NIST AI RMF, measured and remeasured

    The NIST AI Risk Management Framework is voluntary, which is exactly why it has become the common language. Boards ask for it, federal buyers expect it, and state regulators increasingly write it into their own guidance.

    A framework with no score is a framework with no baseline

    AI RMF 1.0 is organized around four functions: Govern, Map, Measure, and Manage. They are not sequential stages. They run as ongoing work, which is the point, and also the difficulty.

    Because adoption is voluntary and the framework is deliberately outcome-based rather than prescriptive, most organizations that claim alignment cannot say how aligned. There is no pass mark to point at, so the claim stays qualitative and quietly untested until someone asks for specifics.

    Voluntary until the moment it is not

    The AI RMF gets cited in federal procurement language, in state AI guidance, and in the diligence questionnaires that enterprise customers send before signing. At that point a voluntary framework is functioning as a requirement, and unevidenced alignment reads as no alignment.

    The Measure function is the one most organizations skip, because it is the one that requires instrumentation rather than policy. It is also the first one a serious reviewer probes.

    What you get from a METRIS™ score

    You get your AI systems scored against all four functions, including Measure, with the evidence attached to each. Alignment stops being a claim you make and becomes a number you can show.

    You get a baseline you can move. Because the assessment repeats, you can demonstrate that your posture improved over two quarters, which is a materially stronger answer than a one-time attestation.

    You get one assessment that answers several questions at once. METRIS™ maps the same underlying evidence to ISO/IEC 42001 and EU AI Act obligations, so proving Govern once does not mean proving it three times.

    The four core functions

    Govern
    A culture of AI risk management, with accountability, policy, and oversight across the lifecycle. Spans the whole organization and makes the other three repeatable.
    Map
    Context established, systems categorized, capabilities and goals clarified, risks identified including from third parties.
    Measure
    Risks quantified, tracked, and analyzed with methods you can substantiate. The function most often skipped.
    Manage
    Responses prioritized and operationalized, with monitoring and documented response to what the measurement surfaces.

    NIST AI RMF 1.0 (NIST AI 100-1), published January 2023. The AI RMF Playbook breaks each function into categories and subcategories.

    Last reviewed 27 July 2026.

    What is coming next: AI agents

    On 17 February 2026, the NIST Center for AI Standards and Innovation launched the AI Agent Standards Initiative, aimed at AI systems that take autonomous action on a user's behalf. It runs across three pillars: industry-led development of agent standards, community-led open-source protocol work, and research into AI agent security and identity.

    Earlier that month, on 5 February 2026, the National Cybersecurity Center of Excellence published a concept paper, "Accelerating the Adoption of Software and AI Agent Identity and Authorization". It asks how an enterprise distinguishes an agent from a human user, how authorization is delegated to an agent, and how you audit what an agent did in a way that survives challenge.

    This is an initiative, not a published standard, and nothing in it is an obligation today. It is worth watching anyway, because it points at the question agents make unavoidable: when a system acts on its own, who is accountable for what it did, and what record proves it.

    That question is not new to us. Measuring where accountability moves between people and systems is part of what METRIS™ was built to do. If you are deploying agents now, you are already carrying the problem the standards are being written to address.

    Turn AI RMF alignment into a number

    One AI system, scored against Govern, Map, Measure, and Manage, with the evidence behind every rating.

    Other frameworks

    The same evidence maps to more than one framework. Proving a control once should not mean proving it three times.

    Cookies

    We use cookies to make sanjeevaniai.com work and to understand how visitors engage with our content. Read our Privacy Policy.