AI Regulation Tracker · NIST · Framework

What does NIST AI RMF 1.0 say about AI in banking?

Published Jan 26, 2023 · Last reviewed Aug 26, 2026

NIST published the AI Risk Management Framework 1.0 (NIST AI 100-1) on January 26, 2023, as directed by the National AI Initiative Act of 2020. It is voluntary and organizes AI risk management into four functions — Govern, Map, Measure and Manage — and defines seven characteristics of trustworthy AI: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. NIST has said the framework is being revised as part of the July 2025 White House AI Action Plan.

DocumentNIST AI RMF 1.0Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1
Issued byNational Institute of Standards and Technology — AI Risk Management Framework
TypeFramework
StatusIn force
PublishedJan 26, 2023
EffectiveJan 26, 2023
Applies toVoluntary; any organization designing, developing, deploying or using AI systems. Widely adopted by US banks as the scaffold for enterprise AI governance.
Official sourcenist.gov
Use casesAI governance (general) · Model risk management · Generative & agentic AI · Third-party & vendor AI

What are the key points of NIST AI RMF 1.0?

  • Released January 26, 2023 after two public drafts (March and August 2022) and a 2021 request for information; developed under the National Artificial Intelligence Initiative Act of 2020.
  • Part 1 explains how organizations should frame AI risk and lists seven trustworthiness characteristics; Part 2 is the Core, built from four functions: Govern (cross-cutting), Map, Measure and Manage.
  • Each function breaks into categories and subcategories of outcomes (e.g., Govern 1.1: legal and regulatory requirements are understood, managed and documented) that organizations tailor to their context.
  • Explicitly rights-preserving and sector-agnostic; intended to be used alongside existing frameworks such as NIST's Cybersecurity Framework and Privacy Framework.
  • Companion resources: the online AI RMF Playbook, a Roadmap, and crosswalks to ISO/IEC standards and other frameworks, hosted at the NIST AI Resource Center (airc.nist.gov).
  • 'Profiles' — use-case or sector implementations of the Core — are the mechanism for later work such as the Generative AI Profile (AI 600-1) and the 2026 critical-infrastructure profile.

What did NIST AI RMF 1.0 change for banks?

Before 2023, US banks had model risk management guidance (SR 11-7 / OCC 2011-12) but no widely accepted, examiner-legible structure for governing AI as an enterprise risk rather than as individual quantitative models. The AI RMF supplied that structure, and its role grew when the April 2026 interagency model-risk revision left generative and agentic AI to banks' broader risk programs: institutions now routinely present NIST-aligned Govern/Map/Measure/Manage programs to examiners as evidence of control over systems outside formal model-risk scope.

Is the NIST AI RMF mandatory for banks?

No. It is a voluntary framework. But it is the reference most US banks use to structure AI governance, and examiners increasingly expect to see something equivalent for generative and agentic AI that the 2026 model-risk guidance does not cover.

What are the four functions of the NIST AI RMF?

Govern, Map, Measure and Manage. Govern is cross-cutting culture and accountability; Map establishes context and identifies risks; Measure analyzes and tracks them; Manage prioritizes and acts on them.

Is the AI RMF being updated?

Yes. NIST states that AI RMF 1.0 is being revised as part of the White House AI Action Plan of July 2025; no revised draft had been published as of August 2026. The Playbook will be updated after the revision.

DateDocumentStatus
Apr 7, 2026AI RMF critical-infrastructure profile (concept note)Concept Note: AI RMF Profile on Trustworthy AI in Critical InfrastructureProposed
Jan 12, 2026CAISI RFI on AI agent security (2026)Request for Information: Security Considerations for Artificial Intelligence AgentsProposed
Dec 16, 2025NIST IR 8596 (Cyber AI Profile)Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile), NIST IR 8596 — preliminary draftProposed
Aug 14, 2025NIST COSAiS control overlaysControl Overlays for Securing AI Systems (COSAiS): SP 800-53 overlays for generative, predictive and agentic AIProposed
Mar 24, 2025NIST AI 100-2e2025 (Adversarial ML)Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2e2025)Final
Jul 26, 2024NIST AI 600-1 (Generative AI Profile)Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1)In force

Follow every document these regulators publish

6 curated AI stories for banking executives · Every morning · Free

Subscribe to BankingNewsAI →