The NIST AI RMF Self-Assessment

Checklist

A self-assessment structured around NIST AI RMF's four functions: Govern, Map, Measure, Manage.

01

Govern

  • Is there a named owner for this AI system?
  • Is it recorded in an AI system inventory?
  • Is there a clear escalation route if something looks wrong?
02

Map and Measure

  • Is the intended use, and foreseeable misuse, documented?
  • Has the system been tested for accuracy, bias and fairness, not accuracy alone?
  • Does a model card exist covering known limitations?
03

Manage

  • Is there a documented risk treatment decision, not just a risk list?
  • Are human-in-the-loop controls and monitoring in place after launch?
  • Is there a deactivation plan if the system needs to be withdrawn?

Start a conversation

Have a product or AI decision to make?

Useful first calls usually start with one unclear decision, a deadline and a team that needs a practical next move.

Tell us about it