NIST AI RMF vs US federal: what they share and how they differ
NIST AI RMF and US federal share 8 of 24 control themes and 8 checks. 100% of US federal requirements can be proven with checks NIST AI RMF already uses, 28% the other way round.
Voluntary
NIST AI RMF
How to apply the NIST AI RMF to your AI systems
72 requirementsNext Dec 2026
In force
US federal
What US federal AI policy requires
4 requirementsNext 2027
8/24shared control themes
8shared checks
100%of US federal requirements covered by NIST AI RMF evidence
28%of NIST AI RMF requirements covered by US federal evidence
At a glance
| NIST AI RMF | US federal | |
|---|---|---|
| Jurisdiction | United States (federal) same | United States (federal) same |
| Kind | Voluntary framework | Executive policy |
| Status | Voluntary | In force |
| Binding | No | Yes |
| Object analysed | AI system same | AI system same |
| Scope | Any organisation designing, deploying or using AI. | Federal agencies and their vendors. |
| Territorial reach | No territorial scope; de facto reference for US public buyers. | Federal government. |
| Penalties | None (voluntary). Leverage: safe harbour in state laws. | No direct penalty; contractual and budget conditions. |
| Qualification axes | Internal risk tier (organisation-defined) | High-impact AI (OMB M-25-21) |
| Roles | AI actor | Federal agency, Vendor |
| Requirements | 72 | 4 |
| Next milestone | Dec 2026, Expected RMF revision | 2027, Federal pre-emption statute |
Theme by theme
requirements per theme
NIST AI RMFUS federal
Governance
Assessment
Build
People & use
Lifecycle & third parties
What they share: one piece of evidence, two frameworks
8
| Code | Check | Requirements NIST AI RMF | Requirements US federal |
|---|---|---|---|
| CHK-ROLES-CLARIFIED | Roles, responsibilities and delegated authorities are documented and clear to relevant stakeholders | ||
| CHK-INVENTORY | A mechanism to inventory AI systems is in place and resourced | ||
| CHK-EXEC-ACCOUNT | Executive leadership is accountable for AI risk decisions (board committee, risk appetite) | ||
| CHK-IMPACT-ASSESS | An impact assessment is performed, documented and used in go/no-go and risk decisions | ||
| CHK-THIRDPARTY-POL | Policies address third-party AI/data risks, incl. IP, transparency and testing | ||
| CHK-TEVV | TEVV plan, test sets, metrics and data considerations are documented | ||
| VER-021-F-01 | Operational monitoring plan | ||
| VER-008-02 | System designed to allow human oversight (stop button, override) |
Differences: requirements specific to each framework
Requirements with no check serving the other framework: the extra work.
NIST AI RMF
52
GOVERN-1.1
GOVERN-1.2
GOVERN-1.3
GOVERN-4.3
GOVERN-6.2
MAP-1.3
MAP-3.1
MEASURE-2.2
MEASURE-2.7
MEASURE-2.8
MEASURE-2.10
MEASURE-2.11
MEASURE-2.12
MEASURE-3.3
MANAGE-1.2
MANAGE-2.3
MANAGE-3.1
MANAGE-3.2
US federal
0
None: every requirement shares at least one check.
Timelines
PastSet in the textPotentialTo verify
Jan 26, 2023NIST AI RMF · AI RMF 1.0
Oct 30, 2023US federal · EO 14110 (safe AI)
Jul 26, 2024NIST AI RMF · Generative AI Profile (NIST AI 600-1)
Jan 20, 2025US federal · EO 14110 revoked
Jan 23, 2025US federal · EO 14179: removing barriers to AI
Apr 3, 2025US federal · OMB memos M-25-21 (use) and M-25-22 (procurement)
Jul 23, 2025NIST AI RMF · AI Action Plan asks for a revision of the framework
Jul 23, 2025US federal · America's AI Action Plan
Dec 11, 2025US federal · EO on a national framework: challenge to state laws
Dec 2026NIST AI RMF · Expected RMF revision
2027US federal · Federal pre-emption statute
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.