AI Governance & Compliance

NIST AI RMF: Turn the AI Risk Management Framework Into Working Governance

The NIST AI Risk Management Framework (AI RMF) is the United States government's voluntary framework for identifying, measuring, and managing the risks of artificial intelligence systems, organized around four functions: Govern, Map, Measure, and Manage. Petronella Technology Group helps organizations implement the AI RMF as a working program, with the policies, risk registers, and evidence that customers, regulators, and auditors are starting to ask for.

BBB A+ Since 2003 MIT AI-Certified Leadership Securing Businesses Since 2002

Last Updated: August 22, 2026

What Is the NIST AI RMF?

The NIST AI Risk Management Framework is a voluntary framework published by the National Institute of Standards and Technology to help organizations govern the risks that come with designing, buying, deploying, and operating AI systems. Version 1.0 was published in January 2023 as NIST AI 100-1, developed under the direction of the National Artificial Intelligence Initiative Act of 2020, and it has quickly become the reference point that US customers, insurers, and government agencies use when they ask, "how do you manage AI risk?"

The framework's core insight is that AI risk is not just a technical problem. A model can be accurate and still be harmful: it can leak sensitive data, produce biased outcomes, drift silently after deployment, or be manipulated by a prompt injection attack. The AI RMF therefore addresses the full lifecycle - the people and accountability structures around AI, the context each system operates in, the metrics used to evaluate it, and the actions taken when risk is found. It applies whether you build models in-house, fine-tune open-source models, or simply let employees use commercial chatbots and copilots.

Key Takeaways

  • The NIST AI RMF (AI 100-1) is the leading US framework for AI risk management, organized around four functions: Govern, Map, Measure, and Manage.
  • It is voluntary, but it is rapidly becoming the de facto standard in vendor questionnaires, cyber insurance applications, and government contracting conversations.
  • The AI RMF is a framework, not a certification. If you need a certifiable AI management system, it pairs naturally with ISO 42001; the two share most of their underlying work.
  • Petronella Technology Group implements the framework end to end, from an AI risk assessment and AI governance framework to the recurring measurement and management program that keeps it alive.

The Four Core Functions: Govern, Map, Measure, Manage

The framework organizes everything an organization should do about AI risk into four functions. Govern is the cross-cutting function that makes the other three possible; Map, Measure, and Manage are applied to each AI system or use case in scope.

Govern: Build the Culture and Accountability

Govern establishes who is responsible for AI risk and under what rules. It covers policies, roles, escalation paths, workforce awareness, and how AI risk connects to the rest of enterprise risk management. In practice this is where an AI acceptable use policy, an AI system inventory, and a review board or approval workflow get created. Without Govern, the other functions are one-time projects that decay.

Map: Establish Context and Identify Risk

Map documents what each AI system actually does, who it affects, and what could go wrong. That means categorizing the use case, identifying the data it touches, naming the people and processes that depend on its output, and surfacing risks specific to the context: a chatbot answering benefits questions carries different risks than a model scoring loan applications. Mapping is also where shadow AI gets discovered and brought into the inventory.

Measure: Analyze and Track the Risk

Measure applies quantitative and qualitative methods to evaluate the risks identified during mapping. It includes testing for accuracy, bias, robustness, and security before deployment, and monitoring for drift, misuse, and degraded performance afterward. For generative systems this is where red-teaming and LLM security testing live: prompt injection, jailbreaks, data leakage, and insecure output handling.

Manage: Prioritize and Act

Manage takes the measured risks and does something about them: accept, mitigate, transfer, or retire the system. It covers risk treatment plans, resourcing decisions, third-party AI risk, and the response playbooks used when an AI system misbehaves in production, which is where a documented AI incident response capability plugs in.

Why a Voluntary Framework Now Has Teeth

No law forces a private company to adopt the NIST AI RMF. What forces the issue is everyone around you. Enterprise customers have started adding AI governance sections to vendor security questionnaires, and "do you follow the NIST AI RMF?" is the most common phrasing. Cyber insurance carriers are asking how AI tools are inventoried and controlled before they price a policy. Federal agencies and prime contractors, already anchored to NIST for cybersecurity through frameworks like NIST SP 800-171, default to NIST guidance when they evaluate how a supplier handles AI.

There is also a defensive reason to adopt it. When an AI system causes harm - a hallucinated answer given to a customer, a discriminatory screening outcome, a data leak through a chatbot - the first question in any dispute is whether the organization acted reasonably. A documented, framework-based AI risk program is the strongest available evidence of reasonable care. An undocumented pile of AI tools that nobody formally approved is the opposite.

The practical problem is that the framework tells you what outcomes to achieve, not how to achieve them in a 50-person company. That translation is the service. Petronella Technology Group has spent 24+ years turning frameworks into operating reality for regulated small and mid-sized businesses, from HIPAA to CMMC, and applies the same discipline here: scoped policies people actually follow, controls matched to the size of the risk, and evidence generated as a byproduct of normal work rather than a scramble before an audit.

NIST AI RMF vs ISO 42001 vs NIST 800-37 RMF

Three frameworks with similar names cause constant confusion in AI governance conversations. They are related but answer different questions, and choosing the wrong one wastes budget.

FrameworkWhat It IsCertifiable?Best For
NIST AI RMF (AI 100-1)Voluntary US framework for managing AI risk across the lifecycle via Govern, Map, Measure, ManageNo - a framework you align to and attest againstUS organizations that need a defensible AI risk program and answers for customer questionnaires
ISO/IEC 42001International standard for an auditable AI management system (AIMS)Yes - third-party certification auditOrganizations whose customers or markets require a certificate, especially internationally
NIST 800-37 RMFThe classic Risk Management Framework for authorizing federal information systemsNo - an authorization process, not a certificateFederal systems and contractors working toward an Authority to Operate

The good news: the work overlaps heavily. An AI system inventory, impact assessments, testing procedures, and governance policies built for the NIST AI RMF map almost directly into an ISO 42001 management system. We routinely build the AI RMF program first, because it delivers risk reduction immediately, and treat certification as a later milestone if the business case appears. Our AI governance maturity model shows where each organization sits on that path.

The Generative AI Profile (NIST AI 600-1)

In July 2024, NIST published a companion document that most organizations now need more urgently than the base framework: the Generative AI Profile, NIST AI 600-1. It applies the AI RMF specifically to generative systems - chatbots, copilots, image generators, and the retrieval-augmented applications built on top of large language models - and catalogs the risks unique to or amplified by them.

Those risks will sound familiar to anyone who has watched employees adopt AI tools faster than IT can review them: confabulation (confidently wrong output), data privacy leakage through prompts and training, harmful or biased content, information security attacks such as prompt injection, intellectual property exposure, and the erosion of human oversight when people over-trust fluent output. For each, the profile suggests concrete actions mapped back to the four functions.

This is where governance meets engineering. Writing a policy that says "validate model output" is easy; deciding how a specific retrieval pipeline should ground its answers, log its sources, and fail safely is an engineering decision. Because Petronella Technology Group runs production AI agents in its own business - Penny for sales, Eve for emergency response, ComplyBot for compliance chat, and Joe for scheduling, automating 87% of routine tasks - our recommendations come from operating these systems, not just auditing them. Organizations that want the controls without sending data to third-party clouds pair the profile with private AI deployment, where models run entirely on infrastructure you control.

Not Sure Where Your AI Risk Actually Is?

Start with a scoped AI risk assessment. We inventory every AI system and shadow tool in use, map each one to the AI RMF, and hand you a prioritized risk register in plain English.

The Seven Characteristics of Trustworthy AI

The framework defines what "good" looks like through seven characteristics of trustworthy AI. Every mapping and measurement activity ultimately tests a system against these, and they make a practical checklist for evaluating any AI tool before it touches production data:

  • Valid and reliable: the system performs as intended, with accuracy demonstrated for its actual use case, not just a vendor benchmark.
  • Safe: it does not endanger human life, health, property, or the environment under foreseeable conditions and misuse.
  • Secure and resilient: it withstands adversarial attack, including prompt injection, model manipulation, and data poisoning, and recovers when disrupted. This overlaps directly with enterprise AI security.
  • Accountable and transparent: a named human owns each system, and enough information exists about how it works for stakeholders to understand decisions that affect them.
  • Explainable and interpretable: outputs can be explained at a level appropriate to the audience, from a customer asking "why was I denied?" to an engineer debugging drift.
  • Privacy-enhanced: data minimization, consent, and confidentiality are designed in, which matters intensely when models are trained or prompted with customer, patient, or employee data.
  • Fair, with harmful bias managed: the organization actively looks for and mitigates biased outcomes rather than assuming the vendor handled it.

No system maximizes all seven at once; the framework is explicit that trade-offs are contextual. What matters is that someone with authority looked, measured, decided, and wrote the decision down.

How We Implement the NIST AI RMF

Every engagement follows a five-step path from zero to an operating program. Organizations that already have pieces in place enter mid-stream; the sequence stays the same.

1

Discover and Inventory

You cannot govern what you have not found. We inventory sanctioned AI systems, embedded AI features inside SaaS products, and the unsanctioned tools employees adopted on their own, using the same discovery techniques behind our shadow AI detection service. Each entry gets an owner, a purpose, and a data-sensitivity rating.

2

Stand Up Govern

We draft the governance backbone: an AI policy suite including acceptable use, a lightweight review-and-approval workflow sized to your organization, defined roles, and reporting lines into existing risk management. The documentation discipline comes from the same team that builds compliance evidence with the ComplianceArmor® platform, so every artifact is written to survive an auditor's reading.

3

Map Each Use Case

For every in-scope system we document context, affected people, data flows, and failure modes, producing an impact assessment proportional to the risk: a marketing copy assistant gets a page, a system that touches patient or financial data gets a rigorous review tied to your HIPAA, CMMC, or SOC 2 obligations.

4

Measure What Matters

We define tests and metrics per system: pre-deployment evaluation, security testing against the OWASP LLM risks, bias checks where decisions affect people, and production monitoring for drift and misuse. Findings land in a risk register with severity and ownership, not in a slide deck.

5

Manage and Operate

Risk treatment decisions get made and documented, incident playbooks get written and exercised, and the program moves onto a recurring cadence: quarterly inventory refresh, re-measurement on major model changes, and an annual program review. Delivered standalone or as part of ongoing AI governance consulting.

Who Needs the NIST AI RMF?

Defense Contractors

Contractors handling CUI face a compounding problem: employees pasting controlled data into public AI tools can create a reportable incident. An AI RMF program built alongside CMMC keeps AI usage inside the enclave boundary. As a CyberAB Registered Provider Organization (RPO #1449), Petronella Technology Group aligns AI governance with your NIST SP 800-171 system security plan instead of bolting it on.

Healthcare Practices

Ambient scribes, coding assistants, and chatbots are entering clinics faster than policy can keep up, and every one of them touches PHI. Mapping those tools under the AI RMF and the HIPAA Security Rule together prevents the worst outcome: discovering an unvetted AI vendor in the middle of a breach investigation.

Financial and Professional Services

Firms using AI for underwriting, screening, research, or client communication carry fairness and confidentiality risk with every output. A documented Measure function - accuracy, bias, and leakage testing - is what separates defensible AI adoption from liability.

Any Business Answering Questionnaires

If your customers send security questionnaires, AI governance questions are already in them or will be within the year. A real AI RMF program turns a week of awkward drafting into an afternoon of copy-paste, and an AI readiness assessment shows how far you are from that position today.

DIY Adoption vs Managed Implementation

ApproachWhat You GetWhere It Falls Short
Read the framework and self-implementFree documents, the NIST AI RMF Playbook, and full controlThe framework is outcome-based by design. Translating it into right-sized policies, tests, and evidence is weeks of specialist work, and internal teams rarely get the time.
Generic policy templatesFast paperworkTemplates govern nothing. A policy with no inventory, no measurement, and no owner fails the first serious questionnaire or audit reading.
Implementation with Petronella Technology GroupInventory, governance structure, per-system impact assessments, security and bias testing, risk register, incident playbooks, and audit-ready evidence, delivered by a team that operates production AI dailyRequires a scoping conversation and access to your tool inventory during discovery.

Engagements are scoped to clear deliverables without long-term contract lock-in, and quotes start from a fixed discovery phase so you know the cost before committing to the full program.

"Craig takes the time to understand our business model, not just our technology stack. It makes his recommendations more strategic and tailored to our actual goals." Daniel Lee, TrustIndex verified review

That review reflects the standard we hold across 92 verified TrustIndex reviews (4.7 rating) and 15 Google reviews (5.0 rating).

Guidance from People Who Build and Secure AI

AI governance advice is only as good as the adviser's contact with real systems. The program at Petronella Technology Group is led by Craig Petronella, an MIT AI-certified technologist, cybersecurity expert witness, and author of "Beautifully Inefficient," his book on AI, human creativity, and innovation. The company has operated its own AI division since 2023, building and running production agents on private infrastructure, which means the risks the AI RMF describes - drift, leakage, over-trust, injection - are problems our team has engineered against firsthand.

That builder's perspective sits on top of a 24-year compliance foundation. The same organization guides defense contractors through CMMC, medical practices through HIPAA, and growing companies through SOC 2, so AI governance lands as an extension of your existing compliance program rather than a parallel bureaucracy. Headquartered in Raleigh, North Carolina, we serve the Research Triangle - Durham, Cary, Chapel Hill, and Apex - alongside clients nationwide, with commentary on emerging threats featured on NBC, ABC, CBS, FOX, and WRAL.

NIST AI RMF FAQ

What is the NIST AI RMF in simple terms?

It is a playbook from the US National Institute of Standards and Technology for keeping artificial intelligence from hurting your business or the people it affects. It tells organizations to inventory their AI, understand what each system could do wrong, test and monitor for those failures, and assign real people to act on what they find, organized into four functions: Govern, Map, Measure, and Manage.

Is the NIST AI RMF mandatory?

No law requires private companies to adopt it. In practice it is enforced socially and contractually: enterprise customers reference it in vendor questionnaires, insurers ask about AI governance on applications, and federal-adjacent work defaults to NIST guidance. It is voluntary the way strong passwords are voluntary.

Can we get certified against the NIST AI RMF?

No. The AI RMF is a framework you align with and attest against, not a certifiable standard. If your market requires a certificate, ISO/IEC 42001 provides an auditable AI management system, and a program built on the AI RMF covers most of the ISO 42001 groundwork already.

What are the four functions of the AI RMF?

Govern establishes policies, accountability, and culture across the whole organization. Map documents each AI system's context, purpose, and potential harms. Measure tests and monitors systems for accuracy, security, bias, and drift. Manage prioritizes the measured risks and acts: mitigate, accept, transfer, or retire.

What is the Generative AI Profile?

NIST AI 600-1, published in July 2024, applies the framework specifically to generative AI such as chatbots and LLM-based applications. It catalogs generative-specific risks, including confabulation, prompt injection, data leakage, and intellectual property exposure, and maps suggested actions back to the four functions. Most organizations adopting AI today should start here.

Does the AI RMF apply if we only use AI tools rather than build them?

Yes. The framework covers deployers and users, not just developers. Choosing vendors, configuring tools, deciding what data employees may paste into them, and monitoring outputs are all lifecycle activities the framework addresses. For most small and mid-sized businesses, third-party and employee AI use is the entire risk surface.

How does the AI RMF relate to CMMC, HIPAA, or SOC 2?

It complements them. Those frameworks govern the confidentiality and integrity of data and systems generally; the AI RMF governs the specific risks AI introduces on top, such as model behavior, bias, and misuse. We implement them together so an AI system that touches CUI or PHI is covered by one coherent set of controls, and documented AI governance increasingly strengthens answers on the security questionnaires those frameworks generate.

How much does NIST AI RMF implementation cost?

Cost depends on how many AI systems are in scope, how sensitive the data they touch is, and how much governance already exists, so engagements are quoted from a fixed-price discovery phase. Call 919-348-4912 or schedule a free consultation for a scoped quote.

Govern Your AI Before It Governs You

Petronella Technology Group has turned frameworks into working programs for businesses in Raleigh, the Triangle, and nationwide since 2002. The AI RMF is next.