The AI RMF Playbook is NIST's companion to AI RMF 1.0, released alongside the framework on January 26, 2023 and hosted at the NIST AI Resource Center. It lists suggested actions, transparency and documentation practices, and references for every subcategory of the Govern, Map, Measure and Manage functions, and is downloadable as PDF, CSV, Excel and JSON. NIST stresses it is 'neither a checklist nor a set of steps to be followed in its entirety', and says it will be updated after the AI RMF revision now under way.
| Document | NIST AI RMF Playbook — AI Risk Management Framework Playbook |
| Issued by | National Institute of Standards and Technology — AI Risk Management Framework |
| Type | Guidance |
| Status | In force |
| Published | Jan 26, 2023 |
| Effective | Jan 26, 2023 |
| Applies to | Voluntary companion to the AI RMF for any organization implementing it; commonly used by bank AI governance and model-risk teams to build control inventories. |
| Official source | airc.nist.gov ↗ |
| Use cases | AI governance (general) · Model risk management · Generative & agentic AI |
What are the key points of NIST AI RMF Playbook?
- Organized by the AI RMF Core: for each subcategory it offers suggested actions, transparency and documentation guidance, and references.
- Available in machine-readable formats (CSV, Excel, JSON) as well as PDF, which lets banks load it directly into GRC tools to build AI control libraries.
- Explicitly non-prescriptive: organizations select the actions relevant to their industry and use case rather than implementing all of them.
- NIST updates the Playbook roughly twice a year and states it will be revised after the AI RMF 1.0 revision under the White House AI Action Plan.
- Sits with other AI RMF resources at the NIST AI Resource Center: the Roadmap, crosswalks to ISO/IEC 42001 and other standards, and use-case profiles.
What did NIST AI RMF Playbook change for banks?
The Playbook turned the abstract Core of the AI RMF into concrete, inventory-able actions. For banks this is the layer that maps most directly onto existing three-lines-of-defense control frameworks: model-risk and technology-risk teams generally build their AI control libraries from the Playbook's subcategory actions and then evidence them to internal audit and examiners.
Is the NIST AI RMF Playbook a checklist?
No. NIST states it is neither a checklist nor a set of steps to be followed in its entirety; organizations pick the suggested actions relevant to their context.
Where can I download the AI RMF Playbook?
From the NIST AI Resource Center at airc.nist.gov, in PDF, CSV, Excel and JSON formats.
| Date | Document | Status |
|---|---|---|
| Apr 7, 2026 | AI RMF critical-infrastructure profile (concept note) — Concept Note: AI RMF Profile on Trustworthy AI in Critical Infrastructure | Proposed |
| Jan 12, 2026 | CAISI RFI on AI agent security (2026) — Request for Information: Security Considerations for Artificial Intelligence Agents | Proposed |
| Dec 16, 2025 | NIST IR 8596 (Cyber AI Profile) — Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile), NIST IR 8596 — preliminary draft | Proposed |
| Aug 14, 2025 | NIST COSAiS control overlays — Control Overlays for Securing AI Systems (COSAiS): SP 800-53 overlays for generative, predictive and agentic AI | Proposed |
| Mar 24, 2025 | NIST AI 100-2e2025 (Adversarial ML) — Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2e2025) | Final |
| Jul 26, 2024 | NIST AI 600-1 (Generative AI Profile) — Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1) | In force |
Follow every document these regulators publish
6 curated AI stories for banking executives · Every morning · Free
Subscribe to BankingNewsAI →