NIST AI Risk Management Framework explained, and how it fits the EU AI Act
Not every company answers to Brussels. The NIST AI Risk Management Framework is how a lot of organisations govern AI without a regulator forcing them to.
The NIST AI Risk Management Framework is the most widely used voluntary standard for governing AI, especially for organisations outside the EU or operating across borders. Where the EU AI Act is law, the NIST AI RMF is guidance: a structured way to identify and manage AI risk that customers, partners and boards increasingly expect to see, even when no statute demands it.
This guide explains what the framework is, its four core functions, and how it sits alongside regulation like the EU AI Act.
What the NIST AI RMF is
Published by the US National Institute of Standards and Technology, the AI Risk Management Framework is a voluntary, sector-agnostic framework for managing the risks of AI systems across their lifecycle. It is not a certification and not a law. It is a common language and a set of practices that an organisation adopts to make AI risk visible and manageable, which is why it travels well across industries and borders.
Whichever framework you choose, Grasp helps you put a standard like the NIST AI RMF into practice with a live inventory and the evidence it assumes you have.
The four core functions
Govern. Establish the culture, roles and accountability for AI risk across the organisation. This function runs through the other three rather than sitting beside them, and it mirrors the foundations covered in what AI governance is.
Map. Establish the context and identify the AI systems in use and the risks each one carries. You cannot map what you cannot see, so this function depends on a complete inventory.
Measure. Assess, analyse and track the identified risks using appropriate methods, so risk is quantified rather than assumed.
Manage. Prioritise and act on the risks, allocating resources to the systems that matter most and monitoring them over time.
NIST AI RMF and the EU AI Act
The two are complementary, and work done for one rarely goes to waste on the other. The NIST framework gives you the operating model: how to identify, measure and manage AI risk as a continuous practice. The EU AI Act gives you specific legal obligations for systems that fall into its risk tiers. An organisation that has implemented the NIST AI RMF already has most of the muscle the AI Act expects, and one preparing for the AI Act can use NIST as the framework that organises the effort. For companies caught by both, the EU AI Act for US companies guide sets out where the legal duties begin.
Where to start
The framework rewards the same first move regulation does. Begin with the Map function in practice: a live inventory of the AI systems in use and the risks attached to each. From there, Measure and Manage have something concrete to work on, and Govern gives the whole effort an owner. Treating this as an ongoing practice rather than a one-off exercise is what turns governance into an enabler, the case made in governance as a growth enabler.
Frequently asked questions
What is the NIST AI Risk Management Framework?
A voluntary framework from the US National Institute of Standards and Technology for managing AI risk across a system's lifecycle. It offers a common language and set of practices, organised into four functions, rather than a certification or legal requirement.
What are the four functions of the NIST AI RMF?
Govern, Map, Measure and Manage. Govern sets the culture and accountability and runs through the others; Map identifies systems and risks; Measure assesses and tracks them; and Manage prioritises and acts on them over time.
Is the NIST AI RMF mandatory?
No. It is voluntary guidance, not law. Many organisations adopt it because customers, partners and boards expect a recognised AI risk practice, and because it provides a ready structure for meeting regulations such as the EU AI Act.
How does the NIST AI RMF relate to the EU AI Act?
They complement each other. NIST supplies the operating model for managing AI risk continuously, while the EU AI Act imposes specific legal obligations on systems in its risk tiers. Implementing NIST builds much of the capability the AI Act then requires you to evidence.
Do I need the NIST AI RMF if I follow the EU AI Act?
You are not required to, but it helps. The AI Act tells you what to comply with; the NIST framework gives you a structured way to organise the work and manage risks that fall outside the Act's scope, which is useful for global operations.
Grasp gives the NIST AI RMF something to act on: a live map of every AI system in use, the risks attached to each, and the evidence to manage them over time. See the AI governance solution →

