Agent skill · Business & Finance

nist-ai-rmf

Expert NIST AI Risk Management Framework (AI RMF 1.0) advisor covering all four NIST AI RMF, AI risk management, AI trustworthiness, GOVERN function, MAP function, MEASURE function, MANAGE function, AI RMF Playbook, AI risk profiles, responsible AI, AI bias management, AI transparency, AI explainability, AI reliability, AI safety, NIST AI 100-1, AI risk assessment, AI incident response, or alignment to EU AI Act, ISO 42001, or NIST CSF via AI RMF. Trigger even if the user doesn't say "skill" — any NIST AI RMF or AI governance risk question should use this skill.

Sushegaadgithub.com/SushegaadGitHub ↗
claude-codeMIT
Install
npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nist-ai-rmf --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 3
SKILL.md size: 29 KB
Bundled scripts: none
Path: plugins/nist-ai-rmf/skills/nist-ai-rmf/SKILL.md
Open the folder on GitHub →
Where it comes from
Stars: 801
Language: HTML

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

Review
written from the skill's own SKILL.md · Aug 5, 2026

What it does

The skill acts as an expert advisor on the NIST AI Risk Management Framework (AI RMF 1.0). It helps identify, assess, and manage risks across the AI lifecycle, covering all four core functions (GOVERN, MAP, MEASURE, MANAGE) and related topics such as AI risk, trustworthiness, and alignment to other standards. It emphasizes that AI RMF is voluntary, outcome-based, not a compliance checklist, and points to the AI RMF Playbook for suggested actions. It requires citing specific function + category + subcategory (e.g., GOVERN 1.1, MAP 4.1, MEASURE 2.3, or MANAGE 3.2) for stakeholder communications and decision-making.

How it works

  • Responds to general questions or task types by producing outputs aligned to the requested format (organizational profile, action plan, policy draft, risk register, cross-framework mapping, or general question).
  • Requires citations to the framework text in the form of function + category + subcategory for every recommendation or conclusion.
  • Includes an output structure that mirrors the framework: MEASURE, MAP, GOVERN, MANAGE, and related subcategories, with explicit organizational activities tied to each subcategory (e.g., MAP 1.1, MEASURE 2.4).
  • References the companion AI RMF Playbook in its guidance and notes that the Playbook provides suggested actions for each category and subcategory.

When to use it

Use this skill for any inquiry about NIST AI RMF or AI governance risk, including risk management, trustworthiness, and alignment to other standards (EU AI Act, ISO 42001, NIST CSF). Trigger even if the user doesn’t say "skill".

What it can touch

  • Employs the tool set and structure of the AI RMF (GOVERN, MAP, MEASURE, MANAGE) with explicit subcategory references.
  • Requires constructing outputs that cite specific function + category + subcategory in every guidance piece.

Caveats

  • The AI RMF is voluntary and non-prescriptive; outputs should be framed as guidance rather than mandatory rules.
  • The Playbook provides suggested actions rather than automatic prescriptions; outcomes depend on organizational context.
  • The seven trustworthiness characteristics are used as risk lenses when assessing AI systems, with attention to corresponding assessment questions.
From the SKILL.md

# NIST AI Risk Management Framework (AI RMF 1.0) Skill > **Last verified:** 2026-07-03 You are an expert advisor on the **NIST AI Risk Management Framework (AI RMF 1.0)**, published January 2023 as NIST AI 100-1. You help organizations identify, assess, and manage risks throughout the AI lifecycle — from design through deployment and decommission. The AI RMF is **voluntary and non-prescriptive**. It provides a structured, outcome-based approach applicable to any organization designing, developing, deploying, or evaluating AI systems. --- ## How to Respond Match your output to the task type: | Task | Output Format | |------|--------------| | Organizational profile / current state | Table: Function → Category → Status (🔴/🟡/🟢) → Gap Notes | | Action planning | Table: Category → Suggested Actions → Owner → Priority | | Policy drafting | Full structured document with section headers and purpose statement | | Risk register | Table: Risk ID | AI System | Lifecycle Stage | TEVV Activity | Characteristic at Risk | Likelihood/Impact | Treatment | Owner | | Cross-framework mapping | Side-by-side comparison table | | General question | Clear concise prose with specific AI RMF category citat

What's inside
Steps it walks through
  1. How to Respond
  2. AI RMF Structure Overview
  3. The Four Core Functions
  4. GOVERN — Organizational Accountability (6 categories, ~21 subcategories)
  5. MAP — Risk Identification (5 categories, ~20 subcategories)
  6. MEASURE — Risk Analysis (4 categories, ~16 subcategories)
  7. MANAGE — Risk Response (4 categories, ~18 subcategories)
  8. The Seven Trustworthiness Characteristics
  9. AI Risk Register Template
  10. Common Workflows
  11. 1. GOVERN Gap Assessment
  12. 2. Hiring / Employment AI Risk Assessment
  13. 3. Credit Scoring Risk Register
  14. 4. Incident Response (MANAGE 3)
Ships with 2 files
  • references/rmf-core.md
  • references/rmf-profiles.md
More from Claude-Skills-Governance-Risk-and-Compliance
All skills →
About this skill
What does the nist-ai-rmf skill do?

Expert NIST AI Risk Management Framework (AI RMF 1.0) advisor covering all four NIST AI RMF, AI risk management, AI trustworthiness, GOVERN function, MAP function, MEASURE function, MANAGE function, AI RMF Playbook, AI risk profiles, responsible AI, AI bias management, AI transparency, AI explainability, AI reliability, AI safety, NIST AI 100-1, AI risk assessment, AI incident response, or alignment to EU AI Act, ISO 42001, or NIST CSF via AI RMF. Trigger even if the user doesn't say "skill" — any NIST AI RMF or AI governance risk question should use this skill.

How do I install it?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill nist-ai-rmf --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, a repository with 801 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going