Bern, Lisbon, New York info@ai-ei.org +351 93 832 8533
Assessment Platform

NIST AI RMF Readiness Assessment

Your practice against Govern, Map, Measure and Manage, plus the trustworthy AI characteristics and TEVV.

NIST Risk Framework 30 questions About 15 minutes Free, no account
Step 1 of 2 Organisation context
Organisation context

This shapes the recommendations you get at the end. Nothing here changes your score.

Please enter your organisation name.

Please enter a valid email address.

Please choose an option.

Please choose an option.

Please choose an option.

Please choose an option.

Choose another framework

Self-assessment only. Not legal advice, not an audit opinion, and not certification.

Readiness questions

Answer all 30 questions as honestly as you can. There are no right or wrong answers; an honest picture produces a useful action plan.

01

Govern — Policies and Accountability

01 Are AI risk management policies, processes, and procedures documented and approved?

Critical requirement, weight 3

02 Are accountability structures in place so teams and individuals are empowered and responsible for AI risks?

Critical requirement, weight 3

03 Are legal and regulatory requirements applicable to your AI systems identified and tracked?

Critical requirement, weight 3

04 Is workforce diversity, equity, and multidisciplinary input part of AI decision-making?

Important requirement, weight 2

02

Govern — Culture and Third Parties

05 Does the organisation foster a culture where AI risks can be raised without fear (critical thinking, safety-first mindset)?

Important requirement, weight 2

06 Are processes in place to manage AI risks arising from third-party software, data, and models?

Critical requirement, weight 3

07 Are mechanisms in place to collect and integrate feedback from relevant AI actors and affected communities?

Important requirement, weight 2

03

Map — Context and Categorization

08 Is the context of each AI system established (intended purpose, users, deployment setting, expectations)?

Critical requirement, weight 3

09 Are AI systems categorized (type, capability, criticality) to guide risk treatment?

Critical requirement, weight 3

10 Are the system’s benefits, costs, and potential negative impacts mapped for each intended use?

Important requirement, weight 2

11 Are risks from foreseeable misuse or off-label use of AI systems identified?

Critical requirement, weight 3

12 Are impacts on individuals, groups, communities, and society mapped for each AI system?

Critical requirement, weight 3

04

Measure — Metrics and TEVV

13 Are appropriate methods and metrics selected to measure AI risks and trustworthiness?

Critical requirement, weight 3

14 Are AI systems evaluated for validity and reliability against defined performance criteria?

Critical requirement, weight 3

15 Are AI systems tested for safety, security, and resilience (including adversarial testing/red-teaming)?

Critical requirement, weight 3

16 Are fairness and harmful bias measured and evaluated for relevant AI systems?

Critical requirement, weight 3

17 Are privacy and explainability/interpretability characteristics assessed?

Important requirement, weight 2

18 Is test, evaluation, verification, and validation (TEVV) performed throughout the lifecycle, not only pre-launch?

Critical requirement, weight 3

19 Are measurement results tracked over time to detect degradation or drift?

Important requirement, weight 2

05

Manage — Prioritization and Response

20 Are AI risks prioritized and treated based on measured impact and organisational risk tolerance?

Critical requirement, weight 3

21 Are documented risk responses in place (mitigate, transfer, avoid, accept) for significant AI risks?

Critical requirement, weight 3

22 Are resources allocated to manage the highest-priority AI risks?

Important requirement, weight 2

23 Are plans in place for superseding, decommissioning, or deactivating AI systems safely?

Important requirement, weight 2

06

Manage — Monitoring and Improvement

24 Are deployed AI systems monitored in production, with defined intervention criteria?

Critical requirement, weight 3

25 Are incident response and recovery plans in place for AI system failures or harms?

Critical requirement, weight 3

26 Are mechanisms in place to capture and act on feedback from users and affected parties post-deployment?

Important requirement, weight 2

27 Are risk management practices themselves reviewed and improved over time?

Important requirement, weight 2

07

Trustworthy AI Characteristics

28 Do you document how each AI system addresses the trustworthy AI characteristics (valid, safe, secure, accountable, explainable, privacy-enhanced, fair)?

Important requirement, weight 2

29 Are trade-offs between trustworthiness characteristics (e.g., accuracy vs. explainability) explicitly considered and documented?

Important requirement, weight 2

30 Have you used or considered structured profiles or playbooks (e.g., NIST AI RMF Playbook) to implement the framework?

Important requirement, weight 2

Results are generated instantly. Self-assessment only, not an audit.