Unofficial checklist · NIST AI 600-1

Generative AI needs
a closer review.

Document safeguards, evidence, gaps, and next actions for one generative AI use. This free starter checklist draws on selected suggested actions in NIST’s Generative AI Profile.

Unofficial · Independent resource

Decision Terrain created the questions and completion criteria. NIST did not create, review, sponsor, or endorse this checklist. These 24 selected checks do not cover every action or risk in NIST AI 600-1. Answers are self-reported and do not establish NIST conformance, certification, legal compliance, safety, or readiness to deploy.

A record for one use

Start with the system. Then record what you know.

Select a status for each check. Add evidence, a gap, or a next action in the notes. If a check does not apply, explain why.

Answers stay in this browser’s local storage and are not uploaded by this tool. Export a JSON backup before clearing browser data. Other scripts on this site can access this origin’s local storage. Keep entries unclassified and non-sensitive; do not enter CUI, secrets, or operational details.

System facts

GOVERN

Govern

Set ownership, acceptable use, and decision boundaries.

GAI-G01

Record the system and its owner

The review names the generative AI system, its model or service versions, responsible owner, and human oversight roles.

Evidence to look for: System inventory entry, model versions, owner and review roster.

Related NIST AI 600-1 actions: GV-1.6-003

GAI-G02

Set risk and release boundaries

A decision owner has defined unacceptable outcomes, review thresholds, and who can approve, pause, or reject deployment.

Evidence to look for: Risk tier, acceptance criteria, release record, stop criteria.

Related NIST AI 600-1 actions: GV-1.3-001, GV-1.3-002, GV-1.3-007

GAI-G03

Define acceptable use

Users and operators have clear permitted and prohibited uses, including when a request or output must be refused or escalated.

Evidence to look for: Acceptable use policy, user instructions, escalation path.

Related NIST AI 600-1 actions: GV-1.4-002, GV-3.2-003

GAI-G04

Set data and content provenance policy

The team has decided what origin, rights, and modification information to keep for inputs, training or grounding data, and generated content.

Evidence to look for: Data and content lineage policy, retention rules, provenance design.

Related NIST AI 600-1 actions: GV-1.2-001, GV-1.5-003

GAI-G05

Review third-party terms and dependencies

Model, data, API, and tool suppliers have been reviewed for usage rights, privacy, security, change notice, and incident responsibilities.

Evidence to look for: Supplier assessment, contract or service terms, dependency register.

Related NIST AI 600-1 actions: GV-6.1-004, GV-6.1-009

MAP

Map

Describe the use, dependencies, people, and foreseeable harms.

GAI-M01

Bound the intended use

The assessment specifies users, tasks, modalities, deployment setting, data sources, and where generated output will be used.

Evidence to look for: Use-case description, workflow map, system boundary.

Related NIST AI 600-1 actions: MP-1.1-001, MP-1.1-002

GAI-M02

Identify foreseeable misuse

The team has considered off-label use, harmful or illegal requests, and uses that exceed its risk tolerance.

Evidence to look for: Misuse scenarios, prohibited-use register, threat model.

Related NIST AI 600-1 actions: MP-1.1-003, MP-1.1-004

GAI-M03

Include affected people and domain expertise

The review identifies affected groups and obtains relevant domain and user input for the actual context of use.

Evidence to look for: Stakeholder map, consultation notes, representative test plan.

Related NIST AI 600-1 actions: MP-1.2-001, MP-1.2-002

GAI-M04

Trace data and model dependencies

The team can describe the origin and role of grounding, retrieval, fine-tuning, model, and downstream components, including known limits.

Evidence to look for: Data lineage, model card, retrieval and integration diagram.

Related NIST AI 600-1 actions: MP-2.1-001, MP-2.2-001

GAI-M05

Prioritize context-specific harms

Relevant privacy, security, false-output, bias, harmful-content, rights, and information-integrity risks are ranked for this use.

Evidence to look for: Risk register with likelihood, impact, rationale, and unknowns.

Related NIST AI 600-1 actions: MP-1.1-003, MP-5.1-006

MEASURE

Measure

Test claims and failure modes with evidence from the intended context.

GAI-E01

Define a representative evaluation

Tests use cases and acceptance criteria tied to the deployment setting, rather than only a benchmark or demonstration.

Evidence to look for: Test plan, case selection, criteria, limitations.

Related NIST AI 600-1 actions: MP-2.3-001, MS-2.3-002, MS-2.5-001

GAI-E02

Test factual accuracy and grounding

The team tests whether consequential outputs are supported by sources or known ground truth and records confident but false answers.

Evidence to look for: Evaluation cases, ground-truth comparison, error analysis.

Related NIST AI 600-1 actions: MP-2.3-001, MP-2.3-003, MS-4.2-002

GAI-E03

Test harmful and prohibited outputs

The review probes harmful, abusive, and otherwise prohibited requests that are plausible for the system's access and context.

Evidence to look for: Safety test cases, refusal results, escalation findings.

Related NIST AI 600-1 actions: MS-2.6-006, MS-2.6-007

GAI-E04

Test privacy and rights exposure

The team checks for sensitive-data leakage and output that may reproduce protected or restricted material, using cases suited to its data and licenses.

Evidence to look for: Privacy tests, output review, data and rights assessment.

Related NIST AI 600-1 actions: MP-4.1-009, MP-4.1-010

GAI-E05

Check performance across relevant groups

Evaluation looks for material differences across affected users, languages, or other relevant groups and records limits of the sample.

Evidence to look for: Disaggregated results, reviewer feedback, sample limitations.

Related NIST AI 600-1 actions: MS-3.3-003, MS-2.11-004

GAI-E06

Run adversarial security tests

The team tests plausible manipulation paths, including prompt injection and attempts to bypass system safeguards or expose protected data.

Evidence to look for: Threat-led test plan, attack results, remediation tickets.

Related NIST AI 600-1 actions: MP-2.3-005, MS-2.7-007

GAI-E07

Check content provenance claims

Any authenticity, watermark, signature, or lineage claim is tested for reliability and known false positives or negatives.

Evidence to look for: Provenance test results, method limits, disclosure copy.

Related NIST AI 600-1 actions: MS-2.7-005

GAI-E08

Get independent or representative feedback

People outside the frontline development team review material risks and test results where the use warrants it.

Evidence to look for: Independent review record, user study, red-team findings.

Related NIST AI 600-1 actions: MS-1.3-002, MS-1.3-003

GAI-E09

Record measurement limits

The assessment names risks it cannot measure well, reasons for those limits, and how they affect the decision.

Evidence to look for: Evaluation limitations and unmeasured-risk register.

Related NIST AI 600-1 actions: MS-1.1-009, MS-2.13-001

MANAGE

Manage

Respond to results, monitor operation, and revisit decisions.

GAI-R01

Decide on each material risk

A named owner records whether each high-priority risk will be mitigated, accepted, avoided, or transferred, with a reason and follow-up.

Evidence to look for: Risk treatment plan, decision log, release conditions.

Related NIST AI 600-1 actions: MG-1.3-001

GAI-R02

Monitor deployed behavior

Monitoring covers the failure modes important to this use, with thresholds, a reviewer, and a way to investigate problems.

Evidence to look for: Monitoring plan, alert rules, sampled review records.

Related NIST AI 600-1 actions: MG-4.1-002, MG-1.3-002

GAI-R03

Receive and act on feedback

Users and affected people have a way to report problems, and the team reviews feedback for changes in output quality or harm.

Evidence to look for: Feedback channel, triage log, response and update records.

Related NIST AI 600-1 actions: MG-2.2-008, MG-3.2-004

GAI-R04

Retest after meaningful changes

Model, prompt, retrieval, fine-tuning, or supplier changes trigger a review of assumptions and relevant evaluations.

Evidence to look for: Change log, regression tests, approval history.

Related NIST AI 600-1 actions: MG-3.1-003

GAI-R05

Prepare incident response and shutdown

The team can report, contain, recover from, and communicate incidents, and knows when to pause or deactivate the system.

Evidence to look for: Incident plan, contacts, rehearsal, deactivation criteria.

Related NIST AI 600-1 actions: MG-2.3-001, MG-2.4-004

Source and method

How to read this mapping

This is a selected, project-authored starter set based on the July 2024 NIST AI RMF Generative AI Profile (AI 600-1). NIST organizes suggested actions by AI RMF function and action ID and notes that applicability varies by role and use. Our check titles, criteria, evidence examples, statuses, and export format are Decision Terrain interpretations. An action ID identifies relevant source material; it is not a claim of complete action coverage.

Use this alongside the general AI RMF checklist, the OWASP LLM security checklist, and the original NIST publication. Checklist version 0.1.0-draft; source reviewed September 22, 2026.