The NIST AI Risk Management Framework is a voluntary framework from the U.S. National Institute of Standards and Technology for managing risks associated with the use of artificial intelligence. It is designed to be cross-industry, does not mandate specific tools, and is not tied to any single legal jurisdiction. Unlike a law, it is not compulsory. Its impact lies in providing a common language that regulators, standards bodies, and international frameworks refer to.
The core consists of four functions that structure the handling of AI risks throughout the entire lifecycle.
1. Govern is the overarching function. It establishes the culture, roles, responsibilities, and processes for risk management and permeates the other three functions.
2. Map captures the context. Which AI systems exist, for what purpose, with which stakeholders, and with what potential impacts? Without this inventory, any further risk management remains incomplete.
3. Measure assesses, analyzes, and tracks identified risks using traceable methods and metrics.
4. Manage prioritizes risks and directs the response, from risk treatment and monitoring to incident response.
5. The supplementary profiles. The base framework is supplemented by profiles that tailor it to specific contexts.
The Generative AI Profile, released in July 2024, extends the RMF to address the risks of large language models and multimodal systems. It identifies twelve risk categories that are unique to or amplified by generative AI, including confabulation—the generation of plausible-sounding but false content—data privacy, harmful bias, and information security. Each of these categories is mapped to the four core functions, so organizations do not need to build a separate framework but can instead layer the profile onto their existing one.
A profile for agentic AI addresses the additional risks posed by autonomously acting agents. NIST recommends applying both profiles for agents based on generative models: the Generative AI Profile for the behavior of model output and the Agent Profile for autonomous behavioral actions.
On April 7, 2026, NIST published a concept note for an RMF profile on trustworthy AI in critical infrastructure. This profile is intended to provide critical infrastructure operators with specific risk management practices when deploying AI-enabled capabilities. For organizations in the critical infrastructure sector, this is a directly relevant component.
1. A common language instead of an isolated standard. For a European SAP organization, the question arises as to why a voluntary U.S. framework is relevant when the EU AI Act is legally binding anyway. The answer lies in the connection. NIST provides crosswalk documents that map the AI RMF to other frameworks, including ISO 42001 and the EU AI Act. This makes the RMF the operational link between what the law requires and what an organization does on a daily basis.
2. The relationship with ISO 42001. The two frameworks operate at different levels and complement each other. ISO 42001 is a management system standard. It describes how an organization builds, operates, and improves an AI governance program, and it is certifiable. The NIST AI RMF is a risk framework. It focuses on identifying and mitigating specific AI risks throughout the lifecycle. Many organizations pursue both simultaneously: ISO 42001 as the framework for the program, and the NIST AI RMF as the methodology for managing risk within it.
3. Relevance for the SAP AI landscape in 2026. The need has become concrete because, in 2026, AI in SAP landscapes is shifting from a feature to an active component. Joule agents access SAP data via the Model Context Protocol, autonomous agents execute multi-step processes, and AI-assisted tools generate code and changes. This creates exactly the risks for which the NIST AI RMF and its profiles were developed. The framework provides a structure to address these risks systematically rather than ad hoc.
The four functions can be translated into concrete steps for an SAP organization.
1. Anchoring Govern in the SAP organization. Govern means establishing accountability for AI risks with executive-level support and cross-functional staffing, ranging from legal and compliance to development and operations. In the SAP world, this means not separating AI governance from existing change and release governance, but rather integrating it. By routing AI changes through the same controlled process as other changes, you leverage existing structures.
2. Map through an AI inventory. Map begins with an inventory of all AI systems in development, operation, and procurement. For SAP landscapes, this means recording all deployed agents, models, and MCP servers, including authorized external assistants. An inventory that does not track which agents access which data cannot assess risks.
3. Measure with traceable metrics. Measure requires evaluating and tracking identified risks using methods and metrics. In practice, this means defining measurable checkpoints for AI-supported changes: test coverage, error rates, frequency of human corrections, and escalations. These metrics turn a gut feeling about risk into a reliable assessment.
4. Manage via the response chain. Manage prioritizes risks and directs the response. For SAP organizations, this means defining clear thresholds for human approval, setting up monitoring for productive agents, and maintaining a response path for AI-related incidents. The response is not a one-time state, but a continuous cycle.
1. Voluntariness without enforcement. The first limit is its voluntary nature. The NIST AI RMF does not enforce anything. It provides structure, but no sanctions. An organization that treats the framework as a box-ticking exercise gains little. It only delivers value when understood as operational infrastructure rather than a compliance formality.
2. US context versus EU mandate. The second limit is the context. The RMF originated in the US environment, while the EU AI Act is the legally binding requirement in Europe. The framework does not replace legal obligations; it supports their fulfillment. Applying the NIST AI RMF does not automatically satisfy EU legal requirements, but it provides a method to address them in a structured way.
3. The gap regarding autonomous systems. The third boundary concerns the speed of development. Autonomous agents are emerging faster than profiles and standards can mature. The agent profile and the associated standards initiative from NIST are a response to this, but they are partially lagging behind reality. The more difficult question, which no framework maturity level can answer, is whether humans will retain the choice to disagree with the system when its representation of the situation seems more convincing than the situation itself. This is precisely where it is decided whether governance means control or merely documentation.
4. Mapping effort. The fourth boundary is the effort involved. Anyone working with the NIST AI RMF, ISO 42001, and the EU AI Act simultaneously must map the requirements cleanly to one another to avoid duplication of work. Crosswalk documents are helpful, but they do not replace organization-specific mapping.
1. Clearly separate roles. ISO 42001 provides the management system, the NIST AI RMF provides the risk methodology, and the EU AI Act provides the legal obligation. Each framework answers a different question.
2. Start with the inventory. Without a complete directory of AI systems, agents, and models, none of the three disciplines can be considered robust. The inventory is the common starting point.
3. Choose the appropriate profile. Use the generative AI profile for generative AI, the agent profile for autonomous agents, and the critical infrastructure profile for operators of essential services. The profile principle allows the framework to be adapted to your specific context.
4. Integrate with change governance. Manage AI changes through the same controlled change and release process as other changes. This links AI risk management with the end-to-end audit trail already required by SOX, NIS2, and the EU AI Act.
5. Metrics over gut feeling. Take "Measure" seriously and define measurable checkpoints for AI-supported changes so that risks can be substantiated.
6. Operate as an ongoing cycle. The four functions are not a one-time project, but a continuous cycle that is updated with every new agent and every new profile.
The NIST AI RMF describes what to do, not which tools to use. The following table categorizes which tool class is used to actually implement the Govern, Map, Measure, and Manage functions for AI-supported SAP changes. It is an operational view, not a framework comparison.
Tool ClassMap (AI Inventory)Measure (Metrics)Manage (Release and Response)Govern (Audit Trail Req-to-Deploy)SAP AI Agent HubFullyPartiallyPartiallyPartiallyMCP Server Governance (Whitelist, Sandbox)PartiallyPartiallyPartiallyPartiallySAP Cloud ALM (Change and Deploy)NoPartiallyPartiallyPartiallyChaRM (SAP Solution Manager)NoPartiallyFullyFullyOrchestration Layer¹NoPartiallyFullyFully¹ Solutive AG is the initiator of the Change Orchestration Institute. The assessment in the table is a self-disclosure by the provider and is not part of an editorially independent validation. The AI inventory in the sense of "Map" lies outside the functional scope of a change and transport governance layer and is covered by dedicated agent management such as the SAP AI Agent Hub.
The table illustrates the division of labor. Inventory and tracking of AI systems—the Map function—are handled by agent management. The Manage and Govern functions, specifically controlled release and a comprehensive audit trail, are handled by change and transport governance. A complete implementation of the NIST AI RMF in an SAP landscape therefore combines agent management with established change governance, rather than viewing either one alone as sufficient.
1. Framework comparison for classification. To distinguish between the frameworks themselves, independent of tools:
FeatureNIST AI RMFISO 42001EU AI ActNatureVoluntary risk frameworkCertifiable management system standardBinding lawScopeCross-industry, globally referencedInternational, certifiableEU, with third-country impactFocusRisks across the lifecycleEstablishment and operation of the governance programObligations by risk classEnforcementNoneVia certificationVia oversight and sanctionsGenerative and agentic AIIndividual profilesVia the management systemVia transparency and high-risk obligationsThe framework leads to concrete steps.
The first consequence concerns positioning. The NIST AI RMF does not belong in a separate AI silo; it should be docked to existing change and release governance. Anyone building AI risk management alongside the established process creates two worlds that will inevitably drift apart.
The second consequence concerns the inventory. Without a complete directory of deployed agents, models, and MCP servers, the Map function is not fulfilled, rendering the rest of the risk management unreliable. The inventory is the first concrete step.
The third consequence concerns profiles. Organizations should choose the appropriate profile rather than applying the base framework generically. For critical infrastructure operators, the profile for critical infrastructure is a component tailored directly to their situation.
The fourth consequence concerns the interaction with the EU AI Act. The NIST AI RMF supports the fulfillment of legal obligations but does not replace them. The legal assessment under the EU AI Act remains a separate task, for which the framework provides a methodological foundation.
First key takeaway: The NIST AI RMF structures AI risk management across four functions—Govern, Map, Measure, and Manage—and is supplemented by profiles for generative AI, agentic systems, and, as of April 2026, critical infrastructure. It is voluntary but widely applicable as a common language between law and practice. Recommendation: Understand the framework as an operational method, not a compliance formality.
Second key takeaway: The NIST AI RMF, ISO 42001, and the EU AI Act complement each other at different levels. The RMF provides the risk methodology, ISO 42001 the management system, and the EU AI Act the legal obligation. Recommendation: Map the three frameworks clearly to one another and use crosswalks instead of building duplicate structures.
Third key takeaway: In the SAP landscape, the NIST functions are not implemented by a single tool. The inventory is handled by agent management, while controlled release and the audit trail are handled by change governance. Recommendation: Dock AI risk management to existing change and release governance and begin with a complete AI inventory.
NIST. "AI Risk Management Framework". nist.gov/itl/ai-risk-management-framework. Accessed June 2026. NIST. "NIST AI 600-1, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile". July 2024, DOI 10.6028/NIST.AI.600-1. NIST. "Concept Note: AI RMF Profile on Trustworthy AI in Critical Infrastructure". April 7, 2026. NIST. "NIST AI 100-5, Agentic AI Profile". 2026. NIST. "NIST IR 8596, Cyber AI Profile (Preliminary Draft)". December 2025. ISO/IEC. "ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system". European Commission. "Artificial Intelligence Act (EU AI Act)". digital-strategy.ec.europa.eu. Accessed June 2026.
"ISO 42001 and the EU AI Act in the SAP context", "AI Governance: Introduction and Fundamentals", "MCP Server Governance for SAP: Whitelist, Sandbox, and Audit", "Agentic AI in SAP Change Management: Pipeline Architecture and the Governance Gap", "SAP Sapphire 2026: Autonomous Enterprise, AI Agent Hub, and the Open Questions of the Governance Layer".
Thomas A. Anderson is a Research Contributor at the Change Orchestration Institute, focusing on AI architecture, governance frameworks, and the integration of autonomous systems into regulated enterprise landscapes. His work bridges the gap between technical architecture and the requirements imposed on production environments by risk frameworks and regulations.
*The Change Orchestration Institute is an independent knowledge resource for SAP ALM, Change Orchestration, and AI Governance. Initiator and research partner: Solutive AG, solutive.ag/kontakt.*