NIST AI RMF templates are the question the framework itself refuses to answer. The
AI Risk Management Framework is deliberately outcome-based: it tells you what good looks like and
leaves the documentation entirely to you, which is why teams read it, agree with it, and then stall.
Why NIST AI RMF templates are the hard part
The framework was released on 26 January 2023 and is voluntary. It describes outcomes and
characteristics of trustworthy AI rather than prescribing artefacts, so there is no annex listing the
documents you must hold — no equivalent of a Statement of Applicability to work through.
That freedom is genuinely useful for a research lab and genuinely unhelpful for a compliance
function that has been asked to “align to the AI RMF” and needs to show something for it. The
practical move is to work backwards: take the four functions, and for each one decide what a sceptical
reviewer would ask to see.
NIST AI RMF templates by function: what each one produces

NIST organises the framework core into Govern, Map, Measure and Manage. Govern is
cross-cutting; the other three run roughly in sequence for any given system.
| Function | The question it answers | Documents it produces |
|---|---|---|
| Govern | Who is accountable, and against what appetite? | AI policy, governance charter, roles, acceptable use, risk tolerance, AI inventory |
| Map | What is this system, in what context? | System context documentation, use case categorisation, impact assessment, actor mapping |
| Measure | How do we know it behaves? | Metrics catalogue, evaluation plan, bias and fairness testing, robustness and red-team procedures, monitoring |
| Manage | What do we do about what we found? | Risk register, treatment plan, incident response, lifecycle and human oversight procedures, decommissioning |
Read down the right-hand column of NIST AI RMF templates and the shape of an AI governance programme appears. It is
recognisably a management system, which is why organisations that already run one find this far less
alarming than they expected.
Start with the inventory, not the policy
The instinct is to write the AI policy first. Resist it. Almost every organisation underestimates
how much AI it is already running, and a policy written against an imagined estate gets rewritten
within a quarter.
An AI inventory and use case register is the document that makes everything after it possible. It
should capture, per use case: what the system does, who owns it, whether the model is built, bought or
embedded in a supplier’s product, what data it touches, and whether a human reviews its output before
it affects anyone. Embedded AI inside procured software is the category that surprises people most —
it rarely arrives through the channel that would have triggered a review.
Once the inventory exists, the policy can be written against reality, and the risk tolerance
statement has something concrete to apply to.
The documents the framework leaves you to write.
The NIST AI RMF Toolkit is organised by the four functions: governance charter, AI risk and acceptable use policies, roles, risk tolerance and the AI inventory for Govern; context, categorisation, impact assessment and generative AI risk mapping for Map; a trustworthiness metrics catalogue, evaluation plan, bias, robustness and red-teaming procedures for Measure; and the risk register, treatment plan, incident response, human oversight and decommissioning procedures for Manage — plus model and system card templates and a crosswalk to ISO 42001, ISO 23894 and the EU AI Act.
Model cards: the NIST AI RMF templates other people read
Two artefacts do disproportionate work because they are the ones other people read.
A model card records what a model was trained to do, how it performed, on what
evaluation data, and where it should not be used. A system card does the same for the
deployed system rather than the model, which matters when the model is somebody else’s and your risk
sits in how you wired it up.
Both are the natural output of the Measure function, and both are what a customer, regulator or
internal audit function will ask for first. If you produce nothing else from an AI RMF programme,
produce these for your highest-impact use cases.
Generative AI needs its own treatment
General-purpose and generative systems break several assumptions the rest of the framework rests
on. The use case is not fixed, the failure modes include confabulation and prompt injection rather
than classification error, and the provenance of both training data and generated output becomes a
question in its own right.
Practically, that means a separate acceptable use policy for generative tools, explicit risk
mapping for them, and a standard covering synthetic content and provenance. Treating a general-purpose
assistant as just another model in the inventory is how organisations end up with no controls over the
system their staff actually use every day.
Where NIST AI RMF templates meet ISO 42001 and the EU AI Act
The AI RMF is voluntary and carries no certification. ISO/IEC 42001 is a certifiable management
system standard, and the EU AI Act is law with obligations that depend on how a system is classified.
They overlap heavily in substance and differ entirely in force.
That makes a crosswalk one of the more valuable documents in the set: the same control evidence can
usually serve all three, but only if you can show which requirement each artefact satisfies. Building
that mapping once is far cheaper than rebuilding your evidence for each regime. Our comparison of
ISO 42001 and the NIST AI RMF covers
which to lead with.
The revision, and what it means for your documents
NIST states that AI RMF 1.0 is being revised as part of the White House AI Action Plan. No revised
version has been published, so 1.0 remains the current framework.
The sensible response is not to wait. The four functions describe a governance cycle rather than a
control catalogue, and revisions to that kind of framework tend to adjust emphasis rather than
invalidate the inventory, the impact assessments or the model cards you have already produced. Build
now, and keep the crosswalk maintainable so a re-mapping is an afternoon rather than a project.
Sequencing your NIST AI RMF templates: the first ninety days
Programmes stall when every function is opened at once. A sequence that survives contact with a
real organisation looks like this.
- Inventory the estate. Every use case, including embedded AI in purchased
software. Expect the list to be longer than anyone predicted. - Set the governance layer. Policy, roles, acceptable use and risk tolerance,
written against the inventory rather than against an ideal. - Triage. Rank use cases by impact on people. Most of the estate needs a register
entry and nothing more; a small number need the full treatment. - Work the high-impact cases through Map, Measure and Manage, ending each with a
model or system card. - Map to the regimes that bind you — ISO 42001 if certification is the goal, the EU
AI Act if you place systems on that market.
Ninety days is enough for steps one to three across an organisation and step four for two or three
systems. It is not enough to document everything, and attempting that is the most reliable way to
produce a set of NIST AI RMF templates that is complete on paper and unused in practice.
What NIST AI RMF templates cannot settle for you
Two decisions stay with the organisation no matter how good the document set is.
The first is risk tolerance. The framework is explicit that it does not prescribe
how much risk is acceptable, and no template can decide whether a given error rate is tolerable in
your context. That is a business judgement that has to be made and recorded.
The second is where a human must remain in the loop. Documenting an oversight
procedure is easy; deciding which decisions may never be fully automated is not, and it is the
question regulators and customers actually probe.
Frequently asked questions
Is the NIST AI RMF mandatory?
No. It is a voluntary framework, released in January 2023, with no certification scheme attached.
What are the four functions?
Govern, Map, Measure and Manage. Govern is cross-cutting; the others apply per system.
Which document should we write first?
The AI inventory and use case register. Policies written before you know your estate get rewritten.
Do NIST AI RMF templates satisfy the EU AI Act?
Not automatically. The evidence often transfers, but the Act imposes obligations by risk
classification that the framework does not address, so a crosswalk is needed rather than an
assumption.
Should we wait for the revised framework?
No. 1.0 is current, and the artefacts that matter — inventory, impact assessments, evaluation records,
model cards — survive framework revisions.
Where this leaves you
The AI RMF gives you a defensible structure and no documents. Build the inventory first, write the
governance layer against what you actually run, then work each significant use case through Map,
Measure and Manage, producing a model or system card at the end.
Keep a crosswalk to ISO 42001 and the EU AI Act from the start. The organisations that struggle are
not the ones that chose the wrong framework — they are the ones that produced evidence for one and
cannot show what it satisfies anywhere else.
References
- NIST AI Risk Management Framework — the overview page, including the note that AI RMF 1.0 is being revised.
- NIST AI RMF Playbook — the Govern, Map, Measure and Manage resources.
- ISO/IEC 42001 — the certifiable AI management system standard.
More on AI governance
- NIST AI RMF templates — you are here
- The NIST AI RMF explained
- ISO 42001 vs NIST AI RMF
- ISO 42001 controls
- Prohibited AI practices
The document set is available as the NIST AI RMF Toolkit, or start with the free ISO templates.