What is the NIST AI RMF and is it useful in Europe?
NIST's voluntary framework for managing AI system risk: it gives structure and vocabulary, not a certification.
The NIST AI RMF is the risk management framework for artificial intelligence systems published by the US National Institute of Standards and Technology, in its version 1.0, released in January 2023 under the official designation NIST AI 100-1 (NIST, AI Risk Management Framework). It organizes oversight into four functions: Govern builds culture, roles and accountability, Map frames a system's purpose, capabilities and impacts in its context, Measure evaluates it with tests and metrics, Manage allocates resources to mitigation and monitoring. What the framework is not matters at least as much as the definition itself: it is a document for voluntary use, it binds nobody, and no body issues a NIST AI RMF conformity statement or certification. Organizations adopt it because they need an orderly way to reason, not because anyone requires it of them.
What the four functions are for
The four functions are not a checklist but a working cycle: they exist to stop the risk of an AI system being discussed once, at purchase time, and never again. The part most often missing inside a company is not measurement, it is the first one: someone answering for the system and a place where the decision gets made. How that oversight is built is the subject of AI governance, and the NIST framework is the vocabulary scaffolding for organizing it without inventing categories from scratch.
Why it matters for decision makers
An Italian company falls under the AI Act, which is law, but which obligations apply depends on the role (provider, deployer, importer) and on the risk class: using a third-party tool carries far less than building one. For high-risk systems the regulation prescribes a good deal, a risk management system (Art. 9) and a quality management system (Art. 17), and what it does not impose is the method or framework you build them with. The NIST AI RMF sits exactly there: it imposes nothing, it proposes a method. The limit deserves the same clarity: in front of a market surveillance authority the framework cannot be produced in place of compliance, because it attests to nothing. The third option on the table is ISO/IEC 42001, voluntary like the NIST framework but, unlike it, certifiable through accredited bodies, and the one starting to appear in tender requirements.
A concrete example
A manufacturing company of eighty people uses a conversational assistant on technical manuals and a model that suggests quotation prices. It takes three things from the framework and ignores the rest: a record per system with purpose, data used and an owner, a criterion for saying which use cases touch decisions about people, and a twice-yearly review where errors and complaints are examined. The NIST vocabulary is there to write those three things in a form that holds up when a German customer sends over its AI questionnaire.
When adopting it is overkill
For a company with two use cases and no dedicated structure, adopting a whole framework is work that does not pay back: the functions presuppose roles that are not there. The part genuinely used is the inventory of systems in use, including the ones that arrived on their own, and the risk classification per use case, which is also where the AI Act begins. From there you can see how much governance is really needed, bearing in mind that staff training (Art. 4) does not depend on the risk class, and it is the same snapshot produced by an AI maturity assessment.
This entry is informational and does not constitute legal advice: the role and risk class of an AI system should be verified with legal counsel.
Frequently asked questions
Related terms
- AI governance · The policies, roles and controls governing AI use in a company: system inventory, risk classification, approval flows and monitoring.
- AI Act · The EU's risk-based AI regulation: transparency, GPAI rules and sanctions apply from 2 August 2026, with high-risk duties partly postponed.
- AI maturity assessment · The assessment of how ready a company is for AI across dimensions: data, skills, processes, governance, measurement.
- Agentic maturity · The stage where systems no longer just show data but act inside processes, and the order of steps to get there.
- Shadow AI · The use of AI tools at work without approval or oversight: employees pasting company data into ChatGPT and the like.
A term that hits close to home? Let's talk.
CONTACT ME