NIST AI RMF (framework self-assessment) v0.1.0
framework-nist · 1 sections
Metadata
Scales, categories & audiences
Scales: maturity5 (5 levels) · Categories: govern map measure manage trust · Audiences: lead owner exec
Edit these in the raw JSON editor below — they change rarely and carry structure (levels, signals, deep-dive wiring) that a form would mangle.
NIST RMF elements core
Everyone answers these. The executive accountable for AI risk, the risk register owner, whoever leads generative AI use, procurement or vendor management, and a board member if the characteristics are to be board vocabulary.
| Id | Question | Type | Category | Scale | |
|---|---|---|---|---|---|
| nist-gv-1 | If an AI system in your organisation caused harm tomorrow, who would be held to account, and what written rule would they point to for how it should have been handled? | scored_text · scored | govern | maturity5 | |
| nist-gv-2 | When you last introduced an AI tool that changed how people work, who was consulted beforehand, and what did the people using it know about its risks? | scored_text · scored | govern | maturity5 | |
| nist-gv-3 | Which of your suppliers use AI to deliver what they sell you, and how would you find out if one of them changed the model behind it? | scored_text · scored | govern | maturity5 | |
| nist-mp-1 | How many AI systems does your organisation run today, and for the one you are least sure about, what is it for and who uses it? | scored_text · scored | map | maturity5 | |
| nist-mp-2 | Pick one of your AI systems: who could it affect badly if it got things wrong, and where is that written down? | scored_text · scored | map | maturity5 | |
| nist-ms-1 | How do you know an AI system is working as intended? What do you measure, how often, and who sees the number? | scored_text · scored | measure | maturity5 | |
| nist-ms-2 | If one of your AI systems had slowly started giving worse answers over the last three months, what would have told you, and who would have noticed first? | scored_text · scored | measure | maturity5 | |
| nist-mg-1 | Of the AI risks you have identified, which three worry you most right now, and what has been done about each since you named them? | scored_text · scored | manage | maturity5 | |
| nist-mg-2 | Tell me about the last time an AI system did something it should not have. What happened next, and what changed afterwards? | scored_text · scored | manage | maturity5 | |
| nist-tc-1 | If a board member asked you what good AI means for this organisation, what words would you use, and are they the same words the people building it would use? | scored_text · scored | trust | maturity5 | |
| nist-tc-2 | Where is generative AI used in your organisation today, and for one of those uses, what stops it making things up, leaking data or producing content you would not want your name on? | scored_text · scored | trust | maturity5 |
+ Add question to “NIST RMF elements”
Add section
Advanced — raw JSON
Full pack document, validated on save (schema yarn-pack/2). This is where scales, audiences, structured conditions and adaptive config live.