United States · Governance guidance

NIST AI Risk Management Framework

The framework organises AI risk work around Govern, Map, Measure and Manage and can support product development, procurement, deployment and continuing monitoring.

Current status
Voluntary framework; revision work is under way
Published or updated
26 January 2023
Last verified
19 August 2026

Prepared by Longan Bay Area AI Legal Research Center based on official public materials.

01

Scope of application & addressees

  • Organisations developing, procuring, deploying or evaluating AI systems
  • Product, risk, compliance, security and audit teams

02

Core regulatory mandates & key requirements

01Governance covers accountability, policy, staff capability and organisational culture.

02Risk mapping considers intended use, stakeholders and possible impacts.

03Testing, metrics, monitoring and response records support continuing improvement.

03

Enforcement & compliance timeline

Version 1.0 was released.

The Generative AI Profile was released.

NIST continued work on the next revision.

Primary text

Statutory & regulatory text

PROJECT ENQUIRY

Need to evaluate this regulation against your system architecture?

Consult with our regulatory team →