension Art. 51–55 GPAI obligations · Art. 50(4) Synthetic content marking NIST AI 600-1 confabulation / privacy / IP / watermarking actions map to the GPAI documentation duty under Art. 53 and the synthetic-content marking duty under Art. 50(4).
Affirmative defense / penalty No formal defense; €35M / 7% (Art. 5), €15M / 3% (other), €7.5M / 1% (info) Adoption does not eliminate penalties; substantially reduces the operational work and produces the audit file competent authorities request.

Sources: NIST AI RMF 1.0 — NIST; Regulation (EU) 2024/1689 — EUR-Lex. See also EU AI Act deep dive and EU AI Act SMB pillar.

Downloadable Checklist

The NIST AI RMF compliance checklist — printable HTML version

The four core functions are reproduced below in operational checklist form for easy use. A standalone, print-friendly HTML version is also available for download — print it, walk it with your team, file it with your governance record.

📜

1. Govern — Policies & Roles

  • AI acceptable-use policy documented and signed
  • AI risk owner named and accountable
  • Escalation path documented and rehearsed
  • Vendor AI procurement clause library maintained
  • AI literacy training brief for operators
  • Regulatory mapping updated on rule changes
  • Annual governance review by accountable executive
  • Internal grievance channel operational
🧭

2. Map — Context Per System

  • Intended purpose documented for every in-scope AI
  • Deployment surface and out-of-scope uses recorded
  • Regulatory context mapped (HIPAA, GDPR, state, EU)
  • Stakeholder register per system
  • Data modalities and provenance recorded
  • Lifecycle stage + next transition tracked
  • Risk identification (direct / disparate / security / IP)
  • Re-map on material change (typically 30-day trigger)
🧪

3. Measure — TEVV Baseline

  • TEVV plan written before deployment
  • Baseline accuracy / F1 / calibration recorded per system
  • Drift monitoring on production traffic enabled
  • Disparate-impact tests across protected classes
  • Robustness tests (prompt injection, adversarial inputs)
  • GenAI: confabulation, IP, watermarking (NIST AI 600-1)
  • Output traceability / confidence surfaced
  • Test data held out from training (clean separation)
🔧

4. Manage — Risk Treatment & Response

  • AI risk register with priority ranking
  • Resource allocation tied to register
  • Incident response plan with severity classification
  • Customer / regulator notification templates
  • Vendor risk register per in-scope AI
  • Material-change clauses in vendor contracts
  • Model + prompt version control and rollback tested
  • Records retained ≥3 years (SB 26-189 cadence)

Save the checklist — printable HTML version

A standalone, print-friendly version of this checklist is available at /checklists/nist-ai-rmf-checklist.html. It contains no JavaScript or analytics, and is sized for letter paper — drop it into your compliance binder or share with your accountability executive.

How GovernIQ Helps

From the NIST AI RMF to a documented AI governance program in under a week

Reading the framework is the first step. Knowing exactly which of your AI systems map to each core function, where the gaps are in your Govern / Map / Measure / Manage practice, and getting a prioritized written action plan is the second. GovernIQ automates the gap analysis specifically for SMB resource budgets — without enterprise GRC overhead.

01

12-Question Assessment

Covers AI tool inventory, data handling practices, employee training status, vendor procurement clauses, policy governance, and incident-response posture. Takes 5 minutes. Generates a 0–100 compliance score and up to 8 specific policy gaps — mapped to the four NIST AI RMF core functions with citations.

Take the Assessment →
02

Sample Compliance Plan

See a real example of the personalized Compliance Action Plan output for a fictional financial advisory firm facing a similar AI RMF / EU AI Act alignment challenge. Understand what you'll get before you purchase.

View Sample Plan →
03

Personalized Action Plan

After a $299 one-time purchase, receive a full Compliance Action Plan specific to your company's AI stack, NIST AI RMF core-function gaps, EU AI Act risk classification, Colorado SB 24-205 / SB 26-189 obligations, and industry — with action items, governance templates, Map / Measure / TEVV templates, vendor clause language, and a 30/60/90-day roadmap.

See Pricing →
Frequently Asked Questions

NIST AI RMF compliance — the questions we hear most

What is the NIST AI Risk Management Framework?
The NIST AI RMF 1.0 (NIST AI 100-1, January 2023) is a voluntary framework for managing AI risks across the AI lifecycle. It is organized around four core functions — Govern, Map, Measure, Manage — with subcategories and example actions under each. NIST also published a companion Generative AI Profile (NIST AI 600-1, July 2024) addressing gen-AI-specific risks. The framework is voluntary at the federal level but is increasingly referenced by state laws (Colorado SB 24-205), procurement, and sector regulators as the de facto baseline. Read more at NIST AI RMF — NIST.
What are the four core functions?
Govern establishes the policies, processes, procedures, and organizational structures for AI risk management. Map establishes the context to identify risks related to each AI system — intended purpose, stakeholders, lifecycle, and impacts. Measure employs quantitative, qualitative, or mixed-method tools to analyze, assess, benchmark, and monitor AI risk and related impacts. Manage allocates resources to mapped and measured risks on a regular basis and as defined by the Govern function. Govern sits at the top and scopes the other three. Walk through each take our 12-question assessment.
Is NIST AI RMF compliance mandatory?
No direct federal mandate and no fines. Adoption is voluntary. But the framework is functionally required in many contexts: Colorado SB 24-205 cites AI RMF + ISO/IEC 42001 as a rebuttable presumption of reasonable care; OMB Memorandum M-24-10 mandates it for federal agencies; many state procurement solicitations and federal RFPs ask for AI RMF-aligned disclosures; sector regulators (OCR/HIPAA, FTC) routinely reference it as the expected baseline. For most SMBs operating in Colorado, in federal supply chains, or in healthcare / finance / legal verticals, the operational answer is "yes, you should adopt it."
What is the Generative AI Profile (NIST AI 600-1)?
NIST AI 600-1 (published July 2024) is a companion profile to AI RMF 1.0 that addresses risks unique to generative AI systems. It enumerates 12 GenAI-specific risks (confabulation, data privacy, information integrity, harmful bias, IP infringement, etc.) and 200+ mitigation actions mapped to the same Govern / Map / Measure / Manage structure. If you deploy an LLM in production, fine-tune a frontier model, or expose GenAI to customers, AI 600-1 is the operational extension that AI RMF 1.0 references without specifying. See NIST AI 600-1 — NIST.
How does the AI RMF align with Colorado SB 24-205?
SB 24-205 explicitly cites AI RMF (and ISO/IEC 42001) as creating a rebuttable presumption of reasonable care for developers and deployers of high-risk AI systems. The four core functions map cleanly onto SB 24-205's reasonable-care framework: Govern supplies the policies and roles, Map supplies the contextual analysis and risk identification, Measure supplies the testing and ongoing monitoring, Manage supplies the response and remediation loop. A documented AI RMF adoption record is therefore the most concrete defense available to an SMB operating in Colorado. See our SB 205 deep dive.
How does the AI RMF align with the EU AI Act?
Largely function-by-function. Govern maps to Art. 4 AI literacy and Art. 17 quality management. Map maps to Art. 9 risk management, Art. 10 data governance, and Art. 11 technical documentation. Measure maps to Art. 15 accuracy / robustness / cybersecurity, Art. 72 post-market monitoring, and Art. 14 human oversight. Manage maps to Art. 26 deployer obligations and Art. 73 serious-incident reporting. Adoption does not eliminate EU AI Act penalties but substantially reduces the operational work. See our EU AI Act deep dive.
How long does it take a small business to implement the AI RMF?
A 30/60/90-day roadmap fits most SMBs. Days 1–30 (Govern): inventory AI systems, assign a risk owner, draft an AI acceptable-use policy. Days 31–60 (Map): per-system context, stakeholders, lifecycle, risk identification. Days 61–90 (Measure baseline): TEVV, baseline metrics, drift monitoring, bias testing. Day 91+ (Manage, continuous): risk register, incident response, vendor change triggers, records retention. After day 90 the practice is operational: quarterly inventory reviews, annual impact assessments, ongoing incident response. Take our free assessment to scope your starting point.
How does the AI RMF relate to ISO/IEC 42001?
ISO/IEC 42001 (December 2023) is an international management-system standard for AI governance, modeled on ISO 27001's management-system approach. The two frameworks explicitly cross-reference each other. Colorado SB 24-205 names both as creating a rebuttable presumption of reasonable care. The AI RMF is more concrete at the technical layer (TEVV, Bias testing, GenAI Profile); ISO 42001 is more concrete at the management-system layer (PDCA cycles, audit-ready artifacts, certification pathway). Many SMBs adopt AI RMF as the operational baseline and reference ISO 42001 for the management-system scaffolding.
Does the AI RMF apply to AI vendors and SaaS tools my business uses?
Yes. When you deploy a vendor AI tool inside your business, you as the deployer inherit Map / Measure / Manage obligations for that system. Vendor procurement clauses should require AI RMF-aligned disclosures: model card, training data summary, known limitations, evaluation results, change-notice SLA, audit cooperation. A Manage-side vendor register tracks all of this. The deployer cannot transfer Map/Measure obligations to the vendor through contract — but a well-drafted procurement clause substantially reduces the deployer's operational work. See our SB 26-189 deep dive for vendor management specifics.
📋
Free Tool — No signup required
Need a starting AI acceptable-use policy? Get a customized policy in 60 seconds.
Includes AI system inventory template, NIST AI RMF core-function checklist, vendor procurement clause library, incident-response skeleton, and reporting escalation path — generated for your org.
Build Your Policy Free →

Move from framework reading to documented AI governance — start today.

The GovernIQ assessment maps each of your AI systems to the four NIST AI RMF core functions, identifies the specific Map / Measure / Manage gaps, and produces a prioritized 30/60/90-day action plan. Free. No account required. The output is the documented AI RMF adoption record that supports the Colorado SB 24-205 affirmative defense and substantially reduces the work to satisfy the EU AI Act for the same system.

Create a workspace → Guided intake → See a Sample Report

Free assessment · Personalized Compliance Action Plan $299 · No subscription