Profiles, the Playbook, and the crosswalks

Lesson 4 of 5 in NIST AI RMF Deep Dive: Govern, Map, Measure, Manage.

Seventy-two subcategories for every AI system in every organization would be absurd — and NIST knows it. The instrument that makes the RMF usable is the profile: a tailored selection and implementation of the Core for a specific context. Three profile types matter:

  • Use-case profiles implement the functions for a setting: hiring, lending, a hospital, generative AI. The flagship is the Generative AI Profile (NIST-AI-600-1, July 2024) — the next module’s subject — and in April 2026 NIST floated a Critical Infrastructure AI Profile concept note, extending the pattern to power grids, water systems, and transport.
  • Temporal profiles come in pairs: a current profile (what you actually do today, honestly assessed) and a target profile (what your risk tolerance says you should do). The distance between them is your improvement roadmap — this current-versus-target gap analysis is the single most practical exercise in the entire framework.
  • Cross-sectoral profiles address activities that span settings — large language models, cloud services — where risks travel with the technology rather than the industry.

Building an RMF profile: the gap-analysis loop

  1. Scope the profile

    Pick the use case or portfolio: one system, one product line, or the whole organization. Narrow scopes produce honest profiles.

  2. Draft the current profile

    Walk the Core: for each relevant category, record what you actually do today — with evidence, not aspiration. “We have no drift monitoring” is a legitimate, useful entry.

  3. Confront risk tolerance

    Does today’s practice hold identified risks within the tolerance GOVERN documented? This is a judgment call by accountable owners, not a formula.

  4. Maintain and monitor

    Within tolerance: keep measuring (MEASURE 3), and stay alert for context changes that reopen the question.

  5. Define the target profile

    Out of tolerance: specify the practice level each gap category must reach — informed by Playbook suggested actions, legal duties, and stakeholder input.

  6. Prioritize the gaps

    Rank by risk severity and feasibility. High-consequence gaps (no decommissioning plan for a patient-facing system) outrank cosmetic ones.

  7. Implement and resource

    Fund and execute the changes — this is MANAGE doing its job with GOVERN’s budget authority.

  8. Reassess on a cycle

    The new current profile gets drafted next cycle. Profiles are living documents: reorganizations, new laws, and new model versions all reopen them.

Around the Core, NIST maintains a small ecosystem you should be able to name in a meeting:

  • The AI RMF Playbook — for every subcategory, suggested actions, transparency and documentation guidance, and references. NIST’s italics, not ours: the Playbook is explicitly not a checklist, and nobody is expected to do everything in it. It lives in NIST’s Trustworthy and Responsible AI Resource Center as a living online resource.
  • The Roadmap — NIST’s own to-do list: the work it knows remains, from better TEVV methods to metrics for risks that resist quantification.
  • The Crosswalks — official mappings from RMF subcategories to ISO/IEC 42001, ISO/IEC 23894, the OECD AI Principles, and the EU AI Act. These are load-bearing for multinationals: they are how one control set gets evidenced against several regimes at once.
One control set, three regimes: RMF ↔ ISO/IEC 42001 ↔ EU AI Act
RMF functionWhat it coversISO/IEC 42001 (certifiable AIMS)EU AI Act (binding law, high-risk systems)

GOVERN

Culture, roles, policies, risk tolerance, third-party policy — the cross-cutting foundation

Clauses 4–7: context, leadership and AI policy (5), planning (6), support and competence (7); Annex A governance controls

Art 17 quality management system; Art 26 deployer governance duties; Art 4 AI literacy

MAP

Context, categorization, benefit/cost scoping, third-party risks, impact characterization

Clause 6.1.2 AI risk assessment; 6.1.4 AI system impact assessment; Clause 4 context of the organization

Art 9 risk management system (identification and analysis steps); Art 10 data governance; classification duties under Art 6 and Annex III

MEASURE

Metrics, evaluation against the seven characteristics, tracking over time, validating the metrics

Clause 9 performance evaluation: monitoring, measurement, internal audit, management review

Art 15 accuracy, robustness, cybersecurity; Art 9 testing duties; Art 72 post-market monitoring evidence base

MANAGE

Mitigate / transfer / avoid / accept, benefit management, decommissioning plans, incident response, improvement

Clause 8 operation (risk treatment execution); Clause 10 improvement and nonconformity handling

Art 9 risk treatment and residual-risk acceptability; Art 73 serious-incident reporting; corrective actions under Art 20

Legal nature

Voluntary framework — force arrives by reference (statutes, contracts, procurement)

Voluntary but certifiable — third-party audits produce a certificate procurement teams increasingly demand

Binding regulation — non-compliance for high-risk systems risks penalties up to 3% of worldwide turnover (Art 99)

Key terms: AI RMF profile, gap analysis, crosswalk, AI management system

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.