How can a small business use the NIST AI Risk Management Framework?
The NIST AI Risk Management Framework (AI RMF 1.0) is voluntary guidance, released January 26, 2023, for managing risks from AI systems. It has four functions: Govern, Map, Measure and Manage. A small business can use it by naming an owner for AI risk, listing where AI is used, testing the uses that matter most, and deciding what to fix, monitor or stop.
What the framework is
NIST describes the AI RMF as voluntary, rights-preserving, non-sector-specific and use-case agnostic, so it fits organizations of any size. It defines trustworthy AI as valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed.
In July 2024 NIST added NIST AI 600-1, a Generative AI Profile that applies the framework to tools like chatbots and copilots. NIST states that AI RMF 1.0 is being revised under the White House AI Action Plan, so check the NIST page for the current version before you build a program around it.
NIST also publishes a companion AI RMF Playbook with suggested actions for each part of the framework, and on April 7, 2026 released a concept note for an AI RMF profile for critical infrastructure. For most small businesses, the core framework, the Playbook and the Generative AI Profile are enough to start.
The four functions in plain terms
- Govern: set the policies, roles and accountability for AI. NIST notes Govern applies across all the other functions.
- Map: understand the context of each AI use, who it affects, what data it touches and what could go wrong.
- Measure: assess, test and track the risks you mapped, such as accuracy, bias, security and privacy.
- Manage: prioritize the risks, act on them, and monitor and respond over time.
A lightweight version for a 30 to 300 person company
- Govern: assign one executive owner, adopt an AI acceptable use policy, and decide which tools are approved for which data.
- Map: keep a simple register of every AI tool and feature in use, including AI built into software you already license.
- Measure: for each high-impact use, such as anything touching customers, hiring, money or regulated data, test outputs on real examples and record the results.
- Manage: set controls such as human review, data-loss rules and logging, and review the register quarterly.
Generative AI risks to put on your list
NIST AI 600-1 names risks that generative AI creates or makes worse. Those most relevant to a typical business are confabulation, meaning confident but false output; data privacy and leakage; information security, including easier attacks; intellectual property; harmful bias; human-AI configuration problems such as over-reliance; and value chain and component integration, meaning risk inherited from the vendors and models you build on.
Common mistakes
The usual failure is treating the framework as a document exercise. A 40-page policy that nobody follows is worse than a one-page rule set people actually use. Start with your highest-risk uses, keep evidence of the testing you did, and expand from there. If you are also under CMMC, HIPAA or GxP, map AI controls to those programs rather than running a separate track.
Common follow-up questions
Is the NIST AI RMF mandatory?
No. NIST states the framework is intended for voluntary use. Customers, investors, insurers or contracts may ask you to show how you manage AI risk, and the AI RMF is a widely recognized way to structure that answer.
How is the AI RMF different from an AI policy?
An AI policy sets rules for employees. The AI RMF is a management framework covering governance, context, testing and ongoing risk treatment. Your acceptable use policy is one output of the Govern function, not the whole program.
Do we need special software to follow it?
No. A small business can run the framework with a policy, a spreadsheet register of AI uses, documented tests for high-impact uses and a quarterly review. Tools help at scale, but ownership and evidence matter more.
LAN Service Group helps small and mid-size businesses stand up practical AI governance aligned to the NIST AI RMF, from an AI use register and acceptable use policy to testing and controls for high-impact uses.
Talk to LAN Service Group (888) 281-7243