NIST AI RMF 1.0 Governance Auditor

Evaluate enterprise AI & LLM deployments across GOVERN, MAP, MEASURE, MANAGE.

Overall AI Risk

0/100

GOVERN

0/100

Cultivate a culture of AI risk management and establish governance structures.

G1 Has the organization established formal AI governance policies and procedures?

G2 Are roles and responsibilities for AI systems clearly defined and assigned?

G3 Is there a documented risk management framework specifically for AI systems?

G4 Are AI systems reviewed for legal, regulatory, and ethical compliance?

G5 Is there clear accountability and ownership for AI system outcomes?

MAP

0/100

Establish context to frame risk and identify characteristics of AI systems.

M1 Has the AI system context, intended use case, and deployment environment been documented?

M2 Are potential risks and impacts to stakeholders identified and documented?

M3 Has the impact on external stakeholders and affected communities been assessed?

M4 Are data sources, lineage, and quality documented and assessed?

M5 Are third-party AI components and vendor dependencies assessed for risk?

MEASURE

0/100

Assess, analyze, track, and monitor AI risk and trusted characteristics.

E1 Are AI systems regularly tested for performance, accuracy, and reliability?

E2 Is model drift monitored, detected, and addressed on an ongoing basis?

E3 Are bias, fairness, and harmful bias metrics tracked and evaluated?

E4 Is privacy impact assessed for each AI system handling PII or sensitive data?

E5 Are safety, security, and resilience metrics measured and benchmarked?

MANAGE

0/100

Prioritize and act upon risks to AI systems and respond to identified incidents.

A1 Are risk mitigation strategies and controls implemented for identified risks?

A2 Is there an incident response plan specific to AI system failures or misuse?

A3 Are AI system changes managed through formal change control processes?

A4 Are lessons learned from AI incidents documented and applied to future deployments?

A5 Is continuous monitoring of AI systems in production in place and effective?

Trustworthiness Characteristics

Score each NIST AI 100-1 trustworthiness characteristic (0-100).

Valid & Reliable
050100
Safe
050100
Secure & Resilient
050100
Accountable & Transparent
050100
Explainable & Interpretable
050100
Privacy-Enhanced
050100
Fair with Harmful Bias Managed
050100

Executive AI Risk Matrix

Assess likelihood and impact for each AI failure mode.

Prompt Injectionmedium

Adversarial manipulation of LLM inputs to bypass safety controls or extract sensitive data.

LLM Data Poisoningmedium

Malicious injection of corrupted training data to degrade model integrity or introduce backdoors.

PII Leakagemedium

Unauthorized exposure of personally identifiable information through model outputs or inference attacks.

Model Driftmedium

Degradation of model performance over time due to shifts in input data distributions or environment changes.