The NIST AI Risk Management Framework is useful when it changes the questions a team asks about a real workflow. It is much less useful as a label on an inventory or a substitute for a decision.
Applied carefully, its four functions help expose missing ownership, context, evidence, and failure handling. The framework does not decide whether a proposed workflow is appropriate, and a completed worksheet is neither certification nor a compliance determination.
This article provides general operational education. It is not legal advice or a compliance determination. No attorney-client relationship exists, and none of its protections apply.
Use the version that actually exists
NIST is the United States National Institute of Standards and Technology. Its AI Risk Management Framework is intended for voluntary use across sectors.
Version 1.0 was released in January 2023. As checked on September 18, 2026, NIST says that version is being revised as part of the White House AI Action Plan. This reference describes version 1.0, not an assumed final successor.
The framework is distinct from legislation, a regulator's determination, and a professional ethics opinion. Any obligations affecting a firm's work need their own source and qualified assessment.
Turn four functions into operating questions
The AI RMF Core has 4 functions: GOVERN, MAP, MEASURE, and MANAGE. They interact throughout the system's life; they are not a one-time approval sequence.
The questions below are Ortaire's suggested application to one workflow. They are not an official NIST checklist or a complete implementation of the framework.
GOVERN: who can decide?
Identify the workflow owner, reviewer, and person authorized to approve changes. Record where people raise an error and who can stop the process.
This reference reuses the fictional internal-request workflow from the small-law-firm workflow guide. There, the office manager owns the operating result and can pause it. The coordinator reviews every proposed routing before it is sent. The administrator holds the approved account and is the only person who changes its connections. The firm writes those 3 names on the ownership card, with a backup for the coordinator.
MAP: what is the work and its context?
Describe the inputs, output, intended users, and destination. Identify excluded cases and plausible consequences of a wrong result.
For the same workflow, the included inputs are meeting-room, equipment, and administrative requests, in synthetic form. Anything that reads like a client matter or a legal deadline goes to the coordinator by the existing route without touching the assistant. The office manager can explain that boundary to a new hire in 1 sentence, which is the test that it is real.
MEASURE: what evidence would support continued use?
Set acceptance conditions before testing. Compare similar completed work, including review and correction effort. Keep errors visible alongside averages.
The coordinator writes 4 acceptance conditions before the first run. They are an allowed category or an explicit request for clarification, no invented facts, excluded requests reaching the human route, and nothing forwarded until accepted. Twelve synthetic messages go through, including 2 marked urgent. Both urgent messages are misrouted. The failure count, not the 10 successes, is what the team records. A rehearsal like this cannot establish a live operating history.
MANAGE: what happens when the result is unacceptable?
Define correction, escalation, fallback, and pause routes. Decide who can authorize a restart and what evidence they need.
The 2 misroutes narrow the scope: urgent messages now bypass the assistant entirely. The office manager may pause routing at any time. Only the administrator restarts it, after the changed boundary passes the 2 failed cases again. If the narrower workflow stops saving effort, the firm keeps the manual route and records why.
What the framework changed
For the fictional firm, the 4 functions did not add a document. They changed 4 decisions. GOVERN gave the office manager, not the vendor, the authority to pause routing. MAP moved "urgent" messages out of the assistant's scope before the first test. Nobody could say whether urgent meant a meeting room or a client deadline. MEASURE turned "it seems to work" into 12 test messages, 2 of which failed. MANAGE wrote down who could restart the assistant and what they needed to see first.
That is the useful size of the framework for 1 workflow: enough process for the consequence, kept in a system the team already uses. The checkpoint and ownership card and the workflow evidence card hold the answers. Reread this reference when NIST publishes the revision it has announced.
Ortaire's AI Governance Toolkit is arranged roughly along the same 4 functions. MAP has intake and inventory records, GOVERN an oversight and accountability record, MEASURE testing and success metrics, and MANAGE leadership reporting. It is a starting set of records, not an implementation of the framework.
Sources used
- NIST AI Risk Management Framework, January 2023; revision status and stated White House AI Action Plan driver checked September 18, 2026.
- AI RMF Core, AI RMF 1.0; checked September 18, 2026.




