What NIST AI Risk Management Framework 1.0 is and how to turn GenAI risk into a test plan
NIST AI RMF helps answer the questions leaders ask before adopting AI: what can go wrong, how will it be measured, and who decides? This page connects AI RMF 1.0, NIST AI 600-1, and evidence from AI red teaming.
- Target Audience
- Enterprises developing, procuring, or deploying AI and Generative AI systems across industries
- Mandatory Frequency
- Continuous empirical evaluation and risk management across all lifecycle phases
- Required Scope
- Govern, Map, Measure, Manage, seven trustworthy-AI characteristics, and the 12 NIST AI 600-1 risk categories
- Non-Compliance Risk
- Confabulation, data disclosure, prompt injection, agent abuse, supply-chain risk, and evidence-free release decisions
Four functions that move teams from policy to decisions
AI RMF 1.0 is voluntary and sector agnostic. Version 1.0 remains the current published framework while NIST develops a revision that has not yet replaced it.

GOVERN spans the other three functions throughout the lifecycle. MAP, MEASURE, and MANAGE share feedback to improve decisions; they are not a one-time checklist.
- GOVERN — Set owners, policies, and risk criteria
- MAP — Understand use, affected people, and limits
- MEASURE — Test, analyze, and document evidence
- MANAGE — Prioritize, treat, and monitor risk
- GOVERN establishes risk culture, policy, accountability, risk tolerance, and third-party processes so teams use consistent criteria.
- MAP identifies intended use, users, context, boundaries, dependencies, and impacts so teams do not evaluate a model outside its deployment reality.
- MEASURE selects metrics and TEVV methods for performance, trustworthiness, limitations, and control effectiveness before and after deployment.
- MANAGE prioritizes risk, informs go-live decisions, selects treatment, tracks residual risk, and returns incident evidence to governance.
Seven trustworthy-AI characteristics that must be measured together
High accuracy does not make a system deployment-ready. NIST identifies seven characteristics that can reinforce or conflict with one another, requiring context-specific trade-offs.
- Valid and Reliable and Safe address intended performance, known limitations, and harm within the deployment context.
- Secure and Resilient and Privacy-Enhanced address attacks, failures, disruption, and inappropriate data disclosure.
- Accountable and Transparent and Explainable and Interpretable address responsibility, traceability, and explanations suitable for affected users.
- Fair with Harmful Bias Managed addresses uneven impact and the processes used to discover, document, and reduce harmful bias.
NIST AI 600-1 adds risks amplified by generative AI
NIST AI 600-1 is the cross-sectoral Generative AI Profile for AI RMF 1.0. It identifies 12 risks unique to or exacerbated by generative AI and provides voluntary suggested actions mapped across GOVERN, MAP, MEASURE, and MANAGE.
- Content risks: CBRN Information or Capabilities; Dangerous, Violent, or Hateful Content; Obscene, Degrading, and/or Abusive Content.
- Accuracy and privacy risks: Confabulation; Information Integrity; Data Privacy.
- Societal and use-context risks: Harmful Bias or Homogenization; Human-AI Configuration; Environmental Impacts.
- System and rights risks: Information Security; Intellectual Property; Value Chain and Component Integration.
- The voluntary suggested actions focus primarily on governance, content provenance, pre-deployment testing, and incident disclosure. Examples include empirically validated evaluation, context-appropriate red teaming, monitoring, and incident-response planning.
Where penetration testing and AI red teaming fit in Measure
AI RMF does not impose a fixed pentest requirement. It establishes TEVV and independent-assessment outcomes. NIST AI 600-1 then names AI red teaming as a suggested action for information security.

MAP identifies what to test, MEASURE produces evidence, and MANAGE uses it to make decisions. GOVERN spans all three. Testing is one part of risk management.
- GOVERN — Set ownership and decision criteria
- MAP — Understand context, impact, and limitations
- MEASURE — Test, evaluate, and collect evidence
- MANAGE — Prioritize, treat, and monitor risk
- MEASURE 1.3 involves internal experts who were not front-line developers or independent assessors according to organizational risk tolerance.
- MEASURE 2.3 evaluates performance or assurance criteria under deployment-like conditions. MEASURE 2.4 monitors system functionality and behavior in production.
- NIST AI 600-1 action MS-2.7-007 recommends red teaming for prompt injection, data poisoning, membership inference, model extraction, and abuse against other systems.
- Feed test results into MANAGE for treatment, go-live decisions, remediation priority, and residual-risk acceptance rather than ending with a vulnerability report.
Turn AI RMF into a test plan tied to business risk
A strong test plan begins with use cases and harms, not a payload list. It then selects metrics, attack scenarios, and evidence that answer the risk owner's questions.

For a customer-support AI, first identify accessible data and unacceptable outcomes. Combine test evidence with business impact to choose fixes and make deployment decisions.
- Define the scope — Data sources, AI permissions, and owners
- Design scenarios — Misleading data, injected instructions, wrong answers
- Evaluate results — Compare criteria, retain logs, record limitations
- Decide and follow up — Fix, retest, and monitor after release
- GOVERN defines risk owners, approval authority, risk tolerance, escalation, and testing constraints.
- MAP creates the AI inventory, data flows, trust boundaries, dependencies, user journeys, agent permissions, and misuse cases.
- MEASURE runs benchmarks, abuse cases, prompt injection, data leakage, agent-tool abuse, load tests, and detection validation in controlled environments.
- MANAGE prioritizes findings from impact and likelihood, then assigns remediation, retesting, risk acceptance, and production-monitoring triggers.
Requirements and Testing Scope Matrix
Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.
| Reference | Mandate Title | Scope Required | Testing Cycle |
|---|---|---|---|
| MEASURE 1.3, 2.3, and 2.4 | Independent assessment, assurance criteria, and production monitoring | Use risk-appropriate assessors, measure deployment-like conditions, and monitor behavior in production | Before go-live, after significant change, and according to risk tolerance |
| MAP 1.1 and MAP 1.5 | Context, boundary mapping, and impact assessment | Map AI attack surfaces, functional boundaries, and stakeholder safety/privacy impacts | Project inception and major architectural revisions |
| NIST AI 600-1 MS-2.7-007 | AI red teaming for information security | Test prompt injection, data poisoning, membership inference, model extraction, and GenAI-assisted attacks | Before release and after changes to models, data, prompts, tools, or risk profiles |
| MANAGE 2.4 and 4.1 | Risk treatment, remediation, and feedback | Execute remediation plans for identified vulnerabilities and feed results into governance | Continuous remediation and retest tracking |
Compliance Readiness Self-Assessment
Select items your organization has completed to evaluate your readiness score.
Frequently Asked Questions (FAQ)
Key answers and practical guidance addressing common compliance questions.
Is NIST AI RMF 1.0 mandatory?
AI RMF 1.0 is voluntary, sector agnostic, and adaptable. Organizations must separately identify laws, contracts, and sector requirements that may be binding.
Does NIST AI RMF require AI red teaming?
AI RMF 1.0 does not impose a fixed pentest requirement. It supports TEVV and independent assessment. NIST AI 600-1 action MS-2.7-007 specifically recommends AI red teaming for information-security risks.
Is AI RMF 1.0 still the current edition?
Yes. AI RMF 1.0 remains the current published framework as of October 2026. NIST states that a revision is in progress, but no replacement edition has been published.
