NIST AI RMF 1.0 and the Generative AI Profile, and what they are actually for
A customer has asked whether you follow the NIST AI framework, and somebody has already said yes in an email. The honest follow-up questions are which framework, which version, and what “follow” would have to mean for the answer to survive a second round of diligence.
Published 22 September 2026. Written by the SecHB practice, Greater Vancouver, British Columbia.
The short version
No. There is no certificate against NIST AI RMF 1.0 and no body that issues one, because NIST publishes the framework for voluntary use rather than as a scheme anybody assesses you under. What it gives you instead is a structure for deciding what to do and a vocabulary for writing down why — which turns out to be what most AI governance questions are actually asking for.
NIST states that the framework is intended for voluntary use, so it binds nobody on its own. What makes it land in practice is a contract, a customer questionnaire, a sectoral regulator or an internal policy naming it.
What AI RMF 1.0 is, and when it was released
The NIST AI Risk Management Framework (AI RMF 1.0) was released on 26 January 2023. NIST describes it as intended for voluntary use, developed through an open consensus process, and aimed at helping organizations build trustworthiness considerations into how AI products and systems are designed, developed, used and evaluated.
It is deliberately not a control catalogue. It does not tell you to encrypt a particular thing or log a particular event. It tells you which questions an organization running AI has to have answers to, and leaves the answers to your context — which is why it pairs well with a technical checklist and badly with a procurement team hoping for a pass or fail.
The four functions, described as work rather than as a diagram
The framework core is organized into four functions — Govern, Map, Measure and Manage — which the NIST AI RMF Playbook names and expands into suggested actions per subcategory. Read as a diagram they look like a process. Read as work, they are four questions with evidence attached.
Govern
Who decides, on what authority, and what happens when the answer is no. In practice this is the least technical and most often skipped: an owner for AI risk, a policy that says which uses need approval, a route for raising a concern, and a record of decisions that someone outside the team can read.
Map
What AI is actually running, in what context, for whom, with what data, and what could go wrong in that specific setting. Most organizations discover during this step that the inventory they thought they had is a list of approved tools rather than a list of live ones.
Measure
Testing, evaluating and tracking the things Map said mattered — with methods and metrics written down, so a later result can be compared to an earlier one rather than argued about.
Manage
Acting on what Measure found: prioritizing, treating, accepting or stopping, with the resourcing and the monitoring that makes the treatment real rather than intended.
What the Generative AI Profile adds, and who it is for
On 26 July 2024 NIST released NIST AI 600-1, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile. NIST describes it as helping organizations identify the risks that are distinctive to generative AI and proposing actions to manage them in line with their own goals and priorities.
The distinction that matters when you are deciding whether to read it: AI RMF 1.0 is written for AI in general, including the ordinary predictive models a business has run for years. The profile is written for the case where the system generates content, which brings in the failure modes a fraud model never had — an output that is fluent and wrong, a third-party model whose training data you cannot see, and a component that takes instructions from whatever text reaches it.
If your generative features are already live, the profile is the more useful of the two to read first, and the framework is the structure you hang the answers on.
How a gap review against it actually runs
A review against AI RMF 1.0 is not a scan and not a questionnaire. It runs roughly as four passes, one per function, and its output is a list of places where the organization has a practice with nothing written down, something written down that nobody follows, or neither.
- Inventory first. Every AI system and feature in use, including the ones procured on a corporate card and the ones embedded in software you already licence. Nothing downstream is real without this.
- Context per system. Who it affects, what data it touches, what decision it influences, and what a wrong output costs. This is what makes the difference between a marketing drafting tool and an eligibility screen.
- Evidence per claim. For each control the organization believes it has, the artifact that shows it operates — a log, a configuration, a ticket, an approval record. A claim with no artifact is a finding.
- A plan that survives contact. Ranked by exposure rather than by how easy a gap is to close, with an owner and a date per item.
The deliverable a buyer should expect is the gap list, the evidence map and the plan — not a score. A score against a voluntary framework is a number somebody invented.
What it will not do for you
No. There is no certificate against NIST AI RMF 1.0 and no body that issues one, because NIST publishes the framework for voluntary use rather than as a scheme anybody assesses you under. That is worth being blunt about, because a customer who asks in a questionnaire whether you hold a NIST AI RMF credential is asking a question with no true yes. The answer that survives is a description of what you have done against the framework, with the artifacts behind it.
It will also not tell you whether a specific prompt-injection path reaches your database. Nothing in the framework is at that altitude, and it does not claim to be.
Why the version matters
Write "AI RMF 1.0", not "the NIST AI framework", because NIST states that AI RMF 1.0 is being revised and a document that does not name its version cannot be checked against the one it was written from. The same NIST page that carries the release date states that AI RMF 1.0 is being revised as part of the White House AI Action Plan, and the Playbook notes that it will be updated after the framework is. Two documents that both say “aligned to the NIST AI framework” can therefore mean different things by the time anyone compares them.
Waiting costs more than it saves. The four functions describe work an organization has to do in any version — knowing what AI it runs, deciding who owns the decisions, measuring behaviour and acting on what the measurement says — and an inventory built this year is not invalidated by a renumbered subcategory next year.
Using it alongside the OWASP LLM Top 10
The two are complementary and are often presented as alternatives, which helps nobody. AI RMF 1.0 answers “who decides, what do we run, how do we know, what do we do about it”. The OWASP Top 10 for LLM Applications answers “what specifically goes wrong in a system with a language model in it”.
In a review that uses both, the framework supplies the Map and Govern structure and the OWASP list supplies the threat content that Measure is measuring. Used alone, the framework tends to produce governance with no technical findings, and the OWASP list tends to produce technical findings nobody owns.
How the work is bounded
The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
Questions we are asked
Can we get a NIST AI RMF certificate?
No. There is no certificate against NIST AI RMF 1.0 and no body that issues one, because NIST publishes the framework for voluntary use rather than as a scheme anybody assesses you under.
Is NIST AI RMF mandatory for anyone?
NIST states that the framework is intended for voluntary use, so it binds nobody on its own. What makes it land in practice is a contract, a customer questionnaire, a sectoral regulator or an internal policy naming it.
Should we wait for the revision before starting?
Waiting costs more than it saves. The four functions describe work an organization has to do in any version — knowing what AI it runs, deciding who owns the decisions, measuring behaviour and acting on what the measurement says — and an inventory built this year is not invalidated by a renumbered subcategory next year.
Why does the version number matter?
Write "AI RMF 1.0", not "the NIST AI framework", because NIST states that AI RMF 1.0 is being revised and a document that does not name its version cannot be checked against the one it was written from.
Where to go from here
If the question behind this is a customer asking for governance evidence, AI governance readiness is the engagement that builds it. If the question is what an attacker can reach, an AI security assessment answers that instead. If someone has asked you to choose between this and a management system standard, ISO/IEC 42001 and NIST AI RMF compared sets out what exists at the end of each path. The rest of the AI security practice and the other articles are indexed under Writing.
Describe what AI is running and who is asking about it, and the reply will say which of the two frames answers them.