Core, Profiles and Playbook
The NIST AI RMF is designed for flexible, risk-based use. Its parts serve different purposes and should not be collapsed into a single checklist or maturity score.
The Framework
Section titled “The Framework”NIST AI 100-1 provides:
- A framing of AI risk and trustworthiness.
- Intended audiences and AI actors.
- The four-function AI RMF Core.
- The concept of Profiles for tailoring the framework.
The framework is voluntary and outcome-oriented. Organisations apply it according to their role, resources, risk tolerance, use case and operating context.
The Core
Section titled “The Core”The Core contains:
- 4 functions
- 19 categories
- 72 subcategories
The subcategories express risk-management outcomes. They do not constitute an ordered checklist, and NIST does not assign a universal implementation score to them.
| Function | Relationship |
|---|---|
| GOVERN | Cross-cutting conditions, accountability and culture that inform the other functions |
| MAP | Context and risk identification |
| MEASURE | Analysis, evaluation, testing and monitoring |
| MANAGE | Prioritisation, treatment, response, recovery and communication |
Profiles
Section titled “Profiles”A Profile tailors the Core to a particular application, sector, technology, organisation or system. Profiles help describe what is relevant and how outcomes should be prioritised.
Current Profile
Section titled “Current Profile”The Current Profile describes what is presently achieved for the selected system and context.
It should answer:
- What practice exists now?
- Is it specific to this system?
- Who owns it?
- Is it documented?
- Is it operating?
- Has effectiveness been tested?
- What evidence or adverse finding affects the conclusion?
Target Profile
Section titled “Target Profile”The Target Profile describes the desired risk-management position.
It should reflect:
- Intended purpose and deployment context.
- Organisational risk tolerance.
- Legal, contractual and policy requirements.
- Potential impacts on people, organisations, society and the environment.
- Technical and operational dependencies.
- Lifecycle stage.
- Resource and implementation constraints.
- Relevant stakeholder expectations.
Profile gap
Section titled “Profile gap”The difference between Current and Target Profiles becomes a prioritised improvement plan. A gap may require:
- A new or strengthened practice.
- Better ownership or documentation.
- Additional evidence.
- A test or evaluation.
- Supplier action.
- A deployment restriction.
- Risk treatment or acceptance.
- Monitoring and reassessment.
How Gamut presents Profile outcomes
Section titled “How Gamut presents Profile outcomes”Gamut uses plain assessment language:
| Current outcome | Meaning |
|---|---|
| Not assessed | No defensible determination has been made. |
| Not achieved | The outcome is absent or materially ineffective for this system. |
| Partially achieved | Some elements operate, but material gaps remain. |
| Achieved | The outcome operates for this system and is sufficiently supported. |
The Target Profile uses the substantive target outcomes: Not achieved, Partially achieved or Achieved.
These are Gamut assessment labels, not a NIST maturity scale.
The Playbook
Section titled “The Playbook”The NIST AI RMF Playbook provides suggested actions aligned to Core subcategories. NIST describes it as a voluntary companion resource, not a checklist or mandatory sequence.
Use the Playbook to:
- Explore possible implementation actions.
- Identify documentation and evidence ideas.
- Tailor practices to role, sector and use case.
- Compare alternative ways to achieve an outcome.
- Support workshops and improvement planning.
Do not:
- Treat every suggestion as mandatory.
- Assume one suggestion is sufficient in every context.
- Copy a suggested action without linking it to the selected system.
- Represent a Playbook action as evidence that the outcome is achieved.
The Generative AI Profile
Section titled “The Generative AI Profile”NIST AI 600-1 is a cross-sectoral companion Profile for generative AI. It identifies generative-AI risk considerations and recommended actions that supplement the AI RMF Core.
When a selected system has generative-AI characteristics, Gamut highlights the Generative AI Profile as an additional lens. The Core remains active; the companion Profile does not replace it.
Tailoring without losing accountability
Section titled “Tailoring without losing accountability”Tailoring should be explicit. Record:
- The system and context.
- The outcome being considered.
- The reason for its priority.
- The intended target.
- Any decision to defer work.
- The accountable decision-maker.
- The trigger for revisiting the decision.
Tailoring does not mean:
- Quietly removing inconvenient outcomes.
- Treating low priority as not applicable.
- Reducing evidence because a system is familiar.
- Using another system’s assessment.
- Ignoring an outcome because a mapped framework appears stronger.
Frequently confused concepts
Section titled “Frequently confused concepts”| Concept | It is | It is not |
|---|---|---|
| Core outcome | A NIST risk-management outcome | A prescriptive technical control |
| Current Profile | Assessed present position | A general organisational aspiration |
| Target Profile | Intended future position | Proof of implementation |
| Playbook action | A voluntary implementation suggestion | A mandatory checklist item |
| Gamut priority | Assessment-planning emphasis | A NIST severity rating |
| Assurance depth | Strength of support for a claim | The Current outcome itself |
| Crosswalk | A traceability aid | Automatic equivalence |