Research & ReportsreportRiskLegalAll

NIST AI Risk Management Framework (AI RMF 1.0) — full PDF

~40 min readPublished January 2023 (AI RMF 1.0)Foundational standard· U.S. National Institute of Standards and Technology

Open source· PDF

Estimated time: ~40 min read — for the executive read / key chapters, not necessarily every appendix.

What this is

Official NIST.AI.100-1 PDF: voluntary framework to Map, Measure, Manage, and Govern AI risks. Direct standards document used widely in enterprise risk and audit conversations.

Map–Measure–Manage–Govern gives enterprises a common AI risk spine without requiring model engineering.

  • NIST.AI.100-1 (Jan 2023) is voluntary and widely referenced by auditors and risk committees.
  • Four core functions organize documentation, testing, and oversight for AI systems.
  • Designed to work with existing enterprise risk management, not replace it.
  • Profiles and playbooks exist for deeper application after the core functions.

Next action: Rewrite one existing AI risk review using the four functions as section headers.

Primary source

Read the full source · published January 2023 (AI RMF 1.0).

Open source· PDF

What changes in how you lead

How decision rights, process, and ownership should change.

  • Name a monitoring owner for every material AI use — RMF only works with accountability.
  • Put RMF vocabulary into vendor questionnaires so diligence is comparable.
  • Treat voluntary best practice as the default bar even where law is still catching up.

Deep dive

NIST AI RMF 1.0 (NIST.AI.100-1) is the U.S. voluntary risk framework most boards and vendors now reference.

Focus first on the four core functions; profiles can wait.

Connect one high-risk use case in your function to documentation and oversight.

Related weekly lessons

frameworknistpdfrisk