Govern, Map, Measure, Manage: The Four Core Functions of the NIST AI Risk Management Framework
The NIST AI Risk Management Framework (AI RMF) provides a voluntary, four-step methodology for enterprises to identify, assess, and mitigate the risks of artificial intelligence systems before they reach production. By breaking AI governance into continuous cycles of governing, mapping, measuring, and managing, the framework translates abstract ethical principles into verifiable engineering controls.
By Harper Lane
- Enterprise Security Leaders
- Argue that the framework's value lies in its continuous, operational nature, moving AI risk from a one-time compliance checklist to an ongoing engineering metric.
- AI Governance Advocates
- Emphasize that the 'Govern' function is the most critical, as technical measurements fail without a culture of accountability and clear risk-tolerance policies.
- Critical Infrastructure Operators
- Focus on the framework's sector-specific profiles, requiring more stringent controls for AI systems deployed in high-stakes physical environments.
Perspectives this story doesn't cover
- Open-Source AI Developers
- Consumer Privacy Advocates
When an enterprise board approves a generative artificial intelligence deployment, the executive team holds the ultimate liability for its failures, but they rely on engineering and compliance teams to quantify those risks before launch. The mechanism they increasingly use to bridge that gap is the NIST AI Risk Management Framework (AI RMF). Published by the U.S. National Institute of Standards and Technology on January 26, 2023, the voluntary standard has become the load-bearing architecture for enterprise AI security. According to the 2026 Hitch Partners Global CISO Leadership Report, between 57% and 67% of Chief Information Security Officers in the United States now use the framework to evaluate their AI systems.[2]
The framework does not dictate which models an organization can build or buy. Instead, it provides a structured, repeatable methodology for identifying, measuring, and controlling the risks an AI system creates across its entire lifecycle. This approach is organized into four continuous core functions: Govern, Map, Measure, and Manage. These functions are designed to operate as an ongoing cycle rather than a linear checklist, reflecting the reality that AI systems are probabilistic and their behavior changes as they interact with new data.[1][2]
"An AI risk management framework is a repeatable structure for governing AI risk: it defines who is accountable, how risks are identified and classified, how they're measured, and how they're acted on," notes Collibra in its 2026 assessment of the standard. Without this structure, risk management is often improvised team by team, leaving organizations blind to systemic vulnerabilities.
The foundation of the framework is the "Govern" function, which is the only pillar that spans the entire organization rather than applying to individual models. Govern establishes the culture of risk awareness, defining who holds accountability for AI failures, how risk tolerance is calculated, and what policies dictate the acceptable use of third-party models. Enterprise security leaders argue that organizations frequently underestimate this function, treating it as a paperwork exercise rather than the mechanism that allocates resources for safety testing.[1]
Once governance is established, the "Map" function requires teams to document the specific context in which an individual AI system operates. This involves identifying the system's intended purpose, its technical boundaries, the data flows it relies on, and the stakeholders it affects. Mapping forces engineering teams to explicitly state what a model is supposed to do and, crucially, what potential misuses or failure modes exist in its operational environment.[1]
The "Measure" function translates the context gathered during mapping into verifiable metrics. This is where organizations deploy quantitative and qualitative testing to assess the likelihood and impact of identified risks. Measurement covers variables such as algorithmic bias, model explainability, data quality, and security vulnerabilities. For generative AI systems, this includes adversarial testing—often called red teaming—to evaluate how a model responds to malicious inputs or edge cases.[1]
Finally, the "Manage" function dictates how an organization responds to the risks surfaced by measurement. Teams must prioritize vulnerabilities based on their potential impact and the organization's defined risk tolerance, applying technical controls to mitigate exposure. Because AI models are subject to data drift and evolving adversarial tactics, the Manage function requires continuous monitoring of residual risk long after a system is deployed into production.[1]
Finally, the "Manage" function dictates how an organization responds to the risks surfaced by measurement.
These four functions serve a broader goal: achieving the seven characteristics of trustworthy AI defined by NIST. According to the framework, trustworthy AI must be valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. Balancing these characteristics often requires engineering trade-offs; a model optimized for maximum privacy, for example, might sacrifice a degree of explainability.[1][2]
The framework's adaptability has been tested by the rapid evolution of large language models. On July 26, 2024, NIST released the Generative AI Profile (NIST AI 600-1), an extension of the core framework designed specifically for generative systems. The profile introduced 12 new risk categories unique to generative AI, including confabulation, prompt injection, and the exposure of intellectual property through training data. By mapping these novel risks back to the Govern, Map, Measure, and Manage functions, the profile provided a concrete structure for mitigating threats that did not exist when the original framework was drafted.[1][2]
"The NIST AI risk management framework provides structured guidance for defining trustworthiness metrics and operationalizing measurement across the AI lifecycle," Databricks researchers observed, emphasizing that organizations must embed continuous evaluation into every stage rather than treating risk assessment as a one-time gate.
The framework's influence has outlived the political mandates that initially accelerated its adoption. On October 30, 2023, Executive Order 14110 directed U.S. federal agencies to align their AI procurement and risk practices with the NIST AI RMF. While that executive order was rescinded and replaced on January 20, 2025, the framework itself remained untouched. Because it was developed through a consensus-driven process involving over 240 organizations, it retained its authority as the de facto standard for buyers, boards, and auditors.[1][2]
The framework is now evolving toward highly specific operational environments. On April 7, 2026, NIST released a concept note for an AI RMF Profile focused on Trustworthy AI in Critical Infrastructure. This profile aims to guide operators in sectors such as energy, healthcare, and transportation, where AI failures carry physical or systemic consequences.[1]
Despite its widespread adoption, the framework exposes a persistent gap in enterprise capabilities: the transition from mapping risks to actually measuring them. Organizations frequently complete the Govern and Map functions on paper but struggle to implement the Measure function because they lack the automated data infrastructure required to benchmark AI risk consistently.
To address this, the cybersecurity industry has rapidly expanded its tooling around AI Security Posture Management (AI-SPM). These platforms automate the discovery of shadow AI models, monitor data pipelines for exposure, and continuously test production systems against the controls defined in the Manage function.
The framework does not guarantee that an AI system will operate without flaws. Instead, it provides a defensible, standardized language for organizations to prove that they understood the risks of their deployments, measured them accurately, and managed them responsibly. As regulatory scrutiny tightens globally, that verifiable trail of accountability is exactly what executive boards require to authorize deployment.[2]
Key takeaways
- The NIST AI Risk Management Framework provides a voluntary, four-step methodology (Govern, Map, Measure, Manage) for enterprises to control AI risks.
- The framework is designed as a continuous lifecycle, recognizing that AI models drift and evolve after deployment.
- The 'Govern' function spans the entire organization, establishing the accountability and risk tolerance required for the other three functions to succeed.
- A 2024 Generative AI Profile extended the framework to address 12 novel risks, including prompt injection and confabulation.
- Despite the rescission of Executive Order 14110, the framework remains the most widely adopted AI governance standard among US enterprise CISOs.
Unsettled ground
- How the forthcoming NIST AI RMF Profile for Critical Infrastructure will alter compliance requirements for energy and healthcare operators.
- Whether the widespread adoption of the voluntary NIST framework will preempt the creation of binding, certifiable US federal AI regulations.
- How organizations will standardize the measurement of subjective risks, such as algorithmic fairness and explainability, across different cultural contexts.
Sources
[1]NISTCritical Infrastructure OperatorsAI Risk Management Framework
Read on NIST →
[2]Factlen Editorial TeamCritical Infrastructure OperatorsSynthesis by Factlen editorial team
Read on Factlen Editorial Team →
Comments
More in Artificial Intelligence
See all →AI Infrastructure
How KV Caching Solves the LLM Latency Bottleneck
7 sources
AI Watermarking
How Invisible AI Watermarks Actually Work: Inside the Push to Tag Synthetic Text
5 sources
Agent Architecture
Translating the OODA Loop: How Autonomous AI Agents Observe, Orient, Decide, and Act
7 sources
Model Alignment
How Human Preferences Train the Reward Model to Align AI Behavior
7 sources
Every angle. Every day.
Get Artificial Intelligence stories with full source coverage and perspective breakdowns delivered to your inbox.




