← ClaudeAtlas

nist-ai-rmf-assessmentlisted

Run a gap assessment against the NIST AI Risk Management Framework — GOVERN, MAP, MEASURE, MANAGE — and produce prioritised findings with evidence. Use this whenever NIST AI RMF, AI RMF 1.0, the AI risk management framework, trustworthy AI characteristics, or the Generative AI Profile (NIST AI 600-1) comes up; whenever a US-based or federally-connected organisation needs an AI risk assessment; whenever someone asks "how mature is our AI governance?", "what's our AI risk posture?", or "where are the gaps in how we manage AI?"; and whenever a customer, regulator, insurer, or procurement process asks an organisation to demonstrate AI risk management against a recognised framework. Also use it when an organisation wants a voluntary framework to structure AI governance and has not chosen one, since AI RMF is the most common starting point and maps onward to ISO 42001 and the EU AI Act.
PKusch/remit · ★ 0 · AI & Automation · score 72
Install: claude install-skill PKusch/remit
# NIST AI RMF assessment The AI RMF is voluntary, outcome-based, and deliberately non-prescriptive. That is its strength and its trap: because it describes outcomes rather than controls, it is easy to produce an assessment where everything is "partially met" and nothing is actionable. Avoid that by insisting on evidence. A subcategory is met when you can point at something — a document, a log, a test result, a named owner, a decision record. "We do that informally" is *not met*, and saying so plainly is the most useful thing this assessment does. Framework: AI RMF 1.0 (January 2023), four functions, 19 categories, 72 subcategories. For generative and foundation-model systems, also consult the Generative AI Profile (NIST AI 600-1, July 2024). Detail in [`references/functions.md`](references/functions.md). ## Scope first Assess a **system**, or an **organisation**, but say which. Mixing them produces findings nobody can own. - **System-level** — MAP, MEASURE, and the system-facing parts of MANAGE carry the weight. GOVERN is assessed as inherited from the organisation. - **Organisation-level** — GOVERN carries the weight; the others are sampled across systems. Work from system records where they exist. ## The four functions **GOVERN** — the culture, structures, and accountability that make the rest possible. Cross-cutting; assess it first, because weakness here explains most findings elsewhere. Look for: an AI policy that someone can produce, named accountability th