# NIST AI RMF 1.0: Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1

Source: https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-1
Last updated: Sep 2, 2026

NIST published the AI Risk Management Framework 1.0 (NIST AI 100-1) on January 26, 2023, as directed by the National AI Initiative Act of 2020. It is voluntary and organizes AI risk management into four functions — Govern, Map, Measure and Manage — and defines seven characteristics of trustworthy AI: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. NIST has said the framework is being revised as part of the July 2025 White House AI Action Plan.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [NIST](https://www.bankingnewsai.com/ai-regulation/nist) |
| Type | Framework |
| Status | In force |
| Published | Jan 26, 2023 |
| Effective | Jan 26, 2023 |
| Applies to | Voluntary; any organization designing, developing, deploying or using AI systems. Widely adopted by US banks as the scaffold for enterprise AI governance. |
| Official text | https://www.nist.gov/itl/ai-risk-management-framework |

## Key points

- Released January 26, 2023 after two public drafts (March and August 2022) and a 2021 request for information; developed under the National Artificial Intelligence Initiative Act of 2020.
- Part 1 explains how organizations should frame AI risk and lists seven trustworthiness characteristics; Part 2 is the Core, built from four functions: Govern (cross-cutting), Map, Measure and Manage.
- Each function breaks into categories and subcategories of outcomes (e.g., Govern 1.1: legal and regulatory requirements are understood, managed and documented) that organizations tailor to their context.
- Explicitly rights-preserving and sector-agnostic; intended to be used alongside existing frameworks such as NIST's Cybersecurity Framework and Privacy Framework.
- Companion resources: the online AI RMF Playbook, a Roadmap, and crosswalks to ISO/IEC standards and other frameworks, hosted at the NIST AI Resource Center (airc.nist.gov).
- 'Profiles' — use-case or sector implementations of the Core — are the mechanism for later work such as the Generative AI Profile (AI 600-1) and the 2026 critical-infrastructure profile.

## What changed for banks

Before 2023, US banks had model risk management guidance (SR 11-7 / OCC 2011-12) but no widely accepted, examiner-legible structure for governing AI as an enterprise risk rather than as individual quantitative models. The AI RMF supplied that structure, and its role grew when the April 2026 interagency model-risk revision left generative and agentic AI to banks' broader risk programs: institutions now routinely present NIST-aligned Govern/Map/Measure/Manage programs to examiners as evidence of control over systems outside formal model-risk scope.

## Use cases it governs

- [AI governance (general)](https://www.bankingnewsai.com/ai-regulation/by-use-case#governance-general)
- [Model risk management](https://www.bankingnewsai.com/ai-regulation/by-use-case#model-risk)
- [Generative & agentic AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#generative-agentic-ai)
- [Third-party & vendor AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#third-party-vendors)

## Where is the official NIST AI RMF 1.0 PDF, and what does the framework contain?

The official NIST AI Risk Management Framework 1.0 is document NIST AI 100-1, published January 26, 2023, and the PDF is hosted by NIST at nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf (DOI 10.6028/NIST.AI.100-1). It has two parts. Part 1 frames AI risk — how it differs from traditional software risk, who the intended audience is, and the seven characteristics of trustworthy AI: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. Part 2 is the Core: four functions — Govern, Map, Measure and Manage — each broken into categories and subcategories of outcomes that an organization tailors into a 'profile' for its own context. The framework is voluntary. Its companions are the online AI RMF Playbook, a Roadmap, crosswalks to other standards, and the Generative AI Profile (NIST AI 600-1, July 26, 2024), also a NIST-hosted PDF. NIST states that AI RMF 1.0 is being revised under the July 2025 White House AI Action Plan; no revised draft has been published.

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| NIST AI 100-1 — AI RMF 1.0 (official PDF) | [NIST](https://www.bankingnewsai.com/ai-regulation/nist) | The framework document itself, January 26, 2023: Part 1 (framing risk, audience, trustworthiness characteristics) and Part 2 (the Core: Govern, Map, Measure, Manage) plus appendices on AI risk versus traditional software risk and on attributes of the framework. | Published Jan 26, 2023 | [official text](https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf) |
| AI RMF landing page | [NIST](https://www.bankingnewsai.com/ai-regulation/nist) | NIST's page for the framework, with the PDF, the Playbook, Roadmap, crosswalks, profiles and the notice that AI RMF 1.0 is being revised as part of the White House AI Action Plan. | Maintained | [NIST AI RMF 1.0](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-1) |
| AI RMF Playbook | [NIST](https://www.bankingnewsai.com/ai-regulation/nist) | Suggested actions, references and documentation guidance for every subcategory of the Core, hosted at the NIST AI Resource Center; NIST will update it after the framework revision. | Online | [official text](https://airc.nist.gov/airmf-resources/playbook/) |
| NIST AI 600-1 — Generative AI Profile (official PDF) | [NIST](https://www.bankingnewsai.com/ai-regulation/nist) | The July 26, 2024 profile of the AI RMF for generative AI: twelve risk categories unique to or exacerbated by generative systems, with suggested actions mapped to the Core. | Published Jul 26, 2024 | [NIST AI 600-1 (Generative AI Profile)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-600-1) |
| NIST AI 100-2 E2025 — Adversarial machine learning taxonomy | [NIST](https://www.bankingnewsai.com/ai-regulation/nist) | NIST's companion taxonomy of attacks on predictive and generative AI and their mitigations — the reference for the 'secure and resilient' characteristic. | Published Mar 2025 | [NIST AI 100-2e2025 (Adversarial ML)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-2e2025) |
| Concept note — AI RMF profile for critical infrastructure | [NIST](https://www.bankingnewsai.com/ai-regulation/nist) | April 7, 2026 concept note for a sector profile covering critical infrastructure, which includes the financial services sector. | Apr 2026 | [AI RMF critical-infrastructure profile (concept note)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-rmf-critical-infrastructure-profile-concept-note) |

The Core is what banks actually implement. Govern is cross-cutting: policies, accountability, workforce, culture and the processes that make the other three functions run. Map establishes context — the intended purpose, the deployment setting, the affected people, the risks and benefits — before a system is built or bought. Measure covers the metrics, tests and tracking that show whether the trustworthiness characteristics are met, including how the system is evaluated over time. Manage is the prioritisation and response: which risks are treated, transferred, avoided or accepted, and how incidents and decommissioning are handled. Each function's categories and subcategories are written as outcomes rather than controls, which is why the Playbook exists — it turns each outcome into suggested actions and the documentation an examiner would expect to see.

Profiles are the mechanism for sector-specific use. A profile is a selection and tailoring of Core outcomes for a use case, sector or technology; the Generative AI Profile is the first NIST-authored one and lists twelve risks — among them confabulation, data privacy, information security, harmful bias, intellectual property and value-chain integration — with actions mapped back to the Core subcategories. For a bank, an internal profile is typically the artefact that ties the framework to model risk management, third-party risk and information security programmes: the same Govern outcomes appear in each, and the Measure outcomes are where model validation evidence is filed.

Two practical notes on the documents themselves. The framework is voluntary and non-sector-specific; nothing in it creates an obligation, and US banking agencies have not incorporated it into guidance, though examiners increasingly expect something equivalent for generative and agentic AI that the April 2026 interagency model risk guidance leaves outside formal validation scope. And it is about to change: NIST says AI RMF 1.0 is being revised as part of the White House AI Action Plan of July 2025. Programmes built on the 1.0 Core will need a re-mapping when the revision lands; the Playbook will be updated after it.

### What this means in practice

- Cite the document, not a summary: NIST AI 100-1 (DOI 10.6028/NIST.AI.100-1) for the framework and NIST AI 600-1 for the generative AI profile — both PDFs are on nvlpubs.nist.gov and linked above.
- Build a written profile: select the Core subcategories that apply, record the tailoring, and map each to the bank's existing controls — that document is what examiners can read.
- Use the Playbook's suggested actions as the evidence checklist for each subcategory; it is the closest thing to an implementation guide NIST provides.
- Track the revision: when the revised framework is published, re-map the profile before the next examination cycle rather than after.

## FAQ

### Is the NIST AI RMF mandatory for banks?

No. It is a voluntary framework. But it is the reference most US banks use to structure AI governance, and examiners increasingly expect to see something equivalent for generative and agentic AI that the 2026 model-risk guidance does not cover.

### What are the four functions of the NIST AI RMF?

Govern, Map, Measure and Manage. Govern is cross-cutting culture and accountability; Map establishes context and identifies risks; Measure analyzes and tracks them; Manage prioritizes and acts on them.

### Is the AI RMF being updated?

Yes. NIST states that AI RMF 1.0 is being revised as part of the White House AI Action Plan of July 2025; no revised draft had been published as of August 2026. The Playbook will be updated after the revision.

## Compare

- [NIST AI RMF vs ISO 42001](https://www.bankingnewsai.com/ai-regulation/compare/nist-ai-rmf-vs-iso-42001): NIST AI RMF vs ISO/IEC 42001: Which Should a Bank Use?

## Which AI tools for banks does NIST AI RMF 1.0 apply to?

- [Model risk and AI governance](https://www.bankingnewsai.com/ai-tools/model-risk-governance) — NIST AI RMF: [ValidMind](https://www.bankingnewsai.com/vendors/validmind) · [Credo AI](https://www.bankingnewsai.com/vendors/credo-ai) · [SAS Model Risk](https://www.bankingnewsai.com/vendors/sas-model-risk) · [Monitaur](https://www.bankingnewsai.com/vendors/monitaur) · [Yields](https://www.bankingnewsai.com/vendors/yields-io)

## Related documents

- [AI RMF critical-infrastructure profile (concept note)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-rmf-critical-infrastructure-profile-concept-note) — Concept Note: AI RMF Profile on Trustworthy AI in Critical Infrastructure (Apr 7, 2026)
- [CAISI RFI on AI agent security (2026)](https://www.bankingnewsai.com/ai-regulation/documents/nist-caisi-rfi-ai-agent-security-2026) — Request for Information: Security Considerations for Artificial Intelligence Agents (Jan 12, 2026)
- [NIST IR 8596 (Cyber AI Profile)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ir-8596) — Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile), NIST IR 8596 — preliminary draft (Dec 16, 2025)
- [NIST COSAiS control overlays](https://www.bankingnewsai.com/ai-regulation/documents/nist-cosais-control-overlays) — Control Overlays for Securing AI Systems (COSAiS): SP 800-53 overlays for generative, predictive and agentic AI (Aug 14, 2025)
- [NIST AI 100-2e2025 (Adversarial ML)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-2e2025) — Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2e2025) (Mar 24, 2025)
- [NIST AI 600-1 (Generative AI Profile)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-600-1) — Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1) (Jul 26, 2024)
- [NIST SP 800-218A (SSDF profile for generative AI)](https://www.bankingnewsai.com/ai-regulation/documents/nist-sp-800-218a) — Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile (NIST SP 800-218A) (Jul 26, 2024)
- [NIST AI RMF Playbook](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-rmf-playbook) — AI Risk Management Framework Playbook (Jan 26, 2023)

Last reviewed Sep 2, 2026. Cite the official text (https://www.nist.gov/itl/ai-risk-management-framework) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-1
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
