Skip to content

Assessment workflow

Choose the registered AI system that is being assessed. Confirm its name, version, purpose, lifecycle stage and deployment context.

Do not begin from an unbounded enterprise assumption when the intended conclusion is system-specific.

Confirm the intake covers:

  • Purpose, users and affected people.
  • Data and model sources.
  • Suppliers and deployment.
  • Human oversight and autonomy.
  • Public-facing or consequential use.
  • Relevant jurisdictions and obligations.
  • Retrieval, tools and integrations.
  • Known risks, limitations and incidents.

Incomplete context should be recorded as uncertainty, not converted into a favourable outcome.

The NIST AI RMF Core is the primary baseline.

For generative AI, also use the Generative AI Profile. Other sector or use-case Profiles may inform tailoring where appropriate and authoritative.

Use Baseline, Priority and Enhanced labels to sequence work. Confirm that the reasons match the system facts.

Priority affects assessment effort; it does not decide the outcome.

A common sequence is:

  1. GOVERN — confirm policy, roles, accountability, culture and supplier governance.
  2. MAP — establish context, purpose, system boundaries, actors, impacts, benefits and risks.
  3. MEASURE — inspect metrics, evaluations, tests, monitoring and stakeholder feedback.
  4. MANAGE — review treatment, proceed decisions, incidents, recovery and continual improvement.

The process is iterative. A MEASURE result may reveal new MAP risks. A MANAGE decision may require new governance or measurement.

For each outcome, use the on-screen guidance to:

  • Understand the outcome being assessed.
  • Ask accountable owners targeted questions.
  • Identify appropriate evidence.
  • Design a bounded test or review.
  • Understand pass criteria.
  • Recognise common failure patterns.
  • Define monitoring and reassessment.

The advisory supports judgement. The official NIST publication remains authoritative.

Choose:

  • Not assessed.
  • Not achieved.
  • Partially achieved.
  • Achieved.

The label must reflect the selected system, not merely an organisation-wide policy.

Separately state whether the conclusion is:

  • Unverified.
  • Documented.
  • Implemented.
  • Assured.

Outcome and assurance answer different questions:

Outcome: what is the current position?

Assurance: how strongly is that position supported?

Choose the intended target for the outcome. Consider:

  • Risk tolerance.
  • Intended use and impact.
  • Legal and contractual duties.
  • Trustworthiness characteristics.
  • Supplier and operating constraints.
  • Stakeholder needs.
  • Proportionality and available resources.

An Achieved target does not mean every Playbook suggestion must be implemented. It means the organisation intends to demonstrate the outcome appropriately for this context.

The note should explain:

  • The system-specific facts.
  • What exists today.
  • What is missing.
  • Evidence inspected.
  • Test result.
  • Owner.
  • Treatment or accepted limitation.
  • Target date or review trigger.

For Not achieved or Partially achieved outcomes, document the gap and treatment direction.

Attach or reference:

  • Approved policies and procedures.
  • System cards and architecture records.
  • Risk and impact assessments.
  • Data and model documentation.
  • Supplier records.
  • Evaluation and monitoring results.
  • Training and oversight records.
  • Incident, appeal and change records.

See Evidence, testing and findings.

Define:

  • Objective.
  • Procedure.
  • Sample and environment.
  • Expected result.
  • Pass criteria.
  • Safety limits.
  • Actual result.
  • Exceptions.
  • Reviewer and date.

Tests should be authorised, proportionate and non-destructive.

Create a finding when:

  • The Current outcome is unsupported.
  • Evidence is missing, stale or rejected.
  • A test fails.
  • Practice differs from policy.
  • Ownership is unclear.
  • A supplier dependency is unresolved.
  • The Target gap creates material exposure.

Check for:

  • Unassessed outcomes.
  • Optimistic Achieved claims.
  • Weak assurance.
  • Contradictions between outcomes.
  • Open adverse findings.
  • Failed tests.
  • Missing supplier or stakeholder evidence.
  • Inconsistent targets.
  • Missing owners or dates.

The conclusion should state:

  • System and boundary.
  • Current Profile position.
  • Material strengths.
  • Material gaps.
  • Evidence and testing limitations.
  • Residual risk.
  • Treatment priorities.
  • Confidence.
  • Review date.
  • Reassessment triggers.
  • Decision owner.

Avoid saying “NIST compliant” or “NIST certified.”

Confirmation is an accountable human statement about the recorded Profile at that time. It is not permanent. Review it after a material change or by the scheduled date.

  • Correct system selected.
  • Context current.
  • All Core outcomes considered.
  • Current and Target outcomes recorded.
  • Outcome and assurance depth are consistent.
  • Achieved claims are evidence-backed.
  • Relevant tests have passed.
  • Findings and adverse evidence are reflected.
  • Generative AI Profile considered where relevant.
  • Human conclusion complete.
  • Reassessment triggers recorded.