Frame the system
Define intended purpose, context, actors, affected communities, benefits, and plausible harms.
NIST AI RMF WORKING-GROUP SIMULATION
A regulator is coming. A lending model has changed without approval. Customer harm may already be occurring. Your working group must decide what continues, what is restricted, and what stops.
Training simulation: Cedarwell Bank, its people, vendors, systems, and data are fictional. Laws, standards, and framework references are real.
LEARNING DESIGN
Participants use incomplete evidence, competing incentives, and real constraints to apply the NIST AI RMF as an operating discipline.
Define intended purpose, context, actors, affected communities, benefits, and plausible harms.
Separate what is known, inferred, missing, disputed, and time-sensitive.
Connect measurements and risk tolerance to a defensible operating decision.
Record owners, conditions, residual risk, monitoring, escalation, and review dates.
THE CASE
Cedarwell Bank is a privately held U.S. regional bank with a fast-growing digital subsidiary. Its AI portfolio expanded system by system; governance did not.
It is Monday, 8:15 a.m. You have been asked to lead a temporary AI Risk Working Group reporting to Chief Risk Officer Elena Marquez.
On Friday evening, Internal Audit reopened a high-rated model-change finding. The current small-business lending model was promoted three weeks ago without independent validation. Early monitoring suggests a material approval-rate gap, but the data pipeline cannot reproduce the production sample.
At 9:40 p.m., the bank's generative customer assistant gave a borrower an incorrect explanation for a credit decline. The answer contradicted the official adverse-action notice. Customer Operations initially classified the event as a “content quality issue,” not a compliance incident.
On Thursday morning, examiners will meet management for a previously scheduled model-risk review. The CEO wants growth targets protected. The Risk Committee wants an evidence-based recommendation before the meeting.
“Do not give me a maturity score. Tell me what is safe enough to continue, under which conditions, and who is accepting the residual risk.”— Elena Marquez, Chief Risk Officer
THE PEOPLE
You will deal with these people during the session, directly or through the exhibits. A recommendation that ignores their wants will not survive Thursday.
| Name | Role | What they want | What you should know |
|---|
AI ESTATE
EVIDENCE ROOM
The exhibits are deliberately incomplete and occasionally contradictory. The quality of the decision depends on how the team handles uncertainty—not on inventing facts.
RMF WORKBENCH
Use the four functions as a connected loop. GOVERN is cross-cutting; MAP establishes the context; MEASURE tests the claims; MANAGE turns evidence into action.
DECISION BOARD
For the three priority systems, select a provisional decision and document the minimum rationale. Your work is saved only in this browser.
MASTERY PORTFOLIO
Twenty-seven artifacts, organized under GOVERN, MAP, MEASURE, and MANAGE. Each should demonstrate judgment, traceability, and practical implementation for a financial-services AI estate — not merely reproduce framework language.
| ID | Portfolio artifact | Primary RMF mapping | Quality signal | Template |
|---|
If the artifact could be pasted into any bank without changing the systems, people, evidence, thresholds, or decisions, it is not yet portfolio quality.
COVERAGE MAP
Computed directly from the 27 artifacts above — every subcategory at least one artifact maps to, and how many artifacts back it.
| Subcategory | Artifacts mapped | Depth |
|---|
ARTIFACT BUILDER · PILOT
A deterministic, step-by-step guide through one artifact at a time — no generative AI. Cedarwell's worked example stays visible as a reference; the field you fill in is for your own organization. Four of the 27 artifacts are interactive so far.
Your answers save only in this browser. To hand off to a teammate or pick up on another device, export a workspace file and import it there.
FACILITATOR VIEW
This demo supports a remote or in-person working group of 6–24 participants. It intentionally stops short of publishing a model answer.
Assign the team as an advisory working group. Emphasize evidence, decision rights, and the 72-hour clock.
Individuals scan the case and exhibits. Team records facts, inferences, gaps, conflicts, and time-sensitive items.
Breakouts analyze one priority system: purpose, actors, affected groups, harms, benefits, dependencies, and assumptions.
Define the evidence needed to support trustworthiness and determine what can and cannot be concluded now.
Choose continue, restrict, or pause. Add conditions, owner, residual risk, monitoring, and escalation.
Teams present. Peers challenge assumptions. Close by identifying reusable portfolio artifacts and learning gaps.
AUTHORITATIVE SOURCES
The simulation operationalizes NIST guidance; it is not affiliated with or endorsed by NIST.
Demo v0.0.0 · Prepared for collaborative learning and portfolio development · Framework status should be rechecked before each cohort.