AI is showing up in procurement requests, pilot projects, and vendor contracts faster than most compliance programs can process it. IT directors are being asked to greenlight tools that touch sensitive data, automate decisions, or plug into existing information systems, often before anyone has fully mapped what could go wrong. That gap is exactly what the NIST AI Risk Management Framework was built to close.
Unlike a checklist, the NIST AI Risk Management Framework gives IT teams a structure for thinking through AI risk in a repeatable way. It doesn’t ask you to start from scratch either. If your organization already runs a risk management framework for information systems generally, the AI-specific version is designed to extend that work rather than replace it.
If you’re using AI tools, make sure you’ve got a set of controls in place to govern their use: AI Governance Framework for Enterprise IT Teams
What is the NIST AI Risk Management Framework?
The NIST AI Risk Management Framework (RMF) is voluntary guidance published by the National Institute of Standards and Technology (NIST) to help organizations manage the risks that come with designing, deploying, and operating AI systems. It doesn’t prescribe specific tools or vendors; instead, it outlines a structure for identifying, assessing, and managing cybersecurity risks, along with the broader operational and strategic risks that AI introduces.
It’s worth separating this from the traditional NIST risk management framework most IT directors already know, the one built around information systems and codified in SP 800-37. That version focuses on securing systems through defined control baselines.
The AI-specific framework covers similar ground but accounts for risks that don’t map cleanly onto traditional security controls, including bias in outputs, model drift over time, and the difficulty of predicting how an AI system will behave in situations it wasn’t explicitly trained for.
The Four Core Functions
NIST organizes the AI Risk Management Framework into four functions: Govern, Map, Measure, and Manage. They aren’t meant to run in strict sequence. In practice, most IT teams work through them iteratively, revisiting earlier functions as new AI use cases come up or existing ones change.
Govern
Govern is the foundation the other three functions sit on. It covers the policies, accountability structures, and oversight that determine how your organization approaches AI risk in the first place.
For IT teams, this looks like:
- Assigning clear ownership for AI risk decisions, so approvals don’t get stuck between security, legal, and whichever department wants to use the tool
- Documenting acceptable use policies that spell out what AI tools can and can’t touch, particularly around sensitive data
- Establishing an escalation path for when someone flags a concern about an AI system already in production
Without this piece in place, the other three functions tend to happen inconsistently, if they happen at all.
Map
Map is where you build context around a specific AI use case before it goes anywhere near production. This is the identifying risks stage, and it’s easy to rush past if there’s pressure to deploy quickly.
Practical steps include:
- Inventorying where the AI tool touches existing information systems, including any integrations with databases, applications, or third-party services
- Documenting data flows to understand what data the system will see, process, or generate, and whether any of it is sensitive or regulated
- Building an initial risk profile for the specific use case, rather than relying on a generic risk profile for “AI” as a category
Two AI tools performing similar tasks can carry very different risk profiles depending on what data they touch and who has access to their outputs. Mapping is what surfaces that difference before it becomes a problem.
Measure
Measure is where identifying risks turns into assessing them. This function is about analysis, not just intuition, and it’s often the step that gives an assessment credibility with auditors and regulators later on.
For IT teams, this means:
- Defining metrics tied to accuracy, bias, and the strength of existing security controls around the system
- Testing AI outputs against expected performance before go-live, rather than assuming the vendor’s benchmarks apply to your specific context
- Documenting assessment results in a format that can support an audit trail, since this is often the evidence regulators or assessors will ask for directly
Measure doesn’t need to be exhaustive for every deployment. It does need to be consistent, so results can be compared over time and across different AI use cases.
Manage
Manage is where the framework becomes an ongoing risk management process rather than a one-time review. It covers how your organization prioritizes and responds to the risks that Map and Measure identified.
Actionable steps include:
- Setting thresholds for acceptable risk that reflect your organization’s actual risk appetite, rather than defaulting to whatever a vendor claims is safe
- Building continuous monitoring into the deployment plan from the start, so risk tracking doesn’t depend on someone remembering to check back in six months
- Scheduling periodic reassessment as models are updated, use cases expand, or the regulatory environment shifts
This is also where strategic risk and operational risk tend to surface. A model that performs fine in isolation can still create strategic risk if it’s used in ways that weren’t part of the original assessment, which is exactly why Manage treats risk management as ongoing rather than a box to check once.
Learn more about the potential risks of AI before adopting tools: AI’s Double-Edged Sword: Innovation, Risk, and Responsibility
Aligning AI Deployments with Existing Compliance Programs
One of the more practical advantages of the NIST AI Risk Management Framework is that it wasn’t designed to operate in isolation. Most IT directors are managing AI alongside HIPAA, CMMC, SOC 2, or some combination of the three, and the good news is that a lot of the groundwork already overlaps.
HIPAA
HIPAA already requires a documented risk analysis covering how protected health information is accessed, stored, and transmitted. AI systems that touch clinical data, scheduling tools, or patient communications fall squarely into that requirement, whether or not the tool was purchased with HIPAA in mind.
The Map and Measure functions from the AI RMF slot directly into existing HIPAA risk analysis work. Specific points worth checking:
- Whether training data or system logs expose PHI in ways the existing risk analysis hasn’t accounted for
- Whether access controls around the AI tool match the access controls already required for other systems handling PHI
- Whether audit logging captures AI-driven decisions the same way it captures other system activity
CMMC
For organizations pursuing or maintaining CMMC certification, AI RMF documentation can double as supporting evidence. CMMC Level 2 already requires documented security controls across a wide range of practices, and the Govern and Map functions produce artifacts, ownership records, data flow documentation, risk profiles, that assessors are likely to ask for regardless of whether AI was part of the original scope.
Treating AI risk documentation as a CMMC deliverable from the start avoids having to reconstruct that paperwork later under assessment pressure.
SOC 2
SOC 2’s trust services criteria focus heavily on how an organization monitors and responds to risk over time, which maps closely to the Measure and Manage functions. Continuous monitoring built into an AI deployment plan can serve double duty, supporting both AI risk management and the ongoing monitoring evidence SOC 2 auditors expect to see.
A Note on International Standards
For organizations operating across borders, it’s worth knowing that NIST built the AI RMF to be interoperable with international standards, including ISO/IEC 42001. That interoperability matters in practice: a risk management program built around NIST’s structure shouldn’t require a separate rebuild to satisfy regulatory requirements in another jurisdiction. The underlying documentation largely transfers.
Common Difficulties IT Directors Must Watch For
Even with a solid framework in place, a few recurring mistakes show up across AI risk management programs. Watching for these early can save significant rework later.
- Treating risk assessment as a one-time event. AI systems change as models are updated or retrained. A risk profile built at launch can be outdated within months if nobody revisits it.
- Siloing AI oversight away from existing security teams. When AI risk is managed separately from the rest of the security program, duplicate work and inconsistent standards tend to follow.
- Underestimating operational risk in favor of strategic risk, or the reverse. Some teams focus entirely on high-level strategic risk, like reputational exposure, while missing the operational risk of a system that simply produces inconsistent results day to day. A complete risk management strategy accounts for both.
- Skipping documentation because a deployment feels low-risk. Low-risk use cases still need a paper trail. Auditors and regulators generally care less about the outcome and more about whether a process existed to assess it.
Turn the NIST AI RMF Into Practice
The NIST AI Risk Management Framework gives IT directors something they didn’t have before: a structured way to talk about AI risk that holds up in front of auditors, regulators, and leadership alike. The four functions provide the shape of the work. The real value comes from connecting that work to what your organization is already doing under HIPAA, CMMC, or SOC 2, rather than treating AI as a separate compliance track that needs its own infrastructure from the ground up.
Getting this right early tends to matter more than it seems to at the time. A risk management program built with intention now is a lot easier to defend, extend, and maintain than one assembled after the fact.
Developing an AI risk management program is easier with a partner who has spent decades working inside federal-grade security and compliance requirements. SMS brings that background to commercial organizations navigating HIPAA, CMMC, and SOC 2 alongside their AI deployments, helping IT teams put a NIST-aligned framework in place that holds up to scrutiny from day one of an audit.
If you’re weighing how AI fits into your existing compliance program, we can talk you through where your current risk management process stands and what it would take to align it with the NIST AI RMF.