NIST AI RMF vs US federal: what they share and how they differ

NIST AI RMF and US federal share 8 of 24 control themes and 8 checks. 100% of US federal requirements can be proven with checks NIST AI RMF already uses, 28% the other way round.

USVoluntary frameworkVoluntary

NIST AI RMF

How to apply the NIST AI RMF to your AI systems

72 requirementsNext Dec 2026
USExecutive policyIn force

US federal

What US federal AI policy requires

4 requirementsNext 2027
8/24shared control themes
8shared checks
100%of US federal requirements covered by NIST AI RMF evidence
28%of NIST AI RMF requirements covered by US federal evidence

At a glance

NIST AI RMF US federal
JurisdictionUnited States (federal) sameUnited States (federal) same
KindVoluntary frameworkExecutive policy
StatusVoluntaryIn force
BindingNoYes
Object analysedAI system sameAI system same
ScopeAny organisation designing, deploying or using AI.Federal agencies and their vendors.
Territorial reachNo territorial scope; de facto reference for US public buyers.Federal government.
PenaltiesNone (voluntary). Leverage: safe harbour in state laws.No direct penalty; contractual and budget conditions.
Qualification axesInternal risk tier (organisation-defined)High-impact AI (OMB M-25-21)
RolesAI actorFederal agency, Vendor
Requirements724
Next milestoneDec 2026, Expected RMF revision2027, Federal pre-emption statute

Theme by theme

requirements per theme

What they share: one piece of evidence, two frameworks

8

CodeCheckRequirements NIST AI RMFRequirements US federal
CHK-ROLES-CLARIFIEDRoles, responsibilities and delegated authorities are documented and clear to relevant stakeholders
CHK-INVENTORYA mechanism to inventory AI systems is in place and resourced
CHK-EXEC-ACCOUNTExecutive leadership is accountable for AI risk decisions (board committee, risk appetite)
CHK-IMPACT-ASSESSAn impact assessment is performed, documented and used in go/no-go and risk decisions
CHK-THIRDPARTY-POLPolicies address third-party AI/data risks, incl. IP, transparency and testing
CHK-TEVVTEVV plan, test sets, metrics and data considerations are documented
VER-021-F-01Operational monitoring plan
VER-008-02System designed to allow human oversight (stop button, override)

Differences: requirements specific to each framework

Requirements with no check serving the other framework: the extra work.

NIST AI RMF

52

US federal

0

None: every requirement shares at least one check.

Timelines

PastSet in the textPotentialTo verify
Jan 26, 2023NIST AI RMF · AI RMF 1.0
Oct 30, 2023US federal · EO 14110 (safe AI)
Jul 26, 2024NIST AI RMF · Generative AI Profile (NIST AI 600-1)
Jan 20, 2025US federal · EO 14110 revoked
Jan 23, 2025US federal · EO 14179: removing barriers to AI
Apr 3, 2025US federal · OMB memos M-25-21 (use) and M-25-22 (procurement)
Jul 23, 2025NIST AI RMF · AI Action Plan asks for a revision of the framework
Jul 23, 2025US federal · America's AI Action Plan
Dec 11, 2025US federal · EO on a national framework: challenge to state laws
Dec 2026NIST AI RMF · Expected RMF revision
2027US federal · Federal pre-emption statute

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo