Spaces:
Sleeping
Sleeping
Create OMB_NIST_AI_RMF_MAPPING.md
Browse files- OMB_NIST_AI_RMF_MAPPING.md +74 -0
OMB_NIST_AI_RMF_MAPPING.md
ADDED
|
@@ -0,0 +1,74 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
# OMB & NIST AI Risk Management Framework (AI RMF) Mapping
|
| 2 |
+
|
| 3 |
+
## Project
|
| 4 |
+
**Federal FOIA Intelligence Search**
|
| 5 |
+
|
| 6 |
+
## Applicable Frameworks
|
| 7 |
+
- NIST AI Risk Management Framework (AI RMF 1.0)
|
| 8 |
+
- OMB Guidance on Responsible AI Use (M-21-06, M-23-10)
|
| 9 |
+
|
| 10 |
+
---
|
| 11 |
+
|
| 12 |
+
## AI System Classification
|
| 13 |
+
|
| 14 |
+
**Risk Tier:** Low-Risk, Assistive, Non-Autonomous
|
| 15 |
+
**Use Case:** Research assistance for public records
|
| 16 |
+
**Decision Authority:** Human only
|
| 17 |
+
|
| 18 |
+
---
|
| 19 |
+
|
| 20 |
+
## NIST AI RMF Core Mapping
|
| 21 |
+
|
| 22 |
+
### GOVERN (G)
|
| 23 |
+
|
| 24 |
+
| Control | Implementation |
|
| 25 |
+
|------|----------------|
|
| 26 |
+
| G-1 Transparency | Public documentation, disclosures |
|
| 27 |
+
| G-2 Accountability | Maintainer governance, feature flags |
|
| 28 |
+
| G-3 Human Oversight | User-initiated actions only |
|
| 29 |
+
| G-4 Policy Alignment | FOIA, journalism, legal ethics |
|
| 30 |
+
|
| 31 |
+
---
|
| 32 |
+
|
| 33 |
+
### MAP (M)
|
| 34 |
+
|
| 35 |
+
| Control | Implementation |
|
| 36 |
+
|------|----------------|
|
| 37 |
+
| M-1 Context | Public FOIA materials only |
|
| 38 |
+
| M-2 Stakeholders | Journalists, researchers, courts |
|
| 39 |
+
| M-3 Harm Identification | Hallucination, misinterpretation |
|
| 40 |
+
|
| 41 |
+
---
|
| 42 |
+
|
| 43 |
+
### MEASURE (ME)
|
| 44 |
+
|
| 45 |
+
| Control | Implementation |
|
| 46 |
+
|------|----------------|
|
| 47 |
+
| ME-1 Output Evaluation | Citation anchoring |
|
| 48 |
+
| ME-2 Performance | No accuracy claims |
|
| 49 |
+
| ME-3 Monitoring | Integrity hashes |
|
| 50 |
+
|
| 51 |
+
---
|
| 52 |
+
|
| 53 |
+
### MANAGE (MA)
|
| 54 |
+
|
| 55 |
+
| Control | Implementation |
|
| 56 |
+
|------|----------------|
|
| 57 |
+
| MA-1 Risk Mitigation | AI opt-in, disclaimers |
|
| 58 |
+
| MA-2 Incident Response | Disable AI feature flags |
|
| 59 |
+
| MA-3 Change Control | Phase-based rollout |
|
| 60 |
+
|
| 61 |
+
---
|
| 62 |
+
|
| 63 |
+
## OMB Alignment Summary
|
| 64 |
+
|
| 65 |
+
✔ No automated decision-making
|
| 66 |
+
✔ No surveillance functionality
|
| 67 |
+
✔ No personal data processing
|
| 68 |
+
✔ No training on user inputs
|
| 69 |
+
|
| 70 |
+
---
|
| 71 |
+
|
| 72 |
+
## Compliance Conclusion
|
| 73 |
+
|
| 74 |
+
This system aligns with **low-risk assistive AI** under NIST AI RMF and OMB guidance.
|