The AI tools your employees brought in and the models your teams deployed are the same question wearing two hats: what does it touch, who owns it, and what happens when it's wrong. Put both in one list and get a risk tier for each, aligned to the NIST AI Risk Management Framework. The tiers are free and ungated, and your inventory stays in this browser.
Every tier comes with a plain-language why this tier explanation, so you can argue with it, and the NIST AI RMF categories that entry actually speaks to. It is a starting point built by senior practitioners, readiness, not a model validation or a certification.
This wizard is a structured starting point for a materiality-based risk-tiering conversation, framed against the NIST AI RMF and SR 26-2. The tiers, scores, and controls are our own structured heuristics, not codified regulatory definitions. This is not a model validation, not legal or regulatory advice, and not a certification. DSE prepares programs for audit and does not certify or guarantee any examination outcome. Your inventory is never uploaded. The optional report gate submits your email address, your consent, and the campaign attribution this site already collects under your analytics consent, never anything from your inventory.
Returning after a previous visit? We expanded the assessment from four factors to nine, so existing entries need the new questions answered before they are scored again. Nothing was lost: every entry, and everything you typed into it, is still here.
Each AI system or use case is one record, whether you deployed it deliberately or discovered it in an expense report. Owner is a role or team, never a person, and the same goes for how you describe where you found something. The register persists in this browser and is reused across the stack. Use Export to keep a copy or move it to another machine.
One form for everything. A tool a team signed up for without asking and a model you deployed on purpose are both records here, separated only by governance status. Fill the fields and save: the wizard computes the risk tier, the required controls, and the NIST AI RMF categories that entry speaks to, then writes the record to your register.
·
·
·
Sorted by weighted contribution, so the top row is the answer to "why". Weighted points are the raw answer multiplied by that signal's fixed weight; the share is of this entry's own total.
Each line recalculates the score with that one answer changed and nothing else. It is arithmetic, not advice.
Normalized deficit per Core function: 0% means nothing of concern in this entry, 100% is the worst case. These are normalized, not raw counts, because the nine signals are unevenly distributed across the functions (GOVERN 2, MAP 3, MEASURE 2, MANAGE 2).
·
·
Every entry is scored on nine signals. Each signal has a fixed weight; the weighted points are summed to a maximum of 62, then converted to a 0 to 100 score with round(weightedSum / 62 × 100). Four escalation rules can then raise a tier, never lower it. The whole rubric lives in one file, /js-stack/ai-tiering-rubric.js, as one pure function over one declarative object, so you can read exactly what it does and check the arithmetic yourself.
This is DSE's rubric, not NIST's. The NIST AI RMF does not define tiers, weights, thresholds, or scores. What the framework references below tell you is which part of the framework each answer speaks to. They are not a statement that you satisfy it.
·
Last reviewed: 2026-09-17 · Shadow-AI release, rubric tracker-spec-1.0. One unified register covering both shadow AI and deliberately deployed AI, a transparent nine-signal weighted rubric scored 0 to 100 with four escalation rules that can raise a tier but never lower it, per-entry "why this score" reasoning, explicit per-entry NIST AI RMF Core mapping, ungated CSV + JSON export/import, and an optional formatted report generated in your browser.
Your tiers are on screen and they're yours, screenshot them, or export CSV and JSON right now without giving us an email. The PDF is a different artifact: your full inventory laid out as a dated report, every entry with its tier and the reasoning written out beside it, the NIST AI RMF categories each one touches, a provenance header recording what the tiers were based on, and the limitations stated on the first page. It's built to survive being emailed to someone who wasn't in the room when you made the list.
If that's useful to you, tell us where to send the unlock. If it isn't, you already have what you came for, and that's genuinely fine.
What the report contains:
Unlocked. Your PDF is generating in this browser now. If your list surfaced more than you expected, that's the normal result, the next question is usually which of these should have had an owner all along.
This wizard gets your inventory and tiering started. When a tier carries real obligations, a principal pressure-tests the tiering, maps controls to SR 26-2 and the frameworks around it, and scopes the readiness work in a 30-minute call.
More free tools: All AI Governance Tools · Model Risk Tiering Calculator · AI System Inventory
This wizard is a structured heuristic for building an AI inventory and organizing a materiality-based tiering conversation framed against the NIST AI RMF and SR 26-2. It does not perform a model validation, does not provide legal or regulatory advice, and does not certify NIST AI RMF, SR 26-2, or any other compliance. The tiers, scores, and controls are our own structured device, not codified regulatory definitions.
DSE provides AI governance and compliance readiness consulting. We are not an accredited certification body and do not issue ISO/IEC 42001 certificates or certify EU AI Act or NIST AI RMF compliance. We cannot guarantee passing an audit or avoiding enforcement, and we do not provide legal advice. We work alongside your counsel.