Frameworks Voluntary framework National Institute of Standards and Technology (NIST)
NIST AI Risk Management Framework (AI RMF)
A framework for managing AI risk across the whole lifecycle, organised into the four functions Govern, Map, Measure and Manage.
What this framework governs
The National Institute of Standards and Technology is the standards and measurement agency of the United States, part of the Department of Commerce. Its AI Risk Management Framework describes how an organisation identifies, measures and manages AI risk.
Two further NIST publications round out the picture: the generative AI profile, which applies the framework’s functions to this class of models, and the taxonomy of adversarial attacks on machine learning, which gives attack types names and identifiers.
The NIST sources connect AI risk governance at the organisational level with the analysis of individual technical threats.
Mappings in the threat catalogue
NIST AI Risk Management Framework (AI RMF). Publisher: National Institute of Standards and Technology (NIST). The Versatile AI Risk Assessment threat catalogue reaches 47 of its 52 threats through this framework, backed by 3 documents at 41 locations. Mappings are documented for 47 of the 52 threats in the catalogue. The overview shows their distribution by topic group.
5 threats without a mapped reference
The catalogue contains no reference from this framework for these threats. This does not establish whether the original document addresses them. See the threat pages for recorded mappings to other frameworks.
- Cost Harvesting / Repurposing Attacks on the Running Model and Service
- Application Denial of Service Attacks on the Running Model and Service
- Misalignment Agentic and Autonomous AI
- Agent Memory Poisoning (Persistent Context) Agentic and Autonomous AI
- Insecure Inter-Agent Communication (A2A/MCP) Agentic and Autonomous AI
Analysis: combine several frameworks and see the gaps that remain
Threats referencing this framework (47)
Grouped by topic. Every entry leads to the full threat page.
Agentic and Autonomous AI
2 threatsApplication and Integration Security
7 threatsAttacks on the Running Model and Service
5 threatsHarmful Content
9 threatsMalicious Use for Attacks, Fraud and Disinformation
4 threatsModel and Training Data Manipulation
4 threatsPrivacy and Data Leakage
4 threatsPrompt Attacks and Guardrail Evasion
5 threatsReliability and Responsible Use
4 threatsSupply Chain and Provenance
3 threatsNo threat matches this input. Reset the filters to see all of them again.
Filter the catalogue by NIST AI Risk Management Framework (AI RMF)
Sources used (3)
These exact versions are pinned in the catalogue. Every page states the publisher, the version used, the locations and the referencing threats.
This page does not reproduce the text of the standards. It states the identifier, title and location; the wording itself is in the original document. The mappings are taxonomic and not evidence of compliance.
The AI RMF provides voluntary guidance for risk management. It does not set universally binding risk thresholds. A mapping to its contents does not constitute certification.
Further frameworks
The frameworks address different aspects: legal requirements, organisational risk management and technical security. Explore the further perspectives included in the catalogue.
From the framework to the assessment
The full catalogue states the mitigations, the possible impact and every verified location for each threat. The live demo runs locally in your browser, with no sign-up.
Cite this page
For reports, policies or internal documents; the link leads directly to this framework page.
“NIST AI Risk Management Framework (AI RMF)” (National Institute of Standards and Technology (NIST)). Mappings in the AI threat catalogue, Versatile AI Risk Assessment, as of July 2026. https://www.versatile-ai-risk-assessment.com/en/wissensbasis/frameworks/nist-ai-rmf/