Step-by-step Guide to Prepare for a NIST AI Risk Management Framework Risk Assessment
Posted in AI Risk Assessment, NIST Audit
How to Prepare for a NIST AI RMF Risk Assessment
Artificial intelligence can create significant opportunities for a business.
It can also create risks that traditional IT security assessments may not fully address.
A company might use AI to review documents, summarize customer interactions, write marketing content, analyze financial information, screen applications, assist employees, or make recommendations. It might also use generative AI tools that employees adopt without a formal technology review.
AI technology may have arrived quickly.
The risk management process often has not.
That is where the NIST Artificial Intelligence Risk Management Framework (AI RMF) can help.
The NIST AI RMF helps organizations manage AI risks and use AI responsibly. NIST released version 1.0 in January 2023, and it is available for any industry to use voluntarily. An updated version is already being developed.
If your company is planning a NIST AI RMF risk assessment, Tanner put together a step-by-step guide so companies can prepare for the assessment and can make it a valuable process, not just another report that gets ignored.
First, Understand What a NIST AI RMF Assessment Actually Is
One of the first things to understand about the NIST AI RMF is that it does not operate like a traditional certification checklist.
NIST describes the AI RMF as a voluntary resource, not a certification standard. The AI RMF Core organizes AI risk management around four functions:
Govern, Map, Measure, and Manage.
These functions provide a structure for understanding and addressing AI risks, but NIST specifically says the actions within the framework do not constitute a checklist or necessarily represent an ordered set of steps.
This difference is important.
Companies should avoid treating an AI RMF assessment as a simple checklist where a NIST IT audit just checks boxes and gives approval.
Instead, think of the assessment as a building inspection.
An inspector does not simply ask whether the building has a roof.
They look at the roof, electrical system, plumbing, foundation, fire protection, entrances, and other areas that affect the building’s safety and intended use.
A NIST AI RMF assessment takes a similar approach to how your company uses AI.
It asks whether your company understands its AI systems, the risks those systems create the controls you have established, and whether you have a process for managing those risks over time.
What Are the Four NIST AI RMF Functions?
The AI RMF organizes its Core around four functions:
Govern establishes the policies, processes, accountability, culture, and responsibilities needed to manage AI risk.
Think of this as setting the rules of the road.
Before employees start driving company vehicles, the company establishes who can drive, what rules apply, who maintains the vehicles, and what happens when something goes wrong.
AI needs similar governance.
- Who can approve an AI system?
- Who owns the risk?
- Who can use AI with customer information?
- Who reviews new AI vendors?
- Who investigates an AI incident?
- Who decides whether an AI system should continue operating?
Those are governance questions.
Map establishes the context in which an AI system operates and identifies risks associated with that context.
This is like knowing your destination before you start driving.
You need to know the destination, the roads, the conditions, and the potential hazards.
For an AI system, that means understanding its intended purpose, users, data, environment, potential impacts, limitations, and risks.
Measure involves analyzing, assessing, and monitoring AI risks using appropriate methods and metrics.
This is like checking the brakes before driving on the highway.
It is not enough to say that an AI system should be accurate, secure, fair, reliable, or explainable.
Your company needs ways to evaluate those characteristics.
NIST describes the Measure function as using quantitative, qualitative, or mixed methods to analyze, assess, benchmark, and monitor AI risks and related impacts.
Manage focuses on prioritizing risks and acting based on the results of the Govern, Map, and Measure functions.
This is where the company decides what to do about the risks it identified.
- Do you accept the risk?
- Reduce it?
- Transfer it?
- Change the system?
- Restrict its use?
- Stop using the system?
NIST’s Manage function includes prioritizing documented risks based on factors such as impact, likelihood, and available resources or methods.
These four functions work together, not as separate projects.
Govern → Map → Measure → Manage
And then the process continues.
Step 1: Create an Inventory of Your Company’s AI Systems
Before you can assess AI risk, you need to know what AI your company actually uses.
That might sound obvious.
But in practice, it often is not.
Many companies have formal AI applications purchased by IT, and informal AI tools employees adopted independently.
An employee may use ChatGPT to draft emails.
Another may use an AI transcription service for meetings.
The marketing department may use an AI image or writing platform.
The accounting department may use AI features built into financial software.
A customer service team may use an AI assistant.
IT may have approved a Microsoft or other enterprise AI service.
Some of these tools may never appear on a traditional software inventory.
This can cause problems.
“You cannot manage AI risks you do not know about.”
Think about your company’s AI inventory like a company’s list of vehicles.
If the fleet manager knows about 20 company vehicles but employees have independently purchased and started using five additional vehicles, the manager does not have a complete picture of the fleet.
AI works the same way.
Your inventory should identify, at a minimum:
- AI systems and applications currently in use.
- Business purpose.
- Business owner.
- Technology or vendor.
- Users.
- Types of data processed.
- Whether the system makes recommendations or decisions.
- Whether humans review AI output.
- Whether the system is internally developed or provided by a third party.
- Where the system fits into important business processes.
The goal is not to create paperwork just for the sake of it.
Instead, you want a clear and complete picture of your company’s AI environment.
Step 2: Identify Who Owns Each AI System
AI risk does not belong exclusively to IT.
That is an important point to establish before an assessment.
The IT department may manage the technology, but the business department may determine how it is used.
For example, IT may administer an AI-powered customer service platform.
The customer service department may decide what information employees enter.
Legal may determine whether certain information can be processed.
Compliance may identify regulatory requirements.
Executive leadership may determine how much risk the company is willing to accept.
These responsibilities should be clear before an assessment begins.
For each significant AI system, identify:
- Who owns the business process?
- Who owns the technology?
- Who approves its use?
- Who manages the vendor relationship?
- Who monitors performance?
- Who responds when something goes wrong?
Think of this as owning a company vehicle.
The person who maintains the vehicle may not be the person who decides where the vehicle goes.
Both responsibilities matter.
Step 3: Document What Each AI System Is Supposed to Do
One of the simplest ways to prepare for an AI risk assessment is to clearly document each AI system’s intended purpose.
- What problem is the company trying to solve?
- What does the AI actually do?
- What decisions does it influence?
- What decisions does it make?
- Who uses its output?
- What happens if the output is wrong?
This matters because you cannot tell if an AI system is working properly unless you know what it is supposed to do.
Imagine hiring an employee and never giving that employee a job description.
Six months later, you ask whether the employee is performing well.
That would be difficult to answer.
AI systems need the same clarity.
Step 4: Identify the Data Your AI Systems Use
Data represents one of the most important areas to examine before an AI risk assessment.
Your company should understand what information enters an AI system and what happens to that information afterward.
Consider an employee who copies a customer email into a public AI tool to ask for help writing a response.
The employee may think:
“I’m just asking AI to rewrite an email.”
From a risk perspective, the more important question may be:
“What information did the employee just send to a third-party AI service?”
The same issue applies to contracts, financial information, employee records, customer information, intellectual property, source code, health information, and other sensitive data.
Before the assessment, identify:
- What data each AI system receives.
- Where the data comes from.
- Whether the data contains sensitive or confidential information.
- Whether the AI provider retains submitted data.
- Whether the provider uses data to train models.
- Where data gets stored.
- Who can access the data.
- How the company removes or retains the information.
You do not need to understand the math behind an AI model to answer these questions.
You need to understand what information goes in and what happens to it afterward.
Step 5: Identify the AI Risks That Matter to Your Business
NIST’s AI RMF focuses on risk and trustworthiness rather than treating every AI system identically.
That means your assessment should consider the context of your company’s actual AI use.
For example, an AI tool that helps employees brainstorm marketing headlines may present very different risks from an AI system that helps determine whether a customer receives a loan.
The technology may be similar.
The consequences are not.
Consider the difference between an AI assistant that recommends lunch restaurants and an AI system that recommends whether a customer receives financing.
If the restaurant recommendation is wrong, someone eats somewhere else.
If a financial recommendation is wrong, someone could face significant financial consequences.
The potential impact changes the risk.
NIST identifies several characteristics associated with trustworthy AI, including validity and reliability, safety, security and resilience, accountability and transparency, explainability and interpretability, privacy enhancement, and fairness with harmful bias managed.
Your assessment should consider which of these characteristics matter most for each AI system.
Step 6: Review Your AI Policies
If your company uses AI, employees should not have to guess what they can and cannot do.
Before assessing your policies, review your existing policies.
- Do you have an acceptable-use policy for AI?
- Does it explain what information employees can enter into AI tools?
- Does it identify approved AI platforms?
- Does it explain whether employees can use personal AI accounts for company work?
- Does it address confidential information?
- Does it address customer information?
- Does it address AI-generated content?
- Does it explain when employees must verify AI output?
- Does someone approve new AI applications before employees begin using them?
Your policy does not need to be 50 pages long. Often, a clear policy that employees understand is more helpful than a long document that no one reads.
Think about a fire evacuation plan.
The goal is not to create the longest possible emergency manual.
The goal is to make sure people know what to do when something goes wrong.
AI governance should work the same way.
Step 7: Review Your AI Vendor Agreements
Many companies do not build their own AI systems.
They purchase or subscribe to AI services from third-party vendors.
That means some of your AI risk exists outside your company’s network.
Before the assessment, gather contracts and agreements for significant AI vendors.
Look for provisions related to:
- Data ownership.
- Data retention.
- Data use.
- Model training.
- Security controls.
- Breach notification.
- Data location.
- Service availability.
- Audit rights.
- Incident response.
- Termination and data deletion.
You can think of this as hiring a company to store valuable inventory for your business.
Even though the inventory is physically somewhere else, you still care about the facility’s security, access controls, insurance, procedures, and ability to respond to a break-in.
Your AI vendors should get the same careful review when they handle important company information or business tasks.
Step 8: Determine Where Humans Remain in the Process
One of the most important questions in an AI risk assessment is:
Where does human judgment remain?
AI output should not automatically become a business decision simply because a computer produced it.
Consider an AI system that reviews customer applications and recommends approval or denial.
If a human reviews the recommendation before making the final decision, the process differs from one in which the AI makes the decision automatically.
That distinction can materially affect risk.
Document:
- What does the AI decide?
- What does the AI recommend?
- When must a human review the result?
- Can a human override the AI?
- Who is responsible for the final decision?
- What happens when the AI produces an unexpected result?
Human oversight should be genuine, not just something written in a policy.
The people responsible for reviewing AI output need enough information and authority to recognize and challenge problematic results.
Step 9: Identify How You Test AI Systems
A company should not assume an AI system works correctly simply because the vendor says it does.
Testing should reflect the system’s actual risks.
Depending on the use case, testing might examine:
- Accuracy
- Reliability
- Security
- Privacy
- Privacy
- Unexpected outputs.
- Prompt injection.
- Data leakage.
- Unauthorized access.
- Model behavior.
- Performance degradation.
- Human oversight.
- Failure conditions
NIST’s Measure function calls for appropriate methods and metrics to assess AI risks and notes that AI systems should be tested before deployment and regularly during operation.
Think of testing an AI system as similar to checking a new employee’s work.
You would not give an employee access to your most sensitive information on the first day and never review their work again.
You establish expectations, review performance, identify problems, and adjust.
AI systems should go through a similar process.
Step 10: Document How You Handle AI Incidents
What happens if an AI system produces a harmful result?
What happens if confidential information enters the wrong AI platform?
What happens if an AI vendor experiences a security incident?
What happens if an AI system starts producing inaccurate results?
What happens if someone discovers that the system behaves differently for different groups of users?
Your company should have a process to identify, report, investigate, and respond to AI-related incidents.
This process should connect with your existing cybersecurity and incident response programs where appropriate.
AI should not create a completely separate emergency-response universe.
Instead, determine where AI-specific risks require additional procedures.
Step 11: Establish AI Risk Acceptance Criteria
No company can eliminate every AI risk.
That means leadership needs a way to decide which risks the company will accept, which risks it will reduce, and which uses it will not permit.
Suppose an AI system occasionally produces a minor formatting error.
That may be acceptable.
Now suppose an AI system occasionally produces incorrect information that could cause a significant financial loss.
That requires a different response.
NIST’s Manage function calls for prioritizing documented AI risks based on impact, likelihood, and available resources or methods, with responses developed for higher-priority risks.
At this point, managing AI risk becomes a business decision, not just an IT task.
Step 12: Gather Evidence Before the Assessment
One of the easiest ways to make an assessment more efficient is to gather documentation before the assessor starts asking for it.
Depending on your AI environment, this could include:
- AI inventory: A list of AI systems, applications, vendors, owners, and business purposes.
- AI policies: Policies governing acceptable AI use, data handling, approvals, human oversight, and other relevant practices.
- Vendor documentation: Contracts, security documentation, privacy terms, data-processing agreements, and other vendor materials.
- Risk assessments: Previous assessments or analyses of AI systems and related technology.
- Testing documentation: Evidence showing how AI systems have been evaluated for security, performance, accuracy, privacy, or other relevant risks.
- Incident records: Documentation of AI-related incidents, errors, complaints, or investigations.
- Training records: Evidence that employees understand applicable AI policies and responsibilities.
- Governance records: Meeting notes, approvals, risk decisions, committee records, or other documentation demonstrating that leadership actively manages AI risk.
This evidence shows not just what your company says it does, but what it actually does.
That difference is important.
What Happens If You Do Not Have Everything Ready?
Do not stop the assessment simply because your AI governance program is still developing.
In fact, identifying gaps is one reason to conduct a risk assessment.
If you discover you don’t have a formal AI inventory, that is a finding.
If nobody owns AI risk, that is a finding.
If employees use AI tools without clear guidance, that is a finding.
If you cannot explain what data an AI vendor retains, that is a finding.
The assessment should help turn those unknowns into manageable risks.
Consider how a financial audit works.
The purpose is not to pretend every accounting process is perfect before the auditor arrives.
The purpose is to determine what the company needs to understand, document, correct, or improve.
An AI risk assessment has a similar goal.
Common Mistakes Companies Make Before an AI Risk Assessment
Treating AI as Only an IT Issue: AI risk can involve IT, security, privacy, legal, compliance, HR, operations, finance, and executive leadership. Limiting the assessment to the IT department can leave important risks outside the conversation.
Assuming an AI Vendor Handles All the Risk: A vendor may provide security controls, but your company still needs to understand how the technology is used, what information it processes, and what responsibilities remain with your business.
Creating Policies Nobody Follows: A policy doesn’t reduce risk just because it exists. Your company should know whether employees understand the policy and whether the company actually follows it.
Focusing Only on Security: AI security matters. But AI risk extends beyond traditional cybersecurity. Depending on the use case, companies may also need to consider privacy, accuracy, reliability, transparency, explainability, fairness, safety, and other trustworthiness characteristics.
Treating the AI RMF Like a Checklist: NIST specifically states that the AI RMF Playbook is not a checklist or an ordered set of steps. It provides suggested actions that organizations can adapt to their circumstances. The goal should be real risk management, not just checking boxes.
How Tanner Security Can Help with a NIST AI RMF Risk Assessment
AI can move faster than traditional governance processes.
That creates a challenge for companies that want to leverage AI without losing control of the associated risks.
Tanner Security can help your company evaluate its AI environment using the NIST AI Risk Management Framework as a practical risk-management reference.
An assessment can help your company understand:
- What AI systems are we actually using?
- What risks do those systems create?
- Are our policies and governance processes keeping pace with AI adoption?
- What information are our AI systems processing?
- Are our security and privacy controls appropriate?
- How do we test AI systems before and after deployment?
- Which risks should leadership address first?
The goal is not to produce a massive AI compliance report.
The goal is to help leadership clearly see where AI creates risk, where current controls offer protection, and where the company needs to act.
If your company is considering a NIST AI RMF assessment, Tanner Security can help you prepare, evaluate your current AI risk management practices, and develop a practical roadmap for addressing identified gaps.
Talk with Tanner Security about a NIST AI Risk Management Framework assessment.
NIST AI RMF Risk Assessments FAQ’s
What is a NIST AI RMF risk assessment?
A NIST AI RMF risk assessment evaluates how a company identifies, measures, manages, and governs risks associated with its use of artificial intelligence. The assessment can use the four AI RMF functions—Govern, Map, Measure, and Manage, as a structure for evaluating an organization’s AI risk management practices.
Is the NIST AI RMF mandatory?
The NIST AI RMF is voluntary. NIST describes it as a voluntary, cross-sector framework that organizations can adapt to their AI systems, risks, and circumstances.
However, a company may still have contractual, regulatory, customer, or internal requirements that make AI risk management important.
Is NIST AI RMF a certification?
No. NIST AI RMF 1.0 is not a certification program. Companies can use the framework to structure AI risk management and assessments, but completing the framework does not create a NIST certification.
What are the four functions of the NIST AI RMF?
The four functions are Govern, Map, Measure, and Manage. Govern establishes the foundation for AI risk management. Map establishes context and identifies risks. Measure assesses and monitors risks. Manage prioritizes and responds to those risks.
What should a company have ready for a NIST AI RMF assessment?
Companies should be prepared to provide information about their AI systems, business purposes, data, users, owners, policies, vendors, testing, monitoring, incidents, risk decisions, and controls. The specific evidence needed depends on the company’s AI environment and assessment objectives.
Do we need an AI inventory?
An AI inventory provides an important foundation for AI risk management. Companies need to know what AI systems they use before they can effectively assess the risks those systems create.
Who should participate in an AI risk assessment?
AI risk can involve multiple areas of a company. Depending on the use cases, participants may include IT, information security, legal, compliance, privacy, HR, operations, finance, business-unit leaders, and executive management.
Does NIST AI RMF only apply to companies that develop AI?
No. NIST designed the AI RMF for companies that design, develop, deploy, or use AI systems. A company does not need to build its own AI model to have AI-related risk. Read more about why every business using AI needs an AI security assessment.
Does the NIST AI RMF address generative AI?
Yes. NIST published the Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile in 2024 as a companion resource to AI RMF 1.0. It addresses risks associated with generative AI and provides additional guidance for applying the framework to generative AI systems. It also addresses AI exploit strategies for security professionals.
What types of AI risks does the NIST AI RMF address?
The framework addresses AI risks associated with trustworthy and responsible AI. Depending on the use case, this can include security, privacy, reliability, safety, transparency, explainability, accountability, and fairness-related concerns.
What if our company does not have an AI policy?
That does not necessarily mean you should postpone an assessment. The absence of an AI policy can itself represent a governance gap that the assessment can identify and help the company address.
How often should a company conduct an AI risk assessment?
No single assessment frequency applies to every company. AI risk management should continue throughout the AI lifecycle, and companies should reassess systems when their capabilities, use cases, risks, or operating environments change.
Can a NIST AI RMF assessment identify AI security vulnerabilities?
It can help identify AI-related security risks and weaknesses in governance, processes, controls, and system use. However, an AI RMF assessment is not necessarily a substitute for technical security testing such as penetration testing or application security testing.
How is an AI risk assessment different from a cybersecurity assessment?
A cybersecurity assessment primarily examines information security risks and controls. An AI risk assessment can include cybersecurity but also considers AI-specific concerns such as intended use, model behavior, human oversight, transparency, explainability, privacy, reliability, and potential impacts.
Can Tanner Security help prepare for a NIST AI RMF assessment?
Yes. Tanner Security can help companies understand their current AI risk management practices, identify gaps, evaluate relevant controls, and develop practical recommendations using the NIST AI RMF as a reference framework.
Related Cybersecurity Services
AI risk management often overlaps with several other areas of cybersecurity and risk management.
AI Risk Assessment can help your company identify and evaluate risks associated with specific AI systems and use cases.
IT Risk Assessment can place AI-related risks within the broader technology and business risk environment.
Cybersecurity Consulting can help companies develop practical security and governance controls as AI adoption expands.
Penetration Testing can provide technical testing of applications, infrastructure, and AI-enabled systems where appropriate.
IT Policy Development can help establish clear rules for acceptable AI use, data handling, security responsibilities, and employee expectations.
Privacy Consulting can help companies evaluate privacy considerations when AI systems process personal or sensitive information.
Know what happens when those controls fail.
NIST’s AI RMF provides a flexible structure for doing that through Govern, Map, Measure, and Manage. The framework supports continuous risk management rather than a one-time compliance exercise.
The companies that manage AI risk effectively will not necessarily be the companies that use the least AI.
They will be the companies that understand where AI creates value, where it creates risk, and how to manage the difference.
If your company is preparing for a NIST AI RMF assessment or wants to understand where its current AI risk management program stands, Tanner Security can help.
Schedule a Call