Skip to content
New · AI governance: inventory your AI systems, check the controls, certify ISO 42001.See it
NIST AI RMF

NIST AI RMF: trustworthy AI, mapped to evidence

Map the four functions of the NIST AI Risk Management Framework to controls with automated checks, build your profile from the AI inventory and impact assessments you already keep, and show buyers, insurers and regulators how AI risk is governed, on the same evidence base as ISO 42001.

What is NIST AI RMF?

The NIST AI Risk Management Framework, AI RMF 1.0, is a voluntary framework published by the US National Institute of Standards and Technology in January 2023 to help organizations manage the risks of designing, developing, deploying and using AI systems. Its core has four functions. Govern establishes the policies, roles, accountability and culture for AI risk across the organization. Map sets the context: the intended purpose of each system, its users, the data it uses, and the risks and benefits it carries. Measure applies methods and metrics to assess and track those risks, including testing for the characteristics of trustworthy AI: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. Manage prioritizes and acts on the risks, with plans for response and recovery. The functions break down into 19 categories and 72 subcategories, supported by a companion Playbook and a Generative AI Profile published in 2024. There is no certificate: an organization builds a profile of its current and target practices, and NIST publishes a crosswalk to ISO 42001, so the two can run on one evidence base.

In one paragraph

The NIST AI Risk Management Framework (AI RMF 1.0) is the US National Institute of Standards and Technology's voluntary framework for managing the risks of AI systems, released in January 2023. It organizes AI risk management into four functions, Govern, Map, Measure and Manage, and describes the characteristics of trustworthy AI. There is no certification; organizations build profiles that describe their current and target practices, and it is increasingly referenced by US policy, state AI laws, insurers and enterprise buyers.

Who it's for

Companies that build or deploy AI systems for US customers or the public sector, and anyone whose buyers, insurers or regulators ask how AI risk is governed, especially alongside an ISO 42001 program.

With Viglyn

How Viglyn runs NIST AI RMF

  • All 72 subcategories mapped to controls in the library, with automated checks where the evidence lives in your cloud, identity and code systems and structured evidence requests where it does not
  • The Map function built from your AI inventory: purpose, users, data and risks for every system you build and buy, each with an accountable owner
  • Measure and Manage evidenced through impact assessments, test results and risk treatments in the risk module, linked to the systems they cover
  • A current and a target profile scored from evidence rather than self-assessment, with each gap linked to its control and owner
  • The NIST crosswalk to ISO 42001 applied, so AI RMF alignment and ISO 42001 certification share one set of evidence
Straight answers

The NIST AI RMF questions that decide it

Is NIST AI RMF a certification?

No. There is no NIST AI RMF certificate or auditor. You describe your practices as a profile and show the evidence behind them. Buyers, insurers and regulators who ask for AI RMF alignment want that evidence, and where a certificate matters, ISO 42001 is the standard that provides one; Viglyn runs both on the same evidence.

How long does an AI RMF profile take?

A first current profile takes days once your AI inventory exists and your systems are connected, because many Govern and Measure subcategories draw on evidence Viglyn already collects. Agreeing the target profile and writing the AI policies is where the weeks go, and our practitioners do that with you.

How much does NIST AI RMF cost with Viglyn?

NIST AI RMF counts as one of the frameworks included in your plan, from $2,699 a year with implementation by our practitioners included. There is no auditor fee because there is no audit.

FAQ

More NIST AI RMF questions

How does NIST AI RMF relate to ISO 42001?
ISO 42001 is a certifiable management system standard; the AI RMF is a voluntary framework of outcomes. They cover the same ground, governance, impact assessment, measurement and third parties, and NIST publishes a crosswalk between them. Companies selling into the US often align with the AI RMF and certify to ISO 42001 for buyers elsewhere; Viglyn maps one set of evidence to both.
What is the Generative AI Profile?
NIST AI 600-1, published in July 2024, is a companion to the AI RMF that lists risks specific to generative AI, from confabulation and harmful content to data privacy and information integrity, with suggested actions for each under the same four functions. Viglyn carries those actions as controls for the generative AI systems in your inventory.
Do US laws require the AI RMF?
It is voluntary at the federal level, but it is written into US policy and procurement expectations and referenced by state AI laws, Colorado's among them, as a recognized framework for managing AI risk, and insurers and enterprise buyers increasingly ask for alignment. A documented profile with evidence behind it is what those conversations need.

See NIST AI RMF run on your stack

A 30-minute walkthrough with your systems and your framework. No commitment.