nist-ai-rmf-assessmentlisted
Install: claude install-skill patkusch/remit
# NIST AI RMF assessment
The AI RMF is voluntary, outcome-based, and deliberately non-prescriptive. That is its
strength and its trap: because it describes outcomes rather than controls, it is easy to
produce an assessment where everything is "partially met" and nothing is actionable.
Avoid that by insisting on evidence. A subcategory is met when you can point at
something — a document, a log, a test result, a named owner, a decision record. "We do
that informally" is *not met*, and saying so plainly is the most useful thing this
assessment does.
Framework: AI RMF 1.0 (January 2023), four functions, 19 categories, 72 subcategories.
For generative and foundation-model systems, also consult the Generative AI Profile
(NIST AI 600-1, July 2024). Detail in
[`references/functions.md`](references/functions.md).
## Scope first
Assess a **system**, or an **organisation**, but say which. Mixing them produces findings
nobody can own.
- **System-level** — MAP, MEASURE, and the system-facing parts of MANAGE carry the
weight. GOVERN is assessed as inherited from the organisation.
- **Organisation-level** — GOVERN carries the weight; the others are sampled across
systems.
Work from system records where they exist.
## The four functions
**GOVERN** — the culture, structures, and accountability that make the rest possible.
Cross-cutting; assess it first, because weakness here explains most findings elsewhere.
Look for: an AI policy that someone can produce, named accountability th