This tool helps you assess the risk of a proposed AI use case across six dimensions drawn from the NIST AI Risk Management Framework. Set each slider to match your situation; the risk score, comparison case, and governance recommendations update as you go.
How to use this tool
Describe your use case with the six sliders
Each slider runs from 1 (lowest risk) to 10 (highest risk). As you move one, the text below it describes exactly what that level means and gives a concrete example. Pick the level whose description best matches what you are actually planning — not what you hope to achieve later.
- Scope — how much of the task the AI performs, from a single suggestion to fully autonomous operation.
- Human Oversight — whether and when a person reviews or approves the AI's work.
- Transparency — how visible and auditable the AI's actions and reasoning are.
- Stakes — how much harm an error causes, and how reversible that harm is.
- Bias & Fairness — the risk of discriminatory or inequitable outcomes across groups.
- Privacy — how sensitive the personal data involved is, and what protections are in place.
Read the risk score and the shape of the chart
The score is the average of all six dimensions, banded as Minimal, Low, Moderate, High, or Critical. Pay attention to the shape of the chart, not just the number: a single dimension at 9 is a real problem even when the average looks comfortable. A spike on one axis tells you where to focus mitigation.
Compare against the closest real-world analog
The tool matches your profile against a library of well-understood AI use cases and shows the nearest one, with a similarity percentage. This is a sanity check. If your proposed internal tool lands next to an autonomous fraud-blocking system, that mismatch is worth a conversation before you build anything.
Work through the NIST AI RMF guidance
The panel below the tool maps your profile to the four functions of the NIST AI Risk Management Framework, and its recommendations scale with your score:
- Govern — the policy, ownership, and accountability you need in place.
- Map — the context to document and the stakeholders to identify.
- Measure — the testing, bias audits, and monitoring to perform.
- Manage — the mitigations, escalation paths, and incident response to build.
High scores on individual dimensions add targeted recommendations — elevated privacy risk triggers a Privacy Impact Assessment, elevated bias risk calls for a fairness audit, and so on.
Use it to structure the conversation
The most useful move is to score a use case twice: once as proposed, and once with mitigations applied. Watching the score drop when you add human review or an audit log makes the value of a control concrete, and turns an abstract debate into a specific list of things to change.
About this framework & why to use it
What it measures
Six sliders, each scored from 1 to 10, with ten written levels and a concrete example at every level so that scoring is a matter of recognition rather than guesswork.
| Dimension | Question it answers | NIST characteristic |
|---|---|---|
| Scope | How much of the task is the AI doing? | Reliable, Resilient & Safe |
| Human Oversight | Whether and when a person is in the loop | Accountable & Transparent |
| Transparency | How visible and auditable the AI's actions are | Explainable & Interpretable |
| Stakes | Magnitude of harm, combined with reversibility | Reliable, Resilient & Safe |
| Bias & Fairness | Risk of discriminatory or inequitable outcomes | Fair with Bias Managed |
| Privacy | Sensitivity of personal data and protections in place | Privacy Enhanced |
What it produces
- A banded risk score — Minimal, Low, Moderate, High, or Critical.
- A six-axis chart that shows the shape of the risk, not just its magnitude.
- The closest real-world analog — the nearest match from a library of twenty well-understood AI systems, with a similarity percentage.
- NIST AI RMF guidance across all four functions — Govern, Map, Measure, and Manage — scaled to the score, with additional recommendations triggered when an individual dimension runs high.
Benefits
It makes an abstract argument concrete
"This feels risky" is hard to act on. "Oversight is a 7 and Stakes are an 8" identifies what to change. The assessment ends with a list of specific conditions rather than a verdict.
It gives non-specialists a shared vocabulary
Technical, legal, and business stakeholders routinely talk past each other because each is weighing a different dimension. Six named axes let a mixed group disagree about inputs instead of arguing from incompatible premises.
It shows where the risk actually lives
Averages hide problems. A use case that scores Moderate overall but has Privacy at 9 is a privacy problem, not a moderate one — and the shape of the chart says so at a glance.
It quantifies what a control buys you
Score a proposal as designed, then re-score it with mitigations applied. Watching the number fall when you add human review or an audit log turns a vague recommendation into a measurable reduction.
It is defensible
Recommendations map to a published federal framework rather than institutional opinion. That matters when an assessment is questioned by an auditor, a board, a vendor, or a governance committee.
It calibrates intuition
The analog matcher is a reality check. If an internal productivity tool lands next to an autonomous fraud-blocking system, either the scoring is wrong or the proposal is more consequential than anyone realized.
It covers the dimensions people forget
Bias and privacy are the two risks most often omitted from informal AI reviews, and the two most likely to create legal exposure. Here they are first-class axes, not footnotes.
It scales governance to actual risk
Low-risk uses get a catalog entry; high-risk uses get committee review, independent audit, and tested circuit breakers. Proportionality keeps the process credible.
It works as a triage step
A first pass takes a few minutes, which makes it practical to screen every proposal and reserve deep assessment for the cases that warrant it.
Culture & accountability
Context & risk categorization
Analysis & testing
Mitigation & response
What this tool is not
A structured judgment aid, not a compliance determination. Scores reflect the assessor's own inputs, so the output is only as honest as the person setting the sliders. It surfaces risk, focuses discussion, and prioritizes effort — it does not replace legal review, a formal privacy or security assessment, or the university's own governance process.