The Four NIST AI RMF Functions
Candidates learn the four functions of the NIST AI RMF as a running order. Govern first, then map, then measure, then manage. The framework says something different, and the difference is testable. NIST states that the functions may run in any order across the AI lifecycle, once a governance structure exists.
What the AI RMF is, and what it is not
The Artificial Intelligence Risk Management Framework, published as NIST AI 100-1 in January 2023, is voluntary guidance. It carries no legal force of its own. NIST describes it as rights-preserving, non-sector-specific and use-case agnostic, built to suit organisations of any size.
Part 1 frames AI risk and lists the characteristics of trustworthy AI. Seven appear: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. Part 2 holds the Core. That is where the four functions live, each broken into categories and subcategories. Supporting material sits in the AI RMF Playbook.
Govern
Govern cultivates a culture of risk management inside the organisation. It sets out the processes, documents and organisational schemes that anticipate and manage the risks a system can pose. It provides the structure by which risk management meets organisational principles and strategic priorities. Coverage runs across the full product lifecycle, third-party software, hardware and data included.
NIST calls Govern a cross-cutting function, infused throughout the process and enabling the other three. Aspects of it, particularly those touching compliance or evaluation, belong inside each of the others rather than beside them.
Map
Map establishes the context that frames risk for a specific system. Five categories sit under it. Context comes first, then categorisation of the system. Capabilities, goals and benchmarks follow. Risks and benefits get mapped across all components, third-party data and software included. Impacts on individuals, groups, communities, organisations and society close the set.
Finish Map and an organisation should hold enough context for an initial go or no-go decision on the system. That decision point matters more than the ordering question, and exam items like it.
Measure
Measure analyses, assesses, benchmarks and monitors risk using quantitative, qualitative or mixed methods. It draws on what Map produced and feeds what Manage does next. Systems get tested before deployment and regularly while running.
One detail repays attention. The AI RMF asks organisations to document the risks or trustworthiness characteristics they will not or cannot measure. Admitting a measurement gap counts as an outcome, not a failure.
Manage
Manage allocates resources to the risks that Map and Measure identified, on a regular basis and as Govern defined. Risk response options include mitigating, transferring, avoiding or accepting. Negative residual risk gets documented for downstream acquirers and end users.
Why the AI RMF ordering question matters
NIST is explicit that the actions inside the Core are neither a checklist nor an ordered set of steps. Some organisations select from among the categories, others apply all of them. Having instituted the outcomes in Govern, NIST expects the typical user to start with Map. Measure or Manage comes next, iterating and cross-referencing throughout.
So Govern comes first in a structural sense and not a chronological one. It is the condition making the other three repeatable. NIST therefore draws it across all of them rather than in front of them.
Where profiles fit
Profiles implement the functions, categories and subcategories for a particular setting or application. A current profile describes how AI risk management runs today. A target profile describes the outcomes an organisation wants. Comparing the two exposes the gaps worth an action plan. NIST does not prescribe a profile template.
The AI RMF in the AIGP exam
The Body of Knowledge is the IAPP’s published outline of what each certification exam tests. Standards and tools sit in Domain II. The AI RMF appears there beside the OECD principles and the core ISO AI standards.
Three traps recur. The first offers a rigid four-step sequence and calls it the framework. A second treats the AI RMF as binding law, which it is not. Another confuses the four functions with the seven trustworthiness characteristics. Learn both lists cleanly and keep them apart. Our AIGP study guide sets the framework in the wider curriculum. The 2026 update analysis covers what moved in the current Body of Knowledge.
You can recite the four functions and still stumble when a scenario asks which one an activity belongs to. That gap is question technique rather than recall. The AIGP Exam Question Masterclass at €195 addresses that directly.
