Skip to content

Outcomes, assurance and conclusions

Gamut separates what outcome is achieved from how strongly that conclusion is supported. This prevents a documented policy from being mistaken for operating effectiveness.

No defensible determination has been made.

Use when:

  • The outcome has not been reviewed.
  • Required context is missing.
  • Ownership is unresolved.
  • Evidence is unavailable.

Do not use it as a neutral or low-risk answer.

The outcome is absent or materially ineffective for the selected system.

Examples:

  • No responsible owner exists.
  • Required practice is not implemented.
  • A control is routinely bypassed.
  • A test shows the practice fails its objective.

Some elements operate, but material gaps remain.

Examples:

  • Policy and ownership exist, but execution is inconsistent.
  • The practice covers development but not production.
  • Evidence covers only part of the system boundary.
  • Monitoring exists but lacks response thresholds.
  • A supplier process is incomplete.

The outcome operates for the selected system and is sufficiently supported.

An Achieved label should be consistent with:

  • Clear ownership.
  • Appropriate design.
  • Current implementation.
  • System-specific operating evidence.
  • Effective testing or evaluation where relevant.
  • No unresolved adverse finding that contradicts the claim.
DepthLabelMeaning
0UnverifiedAssertion only; no system-specific evidence has been reviewed.
1DocumentedDesign documentation and accountable ownership have been reviewed.
2ImplementedSystem-specific operating evidence demonstrates implementation.
3AssuredOperating evidence, effective testing and adverse-finding review support the conclusion.

Assurance depth does not replace the outcome.

Examples:

Current outcomeDepthInterpretation
Partially achieved2The assessor has evidence that the partial implementation operates as described.
Achieved1The outcome is asserted from design documentation but is not yet strongly assured.
Not achieved3Strong evidence and testing confirm a real gap.
Achieved3The strongest supported positive conclusion.

The Target Profile records the intended future state:

  • Not achieved.
  • Partially achieved.
  • Achieved.

Most material risk-management outcomes will target Achieved, but the target should still be contextual and accountable. A lower target requires a clear reason, risk decision and review trigger.

Baseline, Priority and Enhanced describe assessment emphasis. They do not alter Current or Target outcomes and are not NIST terms.

Confirmation means an authorised human has reviewed the system-specific Profile and conclusion.

A confirmable assessment should:

  • Consider all 72 Core outcomes.
  • Set a Current and Target outcome.
  • Explain material gaps.
  • Support Achieved claims with strong assurance.
  • Reflect failed tests and open findings.
  • Identify owner, confidence, residual risk, review date and triggers.

Confirmation does not mean:

  • NIST certification.
  • Legal compliance.
  • Risk elimination.
  • Permanent approval.
  • External audit opinion.

The accountable person responsible for the conclusion and follow-up.

How reliable and complete the assessment basis is:

  • Low.
  • Medium.
  • High.

Confidence does not change the Current Profile. It explains uncertainty.

The remaining risk after current practices, limitations, evidence and treatment are considered.

Gamut uses:

  • Low.
  • Moderate.
  • Elevated.
  • High.
  • Critical.

Residual risk is not the same as an outcome completion percentage.

The date by which the Profile should be reviewed even if no trigger occurs.

Material events that require earlier review, such as:

  • Model or supplier change.
  • New data.
  • Increased autonomy.
  • New geography or user group.
  • Incident or complaint.
  • Performance drift.
  • Change to purpose or human oversight.

A concise narrative connecting:

  • Scope.
  • Current and Target Profiles.
  • Material evidence.
  • Important gaps.
  • Residual risk.
  • Treatment.
  • Constraints.
  • Monitoring.
  • Decision.

The selected system has a substantially achieved Current Profile across the assessed NIST AI RMF Core, with the stated positive outcomes supported by current operating evidence and testing. Remaining gaps, residual risk and reassessment triggers are recorded below. This is the organisation’s risk-management conclusion, not NIST certification.

The Current Profile is partially achieved. Governance foundations are documented, but material gaps remain in system-specific measurement, supplier assurance and post-deployment monitoring. The Target Profile and treatment plan identify the required improvements before broader use.

A reliable Current Profile cannot yet be concluded because system context, operating evidence and test results are incomplete. The assessment remains open and no positive alignment claim should be made until the identified evidence requests are resolved.

  • “NIST certified.”
  • “NIST compliant.”
  • “100% safe.”
  • “No risk remains.”
  • “The policy proves implementation.”
  • “The AI confirmed the assessment.”
  • “Mapped controls automatically satisfy the outcome.”