NIST AI Risk Management Framework
The US National Institute of Standards and Technology's voluntary framework for managing AI risk, organised around four functions: Govern, Map, Measure, Manage. Buyers increasingly use it as a procurement checklist.
Which edition this covers
NIST AI 100-1, AI Risk Management Framework 1.0 (January 2023)
Checked against the source on 2026-09-13 · read the source
Not covered
- NIST AI 600-1, the Generative AI Profile, which is a companion publication and not part of AI 100-1.
- The AI RMF Playbook, which is guidance rather than framework text and is revised separately.
- Any successor version. This entry names 1.0 and nothing later.
What Trooth witnesses
Read on a schedule, republished with the date
- Govern: the AI governance and accountability statements you publish
- Map: system context, intended use, and known limitations from your AI system cards
- Measure: the testing and evaluation practices you disclose
- Manage: how you say you handle issues, and whether those statements change
What Trooth does not do
Said plainly, so nobody guesses
- Issue a certification, attestation, or audit opinion. Only a licensed auditor can do that.
- Score your AI risk or claim a system is safe. Trooth publishes what you disclosed, not a verdict on it.
- Give legal advice or tell you whether you are compliant. That call is yours and your counsel's.
Why this is worth anything to a buyer
A questionnaire answer is a claim typed once and never checked again. NIST AI RMF here is the rulebook, not the product: what Trooth publishes for it is read from your live systems on a schedule and republished with the date it was last seen, so a buyer checking your company can tell the difference between what was true a year ago and what is true this morning. That is a smaller promise than an audit, and it is one we can actually keep. The full method is on the methodology page.