AxiLayer AI crestAxiLayerAI
NIST AI 100-1 · The US Benchmark

NIST AI RMF: voluntary on paper, expected in practice.

The NIST AI Risk Management Framework is how American institutions have agreed to talk about AI risk. Boards ask for maturity against it, agencies procure against it, and state statutes lean on it as the measure of reasonable care. This guide covers what the framework actually asks of you — and what an independent assessment against it looks like.

Framework
AI RMF 1.0 (2023)
Functions
Govern · Map · Measure · Manage
GenAI Profile
NIST-AI-600-1 (2024)
The framework

Four functions, one discipline

Published by the US National Institute of Standards and Technology in January 2023 under a congressional mandate, the AI RMF gives organizations a shared structure for making AI trustworthy: valid and reliable, safe, secure and resilient, accountable and transparent, explainable, privacy-enhanced, and fair with harmful bias managed.

Govern

The cross-cutting foundation: policies, accountable roles, risk tolerance, workforce competence, and a culture in which AI risk is surfaced rather than buried. In our assessment experience, weakness here predicts weakness everywhere else.

Map

Establishing context system by system — intended purpose, users, deployment setting, data provenance, third-party components — and identifying what could go wrong for whom. An honest AI inventory is the entry fee; most organizations discover theirs is incomplete.

Measure

Quantifying the mapped risks: performance testing, bias measurement, robustness and security evaluation, drift tracking. The RMF expects measurement to be repeatable and documented, not a one-time benchmark run before launch.

Manage

Acting on what was measured — prioritizing risks against tolerance, treating or accepting them explicitly, planning incident response, and communicating with affected parties. This is where documentation meets decision rights.

For generative systems, the Generative AI Profile (NIST-AI-600-1) extends all four functions with risks specific to models that produce content: confabulation, information-integrity harms, data privacy, provenance, and offensive-capability uplift.

Why it matters commercially

Where "voluntary" stops being optional

Federal government. OMB's AI governance memoranda direct agencies to manage AI risk in terms drawn from the RMF, and agency solicitations increasingly require vendors to demonstrate alignment. For contractors, RMF evidence sits alongside FedRAMP and agency-specific requirements as part of the price of admission.

State law. The Colorado AI Act's duty of reasonable care for high-risk AI explicitly recognizes documented compliance with the NIST AI RMF as evidence in a developer's or deployer's favor. Texas's TRAIGA and other state instruments follow the same pattern: the voluntary framework becomes the yardstick courts and attorneys general reach for.

Enterprise procurement and insurance. AI questionnaires from Fortune 500 buyers, cyber insurers, and audit committees are converging on RMF vocabulary. A maturity assessment answered with tested evidence closes those questionnaires in days rather than quarters.

Global interoperability. NIST publishes crosswalks between the RMF and both the EU AI Act and ISO/IEC 42001. Build the evidence once against the RMF's subcategories, and most of it carries directly into European and ISO obligations — which is exactly how AxiLayer AI structures engagements.

How AxiLayer AI assesses

Maturity measured by evidence, not assertion

Inventory & scoping

We build or verify the AI system inventory — including the shadow deployments and vendor-embedded models that self-assessments miss — and agree the assessment boundary with your governance owners.

Function-by-function testing

Each RMF subcategory in scope is examined against artifacts and behavior: we read the policies, then check the meeting minutes, the model cards, the test logs, and the incident tickets to see whether the policies are alive.

Maturity rating & gap register

You receive a defensible maturity rating per function, a prioritized gap register with remediation guidance, and the measurement baselines future assessments will be compared against.

Continuous alignment

Between annual assessments, AxiSentinel keeps Measure and Manage honest — monitoring drift, control health, and new obligations as NIST publications and crosswalks evolve.

Common questions

NIST AI RMF — asked and answered

Is the NIST AI RMF mandatory?
It is voluntary by design, but it has become the de facto US benchmark: agencies reference it in governance memoranda, buyers write it into contracts, and the Colorado AI Act treats documented alignment as evidence of the reasonable care it requires. You will be asked to demonstrate alignment long before anyone cites a statute.
What are the four functions?
Govern (policies, accountability, culture), Map (context and risk identification per system), Measure (testing, metrics, and tracking), and Manage (prioritizing, treating, and responding to measured risks). Govern underpins the other three.
What is the Generative AI Profile?
NIST-AI-600-1 (July 2024) applies the RMF to generative AI, cataloging GenAI-specific risks — confabulation, information integrity, provenance, privacy — and mapping suggested actions to the framework's functions. If you deploy LLMs, expect to be assessed against it.
What does an independent assessment produce?
A maturity rating per function grounded in tested evidence, a prioritized gap register, and a reusable documentation set. Because NIST publishes crosswalks to the EU AI Act and ISO/IEC 42001, the same evidence base serves those frameworks too.

How mature is your AI risk management — measured, not assumed?

A scoping briefing establishes which systems, functions, and profiles belong in your first assessment cycle.