What NIST AI Risk Management Framework 1.0 is and how to turn GenAI risk into a test plan
NIST AI RMF helps answer the questions leaders ask before adopting AI: what can go wrong, how will it be measured, and who decides? This page connects AI RMF 1.0, NIST AI 600-1, and evidence from AI red teaming.
Four functions that move teams from policy to decisions
AI RMF 1.0 is voluntary and sector agnostic. Version 1.0 remains the current published framework while NIST develops a revision that has not yet replaced it.

- GOVERN establishes risk culture, policy, accountability, risk tolerance, and third-party processes so teams use consistent criteria.
- MAP identifies intended use, users, context, boundaries, dependencies, and impacts so teams do not evaluate a model outside its deployment reality.
- MEASURE selects metrics and TEVV methods for performance, trustworthiness, limitations, and control effectiveness before and after deployment.
- MANAGE prioritizes risk, informs go-live decisions, selects treatment, tracks residual risk, and returns incident evidence to governance.
Seven trustworthy-AI characteristics that must be measured together
High accuracy does not make a system deployment-ready. NIST identifies seven characteristics that can reinforce or conflict with one another, requiring context-specific trade-offs.
- Valid and Reliable and Safe address intended performance, known limitations, and harm within the deployment context.
- Secure and Resilient and Privacy-Enhanced address attacks, failures, disruption, and inappropriate data disclosure.
- Accountable and Transparent and Explainable and Interpretable address responsibility, traceability, and explanations suitable for affected users.
- Fair with Harmful Bias Managed addresses uneven impact and the processes used to discover, document, and reduce harmful bias.
NIST AI 600-1 adds risks amplified by generative AI
NIST AI 600-1 is a 2024 cross-sectoral profile of AI RMF 1.0. It defines 12 risk categories and suggested actions that organizations select based on context, resources, and risk tolerance.
- Accuracy and safety risks include Confabulation, Information Integrity, Dangerous Content, CBRN Information, and Obscene or Abusive Content.
- People and societal risks include Data Privacy, Harmful Bias and Homogenization, and Human-AI Configuration.
- Technology and business risks include Information Security, Intellectual Property, Environmental Impact, and Value Chain and Component Integration.
- The profile emphasizes test plans, deployment thresholds, provenance, independent evaluation, monitoring, incident response, and shutdown plans for unacceptable risk.
Where penetration testing and AI red teaming fit in Measure
AI RMF does not impose a fixed pentest requirement. It establishes TEVV and independent-assessment outcomes. NIST AI 600-1 then names AI red teaming as a suggested action for information security.
- MEASURE 1.3 involves internal experts who were not front-line developers or independent assessors according to organizational risk tolerance.
- MEASURE 2.3 evaluates performance or assurance criteria under deployment-like conditions. MEASURE 2.4 monitors system functionality and behavior in production.
- NIST AI 600-1 action MS-2.7-007 recommends red teaming for prompt injection, data poisoning, membership inference, model extraction, and abuse against other systems.
- Feed test results into MANAGE for treatment, go-live decisions, remediation priority, and residual-risk acceptance rather than ending with a vulnerability report.
Turn AI RMF into a test plan tied to business risk
A strong test plan begins with use cases and harms, not a payload list. It then selects metrics, attack scenarios, and evidence that answer the risk owner's questions.

- GOVERN defines risk owners, approval authority, risk tolerance, escalation, and testing constraints.
- MAP creates the AI inventory, data flows, trust boundaries, dependencies, user journeys, agent permissions, and misuse cases.
- MEASURE runs benchmarks, abuse cases, prompt injection, data leakage, agent-tool abuse, load tests, and detection validation in controlled environments.
- MANAGE prioritizes findings from impact and likelihood, then assigns remediation, retesting, risk acceptance, and production-monitoring triggers.
Requirements and Testing Scope Matrix
Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.
| Reference | Mandate Title | Scope Required | Testing Cycle |
|---|---|---|---|
| MEASURE 1.3, 2.3, and 2.4 | Independent assessment, assurance criteria, and production monitoring | Use risk-appropriate assessors, measure deployment-like conditions, and monitor behavior in production | Before go-live, after significant change, and according to risk tolerance |
| MAP 1.1 and MAP 1.5 | Context, boundary mapping, and impact assessment | Map AI attack surfaces, functional boundaries, and stakeholder safety/privacy impacts | Project inception and major architectural revisions |
| NIST AI 600-1 MS-2.7-007 | AI red teaming for information security | Test prompt injection, data poisoning, membership inference, model extraction, and GenAI-assisted attacks | Before release and after changes to models, data, prompts, tools, or risk profiles |
| MANAGE 2.4 and 4.1 | Risk treatment, remediation, and feedback | Execute remediation plans for identified vulnerabilities and feed results into governance | Continuous remediation and retest tracking |
Compliance Readiness Self-Assessment
Select items your organization has completed to evaluate your readiness score.
