Skip to main content
    Regulatory alignment · NIST AI RMF

    Voluntary, and treated as the baseline anyway.

    The NIST AI Risk Management Framework — NIST AI 100-1, released as AI RMF 1.0 on 26 January 2023 — is becoming the common language for trustworthy AI in the United States. It carries no force of law, and regulators, auditors and enterprise risk teams increasingly treat it as the expectation.

    The four functionsThe Generative AI ProfileAll frameworks

    No compliance claim. iTmethods makes no compliance, certification or accreditation claim under the NIST AI Risk Management Framework or any other framework named on this page. We are not certified against, accredited for, or approved under any of them. Alignment is not compliance. The determination belongs to your own risk function, and nothing here transfers it to us.

    The four functions

    Govern, Map, Measure, Manage.

    The framework organises AI risk work into four core functions. The difficulty is not understanding them, it is running them.

    Govern

    The policies, roles and accountability around AI risk. The function most organizations can describe and fewest can evidence on a given day.

    Who owns this, by name?

    Map

    Context, intended use and where a system sits in the business. Mapping goes stale the moment a use case moves, which is constantly.

    When was yours last true?

    Measure

    Analysing and tracking what the system actually does. Measurement is only credible if it happened at the time rather than at review.

    Measured when, exactly?

    Manage

    Acting on what the other three surface: prioritising, treating and monitoring risk over the lifecycle rather than at a point.

    What did you act on last quarter?

    Each function is easy to describe and hard to evidence continuously. An annual documentation exercise satisfies the shape of the framework and not its intent, which is where most programs stall.

    The Generative AI Profile

    A companion profile, and the one buyers actually cite.

    NIST AI 600-1, published 26 July 2024, applies the four functions to generative systems specifically.

    The Generative AI Profile is not a second framework. It identifies the risks that are particular to generative systems and proposes actions against them, organised under the same Govern, Map, Measure and Manage structure as AI RMF 1.0. When an enterprise risk team asks which NIST document applies to a model-backed workflow, this is usually the one they mean.

    It is the profile, rather than the parent framework, that most often turns up in a vendor questionnaire — which is why it is named here rather than left implied.

    Putting it into practice

    Four functions that run, rather than four documents that exist.

    Operationalising the framework means turning the functions into something continuous, not a once-a-year exercise.

    Reign produces the operating record the four functions draw on: what was governed, what was mapped to which risk, what was measured at the moment of each action, and what was done about it. Whether that adds up to a mature program is your risk function’s assessment to make.

    Reign is aligned to the NIST AI Risk Management Framework and its Generative AI Profile. It is not certified against either, no product can be, and no product makes an institution compliant with either. No authority responsible for them endorses, approves or recommends Reign or iTmethods.

    Next step

    Turn the four functions into a running record.

    We will look at which of Govern, Map, Measure and Manage your estate could evidence today without a documentation project.