NIST AI RMF
A plain-English guide to the NIST AI Risk Management Framework for small businesses — what it is, the four functions, who's asking about it, and how to run a full AI RMF self-assessment without consultants.
What is the NIST AI RMF?
The NIST AI Risk Management Framework (AI RMF 1.0) is the U.S. government's playbook for managing the risks of artificial intelligence — published January 2023 as NIST AI 100-1, free to use, and rapidly becoming the reference language for "show me you govern your AI" conversations. Like its older sibling the NIST Cybersecurity Framework, it's voluntary: no auditor, no certificate — but increasingly the thing enterprise customers, insurers, and government buyers point at when they ask how you manage AI.
If your business uses AI at all — ChatGPT in the office, AI features in your product, AI tools in your supply chain — the AI RMF is the framework that turns "we're careful with AI" into something you can demonstrate.
The four functions, in plain English
The AI RMF organizes AI risk management into four functions, broken into 72 specific subcategories:
| Function | What it really asks | Subcategories |
|---|---|---|
| GOVERN | Do you have AI policies, clear accountability, training, and third-party AI rules? | 19 |
| MAP | Do you know what AI you use, why, in what context, and what could go wrong? | 18 |
| MEASURE | Do you evaluate your AI for security, privacy, fairness, and reliability? | 22 |
| MANAGE | Do you act on those risks — prioritize, treat, monitor, and respond to incidents? | 13 |
For a small business, most of GOVERN and MAP is policy-and-process work you can do in weeks — and it's where the framework delivers immediate, visible value: an AI use policy, an AI system inventory, vendor AI rules, and clear human-oversight points.
Who's actually asking for this?
- Enterprise customers — AI questions are appearing on the same security questionnaires that ask about SOC 2, often phrased directly as "do you follow the NIST AI RMF?"
- Insurers — cyber applications now probe AI use, because "employee pasted client data into a chatbot" is a real claims category.
- Government buyers and primes — federal AI guidance traces back to the AI RMF; contractors get asked about AI governance the way they get asked about NIST 800-171.
- Regulators, indirectly — the EU AI Act and U.S. state AI laws reward exactly the documentation the AI RMF produces. NIST also publishes an official crosswalk to ISO/IEC 42001, the certifiable AI management standard — AI RMF work transfers.
How CyberPolicify helps
CyberPolicify runs the complete NIST AI RMF self-assessment — all 72 subcategories, verbatim from NIST AI 100-1 — in plain English, organized by the four functions:
- Guided assessment with evidence notes per subcategory, and an AI Governance Snapshot on your report: per-function maturity bars (Govern / Map / Measure / Manage) that show a customer or insurer exactly where you stand, plus your fastest path to improvement.
- AI governance documents, generated: Generative AI Acceptable Use Guidelines and AI/ML Security Governance — customized to your organization and exported to editable Word. The AI acceptable use policy guide covers what belongs in them.
- A living program, not a binder: gaps become tracked risks in the risk register with owners and treatment plans, alongside your SOC 2, ISO 27001, NIST CSF, or CMMC work — one platform, one controls picture.
The AI RMF assessment is available on every plan, including the 14-day free trial — no credit card, no consultants. Most SMBs finish a first pass in an afternoon and leave with their four-function snapshot and a prioritized to-do list.
AI RMF vs. ISO 42001 — which one?
Start with the AI RMF: it's free, public, U.S.-native, and what your counterparties reference today. ISO/IEC 42001 is the certifiable management standard — heavier, paywalled, and mostly pulled by enterprise deals. The official NIST crosswalk means AI RMF work is a head start on 42001, not a detour.
The order of operations
- Inventory your AI use — tools your team uses, AI in your product, AI at your vendors (the answers will surprise you).
- Run the AI RMF assessment and get your four-function snapshot.
- Generate and adopt your AI acceptable use policy — the highest-leverage single document.
- Put the open items in the risk register with owners and dates.
- Re-assess quarterly — AI use changes faster than any other risk domain.
Being able to answer "how do you govern AI?" with a framework-mapped assessment and signed policies is, right now, a genuine differentiator for a small business — most of your competitors can't.
Generate documentation mapped to frameworks
Start with policies and procedures aligned to the framework, then close gaps with a clear plan.