HomeFrameworksNIST AI RMF
AI GovernanceUnited States (voluntary, used globally)In force Released January 2023

NIST AI RMF

NIST AI Risk Management Framework (AI RMF 1.0)

The voluntary US framework for trustworthy AI

Overview

The NIST AI Risk Management Framework is a voluntary, widely-adopted guide for building trustworthy AI. It organizes AI risk work around four functions — Govern, Map, Measure, and Manage — and defines the characteristics of trustworthy AI (valid, safe, secure, accountable, explainable, privacy-enhanced, fair). It is the de-facto baseline referenced in US procurement and by many enterprises worldwide.

Authority
U.S. National Institute of Standards and Technology
Jurisdiction
United States (voluntary, used globally)
Effective date
Released January 2023
Applicability

Who must comply with NIST AI RMF?

Voluntary for all, but commonly expected by US government buyers and enterprise customers as a baseline for responsible AI. A good fit for any team that wants a practical, function-based way to manage AI risk.

Compliance scope
Your organization collects personal information
You operate in the applicable jurisdiction
Commercial activities are involved
You use or disclose personal data

Not sure if NIST AI RMF applies? Run a free assessment →

Requirements

Key obligations under NIST AI RMF

Govern

Build an AI governance culture — policies, accountability, roles, and risk tolerance across the organization.

Map

Establish the context and intended use of each AI system, and identify its risks and impacts.

Measure

Analyze, benchmark, and test AI risks with quantitative and qualitative metrics.

Manage

Prioritize and respond to risks — allocate resources, treat, monitor, and document.

Trustworthiness characteristics

Address validity, safety, security, accountability, explainability, privacy, and fairness for each system.

Profiles & documentation

Use AI RMF profiles to document your current and target risk posture per use case.

Enforcement

Penalties & enforcement

Maximum penalty
None — voluntary framework
Enforced by: U.S. NIST (no enforcement body)
Notable case

No penalties, but it is the trust baseline many US buyers and partners require before they will contract.

How Canuckt keeps you penalty-free:
Maps your AI systems to the Govern / Map / Measure / Manage functions
Tracks the trustworthiness characteristics per system in your AI registry
Generates the documentation and profiles buyers ask to see
Bridges NIST AI RMF with your EU AI Act and ISO 42001 work so the effort compounds

Run a free NIST AI RMF gap assessment

Complete a short guided assessment, get a scored gap report, and see exactly what you need to do to comply with NIST AI RMF — in under 3 hours. Free forever.

Start free assessment
No credit card
Results in hours
Canadian data residency

Our own compliance

We run our own compliance programme inside Valdra — the product we sell. Our SOC 2, ISO 27001 and ISO 42001 programmes are actively in progress; we do not claim certifications we do not yet hold.

Valdra compliance badge — click to verify
  • PIPEDA
  • Law 25 (Quebec)
  • CASL
  • Data hosted in Canada 🇨🇦
  • AI governance
View our Trust Centre

Self-declared, not audited by a third party. Click the badge to verify it is genuine and see what it covers.

NIST AI RMF Compliance Guide — Govern, Map, Measure, Manage | Valdra | Valdra