AI is changing how businesses operate. Make sure you're managing the risks that come with it.
The InfoPathways NIST AI Risk Management Assessment gives executives and business owners a clear picture of how prepared their organization is to identify, measure, and manage AI-related risks. Based on the NIST AI Risk Management Framework (AI RMF 1.0), the assessment evaluates your approach to AI governance, risk identification, trustworthiness, monitoring, and risk management
Section 1 of 7
NIST AI Risk Management Assessment
This assessment evaluates your organization's AI risk management capabilities based on the NIST AI Risk Management Framework (AI RMF 1.0).
You will be asked about your governance, mapping, measurement, and management practices for AI systems in your organization.
Estimated time: 10-15 minutes
Govern - Policy & Oversight
1. Are AI risk management policies and accountability structures established in your organization?
2. Are roles and responsibilities for AI risk management clearly defined in your organization?
3. Does your organizational culture support critical thinking and questioning about AI risks?
4. Do you prioritize workforce diversity and provide AI risk training to relevant personnel?
5. Do processes exist for AI system decommissioning and incident response?
Govern - Legal & Compliance
6. Are legal and regulatory requirements involving AI understood and actively managed?
7. Are third-party AI risks (vendors, data sources, models) addressed in your policies?
Map - Context Establishment
8. Is the intended purpose, context, and goals of your AI system documented?
9. Are stakeholders and their needs/risk tolerance identified for your AI systems?
10. Are potential benefits and costs of AI systems mapped and documented?
Map - Categorization & Risk Identification
11. Is your AI system appropriately categorized by capabilities, data, and use case?
12. Are risks and potential impacts to individuals, groups, and society identified?
13. Are human oversight roles and capabilities defined for your AI systems?
Measure - Risk Analysis
14. Are appropriate methods and metrics identified for measuring AI risks?
15. Is your AI system evaluated against trustworthiness characteristics (valid, reliable, safe, secure, accountable, explainable, privacy-enhanced, fair)?
16. Is your AI system evaluated for bias, fairness, and disparate impact?
Measure - Monitoring
17. Do mechanisms exist to track identified AI risks over time?
18. Is feedback from affected individuals and communities gathered and incorporated?
Manage - Risk Management & Monitoring
19. Are AI risks prioritized based on impact assessment?
20. Are risk treatment plans (mitigate, transfer, avoid, accept) documented?
21. Are adequate resources allocated to manage identified AI risks?
22. Do mechanisms exist to supersede, disengage, or deactivate AI systems that demonstrate harm?
23. Are incident response plans specific to AI system failures tested and validated?
24. Are third-party AI components and supply chain risks monitored?
Almost Done!
Please enter your information below to receive your results via email.
Assessment Complete
Your detailed results and AI risk remediation recommendations have been sent to . Check your inbox for your full results report.