
Use the NIST AI Risk Management Framework (AI RMF) as your baseline for a defensible, actionable AI risk assessment. It is voluntary, lifecycle-spanning, and built through a public comment process with cross-sector input, making it the most credible starting point for U.S. organizations today.
Start here this week:
- Build an AI system inventory. List every AI tool, model, and automated decision process your organization uses or is evaluating.
- Assign a governance owner. One named person or team must be accountable for the assessment process before you score a single risk.
- Run a rapid scoping assessment. Use the NIST AI RMF Playbook and, for generative AI systems, the NIST-AI-600-1 Generative AI Profile to scope which systems need full assessment versus a lighter review.
The AI RMF covers the full lifecycle from design through decommissioning, and its Govern function runs as a cross-cutting thread across every other activity. That structure is what separates a paper exercise from an operational risk program.
Key Takeaways
The NIST AI RMF's four functions (Govern, Map, Measure, Manage) give U.S. organizations a proven, lifecycle-spanning structure for AI risk assessment that integrates directly into existing enterprise risk and compliance programs.
| Point | Details |
|---|---|
| Start with an inventory | List every AI system before scoring any risk; unknown systems cannot be governed or monitored. |
| Use the NIST AI RMF as your backbone | The Govern, Map, Measure, Manage structure covers the full lifecycle and maps to ISO 31000 and NIST CSF. |
| TEVV makes risk real | Test, Evaluation, Verification, and Validation turn a scored register into evidence-backed, auditable findings. |
| Document every decision | Signed approvals, timestamped TEVV reports, and model cards are the artifacts that demonstrate due diligence to auditors and regulators. |
| Collett Systems LLC supports readiness | Collett Systems LLC provides AI governance advisory, cybersecurity assessments, and managed IT for organizations that need structured support running a defensible assessment. |
Table of Contents
- What is the NIST AI RMF and why should U.S. organizations use it?
- How do the four AI RMF core functions work in practice?
- How to run an AI risk assessment this week
- How do you measure AI risks with TEVV?
- Who owns AI governance, and what documentation do you keep?
- Which tools and templates should you use right away?
- How do you prioritize AI risks and decide on treatment?
- What records do you need to keep and for how long?
- Common implementation gaps and how to fix them fast
- How should you monitor AI systems after deployment?
- How does AI risk assessment fit into your existing risk management program?
- What regulations apply to AI risk in the United States?
- What are the real limits of current AI risk assessment approaches?
- AI risk assessment in practice: industry examples
- Why SMBs should treat AI governance as an infrastructure problem
- Collett Systems LLC: structured AI and IT risk support for Wisconsin businesses
- Primary sources and further reading
- Sources
What is the NIST AI RMF and why should U.S. organizations use it?
The NIST AI Risk Management Framework is a voluntary, consensus-built standard published by the National Institute of Standards and Technology to help organizations identify, assess, and manage risks from AI systems across their full lifecycle. NIST developed it through public workshops and comment rounds with industry, government, academia, and civil society, a provenance that gives it credibility no vendor framework can match.
The AI RMF is organized around four core functions: Govern, Map, Measure, and Manage. Governance is not a separate phase; it is infused across all three other functions as a continuous, cross-cutting activity. That design choice matters because it forces accountability at every stage, not just at launch.
Key NIST artifacts every organization should reference:
- AI RMF Core, the primary framework document with functions, categories, and subcategories
- AI RMF Playbook, suggested actions and outcomes mapped to each subcategory, available through the NIST Trustworthy and Responsible AI Resource Center (AIRC)
- NIST-AI-600-1 Generative AI Profile, a use-case profile that extends the core framework specifically for generative AI systems, including large language models
- NIST Trustworthy and Responsible AI Resource Center (AIRC), the central hub at airc.nist.gov for all companion materials, crosswalks, and profiles
The AI RMF maps cleanly to enterprise risk management programs. Its categories align with ISO 31000 risk principles and can be crosswalked to NIST CSF, SOC 2, and HIPAA security rules, which means you are not building a parallel risk program from scratch. You are extending what you already have.
How do the four AI RMF core functions work in practice?
The AI RMF Core structures every assessment around four functions. Think of them as a continuous loop, not a linear checklist.
Govern: set the conditions for responsible AI
Govern establishes the policies, roles, culture, and accountability structures that make everything else work. Without it, Map, Measure, and Manage produce reports that sit in a folder.
Concrete Govern outcomes include:
- A written AI use policy with defined acceptable and prohibited use cases
- Named roles: AI risk owner, data steward, legal reviewer, and executive sponsor
- Documented sign-off gates at design, pre-deployment, and post-deployment review
- A process for escalating high-risk findings to leadership
- Training records showing staff understand AI limitations and oversight responsibilities
Map: identify what you have and what could go wrong
Map is where you build the picture. Teams scope each AI system, identify affected stakeholders, and catalog the risk categories that apply.
Common AI risk categories surfaced during mapping include bias and fairness, privacy and data exposure, security vulnerabilities (including adversarial attacks and prompt injection), transparency and explainability gaps, reliability and accuracy failures (including hallucinations), and model drift over time.
Map outputs include a system inventory, a stakeholder impact analysis, and a preliminary risk register with unscored entries ready for measurement.
Measure: test and score what you mapped
Measure turns the risk register into scored, evidence-backed findings. This is where Test, Evaluation, Verification, and Validation (TEVV) activities happen. The full NIST AI 100-1 document details trustworthiness characteristics, accuracy, reliability, explainability, privacy, security, fairness, and safety, as the dimensions against which measurement should be structured.
Both quantitative metrics (accuracy rates, false positive rates, demographic parity scores) and qualitative methods (red-team exercises, expert review, stakeholder interviews) belong here.
Manage: treat risks and track residual exposure
Manage is where decisions get made: accept, mitigate, avoid, or transfer each scored risk. It also covers ongoing monitoring, incident response, and the feedback loop back into Govern and Map when conditions change.
"AI risk management should be integrated into broader enterprise risk management and governance processes, and should be applied throughout the AI lifecycle, not just at deployment." This framing from the NIST AI 100-1 document is the clearest argument against treating an AI risk assessment as a one-time event.
The four functions interact continuously. A model retrained on new data re-enters the Map and Measure cycle. A new regulation triggers a Govern update. Decommissioning a system requires a final Manage review to confirm data deletion and audit trail retention.
How to run an AI risk assessment this week
A minimal defensible assessment runs six steps: inventory, scope, score, test, treat, and monitor. Practical assessment guidance recommends scoring each system across three dimensions, data sensitivity, decision impact, and regulatory exposure, to produce comparable, prioritized risk tiers.
-
Inventory all AI systems. List every model, tool, and automated decision process. Include third-party AI embedded in software you already use. Owner: IT lead or CTO. Output: AI system register.
-
Scope each system. Classify by data type (personal, regulated, proprietary), decision impact (low-stakes recommendation vs. high-stakes automated decision), and regulatory exposure (HIPAA, GLBA, sector-specific rules). Owner: IT lead + legal. Output: scoping worksheet per system.
-
Score risks. Apply the data sensitivity × decision impact × regulatory exposure rubric to assign a risk tier (low, medium, high, critical) to each system. Owner: risk owner + data science. Output: scored risk register.
-
Test and measure (TEVV). Run targeted tests against the risk categories identified in step 2. For a high-risk system, this means bias testing, adversarial input testing, and accuracy benchmarking. For a low-risk system, a documented review may suffice. Owner: data science + security. Output: TEVV report.
-
Treat each risk. For every scored risk, assign a treatment: accept (document rationale), mitigate (implement a control), avoid (discontinue the use case), or transfer (contractual liability shift to vendor). Owner: risk owner + executive sponsor. Output: treatment plan with control assignments.
-
Set up monitoring. Define what you will watch, how often, and who reviews alerts. Establish a threshold that triggers re-assessment. Owner: IT operations. Output: monitoring plan with review schedule.
Sign-off template: The assessment package (register + TEVV report + treatment plan) should carry dated signatures from the risk owner, legal reviewer, and executive sponsor before any high-risk system goes to production.
How do you measure AI risks with TEVV?
Measurable TEVV is the difference between a paper assessment and operational risk control. Without it, your risk register is an opinion document.
TEVV stands for Test, Evaluation, Verification, and Validation. The NIST AI 100-1 framework treats these as distinct but related activities that together confirm a system behaves as intended across its expected operating conditions.
| TEVV Activity | Purpose | Sample Method |
|---|---|---|
| Test | Probe system behavior under controlled inputs | Adversarial input sets, edge-case datasets |
| Evaluation | Measure performance against defined metrics | Accuracy, F1 score, demographic parity |
| Verification | Confirm system meets design specifications | Code review, architecture audit |
| Validation | Confirm system meets real-world operational needs | User acceptance testing, field pilot |
Metrics by risk category:
- Bias/fairness: demographic parity ratio, equalized odds, disparate impact score
- Robustness/security: attack success rate under adversarial inputs, out-of-distribution accuracy
- Privacy: membership inference attack success rate, data minimization audit score
- Reliability: hallucination rate (for generative systems), uptime, mean time between failures
- Transparency: explainability coverage (percentage of decisions with accessible rationale)
Pro Tip: Document measurement uncertainty explicitly. If your bias test used a sample that does not represent your full user population, say so in the TEVV report. Auditors and regulators treat undisclosed limitations as a red flag; disclosed ones show maturity.
Who owns AI governance, and what documentation do you keep?
Accountability without documentation is unenforceable. Every AI risk program needs named owners, clear decision gates, and a paper trail that survives an audit.
| Role | Core Responsibilities | Sign-off Gate |
|---|---|---|
| AI Risk Owner | Maintains risk register, coordinates TEVV, escalates findings | Pre-deployment approval |
| Executive Sponsor | Authorizes go/no-go decisions, owns residual risk acceptance | Go/no-go gate |
| Legal/Compliance | Reviews regulatory exposure, approves data use, flags liability | Scoping and pre-deployment |
| Data Scientist/ML Engineer | Runs TEVV, documents model behavior, flags drift | TEVV sign-off |
| IT/Security | Manages infrastructure controls, monitors for anomalies | Deployment and monitoring |
| Data Steward | Governs data provenance, access controls, retention | Data classification step |
Questions to ask each stakeholder before sign-off:
- Legal: "Which regulations apply to this system's outputs, and have we documented our compliance position?"
- Data science: "What are the known failure modes, and are they documented in the model card?"
- Operations: "What is the escalation path if the model produces an anomalous output in production?"
- Product/business: "Is there a human override available for every automated decision this system makes?"
Required artifacts to keep:
- AI system inventory (versioned)
- Scored risk register with treatment assignments
- TEVV reports with methodology and uncertainty disclosures
- Model card for each production model
- Decision log (who approved what, when, and on what evidence)
- Incident log with response records
Which tools and templates should you use right away?
The most immediately useful artifacts are the AI RMF Playbook, the Generative AI Profile (NIST-AI-600-1), and a structured inventory spreadsheet. Start with those three before evaluating any commercial tooling.
- AI RMF Playbook, maps suggested actions to every subcategory in the Core; use it to build your assessment checklist and assign ownership. It is the fastest path from "we need to do something" to a structured work plan.
- NIST-AI-600-1 Generative AI Profile, if your organization uses any large language model, chatbot, or AI-generated content tool, this profile adds use-case-specific risks (hallucination, prompt injection, data poisoning) that the base framework does not fully address.
- NIST Trustworthy and Responsible AI Resource Center (AIRC) at airc.nist.gov, central repository for crosswalks, profiles, and implementation guidance. Bookmark it; NIST updates it as new profiles are released.
- NIST AI RMF Implementation Guide for manufacturing, if you operate in a regulated production environment, this crosswalk maps RMF controls to manufacturing compliance requirements.
- Inventory spreadsheet columns to start with: System name, vendor/owner, data categories processed, decision impact level, regulatory exposure, current oversight mechanism, assigned risk tier, last review date.
- Risk register fields: System ID, risk category, likelihood score, impact score, composite risk tier, treatment decision, control owner, target remediation date, residual risk accepted by (name + date).
- Open-source testing tools: IBM AI Fairness 360 for bias metrics, Microsoft Counterfit for adversarial robustness testing, and Hugging Face's evaluation libraries for generative model benchmarking are all production-ready and free to use.
For AI-assisted drafting of assessment artifacts, AI tools can accelerate the baseline documentation, but every score, control assignment, and TEVV decision requires human review and sign-off. An AI-drafted risk register is a starting point, not a finished assessment.
How do you prioritize AI risks and decide on treatment?
Prioritize by impact multiplied by likelihood, then tune that score for data sensitivity and regulatory exposure. A system with moderate likelihood but catastrophic impact on a regulated data set ranks higher than a high-likelihood, low-impact tool.
Risk matrix approach (generic tiers):
- Critical: High impact + high likelihood, or any system processing sensitive regulated data with automated high-stakes decisions. Requires immediate mitigation or avoidance before deployment.
- High: High impact + moderate likelihood, or moderate impact + high likelihood. Requires documented controls and executive sign-off.
- Medium: Moderate impact + moderate likelihood. Requires monitoring plan and periodic review.
- Low: Low impact or low likelihood. Accept with documented rationale and annual review.
Treatment options:
- Mitigate, implement a technical or process control (bias filter, human review gate, access restriction, output logging). Best for high and critical risks where the use case has clear business value.
- Avoid, discontinue or redesign the use case. The right call when mitigation cost exceeds benefit or when the risk cannot be reliably controlled.
- Accept, document the residual risk and the rationale. Appropriate for low-tier risks or when controls are already in place and residual exposure is within tolerance.
- Transfer, shift liability contractually to a vendor or insurer. Works for third-party AI tools where the vendor bears responsibility for model behavior; requires vendor AI risk disclosures in the contract.
Go/no-go gate criteria: A system clears the gate when the risk register is scored and signed, TEVV results are documented, all critical and high risks have assigned controls, and the executive sponsor has signed the residual risk acceptance. Missing any one of these is a hold, not a conditional approval.
What records do you need to keep and for how long?
Keep a small, mandatory set of artifacts and keep them well. A large, disorganized documentation pile is nearly as bad as none at all when an auditor or regulator asks for evidence of due diligence.
Mandatory artifacts and suggested retention:
- AI system inventory, maintain continuously; retain prior versions for at least three years
- Scored risk register, retain each version for the life of the system plus three years after decommissioning
- TEVV reports, retain for the life of the system plus five years; longer for regulated industries (healthcare, finance)
- Model cards, retain for the life of the model plus three years
- Decision log (go/no-go approvals), retain for the life of the system plus five years
- Incident log, retain for at least five years; align with your sector's incident reporting requirements
Sample report outline for a risk committee or regulator:
- Executive summary (system description, risk tier, treatment decision)
- Scope and methodology (what was assessed, scoring rubric used, TEVV methods)
- Risk findings (scored register, top risks, control assignments)
- TEVV results (test types, metrics, uncertainty disclosures)
- Residual risk statement (what remains after controls, who accepted it, when)
- Monitoring plan (what is watched, frequency, escalation triggers)
Evidence quality matters. Signed approvals with timestamps, independent TEVV results (not self-certified by the model's own team), and version-controlled documents carry far more weight than undated summaries. Treat your AI risk documentation the same way you treat financial audit evidence.
Common implementation gaps and how to fix them fast
The three gaps we see most often in practice: no system inventory, no post-deployment monitoring, and no clear sign-off authority. Organizations that address all three in the first two weeks of an assessment program are dramatically better positioned than those that spend months on policy documents without fixing the basics.

Gap 1: Missing inventory. Teams discover they have AI systems in production that no one formally approved. The fix is a two-hour cross-functional meeting with IT, operations, and department heads to list every tool, then a 48-hour window to verify the list against software licenses and cloud subscriptions.
Gap 2: Weak monitoring. Models are deployed and then forgotten until something breaks visibly. The fix is a simple drift detection check and a monthly accuracy spot-check, both logged and reviewed by a named owner. For manufacturers using AI in quality control, Annex 22 compliance requirements mandate ongoing monitoring and revalidation when model behavior changes, a useful benchmark even for non-regulated environments.
Gap 3: Unclear sign-off. Assessments are completed but no one formally approves them, so they carry no authority. The fix is a one-page sign-off template with three signature lines: risk owner, legal, and executive sponsor.
Quick-action checklist (7, 14 days):
- Complete AI system inventory (Day 1, 2)
- Assign risk owner and executive sponsor (Day 2)
- Score top five highest-impact systems using the data sensitivity × decision impact × regulatory exposure rubric (Day 3, 7)
- Run at least one TEVV activity per high-risk system (Day 7, 12)
- Establish a monitoring schedule and assign reviewers (Day 12, 14)
- Obtain signed go/no-go approvals for any system currently in production without one (Day 14)
Start with your free IT risk score to surface infrastructure and security gaps that directly affect AI system exposure before you begin scoring individual models.
How should you monitor AI systems after deployment?
Post-deployment is where most AI risk programs lose discipline. The assessment is done, the system is live, and monitoring becomes an afterthought until an incident forces a review.
Continuous monitoring for AI systems covers three layers. First, performance monitoring: track accuracy, output quality, and key metrics against the baselines established during TEVV. A generative model's hallucination rate, a classification model's false positive rate, or a recommendation engine's click-through accuracy all need defined alert thresholds. Second, data drift monitoring: the statistical distribution of inputs changes over time, and a model trained on last year's data may behave unpredictably on this year's inputs. Automated drift detection tools can flag when input distributions shift beyond a defined tolerance. Third, security and access monitoring: log who queries the model, what data it accesses, and whether any outputs suggest adversarial manipulation or prompt injection attempts.
Incident response for AI systems should follow your existing security incident process, with one addition: a model behavior review. When an AI system produces an anomalous or harmful output, the response team needs to determine whether the cause was a data issue, a model issue, an infrastructure issue, or an adversarial attack. Each has a different remediation path. Document every incident, the root cause determination, and the corrective action taken.
Post-deployment controls also include scheduled re-assessment triggers. Set a calendar review at six months for high-risk systems and twelve months for medium-risk ones. Any significant change to the model, its training data, or its operating environment should trigger an unscheduled re-assessment regardless of the calendar.
How does AI risk assessment fit into your existing risk management program?
AI risk assessment is not a standalone exercise. It belongs inside your enterprise risk management (ERM) program, your IT governance structure, and your compliance calendar.
The NIST AI RMF is designed to complement, not replace, existing frameworks. Its Govern function maps directly to board-level risk oversight. Its Map and Measure functions align with the risk identification and analysis steps in ISO 31000. Its Manage function mirrors the treatment and monitoring cycle in any mature ERM program. Organizations already running NIST CSF for cybersecurity will find the AI RMF's structure immediately familiar.
Practically, this means AI risks belong in your existing risk register alongside cybersecurity, operational, and compliance risks. The AI system inventory feeds your IT asset management system. TEVV results feed your audit evidence repository. Model cards and decision logs feed your compliance documentation. The cybersecurity assessment services that identify infrastructure vulnerabilities are a natural complement to AI-specific risk scoring, since many AI risks (data exposure, adversarial attacks, access control failures) are fundamentally IT security problems.
For manufacturers, AI systems used in production or quality control carry additional integration requirements. AI governance for manufacturers needs to account for operational technology (OT) environments, production data sensitivity, and the intersection of AI risk with existing quality management systems.
What regulations apply to AI risk in the United States?
The U.S. regulatory picture for AI is sector-specific and evolving. There is no single federal AI law equivalent to the EU AI Act, but sector regulators have issued guidance that creates real compliance obligations.
Key regulatory touchpoints:
- HIPAA, AI systems that process protected health information (PHI) must meet HIPAA Security Rule requirements for access control, audit logging, and data integrity. An AI diagnostic tool or clinical decision support system is in scope. Healthcare IT compliance and AI risk assessment overlap directly here.
- GLBA, Financial institutions using AI for credit decisions, fraud detection, or customer data analysis must address Gramm-Leach-Bliley Act safeguards, including risk assessments for information systems.
- EEOC guidance, AI tools used in hiring, promotion, or performance evaluation face scrutiny under Title VII and the Americans with Disabilities Act. The EEOC has issued technical guidance on algorithmic discrimination.
- FTC Act Section 5, The FTC has signaled that deceptive or unfair AI practices (including undisclosed automated decisions affecting consumers) fall under its authority.
- Executive Order 14110 (2023), Required federal agencies to develop AI risk management practices aligned with the NIST AI RMF; while directed at agencies, it signals the direction of federal procurement and contracting requirements.
- State laws, Illinois BIPA, California CPRA, and Colorado's AI Act (effective 2026) create state-level obligations for automated decision systems, particularly those affecting consumers.
This is general information, not legal advice. Confirm current regulatory requirements with qualified legal counsel for your specific industry and use case.
What are the real limits of current AI risk assessment approaches?
The frameworks are good. The gap is execution, and it is worth being direct about where current approaches fall short.
Measurement standards are immature. There is no universally agreed method for measuring AI fairness, and different fairness metrics can produce contradictory results on the same system. The NIST AI 100-1 document acknowledges this explicitly. Organizations should document which metrics they chose and why, rather than treating any single metric as definitive.
Third-party AI is hard to assess. When you embed a vendor's AI model in your product or workflow, you inherit its risks but often lack access to its training data, architecture, or internal test results. Vendor AI risk disclosures are inconsistent, and contractual protections are still catching up to the technology.
Generative AI moves faster than assessment cycles. A large language model can be updated by its provider without notice, changing its behavior between your last assessment and today. The NIST-AI-600-1 Generative AI Profile addresses this, but it requires continuous monitoring, not just periodic review.
Small teams lack capacity. A six-step assessment with TEVV activities, documentation, and sign-off requires time and skills that many small and mid-sized organizations do not have in-house. The honest answer is that some organizations need external support to run a credible assessment, not just a template.
Bias in the assessment process itself. The people running the assessment may share the same blind spots as the people who built the system. Independent review, whether internal audit or external assessment, catches what internal teams miss.
AI risk assessment in practice: industry examples
Abstract frameworks become real when you see how they apply to specific decisions.
Healthcare: clinical decision support. A regional health system deploying an AI tool to flag patients at risk of sepsis runs a Map phase that identifies the system as high-risk (PHI processing, automated clinical alert, HIPAA in scope). TEVV includes accuracy testing across demographic subgroups to check for disparate performance, plus a validation study comparing AI-flagged cases against physician judgment. The go/no-go gate requires sign-off from the CISO, CMO, and legal counsel. Monitoring tracks false negative rates weekly, with a threshold that triggers immediate review.
Manufacturing: quality control vision system. A Wisconsin manufacturer uses a computer vision model to inspect parts on the production line. The Map phase scores it as medium-risk (no personal data, but production impact is high). TEVV includes accuracy benchmarking against human inspectors and adversarial testing with intentionally degraded images. Annex 22 compliance guidance informs the validation approach, treating the AI system analogously to a validated instrument. Monitoring tracks defect detection rates and flags model drift when accuracy drops below the established baseline.
Financial services: credit underwriting assistance. A community bank uses an AI tool to assist loan officers with initial credit risk scoring. The Map phase flags ECOA and FCRA exposure immediately. TEVV includes disparate impact analysis across protected classes and a documentation review confirming the AI output is advisory, not the final decision. The treatment plan includes a mandatory human review gate for every AI-assisted decision and quarterly bias audits. The AI Governance Institute's scoring rubric, data sensitivity × decision impact × regulatory exposure, produces a critical tier for this system, driving the most rigorous controls.

Why SMBs should treat AI governance as an infrastructure problem
The most common mistake small and mid-sized organizations make with AI risk is treating it as a compliance checkbox rather than an infrastructure discipline. Governance, monitoring, and documentation are not overhead. They are the controls that keep an AI system from becoming a liability.
For most SMBs, the highest-return actions are the simplest ones: build the inventory, name the owner, and set up basic monitoring. Those three steps cost almost nothing and eliminate the most common audit failures. The full NIST AI RMF is the right long-term target, but you do not need to implement every subcategory on day one. Start with the systems that touch regulated data or make consequential decisions, score them honestly, and document what you find.
The tradeoff most SMBs face is capacity, not intent. Running a credible TEVV process for a high-risk system requires data science skills, security testing capability, and legal review. When those skills are not in-house, the options are to accept a less rigorous assessment (and document that limitation honestly), defer deployment until controls are in place, or bring in external support. Accepting risk without documenting it is the worst outcome. Deferring a high-risk deployment until you can assess it properly is a legitimate governance decision, not a failure.
One practical shortcut for small teams: use the AI RMF Playbook's suggested actions as a self-assessment checklist. Work through it with your IT lead and a department head for each system. You will surface the gaps faster than any consultant can, and the documentation you produce along the way is already part of your evidence package.
If you want a structured starting point, Collett Systems LLC can run a readiness assessment that maps your current AI and IT posture against the RMF and identifies your highest-priority gaps.
Collett Systems LLC: structured AI and IT risk support for Wisconsin businesses
Most small and mid-sized businesses in Wisconsin have AI tools in production right now that have never been formally assessed. The gap between "we're using AI" and "we have a documented, governed AI program" is exactly where liability accumulates.
Collett Systems LLC closes that gap with a fixed-cost, engineer-led approach that covers AI governance advisory, cybersecurity assessment, 24/7 monitoring, and compliance documentation. Unlike a one-time consultant engagement, our managed IT services keep your monitoring and documentation current after the initial assessment is done.
What you get:
- A structured AI and IT risk assessment mapped to the NIST AI RMF
- Documented TEVV artifacts and a signed risk register ready for auditors
- Ongoing monitoring with defined alert thresholds and escalation paths
- Cybersecurity solutions that address the infrastructure risks underlying AI deployments
We work with manufacturers, financial firms, and professional services businesses across Southeastern Wisconsin. Over 150 local organizations trust us with their IT infrastructure. Book your IT and security assessment to get a clear picture of where you stand today.
Primary sources and further reading
These are the documents worth bookmarking for ongoing implementation work.
- AI RMF Core, the authoritative source for the four functions, categories, and subcategories; use it to map your existing activities to the framework.
- Nist, the central NIST page for all companion artifacts including the Playbook, Generative AI Profile (NIST-AI-600-1), and the 2026 critical infrastructure concept note.
- NIST AI 100-1 Full Document (PDF), the complete framework text with detailed guidance on trustworthiness characteristics, TEVV, and measurement; essential for teams building a formal program.
- Federal Register: AI RMF Notice, the administrative record documenting NIST's public engagement process; useful for demonstrating the framework's credibility to leadership and auditors.
- AI Governance Institute: How to Perform an AI Risk Assessment, practical scoring rubric and step sequence for running a defensible assessment; pairs directly with the NIST Playbook.
- RiskWatch: AI Risk Management Frameworks and Best Practices, a concise summary of common AI risk categories and how frameworks map to practice; useful for onboarding stakeholders who are new to the topic.
- SentinelOne: AI Risk Assessment Framework Step-by-Step, covers the practical assessment sequence and addresses responsible use of AI-assisted drafting tools in the assessment process.
- TrustFort: Annex 22 Compliance for AI in Manufacturing, explains validation and monitoring requirements for AI systems in regulated manufacturing environments; directly applicable to GxP-adjacent operations.
- The Art of Service: NIST AI RMF Implementation Guide for Manufacturing, maps RMF controls to manufacturing compliance requirements; useful for teams running assessments in production or quality control environments.
