nist-ai-rmf
AI risk assessment using NIST AI RMF 1.0 framework. Evaluate AI systems across 4 core functions (Govern, Map, Measure, Manage) for trustworthy and responsible AI deployment.
What this skill does
# NIST AI Risk Management Framework (AI RMF 1.0) This skill enables AI agents to perform a comprehensive **AI risk assessment** using the **NIST AI Risk Management Framework (AI RMF 1.0)**, published January 2023 by the National Institute of Standards and Technology. The AI RMF is a voluntary, technology- and sector-agnostic framework designed to help organizations manage risks associated with AI systems throughout their lifecycle. It promotes trustworthy AI development by addressing risks that affect individuals, organizations, and society. Use this skill to identify, assess, and manage AI risks; establish governance structures; ensure trustworthy AI characteristics; and align with international AI risk management best practices. Combine with "ISO 42001 AI Governance" for comprehensive compliance coverage or "OWASP LLM Top 10" for security-focused assessment. ## When to Use This Skill Invoke this skill when: - Assessing risks of AI systems before deployment - Establishing AI governance and accountability structures - Evaluating trustworthiness of AI products and services - Preparing for regulatory compliance (EU AI Act, state AI laws) - Conducting periodic AI risk reviews - Evaluating third-party AI tools and vendors - Building organizational AI risk management programs - Documenting AI system risks for stakeholders ## Inputs Required When executing this assessment, gather: - **ai_system_description**: Description of the AI system (purpose, capabilities, deployment context, users, data sources) [REQUIRED] - **system_lifecycle_stage**: Current stage (design, development, deployment, monitoring, decommissioning) [OPTIONAL, defaults to deployment] - **organization_context**: Organization size, industry, risk tolerance, regulatory environment [OPTIONAL] - **deployment_domain**: Sector and setting, including whether the system supports critical infrastructure [OPTIONAL] - **existing_controls**: Current risk management processes or controls in place [OPTIONAL] - **specific_concerns**: Known risks, incidents, or areas of focus [OPTIONAL] - **stakeholders**: Key stakeholders and affected communities [OPTIONAL] ## Trustworthy AI Characteristics The AI RMF identifies seven characteristics of trustworthy AI that serve as evaluation criteria across all functions: 1. **Valid and Reliable**: System performs as intended with consistent results 2. **Safe**: System does not endanger human life, health, property, or the environment 3. **Secure and Resilient**: System withstands adverse events and recovers gracefully 4. **Accountable and Transparent**: Information about the system is available to stakeholders 5. **Explainable and Interpretable**: Mechanisms and outputs can be understood 6. **Privacy-Enhanced**: Human autonomy and data rights are protected 7. **Fair with Harmful Bias Managed**: System does not produce discriminatory outcomes --- ## The 4 Core Functions The AI RMF Core is composed of four functions, each broken into categories and subcategories: ### GOVERN Function Establishes organizational policies, processes, and accountability for AI risk management. GOVERN is cross-cutting and applies across all other functions. #### GOVERN 1: Policies and Processes *Policies, processes, procedures, and practices across the organization related to the mapping, measuring, and managing of AI risks are in place, transparent, and implemented effectively.* - **GOVERN 1.1**: Legal and regulatory requirements involving AI are understood, managed, and documented - **GOVERN 1.2**: Trustworthy AI characteristics integrated into organizational policies, processes, and practices - **GOVERN 1.3**: Processes to determine needed risk management activity levels based on organizational risk tolerance - **GOVERN 1.4**: Risk management process and outcomes established through transparent policies, procedures, and controls - **GOVERN 1.5**: Ongoing monitoring and periodic review of risk management process with clear roles and responsibilities - **GOVERN 1.6**: Mechanisms to inventory AI systems resourced by organizational risk priorities - **GOVERN 1.7**: Processes for decommissioning and phasing out AI systems safely #### GOVERN 2: Accountability Structures *Accountability structures ensure appropriate teams and individuals are empowered, responsible, and trained for AI risk management.* - **GOVERN 2.1**: Roles, responsibilities, and communication lines documented and clear - **GOVERN 2.2**: Personnel receive AI risk management training - **GOVERN 2.3**: Executive leadership takes responsibility for AI decisions #### GOVERN 3: Workforce Diversity and Inclusion *Workforce diversity, equity, inclusion, and accessibility processes are prioritized in AI risk management.* - **GOVERN 3.1**: Decision-making informed by diverse team (demographics, disciplines, expertise) - **GOVERN 3.2**: Policies define roles for human-AI configurations and oversight #### GOVERN 4: Risk Culture *Organizational teams are committed to a culture that considers and communicates AI risk.* - **GOVERN 4.1**: Policies foster critical thinking and safety-first mindset - **GOVERN 4.2**: Teams document and communicate risks and impacts broadly - **GOVERN 4.3**: Practices enable AI testing, incident identification, and information sharing #### GOVERN 5: Stakeholder Engagement *Processes are in place for robust engagement with relevant AI actors.* - **GOVERN 5.1**: Policies collect, consider, and integrate external feedback on impacts - **GOVERN 5.2**: Mechanisms regularly incorporate adjudicated feedback into system design #### GOVERN 6: Third-Party Risk *Policies and procedures address AI risks from third-party software, data, and supply chain.* - **GOVERN 6.1**: Policies address risks from third-party entities including IP infringement - **GOVERN 6.2**: Contingency processes handle failures in high-risk third-party systems --- ### MAP Function Identifies and contextualizes AI system risks within the operational environment. #### MAP 1: Context Established *Context is established and understood.* - **MAP 1.1**: Intended purposes, beneficial uses, laws, norms, and deployment settings documented - **MAP 1.2**: Interdisciplinary AI actors with demographic diversity participate and documented - **MAP 1.3**: Organization's mission and goals for AI technology understood and documented - **MAP 1.4**: Business value or context clearly defined or re-evaluated - **MAP 1.5**: Organizational risk tolerances determined and documented - **MAP 1.6**: System requirements elicited with socio-technical considerations #### MAP 2: System Categorization *Categorization of the AI system is performed.* - **MAP 2.1**: Specific tasks and methods defined (classifiers, generative models, recommenders) - **MAP 2.2**: System knowledge limits and human oversight documented - **MAP 2.3**: Scientific integrity and TEVV considerations identified #### MAP 3: Capabilities and Costs *AI capabilities, targeted usage, goals, expected benefits, and costs are understood.* - **MAP 3.1**: Potential benefits of intended functionality examined and documented - **MAP 3.2**: Potential costs (monetary and non-monetary) from AI errors documented - **MAP 3.3**: Targeted application scope specified based on capability - **MAP 3.4**: Operator and practitioner proficiency assessed - **MAP 3.5**: Human oversight processes defined and documented #### MAP 4: Component Risks *Risks and benefits are mapped for all components including third-party.* - **MAP 4.1**: Approaches for mapping technology and legal risks documented - **MAP 4.2**: Internal risk controls for components identified and documented #### MAP 5: Impact Characterization *Impacts to individuals, groups, communities, organizations, and society are characterized.* - **MAP 5.1**: Likelihood and magnitude of impacts (beneficial and harmful) documented - **MAP 5.2**: Practices for regular engagement with relevant AI actors documented --- ### MEASURE Function Employs
Related in General
modeling-omnistudio-epc-catalog
IncludedSalesforce Industries CME EPC product-modeling skill for Product2-based catalog creation. Use when creating EPC products, configuring product attributes, building offer bundles with Product Child Items, or reviewing EPC DataPack JSON metadata for product catalog changes. TRIGGER when: user creates or updates Product2 EPC records, AttributeAssignment payloads, AttributeMetadata/AttributeDefaultValues, Offer bundles, or ProductChildItem relationships. DO NOT TRIGGER when: designing OmniScripts/FlexCards/Integration Procedures (use building-omnistudio-omniscript, building-omnistudio-flexcard, or building-omnistudio-integration-procedure), implementing Apex business logic (use generating-apex), or troubleshooting deployment pipelines (use deploying-metadata).
relationship-science-coach
IncludedUse this skill for direct, practical adult relationship coaching: couples conflict, repair, trust, marriage, dating, flirting, attachment patterns, emotional connection, sex, desire differences, eroticism, kink negotiation, affection, love languages, breakups, and long-term passion. Draw on Gottman, EFT and Hold Me Tight, attachment science, modern sex research, Perel, Nagoski, Kerner, Schnarch, Love and Stosny, and flexible love-language tools. Be concrete and low-hedge. Redirect only for imminent danger, abuse, coercive control, minors, non-consent, self-harm, stalking, or medical/legal/psychiatric decisions.
building-sf-integrations
IncludedSalesforce integration architecture and runtime plumbing with 120-point scoring. Use this skill to set up Named Credentials, External Credentials, External Services, REST/SOAP callout patterns, Platform Events, and Change Data Capture. TRIGGER when: user sets up Named Credentials, External Services, REST/SOAP callouts, Platform Events, CDC, or touches .namedCredential-meta.xml files. DO NOT TRIGGER when: Connected App/OAuth config (use configuring-connected-apps), Apex-only logic (use generating-apex), or data import/export (use handling-sf-data).
venue-templates
IncludedAccess comprehensive LaTeX templates, formatting requirements, and submission guidelines for major scientific publication venues (Nature, Science, PLOS, IEEE, ACM), academic conferences (NeurIPS, ICML, CVPR, CHI), research posters, and grant proposals (NSF, NIH, DOE, DARPA). This skill should be used when preparing manuscripts for journal submission, conference papers, research posters, or grant proposals and need venue-specific formatting requirements and templates.
let-fate-decide
IncludedDraws the 12 Houses of the Zodiac Tarot spread to inject entropy into planning when prompts are vague, ambiguous, or casually delegated. Interprets the spread to guide next steps. Use when the user says 'let fate decide', 'YOLO', 'whatever', 'idk', or other nonchalant phrases, makes Yu-Gi-Oh references, or when you are about to arbitrarily pick between multiple reasonable approaches. Prefer over ask-questions-if-underspecified when the user's tone is casual or playful rather than precision-seeking.
net-ops
IncludedCross-platform network troubleshooting (Windows, macOS, Linux) via local or remote shell. Use for: DNS broken, can't resolve hostnames, nslookup/dig works but apps fail, NRPT, WFP, scutil, /etc/resolver, systemd-resolved, /etc/resolv.conf, NetworkManager, VPN DNS leak residue (ProtonVPN/Mullvad/WireGuard/AnyConnect), AV/firewall blocking DNS or DoH, Tailscale DNS interaction, intermittent connectivity, remote diagnostics over SSH.