FREE NIST AI RMF GAP ASSESSMENT FOR EXCEL
Find the gap between AI principles and operating evidence.
Download a practical XLSX with 40 original practices organized around GOVERN, MAP, MEASURE, and MANAGE. Track current status, evidence, owners, target dates, priorities, next actions, and notes while the dashboard updates automatically. No signup and no upload.
- Editable XLSX
- 40 practices
- Formula dashboard
- No signup
- No upload
- Not an official NIST checklist

THE PRACTICAL ANSWER
Use the AI RMF to organize work, not manufacture a score.
The NIST AI Risk Management Framework is intended for voluntary use, and the NIST AI RMF Playbook provides suggested actions across GOVERN, MAP, MEASURE, and MANAGE. NIST also states that the Playbook is neither a checklist nor a required sequence. This original workbook keeps that boundary visible while giving a team somewhere practical to record current evidence, ownership, and improvement work.
WHAT THE WORKBOOK TRACKS
The fields needed to turn broad guidance into owned work.
Four AI RMF functions
Review ten original practices for each of GOVERN, MAP, MEASURE, and MANAGE without pretending the worksheet reproduces the full framework or Playbook.
Current status
Choose not started, planned, in progress, implemented, or not applicable from consistent menus that drive the dashboard.
Operating evidence
Record the current artifact that shows what actually operates, such as a policy, setting, contract, test, approval, log, ticket, or incident record.
Accountable ownership
Name the person responsible for each open item instead of leaving improvement work attached only to a committee, policy, or future program.
Priority and timing
Assign a context-specific priority and target date. The starter priorities are editable and should be changed to fit the organization and exact scope.
Next practical action
Describe the smallest verifiable step that advances the practice, then use the dashboard to review progress by function and status.
A WORKABLE FIRST PASS
Complete the worksheet from evidence outward.
- 1
Set one narrow scope
Name the organization, program, system, portfolio, or use cases covered by the review. A smaller exact boundary produces more useful evidence and actions.
- 2
Review current evidence
Do not mark a practice implemented because a policy mentions it. Record the artifact, owner, operating condition, and known limitation that support the status.
- 3
Assign open work
Choose a priority, owner, target date, and next action for gaps. Route material risks and exceptions through the organization's authorized decision process.
- 4
Repeat after change
Reassess after new models, data, users, integrations, automation, vendors, incidents, complaints, failed controls, expanded scope, or changing obligations.
IMPORTANT LIMITS
A completed workbook is not a completed risk program.
- The 40 practices are original BrandQuill prompts. They are not official NIST subcategories, tests, requirements, audit criteria, or certification controls.
- The weighted completion formula is a planning indicator. It cannot show whether an AI system is lawful, safe, secure, fair, accessible, approved, or fit for use.
- A recorded artifact does not prove the underlying control is correctly designed, operating, complete, current, or effective for the exact conditions.
- NIST notes that AI RMF 1.0 is under revision in 2026. Verify current official materials and adapt the workbook before relying on it.
- Use qualified legal, privacy, security, safety, accessibility, procurement, audit, workforce, and leadership review where the context requires it.
WHEN THE GAPS NEED OPERATING RECORDS
Connect framework work to inventory, risk, approvals, incidents, and policy.
The $19 AI Policy Operations Kit combines an AI inventory, 30 starter risks, approval log, incident log, dashboard, and scoring guide in one Excel governance workbook. It also includes five editable Word files, a PDF implementation guide, and lifetime BrandQuill Solo publishing.
$19 once
No subscription. Seven-day fit guarantee.See the complete kit →Download the full free starter kit →COMMON QUESTIONS
Start with evidence and preserve the framework's real boundary.
What is included in the free NIST AI RMF gap assessment template?
The XLSX includes a formula-driven dashboard, 40 original implementation practices across GOVERN, MAP, MEASURE, and MANAGE, status and priority menus, evidence, owners, target dates, next actions, notes, instructions, scoring definitions, and source links.
Is this an official NIST checklist or certification?
No. BrandQuill created this original worksheet as an implementation aid. NIST does not publish, endorse, or certify it. NIST states that the AI RMF Playbook is voluntary and is not a checklist or a set of steps to follow in its entirety.
Does BrandQuill upload the assessment or require an account?
No. The workbook downloads directly. You can edit it locally in Excel or another compatible spreadsheet application without creating an account or uploading governance information to BrandQuill.
How is weighted completion calculated?
Implemented practices receive full weight, in-progress practices receive half weight, and not-applicable practices are excluded from the denominator. The result is a planning indicator, not a risk rating, audit opinion, certification, approval, or compliance conclusion.
What should I record as evidence?
Use current links, file names, ticket IDs, meeting records, test results, approvals, contracts, settings, logs, incident records, or other artifacts that show what operates for the exact scope being reviewed.
What does the $19 AI Policy Operations Kit add?
The paid kit connects AI inventory, 30 starter risks, approvals, incidents, a dashboard, and a scoring guide in one coordinated Excel workbook. It also includes five editable Word files, a PDF implementation guide, and lifetime BrandQuill Solo publishing.