ModelCharter
ModelCharter Team

NIST Risk Management Frameworks Compared

Documents and charts comparing NIST risk management frameworks side by side

Photo: Leeloo The First / Pexels

Key takeaways

  • NIST publishes three commonly confused frameworks: the Cybersecurity Framework (CSF), the AI RMF, and RMF 800-37.
  • Only the AI RMF is written specifically for AI; the CSF covers general security, and 800-37 covers federal system authorisation.
  • None of the NIST frameworks are certifiable, unlike ISO 42001.
  • For most teams, the practical starting point is the AI RMF's GOVERN and MAP functions: a policy and a tool inventory.

NIST, the US National Institute of Standards and Technology, publishes several risk management frameworks, and they're easy to mix up because they share a vocabulary and a house style. If you're trying to manage AI risk specifically, the practical question is which NIST risk management framework actually applies to you. The short answer: the NIST AI Risk Management Framework is the one written for AI. But understanding how it sits alongside the Cybersecurity Framework and the older RMF for federal systems stops you duplicating work, or worse, citing the wrong one in a customer security questionnaire.

NIST Cybersecurity Framework (CSF)

The CSF, updated to version 2.0 in 2024, is the widely adopted framework for managing cybersecurity risk generally. It organises work around six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It isn't AI-specific, but because most everyday AI risk is really a data-security risk in disguise, the CSF's Identify and Protect functions overlap heavily with what AI governance needs anyway: knowing what tools you use, and controlling what data can reach them. If your organisation already has a CSF-aligned security programme, adding AI governance is largely a matter of extending an existing Identify function, your asset inventory, to explicitly cover AI tools rather than starting a parallel process from nothing.

NIST AI Risk Management Framework (AI RMF)

The AI RMF, published in January 2023, is the framework built specifically for AI. It uses four functions, GOVERN, MAP, MEASURE, MANAGE, and is paired with a Generative AI Profile, NIST AI 600-1, that tailors it to tools like ChatGPT and Copilot. This is the framework enterprise buyers and US agencies mean by default when they ask how you manage AI risk. For a small team, GOVERN (a policy and a named owner) and MAP (an inventory of the AI tools actually in use) are the two functions worth doing properly before touching the other two.

The Generative AI Profile: NIST AI 600-1

This is the part of the AI RMF ecosystem most relevant to a normal business right now, because it's written for exactly the tools your team already uses: ChatGPT, Copilot, Gemini and similar. NIST AI 600-1 maps generic AI risks onto generative-AI-specific ones, confabulation (producing fluent but false output), data memorisation, and the risk that a model reproduces training data it shouldn't. It doesn't introduce a new set of functions; it slots into the same GOVERN, MAP, MEASURE, MANAGE structure with generative-AI-specific examples. If you're mapping an AI usage policy to the AI RMF for the first time, this profile is the more concrete companion document to read alongside the base framework.

NIST RMF (SP 800-37)

The Risk Management Framework in Special Publication 800-37 is a different thing again: a seven-step process, Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor, used mainly by US federal agencies and their contractors to formally authorise an information system for operation. Unless you sell to the federal government or handle federal data directly, 800-37 probably isn't the framework you need for everyday AI governance, though its risk vocabulary clearly shaped the AI RMF that came after it. It's also considerably more procedural: authorisation decisions, formal sign-off from an accrediting official, and continuous monitoring obligations that go well beyond what a commercial AI governance programme typically needs.

Is the AI RMF part of the Cybersecurity Framework?

No, they're separate publications, though they're designed to be used together. The CSF doesn't mention AI specifically; the AI RMF doesn't replace the security controls a CSF programme already gives you. In practice, teams that run both use the CSF's Identify and Protect functions for the underlying data security, and layer the AI RMF's GOVERN and MAP functions on top for the AI-specific decisions, which tools are approved, what data can go into them, who owns that call. A useful gut-check: if the question is "do we know what's accessing our network," that's CSF territory; if it's "do we know what our AI tools are doing with our data," that's AI RMF territory, even though both questions often lead to the same tool register.

Can you get certified against a NIST framework?

No, and this trips people up because ISO 42001, a comparable standard for AI management systems, is certifiable. NIST publishes its frameworks as voluntary guidance for self-assessment; there's no accredited body that audits you against the AI RMF and issues a certificate. If a customer specifically wants third-party-verified proof of AI governance, that's a reason to look at ISO 42001 alongside the AI RMF rather than instead of it.

Which one to use for AI

For governing the AI tools your team actually uses, start with the AI RMF, and lean on the CSF for the data-security controls underneath it if you already run a security programme. Reserve 800-37 for federal system authorisation, if that ever applies. A 15-person fintech startup we spoke to hit this exact question answering a bank's vendor security questionnaire: the same evidence, a written policy, a tool inventory, defined access controls, mapped onto the CSF's Identify and Protect functions and the AI RMF's GOVERN and MAP functions, without writing two separate reports. Whichever combination you land on, the underlying artefacts are identical: a written AI usage policy, a register of approved tools, and a record that staff have read the rules. As a rough guide: no security programme yet and just want AI covered, start with the AI RMF alone; already CSF-aligned, extend it with the AI RMF's GOVERN and MAP; selling to federal agencies, add 800-37 on top rather than instead of the other two. For the full function-by-function detail, the AI RMF 1.0 text itself runs to about 42 pages and is worth the read once.

Where to start

If you're being asked about AI risk management for the first time, don't start by reading three NIST documents cover to cover. Start with ModelCharter's free policy generator to get GOVERN's core artefact in place, then build the MAP inventory using the AI Tool Risk Directory. Our NIST AI RMF framework guide breaks down each function in more depth once you've got the basics down.

FrameworkScopeStructureWho typically uses it
NIST CSF 2.0Cybersecurity risk, general6 functions: Govern, Identify, Protect, Detect, Respond, RecoverAny organisation managing security risk
NIST AI RMFAI risk specifically4 functions: GOVERN, MAP, MEASURE, MANAGETeams governing AI tools or building AI systems
NIST RMF (SP 800-37)Federal information system authorisation7 steps: Prepare, Categorize, Select, Implement, Assess, Authorize, MonitorFederal agencies and contractors
NIST's risk management frameworks compared
The Framework is intended to be voluntary, flexible, and usable by organizations of any size, in any sector.
NIST AI RMF 1.0

Frequently asked questions

What's the difference between NIST CSF and NIST AI RMF?
The CSF manages cybersecurity risk generally, using six functions, and applies to any organisation. The AI RMF is written specifically for AI risk, using four functions, and is the one enterprise buyers mean when they ask how you govern AI. They're complementary, not interchangeable.
Does the AI RMF replace the Cybersecurity Framework?
No. If you already run a CSF-based security programme, keep it. The AI RMF adds AI-specific governance, GOVERN and MAP in particular, on top of the data-security controls the CSF already gives you.
Is NIST AI RMF mandatory for federal contractors?
Not in the way RMF 800-37 is mandatory for federal system authorisation. But it's increasingly referenced in federal AI guidance and vendor questionnaires, so contractors working with AI are likely to encounter it even without a hard legal requirement.
Can a small business realistically use the AI RMF without a compliance team?
Yes. Most of the practical value comes from just two of its four functions: GOVERN (a named owner and a written policy) and MAP (an inventory of the AI tools you use). MEASURE and MANAGE matter more once you're building or heavily customising AI systems yourself.
What is NIST AI 600-1 and do I need it separately from the AI RMF?
It's the Generative AI Profile, a companion document that applies the AI RMF's four functions specifically to generative tools like ChatGPT and Copilot. You don't need to treat it as a separate project; read it alongside the base framework once you're past the initial policy-and-inventory stage.

Put this into practice

Generate a free AI usage policy for your team, then see which of your tools are safe to use.

Open the generator