AI governance frameworks: Compare

A learning aid, not legal advice.

Depth, from 0 (least) to 3 (most)0123Under review
Frameworks to compare

Pick two or three frameworks.

Dimension
NIST AI Risk Management Framework 1.0 (NIST AI 100-1) with the Generative AI Profile (NIST AI 600-1)
voluntary guidance
Nature
Depth 1 of 3.

Voluntary guidance from a federal standards body; no one is bound by it unless a law or contract refers to it.

NIST AI 100-1, Executive Summary; AI RMF page
Where and to whom it applies
Depth 2 of 3.

Open to any organisation that designs, develops, deploys or uses AI, in any sector and any country.

NIST AI 100-1, Section 5 (Core), GOVERN function
Roles addressed
Depth 2 of 3.

Speaks of AI actors across the life cycle and asks organisations to define roles and responsibilities, including for human-AI configurations and oversight.

GOVERN 3.2
Risk approach
Depth 3 of 3.

No fixed tiers: organisations map context, measure and manage risk against their own tolerance, estimating the likelihood and magnitude of each impact.

Section 5 (Core); MAP 5.1
Inventory and documentation
Depth 2 of 3.

Asks for mechanisms to inventory AI systems, resourced according to risk priorities.

GOVERN 1.6
Risk or impact assessment
Depth 3 of 3.

The Map function documents intended purposes, context and applicable laws, then the likelihood and magnitude of each beneficial and harmful impact.

MAP 1.1; MAP 5.1
Human oversight
Depth 2 of 3.

Processes for human oversight are defined, assessed and documented; roles for human-AI configurations are set by policy.

MAP 3.5; GOVERN 3.2
Transparency and notices
Depth 2 of 3.

Transparency and accountability risks are examined and documented, and the model is explained and its output interpreted in context.

MEASURE 2.8; MEASURE 2.9
Data governance
Depth 1 of 3.

Data collection and selection (availability, representativeness, suitability) is documented as part of the testing considerations; no separate data governance rulebook.

MAP 2.3
Testing, robustness and security
Depth 3 of 3.

Testing, evaluation, verification and validation run through the Measure function: performance, security and resilience, fairness and bias are evaluated and documented.

MEASURE 2.3; MEASURE 2.7; MEASURE 2.11; GOVERN 4.3
Monitoring and incident reporting
Depth 2 of 3.

Post-deployment monitoring plans with appeal, override, incident response and recovery; incidents are communicated to affected actors. No duty to report to a regulator.

MANAGE 4.1; MANAGE 4.3
Assurance and enforcement
Depth 1 of 3.

No certification scheme; self-assessed. Texas law bars liability where a violation is found through internal review while substantially complying with the Generative AI Profile or a similar framework.

Tex. Bus. & Com. Code § 552.105(e)(2)(D) (HB 149)
Effort to implement
Depth 2 of 3.

Moderate and scalable: the Playbook offers suggested actions per subcategory, and organisations choose which to adopt.

AI RMF Playbook
Key dates
Depth 1 of 3.

AI RMF 1.0 released 2023-01-26; Generative AI Profile released 2024-07-26 (12 risks). A revision was requested in the 2025-07-23 federal AI Action Plan; no revised version was found.

AI RMF page; NIST AI 600-1 publication page

A learning aid, not legal advice. Where AI SENTINEL is mentioned, it supports or maps to the dimension; it does not certify anything. Dates are those the official texts state on the date shown.