§ Free tool◆runs in your browser ◆risk tiers ungated

Name every AI your company is running — including the ones nobody approved.

The AI tools your employees brought in and the models your teams deployed are the same question wearing two hats: what does it touch, who owns it, and what happens when it's wrong. Put both in one list and get a risk tier for each, aligned to the NIST AI Risk Management Framework. The tiers are free and ungated, and your inventory stays in this browser.

Every tier comes with a plain-language why this tier explanation, so you can argue with it, and the NIST AI RMF categories that entry actually speaks to. It is a starting point built by senior practitioners, readiness, not a model validation or a certification.

◆Your inventory stays in this browser. Your email and consent are submitted when you request a download or use any form on this site. Your risk tiers are free and ungated either way.
§ Read this first

This wizard is a structured starting point for a materiality-based risk-tiering conversation, framed against the NIST AI RMF and SR 26-2. The tiers, scores, and controls are our own structured heuristics, not codified regulatory definitions. This is not a model validation, not legal or regulatory advice, and not a certification. DSE prepares programs for audit and does not certify or guarantee any examination outcome. Your inventory is never uploaded. The optional report gate submits your email address, your consent, and the campaign attribution this site already collects under your analytics consent, never anything from your inventory.

§ 01: Your AI register·saved in this browser

Your AI register

Returning after a previous visit? We expanded the assessment from four factors to nine, so existing entries need the new questions answered before they are scored again. Nothing was lost: every entry, and everything you typed into it, is still here.

Each AI system or use case is one record, whether you deployed it deliberately or discovered it in an expense report. Owner is a role or team, never a person, and the same goes for how you describe where you found something. The register persists in this browser and is reused across the stack. Use Export to keep a copy or move it to another machine.

Show
§ 02: Add or edit a system·the rubric runs on save

System details

One form for everything. A tool a team signed up for without asking and a model you deployed on purpose are both records here, separated only by governance status. Fill the fields and save: the wizard computes the risk tier, the required controls, and the NIST AI RMF categories that entry speaks to, then writes the record to your register.

Record New system
·

·

·

·

Why this score

·

What each answer contributed

Sorted by weighted contribution, so the top row is the answer to "why". Weighted points are the raw answer multiplied by that signal's fixed weight; the share is of this entry's own total.

What would lower it

Each line recalculates the score with that one answer changed and nothing else. It is arithmetic, not advice.

NIST AI RMF Core rollup

Normalized deficit per Core function: 0% means nothing of concern in this entry, 100% is the worst case. These are normalized, not raw counts, because the nine signals are unevenly distributed across the functions (GOVERN 2, MAP 3, MEASURE 2, MANAGE 2).

Supporting categories this entry touches

·

§ Limitations

·

Copied to clipboard.
§ 03: How the rubric works·fully transparent

The tiering rubric

▸ Show the exact points, bands, and control mapping

Every entry is scored on nine signals. Each signal has a fixed weight; the weighted points are summed to a maximum of 62, then converted to a 0 to 100 score with round(weightedSum / 62 × 100). Four escalation rules can then raise a tier, never lower it. The whole rubric lives in one file, /js-stack/ai-tiering-rubric.js, as one pure function over one declarative object, so you can read exactly what it does and check the arithmetic yourself.

This is DSE's rubric, not NIST's. The NIST AI RMF does not define tiers, weights, thresholds, or scores. What the framework references below tell you is which part of the framework each answer speaks to. They are not a statement that you satisfy it.

·

Last reviewed: 2026-09-17 · Shadow-AI release, rubric tracker-spec-1.0. One unified register covering both shadow AI and deliberately deployed AI, a transparent nine-signal weighted rubric scored 0 to 100 with four escalation rules that can raise a tier but never lower it, per-entry "why this score" reasoning, explicit per-entry NIST AI RMF Core mapping, ungated CSV + JSON export/import, and an optional formatted report generated in your browser.

§ 04: The formatted report·built in your browser

You already have the answers. This is the version you can forward.

Your tiers are on screen and they're yours, screenshot them, or export CSV and JSON right now without giving us an email. The PDF is a different artifact: your full inventory laid out as a dated report, every entry with its tier and the reasoning written out beside it, the NIST AI RMF categories each one touches, a provenance header recording what the tiers were based on, and the limitations stated on the first page. It's built to survive being emailed to someone who wasn't in the room when you made the list.

§ When you want it built for you·fixed-fee, senior-only

From a starter register to an auditor-ready program.

This wizard gets your inventory and tiering started. When a tier carries real obligations, a principal pressure-tests the tiering, maps controls to SR 26-2 and the frameworks around it, and scopes the readiness work in a 30-minute call.

§ What this is·and what it isn't

A register and a tiering starting point. Not certification.

This wizard is a structured heuristic for building an AI inventory and organizing a materiality-based tiering conversation framed against the NIST AI RMF and SR 26-2. It does not perform a model validation, does not provide legal or regulatory advice, and does not certify NIST AI RMF, SR 26-2, or any other compliance. The tiers, scores, and controls are our own structured device, not codified regulatory definitions.

DSE provides AI governance and compliance readiness consulting. We are not an accredited certification body and do not issue ISO/IEC 42001 certificates or certify EU AI Act or NIST AI RMF compliance. We cannot guarantee passing an audit or avoiding enforcement, and we do not provide legal advice. We work alongside your counsel.