4 min readMaximilian Simkins
What Is a NIST AI RMF Assessment and What Does It Cover?
A NIST AI RMF assessment checks your AI use against the framework's 72 subcategories across Govern, Map, Measure and Manage, and records evidence for each.
- NIST AI RMF
- AI governance
- risk assessment
- compliance
A NIST AI RMF assessment is a structured review of how your organization manages AI risk, measured against the NIST AI Risk Management Framework. It checks your practices against the framework's four functions (Govern, Map, Measure, Manage) and the 72 subcategories under them, and records what evidence exists for each. The result is a picture of where you already meet an outcome and where you don't.
It is not a certification. NIST publishes the framework as voluntary, so no pass or fail stamp comes with it.
What is the NIST AI RMF, in one paragraph?
The AI RMF 1.0 (NIST AI 100-1) is a voluntary framework NIST released in January 2023 to help organizations manage risks from AI systems. Its Core is organized into four functions. Each function breaks into categories, and each category breaks into subcategories, which are short statements of an outcome, such as "Mechanisms are in place to inventory AI systems."
Count the Core tables in the NIST document and you get this. Govern has 6 categories and 19 subcategories. Map has 5 and 18. Measure has 4 and 22. Manage has 4 and 13. That is 19 categories and 72 subcategories in total.
What does an assessment actually check?
An assessment checks whether each subcategory's outcome is true for your organization and whether you can show evidence for it. For each one, the reviewer asks whether the specific outcome holds and where the proof is.
| Function | Scope | What an assessor looks for | Example subcategory |
|---|---|---|---|
| Govern | The whole organization | Policies, named owners, training, an AI inventory, decommissioning rules | GOVERN 2.1: roles and responsibilities for mapping, measuring and managing AI risk are documented and clear |
| Map | Each AI system | Intended purpose, context, users, legal setting, who is affected | MAP 1.1: intended purposes and deployment settings are understood and documented |
| Measure | Each AI system | How the system is tested, which metrics, whether behavior is monitored in production | MEASURE 2.4: functionality and behavior are monitored when in production |
| Manage | Each AI system | Prioritized risk treatment, response and recovery, post-deployment monitoring | MANAGE 4.1: post-deployment monitoring plans are implemented, including incident response and decommissioning |
Govern applies across the organization. Map, Measure and Manage apply to individual AI systems, which is why an assessment usually starts with a list of the systems in use.
How is an assessment different from a gap analysis or an audit?
A NIST AI RMF assessment is closest to a gap analysis. The framework itself describes the idea: a Current Profile shows how AI is being managed today, a Target Profile shows the outcomes you want, and comparing the two reveals the gaps to close.
An audit tests against a fixed standard that someone can certify you against. The AI RMF has no such certification, so an assessment is a judgment of fit against a voluntary framework. The reviewer's rigor and the quality of the evidence carry the weight.
Who needs one?
Nobody is required by NIST to have one. NIST states the framework is voluntary and that organizations are not required to use it. The reasons people ask for an assessment are usually external: a customer questionnaire, a contract, or a procurement requirement. If you sell to the federal government, see our earlier post on NIST AI RMF for federal contractors.
What should you have ready?
Gather these before anyone starts:
- A list of the AI tools and systems in use, including the ones staff adopted on their own.
- Any written AI policy or acceptable use rules.
- Who owns AI decisions, even if the answer is "nobody yet."
- Vendor terms for the AI tools that touch company or customer data.
- Any testing or monitoring records for systems you build or configure.
If most of this does not exist, the assessment will say so. The 72 subcategories then give you an ordered list of what to build.
What do you get at the end?
You should get findings mapped to subcategories, with the evidence behind each rating, and a plan for the gaps. Be wary of any assessment that returns only a score. A score without the evidence trail cannot be defended to a customer or an auditor later.
What do teams usually find first?
When we help clients with AI governance, the most common gap shows up before any detailed rating: many have no written AI acceptable use policy. At the same time, AI use is already widespread across the company, because employees bring their own outside AI tools to work. That puts the Govern function first, since the policies and accountability it covers are what the other three functions rest on.
Simkins & Elgazar offers an independent, evidence-based assessment across all 72 subcategories, reviewed and signed by a person. The details are on our AI governance page.
Sources
- NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1, January 2023: https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf (function, category and subcategory counts tallied by the author from the Core tables; GOVERN 2.1, MAP 1.1, MEASURE 2.4, MANAGE 4.1 wording; Current and Target Profile description in section 6; voluntary status)
- NIST, AI RMF FAQs ("NIST has produced the AI RMF as a voluntary Framework"; organizations are not required to use it): https://www.nist.gov/itl/ai-risk-management-framework/ai-risk-management-framework-faqs
- NIST AI RMF Playbook: https://airc.nist.gov/airmf-resources/playbook
- NIST, AI Risk Management Framework page ("Released on January 26, 2023"): https://www.nist.gov/itl/ai-risk-management-framework
- Simkins & Elgazar, AI governance page (72-subcategory assessment description): https://simkinselgazar.com/governance/