Agent skill · Business & Finance

nist-ai-rmf

Expert NIST AI Risk Management Framework (AI RMF 1.0) advisor covering all four functions: GOVERN, MAP, MEASURE, MANAGE. Use this skill whenever a user asks about NIST AI RMF, AI risk management, AI trustworthiness, GOVERN function, MAP function, MEASURE function, MANAGE function, AI RMF Playbook, AI risk profiles, responsible AI, AI bias management, AI transparency, AI explainability, AI reliability, AI safety, NIST AI 100-1, AI risk assessment, AI incident response, or alignment to EU AI Act, ISO 42001, or NIST CSF via AI RMF. Trigger even if the user doesn't say \"skill\" — any NIST AI RMF

lawve-aigithub.com/lawve-aiGitHub ↗
claude-codeNOASSERTION
Install
npx skills add lawve-ai/awesome-legal-skills --skill nist-ai-rmf-tanaji-hemant-naik --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 5
SKILL.md size: 29 KB
Bundled scripts: none
Path: skills/nist-ai-rmf-tanaji-hemant-naik/SKILL.md
Open the folder on GitHub →
Where it comes from
Stars: 618
Language: Python

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

Review
written from the skill's own SKILL.md · Aug 5, 2026

What it does

The skill functions as an expert advisor on the NIST AI Risk Management Framework (AI RMF 1.0). It is intended to help organizations identify, assess, and manage risks across the AI lifecycle (design through decommission) by applying the four core functions: GOVERN, MAP, MEASURE, and MANAGE, with emphasis on trustworthiness characteristics and alignment to related standards. The output format emphasizes task-type tailored deliverables (organizational profiles, action plans, policy drafts, risk registers, cross-framework mappings, or general questions) and requires citing specific function+category+subcategory (e.g., GOVERN 1.1, MAP 4.2, MEASURE 2.3). It also instructs that outputs should reflect the AI RMF Playbook for suggested actions and that risk registers should include third-party/vendor-model dependency as a dedicated row. It notes that the AI RMF is voluntary, outcome-based, and not a compliance checklist, and that all seven trustworthiness characteristics inform risk assessment across functions. The skill explicitly references the companion Playbook structure mirrored in references/rmf-core.md for concrete next steps.

How it works

  • It positions itself as an expert advisor on AI RMF 1.0 and the companion Playbook.
  • It requires responses to be formatted according to task type, with outputs tied to specific framework categories (e.g., GOVERN 1.1, MAP 4.2, MEASURE 2.3).
  • It mandates including the seven trustworthiness characteristics as a framing device for risk assessment and evaluation across outputs.
  • It instructs that risk registers must include a dedicated third-party/vendor-model dependency row as a first-class risk.
  • It provides a structured approach for different tasks (organizational profiles, action plans, policy drafts, risk registers, cross-framework mappings, general questions).
  • It references the AI RMF Playbook as the source of suggested actions and requires adherence to its structure for concrete steps.

When to use it

Use this skill whenever questions involve NIST AI RMF, AI risk management, AI trustworthiness, GOVERN/MAP/MEASURE/MANAGE functions, AI RMF Playbook, AI risk profiles, responsible AI, bias management, transparency, explainability, reliability, safety, AI risk assessment, incident response, or alignment to EU AI Act, ISO 42001, or NIST CSF via AI RMF. Trigger even if the user doesn’t say 'skill'.

What it can touch

The skill declares tools: "claude-code". It instructs outputs to cite specific function+category+subcategory and to align with the Playbook’s suggested actions.

Caveats

  • The AI RMF is described as voluntary and non-prescriptive, not a compliance checklist.
  • Outputs must be framed around the four core functions and seven trustworthiness characteristics.
  • Third-party/vendor-model dependency must be included as a risk entry in risk registers.
  • Any policy or action recommendations should be grounded in the explicit categories/subcategories and the Playbook guidance; no speculative claims beyond stated framework content.
From the SKILL.md

# NIST AI Risk Management Framework (AI RMF 1.0) Skill > **Last verified:** 2026-07-03 You are an expert advisor on the **NIST AI Risk Management Framework (AI RMF 1.0)**, published January 2023 as NIST AI 100-1. You help organizations identify, assess, and manage risks throughout the AI lifecycle — from design through deployment and decommission. The AI RMF is **voluntary and non-prescriptive**. It provides a structured, outcome-based approach applicable to any organization designing, developing, deploying, or evaluating AI systems. --- ## How to Respond Match your output to the task type: | Task | Output Format | |------|--------------| | Organizational profile / current state | Table: Function → Category → Status (🔴/🟡/🟢) → Gap Notes | | Action planning | Table: Category → Suggested Actions → Owner → Priority | | Policy drafting | Full structured document with section headers and purpose statement | | Risk register | Table: Risk ID | AI System | Lifecycle Stage | TEVV Activity | Characteristic at Risk | Likelihood/Impact | Treatment | Owner | | Cross-framework mapping | Side-by-side comparison table | | General question | Clear concise prose with specific AI RMF category citat

What's inside
Steps it walks through
  1. How to Respond
  2. AI RMF Structure Overview
  3. The Four Core Functions
  4. GOVERN — Organizational Accountability (6 categories, ~21 subcategories)
  5. MAP — Risk Identification (5 categories, ~20 subcategories)
  6. MEASURE — Risk Analysis (4 categories, ~16 subcategories)
  7. MANAGE — Risk Response (4 categories, ~18 subcategories)
  8. The Seven Trustworthiness Characteristics
  9. AI Risk Register Template
  10. Common Workflows
  11. 1. GOVERN Gap Assessment
  12. 2. Hiring / Employment AI Risk Assessment
  13. 3. Credit Scoring Risk Register
  14. 4. Incident Response (MANAGE 3)
Ships with 4 files
  • LICENSE
  • README.md
  • references/rmf-core.md
  • references/rmf-profiles.md
More from awesome-legal-skills
All skills →
About this skill
What does the nist-ai-rmf skill do?

Expert NIST AI Risk Management Framework (AI RMF 1.0) advisor covering all four functions: GOVERN, MAP, MEASURE, MANAGE. Use this skill whenever a user asks about NIST AI RMF, AI risk management, AI trustworthiness, GOVERN function, MAP function, MEASURE function, MANAGE function, AI RMF Playbook, AI risk profiles, responsible AI, AI bias management, AI transparency, AI explainability, AI reliability, AI safety, NIST AI 100-1, AI risk assessment, AI incident response, or alignment to EU AI Act, ISO 42001, or NIST CSF via AI RMF. Trigger even if the user doesn't say \"skill\" — any NIST AI RMF

How do I install it?

Run `npx skills add lawve-ai/awesome-legal-skills --skill nist-ai-rmf-tanaji-hemant-naik --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From lawve-ai/awesome-legal-skills, a repository with 618 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going