Take what your risk framework needs from NIST AI RMF, and leave the rest.
NIST AI RMF binds nobody in Australia or New Zealand, and parts of it still save you writing a risk method from scratch. This page goes through the framework piece by piece, says what to take, and shows where each piece goes in your own risk framework. You finish with a per-system assessment built on the NIST functions, the Playbook actions you chose loaded into your control register, and a version line that survives the coming revision.
NIST AI 100-1 is the AI Risk Management Framework. It is voluntary in the United States and carries no legal weight here. The Voluntary AI Safety Standard uses it, with AS ISO/IEC 42001:2023, as one of its two main reference points. No New Zealand government guidance names it.
The framework is a risk method. It tells you how to find, measure and treat AI risk, and it has no management system and no certification. Those two limits decide what you take from it.
Step 1 of 7
Decide what job NIST does in your programme.
The output is one line at the top of your risk framework naming the management-system spine and the risk method.
Take NIST when
- You need a risk assessment method for a specific system and the organisation has no management system yet.
- You deploy generative AI and want the twelve-risk list and the action catalogue in AI 600-1.
- A US customer, parent or vendor contract asks for it by name.
- You want the Playbook's CSV as the seed of a control register.
Take ISO 42001 when
- The board or a customer wants third-party certification. NIST offers none.
- You need internal audit, management review and a Statement of Applicability. NIST has no construct for any of them.
- You already run ISO 27001 or 9001 and want AI governance to inherit that structure.
- You want stable text. ISO 42001 is a finished standard adopted in Australia, and the NIST revision is unscheduled.
Most PolyGovern clients land on ISO 42001 as the management-system spine and NIST as the risk method inside clause 6 and clause 8. Write that down as the first line of the risk framework. A company with no certification goal and no management system can run NIST on its own and add the ISO pieces later. Steps 2 to 5 assume NIST is the method either way.
Step 2 of 7
Build the assessment on the four functions.
Govern runs across the organisation, and the other three run per system. The output is the section structure of your per-system risk assessment.
- 01
Govern
6 categories · 19 subcategories
Policies and procedures across the organisation (GOVERN 1), accountability structures and roles (2), workforce diversity and accessibility (3), a culture of risk awareness (4), engagement with AI actors and affected communities (5), and third-party software, data and supply-chain risk (6). Take it as the organisation layer above the assessments. It maps to ISO 42001 clause 5 and Practice 1 of Australia's Guidance for AI Adoption, so an AI policy with a roles table covers most of it.
- 02
Map
5 categories · 18 subcategories
Context established (MAP 1), the system categorised (2), its capabilities, usage, goals, benefits and costs understood (3), risks and benefits for every component including third-party parts (4), and impacts on individuals, groups, communities and society (5). Take all five as the opening sections of each assessment. The Guidance's stakeholder impact assessment belongs in MAP 5.
- 03
Measure
4 categories · 22 subcategories
Methods and metrics identified (MEASURE 1), systems evaluated for the trustworthiness characteristics (2), mechanisms for tracking risk over time (3), and the measurement itself assessed with feedback (4). It is the largest function by subcategory count. Take it as the test plan section, ordered as step 3 sets out.
- 04
Manage
4 categories · 13 subcategories
Risks prioritised and responded to (MANAGE 1), strategies to maximise benefit and minimise harm (2), third-party risks and benefits handled (3), and treatments and incident response documented and monitored (4). Take it as the treatment and monitoring sections. MANAGE 4 holds post-deployment monitoring and incident response, and the notifiable data breach schemes in both countries attach there.
A New Zealand agency shows how the pieces fit. The Public Service AI Framework is non-binding. It sets five OECD-derived principles and six work-programme pillars and says nothing about how to assess a system. Map and Measure supply that method. The framework explainer shows where each pillar lands.
If the agency signed the Algorithm Charter, it already has a risk matrix: likelihood (probable, occasional, improbable) against impact (low, moderate, high), where a high rating means the Charter "must" apply. That matrix slots into MAP 5 and MANAGE 1 without modification, so the agency reports the Charter rating from the same assessment.
Step 3 of 7
Put valid and reliable first in the Measure section.
The output is the order of evaluation in every assessment, with a stop point after the first check.
Measure evaluates a system against seven trustworthiness characteristics: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair with harmful bias managed. In the framework, valid and reliable is the necessary condition for the other six.
Build that into the template as a gate. The assessor records the validity and reliability evidence first. A system that cannot show it does what it claims stops there, and the fairness and safety assessment waits until it can.
Step 4 of 7
Load the Playbook actions you choose into the control register.
The output is a set of register rows, each tagged to an ISO 42001 clause and a crosswalk row.
The Playbook lists suggested actions for every subcategory and comes as PDF, CSV, Excel and JSON. It is neither a checklist nor a sequence to follow in full. Pick the actions that fit your context and skip the rest.
Import the CSV or JSON into the register. Delete the actions that do not fit, then tag each remaining action with an ISO 42001 clause and a row of the crosswalk. The same register then answers an ISO auditor and anyone asking about NIST.
Keep the NIST subcategory identifier on every imported row. The Playbook will be updated after the AI RMF 1.0 revision, and that column is what you re-map against when it is.
Step 5 of 7
Add the Generative AI Profile for every generative AI system.
The output is a twelve-line risk list inside the assessment of each generative AI system, with an applies or does not apply decision on every line.
NIST AI 600-1 names twelve risks that generative AI creates or makes worse: CBRN information or capabilities; confabulation; dangerous, violent or hateful content; data privacy; environmental impacts; harmful bias and homogenisation; human-AI configuration; information integrity; information security; intellectual property; obscene, degrading or abusive content; and value chain and component integration.
The PDF holds more than 200 suggested actions. Each carries an ID tied to an AI RMF subcategory, in the form GV-1.1-001, so an action drops straight into the register rows you built in step 4.
For a Copilot or chatbot deployment, take this profile ahead of the parent framework, which was written before generative AI reached the enterprise. Copy the twelve risks into that system's assessment, decide which apply, and import the actions whose IDs match the subcategories you already use.
Step 6 of 7
Point the outputs at the obligations that bind you.
NIST creates no obligation in either country. Its outputs become the evidence for the duties that exist. The output of this step is a line in the framework linking each duty to the assessment section that feeds it.
Australia.
- 01
APP 1.7 to 1.9 from 10 December 2026.
Privacy policies must describe automated decision-making that significantly affects individuals. The duty maps to GOVERN 1, MAP 1 and the MANAGE 4 documentation outcomes. Your MAP 1 inventory of systems and the decisions they make is the list the privacy policy now has to describe. The duty is disclosure only, with no right to an explanation or to contest.
- 02
Your sector regulator.
The proposal for mandatory guardrails in high-risk settings has not become law. The National AI Plan relies on existing technology-neutral laws, keeps regulators responsible in their own domains and sets up an AI Safety Institute without enforcement powers. A NIST-aligned programme is evidence of good practice, and the regulator it has to satisfy is the sector regulator you already have.
- 03
The DTA policy, for Commonwealth entities.
The DTA's Policy for the responsible use of AI in government is in effect, and its remaining mandatory requirements start in December 2026. It asks for accountable officials, transparency statements, use-case registers, staff training and a per-use-case impact assessment. An agency running the NIST method produces those from its Govern and Map outputs.
New Zealand.
- 01
The Privacy Commissioner's PIA expectation.
The OPC expects senior approval after weighing risks, a necessity and proportionality review, a PIA before use, transparency, engagement with Māori on risks to taonga and human review of outputs. File the PIA inside MAP 5 of the assessment.
- 02
IPP 3A since 1 May 2026.
IPP 3A adds a notification duty when personal information is collected from a source other than the individual, which catches scraped and vendor-sourced training data. Record it against MAP 5 and against row 07 (A.7, data for AI systems) of the crosswalk. The Privacy Act 2020 page covers the detail.
- 03
No AI-specific law.
New Zealand's Strategy for Artificial Intelligence takes a light-touch, principles-based regulatory approach and adopts the OECD principles with no new regulatory overlay. The only live reform is the Law Commission's review of automated decision-making by government, which is at scoping stage. For a private organisation the Privacy Act 2020 remains the instrument with teeth.
Step 7 of 7
Pin the version and record what you left out.
The output is a version line in the framework and a short list of the NIST parts you chose not to use, each with its reason.
Version 1.0 is under revision, and there is no draft, version number or release date for its successor.
Vendors and training providers advertise an "AI RMF 2.0", and it does not exist. Write "aligned to NIST AI RMF 1.0 (NIST AI 100-1)" in the framework and cite subcategory identifiers from that version. When the revision appears, the mapping re-runs against the identifier column from step 4.
Then list what you left out. Certification is the first entry, because NIST publishes no certification scheme. Internal audit, management review and the Statement of Applicability come from ISO 42001, since NIST has no construct for any of them. Add each Playbook action you deleted in step 4, with the reason it did not fit.
Our fifteen-row crosswalk maps NIST to ISO 42001 and extends the mapping to the Australian and New Zealand instruments and privacy law.
If the standard is new to you, start with ISO 42001 explained. The maturity model shows where the organisation stands before you choose either.
Frequently asked questions.
Is the NIST AI RMF mandatory in Australia or New Zealand?
No. It is voluntary guidance from the United States National Institute of Standards and Technology. The Voluntary AI Safety Standard uses NIST AI RMF 1.0 and AS ISO/IEC 42001:2023 as its two main reference points. No New Zealand government guidance references it as a baseline.
Is there a NIST AI RMF certification?
No. NIST publishes no certification scheme for the AI RMF. ISO/IEC 42001 is the certifiable AI management system standard.
Is NIST AI RMF 2.0 out?
No. AI RMF 1.0 is under revision, and there is no draft, version number or date for the next version. The Playbook will be updated after the revision.
What is the Generative AI Profile?
NIST AI 600-1 is a companion to AI RMF 1.0. It names twelve risks that are unique to or made worse by generative AI and gives more than 200 suggested actions, each keyed to an AI RMF subcategory.
Does NIST map to ISO 42001?
Our fifteen-row crosswalk maps AI RMF 1.0 subcategories to ISO/IEC 42001 clauses and Annex A themes, and extends the mapping to the Australian and New Zealand instruments and privacy law.
Is the Playbook a checklist?
No. The Playbook lists suggested actions for each subcategory and comes as PDF, CSV, Excel and JSON. Organisations choose the actions that fit their context.
Build the risk framework on NIST and the management system on ISO 42001.
Our risk framework engagements use the NIST functions as the assessment method and tag every control to an ISO 42001 clause and a crosswalk row, so the same register answers an auditor, a regulator and the board.