Skip to main content

NIST AI Risk Management Framework

The US National Institute of Standards and Technology's voluntary framework for managing AI risk, organised around four functions: Govern, Map, Measure, Manage. Buyers increasingly use it as a procurement checklist.

Which edition this covers

NIST AI 100-1, AI Risk Management Framework 1.0 (January 2023)

Checked against the source on 2026-09-13 · read the source

Not covered

  • NIST AI 600-1, the Generative AI Profile, which is a companion publication and not part of AI 100-1.
  • The AI RMF Playbook, which is guidance rather than framework text and is revised separately.
  • Any successor version. This entry names 1.0 and nothing later.

What Trooth witnesses

Read on a schedule, republished with the date

  • Govern: the AI governance and accountability statements you publish
  • Map: system context, intended use, and known limitations from your AI system cards
  • Measure: the testing and evaluation practices you disclose
  • Manage: how you say you handle issues, and whether those statements change

What Trooth does not do

Said plainly, so nobody guesses

  • Issue a certification, attestation, or audit opinion. Only a licensed auditor can do that.
  • Score your AI risk or claim a system is safe. Trooth publishes what you disclosed, not a verdict on it.
  • Give legal advice or tell you whether you are compliant. That call is yours and your counsel's.

Why this is worth anything to a buyer

A questionnaire answer is a claim typed once and never checked again. NIST AI RMF here is the rulebook, not the product: what Trooth publishes for it is read from your live systems on a schedule and republished with the date it was last seen, so a buyer checking your company can tell the difference between what was true a year ago and what is true this morning. That is a smaller promise than an audit, and it is one we can actually keep. The full method is on the methodology page.