Profiles, the Playbook, and the crosswalks
Lesson 4 of 5 in NIST AI RMF Deep Dive: Govern, Map, Measure, Manage.
Seventy-two subcategories for every AI system in every organization would be absurd — and NIST knows it. The instrument that makes the RMF usable is the profile: a tailored selection and implementation of the Core for a specific context. Three profile types matter:
- Use-case profiles implement the functions for a setting: hiring, lending, a hospital, generative AI. The flagship is the Generative AI Profile (NIST-AI-600-1, July 2024) — the next module’s subject — and in April 2026 NIST floated a Critical Infrastructure AI Profile concept note, extending the pattern to power grids, water systems, and transport.
- Temporal profiles come in pairs: a current profile (what you actually do today, honestly assessed) and a target profile (what your risk tolerance says you should do). The distance between them is your improvement roadmap — this current-versus-target gap analysis is the single most practical exercise in the entire framework.
- Cross-sectoral profiles address activities that span settings — large language models, cloud services — where risks travel with the technology rather than the industry.
Building an RMF profile: the gap-analysis loop
- Scope the profile
Pick the use case or portfolio: one system, one product line, or the whole organization. Narrow scopes produce honest profiles.
- Draft the current profile
Walk the Core: for each relevant category, record what you actually do today — with evidence, not aspiration. “We have no drift monitoring” is a legitimate, useful entry.
- Confront risk tolerance
Does today’s practice hold identified risks within the tolerance GOVERN documented? This is a judgment call by accountable owners, not a formula.
- Maintain and monitor
Within tolerance: keep measuring (MEASURE 3), and stay alert for context changes that reopen the question.
- Define the target profile
Out of tolerance: specify the practice level each gap category must reach — informed by Playbook suggested actions, legal duties, and stakeholder input.
- Prioritize the gaps
Rank by risk severity and feasibility. High-consequence gaps (no decommissioning plan for a patient-facing system) outrank cosmetic ones.
- Implement and resource
Fund and execute the changes — this is MANAGE doing its job with GOVERN’s budget authority.
- Reassess on a cycle
The new current profile gets drafted next cycle. Profiles are living documents: reorganizations, new laws, and new model versions all reopen them.
Around the Core, NIST maintains a small ecosystem you should be able to name in a meeting:
- The AI RMF Playbook — for every subcategory, suggested actions, transparency and documentation guidance, and references. NIST’s italics, not ours: the Playbook is explicitly not a checklist, and nobody is expected to do everything in it. It lives in NIST’s Trustworthy and Responsible AI Resource Center as a living online resource.
- The Roadmap — NIST’s own to-do list: the work it knows remains, from better TEVV methods to metrics for risks that resist quantification.
- The Crosswalks — official mappings from RMF subcategories to ISO/IEC 42001, ISO/IEC 23894, the OECD AI Principles, and the EU AI Act. These are load-bearing for multinationals: they are how one control set gets evidenced against several regimes at once.
| RMF function | What it covers | ISO/IEC 42001 (certifiable AIMS) | EU AI Act (binding law, high-risk systems) |
|---|---|---|---|
GOVERN | Culture, roles, policies, risk tolerance, third-party policy — the cross-cutting foundation | Clauses 4–7: context, leadership and AI policy (5), planning (6), support and competence (7); Annex A governance controls | Art 17 quality management system; Art 26 deployer governance duties; Art 4 AI literacy |
MAP | Context, categorization, benefit/cost scoping, third-party risks, impact characterization | Clause 6.1.2 AI risk assessment; 6.1.4 AI system impact assessment; Clause 4 context of the organization | Art 9 risk management system (identification and analysis steps); Art 10 data governance; classification duties under Art 6 and Annex III |
MEASURE | Metrics, evaluation against the seven characteristics, tracking over time, validating the metrics | Clause 9 performance evaluation: monitoring, measurement, internal audit, management review | Art 15 accuracy, robustness, cybersecurity; Art 9 testing duties; Art 72 post-market monitoring evidence base |
MANAGE | Mitigate / transfer / avoid / accept, benefit management, decommissioning plans, incident response, improvement | Clause 8 operation (risk treatment execution); Clause 10 improvement and nonconformity handling | Art 9 risk treatment and residual-risk acceptability; Art 73 serious-incident reporting; corrective actions under Art 20 |
Legal nature | Voluntary framework — force arrives by reference (statutes, contracts, procurement) | Voluntary but certifiable — third-party audits produce a certificate procurement teams increasingly demand | Binding regulation — non-compliance for high-risk systems risks penalties up to 3% of worldwide turnover (Art 99) |
Key terms: AI RMF profile, gap analysis, crosswalk, AI management system
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.