nist-ai-rmf
Expert NIST AI Risk Management Framework (AI RMF 1.0) advisor covering all four NIST AI RMF, AI risk management, AI trustworthiness, GOVERN function, MAP function, MEASURE function, MANAGE function, AI RMF Playbook, AI risk profiles, responsible AI, AI bias management, AI transparency, AI explainability, AI reliability, AI safety, NIST AI 100-1, AI risk assessment, AI incident response, or alignment to EU AI Act, ISO 42001, or NIST CSF via AI RMF. Trigger even if the user doesn't say "skill" — any NIST AI RMF or AI governance risk question should use this skill.
npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nist-ai-rmf --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
What it does
The skill acts as an expert advisor on the NIST AI Risk Management Framework (AI RMF 1.0). It helps identify, assess, and manage risks across the AI lifecycle, covering all four core functions (GOVERN, MAP, MEASURE, MANAGE) and related topics such as AI risk, trustworthiness, and alignment to other standards. It emphasizes that AI RMF is voluntary, outcome-based, not a compliance checklist, and points to the AI RMF Playbook for suggested actions. It requires citing specific function + category + subcategory (e.g., GOVERN 1.1, MAP 4.1, MEASURE 2.3, or MANAGE 3.2) for stakeholder communications and decision-making.
How it works
- Responds to general questions or task types by producing outputs aligned to the requested format (organizational profile, action plan, policy draft, risk register, cross-framework mapping, or general question).
- Requires citations to the framework text in the form of function + category + subcategory for every recommendation or conclusion.
- Includes an output structure that mirrors the framework: MEASURE, MAP, GOVERN, MANAGE, and related subcategories, with explicit organizational activities tied to each subcategory (e.g., MAP 1.1, MEASURE 2.4).
- References the companion AI RMF Playbook in its guidance and notes that the Playbook provides suggested actions for each category and subcategory.
When to use it
Use this skill for any inquiry about NIST AI RMF or AI governance risk, including risk management, trustworthiness, and alignment to other standards (EU AI Act, ISO 42001, NIST CSF). Trigger even if the user doesn’t say "skill".
What it can touch
- Employs the tool set and structure of the AI RMF (GOVERN, MAP, MEASURE, MANAGE) with explicit subcategory references.
- Requires constructing outputs that cite specific function + category + subcategory in every guidance piece.
Caveats
- The AI RMF is voluntary and non-prescriptive; outputs should be framed as guidance rather than mandatory rules.
- The Playbook provides suggested actions rather than automatic prescriptions; outcomes depend on organizational context.
- The seven trustworthiness characteristics are used as risk lenses when assessing AI systems, with attention to corresponding assessment questions.
# NIST AI Risk Management Framework (AI RMF 1.0) Skill > **Last verified:** 2026-07-03 You are an expert advisor on the **NIST AI Risk Management Framework (AI RMF 1.0)**, published January 2023 as NIST AI 100-1. You help organizations identify, assess, and manage risks throughout the AI lifecycle — from design through deployment and decommission. The AI RMF is **voluntary and non-prescriptive**. It provides a structured, outcome-based approach applicable to any organization designing, developing, deploying, or evaluating AI systems. --- ## How to Respond Match your output to the task type: | Task | Output Format | |------|--------------| | Organizational profile / current state | Table: Function → Category → Status (🔴/🟡/🟢) → Gap Notes | | Action planning | Table: Category → Suggested Actions → Owner → Priority | | Policy drafting | Full structured document with section headers and purpose statement | | Risk register | Table: Risk ID | AI System | Lifecycle Stage | TEVV Activity | Characteristic at Risk | Likelihood/Impact | Treatment | Owner | | Cross-framework mapping | Side-by-side comparison table | | General question | Clear concise prose with specific AI RMF category citat
- How to Respond
- AI RMF Structure Overview
- The Four Core Functions
- GOVERN — Organizational Accountability (6 categories, ~21 subcategories)
- MAP — Risk Identification (5 categories, ~20 subcategories)
- MEASURE — Risk Analysis (4 categories, ~16 subcategories)
- MANAGE — Risk Response (4 categories, ~18 subcategories)
- The Seven Trustworthiness Characteristics
- AI Risk Register Template
- Common Workflows
- 1. GOVERN Gap Assessment
- 2. Hiring / Employment AI Risk Assessment
- 3. Credit Scoring Risk Register
- 4. Incident Response (MANAGE 3)
What does the nist-ai-rmf skill do?
Expert NIST AI Risk Management Framework (AI RMF 1.0) advisor covering all four NIST AI RMF, AI risk management, AI trustworthiness, GOVERN function, MAP function, MEASURE function, MANAGE function, AI RMF Playbook, AI risk profiles, responsible AI, AI bias management, AI transparency, AI explainability, AI reliability, AI safety, NIST AI 100-1, AI risk assessment, AI incident response, or alignment to EU AI Act, ISO 42001, or NIST CSF via AI RMF. Trigger even if the user doesn't say "skill" — any NIST AI RMF or AI governance risk question should use this skill.
How do I install it?
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nist-ai-rmf --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, a repository with 801 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.
