Impact and oversight
Show where AI exposure sits before anything gets deployed.
This page is written for the person who has to justify a decision to someone above them. It maps each layer of the F.O.C.U.S. Framework to a function of the NIST AI Risk Management Framework, names what is exposed when a layer is weak, and shows the decision element it protects. It contains no cost estimates and no savings claims, because readiness is not a number you can invent.
What NIST is, and why it belongs on this page
NIST is the National Institute of Standards and Technology, the federal agency that writes the standards other agencies and organizations are expected to follow. Its AI Risk Management Framework is the reference document a public body reaches for when it has to answer how it is governing artificial intelligence. Using it means your readiness record rests on a recognized federal standard rather than on any single consultant's opinion.
- Govern
- Who is accountable, what the policy says, and who signs off.
- Map
- Where artificial intelligence is actually in use and what could go wrong.
- Measure
- How you test whether it works and whether it is causing harm.
- Manage
- What you do about the risks you found, and who keeps watching over time.
F.O.C.U.S. to NIST layer map
Each block states what the layer protects, what is exposed when it is weak, and which NIST function the failure lands under.
- Protects
- Clarity
- What is exposed
- No named owner for artificial intelligence decisions, no written policy, and no shared record of what the organization actually values. Questions from legal, procurement, or an oversight body have no documented answer.
- Protects
- Capacity
- What is exposed
- No inventory of where artificial intelligence is already in use. Staff adopt tools quietly, sensitive information moves into systems nobody approved, and the first time leadership hears about it is after something goes wrong.
C. Create
NIST Map + Measure
- Protects
- Visibility
- What is exposed
- Work gets built and published without a check on sources, accuracy, or who reviewed it. Errors reach constituents, clients, or the public record before anyone inside the organization catches them.
- Protects
- Trust
- What is exposed
- People affected by a decision are not told how it was made, cannot reach a human, and have no route to correct something that is wrong about them. Trust erodes quietly and is expensive to rebuild.
S. Support
NIST Manage + Govern
- Protects
- Freedom
- What is exposed
- The policy exists on paper and nothing maintains it. Reviews stop happening, staff turnover erases the reasoning, and the organization drifts back to where it started while believing it is covered.
The complete guiding question and first action for every layer live in the F.O.C.U.S. Method.
What a completed diagnostic produces
Every run ends in a record you can hand to someone else. Nothing here requires a follow-up purchase to be useful.
- A five-layer score map showing where readiness is strong and where it is thin.
- A named bottleneck layer, with the guiding question and first action attached to it.
- A thirty day install plan written against that bottleneck.
- A monthly review template so the record stays current after the first month.
- A jurisdictional roll up that groups results by location. Individual scores are never released, and a group with fewer than five participants releases nothing but its participant count.
- A print ready export for board packets, council briefings, and audit files.