nist-ai-rmf

Advises on NIST AI RMF 1.0 governance, risk assessment, and cross-framework compliance mapping.

Updated Jul 29, 2026
One-click install
npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill nist-ai-rmf-fr-lyo-cys-aura
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: nist-ai-rmf
Source: https://github.com/FR-LYO-CYS-AURA/GRC-Consultant/tree/main/extracted-skills/nist-ai-rmf
Command: npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill nist-ai-rmf-fr-lyo-cys-aura

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Organizations deploying AI systems struggle to identify, measure, and manage AI-specific risks like bias, opacity, and drift in a structured, defensible way. This Skill provides expert guidance on the NIST AI Risk Management Framework (AI RMF 1.0), turning its four functions — GOVERN, MAP, MEASURE, MANAGE — into concrete policies, risk registers, gap assessments, and remediation roadmaps. ## Core Features & Use Cases - GOVERN Gap Assessments: Rate all six GOVERN categories with status indicators and receive pasteable mini-templates including an AI risk policy outline, governance committee RACI charter, risk tolerance statements, and AI inventory fields. - AI Risk Registers: Build framework-traceable risk registers with worked example rows, including third-party and vendor-model dependency risks aligned to GOVERN 6.1/6.2. - Cross-Framework Mapping: Map AI RMF categories to the EU AI Act, ISO/IEC 42001, NIST CSF 2.0, and the NIST Privacy Framework for unified compliance programs. - Use Case: A financial services firm needs to assess a vendor-hosted credit scoring model. The Skill produces a risk register row covering fairness testing, champion–challenger monitoring, and residual risk acceptance aligned to SR 11-7 model risk management practice. ## Quick Start Ask the assistant to run a GOVERN gap assessment for your organization's AI risk management program using the NIST AI RMF.

Frequently Asked Questions about nist-ai-rmf

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a NIST AI RMF gap assessment?

Rate each of the six GOVERN categories as Not Started, Partial, or Implemented, then identify the evidence needed to close each gap. The Skill delivers a prioritized remediation roadmap plus pasteable templates for AI risk policies, governance committee charters, and risk tolerance statements.

What are the four functions of the NIST AI RMF?

The four functions are GOVERN (organizational accountability and risk tolerance), MAP (risk identification and context), MEASURE (risk analysis via TEVV activities), and MANAGE (risk treatment and incident response). GOVERN is cross-cutting and underpins the other three functions.

How does NIST AI RMF map to the EU AI Act?

GOVERN 1 maps to Article 9 risk management systems, MEASURE 2 to Articles 10 and 15 on data governance and accuracy, and MANAGE 3 to Article 73 incident reporting. The EU AI Act is mandatory for in-scope providers, while the AI RMF is voluntary and can serve as the methodology satisfying Article 9.

What are the seven trustworthiness characteristics in the AI RMF?

The seven characteristics are valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. Each has associated metrics such as demographic parity, SHAP/LIME explanations, adversarial accuracy, and differential privacy epsilon.

Is the NIST AI RMF mandatory for organizations?

No, the AI RMF is voluntary, outcome-based, and not a compliance checklist. Organizations subject to mandatory regimes like the EU AI Act can use it as the risk management methodology to satisfy legal requirements such as Article 9.

How do I build an AI risk register aligned to NIST AI RMF?

Use columns for AI system, lifecycle stage, TEVV activity, characteristic at risk, likelihood and impact, treatment, and owner. Include a dedicated row for third-party or vendor-model dependencies, and update entries whenever MEASURE activities produce new evidence.