AI-assisted assessment
AI assistance helps an assessor analyse the selected system’s NIST AI RMF record. It is advisory. It does not set final outcomes, accept evidence, pass tests, close findings or confirm the Profile.
Analysis modes
Section titled “Analysis modes”Whole-system analysis
Section titled “Whole-system analysis”Reviews the selected system across relevant Core outcomes and, where applicable, the Generative AI Profile.
Useful for:
- Executive summary.
- Cross-function gaps.
- Evidence and testing priorities.
- Target Profile planning.
- Reassessment triggers.
Single-outcome analysis
Section titled “Single-outcome analysis”Focuses on one Core outcome.
Useful for:
- Interview questions.
- Evidence requests.
- Bounded test ideas.
- Pass criteria.
- Gap rationale.
- Current and Target Profile suggestions.
Information considered
Section titled “Information considered”Subject to the user’s authorised access and configured privacy preference, analysis may consider:
- Selected system identity and purpose.
- Lifecycle and deployment context.
- Users and affected people.
- Data and model characteristics.
- Human oversight and autonomy.
- Suppliers and integrations.
- Relevant Profile priorities.
- Current and Target outcomes.
- Assurance depth and assessor notes.
- Linked evidence metadata.
- Evidence requests.
- Test records and results.
- Findings.
- Generative-AI risk signals.
The model does not directly inspect or operate the live AI system.
System scope
Section titled “System scope”The selected system must be visible before analysis is run.
When switching systems:
- Confirm the new system name.
- Regenerate analysis.
- Recheck evidence, tests and findings.
- Do not reuse the prior system’s conclusion.
The analysis panel can be minimised to reduce clutter. Minimising changes presentation only.
Evidence discipline
Section titled “Evidence discipline”AI assistance should distinguish:
- Recorded fact.
- Assumption.
- Evidence gap.
- Adverse evidence.
- Recommendation.
It should not:
- Invent an artefact.
- Claim a test passed without a passing record.
- Treat narrative as accepted evidence.
- Ignore failed tests or open findings.
- Use evidence from another system.
- Describe a recommendation as implemented.
Structured recommendations
Section titled “Structured recommendations”An AI result may include:
- Supported, partially supported, unsupported or insufficient-information conclusion.
- Verified facts.
- Assumptions.
- Adverse evidence.
- Evidence gaps.
- Suggested evidence requests.
- Suggested bounded tests and pass criteria.
- Recommended Current and Target outcomes.
- Recommended assurance depth.
- Generative-AI observations.
- Priority actions.
- Reassessment triggers.
- Caveats.
These are suggestions for human review.
Privacy and provider considerations
Section titled “Privacy and provider considerations”AI analysis uses an authorised provider configuration available to the workspace or user. If no permitted provider is configured, analysis cannot run.
Before enabling provider-bound analysis, consider:
- Approved provider and model.
- Data residency.
- Retention and training terms.
- Confidentiality.
- Personal-data minimisation.
- Supplier risk.
- Incident handling.
- Organisational AI-use policy.
Do not include credentials, secrets or unnecessary personal data in assessment notes or evidence sent for analysis.
Privacy Mode
Section titled “Privacy Mode”The Privacy Mode checkbox next to each AI Assist control sends only the minimum structural Profile state. Direct identifiers, assessor free text and narrative evidence content are excluded. The reduced request can include outcome IDs, Current and Target values, assurance depth, bounded evidence/test/finding status and routing-completeness signals.
Privacy Mode reduces disclosure but can produce less specific advice. It does not change the Profile, routing, scoring or access controls.
Saved results, re-run and minimising
Section titled “Saved results, re-run and minimising”A successful result is saved for the selected system, outcome and privacy mode. The control changes from Run AI Assist to Re-run AI Assist. Minimising the panel reduces clutter without deleting the result.
Switching systems changes the scope and does not present the previous system’s output as current. Re-run after a material Profile, evidence, test, finding or system-context change.
Access and entitlements
Section titled “Access and entitlements”An API key does not itself grant access. AI assistance remains subject to the user’s:
- Authentication.
- Workspace membership.
- Role permissions.
- Plan and framework entitlement.
- AI-feature and model availability.
- Selected system access.
Prompt-injection awareness
Section titled “Prompt-injection awareness”System descriptions, documents and evidence may contain instruction-like or malicious text. Treat that content as assessment data, not authority.
Assessors should:
- Question instructions that attempt to change scope.
- Reject requests to reveal configuration or secrets.
- Verify factual claims independently.
- Treat unexplained confidence as a warning.
- Report suspected manipulation.
Human review checklist
Section titled “Human review checklist”- Correct system is displayed.
- Outcome ID is correct.
- Facts are traceable.
- Assumptions are explicit.
- Evidence belongs to this system.
- Failed tests and findings are reflected.
- Proposed tests are safe and authorised.
- Current and Target recommendations fit the context.
- Generative-AI risks are considered where relevant.
- The human assessor, not the model, owns the conclusion.
Appropriate uses
Section titled “Appropriate uses”- Identify missing facts.
- Summarise evidence gaps.
- Draft interview questions.
- Propose evidence requests.
- Draft a bounded test.
- Compare Current and Target Profiles.
- Identify monitoring signals.
- Draft an assessor narrative for review.
Inappropriate uses
Section titled “Inappropriate uses”- Automatic Profile completion.
- Automatic evidence acceptance.
- Autonomous risk acceptance.
- Legal or certification claims.
- Production testing without authorisation.
- Replacing qualified domain expertise.