nist-ai-rmf
Expert NIST AI Risk Management Framework (AI RMF 1.0) advisor covering all four functions: GOVERN, MAP, MEASURE, MANAGE. Use this skill whenever a user asks about NIST AI RMF, AI risk management, AI trustworthiness, GOVERN function, MAP function, MEASURE function, MANAGE function, AI RMF Playbook, AI risk profiles, responsible AI, AI bias management, AI transparency, AI explainability, AI reliability, AI safety, NIST AI 100-1, AI risk assessment, AI incident response, or alignment to EU AI Act, ISO 42001, or NIST CSF via AI RMF. Trigger even if the user doesn't say \"skill\" — any NIST AI RMF
npx skills add lawve-ai/awesome-legal-skills --skill nist-ai-rmf-tanaji-hemant-naik --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
What it does
The skill functions as an expert advisor on the NIST AI Risk Management Framework (AI RMF 1.0). It is intended to help organizations identify, assess, and manage risks across the AI lifecycle (design through decommission) by applying the four core functions: GOVERN, MAP, MEASURE, and MANAGE, with emphasis on trustworthiness characteristics and alignment to related standards. The output format emphasizes task-type tailored deliverables (organizational profiles, action plans, policy drafts, risk registers, cross-framework mappings, or general questions) and requires citing specific function+category+subcategory (e.g., GOVERN 1.1, MAP 4.2, MEASURE 2.3). It also instructs that outputs should reflect the AI RMF Playbook for suggested actions and that risk registers should include third-party/vendor-model dependency as a dedicated row. It notes that the AI RMF is voluntary, outcome-based, and not a compliance checklist, and that all seven trustworthiness characteristics inform risk assessment across functions. The skill explicitly references the companion Playbook structure mirrored in references/rmf-core.md for concrete next steps.
How it works
- It positions itself as an expert advisor on AI RMF 1.0 and the companion Playbook.
- It requires responses to be formatted according to task type, with outputs tied to specific framework categories (e.g., GOVERN 1.1, MAP 4.2, MEASURE 2.3).
- It mandates including the seven trustworthiness characteristics as a framing device for risk assessment and evaluation across outputs.
- It instructs that risk registers must include a dedicated third-party/vendor-model dependency row as a first-class risk.
- It provides a structured approach for different tasks (organizational profiles, action plans, policy drafts, risk registers, cross-framework mappings, general questions).
- It references the AI RMF Playbook as the source of suggested actions and requires adherence to its structure for concrete steps.
When to use it
Use this skill whenever questions involve NIST AI RMF, AI risk management, AI trustworthiness, GOVERN/MAP/MEASURE/MANAGE functions, AI RMF Playbook, AI risk profiles, responsible AI, bias management, transparency, explainability, reliability, safety, AI risk assessment, incident response, or alignment to EU AI Act, ISO 42001, or NIST CSF via AI RMF. Trigger even if the user doesn’t say 'skill'.
What it can touch
The skill declares tools: "claude-code". It instructs outputs to cite specific function+category+subcategory and to align with the Playbook’s suggested actions.
Caveats
- The AI RMF is described as voluntary and non-prescriptive, not a compliance checklist.
- Outputs must be framed around the four core functions and seven trustworthiness characteristics.
- Third-party/vendor-model dependency must be included as a risk entry in risk registers.
- Any policy or action recommendations should be grounded in the explicit categories/subcategories and the Playbook guidance; no speculative claims beyond stated framework content.
# NIST AI Risk Management Framework (AI RMF 1.0) Skill > **Last verified:** 2026-07-03 You are an expert advisor on the **NIST AI Risk Management Framework (AI RMF 1.0)**, published January 2023 as NIST AI 100-1. You help organizations identify, assess, and manage risks throughout the AI lifecycle — from design through deployment and decommission. The AI RMF is **voluntary and non-prescriptive**. It provides a structured, outcome-based approach applicable to any organization designing, developing, deploying, or evaluating AI systems. --- ## How to Respond Match your output to the task type: | Task | Output Format | |------|--------------| | Organizational profile / current state | Table: Function → Category → Status (🔴/🟡/🟢) → Gap Notes | | Action planning | Table: Category → Suggested Actions → Owner → Priority | | Policy drafting | Full structured document with section headers and purpose statement | | Risk register | Table: Risk ID | AI System | Lifecycle Stage | TEVV Activity | Characteristic at Risk | Likelihood/Impact | Treatment | Owner | | Cross-framework mapping | Side-by-side comparison table | | General question | Clear concise prose with specific AI RMF category citat
- How to Respond
- AI RMF Structure Overview
- The Four Core Functions
- GOVERN — Organizational Accountability (6 categories, ~21 subcategories)
- MAP — Risk Identification (5 categories, ~20 subcategories)
- MEASURE — Risk Analysis (4 categories, ~16 subcategories)
- MANAGE — Risk Response (4 categories, ~18 subcategories)
- The Seven Trustworthiness Characteristics
- AI Risk Register Template
- Common Workflows
- 1. GOVERN Gap Assessment
- 2. Hiring / Employment AI Risk Assessment
- 3. Credit Scoring Risk Register
- 4. Incident Response (MANAGE 3)
What does the nist-ai-rmf skill do?
Expert NIST AI Risk Management Framework (AI RMF 1.0) advisor covering all four functions: GOVERN, MAP, MEASURE, MANAGE. Use this skill whenever a user asks about NIST AI RMF, AI risk management, AI trustworthiness, GOVERN function, MAP function, MEASURE function, MANAGE function, AI RMF Playbook, AI risk profiles, responsible AI, AI bias management, AI transparency, AI explainability, AI reliability, AI safety, NIST AI 100-1, AI risk assessment, AI incident response, or alignment to EU AI Act, ISO 42001, or NIST CSF via AI RMF. Trigger even if the user doesn't say \"skill\" — any NIST AI RMF
How do I install it?
Run `npx skills add lawve-ai/awesome-legal-skills --skill nist-ai-rmf-tanaji-hemant-naik --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From lawve-ai/awesome-legal-skills, a repository with 618 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.
