What is the NIST AI Risk Management Framework?
The NIST AI Risk Management Framework, published as NIST AI 100-1 in January 2023 by the United States National Institute of Standards and Technology, is a framework for identifying and managing the risks that AI systems create. NIST produced it as directed by the National Artificial Intelligence Initiative Act of 2020, and describes it as intended to be voluntary, rights-preserving, non-sector-specific and use-case agnostic, giving organisations of any size and sector flexibility in how they apply it.
The framework comes in two parts. Part 1 frames AI risk and sets out what makes an AI system trustworthy. Part 2 contains the Core, which is the operational half.
Part 1 identifies seven characteristics of trustworthy AI: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. The structure among them is deliberate. Validity and reliability is the necessary condition on which the others rest, and accountability and transparency runs across all of them rather than sitting alongside. NIST is explicit that creating trustworthy AI requires balancing the characteristics against the system's context of use, which is an acknowledgement that they can pull against each other in practice.
Part 2 sets out four core functions, each broken into categories and subcategories. Govern cultivates and implements a culture of risk management, sets out the processes and documentation that anticipate and manage risk, incorporates impact assessment, and connects the technical work to organisational principles, policies and strategic priorities. Map establishes the context needed to frame risks related to an AI system. Measure applies quantitative, qualitative and mixed-method techniques to assess, benchmark and monitor AI risk, drawing on what Map produced and feeding what Manage does, and expects systems to be tested before deployment and regularly while in operation. Manage allocates resources to the risks that have been mapped and measured, on a regular basis and as defined by Govern, and covers plans to respond to, recover from and communicate about incidents.
Govern applies across every stage of an organisation's AI risk management. Map, Measure and Manage are applied to specific systems and at specific points in the AI lifecycle. NIST publishes a companion Playbook of suggested actions, itself voluntary, and released NIST AI 600-1, the Generative AI Profile, on 26 July 2024 to address risks particular to generative systems.
Who does the NIST AI Risk Management Framework apply to?
Nobody, as a matter of law. This is the point most often misstated. The AI RMF is not a regulation, it creates no obligations, and it does not bind organisations in the United States, let alone in Australia. NIST is a standards body, not a regulator, and the framework itself lists being voluntary alongside being risk-based, resource-efficient and pro-innovation among the things it strives for.
Its actual reach is through adoption. Organisations use it because it provides a structure for AI governance that is publicly documented, vendor-neutral and detailed enough to audit against, which is a combination that little else offered when it was published.
It is aimed at any organisation designing, developing, deploying or using AI systems. That framing matters for Australian readers, because it means the framework speaks to buyers and users of AI, not only to builders. An organisation that purchases every model it uses still has a full set of Govern, Map, Measure and Manage responsibilities under the framework's logic.
Where does the NIST AI Risk Management Framework fit in Australia?
Through the Voluntary AI Safety Standard, and through control design.
Australia's Voluntary AI Safety Standard, published by the Department of Industry, Science and Resources on 5 September 2024, sets out 10 guardrails covering accountability, risk management, data governance, testing, human oversight, informing end users, contestability, supply chain transparency, record keeping and stakeholder engagement. The standard states that it draws on and is aligned with a range of international standards, that the most important are AS ISO/IEC 42001:2023 on AI management systems and NIST AI RMF 1.0 on AI risk management, and that each requirement in the guardrails is aligned with relevant international and local standards or practices.
That standard has since moved on, and a 2026 control set built only from the guardrails is out of date. On 21 October 2025 the department published Guidance for AI Adoption, which sets out 6 essential practices, and which the department describes on the Voluntary AI Safety Standard page as updated and simplified guidance that evolves that standard. The guardrails remain published, so the alignment statement above still stands as the department's own account of where the structure came from, but current work should be mapped against the 6 essential practices.
The practical consequence is that an Australian organisation following the department's guidance is already working to a structure with the AI RMF in its lineage. Reading the NIST framework is therefore a way of understanding why the Australian material is shaped as it is, and of borrowing the more detailed categories and subcategories that the Australian guidance summarises.
What the framework cannot do is discharge an Australian legal obligation. Privacy duties come from the Australian Privacy Principles, including the automated decision-making transparency obligation commencing on 10 December 2026. Operational risk and service provider duties for regulated entities come from standards such as APRA CPS 230. Work health and safety duties, anti-discrimination duties and sector obligations all sit independently. Mapping controls to the AI RMF is useful evidence of a considered approach, and nothing more than that.
What should practitioners do with the NIST AI Risk Management Framework?
Use it as a control library rather than a certification target. There is no certification, so the value is in the categories and subcategories, which are specific enough to turn into named controls with owners and evidence.
Start with Govern, because it is the only function that spans the whole programme and because most Australian gaps are governance gaps rather than technical ones. Confirm who is accountable for each AI system, what policy it sits under, and how impacts are assessed before deployment.
Then run Map against the actual inventory. Framing risk requires knowing the context of use, the affected people and the lifecycle stage, which surfaces the systems nobody has assessed. Measure is where most programmes are weakest: pre-deployment testing and regular in-operation testing are both expected, and few organisations do the second.
Where the organisation already works to the department's Australian guidance, whether the 10 guardrails or the 6 essential practices published to evolve them, map it against the AI RMF once and maintain a single control set rather than parallel registers. Where it works to APRA CPS 230 or an ISO management system, do the same. The framework is at its most useful as connective tissue between obligations that already exist. Related material sits under the AI governance hub and across the GRC section.
Bottom line
The AI RMF is a voluntary United States framework with no legal force in Australia, and treating it as a compliance target is the common error. Its value is structural: four functions and a detailed set of categories that convert cleanly into named controls with owners and evidence. Australian practitioners have a further reason to read it, because the Voluntary AI Safety Standard states it is aligned with NIST AI RMF 1.0 and AS ISO/IEC 42001:2023, so the local guardrails already carry its shape. Those 10 guardrails have since been reworked into the 6 essential practices in Guidance for AI Adoption, published 21 October 2025, so map against the current version. Map it once against existing obligations and maintain one control set, rather than running parallel registers that drift.
TheAICommand. Intelligence, At Your Command.*
TheAICommand. Intelligence, At Your Command.
