NIST AI RMF Self-Assessment Workbook
A structured Excel workbook covering all 72 NIST AI RMF subcategories with 0–5 maturity scoring, evidence tracking, action planning, and an automated summary dashboard. Assess your organization’s AI risk management maturity across Govern, Map, Measure, and Manage.
- ✓Fully editable Excel .xlsx. customize for your organization
- ✓5 worksheets: Assessment (72 subcategories), Evidence Repository, Action Plan, Summary Dashboard, and Instructions
- ✓Aligned to 3 frameworks: NIST AI RMF, EU AI Act, ISO 42001
- ✓0–5 maturity scoring with conditional formatting. Red/amber/green visual heat mapping
- ✓Dropdown validations for status, priority, evidence type, and maturity scores
- ✓Updated Q2 2026. 348 pre-mapped evidence entries linked to all 72 subcategories
The NIST AI Risk Management Framework defines 72 subcategories across four functions, Govern, Map, Measure, and Manage. That organizations should address when deploying AI systems. Most teams assess their maturity against these subcategories using ad-hoc spreadsheets that drift out of alignment with the standard, lack structured evidence tracking, and produce dashboards that require manual aggregation.
This workbook provides a complete, structured self-assessment tool pre-populated with all 72 subcategories, their descriptions, and cross-mappings to ISO 42001 and EU AI Act. Each subcategory has a 0–5 maturity score with conditional formatting that visually maps your readiness: red for critical gaps (0–1), amber for developing areas (2–3), and green for strong maturity (4–5). The Evidence Repository links 348 pre-mapped entries to specific subcategories, and the Action Plan tracks remediation with priority and status fields.
The Summary Dashboard auto-calculates from the Assessment tab. Maturity averages by function, status distribution, evidence coverage, and priority metrics. No manual formula maintenance required. Worked examples are included on every tracker to show the expected data format and scoring approach.
Already running NIST AI RMF assessments? Use the cross-mapping columns to identify ISO 42001 and EU AI Act coverage gaps you may not be tracking.
I’ve been building governance documentation since 2012. That year I helped my healthcare analytics company earn its first HITRUST certification. Since then I’ve created and managed compliance documentation for SOC 2, PCI DSS, HITRUST, and ISO 27001 programs across enterprise organizations. I have a writing degree and I genuinely like this work.
Credentials don’t explain the price though. This does:
You’re building something that matters. An assessment process that earns trust from your board, your customers, and your team. And it has to work.
The citations in these templates were checked against the published standards. The actual ISO 42001:2023 PDF, the EU AI Act regulation text, the NIST AI RMF 1.0 document. Control IDs, article numbers, framework mappings. This is practitioner-built tooling from someone who’s sat in the audits, written the remediation plans, and knows what survives a compliance review.
0–5 maturity scoring
348 evidence entries
Conditional formatting
Summary dashboard
Instant download
This tool is a starting point, not a finished product. It’s designed to accelerate your NIST AI RMF self-assessment by giving you a professionally structured foundation with verified subcategory descriptions and cross-framework mappings. It doesn’t replace legal counsel, compliance review, or organizational judgment. Every organization is different. You’ll need to customize the maturity scores, evidence entries, and action plans for your specific regulatory context, risk tolerance, and operational environment. We recommend routing your completed assessment through your legal, compliance, and governance teams before adoption. What you’re buying is a jumpstart that saves you weeks of research and spreadsheet building, not a guarantee of compliance. Framework citations reflect standards as of Q2 2026. Regulatory frameworks evolve. Check for updates to the NIST AI RMF, ISO 42001, and EU AI Act before your annual assessment review. Single organization license. All purchases include a 14-day money-back guarantee. If the tool does not meet your needs, contact us for a full refund.
Author