Skip to content
Oluma Cyber Security Awareness
Framework · AI Risk Management

NIST AI RMF

The voluntary playbook for trustworthy AI — the same calm, structured thinking NIST brought to cybersecurity, now aimed at the unique risks of artificial intelligence.

v1.0 · 20234 Functions7 Trust TraitsGen-AI Profile 2024
01 The Problem

How do you manage a risk you can’t fully see?

AI risk is genuinely strange. A model can be biased in ways no one intended, confidently wrong, impossible to fully explain, or vulnerable to attacks that don’t exist for ordinary software. Traditional risk frameworks weren’t built for systems that learn, drift, and surprise you.

Organizations rushing to deploy AI had no shared way to reason about these risks — or even a common vocabulary for what “trustworthy AI” actually means.

03 The Story Behind It

Built for AI, updated for the generative wave

2023
AI RMF 1.0
Released in January 2023, modeled on the Cybersecurity Framework so the two could be used together, and defining what trustworthy AI means.
2024
The Generative AI Profile
As foundation models exploded, NIST added a companion profile identifying risks unique to generative AI — and suggested actions to manage them.
2026
Still the reference
Version 1.0 remains the finalized core (a revision is underway), while new profiles — for critical infrastructure and beyond — keep extending it to fresh contexts.
04 How It Works

Four functions, seven traits of trust

The framework runs on four functions that work together, not in a strict line — the same intuitive shape as the Cybersecurity Framework, so teams already fluent in CSF feel at home.

GovernMapMeasureManage

Govern sets the culture and accountability; Map establishes context and identifies risks; Measure analyzes and tracks them; Manage acts on them. Underneath sits a definition of what trustworthy AI should be:

01 Valid & reliable
02 Safe
03 Secure & resilient
04 Accountable & transparent
05 Explainable & interpretable
06 Privacy-enhanced
07 Fair — bias managed
+ Profiles: current → target
AI RMF vs. the EU AI Act vs. ISO 42001

The AI RMF is the voluntary method; the EU AI Act is a binding law; ISO/IEC 42001 is the certifiable management system. Many organizations use the RMF to operationalize what the law requires and the ISO standard certifies.

06 Who Uses It

The common backbone of AI governance

🧠
AI builders & deployers
Organizations developing or adopting AI who want a structured way to manage its risks.
🌍
Global enterprises
Though US-origin and voluntary, it’s become a common worldwide backbone for AI risk programs.
⚖️
Regulated & public sector
Bodies that reference it as a benchmark for responsible AI, often alongside binding rules.

It’s the connective tissue between AI law and AI certification.

pairs with EU AI Actcertifiable via ISO 42001mirrors NIST CSFoverlaps Privacy Framework
07 Career Relevance

Get fluent before everyone else does

AI governance roles are being created faster than people can fill them, and the AI RMF is the shared language of the field. Because it mirrors the Cybersecurity Framework, anyone who knows CSF has a real head start.

AI risk analyst
Run the functions
Operate Govern/Map/Measure/Manage across an organization’s AI portfolio.
Responsible-AI lead
Build the program
Turn the trustworthy-AI traits into policies, testing, and oversight that actually hold.
GRC professional
Bridge to the rest
Connect the AI RMF to the EU AI Act, ISO 42001, and your existing CSF program so one effort serves many.

If CSF was the credential of the last decade, AI RMF fluency is shaping up to be the credential of the next.

09 Final Takeaway

The AI RMF brings calm structure to the messiest new risk in technology.

It won’t hand you the answers, but it gives an organization one shared way to ask the right questions about AI — govern, map, measure, manage — built on the same instincts as the Cybersecurity Framework. Learn it now, and you’re fluent in the language AI governance is being built on.