AI governance frameworks: Compare
A learning aid, not legal advice.
| Dimension | NIST AI Risk Management Framework 1.0 (NIST AI 100-1) with the Generative AI Profile (NIST AI 600-1) voluntary guidance |
|---|---|
| Nature | Depth 1 of 3. Voluntary guidance from a federal standards body; no one is bound by it unless a law or contract refers to it. NIST AI 100-1, Executive Summary; AI RMF page |
| Where and to whom it applies | Depth 2 of 3. Open to any organisation that designs, develops, deploys or uses AI, in any sector and any country. NIST AI 100-1, Section 5 (Core), GOVERN function |
| Roles addressed | Depth 2 of 3. Speaks of AI actors across the life cycle and asks organisations to define roles and responsibilities, including for human-AI configurations and oversight. GOVERN 3.2 |
| Risk approach | Depth 3 of 3. No fixed tiers: organisations map context, measure and manage risk against their own tolerance, estimating the likelihood and magnitude of each impact. Section 5 (Core); MAP 5.1 |
| Inventory and documentation | Depth 2 of 3. Asks for mechanisms to inventory AI systems, resourced according to risk priorities. GOVERN 1.6 |
| Risk or impact assessment | Depth 3 of 3. The Map function documents intended purposes, context and applicable laws, then the likelihood and magnitude of each beneficial and harmful impact. MAP 1.1; MAP 5.1 |
| Human oversight | Depth 2 of 3. Processes for human oversight are defined, assessed and documented; roles for human-AI configurations are set by policy. MAP 3.5; GOVERN 3.2 |
| Transparency and notices | Depth 2 of 3. Transparency and accountability risks are examined and documented, and the model is explained and its output interpreted in context. MEASURE 2.8; MEASURE 2.9 |
| Data governance | Depth 1 of 3. Data collection and selection (availability, representativeness, suitability) is documented as part of the testing considerations; no separate data governance rulebook. MAP 2.3 |
| Testing, robustness and security | Depth 3 of 3. Testing, evaluation, verification and validation run through the Measure function: performance, security and resilience, fairness and bias are evaluated and documented. MEASURE 2.3; MEASURE 2.7; MEASURE 2.11; GOVERN 4.3 |
| Monitoring and incident reporting | Depth 2 of 3. Post-deployment monitoring plans with appeal, override, incident response and recovery; incidents are communicated to affected actors. No duty to report to a regulator. MANAGE 4.1; MANAGE 4.3 |
| Assurance and enforcement | Depth 1 of 3. No certification scheme; self-assessed. Texas law bars liability where a violation is found through internal review while substantially complying with the Generative AI Profile or a similar framework. Tex. Bus. & Com. Code § 552.105(e)(2)(D) (HB 149) |
| Effort to implement | Depth 2 of 3. Moderate and scalable: the Playbook offers suggested actions per subcategory, and organisations choose which to adopt. AI RMF Playbook |
| Key dates | Depth 1 of 3. AI RMF 1.0 released 2023-01-26; Generative AI Profile released 2024-07-26 (12 risks). A revision was requested in the 2025-07-23 federal AI Action Plan; no revised version was found. AI RMF page; NIST AI 600-1 publication page |
A learning aid, not legal advice. Where AI SENTINEL is mentioned, it supports or maps to the dimension; it does not certify anything. Dates are those the official texts state on the date shown.