HomeCybersecurityNIST AI RMF 1.0 Assessment & Maturity Profile

🧭 NIST AI Risk Management Framework (AI RMF 1.0) assessment

Build an AI RMF profile and maturity score against the NIST AI Risk Management Framework (AI RMF 1.0). Rate the subcategories under the four functions — GOVERN, MAP, MEASURE and MANAGE — from Not started to Optimized, get per-function maturity percentages, an overall profile, a prioritized findings list with subcategory IDs, and a Word export. Cross-references the EU AI Act and ISO/IEC 42001 where natural.

Organization & scope
Maturity scale

Rate each subcategory on a 0–4 maturity scale: 0 Not started, 1 Initial / ad hoc, 2 Defined, 3 Managed, 4 Optimized, or N/A (excluded with justification — omitted from the score). Each function’s maturity % is the mean rating × 25; the overall AI-RMF profile is the mean across all scored subcategories.

Functions & subcategories
Maturity profile

⚠️ Screening / indicative only — not legal advice. This tool is a self-assessment aid based on the NIST AI Risk Management Framework (AI RMF 1.0, January 2023). The items are representative summaries of the framework’s categories and subcategories — not the full text and not a conformity audit. The AI RMF is voluntary and outcomes-based; maturity scoring here is an AMAADOR Workshop convention, not part of NIST’s framework. Use it alongside the NIST AI RMF Playbook, and read it with applicable obligations (e.g. EU AI Act, ISO/IEC 42001).