RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The record · 100 retrospective records ↗

The record / Safety & policy

Safety & policy / From the record · 26 January 2023 event · prepared 16 September 2026

NIST built a voluntary framework around four functions

The AI RMF, released in January 2023, organises AI risk management into govern, map, measure and manage, without certifying any system.

Visual published with the cited source for this record: NIST built a voluntary framework around four functions
Visual published with the cited source, shown for identification of the record. Credit: nist.gov · source page ↗ Rights: owner-review-pending.

A framework published without regulatory force

On 26 January 2023, the US National Institute of Standards and Technology released the first version of the AI Risk Management Framework. The announcement is explicit that the document is 'for voluntary use by organizations designing, developing, deploying or using AI systems,' and it carries no penalty for non-adoption and no accreditation scheme attached to it. NIST describes the document, as retrieved on 16 September 2026 from its living framework page, as intended to help organisations 'incorporate trustworthiness considerations into the design, development, use, and evaluation' of AI systems, a description of intent rather than of enforceable obligation.

Four functions, not a scorecard

The framework is organised around four functions, described on NIST's AI Resource Center as Govern, Map, Measure and Manage. Govern covers the policies, roles and culture an organisation puts around AI risk before any system is built. Map covers identifying the context and likely impacts of a specific AI use case. Measure covers the analytical and testing methods used to assess identified risks. Manage covers the actions taken in response to measured risk, including deciding whether to proceed, mitigate or stop. None of the four functions specifies a pass or fail threshold; each is a category of activity an organisation is meant to carry out and document, with the specific metrics and tolerances left to the organisation and sector.

What the framework does not do

The framework does not test, certify or grade any AI system, and it does not itself resolve what counts as an acceptable level of risk in a given deployment. Because it is deliberately generic across sectors and system types, an organisation that adopts it still has to build or borrow the specific evaluation methods that fill in the Measure function; the framework describes the activity of measuring, not a fixed test suite. NIST's own materials note the document is subject to revision, and a companion resource specific to generative systems followed in July 2024, extending rather than replacing the original four-function structure. A claim that a product is 'NIST AI RMF compliant' is therefore a claim about following a voluntary process, not a claim verified by NIST or backed by any published conformity assessment.

  • Which of the four functions has an organisation actually documented, as opposed to referenced in marketing language?
  • What specific measurement methods fill the Measure function for this system, and who defined the acceptance threshold?
  • Has the organisation revisited its Map and Measure work since the system's last material change, or is the assessment now stale?

The framework's contribution was to give organisations a common structure for AI risk conversations that previously had none; it does not substitute for the sector-specific testing and evidence that a safety claim still requires.

Sources & reading trail

NIST Risk Management Framework Aims to Improve Trustworthiness of Artificial Intelligence ↗

Announces the AI RMF's release date and states the framework is for voluntary use.

Source published: 26 January 2023 · Retrieved: 16 September 2026

AI Risk Management Framework ↗

Living overview page describing the framework's purpose and noting the later Generative AI Profile.

Source published: Not established · Retrieved: 16 September 2026

AI RMF Resource Center: Applying the AI RMF ↗

Describes the four core functions, Govern, Map, Measure and Manage, that structure the framework.

Source published: Not established · Retrieved: 16 September 2026

Papers and official documents establish the record; the reading and the questions are Model Field Guide editorial analysis. This retrospective draft does not imply the site published on the event date.