Score all 72 subcategories across the Govern, Map, Measure, and Manage functions, with a built-in Generative AI Profile. Each subcategory gives you tier-by-tier examples and Playbook actions, so you always know what the right tier looks like. Free to use, no account required.
The NIST AI RMF organizes AI risk management into four functions: Govern (the cross-cutting culture, policies, and accountability), Map (frame the context and risks), Measure (analyze and track them), and Manage (prioritize and act).
The tool walks you through all 72 subcategories, scoring each on a four-level maturity scale (Partial, Risk Informed, Repeatable, Adaptive). For every subcategory you get specific examples of what each level looks like and the official Playbook actions to reach it.
Built to be completed in a single session or across multiple visits. With Pro, export a JSON snapshot to preserve your assessment and push gaps into your wider GRC workflow.
Name your organization and the AI system you are assessing, then set a target maturity tier. Capture your methodology, scope and constraints, and key assumptions up front so the record is defensible. You can apply one target tier across the board or customize it per subcategory.
Work through the Govern, Map, Measure, and Manage functions. Each subcategory receives a Current tier (Partial to Adaptive), a Target tier, a priority, and an optional completion date and evidence basis. Open any subcategory for tier-by-tier examples written for that specific outcome, official Playbook actions, and a crosswalk to related regulations such as the EU AI Act and ISO/IEC 42001.
If your system uses or builds on generative AI, work through the 12 risk categories from the NIST AI 600-1 Generative AI Profile, from confabulation and data privacy to harmful bias and prompt-injection. Mark which apply, record your mitigations, and use the suggested actions straight from NIST.
The Summary rolls everything into function maturity scores, a radar chart, and a prioritized gap action plan with target dates. Applicable GenAI risks are surfaced alongside the Core gaps. With Pro, push gaps into the POA&M, send AI risks to the Risk Register, and import previous snapshots into the Trends view to chart maturity improvement over time.
All scoring, guidance, and gap analysis is free. Pro adds the file management, reporting, cross-tool workflow, and trend tracking that serious work requires.
Export a complete point-in-time assessment to a JSON file. Share with teammates, archive for audit records, or reimport later to resume exactly where you left off.
Send subcategory tier gaps straight into the POA&M tracker and applicable Generative AI risks into the Risk Register, so findings flow directly into your remediation and risk workflow.
Generate a CSV with every score, target, gap, priority, due date, and evidence basis. It opens in Excel or Google Sheets, ready for stakeholder review or leadership reporting.
Produce a customizable, professionally formatted report with executive summary, function scores, the gap action plan, and your GenAI Profile findings. Always renders in light mode for clean printing.
Load two or more snapshots to see maturity progression over time. Line charts and per-function delta indicators show exactly where your AI governance program is improving.
No account required. Open the tool and start scoring in minutes, with tier-by-tier examples to guide every rating. With Pro, export a JSON snapshot to preserve your work for next time.