[{"data":1,"prerenderedAt":734},["ShallowReactive",2],{"blog-\u002Fblog\u002Fnist-ai-rmf-functions-and-categories":3,"blog-related-\u002Fblog\u002Fnist-ai-rmf-functions-and-categories":716,"blog-surround-\u002Fblog\u002Fnist-ai-rmf-functions-and-categories":733},{"id":4,"title":5,"audience":6,"body":11,"cluster":668,"conversionGoal":669,"cornerstone":670,"date":671,"description":672,"draft":670,"extension":673,"factCheckedAt":671,"faq":674,"featured":670,"language":669,"meta":690,"minRead":691,"navigation":692,"order":693,"originalAsset":669,"path":694,"pillar":695,"primaryKeyword":696,"publicationOrder":697,"relatedProject":669,"releaseScope":698,"reviewCycle":699,"reviewMethod":700,"reviewStatus":701,"reviewedAt":671,"reviewedBy":702,"searchIntent":703,"seo":704,"sources":705,"stem":710,"tags":711,"type":714,"updated":671,"__hash__":715},"blog\u002Fblog\u002Fnist-ai-rmf-functions-and-categories.md","NIST AI RMF: The Functions and Categories, Explained",[7,8,9,10],"enterprise-architect","transformation-lead","financial-controller","engineering-manager",{"type":12,"value":13,"toc":656},"minimark",[14,22,25,30,138,141,153,159,163,174,199,202,206,301,309,322,326,405,412,419,423,493,505,513,516,520,586,594,598,601,611,622,628,632,635,643],[15,16,17,21],"p",{},[18,19,20],"strong",{},"The NIST AI Risk Management Framework has four functions — GOVERN, MAP, MEASURE and MANAGE — holding 19 categories and 72 subcategories between them, and GOVERN is cross-cutting rather than first in a sequence."," It is voluntary, it is not a regulation, and most of what it asks is whether controls a finance function already runs have been extended to cover a component whose output varies.",[15,23,24],{},"This page is the structure, verified line by line against NIST AI 100-1, with the counts stated so you can tell at a glance where the weight sits. The commentary underneath each function is mine: eighteen years of controls work in SAP FI and treasury, pointed at the question the framework actually asks.",[26,27,29],"h2",{"id":28},"the-shape-of-it","The shape of it",[31,32,33,53],"table",{},[34,35,36],"thead",{},[37,38,39,43,47,50],"tr",{},[40,41,42],"th",{},"Function",[40,44,46],{"align":45},"right","Categories",[40,48,49],{"align":45},"Subcategories",[40,51,52],{},"What it asks",[54,55,56,73,89,105,120],"tbody",{},[37,57,58,64,67,70],{},[59,60,61],"td",{},[18,62,63],{},"GOVERN",[59,65,66],{"align":45},"6",[59,68,69],{"align":45},"19",[59,71,72],{},"Is there a culture, an owner and a policy — across all three below",[37,74,75,80,83,86],{},[59,76,77],{},[18,78,79],{},"MAP",[59,81,82],{"align":45},"5",[59,84,85],{"align":45},"18",[59,87,88],{},"Do you understand the context, the system and the risks",[37,90,91,96,99,102],{},[59,92,93],{},[18,94,95],{},"MEASURE",[59,97,98],{"align":45},"4",[59,100,101],{"align":45},"22",[59,103,104],{},"Can you evaluate and track it, with methods and metrics",[37,106,107,112,114,117],{},[59,108,109],{},[18,110,111],{},"MANAGE",[59,113,98],{"align":45},[59,115,116],{"align":45},"13",[59,118,119],{},"Do you act on what you found, including recovery",[37,121,122,127,131,136],{},[59,123,124],{},[18,125,126],{},"Total",[59,128,129],{"align":45},[18,130,69],{},[59,132,133],{"align":45},[18,134,135],{},"72",[59,137],{},[15,139,140],{},"Two things are worth reading off that table before anything else.",[15,142,143,146,147,152],{},[18,144,145],{},"GOVERN is not step one."," NIST is explicit that governance is a cross-cutting function designed to inform and be infused throughout the other three. Treating it as a gate you pass before the work starts produces the failure mode I described in ",[148,149,151],"a",{"href":150},"\u002Fblog\u002Fwhere-to-start-with-enterprise-ai","where to start with enterprise AI",": a control regime written against no concrete case, calibrated for the worst thing anyone imagined.",[15,154,155,158],{},[18,156,157],{},"MEASURE 2 is the heaviest single category in the framework",", with 13 of the 72 subcategories. It is the one about evaluating a system against the trustworthiness characteristics. If your programme's effort is not lopsided toward measurement, it is not following the shape of this framework — whatever the slide says.",[26,160,162],{"id":161},"the-seven-characteristics-of-trustworthy-ai","The seven characteristics of trustworthy AI",[15,164,165,166,169,170,173],{},"The framework names these, and the ordering carries meaning. NIST treats ",[18,167,168],{},"valid and reliable"," as the base condition — the other characteristics do not add up to trustworthiness without it — and ",[18,171,172],{},"accountable and transparent"," as relating to all the others rather than sitting beside them.",[175,176,177,181,184,187,190,193,196],"ol",{},[178,179,180],"li",{},"Valid and reliable",[178,182,183],{},"Safe",[178,185,186],{},"Secure and resilient",[178,188,189],{},"Accountable and transparent",[178,191,192],{},"Explainable and interpretable",[178,194,195],{},"Privacy-enhanced",[178,197,198],{},"Fair, with harmful bias managed",[15,200,201],{},"The framework is explicit that these are balanced for a given system and context, not maximised independently — which is the honest position, because several of them trade against each other in any real design.",[26,203,205],{"id":204},"govern-6-categories-19-subcategories","GOVERN — 6 categories, 19 subcategories",[31,207,208,221],{},[34,209,210],{},[37,211,212,215,218],{},[40,213,214],{},"Category",[40,216,217],{},"In one line",[40,219,220],{},"The finance-control equivalent",[54,222,223,236,249,262,275,288],{},[37,224,225,230,233],{},[59,226,227],{},[18,228,229],{},"GOVERN 1",[59,231,232],{},"Policies, processes and practices for mapping, measuring and managing AI risk are in place and implemented",[59,234,235],{},"The control framework document nobody reads until an audit",[37,237,238,243,246],{},[59,239,240],{},[18,241,242],{},"GOVERN 2",[59,244,245],{},"Accountability structures: teams empowered, responsible and trained",[59,247,248],{},"The named process owner and the delegation of authority",[37,250,251,256,259],{},[59,252,253],{},[18,254,255],{},"GOVERN 3",[59,257,258],{},"Workforce diversity, equity, inclusion and accessibility in the risk work",[59,260,261],{},"No direct equivalent — this one is genuinely additional",[37,263,264,269,272],{},[59,265,266],{},[18,267,268],{},"GOVERN 4",[59,270,271],{},"A culture that considers and communicates AI risk",[59,273,274],{},"Speak-up culture; the thing every incident review says was missing",[37,276,277,282,285],{},[59,278,279],{},[18,280,281],{},"GOVERN 5",[59,283,284],{},"Robust engagement with relevant AI actors",[59,286,287],{},"Stakeholder management, including the people the output lands on",[37,289,290,295,298],{},[59,291,292],{},[18,293,294],{},"GOVERN 6",[59,296,297],{},"Third-party software, data and supply-chain risk",[59,299,300],{},"Vendor risk management, extended to models and training data",[15,302,303,304,308],{},"GOVERN 2 is the one I would put first in practice. Accountability is where AI governance most often fails and it fails the same way every time: the accountable party is \"the AI team\", which is the same as nobody. The rule that holds is the one every control already follows — a named person who can change the system, see the exception queue, and stop it. That is ",[148,305,307],{"href":306},"\u002Fblog\u002Fwhy-most-ai-pilots-never-become-operating-systems","the ownership question",", and no framework can answer it for you.",[15,310,311,312,316,317,321],{},"GOVERN 6 deserves more weight than it usually gets in enterprise programmes, because for most organisations the model is third-party, the training data is third-party, and the agent platform is third-party. Vendor risk management is not a formality here; it is most of the attack surface, and the questions worth asking are ",[148,313,315],{"href":314},"\u002Fblog\u002Fevaluating-enterprise-ai-vendor-claims","the ones a vendor's accuracy claim cannot survive",". The security list names the same gap in almost the same words — ",[148,318,320],{"href":319},"\u002Fblog\u002Fowasp-llm-top-10-2026-for-enterprise-finance","LLM04 Supply Chain in the 2026 OWASP LLM Top 10",".",[26,323,325],{"id":324},"map-5-categories-18-subcategories","MAP — 5 categories, 18 subcategories",[31,327,328,338],{},[34,329,330],{},[37,331,332,334,336],{},[40,333,214],{},[40,335,217],{},[40,337,220],{},[54,339,340,353,366,379,392],{},[37,341,342,347,350],{},[59,343,344],{},[18,345,346],{},"MAP 1",[59,348,349],{},"Context is established and understood",[59,351,352],{},"The scoping workshop, done honestly",[37,354,355,360,363],{},[59,356,357],{},[18,358,359],{},"MAP 2",[59,361,362],{},"Categorization of the AI system is performed",[59,364,365],{},"System classification on the application inventory",[37,367,368,373,376],{},[59,369,370],{},[18,371,372],{},"MAP 3",[59,374,375],{},"Capabilities, usage, goals, benefits and costs against benchmarks",[59,377,378],{},"The business case, with a baseline",[37,380,381,386,389],{},[59,382,383],{},[18,384,385],{},"MAP 4",[59,387,388],{},"Risks and benefits mapped across all components, including third-party",[59,390,391],{},"The interface inventory and the dependency map",[37,393,394,399,402],{},[59,395,396],{},[18,397,398],{},"MAP 5",[59,400,401],{},"Impacts to individuals, groups, organizations and society characterized",[59,403,404],{},"Impact assessment — the half of a risk register nobody fills in",[15,406,407,408,321],{},"MAP 3 is where I would put the most pressure, because \"expected benefits and costs compared with appropriate benchmarks\" is precisely the step that gets skipped. A benefit stated without a baseline cannot be checked afterwards, which is the whole argument for ",[148,409,411],{"href":410},"\u002Fblog\u002Fhow-to-measure-roi-from-an-ai-workflow","measuring the work rather than the tool",[15,413,414,415,321],{},"MAP 4 is the one an enterprise architect will recognise immediately. It is the interface estate, and the reason it matters here is that an AI component's risk is mostly inherited from what it can reach — ",[148,416,418],{"href":417},"\u002Fblog\u002Fwhy-enterprise-ai-is-an-architecture-problem","an architecture problem, not a model problem",[26,420,422],{"id":421},"measure-4-categories-22-subcategories","MEASURE — 4 categories, 22 subcategories",[31,424,425,435],{},[34,426,427],{},[37,428,429,431,433],{},[40,430,214],{},[40,432,217],{},[40,434,220],{},[54,436,437,450,467,480],{},[37,438,439,444,447],{},[59,440,441],{},[18,442,443],{},"MEASURE 1",[59,445,446],{},"Appropriate methods and metrics are identified and applied",[59,448,449],{},"Test strategy: deciding what \"correct\" means before testing",[37,451,452,457,464],{},[59,453,454],{},[18,455,456],{},"MEASURE 2",[59,458,459,460,463],{},"Systems are evaluated for trustworthy characteristics (",[18,461,462],{},"13 subcategories",")",[59,465,466],{},"UAT, regression testing, and the evidence pack",[37,468,469,474,477],{},[59,470,471],{},[18,472,473],{},"MEASURE 3",[59,475,476],{},"Mechanisms for tracking identified risks over time",[59,478,479],{},"KRIs on the risk register; monitoring and alerting",[37,481,482,487,490],{},[59,483,484],{},[18,485,486],{},"MEASURE 4",[59,488,489],{},"Feedback about the efficacy of measurement is gathered and assessed",[59,491,492],{},"The post-implementation review that asks whether the tests were the right tests",[15,494,495,496,500,501,321],{},"MEASURE 1 contains the step teams reliably skip: deciding the method and the metric ",[497,498,499],"em",{},"before"," measuring. In systems delivery that is a test strategy, and the AI version has one extra obligation — the output varies, so a single pass tells you nothing without a defined sample and a defined threshold. That is ",[148,502,504],{"href":503},"\u002Fblog\u002Fai-evaluation-and-regression-testing","regression testing for a probabilistic component",[15,506,507,508,512],{},"MEASURE 3 is the one that ages worst if you leave it. Tracking risk over time means noticing that behaviour drifted, and if the detection mechanism is \"a customer told us\", there is no mechanism — which is what ",[148,509,511],{"href":510},"\u002Fblog\u002Fproduction-ai-observability","production observability"," exists to fix.",[15,514,515],{},"MEASURE 4 — assessing whether your measurement was any good — is unusual, and it is the most self-aware thing in the framework. Very few control environments ask it about anything.",[26,517,519],{"id":518},"manage-4-categories-13-subcategories","MANAGE — 4 categories, 13 subcategories",[31,521,522,532],{},[34,523,524],{},[37,525,526,528,530],{},[40,527,214],{},[40,529,217],{},[40,531,220],{},[54,533,534,547,560,573],{},[37,535,536,541,544],{},[59,537,538],{},[18,539,540],{},"MANAGE 1",[59,542,543],{},"Risks from MAP and MEASURE are prioritized, responded to and managed",[59,545,546],{},"Risk treatment decisions on a RAID log",[37,548,549,554,557],{},[59,550,551],{},[18,552,553],{},"MANAGE 2",[59,555,556],{},"Strategies to maximize benefits and minimize negative impacts",[59,558,559],{},"The design decisions themselves — where the human sits, what is automated",[37,561,562,567,570],{},[59,563,564],{},[18,565,566],{},"MANAGE 3",[59,568,569],{},"Risks and benefits from third-party entities are managed",[59,571,572],{},"Ongoing vendor management, not just onboarding",[37,574,575,580,583],{},[59,576,577],{},[18,578,579],{},"MANAGE 4",[59,581,582],{},"Risk treatments, response, recovery and communication documented and monitored",[59,584,585],{},"Incident management and the cutover fallback",[15,587,588,589,593],{},"MANAGE 4 is the gate I would refuse to waive. Response and recovery for an AI step means a tested way to undo a wrong output and a defined route for who is called when it misbehaves out of hours — which is exactly ",[148,590,592],{"href":591},"\u002Fblog\u002Fai-pilot-exit-criteria","what a pilot has to prove before production",", and it is the gate most often assumed rather than exercised.",[26,595,597],{"id":596},"what-the-framework-does-not-do","What the framework does not do",[15,599,600],{},"Worth stating plainly, because the gap is where the disappointment comes from.",[15,602,603,606,607,321],{},[18,604,605],{},"It is voluntary, and it is not law."," Nothing in it carries a penalty. If your obligation is regulatory, the binding instrument in Europe is the AI Act, with dated requirements — ",[148,608,610],{"href":609},"\u002Fblog\u002Feu-ai-act-high-risk-requirements-finance-systems","which apply on a schedule the framework says nothing about",[15,612,613,616,617,621],{},[18,614,615],{},"It will not tell you whether to build the thing."," The framework assumes a system exists or is planned. The prior question — whether this workflow should be redesigned with AI at all — is not in scope, and ",[148,618,620],{"href":619},"\u002Fblog\u002Fhow-to-find-enterprise-workflows-worth-redesigning-with-ai","an assessment that can answer \"don't\""," is a separate exercise.",[15,623,624,627],{},[18,625,626],{},"It does not size your exception queue, set your thresholds or design your control path."," Those are engineering and operating decisions. The framework tells you they must exist and be documented; it deliberately does not tell you what good looks like for your volume, which is correct for a non-sector-specific framework and unhelpful on the Monday you have to decide.",[26,629,631],{"id":630},"what-i-would-decide","What I would decide",[15,633,634],{},"Use it as a checklist and a vocabulary, not as a programme plan. Run your existing control inventory against the 19 categories and mark the ones an existing control already covers — for most finance functions that is the majority, and the exercise takes an afternoon rather than a workstream. Put the real effort into the three that are genuinely different for a probabilistic component: GOVERN 6 because the supply chain is the model, MEASURE 2 because it is a third of the framework by weight, and MANAGE 4 because a recovery path nobody has exercised does not exist.",[15,636,637,638,642],{},"And do not let the framework substitute for the decision underneath it. Naming a risk in a register is not a control. ",[148,639,641],{"href":640},"\u002Fblog\u002Fthe-enterprise-ai-control-layer","Something deterministic in the path"," is.",[15,644,645],{},[497,646,647,648,651,652,321],{},"See also ",[148,649,650],{"href":609},"the EU AI Act's high-risk requirements"," and ",[148,653,655],{"href":654},"\u002Fblog\u002Fenterprise-ai-agent-security-boundaries","security boundaries for enterprise AI agents",{"title":657,"searchDepth":658,"depth":658,"links":659},"",2,[660,661,662,663,664,665,666,667],{"id":28,"depth":658,"text":29},{"id":161,"depth":658,"text":162},{"id":204,"depth":658,"text":205},{"id":324,"depth":658,"text":325},{"id":421,"depth":658,"text":422},{"id":518,"depth":658,"text":519},{"id":596,"depth":658,"text":597},{"id":630,"depth":658,"text":631},"governance",null,false,"2026-08-19","All four functions and 19 categories of the NIST AI Risk Management Framework, with subcategory counts — and which finance controls already cover each one.","md",[675,678,681,684,687],{"question":676,"answer":677},"What are the four functions of the NIST AI RMF?","GOVERN, MAP, MEASURE and MANAGE. GOVERN is the cross-cutting one: NIST designs it to inform and be infused throughout the other three rather than to sit before them in a sequence. MAP establishes context and identifies risks, MEASURE analyses and tracks them with methods and metrics, and MANAGE prioritises and acts on them, including response and recovery. The framework is voluntary and non-sector-specific, so the functions describe what has to be true rather than prescribing how an organisation achieves it.",{"question":679,"answer":680},"How many categories and subcategories does the NIST AI RMF have?","Nineteen categories and 72 subcategories across the four functions. GOVERN has 6 categories and 19 subcategories, MAP has 5 and 18, MEASURE has 4 and 22, and MANAGE has 4 and 13. MEASURE 2 alone carries 13 subcategories, which is the largest single group in the framework and a fair signal of where NIST expects the work to be — evaluating a system against the trustworthiness characteristics is more detailed than governing or managing it.",{"question":682,"answer":683},"What are the seven characteristics of trustworthy AI in the NIST framework?","Valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. NIST treats valid and reliable as the base condition — without it the others do not get you a trustworthy system — and accountable and transparent as cutting across all the rest. The framework is explicit that these have to be balanced against each other for a given system and context rather than maximised independently.",{"question":685,"answer":686},"Is the NIST AI RMF mandatory?","No. It is a voluntary framework published by a US standards body, not a regulation, and nothing in it carries a penalty. That is a meaningful difference from the EU AI Act, which is binding law with dated obligations. What the AI RMF gives you is a shared vocabulary and a checklist structure that an internal audit function, a risk committee or a customer's due-diligence questionnaire will recognise — which is often exactly what is needed when the alternative is inventing your own categories.",{"question":688,"answer":689},"How does the NIST AI RMF map to existing finance controls?","More closely than the vocabulary suggests. GOVERN 2 (accountability structures) is the named process owner and delegation of authority you already maintain. GOVERN 6 (third-party software and data) is vendor risk management. MAP 4 (risks across all components including third-party) is the interface inventory. MEASURE 3 (tracking risks over time) is a KRI on a risk register. MANAGE 4 (response, recovery and communication) is the incident process and the fallback in a cutover plan. Most of the framework is asking whether controls you already run have been extended to cover a probabilistic component.",{},10,true,7.5,"\u002Fblog\u002Fnist-ai-rmf-functions-and-categories","enterprise-ai-systems","NIST AI RMF functions",225,"Structure and wording verified against NIST AI 100-1 (AI RMF 1.0, January 2023), the current version of the core framework. NIST publishes companion material — the AI RMF Playbook and the Generative AI Profile (NIST AI 600-1) — on a different cadence; this page describes the framework itself, not those profiles. The AI RMF is voluntary and is not a regulation, and mapping it onto your control environment is an interpretation, not a compliance statement.","semiannual","editorial-and-factual","reviewed","Tan Gravam","informational",{"title":5,"description":672},[706],{"title":707,"url":708,"release":709,"accessed":671},"NIST AI 100-1 — Artificial Intelligence Risk Management Framework (AI RMF 1.0): the four functions, 19 categories, 72 subcategories, and the seven characteristics of trustworthy AI","https:\u002F\u002Fnvlpubs.nist.gov\u002Fnistpubs\u002Fai\u002FNIST.AI.100-1.pdf","AI RMF 1.0, January 2023","blog\u002Fnist-ai-rmf-functions-and-categories",[712,668,713],"enterprise-ai","controls","text","giiblBsxVZ1hDfk_J0LOpf6hf2a5p8UfY1xlqF1dBK0",{"related":717,"prev":728,"next":669,"hasOrder":692,"place":730},[718,721,725],{"path":319,"title":719,"description":720},"The OWASP LLM Top 10 (2026), Read From a Finance Seat","All ten 2026 entries with what changed from 2025 — and which of them a finance or treasury deployment actually meets first.",{"path":722,"title":723,"description":724},"\u002Fblog\u002Fprompt-and-model-versioning","Prompt & Model Versioning: Enterprise AI Governance","A prompt is production code and a model is a dependency you don't control. How to version prompts, handle model changes and stop silent regressions.",{"path":510,"title":726,"description":727},"Production AI Observability in the Enterprise","You can't fix what you can't see. How to observe AI running inside an enterprise — quality, cost, latency, drift and failures — as data, not complaints.",{"path":609,"title":729,"type":714,"language":669},"The EU AI Act's High-Risk Rules Are a Control Environment",{"label":731,"position":658,"total":658,"hub":732},"Governance","\u002Ftopics\u002Fenterprise-ai-systems",[],1787169870291]