The NIST AI RMF Self-Assessment
Checklist
A self-assessment structured around NIST AI RMF's four functions: Govern, Map, Measure, Manage.
Govern
- Is there a named owner for this AI system?
- Is it recorded in an AI system inventory?
- Is there a clear escalation route if something looks wrong?
Map and Measure
- Is the intended use, and foreseeable misuse, documented?
- Has the system been tested for accuracy, bias and fairness, not accuracy alone?
- Does a model card exist covering known limitations?
Manage
- Is there a documented risk treatment decision, not just a risk list?
- Are human-in-the-loop controls and monitoring in place after launch?
- Is there a deactivation plan if the system needs to be withdrawn?
Start a conversation
Have a product or AI decision to make?
Useful first calls usually start with one unclear decision, a deadline and a team that needs a practical next move.
Tell us about it