AI Risk Management Framework (AI RMF 1.0) + Generative AI Profile (NIST-AI-600-1)
AI Risk Management Framework (AI RMF 1.0) + Generative AI Profile (NIST-AI-600-1) is a 2024 guide from NIST. Its core idea: Govern, Map, Measure, Manage.
Key ideas
- 01AI RMF 1.0 (Jan 2023) organizes AI risk work into four functions: Govern, Map, Measure, Manage; voluntary and sector-neutral.
- 02The Generative AI Profile (July 2024) names 12 risks unique to or worsened by generative AI and suggests 200+ actions.
- 03A companion online Playbook gives suggested actions per subcategory; NIST is revising the framework under the 2025 White House AI Action Plan.
What it means for you Draft
For executives at $10–100M companies
Do not try to implement all of it. Use the four functions as the outline for a short internal AI policy, and scan the list of 12 generative AI risks to see which apply to how your people actually use AI. This is also the reference larger customers are likely to use when they ask about your AI practices.
Limitations
High trust.Government standards body, public consensus process, sells nothing; dense and not written for small firms.
NIST. "AI Risk Management Framework (AI RMF 1.0) + Generative AI Profile (NIST-AI-600-1)." July 26, 2024. https://www.nist.gov/itl/ai-risk-management-framework


