In a country with no federal AI law, "voluntary" doesn't mean "optional" in practice — it's the framework regulators, insurers, and enterprise customers expect you to use, even though no law forces you to.
The NIST AI Risk Management Framework (AI RMF 1.0) is voluntary guidance for managing risk across an AI system's entire lifecycle, from design to retirement. In the absence of a federal AI law in the US — and with the current administration actively challenging state laws — the AI RMF ended up filling the vacuum: it's what auditors, insurers, and legal teams at large enterprise customers ask to see when evaluating an AI vendor, even without any direct legal obligation to use it.
GOVERN isn't a standalone step, it's the function that runs through the other three: organizational culture, accountability structures, an inventory of AI systems, and supply-chain management (which third-party models you use, and what guarantees they give you). Without this foundation, the other three functions become isolated exercises with no real owner.
MAP contextualizes each AI system within its real operating environment — what technical, social, and ethical impacts it can have, including risks that come from third parties (a model from one provider, data from another). MEASURE defines which metrics to use to evaluate each trustworthiness characteristic (accuracy, bias, robustness) and tracks risk over time. MANAGE allocates resources to the risks already mapped and measured: prioritizing, defining treatments, planning incident response, and continuously monitoring third-party elements.
NIST publishes a Playbook with actionable, function-by-function guidance — the recommended starting point isn't implementing all four functions at once, but starting with a real inventory of which AI systems the company already uses (part of GOVERN) before trying to measure or manage risk for something that isn't even formally mapped yet.
The AI RMF doesn't compete with ISO/IEC 42001 — they complement each other. ISO 42001 certifies that a formally auditable AI management system (AIMS) exists, while the AI RMF provides the practical content of what to manage and how. Many companies use the AI RMF as internal implementation guidance and then formally certify against ISO 42001 when they need to demonstrate it to a customer or regulator.
Carlos Montiel is an enterprise AI solutions architect. He implements LLMs, Agents, RAG, and orchestrators for companies across Guatemala and Latin America. Reach out for a consultation.
Contact Carlos Montiel