NIST AI RMF playbook diagnostic

How ready is your organisation to manage AI risks under the NIST AI RMF?

For leaders putting AI to work, this diagnostic shows how ready your organisation is to govern, map, measure and manage AI risks in line with the NIST AI Risk Management Framework. It builds a structured, shared view across the four core functions that decide whether AI is used safely and responsibly — how you govern accountability and culture, how you map context and risks, how you measure trustworthiness, and how you manage and respond when things go wrong.

Who this diagnostic is for

This diagnostic is built for the people who own AI risk across an organisation: executive leaders, and the heads of risk, compliance, technology, data and analytics, and legal. It suits any organisation that is building, buying or overseeing AI systems and wants a shared, honest view of how ready it really is, rather than each function holding a different opinion.

The problem it addresses

Most organisations are adopting AI faster than they are building the controls around it. Responsibility for AI risk is often unclear, oversight of third-party models and data is patchy, and leaders lack a shared picture of where governance, testing and response plans fall short. Security and compliance checks built for traditional software were never designed for how AI systems learn, drift and fail, so real exposure stays hidden until an incident, a regulator or an affected group forces it into the open.

What it assesses — 4 capability groups, 19 capabilities

The diagnostic mirrors the four core functions of the NIST AI Risk Management Framework — Govern, Map, Measure and Manage — expanded into 19 named capabilities. You respond to structured statements for each capability, so the results show exactly where your organisation is strong and where the gaps sit.

Govern AI Risk and Accountability

This group covers how your organisation sets the tone and rules for using AI safely. It brings together the policies, roles, skills, culture, and outside relationships that make sure AI risks are owned by someone, understood widely, and handled consistently. Strong governance means everyone knows what is expected and who is responsible.

  • AI Risk Policies and Procedures
  • Clear Roles and Accountability Structures
  • Diverse and Skilled AI Workforce
  • Risk-Aware Organisational Culture
  • Engagement with Affected People and Communities
  • Third-Party and Supply Chain Oversight

Without governance, AI risks go unowned and spiral unchecked.

Map AI Context and Risks

This group covers understanding an AI system fully before you trust it. It means knowing why the system exists, what kind of system it is, what it can really do, where risks live across its parts, and how it could affect people and society. Good mapping turns hidden assumptions into clear, shared knowledge.

  • Establish AI System Context
  • Categorise the AI System
  • Understand AI Capabilities and Goals
  • Map Risks Across AI Components
  • Assess Impacts on People and Society

Without mapping, hidden AI risks surface only after harm.

Measure AI Trustworthiness and Performance

This group covers testing whether AI systems really are safe and working well. It means choosing measures that reflect real risks, evaluating systems for fairness, safety, security, and reliability, tracking risks after launch as things change, and checking that your measurement itself still works. Good measurement replaces hope and hype with evidence.

  • Choose Measurement Methods and Metrics
  • Evaluate Trustworthy AI Characteristics
  • Track AI Risks Over Time
  • Gather Feedback on Measurement Effectiveness

Without measurement, unsafe AI passes as working fine.

Manage and Respond to AI Risks

This group covers acting on AI risks and being ready when things go wrong. It means prioritising and responding to the risks that matter most, balancing benefits against harms, managing the suppliers you depend on, and having tested plans to contain, recover from, and communicate about failures. Good management turns knowledge of risk into protection.

  • Prioritise and Respond to Risks
  • Maximise Benefits and Minimise Harms
  • Manage Third-Party AI Risks
  • Plan Response, Recovery, and Communication

Without management, known AI risks turn into real harm.

The assessment is structured around the four functions and 19 capabilities of the NIST AI Risk Management Framework, so every question maps to a recognised, published capability area rather than an ad-hoc checklist.

What you get and how it works

What you get

  • Live dashboard scored across all 19 capabilities
  • Blind spots and weaknesses flagged explicitly
  • Prioritised recommendations across technology, training, process, talent and outsourcing
  • Unlimited re-runs to track progress over time
  • Shared team consensus view to compare perspectives

How it works

  1. 1 Complete the structured assessment. Respond to clear statements across the 19 capabilities — there is nothing to prepare, and you can pause and return at any time.
  2. 2 See your strengths and gaps. The moment you finish, your dashboard highlights where you are strong and where blind spots and weaknesses are holding you back.
  3. 3 Prioritise practical action. Work through prioritised recommendations for the areas that matter most, then re-run the assessment to measure how far you have moved.

Organisations typically use the results to build leadership alignment on AI risk, sequence improvements sensibly, strengthen governance, data, skills, decision ownership and response planning, and create a baseline they can reassess against over time.

Playbook Usage Scenarios

The following examples illustrate typical situations where organisations use this playbook. They are intended to show when the assessment is most valuable and how it can help leadership teams identify capability gaps, build consensus, and prioritise improvement initiatives.

A Chief Risk Officer at a multi-division financial services organisation

Business challenge: The organisation is rolling out AI across lending, servicing and fraud detection, but responsibility for AI risk is split and unclear. The board is asking for assurance, third-party models are in use without consistent oversight, and different divisions hold very different views of how ready they are.

How SuccessOf.ai and the playbook are used: The Chief Risk Officer runs the diagnostic with a cross-functional leadership group spanning risk, technology, data and analytics, compliance and legal. Working through Govern AI Risk and Accountability, Map AI Context and Risks, Measure AI Trustworthiness and Performance, and Manage and Respond to AI Risks, the team creates a common structure, compares perspectives and establishes a shared view of where capability weaknesses are constraining safe AI adoption.

Beneficial result: The leadership team leaves with a clearer, shared picture of where accountability, third-party oversight and testing are weakest, better sequencing of the improvements that matter most, and a baseline they can reassess against as their AI programme grows.

A Chief Technology Officer at a growing healthcare provider

Business challenge: Clinical and operational teams are keen to use generative AI, but use cases are unclear, data is fragmented across systems, and there are real concerns about responsible AI, weak governance and gaps in AI skills. Leaders disagree on whether the organisation is ready to scale.

How SuccessOf.ai and the playbook are used: The Chief Technology Officer invites a cross-functional group — including clinical leadership, data, information governance and operations — to complete the assessment independently, then reviews the consensus view. Using the named capability groups, the team identifies strengths and gaps, understands where weaknesses in governance, data and skills are constraining progress, and prioritises the areas that need leadership attention first.

Beneficial result: The group gains improved alignment on where it is genuinely ready and where it is not, a more deliberate approach to prioritising governance, data and skills, and stronger preparedness before scaling AI initiatives further.

Frequently asked questions

What does the NIST AI RMF readiness diagnostic assess? +

It assesses how ready your organisation is across the four core functions of the NIST AI Risk Management Framework — Govern, Map, Measure and Manage — broken into 19 named capabilities covering AI policies, accountability, context, testing, monitoring and incident response.

Who should take part in the assessment? +

It is designed for executive leaders and the heads of risk, compliance, technology, data and analytics, and legal. Because AI risk crosses functions, the most useful results come when several of these leaders respond and compare their views.

How long does it take, and can we run it more than once? +

You complete it at your own pace in a single sitting, and you can re-run it as often as you like at no extra cost to track how your AI risk capabilities improve over time.

Is this a substitute for legal or regulatory advice? +

No. It is a structured self-assessment that shows where your AI risk capabilities are strong or weak against the NIST AI RMF. It does not provide legal, regulatory or compliance advice, and it does not certify compliance.

Can our leadership team complete it together? +

Yes. Colleagues can respond independently and view a shared consensus dashboard that shows where your team agrees on AI readiness and where perceptions of it differ.

See where your AI risk gaps are — and what to fix first.

Start the readiness diagnostic