# What NIST AI Risk Management Framework 1.0 is and how to turn GenAI risk into a test plan

Locale: `en`

Source: `/en/compliance/nist-ai-rmf/`

On this page

1. [Overview](/en/compliance/nist-ai-rmf/#topic-overview)
2. [Four functions that move teams from policy to decisions](/en/compliance/nist-ai-rmf/#core-four-functions)
3. [Seven trustworthy-AI characteristics that must be measured together](/en/compliance/nist-ai-rmf/#trustworthy-ai-characteristics)
4. [NIST AI 600-1 adds risks amplified by generative AI](/en/compliance/nist-ai-rmf/#genai-profile-risks)
5. [Where penetration testing and AI red teaming fit in Measure](/en/compliance/nist-ai-rmf/#measure-and-red-teaming)
6. [Turn AI RMF into a test plan tied to business risk](/en/compliance/nist-ai-rmf/#risk-to-test-plan)
7. [Requirements Matrix](/en/compliance/nist-ai-rmf/#compliance-matrix)
8. [Readiness Assessment](/en/compliance/nist-ai-rmf/#compliance-readiness-checklist)
9. [Frequently Asked Questions](/en/compliance/nist-ai-rmf/#compliance-faq)
10. [Related Frameworks](/en/compliance/nist-ai-rmf/#related-compliance-frameworks)

# What NIST AI Risk Management Framework 1.0 is and how to turn GenAI risk into a test plan

NIST AI RMF helps answer the questions leaders ask before adopting AI: what can go wrong, how will it be measured, and who decides? This page connects AI RMF 1.0, NIST AI 600-1, and evidence from AI red teaming.

Executive Summary and Mandate Overview

Target Audience

Enterprises developing, procuring, or deploying AI and Generative AI systems across industries

Mandatory Frequency

Continuous empirical evaluation and risk management across all lifecycle phases

Required Scope

Govern, Map, Measure, Manage, seven trustworthy-AI characteristics, and the 12 NIST AI 600-1 risk categories

Non-Compliance Risk

Confabulation, data disclosure, prompt injection, agent abuse, supply-chain risk, and evidence-free release decisions

## Four functions that move teams from policy to decisions

AI RMF 1.0 is voluntary and sector agnostic. Version 1.0 remains the current published framework while NIST develops a revision that has not yet replaced it.

[![AI RMF: four connected functions: GOVERN, MAP, MEASURE, MANAGE](/assets/compliance/nist-framework-overview-en-v1.webp)](/assets/compliance/nist-framework-overview-en-v1.webp)

**AI RMF: four connected functions**

GOVERN spans the other three functions throughout the lifecycle. MAP, MEASURE, and MANAGE share feedback to improve decisions; they are not a one-time checklist.

- **GOVERN** — Set owners, policies, and risk criteria
- **MAP** — Understand use, affected people, and limits
- **MEASURE** — Test, analyze, and document evidence
- **MANAGE** — Prioritize, treat, and monitor risk

- GOVERN establishes risk culture, policy, accountability, risk tolerance, and third-party processes so teams use consistent criteria.
- MAP identifies intended use, users, context, boundaries, dependencies, and impacts so teams do not evaluate a model outside its deployment reality.
- MEASURE selects metrics and TEVV methods for performance, trustworthiness, limitations, and control effectiveness before and after deployment.
- MANAGE prioritizes risk, informs go-live decisions, selects treatment, tracks residual risk, and returns incident evidence to governance.

## Seven trustworthy-AI characteristics that must be measured together

High accuracy does not make a system deployment-ready. NIST identifies seven characteristics that can reinforce or conflict with one another, requiring context-specific trade-offs.

- Valid and Reliable and Safe address intended performance, known limitations, and harm within the deployment context.
- Secure and Resilient and Privacy-Enhanced address attacks, failures, disruption, and inappropriate data disclosure.
- Accountable and Transparent and Explainable and Interpretable address responsibility, traceability, and explanations suitable for affected users.
- Fair with Harmful Bias Managed addresses uneven impact and the processes used to discover, document, and reduce harmful bias.

## NIST AI 600-1 adds risks amplified by generative AI

NIST AI 600-1 is the cross-sectoral Generative AI Profile for AI RMF 1.0. It identifies 12 risks unique to or exacerbated by generative AI and provides voluntary suggested actions mapped across GOVERN, MAP, MEASURE, and MANAGE.

- Content risks: CBRN Information or Capabilities; Dangerous, Violent, or Hateful Content; Obscene, Degrading, and/or Abusive Content.
- Accuracy and privacy risks: Confabulation; Information Integrity; Data Privacy.
- Societal and use-context risks: Harmful Bias or Homogenization; Human-AI Configuration; Environmental Impacts.
- System and rights risks: Information Security; Intellectual Property; Value Chain and Component Integration.
- The voluntary suggested actions focus primarily on governance, content provenance, pre-deployment testing, and incident disclosure. Examples include empirically validated evaluation, context-appropriate red teaming, monitoring, and incident-response planning.

## Where penetration testing and AI red teaming fit in Measure

AI RMF does not impose a fixed pentest requirement. It establishes TEVV and independent-assessment outcomes. NIST AI 600-1 then names AI red teaming as a suggested action for information security.

[![Where testing fits in the AI RMF: GOVERN, MAP, MEASURE, MANAGE](/assets/compliance/nist-testing-en-v1.webp)](/assets/compliance/nist-testing-en-v1.webp)

**Where testing fits in the AI RMF**

MAP identifies what to test, MEASURE produces evidence, and MANAGE uses it to make decisions. GOVERN spans all three. Testing is one part of risk management.

- **GOVERN** — Set ownership and decision criteria
- **MAP** — Understand context, impact, and limitations
- **MEASURE** — Test, evaluate, and collect evidence
- **MANAGE** — Prioritize, treat, and monitor risk

- MEASURE 1.3 involves internal experts who were not front-line developers or independent assessors according to organizational risk tolerance.
- MEASURE 2.3 evaluates performance or assurance criteria under deployment-like conditions. MEASURE 2.4 monitors system functionality and behavior in production.
- NIST AI 600-1 action MS-2.7-007 recommends red teaming for prompt injection, data poisoning, membership inference, model extraction, and abuse against other systems.
- Feed test results into MANAGE for treatment, go-live decisions, remediation priority, and residual-risk acceptance rather than ending with a vulnerability report.

## Turn AI RMF into a test plan tied to business risk

A strong test plan begins with use cases and harms, not a payload list. It then selects metrics, attack scenarios, and evidence that answer the risk owner's questions.

[![Turn AI risk into a test plan: Define the scope → Design scenarios → Evaluate results → Decide and follow up](/assets/compliance/nist-practical-assurance-en-v1.webp)](/assets/compliance/nist-practical-assurance-en-v1.webp)

**Turn AI risk into a test plan**

For a customer-support AI, first identify accessible data and unacceptable outcomes. Combine test evidence with business impact to choose fixes and make deployment decisions.

1. **Define the scope** — Data sources, AI permissions, and owners
2. **Design scenarios** — Misleading data, injected instructions, wrong answers
3. **Evaluate results** — Compare criteria, retain logs, record limitations
4. **Decide and follow up** — Fix, retest, and monitor after release

- GOVERN defines risk owners, approval authority, risk tolerance, escalation, and testing constraints.
- MAP creates the AI inventory, data flows, trust boundaries, dependencies, user journeys, agent permissions, and misuse cases.
- MEASURE runs benchmarks, abuse cases, prompt injection, data leakage, agent-tool abuse, load tests, and detection validation in controlled environments.
- MANAGE prioritizes findings from impact and likelihood, then assigns remediation, retesting, risk acceptance, and production-monitoring triggers.

## Requirements and Testing Scope Matrix

Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.

| Reference | Mandate Title | Scope Required | Testing Cycle |
| --- | --- | --- | --- |
| **MEASURE 1.3, 2.3, and 2.4** | Independent assessment, assurance criteria, and production monitoring | Use risk-appropriate assessors, measure deployment-like conditions, and monitor behavior in production | Before go-live, after significant change, and according to risk tolerance |
| **MAP 1.1 and MAP 1.5** | Context, boundary mapping, and impact assessment | Map AI attack surfaces, functional boundaries, and stakeholder safety/privacy impacts | Project inception and major architectural revisions |
| **NIST AI 600-1 MS-2.7-007** | AI red teaming for information security | Test prompt injection, data poisoning, membership inference, model extraction, and GenAI-assisted attacks | Before release and after changes to models, data, prompts, tools, or risk profiles |
| **MANAGE 2.4 and 4.1** | Risk treatment, remediation, and feedback | Execute remediation plans for identified vulnerabilities and feed results into governance | Continuous remediation and retest tracking |

### Compliance Readiness Self-Assessment

Select items your organization has completed to evaluate your readiness score.

0%

Define risk owners, risk tolerance, approval authority, and third-party policy under GOVERN
          
          
            
            Document the AI inventory, intended use, boundaries, dependencies, stakeholder impacts, and misuse cases under MAP
          
          
            
            Define metrics, test sets, acceptance thresholds, limitations, and independent assessment under MEASURE
          
          
            
            Red-team prompt injection, poisoning, and model extraction using NIST AI 600-1 action MS-2.7-007
          
          
            
            Monitor production functionality and behavior with detection, incident response, and drift monitoring
          
          
            
            Feed findings, remediation, retesting, and residual risk into go-live decisions and MANAGE

Assessment Status

Check items above to view assessment result.

[Request Pentest Quote](/en/#contact)

## Frequently Asked Questions (FAQ)

Key answers and practical guidance addressing common compliance questions.

### Is NIST AI RMF 1.0 mandatory?

AI RMF 1.0 is voluntary, sector agnostic, and adaptable. Organizations must separately identify laws, contracts, and sector requirements that may be binding.

### Does NIST AI RMF require AI red teaming?

AI RMF 1.0 does not impose a fixed pentest requirement. It supports TEVV and independent assessment. NIST AI 600-1 action MS-2.7-007 specifically recommends AI red teaming for information-security risks.

### Is AI RMF 1.0 still the current edition?

Yes. AI RMF 1.0 remains the current published framework as of October 2026. NIST states that a revision is in progress, but no replacement edition has been published.

## Related Compliance Frameworks and Security Standards

- [
                NCSA AI Security Guidelines: lifecycle and governance
                
              ](/en/compliance/ncsa-ai-security-guidelines/)
- [
                ISO/IEC 42001:2023, AI pentesting, and AIMS evidence
                
              ](/en/compliance/iso-42001-ai-management/)
- [
                Google SAIF 2.0 for AI agent security and red teaming
                
              ](/en/compliance/google-saif/)
- [
                Thailand Cybersecurity Act 2019 and penetration testing
                
              ](/en/compliance/cybersecurity-act/)

Open full-size image to zoom

## Official source documents

Original files from the regulating authorities, hosted on sth.sh for convenience. Always defer to the latest version at the source link.

[
            
              
              
              ![First-page preview of NIST AI 100-1: Artificial Intelligence Risk Management Framework (AI RMF 1.0)](/assets/process/compliance-sources/sth-source-nist-ai-100-1.webp)
            
          ](/assets/documents/sth-source-nist-ai-100-1.pdf)

### NIST AI 100-1: Artificial Intelligence Risk Management Framework (AI RMF 1.0)

By National Institute of Standards and Technology (NIST)

[Open document (PDF) ](/assets/documents/sth-source-nist-ai-100-1.pdf)
              [Download ](/assets/documents/sth-source-nist-ai-100-1.pdf)
              
              [Source ](https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf)
              [NIST AI RMF Portal ](https://www.nist.gov/itl/ai-risk-management-framework)

[
            
              
              
              ![First-page preview of NIST AI 600-1: Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile](/assets/process/compliance-sources/sth-source-nist-ai-600-1.webp)
            
          ](/assets/documents/sth-source-nist-ai-600-1.pdf)

### NIST AI 600-1: Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile

By National Institute of Standards and Technology (NIST)

[Open document (PDF) ](/assets/documents/sth-source-nist-ai-600-1.pdf)
              [Download ](/assets/documents/sth-source-nist-ai-600-1.pdf)
              
              [Source ](https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf)
              [NIST AI RMF Portal ](https://www.nist.gov/itl/ai-risk-management-framework)

## Need a pentest that satisfies these requirements?

Tell us about your systems and the requirements you must meet. The STH team will assess the approach and prepare a quotation.

[Request a Pentest quote](/en/#contact)

## PDF document

[Open in new tab ](/en/compliance/nist-ai-rmf/)
              [Download](/en/compliance/nist-ai-rmf/)

Last updated 7 October 2026
