Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

NIST AI RMF Playbook explained

NIST AI RMF Playbook: A Clear Guide to All 72 Subcategories

The NIST AI RMF Playbook is the companion resource that makes the AI Risk Management Framework usable. The framework itself, NIST AI 100-1, describes 72 outcomes across four functions and says almost nothing about how to reach them; the Playbook supplies suggested actions, documentation prompts and references for every one of those 72 subcategories. If you have read the framework and wondered what to actually do on Monday, this is the document that answers.

This guide covers what the Playbook contains, how it is structured, how to use it without turning it into the checklist NIST says it is not, and what its pending update means for organizations building on it now.

NIST AI RMF Playbook: what each of the 72 subcategory entries contains
Four sections per subcategory, repeated 72 times.

What the NIST AI RMF Playbook is

NIST published the AI Risk Management Framework 1.0 on 26 January 2023 as a voluntary framework for managing risks to individuals, organizations and society from AI. The Playbook was released alongside it and is maintained as a living resource on NIST’s Trustworthy and Responsible AI Resource Center, with NIST stating that updates are released approximately twice a year and that comments are reviewed on a semi-annual basis.

The purpose of the NIST AI RMF Playbook is narrow. The framework’s Core lists categories and subcategories — outcomes — under Govern, Map, Measure and Manage. The Playbook takes each subcategory and adds practical content. NIST is explicit about its status: the Playbook is neither a checklist nor a set of steps to be followed in its entirety; organizations may apply any or none of its suggestions, as suits their industry and interests. It is available as web pages and as downloadable PDF, CSV, Excel and JSON files — the structured formats matter, as we come to below.

How the NIST AI RMF Playbook is structured

The Playbook follows the Core exactly. Four functions, 19 categories, 72 subcategories:

Function Categories Subcategories What the function is about
Govern 6 (GOVERN 1–6) 19 Policies, accountability, workforce, culture, engagement with AI actors, third-party and supply-chain risk — the cross-cutting foundation
Map 5 (MAP 1–5) 18 Context, categorisation of the system, capabilities and benefits, risks to individuals and society, impacts
Measure 4 (MEASURE 1–4) 22 Metrics and methods, evaluation of trustworthiness characteristics, tracking, feedback on measurement effectiveness
Manage 4 (MANAGE 1–4) 13 Prioritising and responding to risks, benefits and residual risk, third-party risk, incident response and improvement

Every NIST AI RMF Playbook entry carries the same four sections:

  1. About — a short explanation of why the outcome matters and what it looks like in practice.
  2. Suggested actions — concrete, non-mandatory practices. GOVERN 1.1, for example, is about understanding and documenting applicable legal and regulatory requirements; its actions include maintaining awareness of AI-relevant law and policy and aligning risk management with them.
  3. Transparency and documentation — a list of documentation the organization can produce to evidence the outcome, plus pointers to AI transparency resources such as model and system cards.
  4. References — standards, papers and tools behind the suggestions.

The second and third sections are where the value sits. Together they give you, for each of the 72 outcomes, both a practice and the artefact that proves it — which is what an assessment, a customer questionnaire or a regulator eventually asks for. Our guide to NIST AI RMF templates works through the artefacts function by function.

Using the NIST AI RMF Playbook without turning it into a checklist

NIST’s warning about the NIST AI RMF Playbook is worth taking seriously, because the structured downloads make the wrong use easy: import the CSV, add a status column, mark 72 rows “done”. That produces a compliance spreadsheet and no risk management. A better sequence:

1. Start with Govern, and start with policy

The framework describes Govern as cross-cutting — it enables the other three functions. In the Playbook, GOVERN 1 alone has seven subcategories covering legal and regulatory requirements (1.1), trustworthiness characteristics in policy (1.2), risk tolerance (1.3), transparent risk management processes (1.4), ongoing monitoring and review (1.5), an inventory of AI systems (1.6) and decommissioning (1.7). Working through those seven first gives every later decision a policy to hang from.

2. Build a profile, not a plan to do everything

The framework’s Part 2 describes profiles: a current profile (what you do now) and a target profile (what you intend). Use the Playbook to populate both — the suggested actions become candidate targets, and the gap between profiles becomes the roadmap. NIST’s own Generative AI Profile (NIST AI 600-1, July 2024) shows what a profile looks like for one technology; our guide to the Generative AI Profile covers it.

3. Select actions by risk, and write down why

For each subcategory in the target profile, pick the suggested actions that address a risk you have actually mapped, and record the reasoning. “Not adopted — no third-party models in scope” is a legitimate entry and an auditable one. Adopting every action is neither.

4. Use the documentation section as the evidence list

The “organizations can document the following” prompts in each entry are a ready-made evidence index. Assign an owner and a location to each item you adopt. This is the part of the Playbook that most directly supports an ISO/IEC 42001 audit or an EU AI Act technical file, because both ask for documents, not intentions.

5. Treat the structured download as a data source

The JSON and CSV versions let you load the Playbook into a GRC tool, map subcategories to ISO 42001 controls or EU AI Act articles, and track adoption by system rather than in a single organization-wide sheet. That is the legitimate use of the export.

Where the NIST AI RMF Playbook stops

The NIST AI RMF Playbook does not measure anything for you. MEASURE has 22 subcategories, the most of any function, and its Playbook entries suggest metrics and methods without prescribing thresholds — what counts as acceptable accuracy or acceptable disparity is a decision the framework leaves to the organization’s risk tolerance (GOVERN 1.3). It does not certify anything: the AI RMF has no certification and the Playbook carries none. And it is general by design — sector-specific guidance comes through profiles, which is why NIST released a concept note for a critical-infrastructure profile in April 2026.

The revision, and what it means for building on the NIST AI RMF Playbook now

NIST states that AI RMF 1.0 is being revised as part of the White House AI Action Plan, and that the Playbook will be updated after the framework is. No revised version had been published as of September 2026, so 1.0 and its Playbook remain the current documents.

The sensible posture with the NIST AI RMF Playbook is to build on the structure — functions, categories, subcategories — and hold the specific action wording loosely. The four functions are stable across every profile NIST has published; the subcategory numbering is what other frameworks map to; the suggested actions are the part most likely to be edited. If your evidence index is keyed to subcategory IDs, a revised Playbook is a re-mapping exercise rather than a rebuild. Our overview of the NIST AI RMF covers the revision in more detail.

Frequently asked questions

Is the NIST AI RMF Playbook mandatory?
No. Both the framework and the Playbook are voluntary. NIST describes the Playbook as suggestions organizations may apply in whole, in part or not at all.

How many subcategories does the Playbook cover?
All 72 — 19 under Govern, 18 under Map, 22 under Measure and 13 under Manage — in 19 categories across the four functions.

What formats is it available in?
Web pages by function, plus PDF, CSV, Excel and JSON downloads from NIST’s AI Resource Center.

Does using the Playbook make us compliant with the EU AI Act?
No. It is a risk-management resource, not a legal standard. Its Map and Measure content supports much of the evidence a high-risk provider needs, but the Act’s obligations are specific and must be met on their own terms.

How does the Playbook relate to ISO/IEC 42001?
ISO 42001 is a certifiable management system with 38 controls; the Playbook is non-certifiable guidance with suggested actions. Many organizations use the Playbook’s actions to implement 42001 controls and the 42001 system to give the actions governance and audit. See our comparison of ISO 42001 and the NIST AI RMF.

Where this leaves you

Use the NIST AI RMF Playbook as what NIST built it to be: a menu of practices and evidence keyed to 72 outcomes, from which you select by risk and record your choices. Start with Govern, build a current and target profile, adopt actions you can justify, and key your evidence to subcategory IDs so the coming revision costs you a mapping rather than a rewrite.

References

More on AI governance

Policies, registers and assessment templates keyed to the Govern, Map, Measure and Manage functions are in the NIST AI RMF Toolkit (36 templates), or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.