NIST AI RMF implementation fails most often for a reason that has nothing to do with AI: teams read the framework’s 72 subcategories as a to-do list and start at the top. The framework is voluntary, outcome-based and deliberately non-prescriptive, which means the order of work, the depth of each step and the evidence you keep are yours to decide — and deciding them well is the whole job.
This guide sets out an eight-step plan that has held up across organizations of different sizes, what each step produces, how long it typically takes, and the three places implementations stall.

What NIST AI RMF implementation actually means
The AI Risk Management Framework (NIST AI 100-1, January 2023) has two parts. Part 1 frames AI risk and describes seven characteristics of trustworthy AI. Part 2 is the Core — Govern, Map, Measure and Manage, with 19 categories and 72 subcategories — plus profiles. NIST describes the Core’s functions as outcomes, not activities, and states that the framework is intended to be flexible and to augment existing risk practices, not replace them.
So “implementing” it means three things: choosing which outcomes matter for your AI systems and risk tolerance, putting practices in place that reach them, and keeping evidence that they are reached. There is no certificate at the end. What there is, if you do it properly, is a defensible answer to the question every customer, regulator and board now asks — how do you know your AI is trustworthy?
NIST AI RMF implementation in eight steps
| Step | Function | Output | Typical duration |
|---|---|---|---|
| 1. Inventory AI systems | Govern (1.6) | AI system register: purpose, owner, data, model source, users, decisions influenced | 2–4 weeks |
| 2. Set governance and tolerance | Govern (1–2) | AI policy, roles, risk tolerance statement, legal register | 3–6 weeks |
| 3. Build the current profile | All | Honest status against each subcategory in scope | 2–3 weeks |
| 4. Map each priority system | Map (1–5) | Context, intended use, affected people, risks and benefits per system | 2–4 weeks per system, in parallel |
| 5. Measure | Measure (1–4) | Metrics, test results, evaluation of trustworthiness characteristics; list of what cannot be measured | 4–8 weeks |
| 6. Manage | Manage (1–4) | Risk responses, residual-risk decisions, monitoring and incident plans | 3–6 weeks |
| 7. Set the target profile and roadmap | All | Gap between current and target; prioritised actions with owners | 1–2 weeks |
| 8. Operate and review | Govern (1.5), Manage (4) | Monitoring records, periodic review, updated profiles | Ongoing |
Step 1 — Inventory AI systems
GOVERN 1.6 asks for mechanisms to inventory AI systems, resourced according to risk priorities. Nothing else in a NIST AI RMF implementation can be scoped until this exists, and in most organizations it does not: procurement has bought tools with embedded models, engineering has three prototypes, and marketing has a subscription nobody has declared. Capture purpose, owner, data used, where the model comes from, who uses it and what decisions it informs or makes. The last field drives everything after.
Step 2 — Governance and risk tolerance
Govern is described by NIST as cross-cutting — it infuses the other three functions. GOVERN 1.1 to 1.4 want legal requirements understood, trustworthiness characteristics written into policy, risk tolerance set, and the risk process made transparent. GOVERN 2 wants accountability: named roles, empowered and trained. Write the AI policy and the tolerance statement now, because Measure and Manage decisions are judged against them. Our guide to NIST AI RMF templates covers the Govern document set.
Step 3 — Current profile
The framework’s profile concept is the NIST AI RMF implementation tool most people skip. A current profile records what you do today against each subcategory in scope; a target profile records what you intend. Do the current one honestly — “no practice” is a valid entry — and keep it short. The gap to the target profile, built in step 7, becomes the roadmap.
Step 4 — Map
Map is where NIST AI RMF implementation earns its keep. For each priority system: intended purpose, context and prospective settings (MAP 1); categorisation and the specific tasks the system performs (MAP 2); benefits and costs (MAP 3); risks from third-party components (MAP 4); and impacts to individuals, groups, communities and society (MAP 5). Run it as a facilitated session with product, engineering, legal and someone who can speak for affected people. The output is most of what an EU AI Act technical file or an ISO/IEC 42001 impact assessment also needs.
Step 5 — Measure
Measure has 22 subcategories, more than any other function, and is where NIST AI RMF implementation sinks. MEASURE 1.1 gives the key: select metrics starting with the most significant risks from Map, and document the risks or characteristics that will not or cannot be measured. Pick metrics you can actually compute for validity, safety, security, bias and explainability as they apply to the system; run them; record results and limitations. A measurement plan with five honest metrics beats a matrix with fifty aspirational ones.
Step 6 — Manage
MANAGE 1.1 asks the blunt question: does the system achieve its intended purpose, and should development or deployment proceed? Then treatment is prioritised by impact, likelihood and resources (1.2), responses documented (1.3), residual risk stated (1.4), and MANAGE 4 sets up post-deployment monitoring, appeal and override, incident response and decommissioning. Write the incident and decommissioning plans before launch, not after the first problem.
Step 7 — Target profile and roadmap
Compare current and target profiles, list the gaps in the NIST AI RMF implementation, assign owners and dates. Use the NIST AI RMF Playbook‘s suggested actions as candidate targets, adopting only those that address a mapped risk and recording why the rest were not adopted.
Step 8 — Operate and review
GOVERN 1.5 requires ongoing monitoring and periodic review of the risk process, with frequency defined. Feed monitoring results, incidents and user feedback back into Map and Measure. Re-run steps 4–6 when a system changes materially — new model, new use, new population — and refresh the profiles at a fixed interval.
Where NIST AI RMF implementation stalls
| Stall | Symptom | Fix |
|---|---|---|
| Starting with Measure | Months spent choosing fairness metrics for systems nobody has mapped | Do steps 1–4 first; Measure follows from Map’s risk list |
| Treating the Playbook as a checklist | 72 rows, a status column, no risk decisions | Adopt actions by mapped risk; record non-adoption reasons; keep a profile, not a checklist |
| No risk tolerance statement | Every Measure result triggers an argument about whether it is acceptable | GOVERN 1.3 first; write the tolerance down and have leadership sign it |
| Inventory drift | New systems appear outside the programme | Add AI to procurement and change-control gates; review the inventory quarterly |
| Waiting for the revision | Programme paused because AI RMF 1.0 is being revised | Build on the function and subcategory structure, which is stable; expect action wording to change and key evidence to IDs |
NIST AI RMF implementation alongside ISO 42001 and the EU AI Act
NIST AI RMF implementation does not conflict with either. Organizations that want a certificate run the eight steps inside an ISO/IEC 42001 management system, where the inventory becomes the scope, the Map output becomes the impact assessment and the Manage output becomes the risk treatment plan — see ISO 42001 vs NIST AI RMF. Organizations with EU exposure use the steps to generate the evidence the Act prescribes, while meeting the Act’s own procedural obligations separately — see NIST AI RMF vs EU AI Act.
Frequently asked questions
How long does NIST AI RMF implementation take?
Three to six months to reach a working programme with a current profile, mapped priority systems and a roadmap, for an organization with a handful of AI systems. Larger inventories scale the Map and Measure steps roughly linearly.
Do we have to implement all 72 subcategories?
No. The framework is voluntary and profile-based. Select the subcategories relevant to your systems and risk tolerance, and record the selection.
Is there a NIST AI RMF certification?
No. NIST does not certify against the framework and no accredited scheme exists. Organizations that want a certificate use ISO/IEC 42001.
Which function should come first?
Govern. NIST describes it as cross-cutting and foundational; without policy, roles and a tolerance statement the other functions have nothing to decide against.
Should we wait for the revised framework?
No. NIST states 1.0 is being revised but has published no replacement. The structure will carry over; build on it now and treat the revision as a mapping exercise.
Where this leaves you
Run NIST AI RMF implementation as eight steps in order: inventory, governance, current profile, Map, Measure, Manage, target profile, operate. Keep an artefact from each step, key it to subcategory IDs, and let mapped risk — not the length of the Playbook — decide how deep each step goes. That produces a programme an assessor can follow, a board can understand and a future regulation can be mapped onto.
References
- NIST AI Risk Management Framework — the framework overview page, including the note that AI RMF 1.0 is being revised.
- NIST AI RMF Playbook — suggested actions for each of the 72 subcategories.
More on AI governance
- NIST AI RMF implementation — you are here
- NIST AI RMF: the four functions
- The NIST AI RMF Playbook
- The seven trustworthy AI characteristics
- The Generative AI Profile
The inventory and use case register, AI risk management policy, risk tolerance criteria and the Map, Measure and Manage templates used in these eight steps are in the NIST AI RMF Toolkit (36 templates), or start with the free templates.