NIST Risk Management Frameworks Compared

Photo: Leeloo The First / Pexels
Key takeaways
- NIST publishes three commonly confused frameworks: the Cybersecurity Framework (CSF), the AI RMF, and RMF 800-37.
- Only the AI RMF is written specifically for AI; the CSF covers general security, and 800-37 covers federal system authorisation.
- None of the NIST frameworks are certifiable, unlike ISO 42001.
- For most teams, the practical starting point is the AI RMF's GOVERN and MAP functions: a policy and a tool inventory.
NIST, the US National Institute of Standards and Technology, publishes several risk management frameworks, and they're easy to mix up because they share a vocabulary and a house style. If you're trying to manage AI risk specifically, the practical question is which NIST risk management framework actually applies to you. The short answer: the NIST AI Risk Management Framework is the one written for AI. But understanding how it sits alongside the Cybersecurity Framework and the older RMF for federal systems stops you duplicating work, or worse, citing the wrong one in a customer security questionnaire.
NIST Cybersecurity Framework (CSF)
The CSF, updated to version 2.0 in 2024, is the widely adopted framework for managing cybersecurity risk generally. It organises work around six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It isn't AI-specific, but because most everyday AI risk is really a data-security risk in disguise, the CSF's Identify and Protect functions overlap heavily with what AI governance needs anyway: knowing what tools you use, and controlling what data can reach them. If your organisation already has a CSF-aligned security programme, adding AI governance is largely a matter of extending an existing Identify function, your asset inventory, to explicitly cover AI tools rather than starting a parallel process from nothing.
NIST AI Risk Management Framework (AI RMF)
The AI RMF, published in January 2023, is the framework built specifically for AI. It uses four functions, GOVERN, MAP, MEASURE, MANAGE, and is paired with a Generative AI Profile, NIST AI 600-1, that tailors it to tools like ChatGPT and Copilot. This is the framework enterprise buyers and US agencies mean by default when they ask how you manage AI risk. For a small team, GOVERN (a policy and a named owner) and MAP (an inventory of the AI tools actually in use) are the two functions worth doing properly before touching the other two.
The Generative AI Profile: NIST AI 600-1
This is the part of the AI RMF ecosystem most relevant to a normal business right now, because it's written for exactly the tools your team already uses: ChatGPT, Copilot, Gemini and similar. NIST AI 600-1 maps generic AI risks onto generative-AI-specific ones, confabulation (producing fluent but false output), data memorisation, and the risk that a model reproduces training data it shouldn't. It doesn't introduce a new set of functions; it slots into the same GOVERN, MAP, MEASURE, MANAGE structure with generative-AI-specific examples. If you're mapping an AI usage policy to the AI RMF for the first time, this profile is the more concrete companion document to read alongside the base framework.
NIST RMF (SP 800-37)
The Risk Management Framework in Special Publication 800-37 is a different thing again: a seven-step process, Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor, used mainly by US federal agencies and their contractors to formally authorise an information system for operation. Unless you sell to the federal government or handle federal data directly, 800-37 probably isn't the framework you need for everyday AI governance, though its risk vocabulary clearly shaped the AI RMF that came after it. It's also considerably more procedural: authorisation decisions, formal sign-off from an accrediting official, and continuous monitoring obligations that go well beyond what a commercial AI governance programme typically needs.
Is the AI RMF part of the Cybersecurity Framework?
No, they're separate publications, though they're designed to be used together. The CSF doesn't mention AI specifically; the AI RMF doesn't replace the security controls a CSF programme already gives you. In practice, teams that run both use the CSF's Identify and Protect functions for the underlying data security, and layer the AI RMF's GOVERN and MAP functions on top for the AI-specific decisions, which tools are approved, what data can go into them, who owns that call. A useful gut-check: if the question is "do we know what's accessing our network," that's CSF territory; if it's "do we know what our AI tools are doing with our data," that's AI RMF territory, even though both questions often lead to the same tool register.
Can you get certified against a NIST framework?
No, and this trips people up because ISO 42001, a comparable standard for AI management systems, is certifiable. NIST publishes its frameworks as voluntary guidance for self-assessment; there's no accredited body that audits you against the AI RMF and issues a certificate. If a customer specifically wants third-party-verified proof of AI governance, that's a reason to look at ISO 42001 alongside the AI RMF rather than instead of it.
Which one to use for AI
For governing the AI tools your team actually uses, start with the AI RMF, and lean on the CSF for the data-security controls underneath it if you already run a security programme. Reserve 800-37 for federal system authorisation, if that ever applies. A 15-person fintech startup we spoke to hit this exact question answering a bank's vendor security questionnaire: the same evidence, a written policy, a tool inventory, defined access controls, mapped onto the CSF's Identify and Protect functions and the AI RMF's GOVERN and MAP functions, without writing two separate reports. Whichever combination you land on, the underlying artefacts are identical: a written AI usage policy, a register of approved tools, and a record that staff have read the rules. As a rough guide: no security programme yet and just want AI covered, start with the AI RMF alone; already CSF-aligned, extend it with the AI RMF's GOVERN and MAP; selling to federal agencies, add 800-37 on top rather than instead of the other two. For the full function-by-function detail, the AI RMF 1.0 text itself runs to about 42 pages and is worth the read once.
Where to start
If you're being asked about AI risk management for the first time, don't start by reading three NIST documents cover to cover. Start with ModelCharter's free policy generator to get GOVERN's core artefact in place, then build the MAP inventory using the AI Tool Risk Directory. Our NIST AI RMF framework guide breaks down each function in more depth once you've got the basics down.
| Framework | Scope | Structure | Who typically uses it |
|---|---|---|---|
| NIST CSF 2.0 | Cybersecurity risk, general | 6 functions: Govern, Identify, Protect, Detect, Respond, Recover | Any organisation managing security risk |
| NIST AI RMF | AI risk specifically | 4 functions: GOVERN, MAP, MEASURE, MANAGE | Teams governing AI tools or building AI systems |
| NIST RMF (SP 800-37) | Federal information system authorisation | 7 steps: Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor | Federal agencies and contractors |
“The Framework is intended to be voluntary, flexible, and usable by organizations of any size, in any sector.”