Free tool

Your AI policy says the right things. Can it show them?

This reads the text of your written AI policy and reports which of twelve control areas from the NIST AI Risk Management Framework are actually evidenced in it, and which are not. For every area it finds, it quotes the sentence from your own document that carried it, so you can check the finding yourself.

Your document is never uploaded. The PDF is opened and read entirely inside your browser. No copy of it is transmitted to us, stored on our servers, or sent to any third party. Close the tab and it is gone.

0/12 Control areas evidenced

Get this as a written summary

We will send the findings above as a plain document you can forward to counsel, your auditor, or whoever is going to have to sign for this. No obligation, and no sales sequence.

We send the findings and nothing else. Your policy document is not attached and was never uploaded.

Request received

We will send the written summary shortly. If you want the gaps walked through against your actual environment, the AI-Readiness Diagnostic is the next step.

Method

What this does, and what it does not.

What it does

It extracts the full text of the PDF in your browser and searches it for language corresponding to twelve named subcategories of the NIST AI Risk Management Framework (AI RMF 1.0), across all four Core functions: Govern, Map, Measure and Manage.

  • Reads every page, not a sample.
  • Matches on whole phrases, not letter fragments.
  • Quotes the sentence that produced each finding, with its page number, so you can verify it.

What it does not do

This is a text evidence scan. It is not a compliance assessment, a certification, an audit, or legal advice, and it produces no score or pass mark.

  • It cannot tell you whether a control is operating, only whether the document mentions it.
  • A policy can name a control and still fail. A policy can omit one and still have it, documented elsewhere.
  • Nothing here should be represented to a regulator, an auditor or an insurer as evidence of compliance.

Why these twelve

The NIST AI RMF is voluntary and is the reference most US boards, auditors and cyber insurers have converged on. The twelve areas checked here are the subcategories that most often decide whether an AI system clears internal sign-off: documented legal obligations, named accountability, executive responsibility, human oversight, third-party risk, contingency for vendor failure, independent assessment, privacy, bias, the ability to shut a system off, post-deployment monitoring, and incident response.

On EU obligations

Several of these areas map to obligations under the EU AI Act for organizations in scope: risk management (Article 9), data governance (Article 10), record keeping (Article 12), human oversight (Article 14), deployer obligations (Article 26) and transparency (Article 50). Whether any of it applies to you depends on your role and your systems' classification, which this tool does not determine.

A gap list is not a control environment.

Closing these is the work. The AI-Readiness Diagnostic is a fixed-fee engagement that assesses where your organization actually stands and hands you a prioritized plan, whether or not we ever work together.

Request your AI-Readiness Diagnostic