NIST AI RMF Quick Reference
The NIST AI Risk Management Framework organizes AI risk work into four functions: Govern, Map, Measure, and Manage. It is voluntary guidance, not a certification, which makes it a common starting structure for organizations building an AI governance program.
The framework is sector-agnostic and deliberately flexible. Rather than prescribing controls, it gives organizations a shared vocabulary for deciding who is accountable, where AI is used, how risk is tracked, and how issues are closed. The table below is a plain-language reference for each function.
The four functions at a glance
| Function | In plain language | What it typically produces |
|---|---|---|
| Govern | Who decides, and who is accountable. | A charter, named owners, policies, and a review rhythm. |
| Map | Where AI is used and who it affects. | A use-case inventory and a record of context and affected groups. |
| Measure | How risk and performance are tracked. | Defined measures, testing records, and findings that can be compared over time. |
| Manage | How issues are prioritized, owned, and closed. | A risk register, assigned actions, and an incident response path. |
Questions each function tends to raise
Govern
- Who has authority to approve or stop an AI use?
- Is there a written statement of how AI may and may not be used?
- How often is the arrangement reviewed?
Map
- Is there one list of every AI use, with a named owner for each?
- Who does each use affect, inside and outside the organization?
- Which uses rely on third-party models or data?
Measure
- What is measured for each use, and by whom?
- How are accuracy, bias, and reliability tested before and after launch?
- Where are the results recorded?
Manage
- How are risks ranked and assigned an owner?
- What happens when a measure falls outside its expected range?
- How do closed issues feed back into the inventory?
Where the other resources fit
The functions are not steps to complete once. Many organizations start with the use-case inventory (Map) and the charter (Govern), then build measurement and response around them. See the inventory template and the charter worksheet.
A team uses the four functions as headings on a one-page plan. Under Govern it names an approver. Under Map it lists its AI uses. Under Measure it picks one measure per use. Under Manage it assigns an owner to each open issue. The framework supplies the structure, and the organization supplies the content.
Turn the four functions into a working program.
We map your current AI use to Govern, Map, Measure and Manage, show where the gaps are, and give you an action roadmap.