{
 "catalog": {
  "uuid": "ef9d58aa-53d8-5be7-adde-e60b22009035",
  "metadata": {
   "title": "CoSAI AI Shared Responsibility Framework — Industry Vertical Controls (Proposed Extension)",
   "last-modified": "2026-07-28T22:58:14+00:00",
   "version": "0.1.0",
   "oscal-version": "1.2.2",
   "props": [
    {
     "name": "keywords",
     "ns": "https://aisharedresponsibility.com/ns/oscal",
     "value": "AI, shared responsibility, CoSAI, SRF, OSCAL, industry verticals"
    },
    {
     "name": "control-count",
     "ns": "https://aisharedresponsibility.com/ns/oscal",
     "value": "258"
    },
    {
     "name": "source",
     "ns": "https://aisharedresponsibility.com/ns/oscal",
     "value": "https://aisharedresponsibility.com/data/finance-controls.json"
    },
    {
     "name": "source",
     "ns": "https://aisharedresponsibility.com/ns/oscal",
     "value": "https://aisharedresponsibility.com/data/public-sector-controls.json"
    },
    {
     "name": "source",
     "ns": "https://aisharedresponsibility.com/ns/oscal",
     "value": "https://aisharedresponsibility.com/data/healthcare-controls.json"
    },
    {
     "name": "source",
     "ns": "https://aisharedresponsibility.com/ns/oscal",
     "value": "https://aisharedresponsibility.com/data/insurance-controls.json"
    },
    {
     "name": "source",
     "ns": "https://aisharedresponsibility.com/ns/oscal",
     "value": "https://aisharedresponsibility.com/data/defense-controls.json"
    },
    {
     "name": "source",
     "ns": "https://aisharedresponsibility.com/ns/oscal",
     "value": "https://aisharedresponsibility.com/data/manufacturing-controls.json"
    }
   ],
   "links": [
    {
     "href": "https://aisharedresponsibility.com/",
     "rel": "canonical"
    },
    {
     "href": "https://aisharedresponsibility.com/framework/",
     "rel": "reference",
     "text": "SRF framework reference"
    },
    {
     "href": "https://aisharedresponsibility.com/export/srf-oscal-catalog.json",
     "rel": "related",
     "text": "SRF accountability matrix overlay catalog"
    }
   ],
   "remarks": "Each control operationalizes one SRF vertical control: accountability assignment, measured threshold objective (as an OSCAL parameter), regulatory mappings, and evidence pointers. Groups are SRF layers (L1-L5) with one subgroup per industry vertical. Industry vertical schemas are independently proposed extensions and are not part of the official CoSAI release. Mapping IDs marked TBD are unverified and are carried verbatim as props, never as links; do not substitute invented IDs. Generated from data/*-controls.json."
  },
  "groups": [
   {
    "id": "l1",
    "class": "srf-layer",
    "title": "L1: AI Business & Usage",
    "groups": [
     {
      "id": "l1-finance",
      "class": "srf-vertical",
      "title": "L1 — Finance",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "finance"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/finance-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "fin-srf-l1-dev-001",
        "class": "srf-vertical-control",
        "title": "AI Risk Appetite Statement with Named Accountable Executive",
        "params": [
         {
          "id": "fin-srf-l1-dev-001-p1",
          "label": "risk_appetite_statement_approved",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual-review"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: board-approved AI risk appetite statement exists, names an accountable executive, and covers all operating models in use."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-DEV-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Processes & Governance"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-board-risk-committee"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: L1 policy controls rely on records management and board minutes, not streaming OCSF telemetry. Candidate: audit_activity class if supported by SIEM ingestion of board governance records."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l1-dev-001_stmt",
          "name": "statement",
          "prose": "The institution must publish a board-approved AI risk appetite statement that names a specific senior executive accountable for AI risk. The statement must define risk tolerance thresholds for each operating model (AI-SaaS, AI-PaaS, Agent-PaaS, IaaS) and be reviewed on the cadence defined in SRF-L1-MON-002."
         },
         {
          "id": "fin-srf-l1-dev-001_obj",
          "name": "objective",
          "prose": "Maintain risk_appetite_statement_approved == {{ insert: param, fin-srf-l1-dev-001-p1 }} over window annual-review. Breach action: escalate-to-board-risk-committee."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-RC-022 (Regulatory Compliance and Oversight)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-02 (Risk Management Program)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section VI (Governance and Controls)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (Risk management system)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 2.3 (executive leadership takes responsibility for AI risk decisions); MAP 1.5 (organizational risk tolerances are determined and documented)"
         }
        ]
       },
       {
        "id": "fin-srf-l1-dev-002",
        "class": "srf-vertical-control",
        "title": "AI Model Inventory and Tier Classification Policy",
        "params": [
         {
          "id": "fin-srf-l1-dev-002-p1",
          "label": "tier_classification_policy_approved",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "at-model-onboarding"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: tier classification methodology documented, approved, and applied to all models entering production."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-DEV-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Business Units & Accountability"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-model-production-promotion"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: policy artifact; not directly observable via OCSF streaming events at L1."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-finos-aigf",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-eu-ai-act",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l1-dev-002_stmt",
          "name": "statement",
          "prose": "The institution must maintain a complete inventory of AI models in use, with each model assigned a materiality tier (e.g., Tier 1: high materiality, Tier 2: moderate, Tier 3: low) per SR 26-2's risk-based approach. Tier assignment criteria must be documented and approved by the accountable executive named in SRF-L1-DEV-001."
         },
         {
          "id": "fin-srf-l1-dev-002_obj",
          "name": "objective",
          "prose": "Maintain tier_classification_policy_approved == {{ insert: param, fin-srf-l1-dev-002-p1 }} over window at-model-onboarding. Breach action: block-model-production-promotion."
         }
        ],
        "links": [
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-10 (AI Impact Assessment)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-02 (Risk Management Program)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section VI (Model Inventory)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section III (model materiality)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.6 (mechanisms are in place to inventory AI systems, resourced by risk priority)"
         }
        ]
       },
       {
        "id": "fin-srf-l1-dev-003",
        "class": "srf-vertical-control",
        "title": "Acceptable Use Policy with Named Business-Unit Accountable Individual",
        "params": [
         {
          "id": "fin-srf-l1-dev-003-p1",
          "label": "business_unit_named_aup_signatory_coverage",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual-review"
           }
          ],
          "values": [
           "tier-defined"
          ],
          "guidelines": [
           {
            "prose": "Percentage of business units with AI systems in production that have a current AUP acknowledgment signed by a named individual (not a team or role), linked to that individual's identity record in the HR or IAM system."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-DEV-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Capabilities & Business Strategy"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "suspend-ai-system-access-for-non-compliant-business-unit; notify-mrm-head"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: records management artifact. Where AUP acknowledgment is captured via an IAM or GRC system, authentication events (authentication OCSF class) at the acknowledgment step can confirm a specific user identity completed the sign-off."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l1-dev-003_stmt",
          "name": "statement",
          "prose": "Each business unit deploying AI systems must designate a named individual (not a team, role title, or org-unit) as the accountable signatory for the acceptable use policy covering that unit's AI systems. The AUP must specify permitted use cases, prohibited outputs, user categories, and escalation paths, and must address each operating model in scope. A business-unit-level signature without a named individual does not satisfy SR 26-2's governance accountability expectations and will be a finding under examiner review. The named individual must be recorded in the model inventory alongside the models they are accountable for, and updated when the individual changes (see SRF-L1-MON-003)."
         },
         {
          "id": "fin-srf-l1-dev-003_obj",
          "name": "objective",
          "prose": "Maintain business_unit_named_aup_signatory_coverage >= {{ insert: param, fin-srf-l1-dev-003-p1 }} over window annual-review. Breach action: suspend-ai-system-access-for-non-compliant-business-unit; notify-mrm-head."
         },
         {
          "id": "fin-srf-l1-dev-003_gdn",
          "name": "guidance",
          "prose": "named-individual-constraint: Must be a specific named employee. Cannot be a shared mailbox, team name, or role title. Must have sufficient seniority and authority to enforce the AUP within their business unit."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-OP-018 (Model Overreach / Expanded Use)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-09 (Acceptable Use of the AI Service)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section VI (Roles and Responsibilities)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 26 (Deployer obligations)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 2.1 (roles, responsibilities, and lines of communication are documented); GOVERN 1.2 (trustworthy AI characteristics are integrated into policies)"
         }
        ]
       },
       {
        "id": "fin-srf-l1-dev-004",
        "class": "srf-vertical-control",
        "title": "Agent Business Process Authorization Policy",
        "params": [
         {
          "id": "fin-srf-l1-dev-004-p1",
          "label": "agent_process_authorization_policy_exists",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "at-production-promotion"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: for every Agent-PaaS deployment in production, a written agent authorization policy exists naming an accountable business owner and defining the bounded scope of agent authority for each business process the agent acts within."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-DEV-004"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Processes & Governance"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "cross-layer-controls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-DEV-003"
         },
         {
          "name": "cross-layer-controls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-DEV-002"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-agent-production-deployment; notify-cro-and-legal"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "api_activity"
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent actions observable via api_activity events (actor.process or actor.user identifying the agent) can be cross-referenced against the authorized action scope defined in the policy to detect out-of-scope actions."
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "supplemental",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai_operation events (message_context, role-based interaction tracking) provide session-level context for agent action audit trails."
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l1-dev-004_stmt",
          "name": "statement",
          "prose": "Before any Agent-PaaS system is deployed to act autonomously on the institution's behalf, executing transactions, communicating with clients, initiating workflows, or making decisions that produce regulatory or financial consequences; the institution must produce a written agent authorization policy for each business process the agent is permitted to act within. The policy must specify: the bounded scope of agent authority (which actions are permitted, which require human approval), the named human business owner accountable for agent actions within that process, the escalation path when an agent action falls outside its authorized scope, and the conditions under which the agent must halt and refer to a human. SR 26-2 puts agentic AI out of scope but existing MRM principles require human accountability for model outputs. When an agent acts, the accountable human must be named at L1 before deployment, not identified after an incident. This control applies to Agent-PaaS only; AI-SaaS and AI-PaaS systems that do not act autonomously are out of scope."
         },
         {
          "id": "fin-srf-l1-dev-004_obj",
          "name": "objective",
          "prose": "Maintain agent_process_authorization_policy_exists == {{ insert: param, fin-srf-l1-dev-004-p1 }} over window at-production-promotion. Breach action: block-agent-production-deployment; notify-cro-and-legal."
         },
         {
          "id": "fin-srf-l1-dev-004_gdn",
          "name": "guidance",
          "prose": "cross-layer-note: The agent authorization scope defined here must be reflected in the tool allow-list (SRF-L3-DEV-003) and in the gateway authorization entitlements (SRF-L4-DEV-002). A change to this policy must trigger re-review of both downstream controls. ECH reviews at L3 and L4 must verify alignment with the current version of this policy. named-business-owner-constraint: Each agent business process authorization must name a specific individual as the accountable business owner. The named owner is responsible for reviewing agent action logs at the cadence defined in the policy and for escalating anomalies to the MRM function."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-SEC-024 (Agent Action Authorization Bypass)"
         },
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-PREV-018 (Agent Authority Least Privilege Framework)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-11 (Agents Security Boundaries)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-15 (Human supervision)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section III footnote 3 (generative and agentic AI out of scope"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "MRM principles applied by analogy)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 14 (Human oversight)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.3 (level of risk management activity is set by risk tolerance); GOVERN 3.2 (policies define human-AI configurations and oversight)"
         }
        ]
       },
       {
        "id": "fin-srf-l1-val-001",
        "class": "srf-vertical-control",
        "title": "Independent Review of AI Risk Appetite by Second Line",
        "params": [
         {
          "id": "fin-srf-l1-val-001-p1",
          "label": "independent_review_completed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "12mo"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: second-line independent review of AI risk appetite completed within the past 12 months, with findings documented and remediation tracked."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-VAL-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Processes & Governance"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "independent-validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-cro-and-audit-committee"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: audit artifact. Not directly observable via OCSF streaming events."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-finos-aigf",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l1-val-001_stmt",
          "name": "statement",
          "prose": "The second line of defense (model risk management or independent risk function) must perform an annual independent review of the AI risk appetite statement (SRF-L1-DEV-001) and tier classification policy (SRF-L1-DEV-002). The review must assess whether thresholds remain appropriate given changes to the model portfolio, operating models, and regulatory guidance."
         },
         {
          "id": "fin-srf-l1-val-001_obj",
          "name": "objective",
          "prose": "Maintain independent_review_completed == {{ insert: param, fin-srf-l1-val-001-p1 }} over window 12mo. Breach action: escalate-to-cro-and-audit-committee."
         }
        ],
        "links": [
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "A&A-02 (Independent Assessments)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section III (effective challenge)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (Risk management system)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 1.3 (independent assessors are involved in TEVV); GOVERN 4.1 (practices foster critical thinking about AI risk)"
         }
        ]
       },
       {
        "id": "fin-srf-l1-mon-001",
        "class": "srf-vertical-control",
        "title": "Model Tier Classification Coverage Rate",
        "params": [
         {
          "id": "fin-srf-l1-mon-001-p1",
          "label": "model_tier_classification_coverage_rate",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "30d"
           }
          ],
          "values": [
           "tier-defined"
          ],
          "guidelines": [
           {
            "prose": "Percentage of AI models in production inventory that have a current, approved tier assignment."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-MON-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Business Units & Accountability"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "flag-unclassified-models-for-immediate-tier-assignment; notify-mrm-head"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "api_activity"
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "If AI platform APIs surface model registration events, map model_id from api_activity events against the tier classification register. Gap = unclassified models."
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-finos-aigf",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-eu-ai-act",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l1-mon-001_stmt",
          "name": "statement",
          "prose": "Ongoing monitoring of the percentage of AI models in production that have an assigned materiality tier per the policy in SRF-L1-DEV-002. Any model that has been in production longer than the onboarding window without a tier assignment constitutes a breach."
         },
         {
          "id": "fin-srf-l1-mon-001_obj",
          "name": "objective",
          "prose": "Maintain model_tier_classification_coverage_rate >= {{ insert: param, fin-srf-l1-mon-001-p1 }} over window 30d. Breach action: flag-unclassified-models-for-immediate-tier-assignment; notify-mrm-head."
         }
        ],
        "links": [
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-10 (AI Impact Assessment)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section VI (Model Inventory)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.6 (AI system inventory completeness is maintained)"
         }
        ]
       },
       {
        "id": "fin-srf-l1-mon-002",
        "class": "srf-vertical-control",
        "title": "AI Governance Committee Review Cadence",
        "params": [
         {
          "id": "fin-srf-l1-mon-002-p1",
          "label": "governance_review_cadence_adherence",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "90d"
           }
          ],
          "values": [
           "tier-defined"
          ],
          "guidelines": [
           {
            "prose": "Percentage of scheduled governance reviews that were completed within the required window, across all model tiers."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-MON-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Processes & Governance"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "alert-mrm-head; document-missed-review; reschedule-within-15d"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: calendar and records management artifact, not streaming telemetry. Could be derived from GRC system audit logs if accessible via OCSF."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-finos-aigf",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-eu-ai-act",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l1-mon-002_stmt",
          "name": "statement",
          "prose": "The AI governance committee (or equivalent body) must hold documented reviews of the AI model portfolio at the cadence required by the institution's tier policy. Tier-1 models require quarterly review; Tier-2 and Tier-3 review cadence is institution-defined per SR 26-2's materiality principle. This control monitors that reviews occur as scheduled."
         },
         {
          "id": "fin-srf-l1-mon-002_obj",
          "name": "objective",
          "prose": "Maintain governance_review_cadence_adherence >= {{ insert: param, fin-srf-l1-mon-002-p1 }} over window 90d. Breach action: alert-mrm-head; document-missed-review; reschedule-within-15d."
         }
        ],
        "links": [
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-01 (Governance Program Policy and Procedures)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section VI (Governance and Controls)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.5 (ongoing monitoring and periodic review of the risk management process are planned)"
         }
        ]
       },
       {
        "id": "fin-srf-l1-mon-003",
        "class": "srf-vertical-control",
        "title": "Governance Role Identity Lifecycle Monitoring",
        "params": [
         {
          "id": "fin-srf-l1-mon-003-p1",
          "label": "governance_role_vacancy_age",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "<="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-defined"
           }
          ],
          "values": [
           "tier-defined (Tier-1: 30d, Tier-2: 60d)"
          ],
          "guidelines": [
           {
            "prose": "Number of days any named governance accountability role has been vacant or held by a departed/transferred employee without a confirmed successor. Breach when vacancy exceeds the SLA tier for that role."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-MON-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Business Units & Accountability"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "alert-cro-and-audit-committee; flag-affected-models-as-governance-gap-pending-reassignment"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: requires integration with HR system offboarding events or IAM deprovisioning events. Candidate: account_change OCSF class (account deactivation events) cross-referenced against the governance role registry."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-finos-aigf",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-eu-ai-act",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l1-mon-003_stmt",
          "name": "statement",
          "prose": "When any named individual in an AI governance accountability role changes, including the accountable executive (SRF-L1-DEV-001), business-unit AUP signatories (SRF-L1-DEV-003), agent business process owners (SRF-L1-DEV-004), and the MRM function head; the vacancy or transition must be resolved within the SLA defined per role tier. A stale name on a governance document is an accountability gap and a regulatory finding. This control monitors open vacancies against SLA and flags overdue reassignments. SLA tiers: Tier-1 roles (accountable executive, MRM head) must be reassigned within 30 days of vacancy; Tier-2 roles (business-unit signatories, agent process owners) within 60 days. Institutions may tighten but not loosen these defaults."
         },
         {
          "id": "fin-srf-l1-mon-003_obj",
          "name": "objective",
          "prose": "Maintain governance_role_vacancy_age <= {{ insert: param, fin-srf-l1-mon-003-p1 }} over window continuous. Breach action: alert-cro-and-audit-committee; flag-affected-models-as-governance-gap-pending-reassignment."
         }
        ],
        "links": [
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-06 (Governance Responsibility Model)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section VI (Roles and Responsibilities)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 2.1 (roles and responsibilities stay documented and current)"
         }
        ]
       },
       {
        "id": "fin-srf-l1-ech-001",
        "class": "srf-vertical-control",
        "title": "Board-Level Effective Challenge of AI Risk Profile",
        "params": [
         {
          "id": "fin-srf-l1-ech-001-p1",
          "label": "board_effective_challenge_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "12mo"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: board risk committee review of AI risk profile completed in the past 12 months with documented substantive challenge (questions, findings, or required management actions recorded in board minutes)."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-ECH-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Processes & Governance"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "effective-challenge"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-audit-committee; flag-in-regulatory-exam-preparation"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: board minutes and governance records; not observable via OCSF streaming telemetry. Consider integrating GRC audit trail if SIEM-accessible."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-finos-aigf",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-eu-ai-act",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l1-ech-001_stmt",
          "name": "statement",
          "prose": "The board risk committee (or equivalent) must conduct annual effective challenge of the institution's AI risk profile, including review of the risk appetite statement, tier distribution, open findings from independent validation, and any material incidents from the prior period. Challenge must be documented with evidence of substantive board-level inquiry, not passive acceptance."
         },
         {
          "id": "fin-srf-l1-ech-001_obj",
          "name": "objective",
          "prose": "Maintain board_effective_challenge_documented == {{ insert: param, fin-srf-l1-ech-001-p1 }} over window 12mo. Breach action: escalate-to-audit-committee; flag-in-regulatory-exam-preparation."
         }
        ],
        "links": [
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "A&A-02 (Independent Assessments)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-02 (Risk Management Program)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section III (effective challenge)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 2.3 (executive leadership takes responsibility for AI risk decisions); GOVERN 4.1 (practices foster critical thinking about AI risk)"
         }
        ]
       }
      ]
     },
     {
      "id": "l1-public-sector",
      "class": "srf-vertical",
      "title": "L1 — Public Sector",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "public-sector"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/public-sector-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "pubsec-srf-l1-acq-001",
        "class": "srf-vertical-control",
        "title": "AI Use-Case Inventory Completeness and Public Posting",
        "params": [
         {
          "id": "pubsec-srf-l1-acq-001-p1",
          "label": "ai_use_case_inventory_coverage_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "quarterly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_AI_INVENTORY_COVERAGE_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of known production AI use cases appearing in the current public inventory. Tier-configurable; recommended minimum 95% for agencies with high-impact designations."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-ACQ-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Shared-Service"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agency"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition-integration"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "identify-unregistered-use-cases; notify-CAIO; escalate-to-AI-governance-board"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact at L1. Inventory publication is a governance record. Candidate OCSF class: audit_activity (3002) if the inventory system emits publication or update events to SIEM."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-fedramp-20x-ksi",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l1-acq-001_stmt",
          "name": "statement",
          "prose": "The agency must maintain a current inventory of all AI use cases, confirm completeness against known system deployments, and publicly post the inventory per M-25-21 transparency requirements. Each entry must record the use case, operating component, point of contact, and whether the use case has been designated high-impact."
         },
         {
          "id": "pubsec-srf-l1-acq-001_obj",
          "name": "objective",
          "prose": "Maintain ai_use_case_inventory_coverage_pct >= {{ insert: param, pubsec-srf-l1-acq-001-p1 }} over window quarterly. Breach action: identify-unregistered-use-cases; notify-CAIO; escalate-to-AI-governance-board."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 3(a)(v) (Update AI Use Case Inventories)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.1 (policies, processes, procedures, and practices across the organization); MAP 1.1 (context is established for the AI risk assessment)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l1-acq-002",
        "class": "srf-vertical-control",
        "title": "High-Impact AI Designation with Named Designating Official",
        "params": [
         {
          "id": "pubsec-srf-l1-acq-002-p1",
          "label": "high_impact_designation_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual-review"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: every AI use case in the inventory carries a documented designation decision, names the designating official, and was reviewed within the prior annual cycle."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-ACQ-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Shared-Service"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agency"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition-integration"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "flag-undesignated-use-cases; halt-new-high-impact-deployments-pending-designation; notify-CAIO"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact. Designation records are governance documents. Candidate: audit_activity (3002) for designation event logging."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-fedramp-20x-ksi",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l1-acq-002_stmt",
          "name": "statement",
          "prose": "For each AI use case, the agency must document whether a high-impact designation has been made under M-25-21, name the official who made the designation, and record the rationale. Use cases pending designation must have an open action item with a target date. Designation status must be reviewed at least annually."
         },
         {
          "id": "pubsec-srf-l1-acq-002_obj",
          "name": "objective",
          "prose": "Maintain high_impact_designation_documented == {{ insert: param, pubsec-srf-l1-acq-002-p1 }} over window annual-review. Breach action: flag-undesignated-use-cases; halt-new-high-impact-deployments-pending-designation; notify-CAIO."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(a) (Determining High-Impact AI)"
         },
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 6 (categories presumed high-impact)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.2 (organizational teams document AI risk and benefit); MAP 2.1 (scientific findings, known and foreseeable impacts are characterized)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-10 (AI Impact Assessment)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-06 (Governance Responsibility Model)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l1-acq-003",
        "class": "srf-vertical-control",
        "title": "CAIO Appointment and AI Governance Board Charter Currency",
        "params": [
         {
          "id": "pubsec-srf-l1-acq-003-p1",
          "label": "caio_and_governance_board_active",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual-review"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a confirmed CAIO is in place, an AI governance board exists with a current charter reviewed within the prior annual cycle, and meeting minutes from the prior quarter are on file."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-ACQ-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Shared-Service"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agency"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition-integration"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-agency-head; notify-OMB-liaison; freeze-new-high-impact-AI-approvals"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact. Governance documents are policy records."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-fedramp-20x-ksi",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l1-acq-003_stmt",
          "name": "statement",
          "prose": "The agency must have a confirmed Chief AI Officer (CAIO) in place per M-25-21 and an active AI governance board with a current charter. The charter must define membership, decision rights, meeting cadence, and escalation paths for high-impact AI use cases."
         },
         {
          "id": "pubsec-srf-l1-acq-003_obj",
          "name": "objective",
          "prose": "Maintain caio_and_governance_board_active == {{ insert: param, pubsec-srf-l1-acq-003-p1 }} over window annual-review. Breach action: escalate-to-agency-head; notify-OMB-liaison; freeze-new-high-impact-AI-approvals."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 3(a)(i) (Chief AI Officers)"
         },
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 3(a)(ii) (Agency AI Governance Board)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.1 (policies, processes, procedures documented and in effect); GOVERN 2.1 (roles and responsibilities for AI risk management are designated)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-06 (Governance Responsibility Model)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l1-acq-004",
        "class": "srf-vertical-control",
        "title": "M-25-21 Compliance Plan Currency",
        "params": [
         {
          "id": "pubsec-srf-l1-acq-004-p1",
          "label": "compliance_plan_current",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual-review"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a compliance plan exists, addresses all seven minimum practices, assigns responsible offices, and was updated within the prior annual cycle."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-ACQ-004"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Shared-Service"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agency"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition-integration"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-CAIO; notify-OMB-liaison; block-new-high-impact-AI-onboarding"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact. Compliance plan is a governance record."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-fedramp-20x-ksi",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l1-acq-004_stmt",
          "name": "statement",
          "prose": "The agency must maintain a published compliance plan addressing all seven M-25-21 minimum practices for high-impact AI. The plan must identify which use cases are in scope, assign responsible offices, and specify target dates for any practices not yet fully implemented. It must be updated whenever material changes occur or at least annually."
         },
         {
          "id": "pubsec-srf-l1-acq-004_obj",
          "name": "objective",
          "prose": "Maintain compliance_plan_current == {{ insert: param, pubsec-srf-l1-acq-004-p1 }} over window annual-review. Breach action: escalate-to-CAIO; notify-OMB-liaison; block-new-high-impact-AI-onboarding."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 3(b)(ii) (Develop Compliance Plans)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.1; GOVERN 4.1 (AI risk management is integrated into broader enterprise risk management)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-01 (Governance Program Policy and Procedures)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l1-mon-005",
        "class": "srf-vertical-control",
        "title": "Discontinuation and Waiver Process Readiness",
        "params": [
         {
          "id": "pubsec-srf-l1-mon-005-p1",
          "label": "discontinuation_process_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual-review"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a discontinuation and waiver process exists, names the approving official, and specifies criteria and remediation timelines."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-MON-005"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Shared-Service"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agency"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "notify-CAIO; escalate-to-AI-governance-board; schedule-emergency-compliance-review"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact. Candidate: audit_activity (3002) for discontinuation event logging."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-fedramp-20x-ksi",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l1-mon-005_stmt",
          "name": "statement",
          "prose": "For high-impact AI use cases that cannot meet the minimum practices by the September 22, 2026 deadline, the agency must have a documented discontinuation or waiver process. The process must name the approving official, specify the criteria for waiver, and set a remediation timeline. Discontinued use cases must be removed from the public inventory."
         },
         {
          "id": "pubsec-srf-l1-mon-005_obj",
          "name": "objective",
          "prose": "Maintain discontinuation_process_documented == {{ insert: param, pubsec-srf-l1-mon-005-p1 }} over window annual-review. Breach action: notify-CAIO; escalate-to-AI-governance-board; schedule-emergency-compliance-review."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(a)(i) (Implementing Risk Management Practices and Termination of Non-Compliant AI)"
         },
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(a)(ii) (Authorizing Waivers from Minimum Practices)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.4 (AI risk management frameworks are established for decommissioning); MANAGE 4.1 (post-deployment AI risks are monitored and tracked)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l1-ovr-006",
        "class": "srf-vertical-control",
        "title": "Public Feedback Channel for High-Impact AI",
        "params": [
         {
          "id": "pubsec-srf-l1-ovr-006-p1",
          "label": "public_feedback_channel_operational",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "quarterly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a feedback channel exists for each public-facing high-impact use case, is listed in the inventory entry, and logs show review within the prior quarter."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-OVR-006"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Shared-Service"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agency"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "human-oversight-remedy"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "re-establish-feedback-channel; notify-CAIO; update-public-inventory-entry"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact and operational log. Candidate: api_activity (6003) if the feedback channel is a web form with logging."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-fedramp-20x-ksi",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l1-ovr-006_stmt",
          "name": "statement",
          "prose": "For each high-impact AI use case that affects the public, the agency must operate a public feedback channel allowing affected individuals to report concerns, errors, or adverse outcomes. The channel must be listed in the public use-case inventory entry and reviewed by the responsible office on the cadence defined in the compliance plan."
         },
         {
          "id": "pubsec-srf-l1-ovr-006_obj",
          "name": "objective",
          "prose": "Maintain public_feedback_channel_operational == {{ insert: param, pubsec-srf-l1-ovr-006-p1 }} over window quarterly. Breach action: re-establish-feedback-channel; notify-CAIO; update-public-inventory-entry."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(b)(vii) (Consult and Incorporate Feedback from End Users and the Public)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 4.2 (mechanisms are in place to collect and analyze feedback); GOVERN 6.1 (policies for engaging AI actors across life cycle)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l1-acq-007",
        "class": "srf-vertical-control",
        "title": "AI Acquisition Contract Compliance with M-25-22",
        "params": [
         {
          "id": "pubsec-srf-l1-acq-007-p1",
          "label": "m_25_22_contract_compliance_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual-review"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "1.0"
          ],
          "guidelines": [
           {
            "prose": "Percentage of AI service contracts entered or renewed since M-25-22 that include all required clauses. Recommended minimum 100%."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-ACQ-007"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Shared-Service"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agency"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition-integration"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "notify-contracting-officer; escalate-to-CAIO; flag-for-contract-remediation"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact. Contract records are governance documents."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-21",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-fedramp-20x-ksi",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l1-acq-007_stmt",
          "name": "statement",
          "prose": "All AI service contracts entered or renewed after the M-25-22 effective date must include the required performance terms, data rights clauses (agency data not used to train vendor models without consent), vendor lock-in avoidance provisions, and transparency requirements. The contracting officer and CAIO office must jointly certify compliance for each contract."
         },
         {
          "id": "pubsec-srf-l1-acq-007_obj",
          "name": "objective",
          "prose": "Maintain m_25_22_contract_compliance_pct == {{ insert: param, pubsec-srf-l1-acq-007-p1 }} over window annual-review. Breach action: notify-contracting-officer; escalate-to-CAIO; flag-for-contract-remediation."
         }
        ],
        "links": [
         {
          "href": "#ae7bd07d-92c3-5ea1-915d-6542ebb67973",
          "rel": "reference",
          "text": "Section 4(d)(iii) (Contract Terms)"
         },
         {
          "href": "#ae7bd07d-92c3-5ea1-915d-6542ebb67973",
          "rel": "reference",
          "text": "Section 4(c)(ii) (Protections Against Vendor Lock-In)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 5.1 (organizational risk policies include supply chain risk); GOVERN 5.2 (risk management frameworks include third-party AI providers)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-11 (Supply Chain Agreement Review)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l1-acq-008",
        "class": "srf-vertical-control",
        "title": "AI Staff Training and Assessment Coverage",
        "params": [
         {
          "id": "pubsec-srf-l1-acq-008-p1",
          "label": "ai_staff_training_completion_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual-review"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_STAFF_TRAINING_COMPLETION_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of staff operating or overseeing high-impact AI use cases who have completed current required training. Tier-configurable; recommended minimum 95%."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-ACQ-008"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Shared-Service"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agency"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition-integration"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "identify-untrained-staff; suspend-oversight-role-pending-training; notify-CAIO"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact. Training records are HR governance data."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-fedramp-20x-ksi",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l1-acq-008_stmt",
          "name": "statement",
          "prose": "Staff operating or overseeing high-impact AI use cases must complete agency-approved AI literacy and risk training before deployment and on the annual cadence defined in the compliance plan, per M-25-21 human training and assessment requirements. Training completion rates must be tracked by use case and reported to the CAIO."
         },
         {
          "id": "pubsec-srf-l1-acq-008_obj",
          "name": "objective",
          "prose": "Maintain ai_staff_training_completion_pct >= {{ insert: param, pubsec-srf-l1-acq-008-p1 }} over window annual-review. Breach action: identify-untrained-staff; suspend-oversight-role-pending-training; notify-CAIO."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(b)(iv) (Ensure Adequate Human Training and Assessment)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 3.1 (AI risk and benefit management is reflected in workforce and capacity planning); GOVERN 3.2 (AI risk awareness training is provided)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l1-mon-009",
        "class": "srf-vertical-control",
        "title": "AI Governance Board Review Cadence for High-Impact Use Cases",
        "params": [
         {
          "id": "pubsec-srf-l1-mon-009-p1",
          "label": "governance_board_review_on_cadence",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "quarterly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: board meeting minutes confirm reviews of all high-impact use cases at the charter-specified cadence in the prior review period."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-MON-009"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Shared-Service"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agency"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "convene-emergency-board-session; notify-CAIO; document-gap-in-compliance-plan"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact. Meeting minutes are governance records."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-fedramp-20x-ksi",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l1-mon-009_stmt",
          "name": "statement",
          "prose": "The agency AI governance board must formally review all high-impact AI use cases at the cadence specified in the board charter. Each review must assess minimum-practice compliance status, open remediation items, and any material changes since the prior review. Minutes must be retained and available to OMB on request."
         },
         {
          "id": "pubsec-srf-l1-mon-009_obj",
          "name": "objective",
          "prose": "Maintain governance_board_review_on_cadence == {{ insert: param, pubsec-srf-l1-mon-009-p1 }} over window quarterly. Breach action: convene-emergency-board-session; notify-CAIO; document-gap-in-compliance-plan."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 3(a)(ii) (Agency AI Governance Board)"
         },
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(b)(iii) (Conduct Ongoing Monitoring for Performance and Potential Adverse Impacts)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 2.2 (AI risk management accountability is maintained); MANAGE 4.1 (post-deployment AI risks are monitored)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-01 (Governance Program Policy and Procedures)"
         }
        ]
       }
      ]
     },
     {
      "id": "l1-healthcare",
      "class": "srf-vertical",
      "title": "L1 — Healthcare",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "healthcare"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/healthcare-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "hc-srf-l1-dev-001",
        "class": "srf-vertical-control",
        "title": "Clinical AI Risk Classification Policy",
        "params": [
         {
          "id": "hc-srf-l1-dev-001-p1",
          "label": "risk_classification_policy_approved",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual-review"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: board- or executive-approved AI risk classification policy exists, names an accountable executive, and covers all AI-enabled clinical systems in production."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-DEV-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance & Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-ai-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-new-ai-system-clinical-deployment"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "DocumentReference"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "status == 'current' AND category.code == 'clinical-ai-policy'"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-onc-hti1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l1-dev-001_stmt",
          "name": "statement",
          "prose": "The organization must publish a board- or executive-approved policy assigning FDA SaMD risk tiers (Class I, II, or III) and EU AI Act risk levels (limited, high) to all AI-enabled clinical systems. The policy must name a specific senior executive accountable for clinical AI risk and require tier re-classification upon any significant algorithm change."
         },
         {
          "id": "hc-srf-l1-dev-001_obj",
          "name": "objective",
          "prose": "Maintain risk_classification_policy_approved == {{ insert: param, hc-srf-l1-dev-001-p1 }} over window annual-review. Breach action: block-new-ai-system-clinical-deployment."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 3.1: Intended Use and Device Description"
         },
         {
          "href": "#5c236a56-0fd8-52fc-880b-5e213d233a3f",
          "rel": "reference",
          "text": "Principle 1: Focused scope with verifiable modifications"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (Risk management system)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§4.3: Software safety classification"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§4: Risk analysis"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.1 (legal and regulatory requirements are understood, managed, and documented); MAP 1.5 (organizational risk tolerances are determined)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-02 (Risk Management Program)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-10 (AI Impact Assessment)"
         }
        ]
       },
       {
        "id": "hc-srf-l1-dev-002",
        "class": "srf-vertical-control",
        "title": "Clinical AI System Inventory and Registry",
        "params": [
         {
          "id": "hc-srf-l1-dev-002-p1",
          "label": "ai_system_registry_completeness",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "at-system-onboarding"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: all AI-enabled clinical systems have a registry entry with required fields before first clinical use."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-DEV-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance & Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-ai-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-clinical-deployment"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Device"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "status, deviceName, version, owner, identifier (FDA 510k/De Novo number)"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-fda-pccp",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iso-14971",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l1-dev-002_stmt",
          "name": "statement",
          "prose": "The organization must maintain a complete registry of all AI-enabled clinical systems, including SaMD tier, intended use statement, FDA clearance or approval status, accountable clinician, and deployment date. New systems must be registered before clinical use."
         },
         {
          "id": "hc-srf-l1-dev-002_obj",
          "name": "objective",
          "prose": "Maintain ai_system_registry_completeness == {{ insert: param, hc-srf-l1-dev-002-p1 }} over window at-system-onboarding. Breach action: block-clinical-deployment."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 3.2: Device Description and Specifications"
         },
         {
          "href": "#8e4fc90b-6135-5c7a-81da-30efe01e36ad",
          "rel": "reference",
          "text": "§170.315(b)(11): Decision support interventions"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 51 (Registration of high-risk AI systems)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§5.1: Software development planning"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.6 (mechanisms are in place to inventory AI systems)"
         }
        ]
       },
       {
        "id": "hc-srf-l1-dev-003",
        "class": "srf-vertical-control",
        "title": "Clinical AI Ethics Committee and Oversight Charter",
        "params": [
         {
          "id": "hc-srf-l1-dev-003-p1",
          "label": "ai_governance_body_chartered",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual-review"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: clinical AI governance body exists with approved charter, named chairperson, and documented CMO/CMIO accountability."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-DEV-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance & Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-ai-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-board"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "DocumentReference"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "status == 'current' AND category.code == 'governance-charter'"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-onc-hti1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l1-dev-003_stmt",
          "name": "statement",
          "prose": "The organization must establish a clinical AI governance body (ethics committee, AI review board, or equivalent) with a named chairperson and clear CMO or CMIO accountability. The charter must define scope, meeting cadence, escalation criteria, and authority to suspend AI-enabled clinical systems."
         },
         {
          "id": "hc-srf-l1-dev-003_obj",
          "name": "objective",
          "prose": "Maintain ai_governance_body_chartered == {{ insert: param, hc-srf-l1-dev-003-p1 }} over window annual-review. Breach action: escalate-to-board."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 4.1: Organizational governance"
         },
         {
          "href": "#5c236a56-0fd8-52fc-880b-5e213d233a3f",
          "rel": "reference",
          "text": "Principle 3: Evidence-based with appropriate oversight"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (Risk management)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 14 (Human oversight)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§4.1: Quality management"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§3: General requirements"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 2.1 (roles, responsibilities, and lines of communication are documented); GOVERN 3.2 (policies define human-AI configurations and oversight)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-06 (Governance Responsibility Model)"
         }
        ]
       },
       {
        "id": "hc-srf-l1-hor-001",
        "class": "srf-vertical-control",
        "title": "Clinical AI Governance Review Cadence",
        "params": [
         {
          "id": "hc-srf-l1-hor-001-p1",
          "label": "governance_review_completed_on_cadence",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-approved-cadence"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary per review period: governance review meeting occurred, quorum met, and minutes archived within the approved cadence."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-HOR-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance & Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-ai-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "human-oversight-review"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-cmo"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AuditEvent"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "type.code == 'governance-review' AND outcome == '0' (success)"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-onc-hti1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l1-hor-001_stmt",
          "name": "statement",
          "prose": "The clinical AI governance body must convene on the approved cadence (minimum quarterly for high-risk SaMD, annually for low-risk) and produce documented reviews of system performance, adverse events, and algorithm change requests. Missed reviews constitute a control failure."
         },
         {
          "id": "hc-srf-l1-hor-001_obj",
          "name": "objective",
          "prose": "Maintain governance_review_completed_on_cadence == {{ insert: param, hc-srf-l1-hor-001-p1 }} over window per-approved-cadence. Breach action: escalate-to-cmo."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 4.1: Lifecycle management governance"
         },
         {
          "href": "#5c236a56-0fd8-52fc-880b-5e213d233a3f",
          "rel": "reference",
          "text": "Principle 5: Lifecycle-oriented oversight"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9(6) (Risk management review)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§4.1: Quality system review"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§3.4: Risk management review"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.5 (ongoing monitoring and periodic review of the risk management process are planned)"
         }
        ]
       },
       {
        "id": "hc-srf-l1-hor-002",
        "class": "srf-vertical-control",
        "title": "Acceptable Use Policy for Clinical AI",
        "params": [
         {
          "id": "hc-srf-l1-hor-002-p1",
          "label": "aup_current_and_enforced",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual-review"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: AUP published, covers all deployed AI systems, and clinical staff acknowledgment rate meets threshold."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-HOR-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance & Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-ai-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "human-oversight-review"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "suspend-ai-clinical-access"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "DocumentReference"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "status == 'current' AND category.code == 'acceptable-use-policy'"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-fda-pccp",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-62304",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iso-14971",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l1-hor-002_stmt",
          "name": "statement",
          "prose": "The organization must publish and enforce an acceptable use policy (AUP) covering all clinical AI systems in use. The AUP must address: permitted use cases, prohibited uses, required training for clinical staff, and consequences of misuse. Policy currency must be verified annually."
         },
         {
          "id": "hc-srf-l1-hor-002_obj",
          "name": "objective",
          "prose": "Maintain aup_current_and_enforced == {{ insert: param, hc-srf-l1-hor-002-p1 }} over window annual-review. Breach action: suspend-ai-clinical-access."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 2.4: User interface and intended use"
         },
         {
          "href": "#8e4fc90b-6135-5c7a-81da-30efe01e36ad",
          "rel": "reference",
          "text": "§170.315(b)(11)(vi): Transparency disclosures"
         },
         {
          "href": "#8d9146e5-7a72-5eac-a274-e74a728227e7",
          "rel": "reference",
          "text": "45 CFR §164.308(a)(5): Security awareness training"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 13 (Transparency)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 4 (AI literacy)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.2 (characteristics of trustworthy AI are integrated into organizational policies); GOVERN 2.2 (personnel receive AI risk management training)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-09 (Acceptable Use of the AI Service)"
         }
        ]
       },
       {
        "id": "hc-srf-l1-hor-003",
        "class": "srf-vertical-control",
        "title": "Clinician Override Documentation Policy",
        "params": [
         {
          "id": "hc-srf-l1-hor-003-p1",
          "label": "override_documentation_policy_enforced",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: override documentation policy exists, is enforced in EHR workflow, and override events are captured in AuditEvent."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-HOR-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance & Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-ai-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "human-oversight-review"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-cmo-and-governance-body"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AuditEvent"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "type.code == 'ai-recommendation-override' AND purposeOfEvent captured"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-62304",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iso-14971",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l1-hor-003_stmt",
          "name": "statement",
          "prose": "The organization must maintain a policy requiring clinicians to document when they override an AI recommendation, including the clinical rationale. Override events must be captured in the EHR audit log and reviewed as part of the governance cadence defined in SRF-L1-HOR-001."
         },
         {
          "id": "hc-srf-l1-hor-003_obj",
          "name": "objective",
          "prose": "Maintain override_documentation_policy_enforced == {{ insert: param, hc-srf-l1-hor-003-p1 }} over window continuous. Breach action: escalate-to-cmo-and-governance-body."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 4.3: Post-market performance feedback"
         },
         {
          "href": "#5c236a56-0fd8-52fc-880b-5e213d233a3f",
          "rel": "reference",
          "text": "Principle 2: Risk-based with patient safety focus"
         },
         {
          "href": "#8e4fc90b-6135-5c7a-81da-30efe01e36ad",
          "rel": "reference",
          "text": "§170.315(b)(11): DSI transparency including override tracking"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 14(4) (Human oversight measures)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 3.2 (policies define human-AI configurations and oversight); MANAGE 4.1 (post-deployment monitoring captures input from users)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-15 (Human supervision)"
         }
        ]
       },
       {
        "id": "hc-srf-l1-pms-001",
        "class": "srf-vertical-control",
        "title": "FDA Regulatory Filing Currency",
        "params": [
         {
          "id": "hc-srf-l1-pms-001-p1",
          "label": "regulatory_filing_current",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: all production SaMD have current FDA marketing authorization or documented CDS non-device determination."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-PMS-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance & Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-ai-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "post-market-surveillance"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-legal-and-suspend-system"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Device"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "identifier (FDA 510k/De Novo number), property (authorization status)"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-fda-pccp",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-onc-hti1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iso-14971",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l1-pms-001_stmt",
          "name": "statement",
          "prose": "All SaMD in clinical production must have current FDA marketing authorization (510(k), De Novo, or PMA as applicable) or be classified as non-device clinical decision support (CDS) under the 21st Century Cures Act with documented rationale. Filing status must be tracked in the system registry and reviewed at each governance cycle."
         },
         {
          "id": "hc-srf-l1-pms-001_obj",
          "name": "objective",
          "prose": "Maintain regulatory_filing_current == {{ insert: param, hc-srf-l1-pms-001-p1 }} over window continuous. Breach action: escalate-to-legal-and-suspend-system."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 3: Marketing authorization and lifecycle"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 43 (Conformity assessment)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§4.3: Regulatory compliance"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.1 (legal and regulatory requirements are understood, managed, and documented)"
         }
        ]
       },
       {
        "id": "hc-srf-l1-pms-002",
        "class": "srf-vertical-control",
        "title": "Medical Device Adverse Event Reporting Readiness",
        "params": [
         {
          "id": "hc-srf-l1-pms-002-p1",
          "label": "mdr_reporting_process_tested",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual-test"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: MDR reporting process documented, tested annually, and all AI-related adverse events captured in FHIR AdverseEvent."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-PMS-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance & Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-ai-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "post-market-surveillance"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-quality-and-compliance"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AdverseEvent"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "actuality, seriousness, suspectEntity (device reference)"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-fda-pccp",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-onc-hti1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l1-pms-002_stmt",
          "name": "statement",
          "prose": "The organization must maintain a documented process for detecting, evaluating, and reporting AI-related adverse events to FDA per 21 CFR Part 803 (Medical Device Reporting). The process must be tested annually with a tabletop exercise, and all AI-related adverse events must be logged in FHIR AdverseEvent."
         },
         {
          "id": "hc-srf-l1-pms-002_obj",
          "name": "objective",
          "prose": "Maintain mdr_reporting_process_tested == {{ insert: param, hc-srf-l1-pms-002-p1 }} over window annual-test. Breach action: escalate-to-quality-and-compliance."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 4.4: Adverse event reporting"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 73 (Reporting of serious incidents)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§6.2: Problem resolution process"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§10: Post-production information"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 4.3 (incidents and errors are communicated to relevant AI actors and authorities)"
         }
        ]
       },
       {
        "id": "hc-srf-l1-pms-003",
        "class": "srf-vertical-control",
        "title": "PCCP Algorithm Change Governance",
        "params": [
         {
          "id": "hc-srf-l1-pms-003-p1",
          "label": "pccp_change_governance_active",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "at-each-model-update"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: PCCP-aligned change review occurs before each algorithm update; unauthorized out-of-scope updates are blocked."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-PMS-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance & Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-ai-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "post-market-surveillance"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "rollback-and-escalate-to-regulatory"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Provenance"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "entity (model version), activity.code == 'pccp-change-review', agent (reviewer)"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-onc-hti1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l1-pms-003_stmt",
          "name": "statement",
          "prose": "For AI systems with an FDA-approved Predetermined Change Control Plan, the organization must operate a change governance process that ensures all algorithm updates fall within the approved PCCP modification scope. Changes outside PCCP scope require a new FDA submission before deployment."
         },
         {
          "id": "hc-srf-l1-pms-003_obj",
          "name": "objective",
          "prose": "Maintain pccp_change_governance_active == {{ insert: param, hc-srf-l1-pms-003-p1 }} over window at-each-model-update. Breach action: rollback-and-escalate-to-regulatory."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 4: Total lifecycle change management"
         },
         {
          "href": "#5c236a56-0fd8-52fc-880b-5e213d233a3f",
          "rel": "reference",
          "text": "All five principles"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 43 (Conformity of substantially modified systems)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§6: Software maintenance"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§10: Post-production feedback"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.1 (regulatory change obligations are documented); MANAGE 2.2 (mechanisms are in place to sustain the value of deployed AI systems)"
         }
        ]
       }
      ]
     },
     {
      "id": "l1-insurance",
      "class": "srf-vertical",
      "title": "L1 — Insurance",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "insurance"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/insurance-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "ins-srf-l1-dev-001",
        "class": "srf-vertical-control",
        "title": "AIS Program Document Currency and Board Approval",
        "params": [
         {
          "id": "ins-srf-l1-dev-001-p1",
          "label": "ais_program_board_approved",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual-review"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a written AIS Program exists, carries board or executive approval dated within the prior review cycle, and covers all four required areas."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-DEV-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-board; notify-chief-compliance-officer; block-new-ai-system-deployment"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact. AIS Program approval is a governance record, not streaming telemetry. Store as a versioned policy document with board approval metadata. Candidate OCSF class: audit_activity (3002) if the document management system emits approval events to SIEM."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l1-dev-001_stmt",
          "name": "statement",
          "prose": "The insurer must maintain a written AI Systems (AIS) Program approved by the board or a designated senior executive. The program must cover governance structure, risk management framework, internal controls, and third-party AI oversight. It must be reviewed and reapproved on the cadence defined in SRF-L1-MON-001 and be available to the regulator on request per CO Regulation 10-1-1."
         },
         {
          "id": "ins-srf-l1-dev-001_obj",
          "name": "objective",
          "prose": "Maintain ais_program_board_approved == {{ insert: param, ins-srf-l1-dev-001-p1 }} over window annual-review. Breach action: escalate-to-board; notify-chief-compliance-officer; block-new-ai-system-deployment."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 1.3 (AIS Program vests responsibility with senior management accountable to the board)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit B (Checklist), Ref 1 (written AIS Program adopted, frequency of review)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit B (Checklist), Ref 2/2a (Board or management involvement and role)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(A)(2)-(3) (governance structure overseen by the board or a committee of the board, senior management responsibility and accountability)"
         },
         {
          "href": "#c59939b3-2e4d-575b-878c-2a4ff0ee3ea1",
          "rel": "reference",
          "text": "Section III.A, paragraphs 21-24 (Board and Senior Management Oversight)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (risk management system)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 17 (quality management system)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.1 (legal and regulatory requirements are understood, managed, and documented); GOVERN 2.3 (executive leadership takes responsibility for AI risk decisions)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-01 (Governance Program Policy and Procedures)"
         }
        ]
       },
       {
        "id": "ins-srf-l1-dev-002",
        "class": "srf-vertical-control",
        "title": "AI System Inventory Coverage",
        "params": [
         {
          "id": "ins-srf-l1-dev-002-p1",
          "label": "ai_system_inventory_coverage_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "quarterly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_AI_INVENTORY_COVERAGE_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of known production AI systems appearing in the current inventory. Tier-configurable; recommended minimum 95%."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-DEV-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "identify-unregistered-systems; suspend-unregistered-ai-deployments; report-to-chief-compliance-officer"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact at L1. Continuous coverage tracking can use api_activity (6003) if the inventory system exposes an API that logs registration events to SIEM."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-nydfs-cl7",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l1-dev-002_stmt",
          "name": "statement",
          "prose": "The insurer must maintain a current inventory of all AI systems in use across all lines of business covered by the AIS Program. The inventory must record system name, vendor (if third-party), line of business, risk tier, accountable officer, and deployment date. Coverage is defined as the percentage of known production AI systems appearing in the inventory."
         },
         {
          "id": "ins-srf-l1-dev-002_obj",
          "name": "objective",
          "prose": "Maintain ai_system_inventory_coverage_pct >= {{ insert: param, ins-srf-l1-dev-002-p1 }} over window quarterly. Breach action: identify-unregistered-systems; suspend-unregistered-ai-deployments; report-to-chief-compliance-officer."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 3.3(a) (inventories and descriptions of Predictive Models)"
         },
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 4, Item 1.3(c)(i) (inventories and descriptions of Predictive Models and AI Systems)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit A (quantify AI System model counts currently in use by operations/program area)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(A)(9) (documented up-to-date inventory, including version control, of all utilized ECDIS, algorithms, and predictive models)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 17 (quality management system, inventory of high-risk systems)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.6 (mechanisms are in place to inventory AI systems)"
         }
        ]
       },
       {
        "id": "ins-srf-l1-dev-003",
        "class": "srf-vertical-control",
        "title": "Third-Party AI Vendor Register with Named Accountable Officer",
        "params": [
         {
          "id": "ins-srf-l1-dev-003-p1",
          "label": "vendor_register_accountable_officer_coverage",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual-review"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a third-party AI vendor register exists, every vendor entry names an accountable officer, and the register was reviewed within the prior review cycle."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-DEV-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "identify-vendors-without-accountable-officer; freeze-new-vendor-onboarding; escalate-to-chief-risk-officer"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact. Vendor register is a governance record. Candidate: audit_activity (3002) if vendor management platform emits change events."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l1-dev-003_stmt",
          "name": "statement",
          "prose": "The insurer must maintain a register of all third-party AI vendors whose systems are used in underwriting, rating, claims, or consumer-facing workflows. Each vendor entry must name the insurer-side accountable officer responsible for oversight of that vendor relationship, consistent with the NAIC Model Bulletin's third-party oversight requirements."
         },
         {
          "id": "ins-srf-l1-dev-003_obj",
          "name": "objective",
          "prose": "Maintain vendor_register_accountable_officer_coverage == {{ insert: param, ins-srf-l1-dev-003-p1 }} over window annual-review. Breach action: identify-vendors-without-accountable-officer; freeze-new-vendor-onboarding; escalate-to-chief-risk-officer."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 4.1 (due diligence on third parties to ensure decisions meet the legal standards imposed on the insurer)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit B (Checklist), Ref 3l (standards and guidance for procuring and engaging AI System vendors)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(A)(13) (documented description of the process for selecting external resources including third-party vendors)"
         },
         {
          "href": "#c59939b3-2e4d-575b-878c-2a4ff0ee3ea1",
          "rel": "reference",
          "text": "Section III.D, paragraphs 35-37 (Third-Party Vendors: oversight of tools, ECDIS, or AIS developed or deployed by third-party vendors)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 26 (obligations of deployers of high-risk AI systems)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 25 (responsibilities along the AI value chain)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 6.1 (policies address AI risks associated with third-party entities); GOVERN 2.1 (roles and responsibilities are documented)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-14 (Supply Chain Governance Review)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-06 (Governance Responsibility Model)"
         }
        ]
       },
       {
        "id": "ins-srf-l1-dev-004",
        "class": "srf-vertical-control",
        "title": "Adverse-Decision Appeal Process Documentation",
        "params": [
         {
          "id": "ins-srf-l1-dev-004-p1",
          "label": "adverse_decision_appeal_process_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual-review"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: documented appeal process exists, names the accountable function, specifies the review timeline, and has been reviewed by legal and compliance within the prior annual cycle."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-DEV-004"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-chief-compliance-officer; halt-AI-assisted-adverse-decisions-pending-remediation"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact. Candidate: audit_activity (3002) for policy publication events."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l1-dev-004_stmt",
          "name": "statement",
          "prose": "The insurer must document and publish (internally and, where required, to consumers) a process by which consumers can appeal or seek human review of adverse decisions made with AI assistance, including coverage denials, premium increases, and claims denials. The process must name the accountable function, specify the review timeline, and comply with applicable state requirements."
         },
         {
          "id": "ins-srf-l1-dev-004_obj",
          "name": "objective",
          "prose": "Maintain adverse_decision_appeal_process_documented == {{ insert: param, ins-srf-l1-dev-004-p1 }} over window annual-review. Breach action: escalate-to-chief-compliance-officer; halt-AI-assisted-adverse-decisions-pending-remediation."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 1.9 (notice to consumers that AI Systems are in use and access to appropriate levels of information)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit B (Checklist), Ref 3m (consumer complaints from AI Systems identified, tracked, addressed)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit B (Checklist), Ref 3n (consumer awareness through disclosures and notification procedures)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(A)(7) (documented processes and protocols for addressing applicant, policyholder, beneficiary, or covered person complaints and providing information necessary to take meaningful action on an adverse decision)"
         },
         {
          "href": "#c59939b3-2e4d-575b-878c-2a4ff0ee3ea1",
          "rel": "reference",
          "text": "Section IV.E, paragraphs 38-41 (Disclosure and Notice: right to request information and specific reasons for an adverse underwriting or pricing decision)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 86 (right to explanation of individual decision-making for high-risk AI systems)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 5.1 (policies are in place to collect and integrate feedback from those outside the team); GOVERN 3.2 (policies define human-AI configurations and oversight)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-15 (Human supervision)"
         }
        ]
       },
       {
        "id": "ins-srf-l1-dev-005",
        "class": "srf-vertical-control",
        "title": "Governance Framework Availability Readiness for CO Regulation 10-1-1",
        "params": [
         {
          "id": "ins-srf-l1-dev-005-p1",
          "label": "co_framework_package_availability_ready",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Zero-tolerance: the governance framework package is assembled and can be produced to the Colorado Division of Insurance within the regulatory response window. Failure means the insurer cannot demonstrate compliance on request."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-DEV-005"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "immediate-escalation-to-general-counsel; suspend-AI-use-in-CO-auto-and-health-lines-pending-remediation"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact. Readiness is a procedural verification, not streaming telemetry."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-naic-model-bulletin",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-naic-eval-tool",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nydfs-cl7",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-eu-ai-act",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l1-dev-005_stmt",
          "name": "statement",
          "prose": "Insurers writing private passenger auto or health benefit plans in Colorado must have their complete AI governance structure and risk management framework available to the Division of Insurance on request from July 1, 2026. This control verifies that the framework package (AIS Program, system inventory, risk assessments, audit logs) is assembled, current, and accessible within the required response window."
         },
         {
          "id": "ins-srf-l1-dev-005_obj",
          "name": "objective",
          "prose": "Maintain co_framework_package_availability_ready == {{ insert: param, ins-srf-l1-dev-005-p1 }} over window continuous. Breach action: immediate-escalation-to-general-counsel; suspend-AI-use-in-CO-auto-and-health-lines-pending-remediation."
         }
        ],
        "links": [
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(C) (governance and risk management framework must be available to the Division on request, auto and health benefit plan insurers, July 1, 2026)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.1 (legal and regulatory requirements are understood, managed, and documented)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-01 (Governance Program Policy and Procedures)"
         }
        ]
       },
       {
        "id": "ins-srf-l1-mon-001",
        "class": "srf-vertical-control",
        "title": "AI Risk Appetite Statement Review Cadence",
        "params": [
         {
          "id": "ins-srf-l1-mon-001-p1",
          "label": "risk_appetite_statement_reviewed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "12mo"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: board-approved AI risk appetite statement reviewed and reapproved within the prior 12 months, and within 90 days of any material scope change."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-MON-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-board-risk-committee; flag-in-annual-compliance-report"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact. Candidate: audit_activity (3002) for board approval events."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-ai-act",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l1-mon-001_stmt",
          "name": "statement",
          "prose": "The insurer must maintain a board-approved AI risk appetite statement that names a specific senior executive accountable for AI risk. The statement must define risk tolerance thresholds by line of business and operating model and must be reviewed and reapproved on the cadence defined here. Significant changes in AI system scope or a material market conduct exam finding trigger an out-of-cycle review."
         },
         {
          "id": "ins-srf-l1-mon-001_obj",
          "name": "objective",
          "prose": "Maintain risk_appetite_statement_reviewed == {{ insert: param, ins-srf-l1-mon-001-p1 }} over window 12mo. Breach action: escalate-to-board-risk-committee; flag-in-annual-compliance-report."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 1.3 (senior management accountable to the board for AI System strategy - no fixed review cadence specified in the bulletin)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit B (Checklist), Ref 1 (frequency of review for updating the AIS Program)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(A)(14) (documented comprehensive annual reviews of the governance structure and risk management framework)"
         },
         {
          "href": "#c59939b3-2e4d-575b-878c-2a4ff0ee3ea1",
          "rel": "reference",
          "text": "Section III.B, paragraph 26 (board, governing body, or senior management reviews and approves ECDIS/AIS policies and procedures at least annually)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 1.5 (organizational risk tolerances are determined); GOVERN 1.5 (periodic review of the risk management process is planned)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-02 (Risk Management Program)"
         }
        ]
       },
       {
        "id": "ins-srf-l1-mon-002",
        "class": "srf-vertical-control",
        "title": "Senior Management Accountability Designation for AI Governance",
        "params": [
         {
          "id": "ins-srf-l1-mon-002-p1",
          "label": "senior_officer_designation_current",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual-review"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a named senior officer designation exists, is current (updated within 30 days of any change), and is included in the AIS Program."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-MON-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-board; flag-for-regulatory-disclosure"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-ai-act",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l1-mon-002_stmt",
          "name": "statement",
          "prose": "The insurer must designate a named senior officer accountable for the AIS Program, with documented authority, responsibilities, and reporting line. The designation must be reviewed annually and updated within 30 days of any change in the responsible officer."
         },
         {
          "id": "ins-srf-l1-mon-002_obj",
          "name": "objective",
          "prose": "Maintain senior_officer_designation_current == {{ insert: param, ins-srf-l1-mon-002-p1 }} over window annual-review. Breach action: escalate-to-board; flag-for-regulatory-disclosure."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 1.3 (AIS Program vests responsibility with senior management accountable to the board)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit B (Checklist), Ref 2/2a (Board or management involvement and role in the AI Systems Governance Framework)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(A)(3) (senior management responsibility and accountability for setting and monitoring the overall strategy)"
         },
         {
          "href": "#c59939b3-2e4d-575b-878c-2a4ff0ee3ea1",
          "rel": "reference",
          "text": "Section III.A, paragraphs 21-24 (Board and Senior Management Oversight)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 2.1 (roles, responsibilities, and lines of communication are documented); GOVERN 2.3 (executive leadership takes responsibility)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-06 (Governance Responsibility Model)"
         }
        ]
       },
       {
        "id": "ins-srf-l1-tpo-001",
        "class": "srf-vertical-control",
        "title": "Third-Party AIS Program Alignment Review",
        "params": [
         {
          "id": "ins-srf-l1-tpo-001-p1",
          "label": "vendor_ais_program_review_completed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "12mo"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: annual governance review completed for each in-scope third-party AI vendor, findings documented, and results incorporated into vendor risk ratings."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-TPO-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "third-party-oversight"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-chief-risk-officer; freeze-new-vendor-deployments; initiate-remediation-plan"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact. Vendor review findings are governance records."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l1-tpo-001_stmt",
          "name": "statement",
          "prose": "The insurer must annually review each third-party AI vendor's AIS Program (or equivalent governance documentation) to confirm it meets or exceeds the insurer's own standards. The review must be documented, findings tracked to resolution, and results factored into vendor risk ratings. Insurers remain accountable for vendor AI outcomes under the NAIC Model Bulletin."
         },
         {
          "id": "ins-srf-l1-tpo-001_obj",
          "name": "objective",
          "prose": "Maintain vendor_ais_program_review_completed == {{ insert: param, ins-srf-l1-tpo-001-p1 }} over window 12mo. Breach action: escalate-to-chief-risk-officer; freeze-new-vendor-deployments; initiate-remediation-plan."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 4.1 (due diligence on third-party AI Systems and data)"
         },
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 4, Item 2.1 (due diligence conducted on third parties)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit B (Narrative), Q3 (policy for, and oversight of, material AI System vendors, model design and testing)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(A)(13) (process for selecting external resources and third-party vendors)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(B) (insurer remains responsible for Section 5(A) requirements when using third-party vendors)"
         },
         {
          "href": "#c59939b3-2e4d-575b-878c-2a4ff0ee3ea1",
          "rel": "reference",
          "text": "Section III.D, paragraphs 35-37 (Third-Party Vendors)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 25 (responsibilities along the AI value chain)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 6.1 (policies address AI risks associated with third-party entities); MANAGE 3.1 (AI risks from third-party resources are monitored)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-14 (Supply Chain Governance Review)"
         }
        ]
       },
       {
        "id": "ins-srf-l1-tpo-002",
        "class": "srf-vertical-control",
        "title": "Market Conduct Exam Readiness Documentation Package",
        "params": [
         {
          "id": "ins-srf-l1-tpo-002-p1",
          "label": "exam_readiness_package_current",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "6mo"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: documentation package exists, covers all NAIC Evaluation Tool dimensions, is indexed, and was reviewed within the prior 6 months."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-TPO-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "third-party-oversight"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-general-counsel; convene-exam-readiness-task-force"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-nydfs-cl7",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-eu-ai-act",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l1-tpo-002_stmt",
          "name": "statement",
          "prose": "The insurer must maintain a documentation package structured for market conduct exam review, covering governance, risk management, internal controls, and third-party oversight dimensions as reflected in the NAIC AI Systems Evaluation Tool. The package must be current, indexed, and producible within the insurer's exam response SLA."
         },
         {
          "id": "ins-srf-l1-tpo-002_obj",
          "name": "objective",
          "prose": "Maintain exam_readiness_package_current == {{ insert: param, ins-srf-l1-tpo-002-p1 }} over window 6mo. Breach action: escalate-to-general-counsel; convene-exam-readiness-task-force."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 4 (Regulatory Oversight and Examination Considerations, Items 1.1-2.4: documentation the Department may request in an investigation or market conduct action)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibits A-D (full evaluation submission package used to supplement market conduct, financial analysis, and financial examination review)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(C) (governance and risk management framework must be available to the Division on request)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.1 (regulatory requirements are documented); MEASURE 2.8 (transparency and accountability are examined)"
         }
        ]
       }
      ]
     },
     {
      "id": "l1-defense",
      "class": "srf-vertical",
      "title": "L1 — Defense",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "defense"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/defense-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "def-srf-l1-acq-001",
        "class": "srf-vertical-control",
        "title": "AI Use Case Registry and CDAO Reporting",
        "params": [
         {
          "id": "def-srf-l1-acq-001-p1",
          "label": "ai_registry_coverage_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "quarterly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_AI_REGISTRY_COVERAGE_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of known production AI systems appearing in the current CDAO-reported registry."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-ACQ-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "identify-unregistered-systems; notify-program-manager; escalate-to-CDAO"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Registry publication and update events may map to audit_activity (3002) if the registry system emits SIEM events."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l1-acq-001_stmt",
          "name": "statement",
          "prose": "The DoD component must maintain a current registry of all AI systems in development or operation, record each system's operating model, impact level, NSS determination, accountable program manager, and TEVV status, and report to CDAO on the schedule established by the DoD AI Inventory directive. Unregistered systems must be identified and added within 30 days of discovery."
         },
         {
          "id": "def-srf-l1-acq-001_obj",
          "name": "objective",
          "prose": "Maintain ai_registry_coverage_pct >= {{ insert: param, def-srf-l1-acq-001-p1 }} over window quarterly. Breach action: identify-unregistered-systems; notify-program-manager; escalate-to-CDAO."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Governable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 1.2.4 (DoD AI Inventory reporting to CDAO)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.1"
         }
        ]
       },
       {
        "id": "def-srf-l1-acq-002",
        "class": "srf-vertical-control",
        "title": "Responsible AI Officer Designation",
        "params": [
         {
          "id": "def-srf-l1-acq-002-p1",
          "label": "rai_officer_designation_current",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a named RAI Officer (or equivalent) is designated, documented, and has been confirmed active within the prior annual cycle."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-ACQ-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "flag-gap-to-CDAO; initiate-designation-within-30-days"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document. Designation memo is a static artifact; periodic review events may map to audit_activity (3002)."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l1-acq-002_stmt",
          "name": "statement",
          "prose": "Each DoD component deploying AI systems must designate a Responsible AI Officer (or equivalent role under CDAO guidance) responsible for RAI principle adherence, incident escalation, and annual compliance attestation. The designation must be documented, current, and communicated to CDAO."
         },
         {
          "id": "def-srf-l1-acq-002_obj",
          "name": "objective",
          "prose": "Maintain rai_officer_designation_current == {{ insert: param, def-srf-l1-acq-002-p1 }} over window annual. Breach action: flag-gap-to-CDAO; initiate-designation-within-30-days."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Governable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 1.1.2 (designate DoD Component RAI Leads)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.2"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-06 (Governance Responsibility Model)"
         }
        ]
       },
       {
        "id": "def-srf-l1-acq-003",
        "class": "srf-vertical-control",
        "title": "AI Governance Board with CDAO Oversight Link",
        "params": [
         {
          "id": "def-srf-l1-acq-003-p1",
          "label": "governance_board_meeting_cadence_met",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "quarterly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: the Board has met at its chartered cadence in the prior period, quorum was achieved, and decisions were recorded."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-ACQ-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "schedule-missed-meeting; notify-RAI-officer; document-gap"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance artifact. Meeting minutes and decision records are static documents; may map to audit_activity (3002)."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l1-acq-003_stmt",
          "name": "statement",
          "prose": "The component must establish an AI Governance Board (or equivalent body) with a defined charter, meeting cadence, quorum requirements, and a documented reporting line to CDAO. The Board must review high-risk AI use cases before operational deployment and record decisions."
         },
         {
          "id": "def-srf-l1-acq-003_obj",
          "name": "objective",
          "prose": "Maintain governance_board_meeting_cadence_met == {{ insert: param, def-srf-l1-acq-003-p1 }} over window quarterly. Breach action: schedule-missed-meeting; notify-RAI-officer; document-gap."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Governable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 1.1.7 (update DoD governance framework for AI development and delivery)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 2.2"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-06 (Governance Responsibility Model)"
         }
        ]
       },
       {
        "id": "def-srf-l1-acq-004",
        "class": "srf-vertical-control",
        "title": "DoD RAI Compliance Plan (Five-Principle Assessment)",
        "params": [
         {
          "id": "def-srf-l1-acq-004-p1",
          "label": "rai_compliance_plan_complete",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a RAI compliance plan exists for the system, covers all five principles, and was reviewed within the prior annual cycle."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-ACQ-004"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Equitable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Traceable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-deployment; notify-RAI-officer; produce-plan-within-60-days"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Plan review events may map to audit_activity (3002)."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l1-acq-004_stmt",
          "name": "statement",
          "prose": "Before deploying an AI system, the component must produce a written RAI compliance plan assessing the system against all five DoD RAI principles (Responsible, Equitable, Traceable, Reliable, Governable). The plan must name the accountable official for each principle, identify gaps, and set remediation timelines."
         },
         {
          "id": "def-srf-l1-acq-004_obj",
          "name": "objective",
          "prose": "Maintain rai_compliance_plan_complete == {{ insert: param, def-srf-l1-acq-004-p1 }} over window annual. Breach action: block-deployment; notify-RAI-officer; produce-plan-within-60-days."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "All five RAI principles"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Tenet 3 goal (AI risks considered from the outset with robust documentation)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.3"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-01 (Governance Program Policy and Procedures)"
         }
        ]
       },
       {
        "id": "def-srf-l1-acq-005",
        "class": "srf-vertical-control",
        "title": "AI Acquisition Requirements per DoDI 5000.90",
        "params": [
         {
          "id": "def-srf-l1-acq-005-p1",
          "label": "ai_acq_requirements_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-contract"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: every AI contract or task order includes the required DoDI 5000.90 clauses as verified by the contracting officer."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-ACQ-005"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "flag-contract-for-modification; notify-contracting-officer"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Contract document artifact. Acquisition events may map to audit_activity (3002)."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l1-acq-005_stmt",
          "name": "statement",
          "prose": "Contracting officers and program managers must document AI-specific acquisition requirements in the solicitation or contract in accordance with DoDI 5000.90. Requirements include transparency card delivery, TEVV access, data rights, and vendor incident notification obligations."
         },
         {
          "id": "def-srf-l1-acq-005_obj",
          "name": "objective",
          "prose": "Maintain ai_acq_requirements_documented == {{ insert: param, def-srf-l1-acq-005-p1 }} over window per-contract. Breach action: flag-contract-for-modification; notify-contracting-officer."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Responsible principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 3.1.1 (Acquisition Toolkit: standard AI contract language for T&E access, vendor documentation, and data rights)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.6"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-11 (Supply Chain Agreement Review)"
         }
        ]
       },
       {
        "id": "def-srf-l1-acq-006",
        "class": "srf-vertical-control",
        "title": "AI Supply Chain Risk Assessment",
        "params": [
         {
          "id": "def-srf-l1-acq-006-p1",
          "label": "supply_chain_risk_assessment_complete",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-acquisition"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a supply chain risk assessment exists for every AI system in the registry, covers required provenance dimensions, and was completed before contract award."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-ACQ-006"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.11.1"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.11.2"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-contract-award; notify-PM; escalate-to-program-security-officer"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Candidate OCSF class: audit_activity (3002)."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 15: Service Provider Management"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l1-acq-006_stmt",
          "name": "statement",
          "prose": "Before acquiring an AI system or foundation model, the program must conduct a supply chain risk assessment covering the provenance of training data, model weights, third-party components, and hosting infrastructure. The assessment must identify foreign-origin components and apply appropriate ITAR/EAR and supply chain risk management controls."
         },
         {
          "id": "def-srf-l1-acq-006_obj",
          "name": "objective",
          "prose": "Maintain supply_chain_risk_assessment_complete == {{ insert: param, def-srf-l1-acq-006-p1 }} over window per-acquisition. Breach action: block-contract-award; notify-PM; escalate-to-program-security-officer."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Reliable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 2.1.7 (DoD-wide AI security guidance leveraging supply chain security best practices)"
         },
         {
          "href": "#289aed16-d1f7-58b5-b179-0353578d8705",
          "rel": "reference",
          "text": "Section 3.4 (Cybersecurity in the Supply Chain)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "RA.L2-3.11.1 (periodic risk assessments)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "RA.L3-3.11.6e (assess, respond to, and monitor supply chain risks - Level 3)"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.11.1"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 5.1"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM03: Supply Chain"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-14 (Supply Chain Governance Review)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-11 (Supply Chain Agreement Review)"
         }
        ]
       },
       {
        "id": "def-srf-l1-acq-007",
        "class": "srf-vertical-control",
        "title": "Operator and Commander AI Training Program",
        "params": [
         {
          "id": "def-srf-l1-acq-007-p1",
          "label": "ai_training_completion_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_TRAINING_COMPLETION_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of designated operators and commanders who have completed current AI training within the required refresh cycle."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-ACQ-007"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Equitable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.2.1"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.2.2"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "restrict-system-access-for-untrained-personnel; notify-supervisor"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Training completion records. May map to audit_activity (3002) if the learning management system emits completion events."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l1-acq-007_stmt",
          "name": "statement",
          "prose": "The component must establish a training program covering AI capabilities, limitations, failure modes, and RAI principles for every operator and commander using or authorizing AI-assisted decisions. Training completion must be tracked and refreshed at least annually or upon significant model update."
         },
         {
          "id": "def-srf-l1-acq-007_obj",
          "name": "objective",
          "prose": "Maintain ai_training_completion_pct >= {{ insert: param, def-srf-l1-acq-007-p1 }} over window annual. Breach action: restrict-system-access-for-untrained-personnel; notify-supervisor."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Responsible principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Equitable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 2.2.1 (vendor training and documentation before fielding)"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 6.2.2 (integrate RAI curricula into Component AI training programs)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "AT.L2-3.2.1 (security awareness training)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "AT.L2-3.2.2 (personnel trained for assigned security duties)"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.2.1"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 4.1"
         }
        ]
       },
       {
        "id": "def-srf-l1-ops-008",
        "class": "srf-vertical-control",
        "title": "AI Incident Reporting to CDAO",
        "params": [
         {
          "id": "def-srf-l1-ops-008-p1",
          "label": "incident_report_timeliness_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "rolling-90-day"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_INCIDENT_REPORT_TIMELINESS_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of AI incidents reported to CDAO within the required window from time of discovery."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-OPS-008"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.6.1"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.6.2"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-RAI-officer; submit-late-report-with-explanation"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "security_finding (2001) or incident (6002). Incident records must capture system ID, time of discovery, description, and operator action taken."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l1-ops-008_stmt",
          "name": "statement",
          "prose": "The component must report AI incidents (unexpected outputs, operator overrides of consequential decisions, system failures, and adversarial attacks) to CDAO within the required reporting window. An incident response procedure must be documented, tested annually, and linked to the system's ATO."
         },
         {
          "id": "def-srf-l1-ops-008_obj",
          "name": "objective",
          "prose": "Maintain incident_report_timeliness_pct >= {{ insert: param, def-srf-l1-ops-008-p1 }} over window rolling-90-day. Breach action: escalate-to-RAI-officer; submit-late-report-with-explanation."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Governable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 1.1.6 (methods to report AI Ethical Principles concerns)"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 2.2.3 (operator processes to report changes in capability performance and emergent behavior)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "IR.L2-3.6.1 (operational incident-handling capability)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "IR.L2-3.6.2 (track, document, and report incidents)"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.6.1"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "RESPOND 1.1"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "LOG-13 (Failures and Anomalies Reporting)"
         }
        ]
       },
       {
        "id": "def-srf-l1-acq-009",
        "class": "srf-vertical-control",
        "title": "NSS Boundary Classification Determination",
        "params": [
         {
          "id": "def-srf-l1-acq-009-p1",
          "label": "nss_determination_memo_exists",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-system"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a signed NSS boundary determination memo exists in the ATO package for every AI system in the registry."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-ACQ-009"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-ATO; notify-AO; produce-determination-memo"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Signed determination memo is a static ATO artifact."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l1-acq-009_stmt",
          "name": "statement",
          "prose": "Before deployment, the component must produce and retain a written NSS boundary determination memo signed by the authorizing official. The memo must cite 44 USC 3552(b)(6), document the factors considered, state whether the system is NSS or non-NSS, and specify the resulting security requirements (CNSSI 1253 baseline for NSS; NIST 800-53 for non-NSS)."
         },
         {
          "id": "def-srf-l1-acq-009_obj",
          "name": "objective",
          "prose": "Maintain nss_determination_memo_exists == {{ insert: param, def-srf-l1-acq-009-p1 }} over window per-system. Breach action: block-ATO; notify-AO; produce-determination-memo."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Responsible principle"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.7"
         },
         {
          "href": "#c5d89a8d-2be1-526a-977f-3cc51013206f",
          "rel": "reference",
          "text": "Mission Owner SRG Section 3.3.3 (Choosing the Information Impact Level: IL5 includes unclassified NSS)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-04 (Data Classification)"
         }
        ]
       },
       {
        "id": "def-srf-l1-tevv-010",
        "class": "srf-vertical-control",
        "title": "TEVV Plan Existence and Approval Before Operational Deployment",
        "params": [
         {
          "id": "def-srf-l1-tevv-010-p1",
          "label": "tevv_plan_approved_before_deployment",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-system"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: an approved TEVV plan exists in the program record for every AI system at or beyond initial operational capability."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-TEVV-010"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Traceable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "tevv"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-deployment; notify-PM; escalate-to-AO"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. TEVV plan approval is a static milestone record."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l1-tevv-010_stmt",
          "name": "statement",
          "prose": "A Test, Evaluation, Verification and Validation (TEVV) plan per DoDI 5000.89 must be documented and approved by the authorizing official before the AI system reaches operational deployment. The plan must specify test objectives, acceptance criteria, responsible testers, and re-validation triggers."
         },
         {
          "id": "def-srf-l1-tevv-010_obj",
          "name": "objective",
          "prose": "Maintain tevv_plan_approved_before_deployment == {{ insert: param, def-srf-l1-tevv-010-p1 }} over window per-system. Breach action: block-deployment; notify-PM; escalate-to-AO."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Reliable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Traceable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 2.1.1 (TEVV framework across the AI capability lifecycle)"
         },
         {
          "href": "#8613c5f9-9d01-5ebc-8cc6-19adffb697fe",
          "rel": "reference",
          "text": "Section 3.4 (T&E Program Planning: TEMP and test strategy documentation and approval)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.1"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-02 (Risk Management Program)"
         }
        ]
       },
       {
        "id": "def-srf-l1-ovr-011",
        "class": "srf-vertical-control",
        "title": "Human Oversight Escalation Chain Documented and Rehearsed",
        "params": [
         {
          "id": "def-srf-l1-ovr-011-p1",
          "label": "oversight_escalation_chain_rehearsed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a documented escalation chain exists for every AI system in the registry that falls within scope, and a tabletop exercise or equivalent rehearsal is recorded in the prior annual period."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-OVR-011"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Traceable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "human-oversight-remedy"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Escalate to CDAO liaison and program manager. Conduct tabletop within 30 days. Update ATO package."
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact"
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l1-ovr-011_stmt",
          "name": "statement",
          "prose": "The DoD component must document and rehearse a human oversight escalation chain for every AI system used in decisions affecting personnel, operations, or lethal force. The chain must name the operator, supervising officer, program manager, and the CDAO reporting path. For NSS systems, the chain must include the Authorizing Official. The chain must be tested at least annually through a tabletop exercise or equivalent."
         },
         {
          "id": "def-srf-l1-ovr-011_obj",
          "name": "objective",
          "prose": "Maintain oversight_escalation_chain_rehearsed == {{ insert: param, def-srf-l1-ovr-011-p1 }} over window annual. Breach action: Escalate to CDAO liaison and program manager. Conduct tabletop within 30 days. Update ATO package.."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Responsible principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Governable principle"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 5.1"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-15 (Human supervision)"
         }
        ]
       }
      ]
     },
     {
      "id": "l1-manufacturing",
      "class": "srf-vertical",
      "title": "L1 — Manufacturing",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "manufacturing"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/manufacturing-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "mfg-srf-l1-des-001",
        "class": "srf-vertical-control",
        "title": "EU AI Act Risk Classification and Registry",
        "params": [
         {
          "id": "mfg-srf-l1-des-001-p1",
          "label": "all_high_risk_systems_registered",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-market-placement"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Every high-risk AI system is registered in the EU AI database before market placement or entry into service. EU AI Act Article 49 is a binary obligation — partial registration is not permitted and any unregistered in-scope system constitutes non-compliance."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-DES-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Product-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturer"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "identify-unregistered-systems; halt-market-placement; notify-compliance-manager; initiate-registration"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. EU AI database registration record (printout or API confirmation) for each high-risk system, timestamped before market placement date."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-62443",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l1-des-001_stmt",
          "name": "statement",
          "prose": "The manufacturer must classify every AI system in development or operation by EU AI Act risk tier (prohibited, high-risk, limited-risk, minimal-risk). High-risk systems must be registered in the EU AI database before being placed on the market or put into service. The registry must record the system's operating model, risk class, conformity assessment route, accountable manager, and market placement date. Unregistered high-risk systems identified post-deployment must be added within 30 days of discovery."
         },
         {
          "id": "mfg-srf-l1-des-001_obj",
          "name": "objective",
          "prose": "Maintain all_high_risk_systems_registered == {{ insert: param, mfg-srf-l1-des-001-p1 }} over window per-market-placement. Breach action: identify-unregistered-systems; halt-market-placement; notify-compliance-manager; initiate-registration."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 16 (provider obligations)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 49 (registration)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Annex III (high-risk categories)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.1"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-02 (Risk Management Program)"
         }
        ]
       },
       {
        "id": "mfg-srf-l1-des-002",
        "class": "srf-vertical-control",
        "title": "AI Governance Committee with OT and Safety Representation",
        "params": [
         {
          "id": "mfg-srf-l1-des-002-p1",
          "label": "governance_committee_active",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "quarterly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Governance committee with required membership exists and has met within the last 90 days with documented minutes."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-DES-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Product-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturer"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "convene-committee; appoint-missing-roles; document-composition"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Meeting record and composition document."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l1-des-002_stmt",
          "name": "statement",
          "prose": "The manufacturer must establish an AI governance committee that includes at minimum the Plant AI Safety Officer (or functional safety engineer), OT Security lead, product compliance manager, and a senior operations representative. The committee must meet at least quarterly, review the AI system inventory, approve new high-risk AI deployments, and document decisions. Committee composition and meeting records must be retained for audit."
         },
         {
          "id": "mfg-srf-l1-des-002_obj",
          "name": "objective",
          "prose": "Maintain governance_committee_active == {{ insert: param, mfg-srf-l1-des-002-p1 }} over window quarterly. Breach action: convene-committee; appoint-missing-roles; document-composition."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 17 (quality management system)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 26 (deployer obligations)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-2-1 (part-level)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.2"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-06 (Governance Responsibility Model)"
         }
        ]
       },
       {
        "id": "mfg-srf-l1-des-003",
        "class": "srf-vertical-control",
        "title": "AI Use Case Inventory with Operating Model and Risk Tier",
        "params": [
         {
          "id": "mfg-srf-l1-des-003-p1",
          "label": "inventory_staleness_days",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "<="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "monthly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_INVENTORY_STALENESS_DAYS"
          ],
          "guidelines": [
           {
            "prose": "Maximum number of days since any AI use case record was last reviewed."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-DES-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Product-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturer"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "review-and-update-inventory; notify-governance-committee"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Inventory last-updated timestamp."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l1-des-003_stmt",
          "name": "statement",
          "prose": "The manufacturer must maintain a current inventory of all AI use cases, recording for each: system name, operating model (AI-SaaS, OT-Edge, Product-Embedded, AI-PaaS), EU AI Act risk class, OT applicability, accountable owner, deployment status, and date last reviewed. The inventory must be updated within 14 days of any new AI system entering design, validation, or production."
         },
         {
          "id": "mfg-srf-l1-des-003_obj",
          "name": "objective",
          "prose": "Maintain inventory_staleness_days <= {{ insert: param, mfg-srf-l1-des-003-p1 }} over window monthly. Breach action: review-and-update-inventory; notify-governance-committee."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 17 (quality management system, inventory element)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-2-1 (part-level)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.1"
         }
        ]
       },
       {
        "id": "mfg-srf-l1-val-004",
        "class": "srf-vertical-control",
        "title": "Conformity Assessment Program Management",
        "params": [
         {
          "id": "mfg-srf-l1-val-004-p1",
          "label": "conformity_assessment_register_complete",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "quarterly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "All high-risk systems in the inventory have an assigned conformity assessment route and status in the master register."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-VAL-004"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Product-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturer"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "assign-assessment-route; engage-notified-body-if-required; update-register"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Conformity assessment register."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Article TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-62443",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l1-val-004_stmt",
          "name": "statement",
          "prose": "For each high-risk AI system, the manufacturer must determine the required conformity assessment route (self-assessment per Article 43 or third-party notified body assessment) and track assessment status, scheduled completion date, and responsible manager. Systems requiring notified-body assessment must have an engaged notified body before market placement. A master conformity assessment register must be maintained and reviewed by the governance committee."
         },
         {
          "id": "mfg-srf-l1-val-004_obj",
          "name": "objective",
          "prose": "Maintain conformity_assessment_register_complete == {{ insert: param, mfg-srf-l1-val-004-p1 }} over window quarterly. Breach action: assign-assessment-route; engage-notified-body-if-required; update-register."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 43 (conformity assessment procedures)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Annex VII (third-party assessment)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.4"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "A&A-02 (Independent Assessments)"
         }
        ]
       },
       {
        "id": "mfg-srf-l1-ops-005",
        "class": "srf-vertical-control",
        "title": "Incident Reporting Plan to Market Surveillance Authority",
        "params": [
         {
          "id": "mfg-srf-l1-ops-005-p1",
          "label": "incident_plan_tested",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Incident reporting plan exists, names the responsible reporter and MSA contact, and has been exercised via tabletop test within the last 12 months."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-OPS-005"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Product-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturer"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "draft-or-update-incident-plan; schedule-tabletop-exercise"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Incident reporting plan and tabletop test record."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-62443",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l1-ops-005_stmt",
          "name": "statement",
          "prose": "The manufacturer must maintain a written incident reporting plan for serious incidents involving high-risk AI systems. The plan must define the trigger conditions, the responsible reporter, the market surveillance authority contact, and the 15-business-day reporting deadline per EU AI Act Article 73. The plan must be tested annually via a tabletop exercise, and test results must be documented."
         },
         {
          "id": "mfg-srf-l1-ops-005_obj",
          "name": "objective",
          "prose": "Maintain incident_plan_tested == {{ insert: param, mfg-srf-l1-ops-005-p1 }} over window annual. Breach action: draft-or-update-incident-plan; schedule-tabletop-exercise."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 73 (serious incident reporting)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 72 (post-market monitoring)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 5.1"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "LOG-13 (Failures and Anomalies Reporting)"
         }
        ]
       },
       {
        "id": "mfg-srf-l1-des-006",
        "class": "srf-vertical-control",
        "title": "Third-Party AI System Procurement Policy",
        "params": [
         {
          "id": "mfg-srf-l1-des-006-p1",
          "label": "procurement_policy_active",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "A written AI procurement policy covering the required elements exists and has been communicated to procurement and legal."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-DES-006"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Product-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturer"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "draft-or-update-procurement-policy; communicate-to-procurement"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Procurement policy document with effective date."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 15: Service Provider Management"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l1-des-006_stmt",
          "name": "statement",
          "prose": "The manufacturer must maintain a procurement policy for third-party AI systems that requires: EU declaration of conformity for high-risk systems, technical documentation per Article 11, supplier contractual obligations for post-market monitoring data sharing, and a supply chain AI risk assessment for OT-deployed components. The policy must apply to equipment OEMs, AI software vendors, and system integrators supplying AI-enabled systems."
         },
         {
          "id": "mfg-srf-l1-des-006_obj",
          "name": "objective",
          "prose": "Maintain procurement_policy_active == {{ insert: param, mfg-srf-l1-des-006-p1 }} over window annual. Breach action: draft-or-update-procurement-policy; communicate-to-procurement."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 16 (provider obligations on deployers)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 25 (obligations of distributors and deployers)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 28 (third-party obligations)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-2-1 (part-level)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 6.1"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-11 (Supply Chain Agreement Review)"
         }
        ]
       },
       {
        "id": "mfg-srf-l1-ops-007",
        "class": "srf-vertical-control",
        "title": "Post-Market Monitoring Plan per EU AI Act Article 72",
        "params": [
         {
          "id": "mfg-srf-l1-ops-007-p1",
          "label": "post_market_plan_active",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "A post-market monitoring plan exists for each high-risk AI system, names a responsible owner, and specifies collection frequency and escalation thresholds."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-OPS-007"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Product-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturer"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "create-post-market-plan; assign-owner; define-escalation-thresholds"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Post-market monitoring plan document."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-62443",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l1-ops-007_stmt",
          "name": "statement",
          "prose": "For each high-risk AI system placed on the market or put into service, the manufacturer must maintain a post-market monitoring plan. The plan must define monitoring frequency, performance metrics to track, data collection mechanism, the responsible team, and the escalation threshold for triggering a corrective action or market withdrawal. Plans must be updated when the system's risk profile changes."
         },
         {
          "id": "mfg-srf-l1-ops-007_obj",
          "name": "objective",
          "prose": "Maintain post_market_plan_active == {{ insert: param, mfg-srf-l1-ops-007-p1 }} over window annual. Breach action: create-post-market-plan; assign-owner; define-escalation-thresholds."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 72 (post-market monitoring system)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 17 (quality management system)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 4.1"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-10 (Model Continuous Monitoring)"
         }
        ]
       },
       {
        "id": "mfg-srf-l1-des-008",
        "class": "srf-vertical-control",
        "title": "Fundamental Rights Impact Assessment (FRIA)",
        "params": [
         {
          "id": "mfg-srf-l1-des-008-p1",
          "label": "fria_completed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "FRIA completed and documented for each applicable high-risk AI system before service entry."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-DES-008"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Product-Embedded"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturer"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "schedule-fria; assign-assessor; document-findings"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. FRIA document with completion date and approver."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-62443",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l1-des-008_stmt",
          "name": "statement",
          "prose": "Public-body deployers and private deployers of high-risk AI systems covered by EU AI Act Article 27 must complete a Fundamental Rights Impact Assessment before putting the system into service. The FRIA must address: the rights at risk, the affected populations, the safeguards applied, and the monitoring plan. FRIA records must be retained and provided to market surveillance authorities on request."
         },
         {
          "id": "mfg-srf-l1-des-008_obj",
          "name": "objective",
          "prose": "Maintain fria_completed == {{ insert: param, mfg-srf-l1-des-008-p1 }} over window per-deployment. Breach action: schedule-fria; assign-assessor; document-findings."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 27 (fundamental rights impact assessment for deployers)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 5.1"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-10 (AI Impact Assessment)"
         }
        ]
       },
       {
        "id": "mfg-srf-l1-chg-009",
        "class": "srf-vertical-control",
        "title": "AI Discontinuation and Decommission Procedure",
        "params": [
         {
          "id": "mfg-srf-l1-chg-009-p1",
          "label": "decommission_procedure_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Decommission procedure exists, covers OT safe-state requirements, and has been reviewed within 12 months."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-CHG-009"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Product-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturer"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL1"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "change"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "draft-decommission-procedure; review-with-ot-safety-team"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Decommission procedure document."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l1-chg-009_stmt",
          "name": "statement",
          "prose": "The manufacturer must maintain a documented decommission procedure for AI systems covering: shutdown sequence for OT-edge AI (including safe state transitions and safety interlock preservation), data retention and deletion requirements, EU AI database de-registration for high-risk systems, and post-decommission evidence retention per regulatory requirements. The procedure must be tested for OT-edge systems before any production decommission."
         },
         {
          "id": "mfg-srf-l1-chg-009_obj",
          "name": "objective",
          "prose": "Maintain decommission_procedure_documented == {{ insert: param, mfg-srf-l1-chg-009-p1 }} over window annual. Breach action: draft-decommission-procedure; review-with-ot-safety-team."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 49 (registration and de-registration)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-2-1 (part-level)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 3.1"
         }
        ]
       },
       {
        "id": "mfg-srf-l1-chg-010",
        "class": "srf-vertical-control",
        "title": "OT Change Management Policy for AI Systems",
        "params": [
         {
          "id": "mfg-srf-l1-chg-010-p1",
          "label": "ot_change_policy_active",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "An OT AI change management policy exists, distinguishes OT from IT change cycles, defines safety re-validation triggers, and has been communicated to OT engineering and production."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-CHG-010"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L1"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance and Processes"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturer"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ot-only"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL1"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL3"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "change"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "draft-ot-change-policy; align-with-plant-safety-officer; communicate-to-ot-engineering"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. OT change management policy document with version history."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Annex I item TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l1-chg-010_stmt",
          "name": "statement",
          "prose": "The manufacturer must maintain an OT-specific change management policy for AI systems that defines: version freeze windows aligned to production schedules, the trigger conditions for safety re-validation (model update, training data change, configuration change), the rollback procedure and rollback test requirement, and the change record format. The policy must distinguish between IT-side AI changes (standard change management cycle) and OT-edge AI changes (extended validation window, safety re-validation gate)."
         },
         {
          "id": "mfg-srf-l1-chg-010_obj",
          "name": "objective",
          "prose": "Maintain ot_change_policy_active == {{ insert: param, mfg-srf-l1-chg-010-p1 }} over window annual. Breach action: draft-ot-change-policy; align-with-plant-safety-officer; communicate-to-ot-engineering."
         },
         {
          "id": "mfg-srf-l1-chg-010_gdn",
          "name": "guidance",
          "prose": "mapping-status-note: IEC 61508 clause reference requires verification against IEC 61508-1 through IEC 61508-7. Do not cite specific clause numbers without primary text verification."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 17 (quality management system, change control element)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-2-1 (part-level)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 2.2"
         },
         {
          "href": "#baa4cf26-6159-56d6-a26d-4cb096e75b6c",
          "rel": "reference",
          "text": "IEC 61508 (edition-level)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-01 (Governance Program Policy and Procedures)"
         }
        ]
       }
      ]
     }
    ]
   },
   {
    "id": "l2",
    "class": "srf-layer",
    "title": "L2: AI Information",
    "groups": [
     {
      "id": "l2-finance",
      "class": "srf-vertical",
      "title": "L2 — Finance",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "finance"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/finance-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "fin-srf-l2-dev-001",
        "class": "srf-vertical-control",
        "title": "Training and RAG Data Provenance Documentation",
        "params": [
         {
          "id": "fin-srf-l2-dev-001-p1",
          "label": "provenance_record_completeness",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "at-validation-gate"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: complete provenance record exists for all training and RAG datasets linked to the model, with no missing required fields."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-DEV-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI Training Data"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-model-from-entering-validation"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: provenance is a records artifact. If data pipeline events are captured, candidate: api_activity events at data ingestion endpoints could provide partial lineage."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l2-dev-001_stmt",
          "name": "statement",
          "prose": "Before a model enters validation, the data provider must produce a provenance record for every training dataset and RAG corpus used, covering: source, licensing terms, collection date, preprocessing steps applied, known biases documented, and the data owner accountable for ongoing quality. The record must be stored in the model inventory and linked to the model card. For third-party data sources, the provenance record must additionally name an internal data steward accountable for the vendor relationship and for validating that the source meets the institution's data quality and classification standards. The SRF's single-accountable-party principle applies regardless of whether the data provider is internal or external; accountability does not transfer to the vendor."
         },
         {
          "id": "fin-srf-l2-dev-001_obj",
          "name": "objective",
          "prose": "Maintain provenance_record_completeness == {{ insert: param, fin-srf-l2-dev-001-p1 }} over window at-validation-gate. Breach action: block-model-from-entering-validation."
         },
         {
          "id": "fin-srf-l2-dev-001_gdn",
          "name": "guidance",
          "prose": "data-source-type-field: {\"description\": \"Required field on each provenance record entry. Distinguishes internal data sources from third-party vendors so that the internal_steward requirement can be enforced.\", \"values\": [\"internal\", \"third-party\"], \"constraint\": \"When data_source_type == 'third-party', internal_steward must be a named individual, not a team or role title.\"} internal-steward-field: {\"description\": \"Required on each provenance record entry where data_source_type == 'third-party'. Names the institution employee accountable for the vendor data relationship, quality attestation, and ongoing monitoring. Must be linked to the institution's vendor management record for the data provider.\", \"constraint\": \"Cannot be the same individual as the model developer or application developer for that model.\"}"
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-PREV-006 (Data Quality & Classification/Sensitivity)"
         },
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-RC-023 (Intellectual Property and Copyright)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-20 (Data Provenance and Transparency)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section IV (Model Development)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 10 (Data and data governance)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 4.1 (legal and technology risks of third-party data are mapped); MAP 2.3 (data collection and selection considerations are documented)"
         }
        ]
       },
       {
        "id": "fin-srf-l2-dev-002",
        "class": "srf-vertical-control",
        "title": "Data Classification for AI-Accessible Data Stores",
        "params": [
         {
          "id": "fin-srf-l2-dev-002-p1",
          "label": "ai_accessible_store_classification_coverage",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "at-production-promotion"
           }
          ],
          "values": [
           "tier-defined"
          ],
          "guidelines": [
           {
            "prose": "Percentage of data stores accessible by AI systems in production that carry a current, approved data classification label."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-DEV-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Privacy Controls & Policies"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-production-promotion; notify-data-owner"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "api_activity"
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Cross-reference api_activity events (resource.uid or dst_endpoint.resource) against the data classification register to identify unclassified stores being accessed by AI systems."
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 3: Data Protection"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l2-dev-002_stmt",
          "name": "statement",
          "prose": "All data stores accessible by AI systems at runtime (RAG corpora, grounding databases, tool-accessible APIs) must have a current data classification label (e.g., public, internal, confidential, restricted) before the system enters production. Classification must be performed by or reviewed by the accountable data owner, not the application developer."
         },
         {
          "id": "fin-srf-l2-dev-002_obj",
          "name": "objective",
          "prose": "Maintain ai_accessible_store_classification_coverage >= {{ insert: param, fin-srf-l2-dev-002-p1 }} over window at-production-promotion. Breach action: block-production-promotion; notify-data-owner."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-PREV-006 (Data Quality & Classification/Sensitivity)"
         },
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-PREV-012 (Role-Based Access Control for AI Data)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-04 (Data Classification)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-03 (Data Inventory)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section IV (Model Development)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 10 (Data and data governance)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.10 (privacy risk is examined and documented)"
         }
        ]
       },
       {
        "id": "fin-srf-l2-dev-003",
        "class": "srf-vertical-control",
        "title": "Training Data Quality Baseline and PSI Reference Distribution",
        "params": [
         {
          "id": "fin-srf-l2-dev-003-p1",
          "label": "psi_reference_distribution_stored",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "at-validation-gate"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: reference distribution artifact exists in model registry for all monitored features, linked to model version."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-DEV-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Master Data Management"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-model-from-entering-validation"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: model registry artifact event; not directly observable via OCSF streaming telemetry."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l2-dev-003_stmt",
          "name": "statement",
          "prose": "For each model using institution-provided training data, the data provider must establish a reference distribution at the time of initial training. This reference distribution anchors Population Stability Index (PSI) calculations during ongoing monitoring (SRF-L2-MON-001). The baseline must cover all features used by the model and be stored alongside the model artifacts."
         },
         {
          "id": "fin-srf-l2-dev-003_obj",
          "name": "objective",
          "prose": "Maintain psi_reference_distribution_stored == {{ insert: param, fin-srf-l2-dev-003-p1 }} over window at-validation-gate. Breach action: block-model-from-entering-validation."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-OP-019 (Data Quality and Drift)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-23 (Data Integrity Check)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-24 (Data Differentiation and Relevance)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section IV (Model Development)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 10 (Data and data governance)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.3 (performance is demonstrated for conditions similar to deployment); MAP 2.3 (data selection considerations are documented)"
         }
        ]
       },
       {
        "id": "fin-srf-l2-val-001",
        "class": "srf-vertical-control",
        "title": "Independent Validation of Training Data Quality and Representativeness",
        "params": [
         {
          "id": "fin-srf-l2-val-001-p1",
          "label": "data_validation_completed_with_disposition",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "pre-production-approval"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: independent validation report for training data quality exists, covers all required assessment areas, and records a formal disposition."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-VAL-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI Training Data"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "independent-validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-production-approval"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: validation report artifact; not streaming telemetry."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l2-val-001_stmt",
          "name": "statement",
          "prose": "The independent validation function must assess training data quality before a model is approved for production. Assessment must cover: representativeness of training data relative to the production population, absence of prohibited data (per SRF-L2-DEV-002 classification), bias indicators across protected classes relevant to the use case, and completeness of the provenance record (SRF-L2-DEV-001). Findings must be documented with disposition (accepted, conditionally accepted, or rejected)."
         },
         {
          "id": "fin-srf-l2-val-001_obj",
          "name": "objective",
          "prose": "Maintain data_validation_completed_with_disposition == {{ insert: param, fin-srf-l2-val-001-p1 }} over window pre-production-approval. Breach action: block-production-approval."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-OP-019 (Data Quality and Drift)"
         },
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-PREV-005 (System Acceptance Testing)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-24 (Data Differentiation and Relevance)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-23 (Data Integrity Check)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section V (Conceptual Soundness)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 10 (Data and data governance)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (Risk management system)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 1.3 (independent assessors are involved in TEVV); MEASURE 2.11 (fairness and bias are evaluated and documented)"
         }
        ]
       },
       {
        "id": "fin-srf-l2-mon-001",
        "class": "srf-vertical-control",
        "title": "Training and RAG Data Drift Monitoring (PSI)",
        "params": [
         {
          "id": "fin-srf-l2-mon-001-p1",
          "label": "psi_score",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "<"
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-defined"
           }
          ],
          "values": [
           "tier-defined"
          ],
          "guidelines": [
           {
            "prose": "Population Stability Index calculated between current input distribution and reference distribution. Conventional MRM thresholds: < 0.1 stable, 0.1–0.25 minor shift (investigate), >= 0.25 major shift (re-validate). Institutions set tier-specific alert levels."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-MON-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI Training Data"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "alert-data-provider; escalate-to-mrm-if-psi-ge-0.25; initiate-re-validation"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai_operation"
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "message_context: input feature distributions observable from ai_operation events at inference time can be aggregated to compute PSI against the stored reference distribution."
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "ocsf-class-status",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "unverified-proposal"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l2-mon-001_stmt",
          "name": "statement",
          "prose": "For models using institution-provided training data or runtime RAG corpora, the data provider must monitor Population Stability Index (PSI) against the reference distribution established in SRF-L2-DEV-003. PSI breach thresholds follow MRM convention: PSI >= 0.1 triggers investigation; PSI >= 0.25 triggers re-validation. Tier-1 models require continuous or daily monitoring; lower tiers follow institution-defined cadence per SR 26-2's materiality principle."
         },
         {
          "id": "fin-srf-l2-mon-001_obj",
          "name": "objective",
          "prose": "Maintain psi_score < {{ insert: param, fin-srf-l2-mon-001-p1 }} over window tier-defined. Breach action: alert-data-provider; escalate-to-mrm-if-psi-ge-0.25; initiate-re-validation."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-OP-019 (Data Quality and Drift)"
         },
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-DET-004 (AI System Observability)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-10 (Model Continuous Monitoring)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-23 (Data Integrity Check)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section V (Ongoing Model Monitoring)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 10 (Data and data governance)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.4 (the deployed AI system is monitored for changes); MANAGE 4.1 (post-deployment monitoring plans are implemented)"
         }
        ]
       },
       {
        "id": "fin-srf-l2-mon-002",
        "class": "srf-vertical-control",
        "title": "Data Classification Coverage Rate for AI-Accessible Stores",
        "params": [
         {
          "id": "fin-srf-l2-mon-002-p1",
          "label": "ai_accessible_store_classification_coverage_rate",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "30d"
           }
          ],
          "values": [
           "tier-defined"
          ],
          "guidelines": [
           {
            "prose": "Percentage of data stores accessed by AI systems in the monitoring window that appear in the classification register with a current label."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-MON-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Privacy Controls & Policies"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "cross-layer-controls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-DEV-003"
         },
         {
          "name": "cross-layer-controls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-MON-003"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "alert-data-owner; quarantine-unclassified-store-from-ai-access-pending-classification"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "api_activity"
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Cross-reference api_activity resource identifiers (resource.uid, dst_endpoint.resource) observed in the monitoring window against the data classification register. Unmatched resources are unclassified."
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-sr26-2",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-eu-ai-act",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l2-mon-002_stmt",
          "name": "statement",
          "prose": "Ongoing monitoring of the percentage of data stores accessible by AI systems in production that carry a current data classification. New data stores connected to AI systems after initial production approval must be classified before use. This control catches classification drift as AI systems are extended to new data sources over time. Upward reclassification of an existing store (sensitivity level increasing) is treated as a breach event requiring re-evaluation of platform-level compute controls at L4, not only a coverage metric update."
         },
         {
          "id": "fin-srf-l2-mon-002_obj",
          "name": "objective",
          "prose": "Maintain ai_accessible_store_classification_coverage_rate >= {{ insert: param, fin-srf-l2-mon-002-p1 }} over window 30d. Breach action: alert-data-owner; quarantine-unclassified-store-from-ai-access-pending-classification."
         },
         {
          "id": "fin-srf-l2-mon-002_gdn",
          "name": "guidance",
          "prose": "cross-layer-note: If a data store accessible by a Tier-1 or Tier-2 model is reclassified upward (e.g., from internal to confidential or restricted), the reclassification must trigger re-evaluation of the L4 compute configuration (SRF-L4-DEV-003) to confirm confidential compute requirements are still met. The breach action for an upward reclassification event must notify ai-platform-provider in addition to the data owner."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-PREV-006 (Data Quality & Classification/Sensitivity)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-04 (Data Classification)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.10 (privacy risk is examined and documented)"
         }
        ]
       },
       {
        "id": "fin-srf-l2-mon-003",
        "class": "srf-vertical-control",
        "title": "Agent Runtime Memory Store Integrity Monitoring",
        "params": [
         {
          "id": "fin-srf-l2-mon-003-p1",
          "label": "memory_anomalous_write_rate",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-session"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "0 unauthorized-actor writes"
          ],
          "guidelines": [
           {
            "prose": "Rate of write operations to agent memory stores that deviate from the session baseline (unexpected actor, write volume spike, or content distribution shift). A zero-tolerance threshold applies to writes by actors outside the authorized write-access list."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-MON-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Master Data Management"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "terminate-agent-session; quarantine-memory-store; alert-data-provider-and-agentic-platform-provider; initiate-forensic-review"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "api_activity"
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Monitor api_activity events on memory store endpoints (write operations). Cross-reference actor identity (actor.user.uid or actor.process.name) against the authorized write-access list for the memory store. Flag any write from an unauthorized actor as a Severity-1 event."
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "supplemental",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai_operation events may provide session-level context (message_context) to identify the originating agent session for a given memory write."
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l2-mon-003_stmt",
          "name": "statement",
          "prose": "For Agent-PaaS deployments, the data provider (in coordination with the agentic platform provider at L3/L4) must monitor agent runtime memory stores: episodic memory, working memory, and any mutable knowledge store the agent reads from or writes to, for unauthorized or anomalous write operations. This control targets memory poisoning: the injection of malicious or incorrect content into an agent's memory during a session, which can corrupt subsequent reasoning across that session or persist across sessions if memory is durable. Monitoring must cover: write-access events by actor (agent identity, tool, or external input), write rate relative to session baseline, and content that deviates significantly from the memory store's established distribution. Accountability for the integrity of the data in the store sits at L2 (data-provider); the implementing telemetry sits at L3/L4 (agentic-platform-provider)."
         },
         {
          "id": "fin-srf-l2-mon-003_obj",
          "name": "objective",
          "prose": "Maintain memory_anomalous_write_rate == {{ insert: param, fin-srf-l2-mon-003-p1 }} over window per-session. Breach action: terminate-agent-session; quarantine-memory-store; alert-data-provider-and-agentic-platform-provider; initiate-forensic-review."
         },
         {
          "id": "fin-srf-l2-mon-003_gdn",
          "name": "guidance",
          "prose": "implementing-persona-note: Telemetry and enforcement implemented by agentic-platform-provider at L3/L4. Data-provider is accountable for defining acceptable write patterns and integrity standards for the memory store content."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-SEC-027 (Agent State Persistence Poisoning)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-21 (Data Poisoning Prevention & Detection)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-14 (AI Cache Protection)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section III footnote 3 (generative and agentic AI out of scope"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "MRM principles applied by analogy)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (Risk management system)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 10 (Data and data governance)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.7 (security and resilience are evaluated and documented)"
         }
        ]
       },
       {
        "id": "fin-srf-l2-ech-001",
        "class": "srf-vertical-control",
        "title": "Effective Challenge of Data Quality Standards and Drift Thresholds",
        "params": [
         {
          "id": "fin-srf-l2-ech-001-p1",
          "label": "data_standards_challenge_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "12mo"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: annual second-line challenge of L2 monitoring thresholds completed, with findings documented and any required threshold adjustments tracked to closure."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-ECH-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Master Data Management"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "effective-challenge"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-cro; flag-in-annual-mrm-report"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: governance artifact; not streaming telemetry."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-finos-aigf",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-eu-ai-act",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l2-ech-001_stmt",
          "name": "statement",
          "prose": "The independent validation or second-line risk function must annually challenge whether the PSI thresholds (SRF-L2-MON-001) and classification coverage targets (SRF-L2-MON-002) remain appropriate. Challenge must assess: whether conventional PSI thresholds are calibrated to the institution's specific model population, whether new data modalities (e.g., multimodal inputs, agent tool outputs) require additional drift metrics, and whether any Tier-1 model has exceeded its drift threshold without triggering a re-validation."
         },
         {
          "id": "fin-srf-l2-ech-001_obj",
          "name": "objective",
          "prose": "Maintain data_standards_challenge_documented == {{ insert: param, fin-srf-l2-ech-001-p1 }} over window 12mo. Breach action: escalate-to-cro; flag-in-annual-mrm-report."
         }
        ],
        "links": [
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "A&A-02 (Independent Assessments)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section III (effective challenge)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.13 (effectiveness of the TEVV metrics and processes is evaluated); MEASURE 4.2 (measurement results are informed by domain expert input)"
         }
        ]
       }
      ]
     },
     {
      "id": "l2-public-sector",
      "class": "srf-vertical",
      "title": "L2 — Public Sector",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "public-sector"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/public-sector-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "pubsec-srf-l2-acq-001",
        "class": "srf-vertical-control",
        "title": "Authority-to-Use Verification for Training and RAG Data",
        "params": [
         {
          "id": "pubsec-srf-l2-acq-001-p1",
          "label": "training_rag_data_authority_verified",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-ingestion"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: every data source ingested into training or RAG pipelines has a documented authority-to-use determination on file before ingestion."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-ACQ-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Input Control"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Shared-Service"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agency"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition-integration"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "halt-ingestion; notify-data-governance-officer; escalate-to-privacy-officer"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact. Data ingestion events may emit api_activity (6003) if the pipeline is instrumented."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-fedramp-20x-ksi",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l2-acq-001_stmt",
          "name": "statement",
          "prose": "Before ingesting data into AI training pipelines or retrieval-augmented generation (RAG) stores, the agency must verify authority to use, including Privacy Act System of Records Notice (SORN) coverage for Privacy Act-protected records, copyright clearance for third-party content, and data rights confirmation for vendor-supplied datasets."
         },
         {
          "id": "pubsec-srf-l2-acq-001_obj",
          "name": "objective",
          "prose": "Maintain training_rag_data_authority_verified == {{ insert: param, pubsec-srf-l2-acq-001-p1 }} over window per-ingestion. Breach action: halt-ingestion; notify-data-governance-officer; escalate-to-privacy-officer."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(b)(ii) (Complete AI Impact Assessment)"
         },
         {
          "href": "#ae7bd07d-92c3-5ea1-915d-6542ebb67973",
          "rel": "reference",
          "text": "Section 3(d) (Protect IP Rights and Use of Government Data)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 2.2 (scientific rigor and data quality are characterized for intended context); MAP 3.5 (organizational risk tolerances are considered)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM04: Data and Model Poisoning"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-20 (Data Provenance and Transparency)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l2-acq-002",
        "class": "srf-vertical-control",
        "title": "Agency Data Egress Block to Commercial Model Training",
        "params": [
         {
          "id": "pubsec-srf-l2-acq-002-p1",
          "label": "vendor_training_data_sharing_disabled",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-onboarding-and-after-tos-changes"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: data-sharing configuration for every AI service confirms training data sharing is disabled or contractually prohibited per M-25-22."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-ACQ-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Input Control"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition-integration"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "suspend-service; notify-CAIO; notify-data-protection-officer; escalate-to-legal"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Configuration management artifact. Candidate: configuration_change (5001) if vendor portals emit configuration events."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-21",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l2-acq-002_stmt",
          "name": "statement",
          "prose": "Agency data must not be used to train commercial AI vendor models without explicit agency consent, per M-25-22 data rights requirements. The data-sharing configuration of each AI service must be audited at onboarding and after any vendor terms-of-service update to confirm no training data sharing is enabled."
         },
         {
          "id": "pubsec-srf-l2-acq-002_obj",
          "name": "objective",
          "prose": "Maintain vendor_training_data_sharing_disabled == {{ insert: param, pubsec-srf-l2-acq-002-p1 }} over window per-onboarding-and-after-tos-changes. Breach action: suspend-service; notify-CAIO; notify-data-protection-officer; escalate-to-legal."
         }
        ],
        "links": [
         {
          "href": "#ae7bd07d-92c3-5ea1-915d-6542ebb67973",
          "rel": "reference",
          "text": "Section 3(d)(iv) (Use of Government Data: contracts permanently prohibit training publicly or commercially available AI on nonpublic agency data absent consent)"
         },
         {
          "href": "#aec75536-9650-52f9-bd36-918743c7b0a5",
          "rel": "reference",
          "text": "KSI-CNA-ULN (logical networking enforces traffic flow controls)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 5.2 (risk management includes third-party AI providers and data practices); MAP 5.1 (likelihood of impacts on individuals is assessed)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM10: Unbounded Consumption"
         }
        ]
       },
       {
        "id": "pubsec-srf-l2-acq-003",
        "class": "srf-vertical-control",
        "title": "PII and CUI Classification Coverage for AI-Accessible Data Stores",
        "params": [
         {
          "id": "pubsec-srf-l2-acq-003-p1",
          "label": "ai_accessible_data_store_classification_coverage_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "quarterly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_DATA_CLASSIFICATION_COVERAGE_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of AI-accessible data stores with complete PII and CUI classification. Tier-configurable; recommended minimum 100% for high-impact use cases."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-ACQ-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Input Control"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Shared-Service"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agency"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition-integration"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "suspend-AI-access-to-unclassified-stores; notify-ISSO; escalate-to-privacy-officer"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "file_activity (1001) if the data classification tooling emits events; otherwise document management artifact."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l2-acq-003_stmt",
          "name": "statement",
          "prose": "Data stores accessible by AI systems must have complete PII and Controlled Unclassified Information (CUI) classification coverage. Unclassified data stores must be labelled before AI systems are granted access. Classification coverage must be tracked as a percentage of data stores and reported to the ISSO."
         },
         {
          "id": "pubsec-srf-l2-acq-003_obj",
          "name": "objective",
          "prose": "Maintain ai_accessible_data_store_classification_coverage_pct >= {{ insert: param, pubsec-srf-l2-acq-003-p1 }} over window quarterly. Breach action: suspend-AI-access-to-unclassified-stores; notify-ISSO; escalate-to-privacy-officer."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(b)(ii) (Complete AI Impact Assessment)"
         },
         {
          "href": "#ae7bd07d-92c3-5ea1-915d-6542ebb67973",
          "rel": "reference",
          "text": "Section 3(c) (Protect Privacy)"
         },
         {
          "href": "#aec75536-9650-52f9-bd36-918743c7b0a5",
          "rel": "reference",
          "text": "KSI-PIY-GIV (automated real-time inventories of information resources)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 2.2 (data quality and sensitivity characterized); MAP 5.1 (impacts on individuals assessed)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM02: Sensitive Information Disclosure"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-04 (Data Classification)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-03 (Data Inventory)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l2-mon-004",
        "class": "srf-vertical-control",
        "title": "Input Distribution Shift Monitoring (PSI)",
        "params": [
         {
          "id": "pubsec-srf-l2-mon-004-p1",
          "label": "input_psi",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "<"
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "rolling-30d"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_INPUT_PSI_THRESHOLD"
          ],
          "guidelines": [
           {
            "prose": "Population Stability Index on input features. Tier-configurable; common threshold is PSI < 0.2 (stable), 0.2-0.25 (moderate drift, investigate), > 0.25 (significant drift, re-validate)."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-MON-004"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Input Control"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "alert-application-developer; trigger-re-validation; notify-ISSO; pause-high-impact-outputs-pending-review"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "detection_finding (2004) for drift alerts; api_activity (6003) for inference logging that feeds PSI computation."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finding.severity_id; api_activity.request.data"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-fedramp-20x-ksi",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l2-mon-004_stmt",
          "name": "statement",
          "prose": "For high-impact AI use cases, the agency or application developer must monitor the distribution of AI system inputs against a baseline established at deployment. Population Stability Index (PSI) or an equivalent measure must be computed on a cadence appropriate to the use case risk level and alerts triggered when drift exceeds the configured threshold."
         },
         {
          "id": "pubsec-srf-l2-mon-004_obj",
          "name": "objective",
          "prose": "Maintain input_psi < {{ insert: param, pubsec-srf-l2-mon-004-p1 }} over window rolling-30d. Breach action: alert-application-developer; trigger-re-validation; notify-ISSO; pause-high-impact-outputs-pending-review."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(b)(iii) (Conduct Ongoing Monitoring for Performance and Potential Adverse Impacts)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 2.4 (AI risk treatments are tracked); MEASURE 2.5 (ongoing monitoring tracks fairness and performance)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM09: Misinformation"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-10 (Model Continuous Monitoring)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l2-acq-005",
        "class": "srf-vertical-control",
        "title": "AI Interaction Log Retention Compliance (NARA)",
        "params": [
         {
          "id": "pubsec-srf-l2-acq-005-p1",
          "label": "ai_interaction_log_retention_compliant",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual-review"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: NARA retention determination exists for each high-impact use case, log retention is configured accordingly, and the records officer has confirmed compliance within the prior annual cycle."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-ACQ-005"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Input Control"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Shared-Service"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agency"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition-integration"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "notify-records-officer; escalate-to-ISSO; halt-log-deletion-pending-determination"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "audit_activity (3002) for log retention configuration events."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l2-acq-005_stmt",
          "name": "statement",
          "prose": "AI interaction logs for high-impact use cases may be federal records subject to NARA retention schedules. The agency records officer must determine retention obligations for each use case and configure log retention accordingly. Logs used as evidence for M-25-21 minimum-practice compliance must be retained through the compliance reporting period."
         },
         {
          "id": "pubsec-srf-l2-acq-005_obj",
          "name": "objective",
          "prose": "Maintain ai_interaction_log_retention_compliant == {{ insert: param, pubsec-srf-l2-acq-005-p1 }} over window annual-review. Breach action: notify-records-officer; escalate-to-ISSO; halt-log-deletion-pending-determination."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(b)(iii) (Conduct Ongoing Monitoring for Performance and Potential Adverse Impacts)"
         },
         {
          "href": "#aec75536-9650-52f9-bd36-918743c7b0a5",
          "rel": "reference",
          "text": "KSI-MLA-LET (maintained list of logged event types)"
         },
         {
          "href": "#aec75536-9650-52f9-bd36-918743c7b0a5",
          "rel": "reference",
          "text": "KSI-MLA-RVL (logs persistently reviewed and audited)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.3 (organizational policies include recordkeeping); MANAGE 4.1 (monitoring includes log completeness)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l2-mon-006",
        "class": "srf-vertical-control",
        "title": "AI Output Accuracy Monitoring Against Human Baseline",
        "params": [
         {
          "id": "pubsec-srf-l2-mon-006-p1",
          "label": "ai_output_accuracy_delta_vs_baseline",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "<="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "rolling-30d"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_ACCURACY_DEGRADATION_THRESHOLD_PCT"
          ],
          "guidelines": [
           {
            "prose": "Degradation in output accuracy versus the human-reviewer baseline. Tier-configurable; alert if accuracy drops more than configured percentage points."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-MON-006"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Input Control"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "alert-application-developer; trigger-re-validation; notify-ISSO; pause-high-stakes-outputs"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "detection_finding (2004) for accuracy degradation alerts."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finding.severity_id"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-fedramp-20x-ksi",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l2-mon-006_stmt",
          "name": "statement",
          "prose": "For high-impact AI use cases with measurable accuracy requirements, the agency must track output accuracy against a validated human-reviewer baseline established before deployment. Accuracy must be re-measured on the cadence defined in the compliance plan and reviewed at each governance board cycle."
         },
         {
          "id": "pubsec-srf-l2-mon-006_obj",
          "name": "objective",
          "prose": "Maintain ai_output_accuracy_delta_vs_baseline <= {{ insert: param, pubsec-srf-l2-mon-006-p1 }} over window rolling-30d. Breach action: alert-application-developer; trigger-re-validation; notify-ISSO; pause-high-stakes-outputs."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(b)(iii) (Conduct Ongoing Monitoring for Performance and Potential Adverse Impacts)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.5 (ongoing monitoring tracks performance); MANAGE 2.4 (risk treatments tracked)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM09: Misinformation"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "LOG-15 (Output Monitoring)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-10 (Model Continuous Monitoring)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l2-mon-007",
        "class": "srf-vertical-control",
        "title": "Bias and Disparate Impact Monitoring for Citizen-Facing Use Cases",
        "params": [
         {
          "id": "pubsec-srf-l2-mon-007-p1",
          "label": "disparate_impact_ratio",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "rolling-90d"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_DISPARATE_IMPACT_RATIO_THRESHOLD"
          ],
          "guidelines": [
           {
            "prose": "Four-fifths (80%) rule: adverse outcome rate for a protected group must not fall below 0.8 times the rate for the most favored group. Tier-configurable."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-MON-007"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Input Control"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "suspend-adverse-decisions-for-affected-groups; notify-CAIO; escalate-to-civil-rights-officer; trigger-root-cause-analysis"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "detection_finding (2004) for disparate impact alerts."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finding.severity_id"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-fedramp-20x-ksi",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l2-mon-007_stmt",
          "name": "statement",
          "prose": "For high-impact AI use cases affecting citizen eligibility, benefits, or enforcement decisions, the agency must track output rates across protected demographic groups and test for disparate impact. Disparate impact analysis must be performed before deployment and repeated on the cadence defined in the compliance plan."
         },
         {
          "id": "pubsec-srf-l2-mon-007_obj",
          "name": "objective",
          "prose": "Maintain disparate_impact_ratio >= {{ insert: param, pubsec-srf-l2-mon-007-p1 }} over window rolling-90d. Breach action: suspend-adverse-decisions-for-affected-groups; notify-CAIO; escalate-to-civil-rights-officer; trigger-root-cause-analysis."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(b)(ii) (Complete AI Impact Assessment)"
         },
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(b)(iii) (Conduct Ongoing Monitoring for Performance and Potential Adverse Impacts)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.2 (AI system trustworthiness characteristics are evaluated for relevant population groups); MEASURE 2.5 (ongoing monitoring tracks fairness)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-10 (AI Impact Assessment)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l2-acq-008",
        "class": "srf-vertical-control",
        "title": "FedRAMP Authorization Status Verification for AI Data Services",
        "params": [
         {
          "id": "pubsec-srf-l2-acq-008-p1",
          "label": "fedramp_authorization_current",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "quarterly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: every AI data service in use holds a current FedRAMP authorization at or above the required impact level, confirmed against the current marketplace listing."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-ACQ-008"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Input Control"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Shared-Service"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agency"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition-integration"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "suspend-service-pending-authorization-verification; notify-ISSO; escalate-to-Authorizing-Official"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact. FedRAMP marketplace verification may be logged via api_activity (6003)."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-21",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-fedramp-20x-ksi",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l2-acq-008_stmt",
          "name": "statement",
          "prose": "Any cloud data service feeding AI systems must hold a FedRAMP authorization at or above the required FIPS 199 impact level for the data it handles. The agency ISSO must verify authorization status at onboarding and re-verify quarterly against the current FedRAMP marketplace authorization list."
         },
         {
          "id": "pubsec-srf-l2-acq-008_obj",
          "name": "objective",
          "prose": "Maintain fedramp_authorization_current == {{ insert: param, pubsec-srf-l2-acq-008-p1 }} over window quarterly. Breach action: suspend-service-pending-authorization-verification; notify-ISSO; escalate-to-Authorizing-Official."
         }
        ],
        "links": [
         {
          "href": "#ae7bd07d-92c3-5ea1-915d-6542ebb67973",
          "rel": "reference",
          "text": "Section 4(e)(i) (Authorization To Operate Compliance)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 5.1 (supply chain risk management); MAP 1.5 (organizational risk tolerances for AI supply chain are established)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "A&A-02 (Independent Assessments)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-14 (Supply Chain Governance Review)"
         }
        ]
       }
      ]
     },
     {
      "id": "l2-healthcare",
      "class": "srf-vertical",
      "title": "L2 — Healthcare",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "healthcare"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/healthcare-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "hc-srf-l2-dev-001",
        "class": "srf-vertical-control",
        "title": "Training Data Provenance and Consent Documentation",
        "params": [
         {
          "id": "hc-srf-l2-dev-001-p1",
          "label": "training_data_provenance_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "at-model-development"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: all training datasets have complete provenance records including source, IRB/HIPAA authorization, and de-identification certification, linked to the model version in production."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-DEV-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data & Training"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-data-steward"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-model-clinical-deployment"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Provenance"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "entity (dataset), agent (source institution, IRB), recorded (date)"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-iec-62304",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l2-dev-001_stmt",
          "name": "statement",
          "prose": "All training datasets must have documented provenance including source institution(s), collection period, IRB approval or waiver, HIPAA authorization or de-identification certification per 45 CFR §164.514, and applicable data use agreements. Provenance must be archived and linkable to the deployed model version."
         },
         {
          "id": "hc-srf-l2-dev-001_obj",
          "name": "objective",
          "prose": "Maintain training_data_provenance_documented == {{ insert: param, hc-srf-l2-dev-001-p1 }} over window at-model-development. Breach action: block-model-clinical-deployment."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 2.2: Data management for AI/ML SaMD"
         },
         {
          "href": "#5c236a56-0fd8-52fc-880b-5e213d233a3f",
          "rel": "reference",
          "text": "Principle 3: Evidence-based"
         },
         {
          "href": "#8e4fc90b-6135-5c7a-81da-30efe01e36ad",
          "rel": "reference",
          "text": "§170.315(b)(11)(iii): Training data description"
         },
         {
          "href": "#8d9146e5-7a72-5eac-a274-e74a728227e7",
          "rel": "reference",
          "text": "45 CFR §164.514: De-identification standards"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 10 (Data and data governance)"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§4.2: Risk analysis data"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 4.1 (legal and technology risks of third-party data and software are mapped); MEASURE 2.10 (privacy risk is examined and documented)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM03: Supply Chain (training data source and licensing provenance)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-20 (Data Provenance and Transparency)"
         }
        ]
       },
       {
        "id": "hc-srf-l2-dev-002",
        "class": "srf-vertical-control",
        "title": "Demographic Representation Assessment",
        "params": [
         {
          "id": "hc-srf-l2-dev-002-p1",
          "label": "demographic_representation_rate",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "at-model-development"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "{min_representation_fraction}"
          ],
          "guidelines": [
           {
            "prose": "Minimum representation fraction for each protected demographic group in training data, relative to the intended deployment population."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-DEV-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data & Training"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-data-steward"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-model-clinical-deployment"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "MeasureReport"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "measure (demographic-representation), group.stratifier (age, sex, race), measureScore"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-fda-pccp",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-62304",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l2-dev-002_stmt",
          "name": "statement",
          "prose": "Training data for clinical AI systems must meet minimum representation thresholds for demographic groups (age, sex, race/ethnicity, geographic region) proportionate to the intended patient population. Assessment results must be disclosed per ONC HTI-1 transparency requirements."
         },
         {
          "id": "hc-srf-l2-dev-002_obj",
          "name": "objective",
          "prose": "Maintain demographic_representation_rate >= {{ insert: param, hc-srf-l2-dev-002-p1 }} over window at-model-development. Breach action: block-model-clinical-deployment."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 2.3: Bias, fairness, and representation"
         },
         {
          "href": "#8e4fc90b-6135-5c7a-81da-30efe01e36ad",
          "rel": "reference",
          "text": "§170.315(b)(11)(ii): Inclusivity and bias description"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 10(2)(f) (Appropriate data governance including bias examination)"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§4.3: Intended use analysis"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.11 (fairness and bias are evaluated and documented)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-24 (Data Differentiation and Relevance)"
         }
        ]
       },
       {
        "id": "hc-srf-l2-dev-003",
        "class": "srf-vertical-control",
        "title": "PHI Isolation in Non-Production Environments",
        "params": [
         {
          "id": "hc-srf-l2-dev-003-p1",
          "label": "phi_detected_in_nonprod_rate",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "0"
          ],
          "guidelines": [
           {
            "prose": "Zero tolerance: PHI detected in any non-HIPAA-compliant non-production environment."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-DEV-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data & Training"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-data-steward"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "immediate-environment-lockdown-and-incident-response"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AuditEvent"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "type.code == '110110' (PHI access event in nonprod) AND outcome != '0'"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-fda-tplc",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-fda-pccp",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-onc-hti1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iso-14971",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l2-dev-003_stmt",
          "name": "statement",
          "prose": "Protected Health Information must not appear in development, test, or staging environments unless those environments meet full HIPAA Security Rule requirements. Automated PHI scanning must run on all non-production data stores, and any detection is an immediate zero-tolerance breach."
         },
         {
          "id": "hc-srf-l2-dev-003_obj",
          "name": "objective",
          "prose": "Maintain phi_detected_in_nonprod_rate == {{ insert: param, hc-srf-l2-dev-003-p1 }} over window continuous. Breach action: immediate-environment-lockdown-and-incident-response."
         }
        ],
        "links": [
         {
          "href": "#8d9146e5-7a72-5eac-a274-e74a728227e7",
          "rel": "reference",
          "text": "45 CFR §164.312(a)(1): Access control; §164.308(a)(3): Workforce access"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 10(5) (Special categories data in testing)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§5.7: Software testing (data handling)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.10 (privacy risk is examined and documented)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM02: Sensitive Information Disclosure"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-04 (Data Classification)"
         }
        ]
       },
       {
        "id": "hc-srf-l2-vv-001",
        "class": "srf-vertical-control",
        "title": "External Validation Dataset Independence",
        "params": [
         {
          "id": "hc-srf-l2-vv-001-p1",
          "label": "validation_cohort_independence_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "pre-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: validation cohort documented as geographically and demographically distinct from training data, from at least one external institution."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-VV-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data & Training"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-data-steward"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "verification-validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-clinical-deployment"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "MeasureReport"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "measure (external-validation), reporter (external institution), period"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l2-vv-001_stmt",
          "name": "statement",
          "prose": "Clinical AI validation must use a cohort that is geographically and demographically distinct from the training dataset, collected from a different institution or time period. The independence of the validation cohort must be documented in the validation report and archived with the regulatory submission package."
         },
         {
          "id": "hc-srf-l2-vv-001_obj",
          "name": "objective",
          "prose": "Maintain validation_cohort_independence_documented == {{ insert: param, hc-srf-l2-vv-001-p1 }} over window pre-deployment. Breach action: block-clinical-deployment."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 3.4: Performance testing and validation"
         },
         {
          "href": "#5c236a56-0fd8-52fc-880b-5e213d233a3f",
          "rel": "reference",
          "text": "Principle 4: Transparent with regulator"
         },
         {
          "href": "#8e4fc90b-6135-5c7a-81da-30efe01e36ad",
          "rel": "reference",
          "text": "§170.315(b)(11)(iv): External validation process"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 10(3) (Testing data relevance and appropriateness)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§5.7: System and software testing"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§7: Risk evaluation"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 1.3 (independent assessors are involved in TEVV); MEASURE 2.3 (performance is demonstrated for conditions similar to deployment)"
         }
        ]
       },
       {
        "id": "hc-srf-l2-vv-002",
        "class": "srf-vertical-control",
        "title": "Subgroup Performance Equivalence",
        "params": [
         {
          "id": "hc-srf-l2-vv-002-p1",
          "label": "subgroup_performance_gap_rate",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "<="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "pre-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "{max_subgroup_performance_gap}"
          ],
          "guidelines": [
           {
            "prose": "Maximum allowable performance degradation (e.g., AUC drop, sensitivity drop) for any protected subgroup relative to overall model performance."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-VV-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data & Training"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-data-steward"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "verification-validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-clinical-deployment-and-remediate-bias"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "MeasureReport"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "measure (subgroup-performance), group.stratifier (demographic), measureScore"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-fda-pccp",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-62304",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l2-vv-002_stmt",
          "name": "statement",
          "prose": "Model performance (primary metric) must not degrade beyond the configured threshold across protected demographic subgroups (age, sex, race/ethnicity). Subgroup analysis must be included in the validation report and disclosed per ONC HTI-1 transparency requirements."
         },
         {
          "id": "hc-srf-l2-vv-002_obj",
          "name": "objective",
          "prose": "Maintain subgroup_performance_gap_rate <= {{ insert: param, hc-srf-l2-vv-002-p1 }} over window pre-deployment. Breach action: block-clinical-deployment-and-remediate-bias."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 3.4: Subgroup analysis"
         },
         {
          "href": "#8e4fc90b-6135-5c7a-81da-30efe01e36ad",
          "rel": "reference",
          "text": "§170.315(b)(11)(ii): Bias description and fairness"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 10(2)(f) (Bias examination)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (Accuracy across groups)"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§5: Risk estimation"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.11 (fairness and bias are evaluated across subgroups)"
         }
        ]
       },
       {
        "id": "hc-srf-l2-pms-001",
        "class": "srf-vertical-control",
        "title": "Input Distribution Drift Monitoring",
        "params": [
         {
          "id": "hc-srf-l2-pms-001-p1",
          "label": "psi_score",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "<="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "rolling-30d"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "{max_psi_score}"
          ],
          "guidelines": [
           {
            "prose": "Population Stability Index score for primary input features. PSI > 0.25 signals significant distribution shift requiring re-validation."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-PMS-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data & Training"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-data-steward"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "post-market-surveillance"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "trigger-revalidation-and-notify-governance"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Observation"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "code.code == 'psi-score', value[x], effectiveDateTime"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l2-pms-001_stmt",
          "name": "statement",
          "prose": "Production clinical AI systems must monitor for significant shifts in the distribution of input data relative to the training distribution. Population Stability Index (PSI) or equivalent metric must be computed continuously and trigger re-validation when the threshold is exceeded."
         },
         {
          "id": "hc-srf-l2-pms-001_obj",
          "name": "objective",
          "prose": "Maintain psi_score <= {{ insert: param, hc-srf-l2-pms-001-p1 }} over window rolling-30d. Breach action: trigger-revalidation-and-notify-governance."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 4.3: Real-world performance monitoring"
         },
         {
          "href": "#5c236a56-0fd8-52fc-880b-5e213d233a3f",
          "rel": "reference",
          "text": "Principle 5: Lifecycle-oriented; monitoring plan required"
         },
         {
          "href": "#8e4fc90b-6135-5c7a-81da-30efe01e36ad",
          "rel": "reference",
          "text": "§170.315(b)(11)(v): Ongoing maintenance"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 72 (Post-market monitoring obligations)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§6.2: Problem and modification process"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§10: Post-production activities"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.4 (the deployed AI system is monitored for changes in behavior and performance)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-10 (Model Continuous Monitoring)"
         }
        ]
       },
       {
        "id": "hc-srf-l2-pms-002",
        "class": "srf-vertical-control",
        "title": "Real-World Data Quality Scoring",
        "params": [
         {
          "id": "hc-srf-l2-pms-002-p1",
          "label": "data_completeness_rate",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-inference"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "{min_data_completeness_rate}"
          ],
          "guidelines": [
           {
            "prose": "Fraction of required input features present and within valid range for each inference request."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-PMS-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data & Training"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-data-steward"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "post-market-surveillance"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "flag-recommendation-to-clinician-with-data-quality-warning"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "MeasureReport"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "measure (data-quality-score), measureScore, period"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-fda-pccp",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-onc-hti1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l2-pms-002_stmt",
          "name": "statement",
          "prose": "Production inference inputs must be scored for data quality (completeness, value range validity, temporal consistency) on every inference cycle. Inferences on inputs below the data quality threshold must be flagged to the clinician before the AI recommendation is surfaced."
         },
         {
          "id": "hc-srf-l2-pms-002_obj",
          "name": "objective",
          "prose": "Maintain data_completeness_rate >= {{ insert: param, hc-srf-l2-pms-002-p1 }} over window per-inference. Breach action: flag-recommendation-to-clinician-with-data-quality-warning."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 4.2: Real-world data quality"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 10(3) (Testing data relevance in production)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§6.2: Software problem resolution"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§10.2: Information from post-production phase"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.4 (deployed system inputs and behavior are monitored)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-23 (Data Integrity Check)"
         }
        ]
       },
       {
        "id": "hc-srf-l2-pms-003",
        "class": "srf-vertical-control",
        "title": "Agent Context Store Integrity",
        "params": [
         {
          "id": "hc-srf-l2-pms-003-p1",
          "label": "context_store_integrity_verified",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-agent-session"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary per session: context store integrity hash check passes before each agent inference use."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-PMS-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data & Training"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-data-steward"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "post-market-surveillance"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "invalidate-session-and-alert-clinical-staff"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Provenance"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "entity (context store), signature, recorded"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-fda-pccp",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-onc-hti1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iso-14971",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l2-pms-003_stmt",
          "name": "statement",
          "prose": "For agentic clinical AI systems that maintain session memory or patient context stores (e.g., FHIR-backed context), the integrity of context data must be verified at each use. Context stores must be audited for unauthorized modification, and audit records must reference the source FHIR Provenance."
         },
         {
          "id": "hc-srf-l2-pms-003_obj",
          "name": "objective",
          "prose": "Maintain context_store_integrity_verified == {{ insert: param, hc-srf-l2-pms-003-p1 }} over window per-agent-session. Breach action: invalidate-session-and-alert-clinical-staff."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 4.2: Data integrity in production"
         },
         {
          "href": "#8d9146e5-7a72-5eac-a274-e74a728227e7",
          "rel": "reference",
          "text": "45 CFR §164.312(c)(1): Integrity controls"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (Risk management for agentic AI)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§5.7: Data integrity verification"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.7 (security and resilience are evaluated and documented)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM08: Vector and Embedding Weaknesses (session and patient context store integrity)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-14 (AI Cache Protection)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-23 (Data Integrity Check)"
         }
        ]
       }
      ]
     },
     {
      "id": "l2-insurance",
      "class": "srf-vertical",
      "title": "L2 — Insurance",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "insurance"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/insurance-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "ins-srf-l2-dev-001",
        "class": "srf-vertical-control",
        "title": "ECDIS Source Documentation and Permissible-Purpose Verification",
        "params": [
         {
          "id": "ins-srf-l2-dev-001-p1",
          "label": "ecdis_permissible_purpose_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Zero-tolerance: no ECDIS source may be used in production without a documented permissible-purpose determination and completed proxy screening."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-DEV-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Training"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "suspend-ECDIS-source-from-production; escalate-to-chief-compliance-officer; initiate-permissible-purpose-review"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact for permissible-purpose determination. Data pipeline events: api_activity (6003) for ECDIS API calls, with source identifier as a tracked attribute."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l2-dev-001_stmt",
          "name": "statement",
          "prose": "Any external consumer data or information source (ECDIS) used in underwriting, rating, or claims decisions must be documented with its source, data type, intended use, and a written permissible-purpose determination. Proxy variable screening per SRF-L2-DEV-002 must be completed before deployment. This control is the data-layer counterpart to the adverse-action explanation obligation in SRF-L3-VAL-001."
         },
         {
          "id": "ins-srf-l2-dev-001_obj",
          "name": "objective",
          "prose": "Maintain ecdis_permissible_purpose_documented == {{ insert: param, ins-srf-l2-dev-001-p1 }} over window per-deployment. Breach action: suspend-ECDIS-source-from-production; escalate-to-chief-compliance-officer; initiate-permissible-purpose-review."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 3.2 (data practices and accountability procedures covering currency, lineage, quality, integrity, bias analysis and minimization, and suitability - the bulletin does not define or use the term ECDIS)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit D (AI Systems Data Details: data element type, internal vs. third-party source)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 4(D) (ECDIS definition)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(A)(1) (governing principles ensuring ECDIS, algorithms, and predictive models are designed, developed, used, and monitored to achieve effective oversight and prevent unfair discrimination)"
         },
         {
          "href": "#c59939b3-2e4d-575b-878c-2a4ff0ee3ea1",
          "rel": "reference",
          "text": "Section II.A, paragraphs 11-12 (Data Actuarial Validity, Proxy Assessment)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 10 (data and data governance for high-risk AI systems)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 4.1 (legal and technology risks of third-party data are mapped); MEASURE 2.10 (privacy risk is examined)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-20 (Data Provenance and Transparency)"
         }
        ]
       },
       {
        "id": "ins-srf-l2-dev-002",
        "class": "srf-vertical-control",
        "title": "Protected-Class Proxy Variable Screening",
        "params": [
         {
          "id": "ins-srf-l2-dev-002-p1",
          "label": "proxy_variable_screen_completed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Zero-tolerance: no model or ECDIS source may enter production without a completed and documented proxy variable screen, reviewed and signed off by the accountable officer."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-DEV-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Training"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-deployment; escalate-to-chief-compliance-officer; initiate-proxy-variable-remediation"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact for screen results. Candidate: audit_activity (3002) if the model validation platform logs screening completion events."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l2-dev-002_stmt",
          "name": "statement",
          "prose": "Before any model or ECDIS source is deployed in underwriting, rating, or claims, the data-provider must complete a documented proxy variable screen to identify variables that may serve as proxies for race, color, national origin, religion, sex, marital status, or other protected characteristics. Identified proxy variables must be reviewed by the accountable officer and either removed or subject to a documented fairness mitigation plan."
         },
         {
          "id": "ins-srf-l2-dev-002_obj",
          "name": "objective",
          "prose": "Maintain proxy_variable_screen_completed == {{ insert: param, ins-srf-l2-dev-002-p1 }} over window per-deployment. Breach action: block-deployment; escalate-to-chief-compliance-officer; initiate-proxy-variable-remediation."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 3.2 (data bias analysis and minimization)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit D, Ref 2 (Age, Gender, Ethnicity/Race data element)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit B (Checklist) Ref 3a (assesses, mitigates, evaluates residual AI System risks of unfair trade practices)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(A)(1)(b) (governing principles reasonably designed to prevent unfair discrimination)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(A)(11) (quantitative testing to detect unfair discrimination with respect to race)"
         },
         {
          "href": "#c59939b3-2e4d-575b-878c-2a4ff0ee3ea1",
          "rel": "reference",
          "text": "Section II.A, paragraph 12 (Proxy Assessment)"
         },
         {
          "href": "#c59939b3-2e4d-575b-878c-2a4ff0ee3ea1",
          "rel": "reference",
          "text": "Section II.B-C, paragraphs 13-19 (Unfair and Unlawful Discrimination, Analyzing for Unfair or Unlawful Discrimination)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 10 (data governance, examination of possible biases and discriminatory data processing for high-risk AI)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.11 (fairness and bias are evaluated and documented)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-24 (Data Differentiation and Relevance)"
         }
        ]
       },
       {
        "id": "ins-srf-l2-dev-003",
        "class": "srf-vertical-control",
        "title": "Training Data Representativeness by Line of Business",
        "params": [
         {
          "id": "ins-srf-l2-dev-003-p1",
          "label": "training_data_representativeness_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: representativeness assessment completed and documented before model deployment, with findings incorporated into the model validation plan."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-DEV-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Training"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-deployment; document-representativeness-gap; initiate-data-remediation-or-scope-restriction"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact for representativeness assessment. Candidate: security_finding (2001) if model monitoring platform emits data quality findings."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l2-dev-003_stmt",
          "name": "statement",
          "prose": "Training datasets for models used in underwriting, rating, or claims must be assessed for demographic and geographic representativeness relative to the insurer's book of business and the applicable line of business. Representativeness gaps must be documented and addressed in the model validation plan. This control applies to internally trained models and to vendor model evaluations under SRF-L5-VAL-001."
         },
         {
          "id": "ins-srf-l2-dev-003_obj",
          "name": "objective",
          "prose": "Maintain training_data_representativeness_documented == {{ insert: param, ins-srf-l2-dev-003-p1 }} over window per-deployment. Breach action: block-deployment; document-representativeness-gap; initiate-data-remediation-or-scope-restriction."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 3.2 (data currency, lineage, quality, integrity, bias analysis and minimization, and suitability)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit D (data element details, e.g. Geo-Demographics, Household Composition, enabling representativeness assessment by line of business)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(A)(11) (documented description of quantitative testing methodology, assumptions, and results - scoped to race, not general representativeness)"
         },
         {
          "href": "#c59939b3-2e4d-575b-878c-2a4ff0ee3ea1",
          "rel": "reference",
          "text": "Section II.C, paragraph 18 (Quantitative Assessment metrics: Adverse Impact Ratio, Denial Odds Ratios, Standardized Mean Differences)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 10 (training data requirements for high-risk AI systems)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.11 (fairness and bias are evaluated); MAP 2.3 (data collection and selection considerations are documented)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-24 (Data Differentiation and Relevance)"
         }
        ]
       },
       {
        "id": "ins-srf-l2-val-001",
        "class": "srf-vertical-control",
        "title": "External Data Source Permissible Use Audit",
        "params": [
         {
          "id": "ins-srf-l2-val-001-p1",
          "label": "external_data_permissible_use_audited",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: permissible-use audit completed for all external data sources in the deployment package before production go-live."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-VAL-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Training"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "validation-testing"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-deployment; escalate-to-legal; remove-unaudited-data-sources"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact. Audit results are governance records."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-naic-eval-tool",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l2-val-001_stmt",
          "name": "statement",
          "prose": "Before production deployment, all external data sources must undergo a permissible-use audit confirming that each source's terms of use, data license, and applicable regulatory permissions cover the intended insurance use case. The audit result must be retained in the model documentation package."
         },
         {
          "id": "ins-srf-l2-val-001_obj",
          "name": "objective",
          "prose": "Maintain external_data_permissible_use_audited == {{ insert: param, ins-srf-l2-val-001-p1 }} over window per-deployment. Breach action: block-deployment; escalate-to-legal; remove-unaudited-data-sources."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 4.1 (due diligence on third-party data sources)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(A)(13) (process for selecting external resources including third-party vendors that supply ECDIS)"
         },
         {
          "href": "#c59939b3-2e4d-575b-878c-2a4ff0ee3ea1",
          "rel": "reference",
          "text": "Section III.B, paragraph 29(c) (documentation describing how each AIS operates, including ECDIS or other inputs and their sources)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 10 (data governance for high-risk AI)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 4.1 (legal and technology risks of third-party data are mapped)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-20 (Data Provenance and Transparency)"
         }
        ]
       },
       {
        "id": "ins-srf-l2-mon-001",
        "class": "srf-vertical-control",
        "title": "Input Drift Monitoring via Population Stability Index",
        "params": [
         {
          "id": "ins-srf-l2-mon-001-p1",
          "label": "input_psi_max",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "<"
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "monthly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_PSI_DRIFT_THRESHOLD"
          ],
          "guidelines": [
           {
            "prose": "Maximum PSI across monitored input variables in the current monitoring window. Tier-configurable; recommended threshold: PSI < 0.2 for stable, 0.2-0.25 for minor drift requiring review, > 0.25 for significant drift requiring model review."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-MON-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Training"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "trigger-model-review; notify-model-owner; escalate-to-chief-actuary-if-drift-persists-two-cycles"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "detection_finding (2004): AI monitoring platform emits drift findings when PSI exceeds threshold. Attributes: finding.title = 'input_drift'; analytic.type = 'statistical'; severity_id based on PSI band."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finding.title == 'input_drift' AND analytic.type == 'statistical'"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-nydfs-cl7",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l2-mon-001_stmt",
          "name": "statement",
          "prose": "For each model in production use, the data-provider or model operator must monitor the distribution of input variables against the training baseline using the Population Stability Index (PSI) or an equivalent statistical measure. Drift beyond the tier-configurable threshold triggers model review. This control is the data-layer counterpart to the performance disclosure obligation in SRF-L5-MON-001."
         },
         {
          "id": "ins-srf-l2-mon-001_obj",
          "name": "objective",
          "prose": "Maintain input_psi_max < {{ insert: param, ins-srf-l2-mon-001-p1 }} over window monthly. Breach action: trigger-model-review; notify-model-owner; escalate-to-chief-actuary-if-drift-persists-two-cycles."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 3.3(c) (Model Drift, auditability of these measurements where appropriate)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit C, Ref 8 (testing model outputs including model drift, accuracy, performance degradation, and how model performance is monitored on an ongoing basis)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(A)(12) (documented description of ongoing monitoring regarding the performance of algorithms and predictive models, including model drift)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 72 (post-market monitoring, performance drift reporting)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.4 (the deployed AI system is monitored for changes)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-10 (Model Continuous Monitoring)"
         }
        ]
       },
       {
        "id": "ins-srf-l2-mon-002",
        "class": "srf-vertical-control",
        "title": "Consumer Data Minimization in Agent Context Stores",
        "params": [
         {
          "id": "ins-srf-l2-mon-002-p1",
          "label": "agent_context_pii_retention_violation_count",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-session"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "0"
          ],
          "guidelines": [
           {
            "prose": "Zero-tolerance: no consumer PII or sensitive insurance data retained in agent context stores beyond the configured session retention window without explicit authorization."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-MON-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Training"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "purge-affected-context-stores; notify-data-privacy-officer; suspend-affected-agent-workflows-pending-investigation"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "security_finding (2001): data loss prevention or context store audit system emits findings when PII retention exceeds configured window. Attributes: finding.type_id = data_retention_violation; data.classification = 'PII'."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finding.type_id == 'data_retention_violation' AND data.classification == 'PII'"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-naic-model-bulletin",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-naic-eval-tool",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-co-reg-10-1-1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nydfs-cl7",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l2-mon-002_stmt",
          "name": "statement",
          "prose": "Agentic AI systems used in claims, underwriting, or customer service must enforce data minimization in context stores and retrieval-augmented generation (RAG) pipelines. Consumer PII and sensitive insurance data retained in agent context must be scoped to the current session and purged within the configured retention window. Persistent cross-session consumer profiles must not be built without explicit authorization."
         },
         {
          "id": "ins-srf-l2-mon-002_obj",
          "name": "objective",
          "prose": "Maintain agent_context_pii_retention_violation_count == {{ insert: param, ins-srf-l2-mon-002-p1 }} over window per-session. Breach action: purge-affected-context-stores; notify-data-privacy-officer; suspend-affected-agent-workflows-pending-investigation."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 10 (data governance and minimisation for high-risk AI systems)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM02 (Sensitive Information Disclosure)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.10 (privacy risk is examined and documented)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-04 (Data Classification)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-14 (AI Cache Protection)"
         }
        ]
       },
       {
        "id": "ins-srf-l2-mon-003",
        "class": "srf-vertical-control",
        "title": "Algorithmic Model Input Completeness Monitoring",
        "params": [
         {
          "id": "ins-srf-l2-mon-003-p1",
          "label": "model_input_missing_rate_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "<"
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "monthly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_INPUT_MISSING_RATE_THRESHOLD_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of input records with one or more missing required variables. Tier-configurable; triggers model review when above threshold for two consecutive monitoring windows."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-MON-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Training"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "investigate-data-pipeline; notify-model-owner; escalate-if-persists-two-cycles"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "detection_finding (2004): data quality monitoring platform emits findings on input completeness degradation."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finding.title == 'input_completeness_degradation'"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-co-reg-10-1-1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nydfs-cl7",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l2-mon-003_stmt",
          "name": "statement",
          "prose": "For each model in production use, the rate of missing or null values in required input variables must be monitored against the training baseline. Sustained incompleteness above the tier-configurable threshold may indicate upstream data pipeline failure, ECDIS source degradation, or a distribution shift requiring model review."
         },
         {
          "id": "ins-srf-l2-mon-003_obj",
          "name": "objective",
          "prose": "Maintain model_input_missing_rate_pct < {{ insert: param, ins-srf-l2-mon-003-p1 }} over window monthly. Breach action: investigate-data-pipeline; notify-model-owner; escalate-if-persists-two-cycles."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 3.2 (data quality and integrity)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit C, Ref 8 (testing model outputs including performance degradation - general nexus, not an input-completeness-specific field)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 72 (post-market monitoring, performance indicators)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.4 (deployed system inputs are monitored); MEASURE 2.5 (validity and reliability are documented)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-23 (Data Integrity Check)"
         }
        ]
       },
       {
        "id": "ins-srf-l2-tpo-001",
        "class": "srf-vertical-control",
        "title": "Vendor Data Lineage Documentation",
        "params": [
         {
          "id": "ins-srf-l2-tpo-001-p1",
          "label": "vendor_data_lineage_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual-review"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: data lineage documentation provided by vendor, reviewed by insurer, and retained in the vendor file. Required at onboarding and refreshed at each annual review."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-TPO-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Training"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "third-party-oversight"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "suspend-vendor-data-source; request-documentation; escalate-to-chief-risk-officer-if-not-remediated-within-30-days"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact. Vendor documentation is a governance record."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l2-tpo-001_stmt",
          "name": "statement",
          "prose": "Third-party AI vendors providing models or ECDIS sources must supply documented data lineage covering training data sources, data collection methods, processing steps, and retention policies. The insurer must review and retain this documentation as part of vendor onboarding and annual review under SRF-L1-TPO-001."
         },
         {
          "id": "ins-srf-l2-tpo-001_obj",
          "name": "objective",
          "prose": "Maintain vendor_data_lineage_documented == {{ insert: param, ins-srf-l2-tpo-001-p1 }} over window annual-review. Breach action: suspend-vendor-data-source; request-documentation; escalate-to-chief-risk-officer-if-not-remediated-within-30-days."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 3.2 (data lineage)"
         },
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 4.1 (due diligence on third-party data)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit D (Internal Data Source / Third Party Data Source-Vendor Name columns)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit C, Ref 4 (model development internal or third party, including vendor name)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(A)(13) (process for selecting external resources and third-party vendors)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(B) (insurer oversight of external resources)"
         },
         {
          "href": "#c59939b3-2e4d-575b-878c-2a4ff0ee3ea1",
          "rel": "reference",
          "text": "Section III.B, paragraph 29(c) (description of ECDIS or other inputs and their sources)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 11 (technical documentation for high-risk AI including training data description)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 4.1 (legal and technology risks of third-party data are mapped); GOVERN 6.1 (third-party policies are in place)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-20 (Data Provenance and Transparency)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-11 (Supply Chain Agreement Review)"
         }
        ]
       }
      ]
     },
     {
      "id": "l2-defense",
      "class": "srf-vertical",
      "title": "L2 — Defense",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "defense"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/defense-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "def-srf-l2-acq-001",
        "class": "srf-vertical-control",
        "title": "CUI Classification and Marking on AI Inputs and Outputs",
        "params": [
         {
          "id": "def-srf-l2-acq-001-p1",
          "label": "cui_marking_compliance_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "quarterly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_CUI_MARKING_COMPLIANCE_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of AI data assets in scope confirmed as correctly marked per CUI Registry requirements."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-ACQ-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Feedback"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Traceable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.1.3"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "quarantine-unclassified-assets; notify-ISSO; remediate-within-10-days"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data_security_finding (2004). Data classification scan results may emit findings against unclassified or mismarked objects."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l2-acq-001_stmt",
          "name": "statement",
          "prose": "All data inputs to and outputs from the AI system that contain Controlled Unclassified Information must be classified and marked per 32 CFR Part 2002 and the CUI Registry before use or release. The component must verify that AI-generated outputs do not aggregate or synthesize CUI in ways that elevate the effective classification."
         },
         {
          "id": "def-srf-l2-acq-001_obj",
          "name": "objective",
          "prose": "Maintain cui_marking_compliance_pct >= {{ insert: param, def-srf-l2-acq-001-p1 }} over window quarterly. Breach action: quarantine-unclassified-assets; notify-ISSO; remediate-within-10-days."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Traceable principle"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "AC.L2-3.1.3 (control the flow of CUI)"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.1.3"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 1.6"
         },
         {
          "href": "#c5d89a8d-2be1-526a-977f-3cc51013206f",
          "rel": "reference",
          "text": "Mission Owner SRG Section 3.3.3 (CUI assignment to Impact Levels 4 and 5)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM02: Sensitive Information Disclosure"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-04 (Data Classification)"
         }
        ]
       },
       {
        "id": "def-srf-l2-ops-002",
        "class": "srf-vertical-control",
        "title": "IL-Level Data Boundary Enforcement and Tenant Isolation",
        "params": [
         {
          "id": "def-srf-l2-ops-002-p1",
          "label": "cross_boundary_data_flow_alerts",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "TIER_CROSS_BOUNDARY_ALERTS"
          ],
          "guidelines": [
           {
            "prose": "Number of unresolved cross-IL boundary data flow alerts in the monitoring period. Zero-tolerance: any unresolved alert is a breach."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-OPS-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Feedback"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.1.3"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.13.1"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-data-flow; alert-ISSO; open-security-incident"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "network_activity (4001) or data_security_finding (2004). Cross-boundary flows must generate a finding with source and destination classification tags."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l2-ops-002_stmt",
          "name": "statement",
          "prose": "The platform must enforce data boundaries such that IL4 data cannot flow to IL5 or IL6 environments, and IL5 non-NSS data cannot flow to IL5 NSS or IL6 partitions. For cloud deployments, tenant isolation must be verified against the DISA PA for the applicable IL. Any cross-boundary data flow must trigger an alert."
         },
         {
          "id": "def-srf-l2-ops-002_obj",
          "name": "objective",
          "prose": "Maintain cross_boundary_data_flow_alerts == {{ insert: param, def-srf-l2-ops-002-p1 }} over window continuous. Breach action: block-data-flow; alert-ISSO; open-security-incident."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Reliable principle"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "AC.L2-3.1.3 (control the flow of CUI)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "SC.L2-3.13.1 (boundary protection)"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.1.3"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.6"
         },
         {
          "href": "#c5d89a8d-2be1-526a-977f-3cc51013206f",
          "rel": "reference",
          "text": "CSP SRG Section 5.2.2 (Impact Level Separation Requirements)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM02: Sensitive Information Disclosure"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-04 (Data Classification)"
         }
        ]
       },
       {
        "id": "def-srf-l2-acq-003",
        "class": "srf-vertical-control",
        "title": "Training Data Authority-to-Use Documentation",
        "params": [
         {
          "id": "def-srf-l2-acq-003-p1",
          "label": "training_data_atu_documented_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_ATU_DOCUMENTED_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of training datasets in use for which authority-to-use documentation is complete and current."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-ACQ-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Feedback"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Traceable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "suspend-use-of-undocumented-data; notify-data-steward; remediate-within-30-days"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Data catalog entries with authority-to-use records may map to audit_activity (3002)."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l2-acq-003_stmt",
          "name": "statement",
          "prose": "The component must document the authority to use each training dataset, including data rights clauses, any restrictions on use for AI training, ITAR/EAR applicability, and PII/PHI presence. Documentation must be retained for the life of the system and updated when training data sources change."
         },
         {
          "id": "def-srf-l2-acq-003_obj",
          "name": "objective",
          "prose": "Maintain training_data_atu_documented_pct >= {{ insert: param, def-srf-l2-acq-003-p1 }} over window annual. Breach action: suspend-use-of-undocumented-data; notify-data-steward; remediate-within-30-days."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Traceable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 3.1.3 (government IP and data rights best practices in AI acquisition)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 1.6"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM03: Supply Chain"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-20 (Data Provenance and Transparency)"
         }
        ]
       },
       {
        "id": "def-srf-l2-ops-004",
        "class": "srf-vertical-control",
        "title": "Data Egress Controls per Classification Level",
        "params": [
         {
          "id": "def-srf-l2-ops-004-p1",
          "label": "unauthorized_egress_events",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "TIER_UNAUTHORIZED_EGRESS_EVENTS"
          ],
          "guidelines": [
           {
            "prose": "Number of unauthorized data egress events detected per monitoring period. Zero-tolerance."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-OPS-004"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Feedback"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.1.3"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.13.5"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-egress; alert-ISSO; open-security-incident; notify-AO"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "network_activity (4001). Egress events must log source environment, destination, data classification, and detection method."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l2-ops-004_stmt",
          "name": "statement",
          "prose": "The system must enforce data egress controls that prevent AI outputs containing CUI or classified information from leaving the authorized environment. For IL6 systems, egress must be blocked at the classified enclave boundary. For IL4/IL5, controls must match the DISA PA requirements and be validated during TEVV."
         },
         {
          "id": "def-srf-l2-ops-004_obj",
          "name": "objective",
          "prose": "Maintain unauthorized_egress_events == {{ insert: param, def-srf-l2-ops-004-p1 }} over window continuous. Breach action: block-egress; alert-ISSO; open-security-incident; notify-AO."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Responsible principle"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "AC.L2-3.1.3 (control the flow of CUI)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "SC.L2-3.13.5 (subnetworks for publicly accessible components)"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.1.3"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 2.4"
         },
         {
          "href": "#c5d89a8d-2be1-526a-977f-3cc51013206f",
          "rel": "reference",
          "text": "Mission Owner SRG Section 3.3.2 (VDSS security stack and DMZ zone data flow requirements)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM02: Sensitive Information Disclosure"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "LOG-15 (Output Monitoring)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-04 (Data Classification)"
         }
        ]
       },
       {
        "id": "def-srf-l2-ops-005",
        "class": "srf-vertical-control",
        "title": "Adversarial Input Detection (Prompt Injection and Data Poisoning)",
        "params": [
         {
          "id": "def-srf-l2-ops-005-p1",
          "label": "adversarial_detection_coverage_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_ADVERSARIAL_DETECTION_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of AI inference endpoints covered by active prompt injection detection controls."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-OPS-005"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Feedback"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.14.1"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.14.2"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-input; alert-SOC; escalate-to-cybersecurity-team"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "security_finding (2001). Adversarial input events must log the detected pattern, endpoint, and response action."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l2-ops-005_stmt",
          "name": "statement",
          "prose": "The system must deploy detection controls for prompt injection attacks and data poisoning attempts. Detection must cover both the inference-time layer (malicious user inputs) and the training pipeline (poisoned data sources). Alerts must be generated and routed to the security operations center."
         },
         {
          "id": "def-srf-l2-ops-005_obj",
          "name": "objective",
          "prose": "Maintain adversarial_detection_coverage_pct >= {{ insert: param, def-srf-l2-ops-005-p1 }} over window continuous. Breach action: block-input; alert-SOC; escalate-to-cybersecurity-team."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Reliable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 2.1.2 (AI T&E Toolkit: tools to detect adversarial attacks and natural degradation)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "SI.L2-3.14.1 (identify, report, and correct system flaws)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "SI.L2-3.14.2 (malicious code protection at designated locations)"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.14.1"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.6"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM01: Prompt Injection"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM04: Data and Model Poisoning"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-08 (Input Validation)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-21 (Data Poisoning Prevention & Detection)"
         }
        ]
       },
       {
        "id": "def-srf-l2-ops-006",
        "class": "srf-vertical-control",
        "title": "Bias and Disparate Impact Monitoring on Consequential Decisions",
        "params": [
         {
          "id": "def-srf-l2-ops-006-p1",
          "label": "bias_analysis_current",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_BIAS_ANALYSIS_CURRENT"
          ],
          "guidelines": [
           {
            "prose": "Binary: a bias and disparate impact analysis has been completed within the prior review cycle for every in-scope consequential AI use case."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-OPS-006"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Feedback"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Equitable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "notify-RAI-officer; schedule-analysis; document-gap"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Analysis reports may map to audit_activity (3002)."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l2-ops-006_stmt",
          "name": "statement",
          "prose": "For AI systems that make or inform personnel, benefits, or enforcement decisions, the component must conduct periodic bias and disparate impact analyses disaggregated by protected characteristics as applicable. Results must be reviewed by the RAI Officer and remediated if disparate impact exceeds established thresholds."
         },
         {
          "id": "def-srf-l2-ops-006_obj",
          "name": "objective",
          "prose": "Maintain bias_analysis_current == {{ insert: param, def-srf-l2-ops-006-p1 }} over window annual. Breach action: notify-RAI-officer; schedule-analysis; document-gap."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Equitable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 3.2.5 (best practices to avoid unintended bias in AI capabilities using personal information)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.5"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-10 (AI Impact Assessment)"
         }
        ]
       },
       {
        "id": "def-srf-l2-ops-007",
        "class": "srf-vertical-control",
        "title": "AI Decision Log Retention per NARA Requirements",
        "params": [
         {
          "id": "def-srf-l2-ops-007-p1",
          "label": "decision_log_retention_compliant",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: decision logs are retained for the required period as verified by the records manager and ISSO."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-OPS-007"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Feedback"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Traceable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.3.1"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "notify-records-manager; extend-retention-period; document-gap"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "audit_activity (3002). Log retention compliance may be verified via audit of log storage configuration and retention policy."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l2-ops-007_stmt",
          "name": "statement",
          "prose": "The component must retain logs of AI system decisions, operator overrides, and model version identifiers in accordance with NARA records schedules applicable to the underlying decision type. Retention periods must be configured before system deployment and reviewed when NARA schedules are updated."
         },
         {
          "id": "def-srf-l2-ops-007_obj",
          "name": "objective",
          "prose": "Maintain decision_log_retention_compliant == {{ insert: param, def-srf-l2-ops-007-p1 }} over window annual. Breach action: notify-records-manager; extend-retention-period; document-gap."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Traceable principle"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "AU.L2-3.3.1 (create and retain system audit logs and records)"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.3.1"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.5"
         }
        ]
       },
       {
        "id": "def-srf-l2-acq-008",
        "class": "srf-vertical-control",
        "title": "Contractor Data Isolation from DoD Data Planes",
        "params": [
         {
          "id": "def-srf-l2-acq-008-p1",
          "label": "contractor_data_isolation_verified",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: contractor data isolation architecture has been verified in the most recent TEVV cycle or annual audit."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-ACQ-008"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Feedback"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "contractor"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.1.3"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.13.1"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "notify-contracting-officer; restrict-contractor-access; open-security-incident"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "audit_activity (3002). Isolation verification may include network segmentation scan results and access log review."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l2-acq-008_stmt",
          "name": "statement",
          "prose": "Contractor-operated AI systems must be architected so that contractor infrastructure does not have persistent access to DoD data planes beyond the scope of the contract. Data isolation requirements must be specified in the contract, verified during TEVV, and audited annually."
         },
         {
          "id": "def-srf-l2-acq-008_obj",
          "name": "objective",
          "prose": "Maintain contractor_data_isolation_verified == {{ insert: param, def-srf-l2-acq-008-p1 }} over window annual. Breach action: notify-contracting-officer; restrict-contractor-access; open-security-incident."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Responsible principle"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "AC.L2-3.1.3 (control the flow of CUI)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "SC.L2-3.13.1 (boundary protection)"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.1.3"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 5.2"
         },
         {
          "href": "#c5d89a8d-2be1-526a-977f-3cc51013206f",
          "rel": "reference",
          "text": "Mission Owner SRG Section 3.3.3 (third-party developers prohibited from storing DOD CUI in unauthorized impact levels or corporate networks)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "IAM-16 (Authorization Mechanisms)"
         }
        ]
       },
       {
        "id": "def-srf-l2-tevv-009",
        "class": "srf-vertical-control",
        "title": "Training and RAG Data Integrity Verification Before Deployment",
        "params": [
         {
          "id": "def-srf-l2-tevv-009-p1",
          "label": "data_integrity_signoff_before_deployment",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-system"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a data integrity verification record exists for every data source in scope, signed by the data authority, before the TEVV plan is closed and the system is promoted to IOC."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-TEVV-009"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Input"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Traceable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.11.1"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.11.3"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "tevv"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Block promotion to IOC. Data authority must complete sign-off. Log gap in TEVV report."
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact"
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l2-tevv-009_stmt",
          "name": "statement",
          "prose": "Before a model or RAG pipeline is promoted to any operational environment, the data provider must verify that all training and retrieval data sources have passed quality and provenance checks: authority-to-use documented, CUI markings validated at the required IL, and a data lineage record retained. For IL5 and IL6 systems, a formal data integrity sign-off by the Chief Data Officer or delegated data authority is required before the TEVV plan closes."
         },
         {
          "id": "def-srf-l2-tevv-009_obj",
          "name": "objective",
          "prose": "Maintain data_integrity_signoff_before_deployment == {{ insert: param, def-srf-l2-tevv-009-p1 }} over window per-system. Breach action: Block promotion to IOC. Data authority must complete sign-off. Log gap in TEVV report.."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Traceable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Reliable principle"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "RA.L2-3.11.1 (periodic risk assessments)"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.11.1"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 2.2"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM03: Supply Chain"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM04: Data and Model Poisoning"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-23 (Data Integrity Check)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-21 (Data Poisoning Prevention & Detection)"
         }
        ]
       },
       {
        "id": "def-srf-l2-ovr-010",
        "class": "srf-vertical-control",
        "title": "AI Decision Log Human Review Cadence for High-Stakes Operations",
        "params": [
         {
          "id": "def-srf-l2-ovr-010-p1",
          "label": "decision_log_review_cadence_met",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_DECISION_LOG_REVIEW_COVERAGE_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of required review periods in the window during which a completed human review of AI decision logs is on record. IL4: quarterly (4 reviews/year), IL5: monthly (12/year), IL6: weekly (52/year)."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-OVR-010"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Input"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Equitable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Traceable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.3.1"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.3.2"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "human-oversight-remedy"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Notify CDAO liaison and program manager. Complete overdue reviews. Assess whether anomalous patterns were missed during the gap period."
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "2004"
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l2-ovr-010_stmt",
          "name": "statement",
          "prose": "For AI systems making or informing high-stakes decisions (personnel actions, logistics prioritization, target data triage), the data provider and system owner must conduct periodic human reviews of AI decision logs to detect anomalous patterns, data drift, or systematic bias. Review frequency scales with impact level: IL4 quarterly, IL5 monthly, IL6 continuous with a formal review no less than weekly. Findings must be reported to the CDAO liaison."
         },
         {
          "id": "def-srf-l2-ovr-010_obj",
          "name": "objective",
          "prose": "Maintain decision_log_review_cadence_met >= {{ insert: param, def-srf-l2-ovr-010-p1 }} over window annual. Breach action: Notify CDAO liaison and program manager. Complete overdue reviews. Assess whether anomalous patterns were missed during the gap period.."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Equitable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Traceable principle"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "AU.L2-3.3.1 (audit logs enabling monitoring, analysis, and investigation)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "AU.L2-3.3.2 (trace actions to individual users)"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.3.1"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.5"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-15 (Human supervision)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "LOG-15 (Output Monitoring)"
         }
        ]
       }
      ]
     },
     {
      "id": "l2-manufacturing",
      "class": "srf-vertical",
      "title": "L2 — Manufacturing",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "manufacturing"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/manufacturing-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "mfg-srf-l2-des-001",
        "class": "srf-vertical-control",
        "title": "Sensor and Historian Data Provenance Documentation",
        "params": [
         {
          "id": "mfg-srf-l2-des-001-p1",
          "label": "data_provenance_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-model-version"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Provenance documentation exists for all training and inference data sources used by OT-edge AI systems."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-DES-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Input"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturer"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ot-only"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL1"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "document-data-sources; assign-data-provider; include-in-technical-file"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Data provenance record per data source."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l2-des-001_stmt",
          "name": "statement",
          "prose": "For every AI system using plant sensor or historian data as training or inference input, the data provider must document: the data source (sensor ID, historian tag, PLC address), authority-to-use (operational license or site ownership), data quality specification (sampling rate, expected range, known degradation conditions), and chain of custody for data used in model training. Documentation must be retained as part of the EU AI Act technical file for high-risk systems."
         },
         {
          "id": "mfg-srf-l2-des-001_obj",
          "name": "objective",
          "prose": "Maintain data_provenance_documented == {{ insert: param, mfg-srf-l2-des-001-p1 }} over window per-model-version. Breach action: document-data-sources; assign-data-provider; include-in-technical-file."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 10 (data and data governance)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Annex IV (technical documentation data section)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-2-1 (part-level)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 3.1"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-20 (Data Provenance and Transparency)"
         }
        ]
       },
       {
        "id": "mfg-srf-l2-des-002",
        "class": "srf-vertical-control",
        "title": "Training Data Authority-to-Use for Production Data",
        "params": [
         {
          "id": "mfg-srf-l2-des-002-p1",
          "label": "training_atu_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-training-run"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Authority-to-use documented for all production data sources used in model training before training commences."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-DES-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Input"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturer"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "obtain-authorization; document-legal-basis; pause-training-until-authorized"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Authority-to-use record with agreement reference."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-62443",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l2-des-002_stmt",
          "name": "statement",
          "prose": "The data provider must establish and document the contractual or operational basis authorizing use of plant production data for training or fine-tuning AI models. Where production data was collected under operational agreements that do not explicitly authorize AI training use, the data provider must obtain explicit authorization before training commences. The authority-to-use record must reference the applicable agreement and be retained as part of the technical file."
         },
         {
          "id": "mfg-srf-l2-des-002_obj",
          "name": "objective",
          "prose": "Maintain training_atu_documented == {{ insert: param, mfg-srf-l2-des-002-p1 }} over window per-training-run. Breach action: obtain-authorization; document-legal-basis; pause-training-until-authorized."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 10 (data governance, legal basis for data use)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 3.2"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-20 (Data Provenance and Transparency)"
         }
        ]
       },
       {
        "id": "mfg-srf-l2-ops-003",
        "class": "srf-vertical-control",
        "title": "OT/IT Data Boundary Enforcement",
        "params": [
         {
          "id": "mfg-srf-l2-ops-003-p1",
          "label": "ot_data_boundary_violations",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "0"
          ],
          "guidelines": [
           {
            "prose": "Count of data traversals from OT zones to IT or cloud without an approved conduit record in the current period."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-OPS-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Input"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturer"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ot-only"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL1"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL3"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-unapproved-traversal; alert-ot-security; initiate-conduit-review"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "network_activity (4001) or audit_activity (3002). Log source: OT data diode or conduit gateway syslog."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dst_endpoint.zone; src_endpoint.zone; observables"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l2-ops-003_stmt",
          "name": "statement",
          "prose": "No training or fine-tuning data may traverse from OT network zones to cloud or IT networks without traversing an approved conduit documented in the IEC 62443 zone-and-conduit model. Every such traversal must be logged with source zone, destination, data type, volume, and timestamp. The data provider must verify conduit approval before each extraction and retain traversal audit logs for the period specified in the site data retention policy."
         },
         {
          "id": "mfg-srf-l2-ops-003_obj",
          "name": "objective",
          "prose": "Maintain ot_data_boundary_violations == {{ insert: param, mfg-srf-l2-ops-003-p1 }} over window continuous. Breach action: block-unapproved-traversal; alert-ot-security; initiate-conduit-review."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 10 (data governance)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-3-3 (part-level)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 3.5"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-04 (Data Classification)"
         }
        ]
       },
       {
        "id": "mfg-srf-l2-ops-004",
        "class": "srf-vertical-control",
        "title": "Input Data Drift Monitoring",
        "params": [
         {
          "id": "mfg-srf-l2-ops-004-p1",
          "label": "input_psi_score",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "<="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "TIER_DRIFT_MONITORING_WINDOW"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_INPUT_PSI_THRESHOLD"
          ],
          "guidelines": [
           {
            "prose": "Population Stability Index (or equivalent) on primary model input features. Lower is better; alert threshold set by operating model and criticality."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-OPS-004"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Input"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL1"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "alert-data-provider; investigate-root-cause; consider-retraining-or-fallback"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "api_activity (6003) or model inference log. Drift score computed by data monitoring tool."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "observables; metadata.drift_score"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l2-ops-004_stmt",
          "name": "statement",
          "prose": "For AI systems with tier-configurable thresholds, the data provider must monitor input data distribution drift using a statistical measure (Population Stability Index or equivalent) on sensor or process variable inputs. The drift metric must be computed at least as frequently as the configured monitoring window and trigger an alert when the threshold is exceeded. Drift alerts must be investigated within the configured response window."
         },
         {
          "id": "mfg-srf-l2-ops-004_obj",
          "name": "objective",
          "prose": "Maintain input_psi_score <= {{ insert: param, mfg-srf-l2-ops-004-p1 }} over window TIER_DRIFT_MONITORING_WINDOW. Breach action: alert-data-provider; investigate-root-cause; consider-retraining-or-fallback."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 72 (post-market monitoring)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (risk management system)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-2-1 (part-level)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.5"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-10 (Model Continuous Monitoring)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "LOG-14 (Input Monitoring)"
         }
        ]
       },
       {
        "id": "mfg-srf-l2-val-005",
        "class": "srf-vertical-control",
        "title": "Training Data Bias Assessment for Consequential AI",
        "params": [
         {
          "id": "mfg-srf-l2-val-005-p1",
          "label": "bias_assessment_completed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-model-version"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Training data bias assessment completed, documented, and reviewed before model deployment for consequential AI systems."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-VAL-005"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Input"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "it-only"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "complete-bias-assessment; document-mitigations; update-technical-file"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Bias assessment report with methodology and findings."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-62443",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l2-val-005_stmt",
          "name": "statement",
          "prose": "For AI systems used in personnel, quality, or safety decisions, the data provider must conduct a training data bias assessment before model deployment. The assessment must evaluate representation across relevant subgroups (shift, plant, demographic where applicable), identify and document known gaps, and specify mitigations applied. Assessment results must be retained as part of the technical file for high-risk systems."
         },
         {
          "id": "mfg-srf-l2-val-005_obj",
          "name": "objective",
          "prose": "Maintain bias_assessment_completed == {{ insert: param, mfg-srf-l2-val-005-p1 }} over window per-model-version. Breach action: complete-bias-assessment; document-mitigations; update-technical-file."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 10 (data governance, bias examination)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Annex IV (bias documentation)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.11"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-24 (Data Differentiation and Relevance)"
         }
        ]
       },
       {
        "id": "mfg-srf-l2-ops-006",
        "class": "srf-vertical-control",
        "title": "Adversarial Input Detection for OT-Edge AI",
        "params": [
         {
          "id": "mfg-srf-l2-ops-006-p1",
          "label": "adversarial_input_alert_coverage",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_OT_ANOMALY_DETECTION_COVERAGE_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of OT-edge AI systems with anomaly detection active on primary process variable inputs."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-OPS-006"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Input"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ot-only"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL3"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "deploy-anomaly-detection; alert-ot-security; investigate-uncovered-systems"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "detection_finding (2004). Source: OT anomaly detection platform."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finding.type; src_endpoint.name; severity_id"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Annex I item TBD (protection against third-party attacks)",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l2-ops-006_stmt",
          "name": "statement",
          "prose": "AI systems deployed in OT/ICS environments must include anomaly detection on process variable inputs to identify adversarial manipulation or sensor spoofing. The detection mechanism must be configured with thresholds appropriate to the process's normal operating envelope and must alert the OT security team and process operator on detection. Detection events must be logged and investigated."
         },
         {
          "id": "mfg-srf-l2-ops-006_obj",
          "name": "objective",
          "prose": "Maintain adversarial_input_alert_coverage >= {{ insert: param, mfg-srf-l2-ops-006-p1 }} over window continuous. Breach action: deploy-anomaly-detection; alert-ot-security; investigate-uncovered-systems."
         },
         {
          "id": "mfg-srf-l2-ops-006_gdn",
          "name": "guidance",
          "prose": "mapping-status-note: IEC 61508 clause reference requires verification against primary text. EU Machinery Regulation Annex I item number TBD."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (risk management, security robustness)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-3-3 (part-level)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.6"
         },
         {
          "href": "#baa4cf26-6159-56d6-a26d-4cb096e75b6c",
          "rel": "reference",
          "text": "IEC 61508 (edition-level)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM07 (System Prompt Leakage, adapted to sensor input manipulation)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-08 (Input Validation)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "DSP-21 (Data Poisoning Prevention & Detection)"
         }
        ]
       },
       {
        "id": "mfg-srf-l2-ops-007",
        "class": "srf-vertical-control",
        "title": "AI Decision Log Retention per EU AI Act Article 12",
        "params": [
         {
          "id": "mfg-srf-l2-ops-007-p1",
          "label": "ai_log_retention_days",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_LOG_RETENTION_DAYS"
          ],
          "guidelines": [
           {
            "prose": "Minimum retention period in days for AI decision logs. EU AI Act Article 12 minimum: 180 days."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-OPS-007"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Input"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Product-Embedded"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturer"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL1"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "extend-log-retention; verify-tamper-evidence; alert-compliance-team"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "audit_activity (3002). Log storage metadata: retention policy applied."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "time; actor; observables; metadata.retention_days"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l2-ops-007_stmt",
          "name": "statement",
          "prose": "High-risk AI systems must emit automated logs covering the input data used, the output produced, the date and time, and the operator or automated system that acted on the output. Logs must be retained for a minimum of six months per EU AI Act Article 12. Logs must be stored in a tamper-evident format and be retrievable on request by the deployer, operator, or market surveillance authority."
         },
         {
          "id": "mfg-srf-l2-ops-007_obj",
          "name": "objective",
          "prose": "Maintain ai_log_retention_days >= {{ insert: param, mfg-srf-l2-ops-007-p1 }} over window continuous. Breach action: extend-log-retention; verify-tamper-evidence; alert-compliance-team."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 12 (record-keeping)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 26 (deployer logging obligations)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-2-1 (part-level)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 4.2"
         }
        ]
       },
       {
        "id": "mfg-srf-l2-ops-008",
        "class": "srf-vertical-control",
        "title": "Production Data Egress Audit for Cloud AI Services",
        "params": [
         {
          "id": "mfg-srf-l2-ops-008-p1",
          "label": "undocumented_egress_events",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "monthly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "0"
          ],
          "guidelines": [
           {
            "prose": "Count of confirmed plant data egress events not covered by an approved data flow register entry in the current month."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L2-OPS-008"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L2"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Data and Input"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "it-only"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "investigate-egress; halt-if-feasible; notify-dpo-and-ot-security"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "network_activity (4001). Source: cloud gateway or DLP tool."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dst_endpoint.name; src_endpoint.name; traffic.bytes_out"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-62443",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l2-ops-008_stmt",
          "name": "statement",
          "prose": "For AI systems that send plant production data to cloud AI services, the data provider must verify that no plant data leaves the approved cloud boundary without an audit record. Monthly automated scans must compare actual data egress records against the approved data flow register. Any undocumented egress must be investigated, halted if possible, and reported to the OT security team and data protection officer within 24 hours."
         },
         {
          "id": "mfg-srf-l2-ops-008_obj",
          "name": "objective",
          "prose": "Maintain undocumented_egress_events == {{ insert: param, mfg-srf-l2-ops-008-p1 }} over window monthly. Breach action: investigate-egress; halt-if-feasible; notify-dpo-and-ot-security."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 10 (data governance)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 3.5"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "LOG-15 (Output Monitoring)"
         }
        ]
       }
      ]
     }
    ]
   },
   {
    "id": "l3",
    "class": "srf-layer",
    "title": "L3: AI Application",
    "groups": [
     {
      "id": "l3-finance",
      "class": "srf-vertical",
      "title": "L3 — Finance",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "finance"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/finance-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "fin-srf-l3-dev-001",
        "class": "srf-vertical-control",
        "title": "Input Validation and Prompt Injection Defense Design",
        "params": [
         {
          "id": "fin-srf-l3-dev-001-p1",
          "label": "input_validation_design_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "at-validation-gate"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: input validation design document exists, covers all required layers, and has been reviewed by a party independent of the developer who wrote it."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-DEV-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application Platforms"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-model-from-entering-validation"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: design artifact. Runtime evidence available via SRF-L3-MON-001."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l3-dev-001_stmt",
          "name": "statement",
          "prose": "Before a model-backed application enters validation, the application developer must document and implement input validation controls covering: maximum input length enforcement, character set and encoding validation, detection of prompt injection patterns (instruction override attempts, role-switch instructions, jailbreak patterns), and sanitization of user-supplied content before it reaches the model context. For RAG pipelines, retrieved content must be treated as untrusted input and passed through the same validation chain as user input. Defense-in-depth is required: a single detection layer is not sufficient. Design must be documented and reviewable by the independent validation function."
         },
         {
          "id": "fin-srf-l3-dev-001_obj",
          "name": "objective",
          "prose": "Maintain input_validation_design_documented == {{ insert: param, fin-srf-l3-dev-001-p1 }} over window at-validation-gate. Breach action: block-model-from-entering-validation."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-SEC-010 (Prompt Injection)"
         },
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-PREV-003 (User/App/Model Firewalling/Filtering)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-08 (Input Validation)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-15 (Prompt Differentiation)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section IV (Model Development)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (Risk management system)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (Accuracy, robustness and cybersecurity)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM01: Prompt Injection"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.7 (security and resilience are evaluated and documented)"
         }
        ]
       },
       {
        "id": "fin-srf-l3-dev-002",
        "class": "srf-vertical-control",
        "title": "Output Filtering and Content Safety Design",
        "params": [
         {
          "id": "fin-srf-l3-dev-002-p1",
          "label": "output_filter_design_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "at-validation-gate"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: output filtering design covers all required layers, documents fine-tuning safety impact where applicable, and has been reviewed independently."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-DEV-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "APIs & Fine-tuned Models"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-model-from-entering-validation"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: design artifact. Runtime evidence available via SRF-L3-MON-002."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l3-dev-002_stmt",
          "name": "statement",
          "prose": "The application developer must implement output filtering controls before model outputs reach end users or downstream systems. Required layers: a content safety classifier or rules engine that blocks prohibited output categories (defined by the institution's acceptable use policy at SRF-L1-DEV-003), a PII detection and redaction layer for outputs destined for external parties or low-clearance users, and structured output validation for applications that parse model outputs into downstream decisions or workflows. For fine-tuned models, the developer must document whether fine-tuning altered the base model's built-in safety behaviors and what compensating controls are in place. Output filters must be applied after every model call, including intermediate steps in agentic chains."
         },
         {
          "id": "fin-srf-l3-dev-002_obj",
          "name": "objective",
          "prose": "Maintain output_filter_design_documented == {{ insert: param, fin-srf-l3-dev-002-p1 }} over window at-validation-gate. Breach action: block-model-from-entering-validation."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-PREV-003 (User/App/Model Firewalling/Filtering)"
         },
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-PREV-017 (AI Firewall Implementation and Management)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-09 (Output Validation)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section IV (Model Development)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (Accuracy, robustness and cybersecurity)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM05: Improper Output Handling"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM02: Sensitive Information Disclosure"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.6 (safety risks are evaluated and documented)"
         }
        ]
       },
       {
        "id": "fin-srf-l3-dev-003",
        "class": "srf-vertical-control",
        "title": "Tool-Execution Authorization Design for Agentic Systems",
        "params": [
         {
          "id": "fin-srf-l3-dev-003-p1",
          "label": "tool_authorization_design_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "at-validation-gate"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: tool-execution authorization design document exists covering all required elements, and has been reviewed by a party independent of the framework developer."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-DEV-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agents & Orchestration Models"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agentic-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "cross-layer-controls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-DEV-004"
         },
         {
          "name": "cross-layer-controls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-DEV-002"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-agent-from-entering-validation"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: design artifact. Runtime evidence available via SRF-L3-MON-003."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l3-dev-003_stmt",
          "name": "statement",
          "prose": "For Agent-PaaS deployments, the agentic platform and framework provider must design and document a tool-execution authorization scheme that enforces least-privilege access for each tool the agent can invoke. Required design elements: an explicit allow-list of tools per agent role (no implicit allow-all), per-tool authorization checks that verify the agent's current session context and user delegation before execution, a confirmation gate for irreversible or high-consequence tool calls (as defined in the agent authorization policy at SRF-L1-DEV-004), and an audit trail linking each tool execution to the agent session, the human user or system that initiated the session, and the business process the agent is authorized to act within. Tool authorization must be re-checked at each step in a multi-step orchestration chain, not only at session start."
         },
         {
          "id": "fin-srf-l3-dev-003_obj",
          "name": "objective",
          "prose": "Maintain tool_authorization_design_documented == {{ insert: param, fin-srf-l3-dev-003-p1 }} over window at-validation-gate. Breach action: block-agent-from-entering-validation."
         },
         {
          "id": "fin-srf-l3-dev-003_gdn",
          "name": "guidance",
          "prose": "cross-layer-note: Tool allow-lists defined here must be consistent with the agent authorization scope in the L1 policy (SRF-L1-DEV-004) and must be enforceable at the gateway layer (SRF-L4-DEV-002). A change to the L1 policy must trigger re-review of this control. Changes to this control must be reflected in gateway entitlement configuration."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-SEC-025 (Tool Chain Manipulation and Injection)"
         },
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-PREV-018 (Agent Authority Least Privilege Framework)"
         },
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-PREV-019 (Tool Chain Validation and Sanitization)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-11 (Agents Security Boundaries)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "IAM-19 (Agent Access Restriction)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section III footnote 3 (generative and agentic AI out of scope"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "MRM principles applied by analogy)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 14 (Human oversight)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (Risk management system)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM06: Excessive Agency (includes tool and plugin permission scope)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 1.3 (responses to high-priority AI risks are developed); MEASURE 2.7 (security and resilience are evaluated)"
         }
        ]
       },
       {
        "id": "fin-srf-l3-val-001",
        "class": "srf-vertical-control",
        "title": "Independent Validation of Application-Level Security Controls",
        "params": [
         {
          "id": "fin-srf-l3-val-001-p1",
          "label": "adversarial_validation_completed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "pre-production-approval"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: independent adversarial test report exists covering required scope, with all Critical and High findings dispositioned (remediated or accepted with documented rationale) before production approval."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-VAL-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application Platforms"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "independent-validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-production-approval-until-critical-and-high-findings-remediated"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: test report artifact. Security finding events generated during red-team testing may be captured as security_finding OCSF class events if tooling supports it."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l3-val-001_stmt",
          "name": "statement",
          "prose": "Before production approval, the independent validation function must conduct adversarial testing of the application's security controls. Required scope: prompt injection attempts across at least the OWASP LLM Top 10 attack categories relevant to the architecture, output filter bypass attempts (including indirect injection via RAG retrieval), tool-execution authorization bypass for Agent-PaaS deployments, and chain-of-thought leakage tests for multi-step orchestrations. Testing must be performed by a team with no development accountability for the controls being tested. Findings must be documented with severity ratings, and any Critical or High findings must be remediated before production approval. Tier-1 models require external red-team involvement or independent security firm engagement."
         },
         {
          "id": "fin-srf-l3-val-001_obj",
          "name": "objective",
          "prose": "Maintain adversarial_validation_completed == {{ insert: param, fin-srf-l3-val-001-p1 }} over window pre-production-approval. Breach action: block-production-approval-until-critical-and-high-findings-remediated."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-PREV-005 (System Acceptance Testing)"
         },
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-SEC-010 (Prompt Injection)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-05 (Application Security Testing)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-06 (Adversarial Attack Analysis)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section V (Model Validation)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (Risk management system)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (Accuracy, robustness and cybersecurity)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM01 through LLM10: full 2025 top 10 scope for adversarial testing"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 1.3 (independent assessors are involved in TEVV); MEASURE 2.7 (security and resilience are evaluated)"
         }
        ]
       },
       {
        "id": "fin-srf-l3-mon-001",
        "class": "srf-vertical-control",
        "title": "Prompt Injection Detection Rate Monitoring",
        "params": [
         {
          "id": "fin-srf-l3-mon-001-p1",
          "label": "prompt_injection_detection_rate",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "within-control-limits"
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-defined"
           }
          ],
          "values": [
           "tier-defined (upper and lower control limits set at baseline)"
          ],
          "guidelines": [
           {
            "prose": "Rate of inputs flagged as prompt injection attempts per unit time. Breach conditions: (1) rate exceeds the upper control limit defined at baseline (active attack signal); (2) rate drops below the lower control limit when traffic volume is stable (detector degradation signal)."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-MON-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application Platforms"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "alert-application-developer; escalate-to-security-team-if-upper-limit-exceeded; escalate-to-mrm-if-lower-limit-breached"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai_operation"
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "message_context: input content and role context observable in ai_operation events. Injection detection labels applied at the application layer should be emitted as security_finding events or as enriched fields on ai_operation events."
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "ocsf-class-status",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "unverified-proposal"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l3-mon-001_stmt",
          "name": "statement",
          "prose": "The application developer must monitor the rate of detected prompt injection attempts against the application in production. Detection rate is the proportion of inputs flagged by the injection detection layer (SRF-L3-DEV-001) relative to total inputs. A sustained elevation in detection rate is a signal of active attack or a shift in the user population that warrants investigation. A sudden drop in detection rate when attack volume is expected to be constant may indicate detector degradation. Both conditions are breach events. Tier-1 models require continuous monitoring; lower tiers follow the institution-defined cadence."
         },
         {
          "id": "fin-srf-l3-mon-001_obj",
          "name": "objective",
          "prose": "Maintain prompt_injection_detection_rate within-control-limits {{ insert: param, fin-srf-l3-mon-001-p1 }} over window tier-defined. Breach action: alert-application-developer; escalate-to-security-team-if-upper-limit-exceeded; escalate-to-mrm-if-lower-limit-breached."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-SEC-010 (Prompt Injection)"
         },
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-DET-004 (AI System Observability)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "LOG-14 (Input Monitoring)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-08 (Input Validation)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section V (Ongoing Model Monitoring)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (Accuracy, robustness and cybersecurity)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM01: Prompt Injection"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.7 (security and resilience are evaluated); MANAGE 4.1 (post-deployment monitoring plans are implemented)"
         }
        ]
       },
       {
        "id": "fin-srf-l3-mon-002",
        "class": "srf-vertical-control",
        "title": "Output Filter Block-Rate Monitoring",
        "params": [
         {
          "id": "fin-srf-l3-mon-002-p1",
          "label": "output_filter_block_rate_by_category",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "within-control-limits"
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-defined"
           }
          ],
          "values": [
           "tier-defined per filter category"
          ],
          "guidelines": [
           {
            "prose": "Rate of model outputs blocked or redacted per filter category per unit time. Breach when any category's block rate falls outside its established control limits."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-MON-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "APIs & Fine-tuned Models"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "alert-application-developer; investigate-category-causing-breach; escalate-to-mrm-if-unresolved-within-sla"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai_operation"
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "message_context: output content observable in ai_operation events. Filter decisions should be emitted as enriched fields on ai_operation events or as separate security_finding events, tagged by filter category."
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "ocsf-class-status",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "unverified-proposal"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l3-mon-002_stmt",
          "name": "statement",
          "prose": "The application developer must monitor the rate at which the output filter (SRF-L3-DEV-002) blocks or redacts model outputs in production. An elevated block rate signals model behavior drift, a shift in user inputs driving prohibited outputs, or a fine-tuning regression. A declining block rate over time may indicate filter degradation or evasion. Both are breach conditions. The block rate must be broken down by filter category (content safety, PII redaction, structured output validation) so that category-level anomalies are visible independently."
         },
         {
          "id": "fin-srf-l3-mon-002_obj",
          "name": "objective",
          "prose": "Maintain output_filter_block_rate_by_category within-control-limits {{ insert: param, fin-srf-l3-mon-002-p1 }} over window tier-defined. Breach action: alert-application-developer; investigate-category-causing-breach; escalate-to-mrm-if-unresolved-within-sla."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-PREV-003 (User/App/Model Firewalling/Filtering)"
         },
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-DET-004 (AI System Observability)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "LOG-15 (Output Monitoring)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-09 (Output Validation)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section V (Ongoing Model Monitoring)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (Accuracy, robustness and cybersecurity)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM05: Improper Output Handling"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM02: Sensitive Information Disclosure"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.6 (safety risks are evaluated); MEASURE 2.4 (the deployed AI system is monitored)"
         }
        ]
       },
       {
        "id": "fin-srf-l3-mon-003",
        "class": "srf-vertical-control",
        "title": "Tool-Execution Authorization Failure Rate Monitoring",
        "params": [
         {
          "id": "fin-srf-l3-mon-003-p1",
          "label": "tool_authorization_failure_rate",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-session and rolling-24h"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "0 out-of-allow-list attempts; tier-defined for per-call failures"
          ],
          "guidelines": [
           {
            "prose": "Count of tool invocation attempts that fail authorization checks per session and per time window. Zero tolerance for out-of-allow-list invocation attempts; tier-defined thresholds for per-call authorization check failures."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-MON-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agents & Orchestration Models"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agentic-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "terminate-agent-session-on-out-of-allow-list-attempt; alert-agentic-platform-provider; escalate-to-security-team; notify-l1-agent-business-process-owner"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "api_activity"
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "api_activity events on tool endpoints where authorization fails (status: Failure, status_code: 403 or equivalent). Cross-reference actor identity (agent session id) with the tool allow-list for that agent role to distinguish out-of-scope attempts from misconfiguration failures."
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "supplemental",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai_operation events provide session-level context to trace authorization failures back to the triggering prompt or orchestration step."
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l3-mon-003_stmt",
          "name": "statement",
          "prose": "For Agent-PaaS deployments, the agentic platform provider must monitor the rate of tool-execution authorization failures: attempts by an agent to invoke a tool it is not authorized to call, or invocations that fail the per-call authorization check (SRF-L3-DEV-003). A rising authorization failure rate signals prompt injection driving out-of-scope tool calls, agent scope creep, or a misconfigured allow-list. Any attempt to invoke a tool outside the agent's allow-list is a Severity-1 event regardless of whether it succeeded. Authorization failures must be correlated with the originating session and user to support forensic review."
         },
         {
          "id": "fin-srf-l3-mon-003_obj",
          "name": "objective",
          "prose": "Maintain tool_authorization_failure_rate == {{ insert: param, fin-srf-l3-mon-003-p1 }} over window per-session and rolling-24h. Breach action: terminate-agent-session-on-out-of-allow-list-attempt; alert-agentic-platform-provider; escalate-to-security-team; notify-l1-agent-business-process-owner."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-SEC-024 (Agent Action Authorization Bypass)"
         },
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-DET-021 (Agent Decision Audit and Explainability)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "IAM-19 (Agent Access Restriction)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "LOG-13 (Failures and Anomalies Reporting)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section III footnote 3 (generative and agentic AI out of scope"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "MRM principles applied by analogy)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 14 (Human oversight)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM06: Excessive Agency (includes tool and plugin permission scope)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.7 (security and resilience are evaluated); MANAGE 2.4 (mechanisms are in place to disengage systems that deviate from intended use)"
         }
        ]
       },
       {
        "id": "fin-srf-l3-ech-001",
        "class": "srf-vertical-control",
        "title": "Effective Challenge of Application Security Control Thresholds",
        "params": [
         {
          "id": "fin-srf-l3-ech-001-p1",
          "label": "application_security_challenge_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "12mo"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: annual second-line challenge of L3 monitoring thresholds completed, covering all required assessment areas, with findings and any threshold adjustments tracked to closure."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-ECH-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application Platforms"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "effective-challenge"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-cro; flag-in-annual-mrm-report"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: governance artifact; not streaming telemetry."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-finos-aigf",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-eu-ai-act",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l3-ech-001_stmt",
          "name": "statement",
          "prose": "The independent validation or second-line risk function must annually challenge whether the application-level security control thresholds established in SRF-L3-MON-001, SRF-L3-MON-002, and SRF-L3-MON-003 remain appropriate. Challenge must assess: whether control limits reflect the current threat environment (updated OWASP LLM Top 10 categories, new injection techniques observed in the prior period), whether any Tier-1 application has operated outside its control limits without triggering a documented response, whether fine-tuning or model version changes since last validation have altered the output filter's effectiveness, and whether the agentic tool allow-lists remain appropriately scoped given changes to business processes since initial deployment."
         },
         {
          "id": "fin-srf-l3-ech-001_obj",
          "name": "objective",
          "prose": "Maintain application_security_challenge_documented == {{ insert: param, fin-srf-l3-ech-001-p1 }} over window 12mo. Breach action: escalate-to-cro; flag-in-annual-mrm-report."
         }
        ],
        "links": [
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "A&A-02 (Independent Assessments)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section III (effective challenge)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.13 (effectiveness of the TEVV metrics and processes is evaluated)"
         }
        ]
       }
      ]
     },
     {
      "id": "l3-public-sector",
      "class": "srf-vertical",
      "title": "L3 — Public Sector",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "public-sector"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/public-sector-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "pubsec-srf-l3-val-001",
        "class": "srf-vertical-control",
        "title": "Pre-Deployment Testing Coverage for High-Impact Use Cases",
        "params": [
         {
          "id": "pubsec-srf-l3-val-001-p1",
          "label": "pre_deployment_test_plan_completed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a completed and CAIO-reviewed pre-deployment test report exists for the current version of every high-impact AI use case."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-VAL-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Integration"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agency"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "pre-deployment-validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-deployment; notify-CAIO; escalate-to-AI-governance-board"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact. Test execution may emit api_activity (6003) if the testing pipeline is instrumented."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l3-val-001_stmt",
          "name": "statement",
          "prose": "Before deploying or materially modifying a high-impact AI use case, the agency application developer must complete a pre-deployment test plan covering functional accuracy, safety boundaries, bias and fairness, and security. Test results must be reviewed and signed off by the CAIO office before go-live, per M-25-21 pre-deployment testing minimum practice."
         },
         {
          "id": "pubsec-srf-l3-val-001_obj",
          "name": "objective",
          "prose": "Maintain pre_deployment_test_plan_completed == {{ insert: param, pubsec-srf-l3-val-001-p1 }} over window per-deployment. Breach action: block-deployment; notify-CAIO; escalate-to-AI-governance-board."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(b)(i) (Conduct Pre-Deployment Testing)"
         },
         {
          "href": "#ae7bd07d-92c3-5ea1-915d-6542ebb67973",
          "rel": "reference",
          "text": "Section 4(d)(i) (Testing and Evaluation)"
         },
         {
          "href": "#aec75536-9650-52f9-bd36-918743c7b0a5",
          "rel": "reference",
          "text": "KSI-CMT-VTD (automated testing and validation of changes)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.1 (approaches for evaluating AI system trustworthiness are established); MEASURE 2.6 (evaluations are completed and results documented)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM09: Misinformation"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM05: Improper Output Handling"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-05 (Application Security Testing)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l3-val-002",
        "class": "srf-vertical-control",
        "title": "AI Impact Assessment Completion for High-Impact Use Cases",
        "params": [
         {
          "id": "pubsec-srf-l3-val-002-p1",
          "label": "ai_impact_assessment_completed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a completed and governance-board-reviewed AI impact assessment exists for the current version of every high-impact AI use case."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-VAL-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Integration"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Shared-Service"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agency"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "pre-deployment-validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-deployment; notify-CAIO; escalate-to-AI-governance-board"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact. Impact assessment is a governance record."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-fedramp-20x-ksi",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l3-val-002_stmt",
          "name": "statement",
          "prose": "Before deploying a high-impact AI use case, the agency must complete an AI impact assessment documenting potential harms to individuals and communities, mitigation measures, and residual risks. The assessment must be reviewed by the AI governance board and retained as part of the ATO documentation package."
         },
         {
          "id": "pubsec-srf-l3-val-002_obj",
          "name": "objective",
          "prose": "Maintain ai_impact_assessment_completed == {{ insert: param, pubsec-srf-l3-val-002-p1 }} over window per-deployment. Breach action: block-deployment; notify-CAIO; escalate-to-AI-governance-board."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(b)(ii) (Complete AI Impact Assessment)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 5.1 (likelihood of impacts on individuals is assessed); MAP 5.2 (practices for risk assessment are in use); MEASURE 2.6 (evaluations are completed and results documented)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-10 (AI Impact Assessment)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l3-val-003",
        "class": "srf-vertical-control",
        "title": "Prompt Injection Detection for Citizen-Facing AI Systems",
        "params": [
         {
          "id": "pubsec-srf-l3-val-003-p1",
          "label": "prompt_injection_detection_deployed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: prompt injection detection is deployed and tested for every citizen-facing AI application before production."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-VAL-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Integration"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "pre-deployment-validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-deployment; notify-ISSO; escalate-to-application-security-team"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "detection_finding (2004) for prompt injection alerts."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finding.type_uid; finding.severity_id"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-fedramp-20x-ksi",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l3-val-003_stmt",
          "name": "statement",
          "prose": "AI applications that process citizen-supplied text input must deploy prompt injection detection controls before production. Detection coverage must be tested as part of the pre-deployment security test plan and re-tested after material model or configuration changes."
         },
         {
          "id": "pubsec-srf-l3-val-003_obj",
          "name": "objective",
          "prose": "Maintain prompt_injection_detection_deployed == {{ insert: param, pubsec-srf-l3-val-003-p1 }} over window per-deployment. Breach action: block-deployment; notify-ISSO; escalate-to-application-security-team."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(b)(i) (Conduct Pre-Deployment Testing)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.1 (trustworthiness evaluation includes security); MEASURE 2.6"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM01: Prompt Injection"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-08 (Input Validation)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-15 (Prompt Differentiation)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l3-ovr-004",
        "class": "srf-vertical-control",
        "title": "Human Oversight Gate for Adverse Citizen-Facing Decisions",
        "params": [
         {
          "id": "pubsec-srf-l3-ovr-004-p1",
          "label": "human_oversight_gate_operational",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a human oversight gate is implemented and confirmed operational for every adverse-decision workflow in high-impact AI use cases."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-OVR-004"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Integration"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agency"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "human-oversight-remedy"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "suspend-adverse-decision-outputs; notify-CAIO; escalate-to-AI-governance-board; notify-affected-citizens-of-delay"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "audit_activity (3002) for oversight gate approval events."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-fedramp-20x-ksi",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l3-ovr-004_stmt",
          "name": "statement",
          "prose": "AI systems that generate or inform adverse decisions affecting citizens (benefits denials, eligibility determinations, enforcement actions) must route those decisions through a human oversight gate before they are finalized. The gate must be documented in the impact assessment and tested in the pre-deployment plan."
         },
         {
          "id": "pubsec-srf-l3-ovr-004_obj",
          "name": "objective",
          "prose": "Maintain human_oversight_gate_operational == {{ insert: param, pubsec-srf-l3-ovr-004-p1 }} over window continuous. Breach action: suspend-adverse-decision-outputs; notify-CAIO; escalate-to-AI-governance-board; notify-affected-citizens-of-delay."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(b)(v) (Provide Additional Human Oversight, Intervention, and Accountability)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 3.2 (AI risks are tracked and overseen by designated individuals); GOVERN 6.2 (policies for human oversight are established)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-15 (Human supervision)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l3-ovr-005",
        "class": "srf-vertical-control",
        "title": "Remedy and Appeal Mechanism Coverage",
        "params": [
         {
          "id": "pubsec-srf-l3-ovr-005-p1",
          "label": "remedy_appeal_mechanism_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a documented and published remedy and appeal mechanism exists for every citizen-facing high-impact AI use case."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-OVR-005"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Integration"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Shared-Service"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agency"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "human-oversight-remedy"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "suspend-adverse-decision-outputs; notify-CAIO; escalate-to-legal-and-compliance"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-fedramp-20x-ksi",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l3-ovr-005_stmt",
          "name": "statement",
          "prose": "For each high-impact AI use case affecting citizens, the agency must document and publish a remedy and appeal mechanism that allows affected individuals to challenge an AI-informed decision and receive human review. The mechanism must specify the accountable office, review timeline, and available remedies."
         },
         {
          "id": "pubsec-srf-l3-ovr-005_obj",
          "name": "objective",
          "prose": "Maintain remedy_appeal_mechanism_documented == {{ insert: param, pubsec-srf-l3-ovr-005-p1 }} over window per-deployment. Breach action: suspend-adverse-decision-outputs; notify-CAIO; escalate-to-legal-and-compliance."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(b)(vi) (Offer Consistent Remedies or Appeals)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 3.2; GOVERN 6.2 (policies for human oversight and remedy)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l3-mon-006",
        "class": "srf-vertical-control",
        "title": "Agentic Task Boundary Enforcement for Casework Automation",
        "params": [
         {
          "id": "pubsec-srf-l3-mon-006-p1",
          "label": "agent_task_boundary_violations_per_session",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-session"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "0"
          ],
          "guidelines": [
           {
            "prose": "Count of agent task boundary violations per session. Zero tolerance for high-impact casework agents."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-MON-006"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Integration"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agentic-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "suspend-agent-session; notify-ISSO; escalate-to-human-caseworker; log-to-audit-trail"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "detection_finding (2004) for boundary violation events."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finding.type_uid; finding.severity_id"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l3-mon-006_stmt",
          "name": "statement",
          "prose": "AI agents used in casework, benefits processing, or citizen service workflows must operate within defined task boundaries specifying permitted actions, data access scopes, and escalation triggers. Boundary violations must be logged and trigger automated suspension of the agent session pending human review."
         },
         {
          "id": "pubsec-srf-l3-mon-006_obj",
          "name": "objective",
          "prose": "Maintain agent_task_boundary_violations_per_session == {{ insert: param, pubsec-srf-l3-mon-006-p1 }} over window per-session. Breach action: suspend-agent-session; notify-ISSO; escalate-to-human-caseworker; log-to-audit-trail."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(b)(v) (Provide Additional Human Oversight, Intervention, and Accountability)"
         },
         {
          "href": "#aec75536-9650-52f9-bd36-918743c7b0a5",
          "rel": "reference",
          "text": "KSI-CNA-DFP (strictly defined functionality and privileges)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 3.2; MEASURE 2.7 (AI system trustworthiness is evaluated for agentic contexts)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM02: Sensitive Information Disclosure"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM06: Excessive Agency"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-11 (Agents Security Boundaries)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "IAM-19 (Agent Access Restriction)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l3-val-007",
        "class": "srf-vertical-control",
        "title": "Shared-Service AI Inheritance Chain Documentation",
        "params": [
         {
          "id": "pubsec-srf-l3-val-007-p1",
          "label": "inheritance_chain_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "ato-renewal-cycle"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a current inheritance chain document exists for every shared-service AI deployment, reviewed at each ATO renewal."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-VAL-007"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Integration"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Shared-Service"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "inherited"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "pre-deployment-validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "flag-shared-service-deployment; notify-ISSO; escalate-to-Authorizing-Official"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-21",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l3-val-007_stmt",
          "name": "statement",
          "prose": "For AI systems deployed through interagency shared services (such as GSA platforms), the consuming agency must document the complete inheritance chain: which controls are inherited from the shared-service ATO, which are shared, and which are the agency's sole responsibility. The inheritance chain must be reviewed and confirmed at each ATO renewal cycle."
         },
         {
          "id": "pubsec-srf-l3-val-007_obj",
          "name": "objective",
          "prose": "Maintain inheritance_chain_documented == {{ insert: param, pubsec-srf-l3-val-007-p1 }} over window ato-renewal-cycle. Breach action: flag-shared-service-deployment; notify-ISSO; escalate-to-Authorizing-Official."
         }
        ],
        "links": [
         {
          "href": "#aec75536-9650-52f9-bd36-918743c7b0a5",
          "rel": "reference",
          "text": "KSI-SCR-MIT (persistent supply chain risk identification and mitigation)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 5.1 (supply chain risk includes shared-service providers); GOVERN 5.2"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-14 (Supply Chain Governance Review)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l3-ovr-008",
        "class": "srf-vertical-control",
        "title": "AI Output Explanation for Adverse Citizen Decisions",
        "params": [
         {
          "id": "pubsec-srf-l3-ovr-008-p1",
          "label": "adverse_decision_explanation_provided",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-decision"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: every adverse-decision notice issued by a high-impact AI use case includes a plain-language explanation of contributing factors."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-OVR-008"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Integration"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agency"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "human-oversight-remedy"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "suspend-notice-issuance; notify-CAIO; escalate-to-legal; remediate-notice-template"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "audit_activity (3002) for decision notice issuance events."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-fedramp-20x-ksi",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l3-ovr-008_stmt",
          "name": "statement",
          "prose": "For adverse decisions informed by AI, the agency must provide an explanation to the affected citizen describing, in plain language, the factors that contributed to the decision. The explanation must not require the citizen to have technical knowledge and must accompany any notice of the adverse decision."
         },
         {
          "id": "pubsec-srf-l3-ovr-008_obj",
          "name": "objective",
          "prose": "Maintain adverse_decision_explanation_provided == {{ insert: param, pubsec-srf-l3-ovr-008-p1 }} over window per-decision. Breach action: suspend-notice-issuance; notify-CAIO; escalate-to-legal; remediate-notice-template."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(b)(vi) (Offer Consistent Remedies or Appeals)"
         },
         {
          "href": "#ae7bd07d-92c3-5ea1-915d-6542ebb67973",
          "rel": "reference",
          "text": "Section 3(d)(v) (Documentation, Transparency, and Accessibility)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 3.2; GOVERN 6.2"
         }
        ]
       }
      ]
     },
     {
      "id": "l3-healthcare",
      "class": "srf-vertical",
      "title": "L3 — Healthcare",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "healthcare"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/healthcare-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "hc-srf-l3-dev-001",
        "class": "srf-vertical-control",
        "title": "Human-in-the-Loop Gate for High-Stakes Outputs",
        "params": [
         {
          "id": "hc-srf-l3-dev-001-p1",
          "label": "hitl_gate_enforced",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-high-risk-inference"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: high-risk AI recommendations require and record explicit clinician confirmation before any clinical action."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-DEV-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application & Agent"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-autonomous-action-and-alert-developer"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AuditEvent"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "type.code == 'ai-recommendation-confirmed', agent (clinician), purposeOfEvent"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-fda-pccp",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l3-dev-001_stmt",
          "name": "statement",
          "prose": "Clinical AI outputs classified as high-risk (diagnosis, treatment selection, medication dosing, procedure recommendation) must be surfaced as advisory only and require explicit clinician confirmation before any downstream action is taken. The confirmation step must be logged in the EHR AuditEvent."
         },
         {
          "id": "hc-srf-l3-dev-001_obj",
          "name": "objective",
          "prose": "Maintain hitl_gate_enforced == {{ insert: param, hc-srf-l3-dev-001-p1 }} over window per-high-risk-inference. Breach action: block-autonomous-action-and-alert-developer."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 2.4: Human-machine interface design"
         },
         {
          "href": "#8e4fc90b-6135-5c7a-81da-30efe01e36ad",
          "rel": "reference",
          "text": "§170.315(b)(11): DSI transparency and clinician review"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 14 (Human oversight)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 14(4)(e) (Intervention capability)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§5.2: Software requirements (user interface safety)"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§6: Risk control (human oversight as control)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 3.2 (policies define human-AI configurations and oversight); MAP 3.5 (processes for human oversight are assessed)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM06: Excessive Agency"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM09: Misinformation (unwarranted clinician reliance)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-15 (Human supervision)"
         }
        ]
       },
       {
        "id": "hc-srf-l3-dev-002",
        "class": "srf-vertical-control",
        "title": "AI Explanation Coverage for Clinical Decisions",
        "params": [
         {
          "id": "hc-srf-l3-dev-002-p1",
          "label": "explanation_coverage_rate",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "rolling-7d"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "{min_explanation_coverage_rate}"
          ],
          "guidelines": [
           {
            "prose": "Fraction of clinical AI inferences for which a human-interpretable rationale is surfaced to the clinician at the point of care."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-DEV-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application & Agent"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "alert-product-team-and-notify-governance"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AuditEvent"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "extension (ai-explanation-provided == true), type.code == 'ai-inference'"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iso-14971",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l3-dev-002_stmt",
          "name": "statement",
          "prose": "Clinical AI systems must provide a human-interpretable rationale with each recommendation, meeting ONC HTI-1 transparency requirements for certified health IT. Explanation coverage rate (fraction of inferences with an explanation surfaced to the clinician) must meet the configured threshold."
         },
         {
          "id": "hc-srf-l3-dev-002_obj",
          "name": "objective",
          "prose": "Maintain explanation_coverage_rate >= {{ insert: param, hc-srf-l3-dev-002-p1 }} over window rolling-7d. Breach action: alert-product-team-and-notify-governance."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 2.4: Transparency of AI outputs"
         },
         {
          "href": "#5c236a56-0fd8-52fc-880b-5e213d233a3f",
          "rel": "reference",
          "text": "Principle 4: Transparent"
         },
         {
          "href": "#8e4fc90b-6135-5c7a-81da-30efe01e36ad",
          "rel": "reference",
          "text": "§170.315(b)(11)(vi)(A): DSI transparency; rationale disclosure"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 13 (Transparency and provision of information)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§5.2: Software requirements (output transparency)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.9 (the AI model is explained, validated, and documented)"
         }
        ]
       },
       {
        "id": "hc-srf-l3-dev-003",
        "class": "srf-vertical-control",
        "title": "Adversarial Robustness Testing Before Clinical Deployment",
        "params": [
         {
          "id": "hc-srf-l3-dev-003-p1",
          "label": "adversarial_testing_completed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "pre-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: adversarial/red-team testing completed and critical findings remediated before first clinical deployment."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-DEV-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application & Agent"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-clinical-deployment"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "DocumentReference"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "category.code == 'adversarial-test-report', status == 'current'"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-onc-hti1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l3-dev-003_stmt",
          "name": "statement",
          "prose": "Clinical AI systems must undergo adversarial input testing (red-team exercises) before first deployment to identify failure modes under atypical or manipulated inputs. For LLM-based clinical tools, testing must include prompt injection, jailbreak attempts, and clinical misinformation scenarios. Results must be documented and critical findings remediated before deployment."
         },
         {
          "id": "hc-srf-l3-dev-003_obj",
          "name": "objective",
          "prose": "Maintain adversarial_testing_completed == {{ insert: param, hc-srf-l3-dev-003-p1 }} over window pre-deployment. Breach action: block-clinical-deployment."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 3.3: Algorithmic testing including corner cases"
         },
         {
          "href": "#5c236a56-0fd8-52fc-880b-5e213d233a3f",
          "rel": "reference",
          "text": "Principle 2: Risk-based"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9(5)(b) (Testing of high-risk AI systems)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§5.7: Software testing"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§6.4: Risk control verification"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.6 (safety risks are evaluated and documented); MEASURE 2.7 (security and resilience are evaluated and documented)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM01: Prompt Injection"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM09: Misinformation"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-06 (Adversarial Attack Analysis)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-05 (Application Security Testing)"
         }
        ]
       },
       {
        "id": "hc-srf-l3-vv-001",
        "class": "srf-vertical-control",
        "title": "Clinical Workflow Usability Validation",
        "params": [
         {
          "id": "hc-srf-l3-vv-001-p1",
          "label": "usability_study_completed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "pre-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: usability study with representative clinical users completed; safety-critical issues resolved before deployment."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-VV-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application & Agent"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "verification-validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-clinical-deployment"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "DocumentReference"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "category.code == 'usability-study-report', status == 'current'"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-fda-pccp",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-onc-hti1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l3-vv-001_stmt",
          "name": "statement",
          "prose": "Clinical AI applications must undergo usability testing with representative clinical end users (clinicians, nurses, pharmacists as applicable) before deployment, following FDA Human Factors guidance and IEC 62366. Usability issues rated as safety-critical must be resolved before deployment."
         },
         {
          "id": "hc-srf-l3-vv-001_obj",
          "name": "objective",
          "prose": "Maintain usability_study_completed == {{ insert: param, hc-srf-l3-vv-001-p1 }} over window pre-deployment. Breach action: block-clinical-deployment."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 2.4: Human-machine interface; Human Factors guidance"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 14(4) (Measures for human oversight)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§5.7: System testing"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§5.6: Usability risk analysis (per IEC 62366)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.2 (evaluations involving human subjects meet applicable requirements); MAP 3.4 (operator proficiency requirements are defined)"
         }
        ]
       },
       {
        "id": "hc-srf-l3-vv-002",
        "class": "srf-vertical-control",
        "title": "Prompt Injection and Input Manipulation Defense",
        "params": [
         {
          "id": "hc-srf-l3-vv-002-p1",
          "label": "injection_defense_validated",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "pre-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: prompt injection and input manipulation defenses validated through structured testing before clinical deployment of any LLM-based clinical tool."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-VV-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application & Agent"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "verification-validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-clinical-deployment"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AuditEvent"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "type.code == 'injection-detection', outcome (detection successful)"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-fda-pccp",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-onc-hti1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l3-vv-002_stmt",
          "name": "statement",
          "prose": "LLM-based clinical AI tools must implement and validate defenses against prompt injection, jailbreak, and adversarial input manipulation before clinical deployment. Defense mechanisms must be verified through structured testing and must be validated as part of the V&V package."
         },
         {
          "id": "hc-srf-l3-vv-002_obj",
          "name": "objective",
          "prose": "Maintain injection_defense_validated == {{ insert: param, hc-srf-l3-vv-002-p1 }} over window pre-deployment. Breach action: block-clinical-deployment."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 3.3: Generative AI-specific testing"
         },
         {
          "href": "#8d9146e5-7a72-5eac-a274-e74a728227e7",
          "rel": "reference",
          "text": "45 CFR §164.308(a)(1): Security risk analysis"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9(5)(b) (Testing including cybersecurity)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§5.7: Software testing (security)"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§6.4: Risk control verification"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.7 (security and resilience are evaluated and documented)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM01: Prompt Injection"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-08 (Input Validation)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-15 (Prompt Differentiation)"
         }
        ]
       },
       {
        "id": "hc-srf-l3-pms-001",
        "class": "srf-vertical-control",
        "title": "Clinician Override Rate Monitoring",
        "params": [
         {
          "id": "hc-srf-l3-pms-001-p1",
          "label": "clinician_override_rate",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "<="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "rolling-30d"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "{max_clinician_override_rate}"
          ],
          "guidelines": [
           {
            "prose": "Fraction of AI recommendations dismissed or overridden by clinicians within a rolling 30-day window. High override rates indicate poor model fit or alert fatigue."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-PMS-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application & Agent"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "post-market-surveillance"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "trigger-governance-review-and-consider-model-revalidation"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AuditEvent"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "type.code == 'ai-recommendation-override', agent (clinician), period"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l3-pms-001_stmt",
          "name": "statement",
          "prose": "The rate at which clinicians override or dismiss AI recommendations must be monitored continuously. Override rates exceeding the threshold signal poor model calibration or alert fatigue and must trigger a governance review. Override rate data must be stratified by recommendation type, care setting, and clinician role."
         },
         {
          "id": "hc-srf-l3-pms-001_obj",
          "name": "objective",
          "prose": "Maintain clinician_override_rate <= {{ insert: param, hc-srf-l3-pms-001-p1 }} over window rolling-30d. Breach action: trigger-governance-review-and-consider-model-revalidation."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 4.3: Real-world performance monitoring"
         },
         {
          "href": "#5c236a56-0fd8-52fc-880b-5e213d233a3f",
          "rel": "reference",
          "text": "Principle 5: Lifecycle monitoring"
         },
         {
          "href": "#8e4fc90b-6135-5c7a-81da-30efe01e36ad",
          "rel": "reference",
          "text": "§170.315(b)(11)(v): Ongoing maintenance assessment"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 72 (Post-market monitoring)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§6.2: Problem and modification process"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§10.2: Post-production information"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 4.1 (post-deployment monitoring captures input from users and other AI actors)"
         }
        ]
       },
       {
        "id": "hc-srf-l3-pms-002",
        "class": "srf-vertical-control",
        "title": "Safety-Critical Output Filter Bypass Rate",
        "params": [
         {
          "id": "hc-srf-l3-pms-002-p1",
          "label": "output_filter_bypass_rate",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "0"
          ],
          "guidelines": [
           {
            "prose": "Zero tolerance: any safety-critical output filter bypass constitutes an immediate patient safety incident."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-PMS-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application & Agent"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "post-market-surveillance"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "immediate-patient-safety-escalation-and-system-suspend"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AuditEvent"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "type.code == 'safety-filter-bypass', outcome != '0'"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-fda-pccp",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-onc-hti1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l3-pms-002_stmt",
          "name": "statement",
          "prose": "Clinical AI systems with safety-critical output filters (e.g., filters blocking lethal drug dose recommendations, filters enforcing contraindication checks) must maintain a zero-tolerance bypass rate. Any filter bypass must be treated as a patient safety incident."
         },
         {
          "id": "hc-srf-l3-pms-002_obj",
          "name": "objective",
          "prose": "Maintain output_filter_bypass_rate == {{ insert: param, hc-srf-l3-pms-002-p1 }} over window continuous. Breach action: immediate-patient-safety-escalation-and-system-suspend."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 4.3: Safety monitoring"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (Risk management system)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (Accuracy and robustness)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§6.2: Problem resolution"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§9: Residual risk evaluation"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.6 (safety risks are evaluated and documented); MANAGE 2.4 (mechanisms are in place to supersede or disengage systems that deviate from intended use)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM05: Improper Output Handling"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-09 (Output Validation)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-11 (Guardrails)"
         }
        ]
       },
       {
        "id": "hc-srf-l3-pms-003",
        "class": "srf-vertical-control",
        "title": "Agentic Task Boundary Enforcement",
        "params": [
         {
          "id": "hc-srf-l3-pms-003-p1",
          "label": "unauthorized_scope_access_rate",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "0"
          ],
          "guidelines": [
           {
            "prose": "Zero tolerance: agentic AI accessing FHIR resources outside authorized SMART on FHIR scopes."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-PMS-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application & Agent"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "clinical-application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "post-market-surveillance"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "terminate-agent-session-and-revoke-token"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AuditEvent"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "type.code == 'unauthorized-scope-access', outcome != '0'"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-fda-pccp",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-onc-hti1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-62304",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l3-pms-003_stmt",
          "name": "statement",
          "prose": "Agentic clinical AI systems must be limited to authorized FHIR endpoint scopes defined at deployment. Scope creep, accessing FHIR resources or patient data outside the authorized SMART on FHIR scope, must be detected and blocked in real time."
         },
         {
          "id": "hc-srf-l3-pms-003_obj",
          "name": "objective",
          "prose": "Maintain unauthorized_scope_access_rate == {{ insert: param, hc-srf-l3-pms-003-p1 }} over window continuous. Breach action: terminate-agent-session-and-revoke-token."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 2.4: Intended use boundary enforcement"
         },
         {
          "href": "#8d9146e5-7a72-5eac-a274-e74a728227e7",
          "rel": "reference",
          "text": "45 CFR §164.312(a)(1): Minimum necessary access"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (Risk management for autonomous AI)"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§6: Risk control (scope limitation)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 2.4 (mechanisms are in place to disengage systems that deviate from intended use); MEASURE 2.7 (security and resilience are evaluated and documented)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM06: Excessive Agency"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-11 (Agents Security Boundaries)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "IAM-19 (Agent Access Restriction)"
         }
        ]
       }
      ]
     },
     {
      "id": "l3-insurance",
      "class": "srf-vertical",
      "title": "L3 — Insurance",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "insurance"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/insurance-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "ins-srf-l3-dev-001",
        "class": "srf-vertical-control",
        "title": "Prompt Injection Defense for Consumer-Facing AI",
        "params": [
         {
          "id": "ins-srf-l3-dev-001-p1",
          "label": "prompt_injection_defense_validated",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "0"
          ],
          "guidelines": [
           {
            "prose": "Zero-tolerance: no consumer-facing AI application may enter production without documented prompt injection defense validation."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-DEV-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Agent"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-deployment; require-security-remediation; re-validate-before-release"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "security_finding (2001): application security testing platform emits findings for prompt injection vulnerabilities. Attribute: finding.type_id = 'prompt_injection'; status_id = 'new' for unmitigated findings."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finding.type_id == 'prompt_injection' AND status_id == 'new'"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-naic-model-bulletin",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-naic-eval-tool",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-co-reg-10-1-1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nydfs-cl7",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l3-dev-001_stmt",
          "name": "statement",
          "prose": "AI applications and agentic systems with consumer-facing interfaces in insurance workflows (chatbots, claims intake, policy service) must implement documented defenses against prompt injection attacks. Defenses must include input validation, output filtering, and system prompt isolation. Validation must be completed before production deployment and repeated after any significant update to the application."
         },
         {
          "id": "ins-srf-l3-dev-001_obj",
          "name": "objective",
          "prose": "Maintain prompt_injection_defense_validated == {{ insert: param, ins-srf-l3-dev-001-p1 }} over window per-deployment. Breach action: block-deployment; require-security-remediation; re-validate-before-release."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (accuracy, robustness and cybersecurity for high-risk AI systems)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM01 (Prompt Injection)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.7 (security and resilience are evaluated and documented)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-08 (Input Validation)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-15 (Prompt Differentiation)"
         }
        ]
       },
       {
        "id": "ins-srf-l3-dev-002",
        "class": "srf-vertical-control",
        "title": "Agentic Task Boundary Enforcement for Claims Automation",
        "params": [
         {
          "id": "ins-srf-l3-dev-002-p1",
          "label": "agent_boundary_enforcement_validated",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "0"
          ],
          "guidelines": [
           {
            "prose": "Zero-tolerance: no agentic claims or underwriting workflow may enter production without validated technical task boundary enforcement."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-DEV-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Agent"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-deployment; require-technical-boundary-remediation; escalate-to-chief-claims-officer"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "security_finding (2001): agent boundary validation test results emitted to SIEM. Attribute: finding.type_id = 'agent_scope_violation'; status_id = 'new' for unmitigated findings."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finding.type_id == 'agent_scope_violation' AND status_id == 'new'"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-naic-eval-tool",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-co-reg-10-1-1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nydfs-cl7",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l3-dev-002_stmt",
          "name": "statement",
          "prose": "Agentic AI systems used in claims processing, settlement, or subrogation must enforce explicit task boundaries preventing the agent from taking actions outside the defined scope without human authorization. Boundary enforcement must be implemented as a technical control (not solely policy), tested before deployment, and monitored per SRF-L3-MON-002."
         },
         {
          "id": "ins-srf-l3-dev-002_obj",
          "name": "objective",
          "prose": "Maintain agent_boundary_enforcement_validated == {{ insert: param, ins-srf-l3-dev-002-p1 }} over window per-deployment. Breach action: block-deployment; require-technical-boundary-remediation; escalate-to-chief-claims-officer."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3 (AIS Program should address governance, risk management controls, and internal audit functions for AI-assisted decisions - general internal-controls nexus, not an agent-boundary-specific provision)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 14 (human oversight for high-risk AI)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (robustness)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM06 (Excessive Agency)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 2.4 (mechanisms are in place to disengage systems that deviate from intended use); MEASURE 2.7 (security and resilience are evaluated)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-11 (Agents Security Boundaries)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "IAM-19 (Agent Access Restriction)"
         }
        ]
       },
       {
        "id": "ins-srf-l3-val-001",
        "class": "srf-vertical-control",
        "title": "Adverse-Action Explanation Coverage with Reason Codes",
        "params": [
         {
          "id": "ins-srf-l3-val-001-p1",
          "label": "adverse_action_explanation_coverage_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-decision"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "100"
          ],
          "guidelines": [
           {
            "prose": "Zero-tolerance: 100% of AI-assisted adverse decisions in scope must carry a documented explanation or reason code before deployment and in ongoing production."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-VAL-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Agent"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "validation-testing"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "suspend-AI-assisted-adverse-decisions; escalate-to-chief-compliance-officer; initiate-explanation-remediation"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "api_activity (6003): decision logging API emits records for each adverse decision, including presence or absence of explanation payload. Missing explanation_payload triggers a security_finding (2001)."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "activity_id == 'adverse_decision' AND explanation_payload != null"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-naic-model-bulletin",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l3-val-001_stmt",
          "name": "statement",
          "prose": "Every adverse decision made with material AI assistance (coverage denial, premium increase above threshold, claims denial) must be accompanied by a documented explanation in the form of reason codes or equivalent disclosure sufficient to meet applicable state requirements. Explanation coverage must reach 100% of in-scope adverse decisions before production deployment and be maintained in ongoing monitoring."
         },
         {
          "id": "ins-srf-l3-val-001_obj",
          "name": "objective",
          "prose": "Maintain adverse_action_explanation_coverage_pct == {{ insert: param, ins-srf-l3-val-001-p1 }} over window per-decision. Breach action: suspend-AI-assisted-adverse-decisions; escalate-to-chief-compliance-officer; initiate-explanation-remediation."
         }
        ],
        "links": [
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit B (Checklist), Ref 3n (promotes consumer awareness of AI System use through disclosures and notification procedures)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(A)(7) (information necessary for the applicant, policyholder, beneficiary, or covered person to take meaningful action in the event of an adverse decision)"
         },
         {
          "href": "#c59939b3-2e4d-575b-878c-2a4ff0ee3ea1",
          "rel": "reference",
          "text": "Section IV.E, paragraphs 38-41 (Disclosure and Notice: details about all information upon which the insurer based an adverse underwriting or pricing decision)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 86 (right to explanation of individual decision-making for high-risk AI systems)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.9 (the AI model is explained, validated, and documented); MEASURE 2.8 (transparency and accountability are examined)"
         }
        ]
       },
       {
        "id": "ins-srf-l3-val-002",
        "class": "srf-vertical-control",
        "title": "Human Review Gate for Adverse Underwriting and Claims Decisions",
        "params": [
         {
          "id": "ins-srf-l3-val-002-p1",
          "label": "adverse_decision_human_review_gate_bypass_count",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-decision"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "0"
          ],
          "guidelines": [
           {
            "prose": "Zero-tolerance: no adverse underwriting or claims decision generated with AI assistance may bypass the human review gate."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-VAL-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Agent"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "validation-testing"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "void-bypassed-decision; notify-affected-consumer; escalate-to-chief-claims-officer; regulatory-disclosure-assessment"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "api_activity (6003): workflow system logs each adverse decision with human_review_completed flag. security_finding (2001) emitted on bypass detection."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "activity_id == 'adverse_decision' AND human_review_completed == true"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-nydfs-cl7",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l3-val-002_stmt",
          "name": "statement",
          "prose": "AI-assisted adverse decisions in underwriting and claims must route through a documented human review gate before being communicated to the consumer. The gate must be a technical control in the workflow, not solely a policy requirement. Review completion must be logged with the reviewer identity, timestamp, and outcome."
         },
         {
          "id": "ins-srf-l3-val-002_obj",
          "name": "objective",
          "prose": "Maintain adverse_decision_human_review_gate_bypass_count == {{ insert: param, ins-srf-l3-val-002-p1 }} over window per-decision. Breach action: void-bypassed-decision; notify-affected-consumer; escalate-to-chief-claims-officer; regulatory-disclosure-assessment."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 2.3(c) (independence of decision-makers and lines of defense at successive stages of the AI System life cycle - general governance nexus, not an explicit human-review-gate mandate)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit C, Ref 7 (AI type: automate, augment, support)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit B (Narrative) Q1g (how the company assesses autonomy, reversibility, and reporting impact risk of AI Systems)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(A)(5) (health benefit plan insurers only: a provider acting on behalf of the insurer is ultimately responsible for decisions to modify or deny requests for authorization - the regulation does not extend an equivalent explicit requirement to auto or life lines)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 14 (human oversight for high-risk AI systems)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 3.2 (policies define human-AI configurations and oversight); MAP 3.5 (processes for human oversight are assessed)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-15 (Human supervision)"
         }
        ]
       },
       {
        "id": "ins-srf-l3-val-003",
        "class": "srf-vertical-control",
        "title": "Explainability Validation for Rate and Underwriting Models",
        "params": [
         {
          "id": "ins-srf-l3-val-003-p1",
          "label": "explainability_validation_completed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: explainability validation completed using a documented methodology, evidence artifact produced and retained in model file, before production deployment."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-VAL-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Agent"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "validation-testing"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-deployment; require-explainability-validation; escalate-to-chief-actuary"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact for explainability evidence. Candidate: audit_activity (3002) if model validation platform logs validation completion events."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-co-reg-10-1-1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l3-val-003_stmt",
          "name": "statement",
          "prose": "Before deployment, rate and underwriting models must undergo explainability validation confirming that the model's decision logic can be explained to an examiner, a consumer, or a regulator at the level required by applicable state rules. Validation must use a documented methodology and produce an explainability evidence artifact retained in the model file."
         },
         {
          "id": "ins-srf-l3-val-003_obj",
          "name": "objective",
          "prose": "Maintain explainability_validation_completed == {{ insert: param, ins-srf-l3-val-003-p1 }} over window per-deployment. Breach action: block-deployment; require-explainability-validation; escalate-to-chief-actuary."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 3.7 (narrative description of the model's intended goals and objectives and how the model is developed and validated to ensure correct and efficient implementation of those goals)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit C, Ref 6 (model risks and limitations - general nexus, the Tool has no explicit explainability-methodology field)"
         },
         {
          "href": "#c59939b3-2e4d-575b-878c-2a4ff0ee3ea1",
          "rel": "reference",
          "text": "Section II.C, paragraph 19 (Qualitative Assessment: explain how the insurer's AIS operates and articulate a logical relationship between ECDIS/model variables and risk)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 13 (transparency and provision of information to deployers)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 86 (right to explanation)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.9 (the AI model is explained, validated, and documented)"
         }
        ]
       },
       {
        "id": "ins-srf-l3-mon-001",
        "class": "srf-vertical-control",
        "title": "Unfair-Discrimination Outcome Testing Cadence",
        "params": [
         {
          "id": "ins-srf-l3-mon-001-p1",
          "label": "adverse_impact_ratio_max",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "TIER_FAIRNESS_TESTING_CADENCE"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_ADVERSE_IMPACT_RATIO_MIN"
          ],
          "guidelines": [
           {
            "prose": "Maximum adverse impact ratio across monitored protected-class proxies in the current testing window. Tier-configurable by line of business and consumer impact level; recommended threshold follows the 4/5ths rule (0.8 minimum ratio) as a starting point."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-MON-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Agent"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "initiate-model-review; notify-chief-compliance-officer; consider-model-suspension-pending-remediation; regulatory-disclosure-assessment"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "detection_finding (2004): outcome testing platform emits fairness findings when adverse impact ratio breaches threshold."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finding.title == 'adverse_impact_ratio_breach'"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l3-mon-001_stmt",
          "name": "statement",
          "prose": "For each AI model or system used in underwriting, rating, or claims, the insurer must conduct outcome testing for unfair discrimination on a cadence scaled to consumer impact and line of business. Testing must assess adverse impact ratios across protected class proxies and document results. Findings above the tier-configurable threshold trigger a model review."
         },
         {
          "id": "ins-srf-l3-mon-001_obj",
          "name": "objective",
          "prose": "Maintain adverse_impact_ratio_max >= {{ insert: param, ins-srf-l3-mon-001-p1 }} over window TIER_FAIRNESS_TESTING_CADENCE. Breach action: initiate-model-review; notify-chief-compliance-officer; consider-model-suspension-pending-remediation; regulatory-disclosure-assessment."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3 (Department encourages verification and testing methods to identify errors and bias, and the potential for unfair discrimination)"
         },
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 3.4 (validating, testing, and retesting AI System outputs)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit C, Ref 8 (testing for unfair trade practices and unfair discrimination)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit C, Ref 9 (last date of model testing)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(A)(11) (documented description of quantitative testing to detect unfair discrimination with respect to race)"
         },
         {
          "href": "#c59939b3-2e4d-575b-878c-2a4ff0ee3ea1",
          "rel": "reference",
          "text": "Section II.C, paragraph 17 (Frequency of Testing: administered prior to production and on a regular cadence thereafter, and after material updates)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 72 (post-market monitoring, fairness indicators)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.11 (fairness and bias are evaluated and documented)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-10 (AI Impact Assessment)"
         }
        ]
       },
       {
        "id": "ins-srf-l3-mon-002",
        "class": "srf-vertical-control",
        "title": "Consumer Complaint Monitoring for AI-Driven Decisions",
        "params": [
         {
          "id": "ins-srf-l3-mon-002-p1",
          "label": "ai_complaint_rate_per_1000_decisions",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "<"
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "quarterly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_COMPLAINT_RATE_THRESHOLD"
          ],
          "guidelines": [
           {
            "prose": "Consumer complaint rate related to AI-assisted decisions, expressed per 1,000 decisions. Tier-configurable by line of business."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-MON-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Agent"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "trigger-model-review; notify-accountable-officer; escalate-if-trend-continues-two-quarters"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "detection_finding (2004): complaint management system emits findings when complaint rate exceeds threshold for a given AI system or line of business."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finding.title == 'ai_complaint_rate_breach'"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-co-reg-10-1-1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nydfs-cl7",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l3-mon-002_stmt",
          "name": "statement",
          "prose": "The insurer must monitor the volume and nature of consumer complaints related to AI-assisted underwriting, rating, and claims decisions. Complaints must be categorized by AI system, line of business, and decision type. Complaint rate trends above the tier-configurable threshold trigger a model review and must be reported to the accountable officer."
         },
         {
          "id": "ins-srf-l3-mon-002_obj",
          "name": "objective",
          "prose": "Maintain ai_complaint_rate_per_1000_decisions < {{ insert: param, ins-srf-l3-mon-002-p1 }} over window quarterly. Breach action: trigger-model-review; notify-accountable-officer; escalate-if-trend-continues-two-quarters."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 1 (Market Conduct Surveillance Model Law #693: market conduct actions may result from individual consumer complaints)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit B (Checklist), Ref 3m (considers consumer complaints resulting from AI Systems and whether they are identified, tracked, and addressed)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 72 (post-market monitoring, user feedback and complaints)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 4.1 (post-deployment monitoring captures input from users); GOVERN 5.1 (external feedback policies are in place)"
         }
        ]
       },
       {
        "id": "ins-srf-l3-tpo-001",
        "class": "srf-vertical-control",
        "title": "Vendor Application Interface Security Testing",
        "params": [
         {
          "id": "ins-srf-l3-tpo-001-p1",
          "label": "vendor_interface_security_test_completed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-integration"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "0"
          ],
          "guidelines": [
           {
            "prose": "Binary: security test completed for the vendor application interface, results documented, and critical or high findings resolved before production integration."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-TPO-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Agent"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "third-party-oversight"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-vendor-integration; require-remediation; re-test-before-release"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "security_finding (2001): application security testing platform emits findings for vendor interface vulnerabilities."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finding.severity_id IN ('critical','high') AND status_id == 'new'"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-naic-model-bulletin",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-naic-eval-tool",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-co-reg-10-1-1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nydfs-cl7",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l3-tpo-001_stmt",
          "name": "statement",
          "prose": "Third-party AI applications and API integrations used in insurance workflows must undergo documented security testing before integration into production systems. Testing must cover authentication, authorization, input validation, and output integrity. Test results must be retained and reviewed at each annual vendor assessment under SRF-L1-TPO-001."
         },
         {
          "id": "ins-srf-l3-tpo-001_obj",
          "name": "objective",
          "prose": "Maintain vendor_interface_security_test_completed == {{ insert: param, ins-srf-l3-tpo-001-p1 }} over window per-integration. Breach action: block-vendor-integration; require-remediation; re-test-before-release."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (accuracy, robustness and cybersecurity for high-risk AI)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM01 (Prompt Injection)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM05 (Improper Output Handling)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.7 (security and resilience are evaluated); MANAGE 3.1 (AI risks from third-party resources are monitored)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-05 (Application Security Testing)"
         }
        ]
       }
      ]
     },
     {
      "id": "l3-defense",
      "class": "srf-vertical",
      "title": "L3 — Defense",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "defense"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/defense-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "def-srf-l3-tevv-001",
        "class": "srf-vertical-control",
        "title": "TEVV Plan Execution per DoDI 5000.89",
        "params": [
         {
          "id": "def-srf-l3-tevv-001-p1",
          "label": "tevv_report_signed_before_deployment",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-system"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a signed TEVV report exists in the ATO package for every system at or beyond initial operational capability."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-TEVV-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Orchestration"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Traceable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "tevv"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-deployment; notify-PM; escalate-to-AO"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. TEVV report is a static milestone record in the ATO package."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l3-tevv-001_stmt",
          "name": "statement",
          "prose": "The TEVV plan must be executed before operational deployment, producing a TEVV report documenting test results, acceptance criteria outcomes, identified failure modes, and the disposition decision (approve, conditional, or reject). The TEVV report must be signed by the authorizing official and retained in the ATO package."
         },
         {
          "id": "def-srf-l3-tevv-001_obj",
          "name": "objective",
          "prose": "Maintain tevv_report_signed_before_deployment == {{ insert: param, def-srf-l3-tevv-001-p1 }} over window per-system. Breach action: block-deployment; notify-PM; escalate-to-AO."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Reliable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Traceable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 2.1.1 (TEVV framework: continuous testing with documentation and reporting standards)"
         },
         {
          "href": "#8613c5f9-9d01-5ebc-8cc6-19adffb697fe",
          "rel": "reference",
          "text": "Section 5.3 (DT&E Execution, Evaluation, and Reporting)"
         },
         {
          "href": "#8613c5f9-9d01-5ebc-8cc6-19adffb697fe",
          "rel": "reference",
          "text": "Section 6.4 (Operational and Live Fire Execution)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.1"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "A&A-02 (Independent Assessments)"
         }
        ]
       },
       {
        "id": "def-srf-l3-tevv-002",
        "class": "srf-vertical-control",
        "title": "AI Impact Assessment Before Operational Deployment",
        "params": [
         {
          "id": "def-srf-l3-tevv-002-p1",
          "label": "impact_assessment_approved",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-system"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: an approved AI impact assessment exists in the program record for every system before initial operational capability."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-TEVV-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Orchestration"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Equitable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "tevv"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-deployment; notify-PM; schedule-assessment"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Assessment approval is a static milestone record."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l3-tevv-002_stmt",
          "name": "statement",
          "prose": "The component must complete an AI impact assessment documenting the decision or operational context, potential failure modes, consequences of incorrect outputs, affected populations, and mitigation measures. The assessment must be reviewed and approved before initial operational capability."
         },
         {
          "id": "def-srf-l3-tevv-002_obj",
          "name": "objective",
          "prose": "Maintain impact_assessment_approved == {{ insert: param, def-srf-l3-tevv-002-p1 }} over window per-system. Breach action: block-deployment; notify-PM; schedule-assessment."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Responsible principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Equitable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Tenet 3 goal (identify and mitigate AI risks and unintended consequences from the outset)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 2.1"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-10 (AI Impact Assessment)"
         }
        ]
       },
       {
        "id": "def-srf-l3-ovr-003",
        "class": "srf-vertical-control",
        "title": "Human Oversight Gate for Use-of-Force-Adjacent Decisions",
        "params": [
         {
          "id": "def-srf-l3-ovr-003-p1",
          "label": "human_gate_bypass_events",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "TIER_HUMAN_GATE_BYPASS_EVENTS"
          ],
          "guidelines": [
           {
            "prose": "Number of logged instances where a use-of-force-adjacent decision was executed without affirmative human authorization. Zero-tolerance."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-OVR-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Orchestration"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "nss"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "human-oversight-remedy"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "halt-system; notify-commander; open-safety-incident; report-to-CDAO"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "audit_activity (3002). Override and authorization events must log operator identity, timestamp, decision context, and authorization action."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l3-ovr-003_stmt",
          "name": "statement",
          "prose": "AI systems that inform or recommend use-of-force-adjacent decisions must incorporate a mandatory human oversight gate that prevents autonomous action. The gate must require affirmative authorization from a qualified commander or operator before any decision is executed. DoD Directive 3000.09 compliance is required for autonomous and semi-autonomous weapon functions."
         },
         {
          "id": "def-srf-l3-ovr-003_obj",
          "name": "objective",
          "prose": "Maintain human_gate_bypass_events == {{ insert: param, def-srf-l3-ovr-003-p1 }} over window continuous. Breach action: halt-system; notify-commander; open-safety-incident; report-to-CDAO."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Governable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Responsible principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 1.4.2 (update or supplement DoDD 3000.09 with DoD AI Ethical Principles guidance)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 1.3"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-15 (Human supervision)"
         }
        ]
       },
       {
        "id": "def-srf-l3-ovr-004",
        "class": "srf-vertical-control",
        "title": "Operator Interface Override Capability",
        "params": [
         {
          "id": "def-srf-l3-ovr-004-p1",
          "label": "override_capability_verified",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-TEVV-cycle"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: operator override capability has been verified during TEVV and confirmed operational in the most recent system check."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-OVR-004"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Orchestration"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "human-oversight-remedy"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "restrict-AI-assisted-operations; notify-PM; remediate-before-next-operational-use"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "audit_activity (3002). Override events must log operator identity, timestamp, and reason code."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l3-ovr-004_stmt",
          "name": "statement",
          "prose": "Every AI-assisted operational system must provide qualified operators with a clearly labeled, immediately accessible mechanism to override or disable AI outputs without requiring technical knowledge. Override events must be logged with operator identity, timestamp, and reason code."
         },
         {
          "id": "def-srf-l3-ovr-004_obj",
          "name": "objective",
          "prose": "Maintain override_capability_verified == {{ insert: param, def-srf-l3-ovr-004-p1 }} over window per-TEVV-cycle. Breach action: restrict-AI-assisted-operations; notify-PM; remediate-before-next-operational-use."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Governable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 2.2.2 (traceable feedback on system status and clear operator procedures to activate and deactivate system functions)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 1.3"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-15 (Human supervision)"
         }
        ]
       },
       {
        "id": "def-srf-l3-ovr-005",
        "class": "srf-vertical-control",
        "title": "Remedy and Appeal Mechanism for Adverse Administrative Decisions",
        "params": [
         {
          "id": "def-srf-l3-ovr-005-p1",
          "label": "remedy_mechanism_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-system"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a remedy and appeal procedure is documented, published to affected populations, and has a named review official for every in-scope administrative AI system."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-OVR-005"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Orchestration"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Equitable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "non-nss"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "human-oversight-remedy"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "suspend-adverse-decisions; notify-RAI-officer; publish-procedure-within-30-days"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Appeal outcomes may map to audit_activity (3002)."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l3-ovr-005_stmt",
          "name": "statement",
          "prose": "For AI systems that inform personnel, benefits, or administrative decisions with adverse consequences, the component must provide a documented remedy and appeal mechanism. Affected individuals must be informed of the mechanism. Appeals must be reviewed by a human official with authority to override the AI-informed decision."
         },
         {
          "id": "def-srf-l3-ovr-005_obj",
          "name": "objective",
          "prose": "Maintain remedy_mechanism_documented == {{ insert: param, def-srf-l3-ovr-005-p1 }} over window per-system. Breach action: suspend-adverse-decisions; notify-RAI-officer; publish-procedure-within-30-days."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Equitable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Governable principle"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 4.2"
         }
        ]
       },
       {
        "id": "def-srf-l3-ops-006",
        "class": "srf-vertical-control",
        "title": "Agentic Task Boundary Enforcement",
        "params": [
         {
          "id": "def-srf-l3-ops-006-p1",
          "label": "boundary_violation_events",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "TIER_BOUNDARY_VIOLATION_EVENTS"
          ],
          "guidelines": [
           {
            "prose": "Number of out-of-boundary action attempts not blocked per monitoring period. Zero-tolerance."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-OPS-006"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Orchestration"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agentic-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.1.1"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.1.2"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "suspend-agent; alert-SOC; notify-PM"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "security_finding (2001). Boundary violation events must log the attempted action, agent identity, and blocking action."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l3-ops-006_stmt",
          "name": "statement",
          "prose": "Agentic AI systems must operate within documented task boundaries that restrict the range of actions the agent can take autonomously. The boundary specification must be reviewed and approved before deployment. Any attempt to execute an action outside the boundary must be blocked and logged."
         },
         {
          "id": "def-srf-l3-ops-006_obj",
          "name": "objective",
          "prose": "Maintain boundary_violation_events == {{ insert: param, def-srf-l3-ops-006-p1 }} over window continuous. Breach action: suspend-agent; alert-SOC; notify-PM."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Governable principle"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "AC.L2-3.1.1 (limit system access to authorized users, processes, and devices)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "AC.L2-3.1.2 (limit system access to permitted transactions and functions)"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.1.1"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 1.3"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM06: Excessive Agency"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-11 (Agents Security Boundaries)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "IAM-19 (Agent Access Restriction)"
         }
        ]
       },
       {
        "id": "def-srf-l3-ops-007",
        "class": "srf-vertical-control",
        "title": "Prompt Injection Detection at Application Layer",
        "params": [
         {
          "id": "def-srf-l3-ops-007-p1",
          "label": "prompt_injection_detection_coverage_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_PROMPT_INJECTION_DETECTION_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of AI inference endpoints with active application-layer prompt injection detection."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-OPS-007"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Orchestration"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.14.2"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-input; alert-SOC; notify-ISSO"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "security_finding (2001). Detection events must log the attack pattern, endpoint, and blocking action."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l3-ops-007_stmt",
          "name": "statement",
          "prose": "The application layer must implement prompt injection detection to identify adversarial instructions embedded in user inputs or retrieved documents. Detection must operate before inputs reach the model and must generate security findings routed to the SOC."
         },
         {
          "id": "def-srf-l3-ops-007_obj",
          "name": "objective",
          "prose": "Maintain prompt_injection_detection_coverage_pct >= {{ insert: param, def-srf-l3-ops-007-p1 }} over window continuous. Breach action: block-input; alert-SOC; notify-ISSO."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Reliable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 2.1.2 (AI T&E Toolkit: adversarial attack detection tools with operator notification)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "SI.L2-3.14.2 (malicious code protection at designated locations)"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.14.2"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.6"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM01: Prompt Injection"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-08 (Input Validation)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-15 (Prompt Differentiation)"
         }
        ]
       },
       {
        "id": "def-srf-l3-acq-008",
        "class": "srf-vertical-control",
        "title": "Shared Service Inheritance Chain Documentation",
        "params": [
         {
          "id": "def-srf-l3-acq-008-p1",
          "label": "inheritance_chain_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-ATO-cycle"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: every inherited control in the ATO package identifies the providing service and the authorizing PA or ATO."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-ACQ-008"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Orchestration"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Traceable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "flag-incomplete-ATO; notify-ISSO; remediate-before-ATO-approval"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. ATO inheritance documentation is a static record."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l3-acq-008_stmt",
          "name": "statement",
          "prose": "Where an AI system inherits security controls from a DISA-managed shared service or interagency platform, the inheritance chain must be documented in the ATO package. Documentation must identify each inherited control, the providing service, the PA or ATO that covers it, and any residual component responsibility."
         },
         {
          "id": "def-srf-l3-acq-008_obj",
          "name": "objective",
          "prose": "Maintain inheritance_chain_documented == {{ insert: param, def-srf-l3-acq-008-p1 }} over window per-ATO-cycle. Breach action: flag-incomplete-ATO; notify-ISSO; remediate-before-ATO-approval."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Traceable principle"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.6"
         },
         {
          "href": "#c5d89a8d-2be1-526a-977f-3cc51013206f",
          "rel": "reference",
          "text": "Mission Owner SRG Section 3.3.3 (inheritance of CSP security controls and CSO residual risk)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-14 (Supply Chain Governance Review)"
         }
        ]
       },
       {
        "id": "def-srf-l3-ops-009",
        "class": "srf-vertical-control",
        "title": "Plain-Language Output Explanation for Operators",
        "params": [
         {
          "id": "def-srf-l3-ops-009-p1",
          "label": "explanation_availability_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-TEVV-cycle"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_EXPLANATION_AVAILABILITY_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of AI recommendations presented to operators accompanied by a plain-language explanation as verified by TEVV usability testing."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-OPS-009"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Orchestration"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Traceable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Equitable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "notify-PM; remediate-interface-before-next-TEVV"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance artifact. TEVV usability test results document explanation presence and operator comprehension."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l3-ops-009_stmt",
          "name": "statement",
          "prose": "AI systems that present recommendations to operators must provide a plain-language explanation of the factors driving the output, stated at a level comprehensible to a qualified operator without technical AI knowledge. Explanations must be surfaced in the operator interface alongside the recommendation."
         },
         {
          "id": "def-srf-l3-ops-009_obj",
          "name": "objective",
          "prose": "Maintain explanation_availability_pct >= {{ insert: param, def-srf-l3-ops-009-p1 }} over window per-TEVV-cycle. Breach action: notify-PM; remediate-interface-before-next-TEVV."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Traceable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Equitable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 2.2.1 (documentation ensuring warfighter understanding of capability function, risks, and performance expectations)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 2.2"
         }
        ]
       },
       {
        "id": "def-srf-l3-tevv-010",
        "class": "srf-vertical-control",
        "title": "Red Team and Adversarial Robustness Test Before Deployment",
        "params": [
         {
          "id": "def-srf-l3-tevv-010-p1",
          "label": "adversarial_robustness_assessment_complete",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-system"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: an adversarial robustness assessment (or red team report for IL5 NSS / IL6) is on file in the TEVV package before the system reaches IOC and before each major capability change. No critical-severity findings may remain open at IOC."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-TEVV-010"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Use Case"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Traceable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.11.2"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.14.1"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "tevv"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Block IOC. Program manager and ISSO must remediate critical findings and re-run assessment. Document in TEVV report."
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "2003"
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l3-tevv-010_stmt",
          "name": "statement",
          "prose": "For AI systems at IL5 NSS or IL6, a structured red team exercise testing adversarial inputs, prompt injection, and model manipulation must be completed before initial operational capability and before any major capability change. For IL4 and IL5 Non-NSS systems, a documented adversarial robustness assessment is required; a full red team exercise is recommended. Results must be retained in the TEVV package and reviewed by the program manager and ISSO."
         },
         {
          "id": "def-srf-l3-tevv-010_obj",
          "name": "objective",
          "prose": "Maintain adversarial_robustness_assessment_complete == {{ insert: param, def-srf-l3-tevv-010-p1 }} over window per-system. Breach action: Block IOC. Program manager and ISSO must remediate critical findings and re-run assessment. Document in TEVV report.."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Reliable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Traceable principle"
         },
         {
          "href": "#289aed16-d1f7-58b5-b179-0353578d8705",
          "rel": "reference",
          "text": "Section 3.3.b(2) (periodic threat-representative adversarial assessments)"
         },
         {
          "href": "#8613c5f9-9d01-5ebc-8cc6-19adffb697fe",
          "rel": "reference",
          "text": "Section 3.5 (Cybersecurity T&E: cooperative vulnerability and penetration assessment and adversarial assessment)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "RA.L2-3.11.2 (periodic vulnerability scanning)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "CA.L3-3.12.1e (penetration testing leveraging automated tools and subject matter experts - Level 3)"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.11.2"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.6"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM01: Prompt Injection"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-06 (Adversarial Attack Analysis)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-06 (Penetration Testing)"
         }
        ]
       },
       {
        "id": "def-srf-l3-tevv-011",
        "class": "srf-vertical-control",
        "title": "Bias and Equitable Treatment Assessment Before Deployment",
        "params": [
         {
          "id": "def-srf-l3-tevv-011-p1",
          "label": "bias_assessment_complete_before_ioc",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-system"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a bias and equitable treatment assessment is on file in the program record, reviewed by the RAI Officer, and completed before the system reaches IOC. Residual bias risks must be documented with mitigations or acceptance rationale."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-TEVV-011"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Use Case"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Equitable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Traceable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "tevv"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Block IOC until assessment is complete and reviewed by RAI Officer. Document gap in TEVV report."
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact"
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l3-tevv-011_stmt",
          "name": "statement",
          "prose": "Before initial operational capability, the application developer must complete a bias and equitable treatment assessment for every AI system that affects personnel decisions, benefits, or civil liberties. The assessment must test for disparate impact across protected characteristics to the extent data availability allows, document residual bias risk, and be reviewed by the RAI Officer. For systems where population-level demographic data is unavailable, a proxy-metric approach must be documented with rationale."
         },
         {
          "id": "def-srf-l3-tevv-011_obj",
          "name": "objective",
          "prose": "Maintain bias_assessment_complete_before_ioc == {{ insert: param, def-srf-l3-tevv-011-p1 }} over window per-system. Breach action: Block IOC until assessment is complete and reviewed by RAI Officer. Document gap in TEVV report.."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Equitable principle"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.2"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-10 (AI Impact Assessment)"
         }
        ]
       }
      ]
     },
     {
      "id": "l3-manufacturing",
      "class": "srf-vertical",
      "title": "L3 — Manufacturing",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "manufacturing"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/manufacturing-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "mfg-srf-l3-val-001",
        "class": "srf-vertical-control",
        "title": "EU AI Act Technical Documentation Completeness",
        "params": [
         {
          "id": "mfg-srf-l3-val-001-p1",
          "label": "technical_documentation_complete",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "All required Annex IV elements are present and current in the technical file before market placement."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-VAL-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Use Case"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Product-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "complete-missing-elements; update-technical-file; delay-market-placement"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Technical file completeness checklist with sign-off."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Article TBD (technical file requirements)",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-62443",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l3-val-001_stmt",
          "name": "statement",
          "prose": "Before placing a high-risk AI system on the market or putting it into service, the application developer must verify that technical documentation per Article 11 and Annex IV is complete. Required elements include: general description of the system, detailed design description, information on training methodology and data, testing and validation information, instructions for use, and relevant standards applied. The documentation must be retained for 10 years after the last unit is placed on the market."
         },
         {
          "id": "mfg-srf-l3-val-001_obj",
          "name": "objective",
          "prose": "Maintain technical_documentation_complete == {{ insert: param, mfg-srf-l3-val-001-p1 }} over window per-deployment. Breach action: complete-missing-elements; update-technical-file; delay-market-placement."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 11 (technical documentation)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Annex IV (technical documentation content)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.3"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-04 (Model Documentation Requirements)"
         }
        ]
       },
       {
        "id": "mfg-srf-l3-val-002",
        "class": "srf-vertical-control",
        "title": "Pre-Deployment Testing for Safety-Critical AI",
        "params": [
         {
          "id": "mfg-srf-l3-val-002-p1",
          "label": "safety_critical_test_completed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Pre-deployment test plan and results documented for safety-critical AI systems before deployment."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-VAL-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Use Case"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Product-Embedded"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ot-only"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL1"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL3"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "complete-test-plan; execute-tests; resolve-failures-before-deployment"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Test plan document and test results report."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Annex I item TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l3-val-002_stmt",
          "name": "statement",
          "prose": "Before deploying an AI system in a safety-critical process context, the application developer must complete a documented test plan and test results covering: normal operating envelope, out-of-range input handling, degraded mode behavior, and failure mode effects. Test results must reference specific test cases and pass/fail outcomes. The test record must be included in the technical file."
         },
         {
          "id": "mfg-srf-l3-val-002_obj",
          "name": "objective",
          "prose": "Maintain safety_critical_test_completed == {{ insert: param, mfg-srf-l3-val-002-p1 }} over window per-deployment. Breach action: complete-test-plan; execute-tests; resolve-failures-before-deployment."
         },
         {
          "id": "mfg-srf-l3-val-002_gdn",
          "name": "guidance",
          "prose": "mapping-status-note: IEC 61508 clause reference requires verification against IEC 61508-1 through IEC 61508-7."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (risk management, testing)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Annex IV (testing and validation documentation)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-2-1 (part-level)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.2"
         },
         {
          "href": "#baa4cf26-6159-56d6-a26d-4cb096e75b6c",
          "rel": "reference",
          "text": "IEC 61508 (edition-level)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-05 (Application Security Testing)"
         }
        ]
       },
       {
        "id": "mfg-srf-l3-ops-003",
        "class": "srf-vertical-control",
        "title": "Human Oversight Gate for Safety-Critical AI Outputs",
        "params": [
         {
          "id": "mfg-srf-l3-ops-003-p1",
          "label": "safety_gate_bypass_count",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "0"
          ],
          "guidelines": [
           {
            "prose": "Count of safety-critical AI output events acted upon without a recorded human-confirmed gate acknowledgment."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-OPS-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Use Case"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Product-Embedded"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ot-only"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL3"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "alert-plant-safety-officer; investigate-bypass; verify-gate-implementation"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "api_activity (6003) or audit_activity (3002). Source: HMI audit log or SCADA event log."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "actor.user.name; activity_id; observables.gate_acknowledged"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Annex I item TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l3-ops-003_stmt",
          "name": "statement",
          "prose": "AI systems whose outputs could directly affect safety-critical process states must have a human-confirmed gate before the output is acted upon. The gate must require an affirmative operator acknowledgment rather than passive non-intervention. The system must log each gate event, including whether the operator confirmed or overrode the AI output. Zero-tolerance: no autonomous safety decision without a human-confirmed gate unless the system has a validated safety case demonstrating that automatic response is required to prevent imminent harm."
         },
         {
          "id": "mfg-srf-l3-ops-003_obj",
          "name": "objective",
          "prose": "Maintain safety_gate_bypass_count == {{ insert: param, mfg-srf-l3-ops-003-p1 }} over window continuous. Breach action: alert-plant-safety-officer; investigate-bypass; verify-gate-implementation."
         },
         {
          "id": "mfg-srf-l3-ops-003_gdn",
          "name": "guidance",
          "prose": "mapping-status-note: IEC 61508 clause reference requires verification against primary text."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 14 (human oversight)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (risk management)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-3-3 (part-level)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 4.1"
         },
         {
          "href": "#baa4cf26-6159-56d6-a26d-4cb096e75b6c",
          "rel": "reference",
          "text": "IEC 61508 (edition-level)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-15 (Human supervision)"
         }
        ]
       },
       {
        "id": "mfg-srf-l3-val-004",
        "class": "srf-vertical-control",
        "title": "Safety Interlock Integration Verification",
        "params": [
         {
          "id": "mfg-srf-l3-val-004-p1",
          "label": "sis_integration_verified",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Safety interlock integration verified by test before deployment; AI output cannot override or suppress SIS activation."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-VAL-004"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Use Case"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ot-only"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL3"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "halt-deployment; remediate-integration; retest-before-resuming"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Safety interlock integration test record and sign-off by functional safety engineer."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-iso-42001",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l3-val-004_stmt",
          "name": "statement",
          "prose": "Before deploying an AI system that provides outputs to a safety-instrumented system (SIS) or interlock circuit, the application developer must verify that the AI output cannot override or suppress the SIS response. Verification must be documented via a test record demonstrating that a simulated AI failure mode does not prevent SIS activation. The verification record must be retained in the safety case."
         },
         {
          "id": "mfg-srf-l3-val-004_obj",
          "name": "objective",
          "prose": "Maintain sis_integration_verified == {{ insert: param, mfg-srf-l3-val-004-p1 }} over window per-deployment. Breach action: halt-deployment; remediate-integration; retest-before-resuming."
         },
         {
          "id": "mfg-srf-l3-val-004_gdn",
          "name": "guidance",
          "prose": "mapping-status-note: IEC 61508 clause reference requires verification against IEC 61508-1 and IEC 61508-4. Do not cite specific clause numbers without verification."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (risk management)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Annex IV (safety testing documentation)"
         },
         {
          "href": "#5f62c959-7f28-53d4-b324-ca1206fc7e66",
          "rel": "reference",
          "text": "Annex I item 5 (safety components with self-evolving behaviour)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-3-3 (part-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.2"
         },
         {
          "href": "#baa4cf26-6159-56d6-a26d-4cb096e75b6c",
          "rel": "reference",
          "text": "IEC 61508 (edition-level)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-11 (Guardrails)"
         }
        ]
       },
       {
        "id": "mfg-srf-l3-val-005",
        "class": "srf-vertical-control",
        "title": "EU AI Act Conformity Assessment Completed Before Market Placement",
        "params": [
         {
          "id": "mfg-srf-l3-val-005-p1",
          "label": "conformity_assessment_completed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Conformity assessment completed and declaration of conformity signed before market placement."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-VAL-005"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Use Case"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Product-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "complete-conformity-assessment; sign-declaration; update-technical-file"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Conformity assessment record and EU declaration of conformity document."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Article TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-62443",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l3-val-005_stmt",
          "name": "statement",
          "prose": "For each high-risk AI system, the application developer must verify that the applicable conformity assessment procedure (self-assessment per Annex VI or third-party per Annex VII) has been completed and documented before the system is placed on the market or put into service. The conformity assessment record must be retained as part of the technical file and referenced in the EU declaration of conformity."
         },
         {
          "id": "mfg-srf-l3-val-005_obj",
          "name": "objective",
          "prose": "Maintain conformity_assessment_completed == {{ insert: param, mfg-srf-l3-val-005-p1 }} over window per-deployment. Breach action: complete-conformity-assessment; sign-declaration; update-technical-file."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 43 (conformity assessment procedures)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Annex VI (internal control)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Annex VII (third-party assessment)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 47 (EU declaration of conformity)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.4"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "A&A-02 (Independent Assessments)"
         }
        ]
       },
       {
        "id": "mfg-srf-l3-val-006",
        "class": "srf-vertical-control",
        "title": "FAT/SAT Test Coverage for AI-Enabled Machinery",
        "params": [
         {
          "id": "mfg-srf-l3-val-006-p1",
          "label": "fat_sat_ai_coverage_complete",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "FAT and SAT reports include AI-specific test cases and are completed before commissioning."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-VAL-006"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Use Case"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Product-Embedded"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ot-only"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL1"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "extend-fat-sat-scope; retest-ai-failure-modes; delay-commissioning"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. FAT report and SAT report with AI-specific test case sections."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l3-val-006_stmt",
          "name": "statement",
          "prose": "Factory Acceptance Tests (FAT) and Site Acceptance Tests (SAT) for AI-enabled machinery must include test cases covering AI-specific failure modes: model output at edge-of-envelope inputs, graceful degradation on model failure, and correct override behavior. Test coverage for AI-specific cases must be documented separately in the FAT/SAT report and included in the technical file. Test completion is required before commissioning."
         },
         {
          "id": "mfg-srf-l3-val-006_obj",
          "name": "objective",
          "prose": "Maintain fat_sat_ai_coverage_complete == {{ insert: param, mfg-srf-l3-val-006-p1 }} over window per-deployment. Breach action: extend-fat-sat-scope; retest-ai-failure-modes; delay-commissioning."
         },
         {
          "id": "mfg-srf-l3-val-006_gdn",
          "name": "guidance",
          "prose": "mapping-status-note: IEC 61508 clause reference requires verification against IEC 61508-1 through IEC 61508-7."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Annex IV (testing information)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (risk management testing)"
         },
         {
          "href": "#5f62c959-7f28-53d4-b324-ca1206fc7e66",
          "rel": "reference",
          "text": "Annex I item 5 (safety component validation)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-2-1 (part-level)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.2"
         },
         {
          "href": "#baa4cf26-6159-56d6-a26d-4cb096e75b6c",
          "rel": "reference",
          "text": "IEC 61508 (edition-level)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-05 (Application Security Testing)"
         }
        ]
       },
       {
        "id": "mfg-srf-l3-val-007",
        "class": "srf-vertical-control",
        "title": "Operator Override Interface Verification",
        "params": [
         {
          "id": "mfg-srf-l3-val-007-p1",
          "label": "override_interface_tested",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Operator override interface tested and documented before deployment. Override functions without network connectivity."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-VAL-007"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Use Case"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Product-Embedded"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ot-only"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL1"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "implement-override-capability; test-offline-function; document-results"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Override interface test record."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Annex I item TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-iso-42001",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l3-val-007_stmt",
          "name": "statement",
          "prose": "Every AI-assisted decision interface deployed in OT or product contexts must include a tested, functional operator override capability that allows an authorized operator to reject the AI output and proceed with manual control. The override path must not require network connectivity to function. Override functionality must be tested and documented before deployment; test results must be retained in the technical file."
         },
         {
          "id": "mfg-srf-l3-val-007_obj",
          "name": "objective",
          "prose": "Maintain override_interface_tested == {{ insert: param, mfg-srf-l3-val-007-p1 }} over window per-deployment. Breach action: implement-override-capability; test-offline-function; document-results."
         },
         {
          "id": "mfg-srf-l3-val-007_gdn",
          "name": "guidance",
          "prose": "mapping-status-note: EU Machinery Regulation Annex I item number TBD pending review of Annex I provisions."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 14 (human oversight measures, override capability)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-3-3 (part-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 4.1"
         },
         {
          "href": "#baa4cf26-6159-56d6-a26d-4cb096e75b6c",
          "rel": "reference",
          "text": "IEC 61508 (edition-level)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-15 (Human supervision)"
         }
        ]
       },
       {
        "id": "mfg-srf-l3-ops-008",
        "class": "srf-vertical-control",
        "title": "Agentic Task Boundary Enforcement for Autonomous Systems",
        "params": [
         {
          "id": "mfg-srf-l3-ops-008-p1",
          "label": "authority_boundary_violation_count",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "0"
          ],
          "guidelines": [
           {
            "prose": "Count of runtime events where an agent attempted to execute an action outside its defined task boundary."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-OPS-008"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Use Case"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agentic-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ot-only"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL3"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "halt-agent; alert-operator; review-boundary-definition"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "api_activity (6003) or detection_finding (2004). Source: agent orchestration layer or OT control system event log."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "activity_id; actor.process.name; observables.boundary_exceeded"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l3-ops-008_stmt",
          "name": "statement",
          "prose": "Autonomous AI agents deployed in manufacturing (robotic work cells, AI-driven production schedulers, autonomous quality inspection systems) must operate within a defined task boundary specifying: permitted actions, authority limits (what plant states the agent can command), and abort conditions. The boundary must be enforced at runtime, and any attempt to exceed authority must trigger an alert and operator intervention. Boundary definitions must be version-controlled."
         },
         {
          "id": "mfg-srf-l3-ops-008_obj",
          "name": "objective",
          "prose": "Maintain authority_boundary_violation_count == {{ insert: param, mfg-srf-l3-ops-008-p1 }} over window continuous. Breach action: halt-agent; alert-operator; review-boundary-definition."
         },
         {
          "id": "mfg-srf-l3-ops-008_gdn",
          "name": "guidance",
          "prose": "mapping-status-note: IEC 61508 clause reference requires verification against primary text."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 14 (human oversight)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (risk management)"
         },
         {
          "href": "#5f62c959-7f28-53d4-b324-ca1206fc7e66",
          "rel": "reference",
          "text": "Annex I item 5"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-3-3 (part-level)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 4.2"
         },
         {
          "href": "#baa4cf26-6159-56d6-a26d-4cb096e75b6c",
          "rel": "reference",
          "text": "IEC 61508 (edition-level)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM06 (Excessive Agency)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-11 (Agents Security Boundaries)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "IAM-19 (Agent Access Restriction)"
         }
        ]
       },
       {
        "id": "mfg-srf-l3-ops-009",
        "class": "srf-vertical-control",
        "title": "Prompt Injection and Adversarial Input Detection for AI Assistants",
        "params": [
         {
          "id": "mfg-srf-l3-ops-009-p1",
          "label": "prompt_injection_detection_active",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Prompt injection detection is active and logging on all AI-SaaS and AI-PaaS deployments."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-OPS-009"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Use Case"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "it-only"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "limited-risk"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "enable-injection-detection; review-detection-configuration; alert-security-team"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "detection_finding (2004). Source: AI gateway or application WAF."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finding.type; src_endpoint.name; severity_id"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-62443",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l3-ops-009_stmt",
          "name": "statement",
          "prose": "AI assistants and LLM-backed tools deployed in manufacturing IT environments (AI-SaaS, AI-PaaS) must include input validation and prompt injection detection. Detection must cover direct injection in user inputs and indirect injection via retrieved documents or data feeds. Detection events must be logged, and confirmed injections must be investigated within the configured response window."
         },
         {
          "id": "mfg-srf-l3-ops-009_obj",
          "name": "objective",
          "prose": "Maintain prompt_injection_detection_active == {{ insert: param, mfg-srf-l3-ops-009-p1 }} over window continuous. Breach action: enable-injection-detection; review-detection-configuration; alert-security-team."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 52 (transparency obligations for certain AI systems)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.6"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM01 (Prompt Injection)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-08 (Input Validation)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "AIS-15 (Prompt Differentiation)"
         }
        ]
       },
       {
        "id": "mfg-srf-l3-ops-010",
        "class": "srf-vertical-control",
        "title": "Explanation Availability for AI-Assisted Quality and Safety Decisions",
        "params": [
         {
          "id": "mfg-srf-l3-ops-010-p1",
          "label": "explanation_capability_available",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Explanation capability is available in the operator interface for AI-assisted quality and safety decisions, accessible without external connectivity."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-OPS-010"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L3"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Application and Use Case"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "application-developer"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "implement-explanation-interface; test-offline-access; update-technical-file"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Explanation capability test record in acceptance test documentation."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-62443",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l3-ops-010_stmt",
          "name": "statement",
          "prose": "AI systems used for quality inspection, defect classification, or safety-relevant process decisions must provide operators with an explanation or rationale on request. The explanation must be available in the operator interface without requiring external connectivity. Explanation format and depth must be calibrated to the operating model: OT-edge systems must provide a concise process-variable-level rationale; IT-side systems may provide more detailed feature attributions."
         },
         {
          "id": "mfg-srf-l3-ops-010_obj",
          "name": "objective",
          "prose": "Maintain explanation_capability_available == {{ insert: param, mfg-srf-l3-ops-010-p1 }} over window per-deployment. Breach action: implement-explanation-interface; test-offline-access; update-technical-file."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 13 (transparency and provision of information to deployers)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 14 (human oversight, explainability)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.9"
         }
        ]
       }
      ]
     }
    ]
   },
   {
    "id": "l4",
    "class": "srf-layer",
    "title": "L4: AI Platform",
    "groups": [
     {
      "id": "l4-finance",
      "class": "srf-vertical",
      "title": "L4 — Finance",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "finance"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/finance-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "fin-srf-l4-dev-001",
        "class": "srf-vertical-control",
        "title": "Platform-Level Guardrail Design and Configuration Baseline",
        "params": [
         {
          "id": "fin-srf-l4-dev-001-p1",
          "label": "guardrail_configuration_baseline_approved",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "at-validation-gate"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: guardrail configuration baseline document exists per model tier, has been reviewed independently, and is stored in version control with change-control enforcement."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-DEV-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Guardrails & Safety Systems"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-model-from-entering-validation"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: configuration artifact. Runtime evidence available via SRF-L4-MON-001."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 4: Secure Configuration of Enterprise Assets and Software"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l4-dev-001_stmt",
          "name": "statement",
          "prose": "The AI platform provider must design, configure, and document platform-level guardrails before any model is served in production. Platform guardrails operate below the application layer (SRF-L3-DEV-001/002) and provide a defense-in-depth layer that persists even when application controls are misconfigured or bypassed. Required elements: input guardrails that intercept and evaluate requests before they reach the model, output guardrails that evaluate model responses before returning them to the caller, a configuration baseline that specifies which guardrail policies are active per model tier, and a change-control process requiring re-validation when guardrail configuration changes. Guardrail configuration must be immutable to application-layer callers; applications may request guardrail policies but cannot disable them."
         },
         {
          "id": "fin-srf-l4-dev-001_obj",
          "name": "objective",
          "prose": "Maintain guardrail_configuration_baseline_approved == {{ insert: param, fin-srf-l4-dev-001-p1 }} over window at-validation-gate. Breach action: block-model-from-entering-validation."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-PREV-017 (AI Firewall Implementation and Management)"
         },
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-PREV-003 (User/App/Model Firewalling/Filtering)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-11 (Guardrails)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section IV (Model Development)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (Accuracy, robustness and cybersecurity)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (Risk management system)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.6 (safety risks are evaluated and documented); MANAGE 1.3 (responses to high-priority risks are developed)"
         }
        ]
       },
       {
        "id": "fin-srf-l4-dev-002",
        "class": "srf-vertical-control",
        "title": "LLM Gateway Authentication and Authorization Design",
        "params": [
         {
          "id": "fin-srf-l4-dev-002-p1",
          "label": "gateway_authn_authz_design_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "at-validation-gate"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: gateway authentication and authorization design document covers all required elements and has been reviewed independently. Credential rotation schedule is documented and enforced."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-DEV-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "LLM Routers & Gateways"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "cross-layer-controls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L1-DEV-004"
         },
         {
          "name": "cross-layer-controls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L3-DEV-003"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-model-from-entering-validation"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: design artifact. Runtime evidence available via SRF-L4-MON-002."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-sr26-2",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 6: Access Control Management"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l4-dev-002_stmt",
          "name": "statement",
          "prose": "The AI platform provider must design and document authentication and authorization controls for all LLM gateway and router endpoints before production deployment. Required elements: mutual authentication for all model API calls (service-to-service mTLS or equivalent), per-caller authorization that enforces model access entitlements (a caller authorized for Tier-3 models cannot invoke Tier-1 endpoints), rate limiting and quota enforcement per caller identity to prevent abuse, and audit logging of all gateway requests with caller identity, model invoked, and token usage. For Agent-PaaS, the gateway must distinguish agent-identity calls from human-identity calls and apply appropriate authorization policies to each. Gateway credentials must be rotated on a schedule defined by the institution's secrets management policy."
         },
         {
          "id": "fin-srf-l4-dev-002_obj",
          "name": "objective",
          "prose": "Maintain gateway_authn_authz_design_documented == {{ insert: param, fin-srf-l4-dev-002-p1 }} over window at-validation-gate. Breach action: block-model-from-entering-validation."
         },
         {
          "id": "fin-srf-l4-dev-002_gdn",
          "name": "guidance",
          "prose": "cross-layer-note: Gateway authorization entitlements must reflect the agent authorization scope from the L1 policy (SRF-L1-DEV-004) and must enforce the tool allow-lists defined at L3 (SRF-L3-DEV-003). Any change to either upstream control must trigger re-review of gateway entitlement configuration. The L4 ECH review must verify alignment with current L1 and L3 versions."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-PREV-012 (Role-Based Access Control for AI Data)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "IAM-14 (Strong Authentication)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "IAM-16 (Authorization Mechanisms)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (Accuracy, robustness and cybersecurity)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.7 (security and resilience are evaluated and documented)"
         }
        ]
       },
       {
        "id": "fin-srf-l4-dev-003",
        "class": "srf-vertical-control",
        "title": "Confidential Compute Configuration for Tier-1 Models",
        "params": [
         {
          "id": "fin-srf-l4-dev-003-p1",
          "label": "confidential_compute_attestation_stored",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "at-deployment"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: cryptographic attestation report exists in model registry for Tier-1 model deployments, linked to the model version and infrastructure configuration hash."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-DEV-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Compute Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "tier-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Tier-1 models only at development gate; all tiers must document confidential compute policy decision (use or justified exception)."
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-tier-1-model-deployment-until-attestation-generated"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: attestation artifact generated at deployment. If attestation service emits events, candidate: api_activity events from the attestation endpoint at model load time."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-finos-aigf",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-sr26-2",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l4-dev-003_stmt",
          "name": "statement",
          "prose": "Tier-1 AI models processing confidential or restricted data (as classified per SRF-L2-DEV-002) must be configured to run in confidential compute environments (e.g., AMD SEV-SNP, Intel TDX, or equivalent trusted execution environment) that provide hardware-enforced memory encryption and isolation. The platform provider must document the confidential compute configuration, generate a cryptographic attestation report at deployment, and store the attestation alongside the model artifact in the model registry. Attestation must be re-generated after any infrastructure change that could affect the trusted execution environment. This control applies to Tier-1 models only; lower tiers follow institution-defined policy."
         },
         {
          "id": "fin-srf-l4-dev-003_obj",
          "name": "objective",
          "prose": "Maintain confidential_compute_attestation_stored == {{ insert: param, fin-srf-l4-dev-003-p1 }} over window at-deployment. Breach action: block-tier-1-model-deployment-until-attestation-generated."
         }
        ],
        "links": [
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "CEK-03 (Data Encryption, including in-use)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (Accuracy, robustness and cybersecurity)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.10 (privacy risk is examined and documented); MEASURE 2.7 (security and resilience are evaluated)"
         }
        ]
       },
       {
        "id": "fin-srf-l4-val-001",
        "class": "srf-vertical-control",
        "title": "Independent Validation of Platform Security Controls",
        "params": [
         {
          "id": "fin-srf-l4-val-001-p1",
          "label": "platform_validation_completed_bypass_rate_zero",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "pre-production-approval"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: independent validation report exists covering all required scope. Tested bypass rate for Critical guardrail categories is zero. All High findings are dispositioned before production approval."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-VAL-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Guardrails & Safety Systems"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "independent-validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-production-approval-until-critical-bypass-findings-remediated"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: validation report artifact."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l4-val-001_stmt",
          "name": "statement",
          "prose": "Before a model is approved for production, the independent validation function must assess the effectiveness of the platform's guardrail configuration and gateway security controls. Required scope: guardrail bypass testing (attempts to reach the model with inputs that should be blocked, from the application layer), gateway authentication and authorization boundary testing (confirming callers cannot access model tiers above their entitlement), confidential compute attestation verification for Tier-1 models, and review of the guardrail change-control record since the last validation. Validation findings must include a tested bypass rate: the proportion of attempted guardrail bypasses that succeeded during testing. Any bypass success rate above zero for Critical guardrail categories is a blocking finding."
         },
         {
          "id": "fin-srf-l4-val-001_obj",
          "name": "objective",
          "prose": "Maintain platform_validation_completed_bypass_rate_zero == {{ insert: param, fin-srf-l4-val-001-p1 }} over window pre-production-approval. Breach action: block-production-approval-until-critical-bypass-findings-remediated."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-PREV-005 (System Acceptance Testing)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "A&A-02 (Independent Assessments)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-06 (Penetration Testing)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section V (Model Validation)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (Risk management system)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (Accuracy, robustness and cybersecurity)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 1.3 (independent assessors are involved in TEVV); MEASURE 2.7 (security and resilience are evaluated)"
         }
        ]
       },
       {
        "id": "fin-srf-l4-mon-001",
        "class": "srf-vertical-control",
        "title": "Guardrail Bypass Rate Monitoring",
        "params": [
         {
          "id": "fin-srf-l4-mon-001-p1",
          "label": "guardrail_bypass_rate_by_category",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "<="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "24h"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "tier-defined (0 for Critical; tier-defined for lower severity)"
          ],
          "guidelines": [
           {
            "prose": "Rate of guardrail bypass events per category per monitoring window. Zero tolerance for Critical category bypasses; tier-defined thresholds for lower-severity categories."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-MON-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Guardrails & Safety Systems"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "alert-ai-platform-provider; escalate-to-l1-governance-on-critical-bypass; initiate-guardrail-configuration-review"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai_operation"
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Guardrail evaluation results should be emitted as enriched fields on ai_operation events or as dedicated security_finding events, tagged by guardrail category, verdict (blocked/bypassed), and severity. Token usage metrics in ai_operation can help distinguish legitimate completions from bypass-driven completions."
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "ocsf-class-status",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "unverified-proposal"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l4-mon-001_stmt",
          "name": "statement",
          "prose": "The AI platform provider must monitor the rate at which requests or responses bypass platform-level guardrails in production. A bypass occurs when an input that should have been intercepted reaches the model, or when a model output that should have been blocked is returned to the caller. Bypass rate is the proportion of guardrail evaluation events that result in a bypass verdict relative to total evaluations. Bypass events must be classified by guardrail category and severity. Zero-tolerance applies to Critical category bypasses (e.g., guardrails covering regulated content, PII in outputs, or financial advice prohibitions). Tier-defined thresholds apply to lower-severity categories. Bypass rate monitoring operates at the platform layer independently of application-layer output filter monitoring (SRF-L3-MON-002); both layers must report. Where model serving is operated by a distinct ai-model-serving vendor, that vendor is accountable for reporting guardrail evaluation events to the ai-platform-provider; the ai-platform-provider retains accountability for the aggregate bypass rate."
         },
         {
          "id": "fin-srf-l4-mon-001_obj",
          "name": "objective",
          "prose": "Maintain guardrail_bypass_rate_by_category <= {{ insert: param, fin-srf-l4-mon-001-p1 }} over window 24h. Breach action: alert-ai-platform-provider; escalate-to-l1-governance-on-critical-bypass; initiate-guardrail-configuration-review."
         },
         {
          "id": "fin-srf-l4-mon-001_gdn",
          "name": "guidance",
          "prose": "persona-split-note: Guardrail infrastructure is owned by ai-platform-provider. Where ai-model-serving is a distinct vendor, it must emit guardrail evaluation telemetry to the platform. Accountability for the bypass rate metric and breach response rests with ai-platform-provider."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-PREV-017 (AI Firewall Implementation and Management)"
         },
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-DET-004 (AI System Observability)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-11 (Guardrails)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "LOG-03 (Security Monitoring and Alerting)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section V (Ongoing Model Monitoring)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (Accuracy, robustness and cybersecurity)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.6 (safety risks are evaluated); MANAGE 2.4 (mechanisms are in place to disengage systems that deviate from intended use)"
         }
        ]
       },
       {
        "id": "fin-srf-l4-mon-002",
        "class": "srf-vertical-control",
        "title": "Gateway Authentication Failure Rate Monitoring",
        "params": [
         {
          "id": "fin-srf-l4-mon-002-p1",
          "label": "gateway_authn_failure_rate",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "within-control-limits"
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "1h"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "tier-defined (Tier-1 authz failures: 0; all others: tier-defined)"
          ],
          "guidelines": [
           {
            "prose": "Rate of authentication and authorization failures per gateway endpoint per monitoring window, tracked separately by failure type. Tier-1 authorization failures: zero tolerance. All others: tier-defined control limits."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-MON-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "LLM Routers & Gateways"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "alert-ai-platform-provider; escalate-to-security-team-on-tier-1-authz-failure; investigate-credential-rotation-status-on-authn-spike"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "authentication"
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "authentication OCSF class events at gateway endpoints where status == Failure. Cross-reference actor identity and target resource (model endpoint) to classify as authn failure vs. authz failure. Supplement with api_activity events for authorization boundary checks."
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-sr26-2",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 8: Audit Log Management"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l4-mon-002_stmt",
          "name": "statement",
          "prose": "The AI platform provider must monitor the rate of authentication and authorization failures at all LLM gateway and router endpoints. Authentication failures (invalid credentials, expired tokens, missing credentials) and authorization failures (valid caller attempting to access an unauthorized model tier or endpoint) must be tracked separately. A sustained elevation in authentication failures may indicate credential stuffing, rotation failures, or misconfigured callers. A spike in authorization failures may indicate an application attempting to escalate model access beyond its entitlement, or an agent attempting to invoke a higher-tier model than its authorization permits. All authorization failures for Tier-1 model endpoints are Severity-1 events regardless of rate. Where ai-model-serving operates the inference endpoint directly, it is accountable for authentication failures at that endpoint; the ai-platform-provider is accountable for authorization failures at the routing and gateway layer."
         },
         {
          "id": "fin-srf-l4-mon-002_obj",
          "name": "objective",
          "prose": "Maintain gateway_authn_failure_rate within-control-limits {{ insert: param, fin-srf-l4-mon-002-p1 }} over window 1h. Breach action: alert-ai-platform-provider; escalate-to-security-team-on-tier-1-authz-failure; investigate-credential-rotation-status-on-authn-spike."
         },
         {
          "id": "fin-srf-l4-mon-002_gdn",
          "name": "guidance",
          "prose": "persona-split-note: Authentication at the inference endpoint: ai-model-serving. Authorization at the gateway and routing layer: ai-platform-provider. Where the same vendor fills both roles, the split is internal. Where they are distinct vendors, each is accountable for their respective failure events."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-DET-004 (AI System Observability)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "LOG-03 (Security Monitoring and Alerting)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "IAM-14 (Strong Authentication)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (Accuracy, robustness and cybersecurity)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.7 (security and resilience are evaluated and documented)"
         }
        ]
       },
       {
        "id": "fin-srf-l4-mon-003",
        "class": "srf-vertical-control",
        "title": "Confidential Compute Attestation Validity Monitoring",
        "params": [
         {
          "id": "fin-srf-l4-mon-003-p1",
          "label": "confidential_compute_attestation_valid",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous; polling interval tier-defined"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "fixed"
           }
          ],
          "values": [
           "true per Tier-1 instance"
          ],
          "guidelines": [
           {
            "prose": "Binary per Tier-1 model instance: current cryptographic attestation is valid, has not expired, and matches the expected configuration hash for that deployment."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-MON-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Compute Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "tier-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Tier-1 models only."
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "suspend-tier-1-model-serving-on-attestation-lapse; alert-ai-platform-provider; notify-l1-governance; restore-only-after-valid-attestation-confirmed"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "api_activity"
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "api_activity events from the attestation verification service, polled on schedule. A verification response indicating expired or invalid attestation triggers the breach action. Cross-reference with infrastructure change events to correlate attestation lapses with infrastructure operations."
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-finos-aigf",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-sr26-2",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l4-mon-003_stmt",
          "name": "statement",
          "prose": "For Tier-1 models deployed in confidential compute environments (SRF-L4-DEV-003), the AI platform provider must continuously monitor that the cryptographic attestation for each running instance remains valid. Attestation validity may lapse due to infrastructure patching, node migration, hypervisor updates, or certificate expiry. A Tier-1 model running without a valid attestation has lost its confidentiality guarantee and must be treated as an unprotected workload until attestation is re-established. Attestation status must be checked at model load, on a scheduled polling interval, and on any infrastructure event that could affect the trusted execution environment. Where ai-model-serving operates the compute instances directly, it is jointly accountable with ai-platform-provider for attestation validity; the ai-platform-provider retains accountability for reporting to L1 governance on breach."
         },
         {
          "id": "fin-srf-l4-mon-003_obj",
          "name": "objective",
          "prose": "Maintain confidential_compute_attestation_valid == {{ insert: param, fin-srf-l4-mon-003-p1 }} over window continuous; polling interval tier-defined. Breach action: suspend-tier-1-model-serving-on-attestation-lapse; alert-ai-platform-provider; notify-l1-governance; restore-only-after-valid-attestation-confirmed."
         },
         {
          "id": "fin-srf-l4-mon-003_gdn",
          "name": "guidance",
          "prose": "persona-split-note: Where ai-model-serving operates compute instances, it is accountable for attestation at the instance level. ai-platform-provider is accountable for the monitoring system, aggregate validity status, and L1 governance escalation on breach. Joint accountability; ai-platform-provider is the primary for examiner purposes."
         }
        ],
        "links": [
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "CEK-03 (Data Encryption, including in-use)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "LOG-10 (Encryption Monitoring and Reporting)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (Accuracy, robustness and cybersecurity)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.7 (security and resilience are evaluated and documented)"
         }
        ]
       },
       {
        "id": "fin-srf-l4-ech-001",
        "class": "srf-vertical-control",
        "title": "Effective Challenge of Platform Security Controls and Thresholds",
        "params": [
         {
          "id": "fin-srf-l4-ech-001-p1",
          "label": "platform_security_challenge_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "12mo"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: annual second-line challenge of L4 controls completed, covering all required assessment areas, with findings and any required control updates tracked to closure."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-ECH-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Guardrails & Safety Systems"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "effective-challenge"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-cro; flag-in-annual-mrm-report"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: governance artifact."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-finos-aigf",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-eu-ai-act",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l4-ech-001_stmt",
          "name": "statement",
          "prose": "The independent validation or second-line risk function must annually challenge whether the platform-level security controls and monitoring thresholds remain appropriate. Challenge must assess: whether the guardrail configuration baseline reflects the current model portfolio and threat environment, whether any guardrail bypass events in the prior period were dispositioned correctly and within SLA, whether gateway credential rotation has been executed on schedule, whether any Tier-1 model ran without valid confidential compute attestation during the prior period, and whether new operating models or model serving architectures introduced since last validation require additional platform controls not currently in scope."
         },
         {
          "id": "fin-srf-l4-ech-001_obj",
          "name": "objective",
          "prose": "Maintain platform_security_challenge_documented == {{ insert: param, fin-srf-l4-ech-001-p1 }} over window 12mo. Breach action: escalate-to-cro; flag-in-annual-mrm-report."
         }
        ],
        "links": [
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "A&A-02 (Independent Assessments)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section III (effective challenge)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.13 (effectiveness of the TEVV metrics and processes is evaluated)"
         }
        ]
       }
      ]
     },
     {
      "id": "l4-public-sector",
      "class": "srf-vertical",
      "title": "L4 — Public Sector",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "public-sector"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/public-sector-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "pubsec-srf-l4-acq-001",
        "class": "srf-vertical-control",
        "title": "AI Service FedRAMP Authorization at Required Impact Level",
        "params": [
         {
          "id": "pubsec-srf-l4-acq-001-p1",
          "label": "ai_service_fedramp_authorization_level_met",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-onboarding-and-quarterly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: every AI service in use for the given use case holds a current FedRAMP authorization at or above the required FIPS 199 level, confirmed in the FedRAMP marketplace."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-ACQ-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Shared-Service"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "inherited"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition-integration"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "suspend-service; notify-ISSO; escalate-to-Authorizing-Official; notify-CAIO"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact. Marketplace verification may be logged via api_activity (6003)."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-21",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-fedramp-20x-ksi",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l4-acq-001_stmt",
          "name": "statement",
          "prose": "Every AI service (model API, platform, or data processing service) used in a federal AI use case must hold a current FedRAMP authorization at or above the FIPS 199 impact level required for the data it processes. For high-impact AI use cases, Moderate or High authorization is required. The ISSO must verify and document authorization status before service onboarding."
         },
         {
          "id": "pubsec-srf-l4-acq-001_obj",
          "name": "objective",
          "prose": "Maintain ai_service_fedramp_authorization_level_met == {{ insert: param, pubsec-srf-l4-acq-001-p1 }} over window per-onboarding-and-quarterly. Breach action: suspend-service; notify-ISSO; escalate-to-Authorizing-Official; notify-CAIO."
         }
        ],
        "links": [
         {
          "href": "#ae7bd07d-92c3-5ea1-915d-6542ebb67973",
          "rel": "reference",
          "text": "Section 4(e)(i) (Authorization To Operate Compliance)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 5.1 (supply chain risk management); MAP 1.5"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "A&A-02 (Independent Assessments)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l4-acq-002",
        "class": "srf-vertical-control",
        "title": "Guardrail Configuration Baseline and Change Control",
        "params": [
         {
          "id": "pubsec-srf-l4-acq-002-p1",
          "label": "guardrail_baseline_documented_and_change_controlled",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a current guardrail configuration baseline exists, is under change control, and no unauthorized configuration changes have been detected in the prior review period."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-ACQ-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agentic-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition-integration"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "revert-unauthorized-change; notify-ISSO; escalate-to-Authorizing-Official; trigger-incident-response"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "configuration_change (5001) for all guardrail configuration changes."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "configuration_change.category_uid; configuration_change.actor"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l4-acq-002_stmt",
          "name": "statement",
          "prose": "The agency agentic platform provider must establish and document a guardrail configuration baseline for each AI platform deployment. Changes to guardrail configurations must go through a formal change-control process, be logged, and require ISSO review before applying to production high-impact use cases."
         },
         {
          "id": "pubsec-srf-l4-acq-002_obj",
          "name": "objective",
          "prose": "Maintain guardrail_baseline_documented_and_change_controlled == {{ insert: param, pubsec-srf-l4-acq-002-p1 }} over window continuous. Breach action: revert-unauthorized-change; notify-ISSO; escalate-to-Authorizing-Official; trigger-incident-response."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(b)(i) (Conduct Pre-Deployment Testing)"
         },
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(b)(iii) (Conduct Ongoing Monitoring for Performance and Potential Adverse Impacts)"
         },
         {
          "href": "#aec75536-9650-52f9-bd36-918743c7b0a5",
          "rel": "reference",
          "text": "KSI-SVC-ACM (automated configuration management)"
         },
         {
          "href": "#aec75536-9650-52f9-bd36-918743c7b0a5",
          "rel": "reference",
          "text": "KSI-CMT-RMV (version-controlled change deployment)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 1.3 (responses to AI risks are selected); MEASURE 2.6"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM07: System Prompt Leakage"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM06: Excessive Agency"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-11 (Guardrails)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l4-acq-003",
        "class": "srf-vertical-control",
        "title": "Gateway Authentication and Authorization for AI API Access",
        "params": [
         {
          "id": "pubsec-srf-l4-acq-003-p1",
          "label": "ai_api_gateway_enforced",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: all AI API access for high-impact use cases routes through an authenticated agency-controlled gateway; no unauthorized direct access paths detected."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-ACQ-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agentic-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agency"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition-integration"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-direct-access-path; notify-ISSO; escalate-to-incident-response; log-to-audit-trail"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "network_activity (4001) for gateway traffic logs; api_activity (6003) for API call logs."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "network_activity.connection_info; api_activity.http_request"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-21",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 6: Access Control Management"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l4-acq-003_stmt",
          "name": "statement",
          "prose": "All agency access to AI model APIs and platform services must route through an agency-controlled API gateway enforcing authentication, authorization, and rate limiting. Direct-to-model access outside the gateway is prohibited for high-impact use cases. The gateway configuration must be documented in the system security plan."
         },
         {
          "id": "pubsec-srf-l4-acq-003_obj",
          "name": "objective",
          "prose": "Maintain ai_api_gateway_enforced == {{ insert: param, pubsec-srf-l4-acq-003-p1 }} over window continuous. Breach action: block-direct-access-path; notify-ISSO; escalate-to-incident-response; log-to-audit-trail."
         }
        ],
        "links": [
         {
          "href": "#aec75536-9650-52f9-bd36-918743c7b0a5",
          "rel": "reference",
          "text": "KSI-IAM-JIT (least-privileged, role- and attribute-based, just-in-time authorization)"
         },
         {
          "href": "#aec75536-9650-52f9-bd36-918743c7b0a5",
          "rel": "reference",
          "text": "KSI-IAM-SNU (secure authentication for non-user accounts)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 5.1 (supply chain access controls); MAP 1.5"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM04: Data and Model Poisoning"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM02: Sensitive Information Disclosure"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "IAM-14 (Strong Authentication)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "IAM-16 (Authorization Mechanisms)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l4-mon-004",
        "class": "srf-vertical-control",
        "title": "CUI Encryption and Access Monitoring for AI Workloads",
        "params": [
         {
          "id": "pubsec-srf-l4-mon-004-p1",
          "label": "cui_encryption_and_access_logging_compliant",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: CUI encryption at rest and in transit is verified, and access logging is confirmed active with no gaps in the prior review period."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-MON-004"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Shared-Service"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "suspend-CUI-access-by-AI-processes; notify-ISSO; escalate-to-data-protection-officer; initiate-breach-assessment"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "file_activity (1001) for file-level access; network_activity (4001) for transit encryption verification."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "file_activity.actor; network_activity.tls"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-21",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 3: Data Protection"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l4-mon-004_stmt",
          "name": "statement",
          "prose": "CUI processed or stored by AI workloads must be encrypted at rest and in transit per FIPS 140-3 requirements. Access to CUI-holding stores by AI processes must be logged and monitored for anomalous access patterns. The ISSO must review access logs on the cadence defined in the system security plan."
         },
         {
          "id": "pubsec-srf-l4-mon-004_obj",
          "name": "objective",
          "prose": "Maintain cui_encryption_and_access_logging_compliant == {{ insert: param, pubsec-srf-l4-mon-004-p1 }} over window continuous. Breach action: suspend-CUI-access-by-AI-processes; notify-ISSO; escalate-to-data-protection-officer; initiate-breach-assessment."
         }
        ],
        "links": [
         {
          "href": "#aec75536-9650-52f9-bd36-918743c7b0a5",
          "rel": "reference",
          "text": "KSI-SVC-SIN (information encrypted or otherwise secured)"
         },
         {
          "href": "#aec75536-9650-52f9-bd36-918743c7b0a5",
          "rel": "reference",
          "text": "KSI-MLA-RVL (logs persistently reviewed and audited)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.5 (ongoing monitoring tracks security controls); MAP 1.5"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM02: Sensitive Information Disclosure"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "CEK-03 (Data Encryption, including in-use)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "LOG-10 (Encryption Monitoring and Reporting)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l4-mon-005",
        "class": "srf-vertical-control",
        "title": "Audit Log Completeness Aligned to FedRAMP 20x KSI Evidence",
        "params": [
         {
          "id": "pubsec-srf-l4-mon-005-p1",
          "label": "audit_log_completeness_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_AUDIT_LOG_COMPLETENESS_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of required KSI log fields present and populated in production audit logs. Recommended minimum 100% for High-impact systems; tier-configurable for Moderate and Low."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-MON-005"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Shared-Service"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "alert-ISSO; identify-missing-log-fields; escalate-to-Authorizing-Official-if-High-system"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "audit_activity (3002) as the primary OCSF class for log completeness verification; api_activity (6003) for API audit trails."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "audit_activity.category_uid; audit_activity.actor"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-21",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 8: Audit Log Management"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l4-mon-005_stmt",
          "name": "statement",
          "prose": "Audit logs for AI platform components must meet FedRAMP 20x Key Security Indicator evidence expectations: machine-readable, pulled from production environments, and covering authentication, authorization, configuration changes, and API activity. Log completeness must be assessed against the KSI evidence requirements at each ATO renewal and after any material platform change."
         },
         {
          "id": "pubsec-srf-l4-mon-005_obj",
          "name": "objective",
          "prose": "Maintain audit_log_completeness_pct >= {{ insert: param, pubsec-srf-l4-mon-005-p1 }} over window continuous. Breach action: alert-ISSO; identify-missing-log-fields; escalate-to-Authorizing-Official-if-High-system."
         }
        ],
        "links": [
         {
          "href": "#aec75536-9650-52f9-bd36-918743c7b0a5",
          "rel": "reference",
          "text": "KSI-MLA-LET (maintained list of logged event types)"
         },
         {
          "href": "#aec75536-9650-52f9-bd36-918743c7b0a5",
          "rel": "reference",
          "text": "KSI-MLA-OSM (SIEM or similar persistently reviewed)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.5 (ongoing monitoring includes audit capabilities); MANAGE 4.1"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "LOG-03 (Security Monitoring and Alerting)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l4-mon-006",
        "class": "srf-vertical-control",
        "title": "Model Serving Availability SLA for Mission-Critical Use Cases",
        "params": [
         {
          "id": "pubsec-srf-l4-mon-006-p1",
          "label": "model_serving_availability_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "rolling-30d"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_MODEL_AVAILABILITY_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage uptime of the model serving layer over the measurement window. Tier-configurable; recommended minimum 99.5% for mission-critical High systems."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-MON-006"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-vendor; notify-CAIO; activate-continuity-plan; log-SLA-breach-for-contract-reporting"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "detection_finding (2004) for availability alerts; api_activity (6003) for availability monitoring."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "detection_finding.severity_id"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l4-mon-006_stmt",
          "name": "statement",
          "prose": "For high-impact AI use cases designated mission-critical, the agency must document and enforce an availability SLA for the model serving layer. The SLA must be reflected in the AI service contract per M-25-22 performance-based acquisition terms. Availability must be monitored continuously and reported at each governance board review."
         },
         {
          "id": "pubsec-srf-l4-mon-006_obj",
          "name": "objective",
          "prose": "Maintain model_serving_availability_pct >= {{ insert: param, pubsec-srf-l4-mon-006-p1 }} over window rolling-30d. Breach action: escalate-to-vendor; notify-CAIO; activate-continuity-plan; log-SLA-breach-for-contract-reporting."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(b)(iii) (Conduct Ongoing Monitoring for Performance and Potential Adverse Impacts)"
         },
         {
          "href": "#ae7bd07d-92c3-5ea1-915d-6542ebb67973",
          "rel": "reference",
          "text": "Section 4(d)(iii)(F) (Vendor Performance Requirements)"
         },
         {
          "href": "#aec75536-9650-52f9-bd36-918743c7b0a5",
          "rel": "reference",
          "text": "KSI-CNA-RVP (denial of service protection persistently reviewed)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 2.4 (risk treatments are tracked); MEASURE 2.5"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM10: Unbounded Consumption"
         }
        ]
       },
       {
        "id": "pubsec-srf-l4-val-007",
        "class": "srf-vertical-control",
        "title": "Security Control Inheritance Verification at ATO Boundary",
        "params": [
         {
          "id": "pubsec-srf-l4-val-007-p1",
          "label": "ato_crm_completed_for_ai_controls",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-ato"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: the Customer Responsibility Matrix is completed for all AI-specific controls before ATO is granted, and agency-responsible controls are implemented and documented."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-VAL-007"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Shared-Service"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agency"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "pre-deployment-validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-ATO-issuance; notify-Authorizing-Official; escalate-to-ISSO"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l4-val-007_stmt",
          "name": "statement",
          "prose": "Before authorizing a new AI service, the agency Authorizing Official and ISSO must verify that all security controls within the FedRAMP authorization boundary are properly inherited and that agency-responsible controls are implemented and documented. The Customer Responsibility Matrix must be completed for AI-specific controls, including M-25-21 obligations."
         },
         {
          "id": "pubsec-srf-l4-val-007_obj",
          "name": "objective",
          "prose": "Maintain ato_crm_completed_for_ai_controls == {{ insert: param, pubsec-srf-l4-val-007-p1 }} over window per-ato. Breach action: block-ATO-issuance; notify-Authorizing-Official; escalate-to-ISSO."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(b)(i) (Conduct Pre-Deployment Testing)"
         },
         {
          "href": "#aec75536-9650-52f9-bd36-918743c7b0a5",
          "rel": "reference",
          "text": "KSI-SCR-MIT (persistent supply chain risk identification and mitigation)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 5.1 (supply chain risk); GOVERN 5.2"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "A&A-02 (Independent Assessments)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l4-mon-008",
        "class": "srf-vertical-control",
        "title": "Continuous Vulnerability Scanning for AI Platform Components",
        "params": [
         {
          "id": "pubsec-srf-l4-mon-008-p1",
          "label": "critical_high_vuln_remediation_within_sla_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous-monitoring-cycle"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "1.0"
          ],
          "guidelines": [
           {
            "prose": "Percentage of critical and high-severity vulnerabilities in AI platform components remediated within the SSP-defined timeline. Zero tolerance for overdue critical findings."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-MON-008"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-ISSO; notify-Authorizing-Official; initiate-POA-and-M-if-remediation-delayed"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "detection_finding (2004) for vulnerability findings."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finding.severity_id; finding.remediation"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-21",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 7: Continuous Vulnerability Management"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l4-mon-008_stmt",
          "name": "statement",
          "prose": "AI platform components (model serving infrastructure, gateway, RAG pipeline) must be included in the agency continuous vulnerability scanning program. Critical and high-severity findings must be remediated within the timelines defined in the system security plan and reported to the ISSO at each ATO continuous monitoring cycle."
         },
         {
          "id": "pubsec-srf-l4-mon-008_obj",
          "name": "objective",
          "prose": "Maintain critical_high_vuln_remediation_within_sla_pct == {{ insert: param, pubsec-srf-l4-mon-008-p1 }} over window continuous-monitoring-cycle. Breach action: escalate-to-ISSO; notify-Authorizing-Official; initiate-POA-and-M-if-remediation-delayed."
         }
        ],
        "links": [
         {
          "href": "#aec75536-9650-52f9-bd36-918743c7b0a5",
          "rel": "reference",
          "text": "KSI-SCR-MON (automated monitoring of third-party software for upstream vulnerabilities)"
         },
         {
          "href": "#aec75536-9650-52f9-bd36-918743c7b0a5",
          "rel": "reference",
          "text": "KSI-CNA-MAT (minimal attack surface persistently reviewed)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 2.4 (risk treatments tracked); MEASURE 2.5"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM09: Misinformation"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM04: Data and Model Poisoning"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-07 (Vulnerability Remediation Schedule)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-09 (Vulnerability Management Reporting)"
         }
        ]
       }
      ]
     },
     {
      "id": "l4-healthcare",
      "class": "srf-vertical",
      "title": "L4 — Healthcare",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "healthcare"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/healthcare-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "hc-srf-l4-dev-001",
        "class": "srf-vertical-control",
        "title": "SMART on FHIR Authentication and Scoped Authorization",
        "params": [
         {
          "id": "hc-srf-l4-dev-001-p1",
          "label": "smart_fhir_auth_enforced",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: all clinical AI integrations authenticate via OAuth2/SMART on FHIR; no over-privileged service accounts in production."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-DEV-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform & Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "health-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "revoke-access-and-alert-security"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AuditEvent"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "type.code == '110114' (User Authentication), outcome == '0'"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-fda-tplc",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-fda-pccp",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iso-14971",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 6: Access Control Management"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l4-dev-001_stmt",
          "name": "statement",
          "prose": "All clinical AI integrations with EHR systems must use OAuth 2.0 with SMART on FHIR scopes. Service accounts must not hold over-privileged resource-level access. Scope grants must be reviewed at each governance cycle and reduced to minimum necessary per HIPAA minimum necessary standard."
         },
         {
          "id": "hc-srf-l4-dev-001_obj",
          "name": "objective",
          "prose": "Maintain smart_fhir_auth_enforced == {{ insert: param, hc-srf-l4-dev-001-p1 }} over window continuous. Breach action: revoke-access-and-alert-security."
         }
        ],
        "links": [
         {
          "href": "#8e4fc90b-6135-5c7a-81da-30efe01e36ad",
          "rel": "reference",
          "text": "§170.315(g)(10): Standardized API (SMART on FHIR)"
         },
         {
          "href": "#8d9146e5-7a72-5eac-a274-e74a728227e7",
          "rel": "reference",
          "text": "45 CFR §164.312(d): Person authentication; §164.312(a)(1): Access control"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (Risk management, access security)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§5.2: Software requirements (authentication)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.7 (security and resilience are evaluated and documented)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM06: Excessive Agency (over-privileged service account scopes)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "IAM-14 (Strong Authentication)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "IAM-16 (Authorization Mechanisms)"
         }
        ]
       },
       {
        "id": "hc-srf-l4-dev-002",
        "class": "srf-vertical-control",
        "title": "FHIR AuditEvent Logging Completeness",
        "params": [
         {
          "id": "hc-srf-l4-dev-002-p1",
          "label": "audit_log_completeness_rate",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "rolling-24h"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "{min_audit_completeness_rate}"
          ],
          "guidelines": [
           {
            "prose": "Fraction of qualifying clinical AI events (inferences, overrides, PHI access) with a corresponding FHIR AuditEvent record."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-DEV-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform & Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "health-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "alert-platform-team-and-escalate-to-compliance"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AuditEvent"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "coverage metric (qualifying events with AuditEvent / total qualifying events)"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-fda-tplc",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-fda-pccp",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-62304",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iso-14971",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 8: Audit Log Management"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l4-dev-002_stmt",
          "name": "statement",
          "prose": "All AI-assisted clinical decisions, recommendation events, override events, and PHI access events must generate FHIR AuditEvent records. Audit log completeness rate (fraction of qualifying events with a corresponding AuditEvent) must meet the configured threshold, per 21 CFR Part 11 and HIPAA audit controls."
         },
         {
          "id": "hc-srf-l4-dev-002_obj",
          "name": "objective",
          "prose": "Maintain audit_log_completeness_rate >= {{ insert: param, hc-srf-l4-dev-002-p1 }} over window rolling-24h. Breach action: alert-platform-team-and-escalate-to-compliance."
         }
        ],
        "links": [
         {
          "href": "#8e4fc90b-6135-5c7a-81da-30efe01e36ad",
          "rel": "reference",
          "text": "§170.315(d)(2): Auditing actions on health information"
         },
         {
          "href": "#8d9146e5-7a72-5eac-a274-e74a728227e7",
          "rel": "reference",
          "text": "45 CFR §164.312(b): Audit controls"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 12 (Record-keeping)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.8 (transparency and accountability are examined and documented)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "LOG-03 (Security Monitoring and Alerting)"
         }
        ]
       },
       {
        "id": "hc-srf-l4-dev-003",
        "class": "srf-vertical-control",
        "title": "PHI Encryption at Rest and in Transit",
        "params": [
         {
          "id": "hc-srf-l4-dev-003-p1",
          "label": "phi_encryption_enforced",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: all PHI encrypted at rest (AES-256) and in transit (TLS 1.2+); any unencrypted PHI transmission is zero-tolerance."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-DEV-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform & Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "health-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "immediate-breach-response-and-hipaa-incident-declaration"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AuditEvent"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "type.code == '110112' (Query), security.label (encryption status)"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-fda-tplc",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-fda-pccp",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-onc-hti1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iso-14971",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 3: Data Protection"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l4-dev-003_stmt",
          "name": "statement",
          "prose": "All PHI processed by clinical AI systems must be encrypted at rest (minimum AES-256) and in transit (minimum TLS 1.2). Encryption configuration must be verified at deployment and monitored continuously. Any unencrypted PHI transmission is a zero-tolerance HIPAA Security Rule violation."
         },
         {
          "id": "hc-srf-l4-dev-003_obj",
          "name": "objective",
          "prose": "Maintain phi_encryption_enforced == {{ insert: param, hc-srf-l4-dev-003-p1 }} over window continuous. Breach action: immediate-breach-response-and-hipaa-incident-declaration."
         }
        ],
        "links": [
         {
          "href": "#8d9146e5-7a72-5eac-a274-e74a728227e7",
          "rel": "reference",
          "text": "45 CFR §164.312(a)(2)(iv): Encryption; §164.312(e)(2)(ii): Encryption in transit"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (Risk management, data security)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§5.2: Software requirements (data security)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.10 (privacy risk is examined and documented); MEASURE 2.7 (security and resilience are evaluated and documented)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "CEK-03 (Data Encryption, including in-use)"
         }
        ]
       },
       {
        "id": "hc-srf-l4-vv-001",
        "class": "srf-vertical-control",
        "title": "Platform Security Assessment Before Clinical Deployment",
        "params": [
         {
          "id": "hc-srf-l4-vv-001-p1",
          "label": "platform_pentest_completed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "pre-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: penetration test and vulnerability scan completed before clinical deployment; critical and high findings remediated."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-VV-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform & Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "health-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "verification-validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-clinical-deployment"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "DocumentReference"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "category.code == 'security-assessment-report', status == 'current'"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-fda-pccp",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-onc-hti1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 18: Penetration Testing"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l4-vv-001_stmt",
          "name": "statement",
          "prose": "Clinical AI platforms must undergo a penetration test and vulnerability scan before clinical deployment. Critical and high-severity findings must be remediated before go-live. Results must be archived with the regulatory submission package and reviewed at each governance cycle."
         },
         {
          "id": "hc-srf-l4-vv-001_obj",
          "name": "objective",
          "prose": "Maintain platform_pentest_completed == {{ insert: param, hc-srf-l4-vv-001-p1 }} over window pre-deployment. Breach action: block-clinical-deployment."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 3.2: Cybersecurity considerations"
         },
         {
          "href": "#8d9146e5-7a72-5eac-a274-e74a728227e7",
          "rel": "reference",
          "text": "45 CFR §164.308(a)(8): Evaluation standard"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9(5)(b) (Testing including cybersecurity)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§5.7: Software testing (security)"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§6.4: Risk control verification"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.7 (security and resilience are evaluated and documented)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-06 (Penetration Testing)"
         }
        ]
       },
       {
        "id": "hc-srf-l4-vv-002",
        "class": "srf-vertical-control",
        "title": "Clinical Guardrail Configuration Baseline Verification",
        "params": [
         {
          "id": "hc-srf-l4-vv-002-p1",
          "label": "guardrail_configuration_verified",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "at-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: all clinical safety guardrails verified active at deployment; signed baseline record produced."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-VV-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform & Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "health-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "verification-validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-clinical-activation"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "DeviceMetric"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "operationalStatus == 'on', calibration.time, source (device reference)"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-onc-hti1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l4-vv-002_stmt",
          "name": "statement",
          "prose": "All clinical safety guardrails (contraindication checks, dosing limits, clinical alert thresholds, content safety filters) must be verified as active and correctly configured at platform deployment. Verification must be automated and produce a signed baseline record."
         },
         {
          "id": "hc-srf-l4-vv-002_obj",
          "name": "objective",
          "prose": "Maintain guardrail_configuration_verified == {{ insert: param, hc-srf-l4-vv-002-p1 }} over window at-deployment. Breach action: block-clinical-activation."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 3.2: Safety controls verification"
         },
         {
          "href": "#5c236a56-0fd8-52fc-880b-5e213d233a3f",
          "rel": "reference",
          "text": "Principle 1: Focused and verifiable"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (Risk management controls active)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§5.7: System testing (guardrail verification)"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§6.4: Risk control verification"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.6 (safety risks are evaluated and documented)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM05: Improper Output Handling"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-11 (Guardrails)"
         }
        ]
       },
       {
        "id": "hc-srf-l4-pms-001",
        "class": "srf-vertical-control",
        "title": "Unauthorized Access Attempt Monitoring",
        "params": [
         {
          "id": "hc-srf-l4-pms-001-p1",
          "label": "confirmed_unauthorized_access_rate",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "0"
          ],
          "guidelines": [
           {
            "prose": "Zero tolerance: any confirmed unauthorized access to clinical AI systems or PHI requires immediate breach assessment."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-PMS-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform & Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "health-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "post-market-surveillance"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "immediate-security-incident-response-and-hipaa-breach-assessment"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AuditEvent"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "type.code == '110113' (Security Alert), outcome != '0'"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-fda-pccp",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-onc-hti1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-62304",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l4-pms-001_stmt",
          "name": "statement",
          "prose": "Unauthorized access attempts to clinical AI systems or PHI held by the platform must be detected and alerted in real time. Any confirmed unauthorized access is a zero-tolerance HIPAA Security Incident requiring documented breach assessment per 45 CFR §164.308(a)(6)."
         },
         {
          "id": "hc-srf-l4-pms-001_obj",
          "name": "objective",
          "prose": "Maintain confirmed_unauthorized_access_rate == {{ insert: param, hc-srf-l4-pms-001-p1 }} over window continuous. Breach action: immediate-security-incident-response-and-hipaa-breach-assessment."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 4: Post-market cybersecurity monitoring"
         },
         {
          "href": "#8d9146e5-7a72-5eac-a274-e74a728227e7",
          "rel": "reference",
          "text": "45 CFR §164.308(a)(6)(ii): Response and reporting"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 72 (Post-market monitoring including security)"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§10.2: Post-production information"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.7 (security and resilience are evaluated and documented); MANAGE 4.3 (incidents and errors are communicated)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "LOG-03 (Security Monitoring and Alerting)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "LOG-13 (Failures and Anomalies Reporting)"
         }
        ]
       },
       {
        "id": "hc-srf-l4-pms-002",
        "class": "srf-vertical-control",
        "title": "Clinical AI Platform Availability SLA",
        "params": [
         {
          "id": "hc-srf-l4-pms-002-p1",
          "label": "platform_availability_rate",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "rolling-30d"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "{min_platform_availability_rate}"
          ],
          "guidelines": [
           {
            "prose": "Fraction of scheduled uptime during which the clinical AI platform is available, measured over a rolling 30-day period."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-PMS-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform & Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "health-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "post-market-surveillance"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "alert-operations-and-review-contingency-plan"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OperationOutcome"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "issue.severity (for downtime events), diagnostics (root cause)"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-fda-pccp",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-onc-hti1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-62304",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l4-pms-002_stmt",
          "name": "statement",
          "prose": "Clinical AI platforms integrated into clinical workflows must meet an availability SLA calibrated to the clinical dependency risk tier. Systems supporting emergency or critical-care decisions require a higher SLA than administrative AI tools. Downtime must be logged and root cause documented."
         },
         {
          "id": "hc-srf-l4-pms-002_obj",
          "name": "objective",
          "prose": "Maintain platform_availability_rate >= {{ insert: param, hc-srf-l4-pms-002-p1 }} over window rolling-30d. Breach action: alert-operations-and-review-contingency-plan."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 4: Post-market performance"
         },
         {
          "href": "#8d9146e5-7a72-5eac-a274-e74a728227e7",
          "rel": "reference",
          "text": "45 CFR §164.312(a)(2)(ii): Emergency access; §164.310(a)(2)(i): Contingency plan"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (Accuracy, robustness, and cybersecurity)"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§6: Risk control (availability)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.5 (the deployed system is demonstrated to be valid and reliable)"
         }
        ]
       },
       {
        "id": "hc-srf-l4-pms-003",
        "class": "srf-vertical-control",
        "title": "Runtime Model Artifact Integrity Verification",
        "params": [
         {
          "id": "hc-srf-l4-pms-003-p1",
          "label": "model_artifact_integrity_verified",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "at-each-model-load"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary per model load: cryptographic hash of loaded model artifact matches signed baseline."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-PMS-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform & Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "health-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "post-market-surveillance"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-model-serve-and-initiate-incident-response"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Provenance"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "entity (model artifact), signature (hash), recorded"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-onc-hti1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iso-14971",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l4-pms-003_stmt",
          "name": "statement",
          "prose": "The cryptographic hash of the deployed model artifact must be verified at each model load. A hash mismatch between the loaded artifact and the signed baseline must trigger an immediate alert, prevent the model from serving clinical inferences, and initiate incident response."
         },
         {
          "id": "hc-srf-l4-pms-003_obj",
          "name": "objective",
          "prose": "Maintain model_artifact_integrity_verified == {{ insert: param, hc-srf-l4-pms-003-p1 }} over window at-each-model-load. Breach action: block-model-serve-and-initiate-incident-response."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 4: Post-market integrity assurance"
         },
         {
          "href": "#5c236a56-0fd8-52fc-880b-5e213d233a3f",
          "rel": "reference",
          "text": "Principle 1: Verifiable modification scope"
         },
         {
          "href": "#8d9146e5-7a72-5eac-a274-e74a728227e7",
          "rel": "reference",
          "text": "45 CFR §164.312(c)(1): Integrity"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (Risk management, integrity controls)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§6.3: Software modification process"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.7 (security and resilience are evaluated and documented); MANAGE 3.1 (AI risks from third-party resources are monitored)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM03: Supply Chain"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM04: Data and Model Poisoning"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-08 (Model Integrity Checks)"
         }
        ]
       }
      ]
     },
     {
      "id": "l4-insurance",
      "class": "srf-vertical",
      "title": "L4 — Insurance",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "insurance"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/insurance-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "ins-srf-l4-dev-001",
        "class": "srf-vertical-control",
        "title": "Model Gateway Authentication Configuration",
        "params": [
         {
          "id": "ins-srf-l4-dev-001-p1",
          "label": "unauthenticated_model_gateway_access_count",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "0"
          ],
          "guidelines": [
           {
            "prose": "Zero-tolerance: no unauthenticated access path to model API gateways may exist in production."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-DEV-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-unauthenticated-access-immediately; page-platform-security-team; initiate-incident-response"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "authentication (3001): gateway authentication events logged to SIEM. Unauthenticated access attempts produce security_finding (2001)."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "class_uid == 3001 AND status_id == 'failure' AND auth_protocol == 'none'"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-naic-model-bulletin",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-naic-eval-tool",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-co-reg-10-1-1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nydfs-cl7",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 6: Access Control Management"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l4-dev-001_stmt",
          "name": "statement",
          "prose": "Every model API gateway used to serve AI models in insurance workflows must enforce mutual TLS or equivalent strong authentication. Unauthenticated or weakly authenticated access paths must not exist in production. Configuration must be validated before deployment and after any infrastructure change affecting authentication."
         },
         {
          "id": "ins-srf-l4-dev-001_obj",
          "name": "objective",
          "prose": "Maintain unauthenticated_model_gateway_access_count == {{ insert: param, ins-srf-l4-dev-001-p1 }} over window continuous. Breach action: block-unauthenticated-access-immediately; page-platform-security-team; initiate-incident-response."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (accuracy, robustness and cybersecurity for high-risk AI systems)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM05 (Improper Output Handling, also relevant to authentication bypass vectors)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.7 (security and resilience are evaluated and documented)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "IAM-14 (Strong Authentication)"
         }
        ]
       },
       {
        "id": "ins-srf-l4-dev-002",
        "class": "srf-vertical-control",
        "title": "Guardrail Configuration Baseline Documentation",
        "params": [
         {
          "id": "ins-srf-l4-dev-002-p1",
          "label": "guardrail_baseline_documented_and_current",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-change"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: documented guardrail baseline exists, is current, and all configuration changes in the prior period were logged and approved."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-DEV-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "revert-unapproved-change; notify-platform-security-team; review-change-management-process"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "audit_activity (3002): platform configuration management system logs guardrail configuration changes with approver identity and timestamp."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "activity_id == 'guardrail_config_change' AND approver_id != null"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-naic-eval-tool",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-co-reg-10-1-1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nydfs-cl7",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l4-dev-002_stmt",
          "name": "statement",
          "prose": "AI platforms used in insurance workflows must maintain a documented baseline configuration for content and behavior guardrails. The baseline must specify enabled guardrail categories, thresholds, and the review process for any configuration change. Changes to guardrail configuration must be logged and approved by the accountable officer before taking effect in production."
         },
         {
          "id": "ins-srf-l4-dev-002_obj",
          "name": "objective",
          "prose": "Maintain guardrail_baseline_documented_and_current == {{ insert: param, ins-srf-l4-dev-002-p1 }} over window per-change. Breach action: revert-unapproved-change; notify-platform-security-team; review-change-management-process."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 3.1 (identification of constraints and controls on automation and design to align and balance function with risk)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (risk management system, technical safeguards)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.6 (safety risks are evaluated and documented)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-11 (Guardrails)"
         }
        ]
       },
       {
        "id": "ins-srf-l4-dev-003",
        "class": "srf-vertical-control",
        "title": "PII Encryption at Rest and in Transit",
        "params": [
         {
          "id": "ins-srf-l4-dev-003-p1",
          "label": "pii_unencrypted_at_rest_or_in_transit_count",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "0"
          ],
          "guidelines": [
           {
            "prose": "Zero-tolerance: no consumer PII or sensitive insurance data stored or transmitted in unencrypted form in production AI platform infrastructure."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-DEV-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "isolate-affected-data-store; page-security-team; initiate-incident-response; regulatory-disclosure-assessment"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "security_finding (2001): infrastructure security scanner emits findings for unencrypted PII storage or transmission. Attribute: finding.type_id = 'unencrypted_pii'."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finding.type_id == 'unencrypted_pii' AND status_id == 'new'"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-naic-model-bulletin",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-naic-eval-tool",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-co-reg-10-1-1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nydfs-cl7",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 3: Data Protection"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l4-dev-003_stmt",
          "name": "statement",
          "prose": "All consumer PII and sensitive insurance data processed or stored by AI platform infrastructure must be encrypted at rest using AES-256 or equivalent and in transit using TLS 1.2 or higher. Encryption configuration must be validated before deployment and included in the platform security assessment under SRF-L4-VAL-001."
         },
         {
          "id": "ins-srf-l4-dev-003_obj",
          "name": "objective",
          "prose": "Maintain pii_unencrypted_at_rest_or_in_transit_count == {{ insert: param, ins-srf-l4-dev-003-p1 }} over window continuous. Breach action: isolate-affected-data-store; page-security-team; initiate-incident-response; regulatory-disclosure-assessment."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (cybersecurity, data protection for high-risk AI)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.10 (privacy risk is examined); MEASURE 2.7 (security and resilience are evaluated)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "CEK-03 (Data Encryption, including in-use)"
         }
        ]
       },
       {
        "id": "ins-srf-l4-val-001",
        "class": "srf-vertical-control",
        "title": "Platform Security Assessment",
        "params": [
         {
          "id": "ins-srf-l4-val-001-p1",
          "label": "platform_security_assessment_completed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "0"
          ],
          "guidelines": [
           {
            "prose": "Binary: security assessment completed, all critical and high findings remediated, and assessment report retained before production deployment."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-VAL-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "validation-testing"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-deployment; remediate-open-findings; re-assess-before-release"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "security_finding (2001): security assessment platform emits findings. Unmitigated critical or high findings block deployment."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finding.severity_id IN ('critical','high') AND status_id == 'new'"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-naic-model-bulletin",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-naic-eval-tool",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-co-reg-10-1-1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nydfs-cl7",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 18: Penetration Testing"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l4-val-001_stmt",
          "name": "statement",
          "prose": "AI platform infrastructure used in insurance workflows must undergo a documented security assessment before production deployment and annually thereafter. The assessment must cover authentication, authorization, encryption, guardrail configuration, network segmentation, and third-party component vulnerability status. Critical and high findings must be remediated before production go-live."
         },
         {
          "id": "ins-srf-l4-val-001_obj",
          "name": "objective",
          "prose": "Maintain platform_security_assessment_completed == {{ insert: param, ins-srf-l4-val-001-p1 }} over window per-deployment. Breach action: block-deployment; remediate-open-findings; re-assess-before-release."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (accuracy, robustness and cybersecurity for high-risk AI)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.7 (security and resilience are evaluated and documented)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-06 (Penetration Testing)"
         }
        ]
       },
       {
        "id": "ins-srf-l4-mon-001",
        "class": "srf-vertical-control",
        "title": "Vendor-Model Isolation and Egress Control",
        "params": [
         {
          "id": "ins-srf-l4-mon-001-p1",
          "label": "vendor_model_egress_violation_count",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "0"
          ],
          "guidelines": [
           {
            "prose": "Zero-tolerance: no unauthorized transmission of consumer PII or policy data to vendor endpoints. Any egress control violation is treated as a security incident."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-MON-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-egress-immediately; isolate-affected-system; initiate-incident-response; notify-data-privacy-officer"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "network_activity (4001): network monitoring platform logs outbound connections to vendor endpoints. security_finding (2001) emitted on PII egress detection."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dst_endpoint.type == 'vendor_model' AND data.classification == 'PII' AND authorized == false"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-naic-model-bulletin",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-naic-eval-tool",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-co-reg-10-1-1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nydfs-cl7",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l4-mon-001_stmt",
          "name": "statement",
          "prose": "Third-party model inference endpoints and AI SaaS platforms must be isolated from core insurance systems through network segmentation and egress controls. Consumer PII and policy data must not be transmitted to vendor endpoints beyond what is required for the specific inference task. Egress controls must be monitored continuously and violations treated as security incidents."
         },
         {
          "id": "ins-srf-l4-mon-001_obj",
          "name": "objective",
          "prose": "Maintain vendor_model_egress_violation_count == {{ insert: param, ins-srf-l4-mon-001-p1 }} over window continuous. Breach action: block-egress-immediately; isolate-affected-system; initiate-incident-response; notify-data-privacy-officer."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (cybersecurity, data integrity and confidentiality)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM02 (Sensitive Information Disclosure)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.7 (security and resilience are evaluated); MANAGE 3.1 (AI risks from third-party resources are monitored)"
         }
        ]
       },
       {
        "id": "ins-srf-l4-mon-002",
        "class": "srf-vertical-control",
        "title": "Audit Log Completeness for AI-Assisted Decisions",
        "params": [
         {
          "id": "ins-srf-l4-mon-002-p1",
          "label": "audit_log_completeness_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "daily"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_AUDIT_LOG_COMPLETENESS_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of AI-assisted decisions with complete, tamper-evident audit log entries. Tier-configurable; recommended minimum 99.5%."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-MON-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "investigate-logging-gap; notify-platform-team; escalate-to-chief-compliance-officer-if-gap-exceeds-24h"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "audit_activity (3002): SIEM monitors audit log completeness rate. security_finding (2001) emitted when completeness drops below threshold."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "class_uid == 3002 AND activity_id == 'ai_decision_log' AND status_id == 'success'"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-naic-eval-tool",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 8: Audit Log Management"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l4-mon-002_stmt",
          "name": "statement",
          "prose": "All AI-assisted decisions in underwriting, rating, and claims must generate complete, tamper-evident audit log entries capturing: decision type, AI system identifier, input data hash, output recommendation, human review outcome (if applicable), timestamp, and user identity. Log completeness must be monitored continuously and the completeness rate must remain above the tier-configurable threshold."
         },
         {
          "id": "ins-srf-l4-mon-002_obj",
          "name": "objective",
          "prose": "Maintain audit_log_completeness_pct >= {{ insert: param, ins-srf-l4-mon-002-p1 }} over window daily. Breach action: investigate-logging-gap; notify-platform-team; escalate-to-chief-compliance-officer-if-gap-exceeds-24h."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 2.3(d) (monitoring, auditing, escalation, and reporting protocols and requirements)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(C) (governance and risk management framework components must be available to the Division on request - general availability nexus, not a decision-level tamper-evident audit log requirement)"
         },
         {
          "href": "#c59939b3-2e4d-575b-878c-2a4ff0ee3ea1",
          "rel": "reference",
          "text": "Section III.C, paragraph 34(b) (internal audit verifying records of AIS use and validation)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 12 (record-keeping, automatically generated logs for high-risk AI systems)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.8 (transparency and accountability are examined and documented)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "LOG-03 (Security Monitoring and Alerting)"
         }
        ]
       },
       {
        "id": "ins-srf-l4-mon-003",
        "class": "srf-vertical-control",
        "title": "Runtime Anomaly Detection for AI Workloads",
        "params": [
         {
          "id": "ins-srf-l4-mon-003-p1",
          "label": "runtime_anomaly_mean_time_to_detect_hours",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "<="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_RUNTIME_ANOMALY_DETECT_HOURS"
          ],
          "guidelines": [
           {
            "prose": "Mean time to detect runtime anomaly events. Tier-configurable; lower is better. Recommended: detect within 1 hour for high-severity anomalies."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-MON-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "page-security-operations; initiate-incident-response; isolate-anomalous-workload-if-high-severity"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "detection_finding (2004): runtime monitoring platform emits anomaly findings for AI workloads."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finding.title == 'ai_runtime_anomaly' AND severity_id IN ('critical','high')"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-naic-model-bulletin",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-naic-eval-tool",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-co-reg-10-1-1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nydfs-cl7",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l4-mon-003_stmt",
          "name": "statement",
          "prose": "AI platform infrastructure must monitor runtime behavior of AI workloads for anomalous patterns indicating model compromise, data exfiltration, or unexpected model behavior. Monitoring must cover inference request volume, latency, output distribution, and network activity. Anomaly findings above the tier-configurable sensitivity threshold must trigger an incident response workflow."
         },
         {
          "id": "ins-srf-l4-mon-003_obj",
          "name": "objective",
          "prose": "Maintain runtime_anomaly_mean_time_to_detect_hours <= {{ insert: param, ins-srf-l4-mon-003-p1 }} over window continuous. Breach action: page-security-operations; initiate-incident-response; isolate-anomalous-workload-if-high-severity."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (robustness and resilience, detection of anomalous behavior for high-risk AI)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM04 (Data and Model Poisoning, detected via runtime behavior)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.7 (security and resilience are evaluated); MEASURE 2.4 (the deployed AI system is monitored)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "LOG-13 (Failures and Anomalies Reporting)"
         }
        ]
       },
       {
        "id": "ins-srf-l4-tpo-001",
        "class": "srf-vertical-control",
        "title": "Third-Party Platform Access Review",
        "params": [
         {
          "id": "ins-srf-l4-tpo-001-p1",
          "label": "stale_vendor_access_count",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "quarterly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "0"
          ],
          "guidelines": [
           {
            "prose": "Count of third-party AI platform access credentials or API keys unused in the prior 90 days that have not been deprovisioned or reauthorized."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-TPO-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "third-party-oversight"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "deprovision-stale-access; notify-accountable-officer; update-vendor-register"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "api_activity (6003): access management platform logs vendor credential usage. security_finding (2001) emitted for stale credentials."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finding.type_id == 'stale_vendor_access' AND last_used_days > 90"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-naic-model-bulletin",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-naic-eval-tool",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-co-reg-10-1-1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nydfs-cl7",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l4-tpo-001_stmt",
          "name": "statement",
          "prose": "Third-party AI platforms and SaaS AI providers must undergo an annual access review confirming that access credentials, API keys, and data sharing agreements are current, scoped to current use cases, and consistent with the vendor register in SRF-L1-DEV-003. Access not used in the prior 90 days must be deprovisioned or explicitly reauthorized."
         },
         {
          "id": "ins-srf-l4-tpo-001_obj",
          "name": "objective",
          "prose": "Maintain stale_vendor_access_count == {{ insert: param, ins-srf-l4-tpo-001-p1 }} over window quarterly. Breach action: deprovision-stale-access; notify-accountable-officer; update-vendor-register."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 26 (obligations of deployers of high-risk AI systems, general oversight only, no provision addresses API credential or access review specifically)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 3.1 (AI risks from third-party resources are monitored); GOVERN 6.1 (third-party policies are in place)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "IAM-16 (Authorization Mechanisms)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-14 (Supply Chain Governance Review)"
         }
        ]
       }
      ]
     },
     {
      "id": "l4-defense",
      "class": "srf-vertical",
      "title": "L4 — Defense",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "defense"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/defense-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "def-srf-l4-acq-001",
        "class": "srf-vertical-control",
        "title": "DISA Provisional Authorization at Required IL Before Deployment",
        "params": [
         {
          "id": "def-srf-l4-acq-001-p1",
          "label": "disa_pa_current",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "TIER_DISA_PA_CURRENT"
          ],
          "guidelines": [
           {
            "prose": "Binary: the platform holds a current DISA PA at or above the required IL as verified against the DISA PA list."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-ACQ-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI Platform"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "disa"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "non-nss"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-deployment; notify-PM; identify-alternative-PA-platform"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. PA currency can be verified against public.cyber.mil PA listings."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l4-acq-001_stmt",
          "name": "statement",
          "prose": "The cloud service or AI platform must hold a current DISA Provisional Authorization (PA) at the impact level required for the data being processed before the component may use it for DoD data. The component must verify the PA is current and covers the services in use before deployment and at each annual review."
         },
         {
          "id": "def-srf-l4-acq-001_obj",
          "name": "objective",
          "prose": "Maintain disa_pa_current == {{ insert: param, def-srf-l4-acq-001-p1 }} over window annual. Breach action: block-deployment; notify-PM; identify-alternative-PA-platform."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Responsible principle"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.6"
         },
         {
          "href": "#c5d89a8d-2be1-526a-977f-3cc51013206f",
          "rel": "reference",
          "text": "Mission Owner SRG Section 3.2 (CSP/CSO Approval Process: DOD Provisional Authorization required)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "A&A-02 (Independent Assessments)"
         }
        ]
       },
       {
        "id": "def-srf-l4-acq-002",
        "class": "srf-vertical-control",
        "title": "STIG Baseline Configuration Enforcement",
        "params": [
         {
          "id": "def-srf-l4-acq-002-p1",
          "label": "stig_open_findings_cat1",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "TIER_STIG_OPEN_CAT1_FINDINGS"
          ],
          "guidelines": [
           {
            "prose": "Number of open Category I (high) STIG findings without accepted risk signed by the AO. Zero-tolerance."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-ACQ-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI Platform"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.4.1"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.4.2"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "notify-ISSO; remediate-or-accept-risk-within-30-days; report-to-AO"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "vulnerability_finding (2002). STIG scan results from DISA ACAS must log finding ID, severity, system, and remediation status."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 4: Secure Configuration of Enterprise Assets and Software"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l4-acq-002_stmt",
          "name": "statement",
          "prose": "The platform and all AI-hosting components must be configured to the applicable DISA Security Technical Implementation Guide (STIG) baseline. STIG compliance must be verified during TEVV and continuously monitored. Open STIG findings must be tracked with accepted risk or remediation plans signed by the AO."
         },
         {
          "id": "def-srf-l4-acq-002_obj",
          "name": "objective",
          "prose": "Maintain stig_open_findings_cat1 == {{ insert: param, def-srf-l4-acq-002-p1 }} over window continuous. Breach action: notify-ISSO; remediate-or-accept-risk-within-30-days; report-to-AO."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Reliable principle"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "CM.L2-3.4.1 (baseline configurations and system inventories)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "CM.L2-3.4.2 (security configuration settings)"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.4.1"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 2.4"
         },
         {
          "href": "#c5d89a8d-2be1-526a-977f-3cc51013206f",
          "rel": "reference",
          "text": "Mission Owner SRG Section 3.3.2 (VM OS and applications configured IAW applicable STIGs)"
         }
        ]
       },
       {
        "id": "def-srf-l4-acq-003",
        "class": "srf-vertical-control",
        "title": "IL-Appropriate Cloud Region Enforcement",
        "params": [
         {
          "id": "def-srf-l4-acq-003-p1",
          "label": "out_of_region_processing_events",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "TIER_OUT_OF_REGION_EVENTS"
          ],
          "guidelines": [
           {
            "prose": "Number of data processing events detected in a non-authorized region. Zero-tolerance."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-ACQ-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI Platform"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-processing; alert-ISSO; notify-AO; open-security-incident"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "network_activity (4001). Region enforcement events must log the data classification, region, and enforcement action."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l4-acq-003_stmt",
          "name": "statement",
          "prose": "The platform must enforce that DoD data is processed only in cloud regions that meet the applicable IL requirements: commercial regions for IL4, government-only regions for IL5, and classified cloud only for IL6. Region enforcement must be verified during TEVV and monitored continuously."
         },
         {
          "id": "def-srf-l4-acq-003_obj",
          "name": "objective",
          "prose": "Maintain out_of_region_processing_events == {{ insert: param, def-srf-l4-acq-003-p1 }} over window continuous. Breach action: block-processing; alert-ISSO; notify-AO; open-security-incident."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Responsible principle"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 2.4"
         },
         {
          "href": "#c5d89a8d-2be1-526a-977f-3cc51013206f",
          "rel": "reference",
          "text": "CSP SRG Section 5.2.2 (location and separation requirements by impact level)"
         },
         {
          "href": "#c5d89a8d-2be1-526a-977f-3cc51013206f",
          "rel": "reference",
          "text": "Mission Owner SRG Section 3.3.3 (IL6 restricted to DOD private/community or federal government community cloud)"
         }
        ]
       },
       {
        "id": "def-srf-l4-ops-004",
        "class": "srf-vertical-control",
        "title": "CUI and Classified Data Encryption to NSA-Approved Standards",
        "params": [
         {
          "id": "def-srf-l4-ops-004-p1",
          "label": "encryption_compliance_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "quarterly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_ENCRYPTION_COMPLIANCE_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of data stores and transport channels confirmed compliant with the required cryptographic standard."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-OPS-004"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI Platform"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.13.8"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.13.10"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "quarantine-non-compliant-store; notify-ISSO; remediate-within-30-days"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "data_security_finding (2004). Encryption compliance scans must log store or channel ID, standard verified, and validation status."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 3: Data Protection"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l4-ops-004_stmt",
          "name": "statement",
          "prose": "CUI data at IL4/IL5 must be encrypted at rest and in transit using FIPS 140-3 validated cryptography. IL6 classified data must be encrypted using NSA-approved cryptography (Suite B or Commercial National Security Algorithm Suite). Encryption key management must comply with CNSSI 1300 or equivalent."
         },
         {
          "id": "def-srf-l4-ops-004_obj",
          "name": "objective",
          "prose": "Maintain encryption_compliance_pct >= {{ insert: param, def-srf-l4-ops-004-p1 }} over window quarterly. Breach action: quarantine-non-compliant-store; notify-ISSO; remediate-within-30-days."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Responsible principle"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "SC.L2-3.13.8 (cryptography to prevent unauthorized disclosure of CUI in transit)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "SC.L2-3.13.10 (cryptographic key management)"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.13.8"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 2.4"
         },
         {
          "href": "#c5d89a8d-2be1-526a-977f-3cc51013206f",
          "rel": "reference",
          "text": "Mission Owner SRG Section 3.3.4 (Encryption of Data at Rest: FIPS 140-2/3 with Mission Owner key control)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "CEK-03 (Data Encryption, including in-use)"
         }
        ]
       },
       {
        "id": "def-srf-l4-ops-005",
        "class": "srf-vertical-control",
        "title": "Audit Log Completeness per DISA Requirements",
        "params": [
         {
          "id": "def-srf-l4-ops-005-p1",
          "label": "audit_log_completeness_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "quarterly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_AUDIT_LOG_COMPLETENESS_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of required event types with confirmed log generation, as verified by the most recent completeness audit."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-OPS-005"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI Platform"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Traceable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.3.1"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.3.2"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "notify-ISSO; remediate-logging-gaps; notify-AO"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "audit_activity (3002). Log completeness verification events must record the event types checked and the verification outcome."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 8: Audit Log Management"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l4-ops-005_stmt",
          "name": "statement",
          "prose": "The platform must generate and retain audit logs meeting DISA requirements for the applicable IL. Logs must cover authentication events, API calls, data access, configuration changes, and AI inference requests. Log completeness must be verified quarterly and after any platform update."
         },
         {
          "id": "def-srf-l4-ops-005_obj",
          "name": "objective",
          "prose": "Maintain audit_log_completeness_pct >= {{ insert: param, def-srf-l4-ops-005-p1 }} over window quarterly. Breach action: notify-ISSO; remediate-logging-gaps; notify-AO."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Traceable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 1.2.3 (identify infrastructure gaps for traceability, auditability, risk analysis, and forensics)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "AU.L2-3.3.1 (create and retain system audit logs and records)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "AU.L2-3.3.2 (trace actions to individual users)"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.3.1"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.5"
         },
         {
          "href": "#c5d89a8d-2be1-526a-977f-3cc51013206f",
          "rel": "reference",
          "text": "Mission Owner SRG Section 3.3 (CSSP collaboration to ensure required security-relevant data is accessible)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "LOG-03 (Security Monitoring and Alerting)"
         }
        ]
       },
       {
        "id": "def-srf-l4-ops-006",
        "class": "srf-vertical-control",
        "title": "API Gateway Authentication and Authorization",
        "params": [
         {
          "id": "def-srf-l4-ops-006-p1",
          "label": "unauthenticated_api_request_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "TIER_UNAUTH_API_REQUESTS"
          ],
          "guidelines": [
           {
            "prose": "Percentage of AI platform API requests that bypassed authentication controls. Zero-tolerance."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-OPS-006"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI Platform"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.5.3"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.5.5"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-request; alert-SOC; notify-ISSO"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "authentication (3002) or api_activity (6003). Failed and unauthenticated requests must log source IP, endpoint, and rejection reason."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 6: Access Control Management"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l4-ops-006_stmt",
          "name": "statement",
          "prose": "All AI platform APIs must require authentication using DoD PKI or equivalent credential and enforce attribute-based or role-based authorization before any AI inference or data access is permitted. Unauthenticated requests must be rejected and logged. Privileged API calls require multi-factor authentication."
         },
         {
          "id": "def-srf-l4-ops-006_obj",
          "name": "objective",
          "prose": "Maintain unauthenticated_api_request_pct == {{ insert: param, def-srf-l4-ops-006-p1 }} over window continuous. Breach action: block-request; alert-SOC; notify-ISSO."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Responsible principle"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "IA.L2-3.5.3 (multifactor authentication for local and network access)"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.5.3"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 2.4"
         },
         {
          "href": "#c5d89a8d-2be1-526a-977f-3cc51013206f",
          "rel": "reference",
          "text": "Mission Owner SRG Section 3.3.2 (DOD CAC/PKI authentication for cloud system access)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "IAM-14 (Strong Authentication)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "IAM-16 (Authorization Mechanisms)"
         }
        ]
       },
       {
        "id": "def-srf-l4-acq-007",
        "class": "srf-vertical-control",
        "title": "CMMC Level 2 Assessment for Contractor-Owned CUI Platforms",
        "params": [
         {
          "id": "def-srf-l4-acq-007-p1",
          "label": "cmmc_l2_assessment_current",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "triennial"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "TIER_CMMC_L2_CURRENT"
          ],
          "guidelines": [
           {
            "prose": "Binary: the contractor holds a current C3PAO-assessed CMMC Level 2 certification with results in SPRS."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-ACQ-007"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI Platform"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "contractor"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "non-nss"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.12.1"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.12.2"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.12.3"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.12.4"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-CUI-processing; notify-contracting-officer; initiate-assessment"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. CMMC assessment results are submitted to SPRS by the C3PAO."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l4-acq-007_stmt",
          "name": "statement",
          "prose": "Defense contractors operating AI platforms that process CUI must obtain a third-party CMMC Level 2 assessment (C3PAO assessment) covering the 110 NIST SP 800-171 practices before processing DoD CUI. Assessment results must be submitted to SPRS and referenced in the contract."
         },
         {
          "id": "def-srf-l4-acq-007_obj",
          "name": "objective",
          "prose": "Maintain cmmc_l2_assessment_current == {{ insert: param, def-srf-l4-acq-007-p1 }} over window triennial. Breach action: block-CUI-processing; notify-contracting-officer; initiate-assessment."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Responsible principle"
         },
         {
          "href": "#289aed16-d1f7-58b5-b179-0353578d8705",
          "rel": "reference",
          "text": "Section 3.4.a(3) (vendor CMMC certification level assessed in market research)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "32 CFR Part 170, Level 2 requirements"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.12.1"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.6"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "A&A-02 (Independent Assessments)"
         }
        ]
       },
       {
        "id": "def-srf-l4-acq-008",
        "class": "srf-vertical-control",
        "title": "CMMC Level 3 Assessment for Higher-Value Contractor Platforms",
        "params": [
         {
          "id": "def-srf-l4-acq-008-p1",
          "label": "cmmc_l3_assessment_current",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "triennial"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "TIER_CMMC_L3_CURRENT"
          ],
          "guidelines": [
           {
            "prose": "Binary: the contractor holds a current DIBCAC-assessed CMMC Level 3 certification for the designated program."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-ACQ-008"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI Platform"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "contractor"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.12.1"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.12.2"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.12.3"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.12.4"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-higher-value-program-data; notify-contracting-officer; initiate-assessment"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. DIBCAC assessment results are government records."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l4-acq-008_stmt",
          "name": "statement",
          "prose": "Defense contractors operating AI platforms for programs designated as requiring CMMC Level 3 must obtain a DIBCAC-led government assessment covering the NIST SP 800-172 enhanced practices. The assessment must be current and referenced in the contract before any higher-value program data is processed."
         },
         {
          "id": "def-srf-l4-acq-008_obj",
          "name": "objective",
          "prose": "Maintain cmmc_l3_assessment_current == {{ insert: param, def-srf-l4-acq-008-p1 }} over window triennial. Breach action: block-higher-value-program-data; notify-contracting-officer; initiate-assessment."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Responsible principle"
         },
         {
          "href": "#289aed16-d1f7-58b5-b179-0353578d8705",
          "rel": "reference",
          "text": "Section 3.4.a(3) (vendor CMMC certification level assessed in market research)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "32 CFR Part 170, Level 3 requirements"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.12.1"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.6"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "A&A-02 (Independent Assessments)"
         }
        ]
       },
       {
        "id": "def-srf-l4-ops-009",
        "class": "srf-vertical-control",
        "title": "Continuous Vulnerability Scanning via DISA ACAS",
        "params": [
         {
          "id": "def-srf-l4-ops-009-p1",
          "label": "acas_scan_coverage_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "weekly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_ACAS_COVERAGE_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of AI platform nodes covered by ACAS scans within the required scan cadence."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-OPS-009"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI Platform"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.11.2"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.11.3"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "notify-ISSO; expand-scan-scope; report-gap-to-AO"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "vulnerability_finding (2002). ACAS scan results must log node ID, scan date, findings, and remediation status."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 7: Continuous Vulnerability Management"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l4-ops-009_stmt",
          "name": "statement",
          "prose": "AI platform hosts and containers must be continuously scanned using DISA-approved tools (Assured Compliance Assessment Solution, ACAS) and findings must be tracked and remediated per DISA remediation timelines. Scan coverage must include all AI inference and supporting infrastructure nodes."
         },
         {
          "id": "def-srf-l4-ops-009_obj",
          "name": "objective",
          "prose": "Maintain acas_scan_coverage_pct >= {{ insert: param, def-srf-l4-ops-009-p1 }} over window weekly. Breach action: notify-ISSO; expand-scan-scope; report-gap-to-AO."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Reliable principle"
         },
         {
          "href": "#289aed16-d1f7-58b5-b179-0353578d8705",
          "rel": "reference",
          "text": "Section 3.3.c (dedicated resources to monitor and mitigate exploitable cyber vulnerabilities)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "RA.L2-3.11.2 (periodic vulnerability scanning)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "RA.L2-3.11.3 (remediate vulnerabilities per risk assessments)"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.11.2"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 2.4"
         },
         {
          "href": "#c5d89a8d-2be1-526a-977f-3cc51013206f",
          "rel": "reference",
          "text": "Mission Owner SRG Section 3.3.2 (vulnerability scanning and VDMS endpoint protections including ACAS)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-07 (Vulnerability Remediation Schedule)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-09 (Vulnerability Management Reporting)"
         }
        ]
       },
       {
        "id": "def-srf-l4-ops-010",
        "class": "srf-vertical-control",
        "title": "Mission-Critical AI Availability SLA",
        "params": [
         {
          "id": "def-srf-l4-ops-010-p1",
          "label": "availability_sla_compliance_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "monthly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_AVAILABILITY_SLA_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of monitoring periods in which the system met its approved availability SLA."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-OPS-010"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI Platform"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "notify-operational-commander; activate-degraded-mode; open-availability-incident"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "availability (3003) or infrastructure_status. Availability monitoring must log uptime, degraded-mode events, and failover activations."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l4-ops-010_stmt",
          "name": "statement",
          "prose": "AI systems supporting mission-critical operations must have a documented availability SLA, a tested failover or degraded-mode procedure, and a recovery time objective (RTO) approved by the operational commander. Availability must be monitored continuously and reported against the SLA."
         },
         {
          "id": "def-srf-l4-ops-010_obj",
          "name": "objective",
          "prose": "Maintain availability_sla_compliance_pct >= {{ insert: param, def-srf-l4-ops-010-p1 }} over window monthly. Breach action: notify-operational-commander; activate-degraded-mode; open-availability-incident."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Reliable principle"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.7"
         },
         {
          "href": "#c5d89a8d-2be1-526a-977f-3cc51013206f",
          "rel": "reference",
          "text": "Mission Owner SRG Section 3.3.7 (Contract/SLA Requirements: availability-related security controls)"
         }
        ]
       },
       {
        "id": "def-srf-l4-tevv-011",
        "class": "srf-vertical-control",
        "title": "Platform Security Configuration Validated Against CC SRG Baseline Before ATO",
        "params": [
         {
          "id": "def-srf-l4-tevv-011-p1",
          "label": "cc_srg_baseline_validation_complete",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-ATO-cycle"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a completed CC SRG baseline validation report is on file in the ATO package, no CAT I findings remain open, and the ISSO has signed off before the ATO is granted."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-TEVV-011"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI Platform (Runtime and Infrastructure)"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Traceable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.4.1"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.4.2"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.12.1"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "tevv"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Block ATO. Remediate CAT I findings. ISSO re-validates and updates ATO package."
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "2004"
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l4-tevv-011_stmt",
          "name": "statement",
          "prose": "Before an authority to operate is granted, the platform engineering team and ISSO must verify that the cloud platform configuration conforms to the applicable CC SRG baseline for the target impact level. This includes STIG compliance for OS and middleware, network segmentation validation, and audit logging configuration. For IL6 systems, validation must be performed on the classified network by cleared personnel and documented in the classified ATO package. Findings at CAT I must be remediated before ATO is granted."
         },
         {
          "id": "def-srf-l4-tevv-011_obj",
          "name": "objective",
          "prose": "Maintain cc_srg_baseline_validation_complete == {{ insert: param, def-srf-l4-tevv-011-p1 }} over window per-ATO-cycle. Breach action: Block ATO. Remediate CAT I findings. ISSO re-validates and updates ATO package.."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Reliable principle"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "CM.L2-3.4.1 (baseline configurations and system inventories)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "CM.L2-3.4.2 (security configuration settings)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "CA.L2-3.12.1 (periodic security control assessments)"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.4.1"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 2.2"
         },
         {
          "href": "#c5d89a8d-2be1-526a-977f-3cc51013206f",
          "rel": "reference",
          "text": "Mission Owner SRG Section 2.3 (Security Assessment Information: required STIG and SRG assessments)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "A&A-02 (Independent Assessments)"
         }
        ]
       },
       {
        "id": "def-srf-l4-ovr-012",
        "class": "srf-vertical-control",
        "title": "Platform-Level Emergency Stop Capability Tested",
        "params": [
         {
          "id": "def-srf-l4-ovr-012-p1",
          "label": "emergency_stop_test_current",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a documented emergency stop test result is on file, conducted within the prior annual period (or after most recent major platform change, whichever is more recent), confirming the stop mechanism operates within the required response time."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-OVR-012"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI Platform (Runtime and Infrastructure)"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.1.1"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "human-oversight-remedy"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Notify program manager and CDAO liaison. Conduct emergency stop test within 30 days. Document result in program record."
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact"
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l4-ovr-012_stmt",
          "name": "statement",
          "prose": "Every AI platform hosting systems that directly inform or execute operational decisions must implement a platform-level emergency stop capability: a mechanism that allows an authorized operator to halt all AI-driven decision outputs within a defined response time. The mechanism must be tested annually and after any major platform change. Test results must be retained in the program record. For IL6 and Program-Embedded operating models, the response time requirement is more stringent and must be documented in the program's operational requirements."
         },
         {
          "id": "def-srf-l4-ovr-012_obj",
          "name": "objective",
          "prose": "Maintain emergency_stop_test_current == {{ insert: param, def-srf-l4-ovr-012-p1 }} over window annual. Breach action: Notify program manager and CDAO liaison. Conduct emergency stop test within 30 days. Document result in program record.."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Governable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Responsible principle"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.1.1"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 5.2"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-15 (Human supervision)"
         }
        ]
       }
      ]
     },
     {
      "id": "l4-manufacturing",
      "class": "srf-vertical",
      "title": "L4 — Manufacturing",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "manufacturing"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/manufacturing-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "mfg-srf-l4-des-001",
        "class": "srf-vertical-control",
        "title": "OT Network Zone Segmentation per IEC 62443",
        "params": [
         {
          "id": "mfg-srf-l4-des-001-p1",
          "label": "ot_zone_assignment_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "All OT-deployed AI systems have a documented zone assignment and conduit design reviewed by the OT security team."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-DES-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "system-integrator"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ot-only"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL1"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL3"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "assign-zone; document-conduit; obtain-ot-security-sign-off"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Zone-and-conduit design document with OT security review sign-off."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Annex I item TBD (protection against third-party attacks)",
          "class": "unresolved"
         },
         {
          "name": "mapping-iso-42001",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l4-des-001_stmt",
          "name": "statement",
          "prose": "AI systems deployed within OT/ICS environments must be assigned to the correct security zone in the plant's IEC 62443 zone-and-conduit model. Zone assignment must be documented in the conduit design, and the conduit between the AI system zone and adjacent zones must be documented with its security level, communication protocol, and data flow direction. Zone placement must be reviewed and approved by the OT security team before deployment."
         },
         {
          "id": "mfg-srf-l4-des-001_obj",
          "name": "objective",
          "prose": "Maintain ot_zone_assignment_documented == {{ insert: param, mfg-srf-l4-des-001-p1 }} over window per-deployment. Breach action: assign-zone; document-conduit; obtain-ot-security-sign-off."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (risk management, security measures)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-3-2 (part-level; zone and conduit design); ISA/IEC 62443-3-3 (part-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 1.5"
         }
        ]
       },
       {
        "id": "mfg-srf-l4-des-002",
        "class": "srf-vertical-control",
        "title": "OT-Edge AI Hardware Security Baseline",
        "params": [
         {
          "id": "mfg-srf-l4-des-002-p1",
          "label": "ot_hw_baseline_applied",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Hardware security baseline applied and configuration audit completed for all OT-edge AI hardware before deployment."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-DES-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ot-only"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL1"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL3"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "apply-baseline; audit-configuration; document-deviations-with-risk-acceptance"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Configuration audit report with compliance status."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Annex I item TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-iso-42001",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 4: Secure Configuration of Enterprise Assets and Software"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l4-des-002_stmt",
          "name": "statement",
          "prose": "Edge hardware hosting AI models within OT zones must comply with a documented hardware security baseline covering: firmware signing, secure boot, removal of unnecessary network services, physical port restrictions, and hardened credentials. The baseline must be applied before deployment and verified via a configuration audit. Deviations from the baseline must be documented with a risk acceptance by the OT security lead."
         },
         {
          "id": "mfg-srf-l4-des-002_obj",
          "name": "objective",
          "prose": "Maintain ot_hw_baseline_applied == {{ insert: param, mfg-srf-l4-des-002-p1 }} over window per-deployment. Breach action: apply-baseline; audit-configuration; document-deviations-with-risk-acceptance."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (risk management, cybersecurity measures)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-4-2 (part-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 1.5"
         }
        ]
       },
       {
        "id": "mfg-srf-l4-ops-003",
        "class": "srf-vertical-control",
        "title": "Air-Gap or Approved-Conduit Enforcement for Safety-Critical OT AI",
        "params": [
         {
          "id": "mfg-srf-l4-ops-003-p1",
          "label": "unapproved_ot_connection_count",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "0"
          ],
          "guidelines": [
           {
            "prose": "Count of network connections from safety-critical OT zones to external networks not traversing an approved conduit."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-OPS-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturer"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ot-only"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL3"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-connection; alert-ot-security-and-plant-safety-officer; investigate-source"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "network_activity (4001) or detection_finding (2004). Source: OT firewall or network monitoring platform."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dst_endpoint.name; src_endpoint.zone; severity_id"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Annex I item TBD (protection against third-party attacks for the operational lifetime)",
          "class": "unresolved"
         },
         {
          "name": "mapping-iso-42001",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l4-ops-003_stmt",
          "name": "statement",
          "prose": "AI systems deployed in safety-critical OT zones must be isolated from external networks via an air gap or a documented approved conduit. Unapproved network connections from safety-critical OT zones to external networks, the corporate IT network, or the internet are prohibited. Connections detected outside the approved conduit must trigger an immediate alert to the OT security team and plant safety officer."
         },
         {
          "id": "mfg-srf-l4-ops-003_obj",
          "name": "objective",
          "prose": "Maintain unapproved_ot_connection_count == {{ insert: param, mfg-srf-l4-ops-003-p1 }} over window continuous. Breach action: block-connection; alert-ot-security-and-plant-safety-officer; investigate-source."
         },
         {
          "id": "mfg-srf-l4-ops-003_gdn",
          "name": "guidance",
          "prose": "mapping-status-note: IEC 61508 clause reference requires verification against primary text. EU Machinery Regulation Annex I item number TBD."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (risk management, security measures for high-risk AI)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-3-3 (part-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 1.5"
         },
         {
          "href": "#baa4cf26-6159-56d6-a26d-4cb096e75b6c",
          "rel": "reference",
          "text": "IEC 61508 (edition-level)"
         }
        ]
       },
       {
        "id": "mfg-srf-l4-chg-004",
        "class": "srf-vertical-control",
        "title": "Patch and Update Change Management for OT AI",
        "params": [
         {
          "id": "mfg-srf-l4-chg-004-p1",
          "label": "ot_patch_change_record_completeness",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-change"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_CHANGE_RECORD_COMPLETENESS_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of OT AI patch events with a completed change record, safety impact assessment, and confirmed rollback test."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-CHG-004"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ot-only"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL1"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL3"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "change"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "complete-change-record; conduct-safety-impact-assessment; verify-rollback"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Change record with safety impact assessment and rollback test result."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Annex I item TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 7: Continuous Vulnerability Management"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l4-chg-004_stmt",
          "name": "statement",
          "prose": "Patches and software updates for AI systems in OT zones must follow the OT change management policy: each update requires a change record, a safety impact assessment, and version freeze coordination with production scheduling. Updates to AI systems that affect safety functions must include a safety re-validation gate before deployment. Rollback capability must be verified before any OT AI patch is applied."
         },
         {
          "id": "mfg-srf-l4-chg-004_obj",
          "name": "objective",
          "prose": "Maintain ot_patch_change_record_completeness >= {{ insert: param, mfg-srf-l4-chg-004-p1 }} over window per-change. Breach action: complete-change-record; conduct-safety-impact-assessment; verify-rollback."
         },
         {
          "id": "mfg-srf-l4-chg-004_gdn",
          "name": "guidance",
          "prose": "mapping-status-note: IEC 61508 clause reference requires verification against primary text."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 17 (quality management system, change control)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-2-1 (part-level)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 2.2"
         },
         {
          "href": "#baa4cf26-6159-56d6-a26d-4cb096e75b6c",
          "rel": "reference",
          "text": "IEC 61508 (edition-level)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-07 (Vulnerability Remediation Schedule)"
         }
        ]
       },
       {
        "id": "mfg-srf-l4-ops-005",
        "class": "srf-vertical-control",
        "title": "OT SIEM and Anomaly Detection Coverage",
        "params": [
         {
          "id": "mfg-srf-l4-ops-005-p1",
          "label": "ot_siem_coverage_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "quarterly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_OT_SIEM_COVERAGE_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of OT zones hosting AI systems covered by SIEM or OT anomaly detection."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-OPS-005"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturer"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ot-only"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL3"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "extend-siem-coverage; deploy-sensors; alert-ot-security"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "detection_finding (2004). Source: OT SIEM coverage report."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "observables; src_endpoint.zone"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iso-42001",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l4-ops-005_stmt",
          "name": "statement",
          "prose": "OT zones hosting AI systems must be covered by a security information and event management (SIEM) platform or OT-native anomaly detection tool. Coverage must include the AI host device, the conduit interfaces, and the associated PLCs or SCADA components in the same security zone. Detection coverage must be validated quarterly and reported to the OT security lead."
         },
         {
          "id": "mfg-srf-l4-ops-005_obj",
          "name": "objective",
          "prose": "Maintain ot_siem_coverage_pct >= {{ insert: param, mfg-srf-l4-ops-005-p1 }} over window quarterly. Breach action: extend-siem-coverage; deploy-sensors; alert-ot-security."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (risk management, monitoring measures)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-3-3 (part-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.8"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "LOG-03 (Security Monitoring and Alerting)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "LOG-13 (Failures and Anomalies Reporting)"
         }
        ]
       },
       {
        "id": "mfg-srf-l4-ops-006",
        "class": "srf-vertical-control",
        "title": "Remote Access Security for OT AI Maintenance",
        "params": [
         {
          "id": "mfg-srf-l4-ops-006-p1",
          "label": "unauthenticated_remote_session_count",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "0"
          ],
          "guidelines": [
           {
            "prose": "Count of remote access sessions to OT AI systems without MFA authentication."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-OPS-006"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ot-only"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL1"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL3"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "terminate-session; alert-ot-security; review-access-controls"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "authentication (3002) or access_activity (3003). Source: OT remote access gateway log."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "actor.user.name; mfa_factor; session_duration"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Annex I item TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-iso-42001",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l4-ops-006_stmt",
          "name": "statement",
          "prose": "Remote access sessions to OT AI systems for maintenance, diagnostics, or updates are prohibited unless authenticated using multi-factor authentication (MFA) and authorized via a formal change record or maintenance request. Zero unauthenticated remote sessions are permitted. All remote sessions must be logged with the operator identity, session duration, and actions performed. Session logs must be retained and reviewed monthly."
         },
         {
          "id": "mfg-srf-l4-ops-006_obj",
          "name": "objective",
          "prose": "Maintain unauthenticated_remote_session_count == {{ insert: param, mfg-srf-l4-ops-006-p1 }} over window continuous. Breach action: terminate-session; alert-ot-security; review-access-controls."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (risk management, access control measures)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-3-3 (part-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 1.5"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "IAM-14 (Strong Authentication)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "IAM-16 (Authorization Mechanisms)"
         }
        ]
       },
       {
        "id": "mfg-srf-l4-ops-007",
        "class": "srf-vertical-control",
        "title": "Encrypted Communication for AI Data in Transit",
        "params": [
         {
          "id": "mfg-srf-l4-ops-007-p1",
          "label": "unencrypted_ai_data_in_transit_count",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "<="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "monthly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_UNENCRYPTED_FLOW_TOLERANCE"
          ],
          "guidelines": [
           {
            "prose": "Count of confirmed AI data flows in transit without approved encryption or documented risk-accepted alternative."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-OPS-007"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL1"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "enable-encryption; document-alternative-if-ot-constrained; obtain-risk-acceptance"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "network_activity (4001). Source: network monitoring platform."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "tls.version; dst_endpoint.name; observables"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Annex I item TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-iso-42001",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 3: Data Protection"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l4-ops-007_stmt",
          "name": "statement",
          "prose": "AI data in transit between components must be encrypted using approved cryptographic protocols. For OT-edge deployments where latency constraints preclude standard TLS, the platform provider must document the alternative encryption or integrity protection mechanism and the associated risk acceptance approved by the OT security lead. IT-side AI communications must use TLS 1.2 or later."
         },
         {
          "id": "mfg-srf-l4-ops-007_obj",
          "name": "objective",
          "prose": "Maintain unencrypted_ai_data_in_transit_count <= {{ insert: param, mfg-srf-l4-ops-007-p1 }} over window monthly. Breach action: enable-encryption; document-alternative-if-ot-constrained; obtain-risk-acceptance."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (risk management, security measures)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-3-3 (part-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 1.5"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "CEK-03 (Data Encryption, including in-use)"
         }
        ]
       },
       {
        "id": "mfg-srf-l4-des-008",
        "class": "srf-vertical-control",
        "title": "AI Software Bill of Materials (SBOM/AIBOM) for OT AI Components",
        "params": [
         {
          "id": "mfg-srf-l4-des-008-p1",
          "label": "aibom_current",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-change"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "An AIBOM exists for every OT-deployed AI system and has been updated within 30 days of the last system change."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-DES-008"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Product-Embedded"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ot-only"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL1"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "create-aibom; update-after-changes; include-in-technical-file"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. AIBOM document with version and last-updated date."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 16: Application Software Security"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l4-des-008_stmt",
          "name": "statement",
          "prose": "For AI systems deployed in OT zones, the platform provider must maintain an AI Bill of Materials (AIBOM) covering all software components, ML frameworks, model artifacts, and third-party libraries. The AIBOM must be updated with each change to the AI system and used as the basis for vulnerability management. Component suppliers must be identified for every third-party entry. The AIBOM must be retained as part of the technical file."
         },
         {
          "id": "mfg-srf-l4-des-008_obj",
          "name": "objective",
          "prose": "Maintain aibom_current == {{ insert: param, mfg-srf-l4-des-008-p1 }} over window per-change. Breach action: create-aibom; update-after-changes; include-in-technical-file."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Annex IV (technical documentation, component inventory element)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-2-1 (part-level)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 5.2"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-14 (Supply Chain Governance Review)"
         }
        ]
       },
       {
        "id": "mfg-srf-l4-ops-009",
        "class": "srf-vertical-control",
        "title": "Availability SLA for AI in Critical Production Processes",
        "params": [
         {
          "id": "mfg-srf-l4-ops-009-p1",
          "label": "ai_availability_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "monthly"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_AI_AVAILABILITY_PCT"
          ],
          "guidelines": [
           {
            "prose": "Measured availability of critical-path AI systems as a percentage of total required uptime in the measurement window."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-OPS-009"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L4"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Platform and Infrastructure"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-platform-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-platform-provider; activate-degraded-mode-procedure; investigate-root-cause"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "api_activity (6003) or audit_activity (3002). Source: platform monitoring dashboard uptime report."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "observables.availability_pct; time"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-62443",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l4-ops-009_stmt",
          "name": "statement",
          "prose": "For AI systems that are in the critical path of production (AI-driven quality gates, real-time process control, predictive maintenance with mandatory action) the platform provider must define and monitor an availability SLA. The SLA must specify the target availability percentage, the measurement window, and the degraded-mode behavior when availability falls below threshold. SLA breaches must trigger a defined escalation path."
         },
         {
          "id": "mfg-srf-l4-ops-009_obj",
          "name": "objective",
          "prose": "Maintain ai_availability_pct >= {{ insert: param, mfg-srf-l4-ops-009-p1 }} over window monthly. Breach action: escalate-to-platform-provider; activate-degraded-mode-procedure; investigate-root-cause."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (risk management, continuity measures)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 4.1"
         }
        ]
       }
      ]
     }
    ]
   },
   {
    "id": "l5",
    "class": "srf-layer",
    "title": "L5: AI Model Provider",
    "groups": [
     {
      "id": "l5-finance",
      "class": "srf-vertical",
      "title": "L5 — Finance",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "finance"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/finance-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "fin-srf-l5-dev-001",
        "class": "srf-vertical-control",
        "title": "Model Card Completeness and Security Disclosure",
        "params": [
         {
          "id": "fin-srf-l5-dev-001-p1",
          "label": "model_card_completeness",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "at-model-release"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: model card exists, covers all required fields, is versioned, and is publicly accessible at the time the model is offered to institution consumers."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-DEV-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model Governance"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-model-from-institution-deployment-until-model-card-complete"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: document artifact. Completeness can be assessed programmatically if the model card is machine-readable (e.g., Hugging Face model card schema) by checking required field presence."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l5-dev-001_stmt",
          "name": "statement",
          "prose": "Before a foundation model is made available to institution consumers (via API, download, or marketplace), the model provider must publish a model card that meets the minimum completeness standard for financial services deployment. Required fields: intended use cases and explicitly out-of-scope use cases, known failure modes and documented evaluation results on safety benchmarks, training data description at the level of detail needed for MRM provenance review (SRF-L2-DEV-001 alignment), known limitations relevant to regulated use cases (credit, insurance, financial advice), security evaluation summary covering at minimum prompt injection resistance, jailbreak resistance, and data exfiltration risk, and the vulnerability disclosure process and contact (SRF-L5-MON-002 alignment). Model cards must be versioned and updated with each model release."
         },
         {
          "id": "fin-srf-l5-dev-001_obj",
          "name": "objective",
          "prose": "Maintain model_card_completeness == {{ insert: param, fin-srf-l5-dev-001-p1 }} over window at-model-release. Breach action: block-model-from-institution-deployment-until-model-card-complete."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-OP-018 (Model Overreach / Expanded Use)"
         },
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-OP-017 (Lack of Explainability)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-03 (Model Documentation)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-04 (Model Documentation Requirements)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section VII (Vendor and Other Third-Party Products)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section VI (Documentation)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 11 (Technical documentation)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 53 (General-purpose AI model provider obligations)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 2.2 (information about the AI system knowledge limits is documented); MEASURE 2.8 (transparency and accountability are examined)"
         }
        ]
       },
       {
        "id": "fin-srf-l5-dev-002",
        "class": "srf-vertical-control",
        "title": "Model Artifact Signing and Supply-Chain Provenance",
        "params": [
         {
          "id": "fin-srf-l5-dev-002-p1",
          "label": "model_artifact_signed_and_sbom_published",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "at-model-release"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: all model artifacts for the release are cryptographically signed with a key in the published trust store, and an SBOM or equivalent provenance record is published alongside the model."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-DEV-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model Distribution"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-model-from-institution-deployment-until-signed-artifacts-available"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: signing artifact. Verification event occurs at load time (see SRF-L5-MON-001)."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 16: Application Software Security"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l5-dev-002_stmt",
          "name": "statement",
          "prose": "The model provider must cryptographically sign all model artifacts (weights, tokenizer, configuration files) before distribution. The signing key must be managed under the provider's documented key management policy, with the public key published in a verifiable trust store. The model provider must also publish a Software Bill of Materials (SBOM) or equivalent supply-chain provenance record for each model release, covering training framework versions, key dependencies, and any third-party components incorporated into the model architecture. This provenance record enables the ai-platform-provider to verify model integrity at load (SRF-L5-MON-001) and supports the institution's third-party risk management obligations under SR 26-2's inherited vendor management principles."
         },
         {
          "id": "fin-srf-l5-dev-002_obj",
          "name": "objective",
          "prose": "Maintain model_artifact_signed_and_sbom_published == {{ insert: param, fin-srf-l5-dev-002-p1 }} over window at-model-release. Breach action: block-model-from-institution-deployment-until-signed-artifacts-available."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-SEC-008 (Tampering With the Foundational Model)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-09 (Model Signing/Ownership Verification)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-01 (Training Pipeline Security)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section VII (Vendor and Other Third-Party Products)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 17 (Quality management system)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (Accuracy, robustness and cybersecurity)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 3.1 (AI risks from third-party resources are monitored); MEASURE 2.7 (security and resilience are evaluated)"
         }
        ]
       },
       {
        "id": "fin-srf-l5-dev-003",
        "class": "srf-vertical-control",
        "title": "Pre-Release Security Evaluation Baseline",
        "params": [
         {
          "id": "fin-srf-l5-dev-003-p1",
          "label": "security_evaluation_published",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "at-model-release"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: security evaluation report covering all required categories is published with the model release, with quantitative results and disclosed methodology."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-DEV-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Foundation Models"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-model-from-institution-deployment-until-evaluation-published"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: evaluation report artifact."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l5-dev-003_stmt",
          "name": "statement",
          "prose": "Before a foundation model is made available to institution consumers, the model provider must conduct and publish a security evaluation covering the model's behavior on categories of risk relevant to financial services deployment. Required evaluation categories: prompt injection resistance (resistance to direct and indirect injection attacks), jailbreak resistance across documented bypass techniques, tendency to produce ungrounded financial claims (hallucination in financial contexts), data exfiltration risk (tendency to reproduce training data verbatim), and behavior on agentic tool-use scenarios including tool-call refusal when out of scope. Evaluation methodology and benchmark datasets used must be disclosed. Results must be quantitative where possible and updated with each major model version."
         },
         {
          "id": "fin-srf-l5-dev-003_obj",
          "name": "objective",
          "prose": "Maintain security_evaluation_published == {{ insert: param, fin-srf-l5-dev-003-p1 }} over window at-model-release. Breach action: block-model-from-institution-deployment-until-evaluation-published."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-PREV-005 (System Acceptance Testing)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-06 (Adversarial Attack Analysis)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-07 (Model Hardening)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section IV (Model Development)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section VII (Vendor and Other Third-Party Products)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (Risk management system)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (Accuracy, robustness and cybersecurity)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM01: Prompt Injection"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM02: Sensitive Information Disclosure"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM09: Misinformation"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.7 (security and resilience are evaluated); MEASURE 2.6 (safety risks are evaluated)"
         }
        ]
       },
       {
        "id": "fin-srf-l5-val-001",
        "class": "srf-vertical-control",
        "title": "Independent Evaluation of Model Security Properties",
        "params": [
         {
          "id": "fin-srf-l5-val-001-p1",
          "label": "independent_model_evaluation_completed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "pre-production-approval"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: independent evaluation completed by a party with no development accountability for the model, covering required scope, with findings documented and incorporated into the validation report."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-VAL-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Foundation Models"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "co-accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-system-governance"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "independent-validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-tier-1-and-tier-2-model-production-approval"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: validation report artifact."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l5-val-001_stmt",
          "name": "statement",
          "prose": "Before institution deployment of a Tier-1 or Tier-2 model, the institution's independent validation function (or a commissioned third party) must conduct its own security evaluation of the foundation model, independent of the model provider's published evaluation (SRF-L5-DEV-003). This is required because the provider's evaluation is self-reported and may not cover the institution's specific deployment context, use case constraints, or threat model. The independent evaluation must cover: reproduction of key benchmark results from the provider's evaluation to validate claims, institution-specific red-teaming for the intended use case, and assessment of whether the model's known failure modes are adequately addressed by the application and platform controls (SRF-L3, SRF-L4). Findings must be incorporated into the model's validation report and linked to the model card."
         },
         {
          "id": "fin-srf-l5-val-001_obj",
          "name": "objective",
          "prose": "Maintain independent_model_evaluation_completed == {{ insert: param, fin-srf-l5-val-001-p1 }} over window pre-production-approval. Breach action: block-tier-1-and-tier-2-model-production-approval."
         },
         {
          "id": "fin-srf-l5-val-001_gdn",
          "name": "guidance",
          "prose": "accountability-split: {\"model-provider\": \"Accountable for providing access, documentation, model artifacts, and cooperation sufficient to enable independent evaluation. A provider that withholds artifacts necessary for evaluation is in breach of this control.\", \"ai-system-governance\": \"Accountable for commissioning the evaluation, ensuring it covers the required scope, and incorporating findings into the institution's validation report. Cannot delegate this accountability to the model-provider.\", \"examiner_routing\": \"Findings about evaluation completeness or scope route to ai-system-governance. Findings about provider cooperation or artifact availability route to model-provider.\"}"
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-PREV-005 (System Acceptance Testing)"
         },
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-DET-015 (Using Large Language Models for Automated Evaluation)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-06 (Adversarial Attack Analysis)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "A&A-02 (Independent Assessments)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section V (Model Validation)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section VII (Vendor and Other Third-Party Products)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (Risk management system)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 1.3 (independent assessors are involved in TEVV); MEASURE 2.7 (security and resilience are evaluated)"
         }
        ]
       },
       {
        "id": "fin-srf-l5-mon-001",
        "class": "srf-vertical-control",
        "title": "Model Signature Verification at Load",
        "params": [
         {
          "id": "fin-srf-l5-mon-001-p1",
          "label": "model_signature_verification_success_rate",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-load-event"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "1.0 (100% verification success)"
          ],
          "guidelines": [
           {
            "prose": "Percentage of model load events where signature verification succeeds. Any verification failure for a currently deployed model version is a Severity-1 event."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-MON-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model Distribution"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "cross-layer-controls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L4-DEV-001"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "reject-model-load; alert-ai-platform-provider-and-model-provider; initiate-supply-chain-incident-response; suspend-affected-model-version"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "api_activity"
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "api_activity events at the model loading endpoint, enriched with artifact hash and signature verification result (pass/fail). A failure status on a load event triggers the breach action."
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l5-mon-001_stmt",
          "name": "statement",
          "prose": "Every time a foundation model artifact is loaded into an inference environment, the ai-platform-provider must verify the cryptographic signature against the model provider's published trust store (SRF-L5-DEV-002). A load event that cannot be verified must be rejected; the model must not serve requests from an unsigned or unverifiable artifact. Signature verification must be logged with the model version, artifact hash, and verification result. This control detects supply-chain tampering: an attacker substituting a malicious model artifact for a legitimate one. Accountability for the signing infrastructure sits with the model-provider (L5); accountability for executing verification at load sits with the ai-platform-provider (L4). Both controls are required; neither substitutes for the other."
         },
         {
          "id": "fin-srf-l5-mon-001_obj",
          "name": "objective",
          "prose": "Maintain model_signature_verification_success_rate == {{ insert: param, fin-srf-l5-mon-001-p1 }} over window per-load-event. Breach action: reject-model-load; alert-ai-platform-provider-and-model-provider; initiate-supply-chain-incident-response; suspend-affected-model-version."
         },
         {
          "id": "fin-srf-l5-mon-001_gdn",
          "name": "guidance",
          "prose": "cross-layer-note: Signing infrastructure accountability: model-provider (L5). Verification execution accountability: ai-platform-provider (L4). A verification failure finding is a joint incident: the model-provider must investigate signing infrastructure integrity; the ai-platform-provider must suspend the affected model version. Neither control substitutes for the other. Examiner findings route to the party accountable for the failed component. implementing-persona-note: Verification at load is executed by ai-platform-provider (L4). Model-provider is accountable for maintaining the signing infrastructure and published trust store that makes verification possible. Cross-layer dependency: this control and SRF-L4 platform controls are jointly required."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-SEC-008 (Tampering With the Foundational Model)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-09 (Model Signing/Ownership Verification)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-08 (Model Integrity Checks)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section VII (Vendor and Other Third-Party Products)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (Accuracy, robustness and cybersecurity)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 3.1 (AI risks from third-party resources are monitored); MEASURE 2.7 (security and resilience are evaluated)"
         }
        ]
       },
       {
        "id": "fin-srf-l5-mon-002",
        "class": "srf-vertical-control",
        "title": "Vulnerability Disclosure SLA Adherence",
        "params": [
         {
          "id": "fin-srf-l5-mon-002-p1",
          "label": "vulnerability_disclosure_sla_adherence",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous; checked on disclosure and at SLA boundary"
           }
          ],
          "values": [
           "true per open vulnerability within SLA window"
          ],
          "guidelines": [
           {
            "prose": "Binary per open vulnerability: provider has acknowledged and provided remediation or mitigation within the SLA window for the vulnerability's severity tier."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-MON-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model Governance"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-critical-sla-breach-to-l1-governance; initiate-model-impairment-review; engage-provider-via-vendor-management-process"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: disclosure feed artifact. If provider publishes machine-readable advisories (e.g., OSV format), these can be ingested and tracked programmatically. Candidate: security_finding OCSF class events generated from advisory ingestion."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-finos-aigf",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 7: Continuous Vulnerability Management"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l5-mon-002_stmt",
          "name": "statement",
          "prose": "The model provider must operate a public vulnerability disclosure program for foundation models used by financial institutions, with documented SLAs for acknowledgment and remediation. The institution must monitor the provider's disclosure feed and track open vulnerabilities against the SLA. Required SLA tiers: Critical vulnerabilities (active exploitation or CVSS >= 9.0 equivalent for AI risk): acknowledgment within 24 hours, remediation or documented mitigation within 7 days; High vulnerabilities: acknowledgment within 72 hours, remediation within 30 days. Institutions using a model with an open Critical vulnerability beyond SLA must treat the model as impaired and escalate to L1 governance. This control monitors both provider SLA adherence and the institution's response to disclosed vulnerabilities."
         },
         {
          "id": "fin-srf-l5-mon-002_obj",
          "name": "objective",
          "prose": "Maintain vulnerability_disclosure_sla_adherence == {{ insert: param, fin-srf-l5-mon-002-p1 }} over window continuous; checked on disclosure and at SLA boundary. Breach action: escalate-critical-sla-breach-to-l1-governance; initiate-model-impairment-review; engage-provider-via-vendor-management-process."
         }
        ],
        "links": [
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-09 (Vulnerability Management Reporting)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-07 (Vulnerability Remediation Schedule)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section VII (Vendor and Other Third-Party Products)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 73 (Reporting of serious incidents)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 72 (Post-market monitoring)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 4.3 (incidents and errors are communicated to relevant AI actors); MANAGE 3.1 (third-party resource risks are monitored)"
         }
        ]
       },
       {
        "id": "fin-srf-l5-ech-001",
        "class": "srf-vertical-control",
        "title": "Effective Challenge of Model Governance Standards",
        "params": [
         {
          "id": "fin-srf-l5-ech-001-p1",
          "label": "model_governance_challenge_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "12mo"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: annual challenge of L5 model governance standards completed, covering all required assessment areas, with findings reported to MRM head and factored into third-party model risk ratings."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-ECH-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model Governance"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IaaS"
         },
         {
          "name": "mrm-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "effective-challenge"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-cro; flag-in-annual-mrm-report; review-institution-model-provider-relationships"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: governance artifact."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         }
        ],
        "parts": [
         {
          "id": "fin-srf-l5-ech-001_stmt",
          "name": "statement",
          "prose": "The institution's independent validation or second-line risk function must annually challenge whether the model governance requirements placed on foundation model providers remain appropriate and are being met. Challenge must assess: whether model cards for deployed models remain current and complete relative to the standard in SRF-L5-DEV-001, whether any model provider has missed vulnerability disclosure SLAs in the prior period and whether the institution's response was adequate, whether the model provider's published security evaluation methodology remains credible relative to the current threat environment, whether new model versions deployed in the prior year received independent evaluation per SRF-L5-VAL-001, and whether model signing and SBOM practices have been maintained across all model versions in use. Findings must be reported to the MRM head and factored into the institution's third-party model risk ratings."
         },
         {
          "id": "fin-srf-l5-ech-001_obj",
          "name": "objective",
          "prose": "Maintain model_governance_challenge_documented == {{ insert: param, fin-srf-l5-ech-001-p1 }} over window 12mo. Breach action: escalate-to-cro; flag-in-annual-mrm-report; review-institution-model-provider-relationships."
         },
         {
          "id": "fin-srf-l5-ech-001_gdn",
          "name": "guidance",
          "prose": "accountable-persona-note: Challenge is conducted by the institution's ai-system-governance (L1) on behalf of MRM. Model-provider is the subject of the challenge. Accountability for commissioning and completing the challenge sits with the institution."
         }
        ],
        "links": [
         {
          "href": "#42d3a8ce-e217-5de0-a841-81b227deb27b",
          "rel": "reference",
          "text": "AIR-PREV-007 (Legal and Contractual Frameworks for AI Systems)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-14 (Supply Chain Governance Review)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-11 (Supply Chain Agreement Review)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section VII (Vendor and Other Third-Party Products)"
         },
         {
          "href": "#3f564f95-c419-5856-82e2-62e4a8215e87",
          "rel": "reference",
          "text": "Section III (effective challenge)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 72 (Post-market monitoring)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 6.1 (policies address AI risks associated with third-party entities); MEASURE 2.13 (effectiveness of measurement is evaluated)"
         }
        ]
       }
      ]
     },
     {
      "id": "l5-public-sector",
      "class": "srf-vertical",
      "title": "L5 — Public Sector",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "public-sector"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/public-sector-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "pubsec-srf-l5-acq-001",
        "class": "srf-vertical-control",
        "title": "Model Documentation Completeness per M-25-22 Transparency Terms",
        "params": [
         {
          "id": "pubsec-srf-l5-acq-001-p1",
          "label": "model_documentation_complete",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-contract"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: vendor-supplied model documentation addresses all M-25-22 required transparency fields and is on file before contract execution or renewal."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-ACQ-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model and Supplier"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "csp"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition-integration"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-contracting-officer; hold-contract-execution; notify-CAIO"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-21",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-fedramp-20x-ksi",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l5-acq-001_stmt",
          "name": "statement",
          "prose": "AI vendors must provide model documentation covering training data sources, known limitations, evaluation results, and applicable use-case constraints, per M-25-22 transparency requirements. The agency must verify documentation completeness at contract execution and before renewing or expanding use."
         },
         {
          "id": "pubsec-srf-l5-acq-001_obj",
          "name": "objective",
          "prose": "Maintain model_documentation_complete == {{ insert: param, pubsec-srf-l5-acq-001-p1 }} over window per-contract. Breach action: escalate-to-contracting-officer; hold-contract-execution; notify-CAIO."
         }
        ],
        "links": [
         {
          "href": "#ae7bd07d-92c3-5ea1-915d-6542ebb67973",
          "rel": "reference",
          "text": "Section 3(d)(v) (Documentation, Transparency, and Accessibility)"
         },
         {
          "href": "#ae7bd07d-92c3-5ea1-915d-6542ebb67973",
          "rel": "reference",
          "text": "Section 4(c)(i) (AI Use Transparency Requirements)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 5.2 (third-party AI provider transparency); MAP 4.1 (risks of receiving AI from third parties are enumerated)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-03 (Model Documentation)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-04 (Model Documentation Requirements)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l5-mon-002",
        "class": "srf-vertical-control",
        "title": "Vendor Performance and Drift Disclosure SLA",
        "params": [
         {
          "id": "pubsec-srf-l5-mon-002-p1",
          "label": "vendor_drift_disclosure_within_sla",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "contract-review-cycle"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: no outstanding overdue model performance or drift disclosures from the vendor per contract SLA terms."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-MON-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model and Supplier"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "csp"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "notify-contracting-officer; escalate-to-CAIO; trigger-re-validation; document-SLA-breach"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact. Vendor disclosure events may be logged via api_activity (6003)."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-fedramp-20x-ksi",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l5-mon-002_stmt",
          "name": "statement",
          "prose": "AI vendors must disclose material changes to model performance or behavior (drift, retraining events, capability changes) within the timeline specified in the contract, per M-25-22 transparency requirements. The agency must verify SLA compliance at each contract review period and escalate gaps to the contracting officer."
         },
         {
          "id": "pubsec-srf-l5-mon-002_obj",
          "name": "objective",
          "prose": "Maintain vendor_drift_disclosure_within_sla == {{ insert: param, pubsec-srf-l5-mon-002-p1 }} over window contract-review-cycle. Breach action: notify-contracting-officer; escalate-to-CAIO; trigger-re-validation; document-SLA-breach."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(b)(iii) (Conduct Ongoing Monitoring for Performance and Potential Adverse Impacts)"
         },
         {
          "href": "#ae7bd07d-92c3-5ea1-915d-6542ebb67973",
          "rel": "reference",
          "text": "Section 4(d)(iii)(E) (Ongoing Testing and Monitoring)"
         },
         {
          "href": "#ae7bd07d-92c3-5ea1-915d-6542ebb67973",
          "rel": "reference",
          "text": "Section 4(d)(iii)(F) (Vendor Performance Requirements)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 2.4 (risk treatments tracked); MAP 4.1"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-10 (Model Continuous Monitoring)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-11 (Supply Chain Agreement Review)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l5-acq-003",
        "class": "srf-vertical-control",
        "title": "Model Artifact Signing and Provenance Verification",
        "params": [
         {
          "id": "pubsec-srf-l5-acq-003-p1",
          "label": "model_artifact_signature_verified",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: all model artifacts deployed to production carry valid vendor signatures verified before deployment; no unsigned artifact deployed."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-ACQ-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model and Supplier"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition-integration"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-deployment; notify-ISSO; escalate-to-supply-chain-risk-manager"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "api_activity (6003) for artifact pull and signature verification events."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "api_activity.http_request; api_activity.status_code"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-21",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l5-acq-003_stmt",
          "name": "statement",
          "prose": "AI model artifacts (model weights, containerized inference images, fine-tuned adapters) used in agency deployments must be cryptographically signed by the vendor and the signatures verified before deployment. Unsigned or unverifiable artifacts must not be deployed to production."
         },
         {
          "id": "pubsec-srf-l5-acq-003_obj",
          "name": "objective",
          "prose": "Maintain model_artifact_signature_verified == {{ insert: param, pubsec-srf-l5-acq-003-p1 }} over window per-deployment. Breach action: block-deployment; notify-ISSO; escalate-to-supply-chain-risk-manager."
         }
        ],
        "links": [
         {
          "href": "#aec75536-9650-52f9-bd36-918743c7b0a5",
          "rel": "reference",
          "text": "KSI-SVC-VRI (cryptographic validation of resource integrity)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 5.1 (supply chain risk management includes artifact integrity); MAP 4.1"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM04: Data and Model Poisoning"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-09 (Model Signing/Ownership Verification)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-08 (Model Integrity Checks)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l5-mon-004",
        "class": "srf-vertical-control",
        "title": "Vendor Vulnerability Disclosure SLA",
        "params": [
         {
          "id": "pubsec-srf-l5-mon-004-p1",
          "label": "vendor_vuln_disclosure_within_sla",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: no outstanding overdue vendor vulnerability disclosures per contract SLA terms."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-MON-004"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model and Supplier"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "csp"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "notify-contracting-officer; escalate-to-ISSO; initiate-interim-mitigation; document-SLA-breach"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "detection_finding (2004) for vulnerability disclosures."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finding.severity_id; finding.remediation"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-21",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-m-25-22",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l5-mon-004_stmt",
          "name": "statement",
          "prose": "AI vendors must disclose security vulnerabilities in their models or platforms within the timeline required by the contract and M-25-22 terms. The agency must track open disclosures and verify remediation or mitigation within SLA. Outstanding overdue disclosures must be escalated to the contracting officer and ISSO."
         },
         {
          "id": "pubsec-srf-l5-mon-004_obj",
          "name": "objective",
          "prose": "Maintain vendor_vuln_disclosure_within_sla == {{ insert: param, pubsec-srf-l5-mon-004-p1 }} over window continuous. Breach action: notify-contracting-officer; escalate-to-ISSO; initiate-interim-mitigation; document-SLA-breach."
         }
        ],
        "links": [
         {
          "href": "#aec75536-9650-52f9-bd36-918743c7b0a5",
          "rel": "reference",
          "text": "KSI-PIY-RVD (vulnerability disclosure program effectiveness persistently reviewed)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 2.4 (risk treatments tracked); GOVERN 5.2"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM04: Data and Model Poisoning"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-07 (Vulnerability Remediation Schedule)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-09 (Vulnerability Management Reporting)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l5-acq-005",
        "class": "srf-vertical-control",
        "title": "Model Portability Evidence for Vendor Lock-In Avoidance",
        "params": [
         {
          "id": "pubsec-srf-l5-acq-005-p1",
          "label": "model_portability_evidence_on_file",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-contract"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: portability evidence (data export documentation, migration path description) is on file before contract execution."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-ACQ-005"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model and Supplier"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "csp"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition-integration"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-contracting-officer; hold-contract-execution; notify-CAIO"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-21",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-fedramp-20x-ksi",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l5-acq-005_stmt",
          "name": "statement",
          "prose": "Per M-25-22 vendor lock-in avoidance requirements, the agency must obtain evidence before contract execution that the AI service supports data export in standard formats and that the agency can migrate to an alternative provider without losing access to its data, fine-tuning assets, or interaction history."
         },
         {
          "id": "pubsec-srf-l5-acq-005_obj",
          "name": "objective",
          "prose": "Maintain model_portability_evidence_on_file == {{ insert: param, pubsec-srf-l5-acq-005-p1 }} over window per-contract. Breach action: escalate-to-contracting-officer; hold-contract-execution; notify-CAIO."
         }
        ],
        "links": [
         {
          "href": "#ae7bd07d-92c3-5ea1-915d-6542ebb67973",
          "rel": "reference",
          "text": "Section 4(c)(ii) (Protections Against Vendor Lock-In)"
         },
         {
          "href": "#ae7bd07d-92c3-5ea1-915d-6542ebb67973",
          "rel": "reference",
          "text": "Section 4(d)(iii)(C) (Vendor Lock-In Protections)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 5.1 (supply chain risk includes lock-in); MAP 4.1"
         }
        ]
       },
       {
        "id": "pubsec-srf-l5-mon-006",
        "class": "srf-vertical-control",
        "title": "AI Model Version Change Notification and Re-Validation Trigger",
        "params": [
         {
          "id": "pubsec-srf-l5-mon-006-p1",
          "label": "model_version_change_revalidation_completed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-model-version-change"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: every vendor model version change on a high-impact use case triggers a re-validation assessment that is completed before the new version enters production."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-MON-006"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model and Supplier"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "csp"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-new-model-version-in-production; notify-CAIO; escalate-to-Authorizing-Official; initiate-expedited-re-validation"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact for re-validation report; api_activity (6003) for model version change events."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l5-mon-006_stmt",
          "name": "statement",
          "prose": "When a vendor updates or replaces an AI model version used in a high-impact use case, the agency must be notified in advance per the contract SLA, conduct a re-validation assessment, and confirm that the new model version meets all pre-deployment testing requirements before continuing production use."
         },
         {
          "id": "pubsec-srf-l5-mon-006_obj",
          "name": "objective",
          "prose": "Maintain model_version_change_revalidation_completed == {{ insert: param, pubsec-srf-l5-mon-006-p1 }} over window per-model-version-change. Breach action: block-new-model-version-in-production; notify-CAIO; escalate-to-Authorizing-Official; initiate-expedited-re-validation."
         }
        ],
        "links": [
         {
          "href": "#84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
          "rel": "reference",
          "text": "Section 4(b)(iii) (Conduct Ongoing Monitoring for Performance and Potential Adverse Impacts)"
         },
         {
          "href": "#ae7bd07d-92c3-5ea1-915d-6542ebb67973",
          "rel": "reference",
          "text": "Section 4(d)(iii)(G) (New Feature Notification)"
         },
         {
          "href": "#aec75536-9650-52f9-bd36-918743c7b0a5",
          "rel": "reference",
          "text": "KSI-CMT-LMC (modifications logged and monitored)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 2.4 (post-deployment risk tracking); MEASURE 2.6"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-10 (Model Continuous Monitoring)"
         }
        ]
       },
       {
        "id": "pubsec-srf-l5-mon-007",
        "class": "srf-vertical-control",
        "title": "Third-Party AI Supply Chain Risk Assessment",
        "params": [
         {
          "id": "pubsec-srf-l5-mon-007-p1",
          "label": "supply_chain_risk_assessment_current",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual-review"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a completed supply chain risk assessment exists for every AI vendor, was reviewed by CAIO and Authorizing Official, and was refreshed within the prior annual cycle."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-MON-007"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "public-sector"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model and Supplier"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Shared-Service"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "agency"
         },
         {
          "name": "public-sector-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-contracting-officer; flag-for-CAIO-review; delay-contract-renewal-pending-assessment"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-m-25-21",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cosais",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD: COSAiS overlays are pre-draft as of January 2026 (annotated outline of the Predictive AI overlay only; csrc.nist.gov/projects/cosais). Bind on initial public drafts. Do not substitute invented IDs.",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 15: Service Provider Management"
         }
        ],
        "parts": [
         {
          "id": "pubsec-srf-l5-mon-007_stmt",
          "name": "statement",
          "prose": "The agency must conduct a supply chain risk assessment for each AI vendor covering financial stability, national security considerations, sub-processor dependencies, and open-source component provenance. The assessment must be reviewed by the CAIO and Authorizing Official before contract execution and refreshed annually."
         },
         {
          "id": "pubsec-srf-l5-mon-007_obj",
          "name": "objective",
          "prose": "Maintain supply_chain_risk_assessment_current == {{ insert: param, pubsec-srf-l5-mon-007-p1 }} over window annual-review. Breach action: escalate-to-contracting-officer; flag-for-CAIO-review; delay-contract-renewal-pending-assessment."
         }
        ],
        "links": [
         {
          "href": "#ae7bd07d-92c3-5ea1-915d-6542ebb67973",
          "rel": "reference",
          "text": "Section 4(d)(ii) (Opportunity and Risk Re-Evaluation)"
         },
         {
          "href": "#aec75536-9650-52f9-bd36-918743c7b0a5",
          "rel": "reference",
          "text": "KSI-SCR-MIT (persistent supply chain risk identification and mitigation)"
         },
         {
          "href": "#aec75536-9650-52f9-bd36-918743c7b0a5",
          "rel": "reference",
          "text": "KSI-SCR-MON (automated monitoring of third-party software for upstream vulnerabilities)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 5.1 (supply chain risk management); MAP 4.1 (risks from third-party AI enumerated)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-14 (Supply Chain Governance Review)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-11 (Supply Chain Agreement Review)"
         }
        ]
       }
      ]
     },
     {
      "id": "l5-healthcare",
      "class": "srf-vertical",
      "title": "L5 — Healthcare",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "healthcare"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/healthcare-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "hc-srf-l5-dev-001",
        "class": "srf-vertical-control",
        "title": "Model Card and SaMD Definition Statement",
        "params": [
         {
          "id": "hc-srf-l5-dev-001-p1",
          "label": "model_card_complete",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "at-model-development"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: model card exists with all required fields, linked to the deployed model version, and available for regulatory inspection."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-DEV-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-clinical-deployment"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Device"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "deviceName, version, property (intended-use, training-data-summary, performance-characteristics), note"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l5-dev-001_stmt",
          "name": "statement",
          "prose": "Every clinical AI model must have a model card documenting: intended use and patient population, contraindications, training data summary, performance characteristics (sensitivity, specificity, AUC by subgroup), known limitations, and update history. The model card must map to the IEC 62304 §5.2 software requirements specification and be included in the FDA marketing submission."
         },
         {
          "id": "hc-srf-l5-dev-001_obj",
          "name": "objective",
          "prose": "Maintain model_card_complete == {{ insert: param, hc-srf-l5-dev-001-p1 }} over window at-model-development. Breach action: block-clinical-deployment."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 2.1: Device description and labeling"
         },
         {
          "href": "#5c236a56-0fd8-52fc-880b-5e213d233a3f",
          "rel": "reference",
          "text": "Principle 4: Transparent documentation"
         },
         {
          "href": "#8e4fc90b-6135-5c7a-81da-30efe01e36ad",
          "rel": "reference",
          "text": "§170.315(b)(11)(i): DSI source attributes disclosure"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 11 (Technical documentation)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 13 (Transparency)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§5.2: Software requirements specification"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§4.2: Intended use description"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 2.2 (information about the AI system knowledge limits is documented); MEASURE 2.8 (transparency and accountability are examined and documented)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM09: Misinformation (documented limitations counter unwarranted reliance)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-03 (Model Documentation)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-04 (Model Documentation Requirements)"
         }
        ]
       },
       {
        "id": "hc-srf-l5-dev-002",
        "class": "srf-vertical-control",
        "title": "Software of Unknown Provenance (SOUP) Documentation",
        "params": [
         {
          "id": "hc-srf-l5-dev-002-p1",
          "label": "soup_documentation_complete",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "at-model-development"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: all third-party AI components documented as SOUP with version, license, known vulnerabilities, and validation evidence."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-DEV-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-clinical-deployment"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Device"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "parent (reference to host system), deviceName (component), version, property (license, cve-status)"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-fda-pccp",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-onc-hti1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l5-dev-002_stmt",
          "name": "statement",
          "prose": "All third-party AI components used in clinical AI systems, including pre-trained foundation models, inference frameworks, and data preprocessing libraries, must be documented as Software of Unknown Provenance per IEC 62304 §8. SOUP documentation must include version, license, known vulnerabilities, and validation evidence."
         },
         {
          "id": "hc-srf-l5-dev-002_obj",
          "name": "objective",
          "prose": "Maintain soup_documentation_complete == {{ insert: param, hc-srf-l5-dev-002-p1 }} over window at-model-development. Breach action: block-clinical-deployment."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 2.2: Algorithm description (component provenance)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 11 (Technical documentation)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§8: Software configuration management; SOUP documentation"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§4.2: Hazard identification (from third-party components)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 4.1 (legal and technology risks of third-party components are mapped); MANAGE 3.1 (AI risks from third-party resources are monitored)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM03: Supply Chain"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-11 (Supply Chain Agreement Review)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-14 (Supply Chain Governance Review)"
         }
        ]
       },
       {
        "id": "hc-srf-l5-dev-003",
        "class": "srf-vertical-control",
        "title": "Pre-Deployment Safety Evaluation (ISO 14971)",
        "params": [
         {
          "id": "hc-srf-l5-dev-003-p1",
          "label": "iso14971_risk_file_approved",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "pre-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: ISO 14971 risk file completed, approved by governance body, and residual risk accepted before clinical deployment."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-DEV-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-clinical-deployment"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "DocumentReference"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "category.code == 'iso14971-risk-file', status == 'current', author (governance body)"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-onc-hti1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l5-dev-003_stmt",
          "name": "statement",
          "prose": "A formal risk-benefit analysis must be completed for every clinical AI model before first deployment, following ISO 14971. The analysis must enumerate hazards, estimate probability and severity of harm, define risk controls, and document residual risk. The risk file must be approved by the clinical AI governance body and archived with the regulatory submission."
         },
         {
          "id": "hc-srf-l5-dev-003_obj",
          "name": "objective",
          "prose": "Maintain iso14971_risk_file_approved == {{ insert: param, hc-srf-l5-dev-003-p1 }} over window pre-deployment. Breach action: block-clinical-deployment."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 3.1: Risk management documentation"
         },
         {
          "href": "#5c236a56-0fd8-52fc-880b-5e213d233a3f",
          "rel": "reference",
          "text": "Principle 2: Risk-based"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (Risk management system)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§4.3: Safety classification (informed by risk file)"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§7: Risk evaluation; §8: Risk control; §9: Residual risk"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.6 (safety risks are evaluated and documented); MAP 5.1 (likelihood and magnitude of impacts are assessed)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-10 (AI Impact Assessment)"
         }
        ]
       },
       {
        "id": "hc-srf-l5-vv-001",
        "class": "srf-vertical-control",
        "title": "Independent Clinical Validation",
        "params": [
         {
          "id": "hc-srf-l5-vv-001-p1",
          "label": "independent_validation_completed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "pre-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: independent validation performed by party separate from the development team; validation report archived."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-VV-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "verification-validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-clinical-deployment"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "DocumentReference"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "category.code == 'independent-validation-report', author (independent party), status == 'current'"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l5-vv-001_stmt",
          "name": "statement",
          "prose": "Validation of clinical AI model performance must be performed by a party independent of the development team. For Class II and III SaMD, independent validation must be performed by a qualified external organization. The validation report must be archived and referenced in the FDA marketing submission."
         },
         {
          "id": "hc-srf-l5-vv-001_obj",
          "name": "objective",
          "prose": "Maintain independent_validation_completed == {{ insert: param, hc-srf-l5-vv-001-p1 }} over window pre-deployment. Breach action: block-clinical-deployment."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 3.4: Independent testing and validation"
         },
         {
          "href": "#5c236a56-0fd8-52fc-880b-5e213d233a3f",
          "rel": "reference",
          "text": "Principle 4: Transparent with regulator"
         },
         {
          "href": "#8e4fc90b-6135-5c7a-81da-30efe01e36ad",
          "rel": "reference",
          "text": "§170.315(b)(11)(iv): External validation"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 43 (Conformity assessment by Notified Body)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§5.7: System testing (independence requirement)"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§7: Risk evaluation (independent review)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 1.3 (independent assessors are involved in TEVV)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "A&A-02 (Independent Assessments)"
         }
        ]
       },
       {
        "id": "hc-srf-l5-vv-002",
        "class": "srf-vertical-control",
        "title": "Model Artifact Signing and Supply-Chain Provenance",
        "params": [
         {
          "id": "hc-srf-l5-vv-002-p1",
          "label": "model_artifact_signed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "at-artifact-build"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: all production model artifacts are cryptographically signed; supply-chain provenance record links artifact to training data and build pipeline."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-VV-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "verification-validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-artifact-deployment"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Provenance"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "entity (signed artifact), signature, agent (model-provider), activity.code == 'artifact-signing'"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-onc-hti1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iso-14971",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l5-vv-002_stmt",
          "name": "statement",
          "prose": "All clinical AI model artifacts must be cryptographically signed before deployment. The signing key must be controlled by the model provider and verified by the health platform provider at load time. A supply-chain provenance record must link the signed artifact to the training data, code commit, and build pipeline."
         },
         {
          "id": "hc-srf-l5-vv-002_obj",
          "name": "objective",
          "prose": "Maintain model_artifact_signed == {{ insert: param, hc-srf-l5-vv-002-p1 }} over window at-artifact-build. Breach action: block-artifact-deployment."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 3.2: Cybersecurity and supply chain"
         },
         {
          "href": "#5c236a56-0fd8-52fc-880b-5e213d233a3f",
          "rel": "reference",
          "text": "Principle 1: Verifiable modification scope"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (Risk management)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 28 (Transparency for providers)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§5.5: Software unit implementation (artifact management)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 3.1 (AI risks from third-party resources are monitored); MEASURE 2.7 (security and resilience are evaluated and documented)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM03: Supply Chain"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM04: Data and Model Poisoning"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-09 (Model Signing/Ownership Verification)"
         }
        ]
       },
       {
        "id": "hc-srf-l5-pms-001",
        "class": "srf-vertical-control",
        "title": "Post-Market Performance Monitoring Plan",
        "params": [
         {
          "id": "hc-srf-l5-pms-001-p1",
          "label": "pms_plan_active",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-monitoring-cadence"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: PMS plan documented, approved, and actively generating performance reports on the defined cadence."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-PMS-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "post-market-surveillance"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "alert-governance-body-and-notify-regulatory"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "MeasureReport"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "measure (primary-performance-metric), period (monitoring cadence), status == 'complete'"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-hipaa",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l5-pms-001_stmt",
          "name": "statement",
          "prose": "Every clinical AI model must have a documented Post-Market Surveillance (PMS) plan aligned to FDA PCCP Guiding Principles. The plan must define: primary performance metrics, monitoring cadence, drift thresholds triggering re-validation, and conditions requiring a new FDA submission. The PMS plan must be submitted to FDA as part of the PCCP."
         },
         {
          "id": "hc-srf-l5-pms-001_obj",
          "name": "objective",
          "prose": "Maintain pms_plan_active == {{ insert: param, hc-srf-l5-pms-001-p1 }} over window per-monitoring-cadence. Breach action: alert-governance-body-and-notify-regulatory."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 4: Post-market monitoring requirements"
         },
         {
          "href": "#5c236a56-0fd8-52fc-880b-5e213d233a3f",
          "rel": "reference",
          "text": "Principle 5: Lifecycle-oriented monitoring plan"
         },
         {
          "href": "#8e4fc90b-6135-5c7a-81da-30efe01e36ad",
          "rel": "reference",
          "text": "§170.315(b)(11)(v): Ongoing maintenance assessment"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 72 (Post-market monitoring plan)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§6.2: Problem and modification process"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§10: Post-production activities"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 4.1 (post-deployment monitoring plans are implemented); MEASURE 2.4 (the deployed AI system is monitored)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-10 (Model Continuous Monitoring)"
         }
        ]
       },
       {
        "id": "hc-srf-l5-pms-002",
        "class": "srf-vertical-control",
        "title": "Vulnerability Disclosure and Patch Response SLA",
        "params": [
         {
          "id": "hc-srf-l5-pms-002-p1",
          "label": "cve_critical_patch_days",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "<="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-cve"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "{max_cve_critical_patch_days}"
          ],
          "guidelines": [
           {
            "prose": "Maximum number of days to deploy a patch for a critical (CVSS >= 9.0) CVE affecting clinical AI model components."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-PMS-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "healthcare"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SaMD-Cloud"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "EHR-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Clinical"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "On-Premise"
         },
         {
          "name": "clinical-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "post-market-surveillance"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-security-and-regulatory-and-consider-system-suspension"
         },
         {
          "name": "fhir-resource",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AuditEvent"
         },
         {
          "name": "fhir-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "type.code == 'patch-deployment', entity (cve-id), recorded (patch date)"
         },
         {
          "name": "fhir-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "R4"
         },
         {
          "name": "mapping-fda-pccp",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-onc-hti1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 7: Continuous Vulnerability Management"
         }
        ],
        "parts": [
         {
          "id": "hc-srf-l5-pms-002_stmt",
          "name": "statement",
          "prose": "Critical CVEs affecting clinical AI model components (inference frameworks, SOUP libraries) must be assessed and patched within the configured SLA. Patch deployment must be logged. The SLA aligns to FDA's 2023 Cybersecurity Final Guidance requirements for medical device software."
         },
         {
          "id": "hc-srf-l5-pms-002_obj",
          "name": "objective",
          "prose": "Maintain cve_critical_patch_days <= {{ insert: param, hc-srf-l5-pms-002-p1 }} over window per-cve. Breach action: escalate-to-security-and-regulatory-and-consider-system-suspension."
         }
        ],
        "links": [
         {
          "href": "#df7383c9-314e-55e0-97c8-40d19485fcd7",
          "rel": "reference",
          "text": "Section 4: Post-market cybersecurity obligations"
         },
         {
          "href": "#8d9146e5-7a72-5eac-a274-e74a728227e7",
          "rel": "reference",
          "text": "45 CFR §164.308(a)(1)(ii)(B): Risk management"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 72 (Post-market monitoring including cybersecurity)"
         },
         {
          "href": "#8670371b-4bcd-57ff-860c-f76b86fe9aef",
          "rel": "reference",
          "text": "§6.2: Software problem resolution"
         },
         {
          "href": "#9b4bdb6c-5956-583c-a67b-554142092ad9",
          "rel": "reference",
          "text": "§10.2: Post-production information (vulnerability feedback)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 3.1 (AI risks from third-party resources are monitored); MANAGE 4.3 (incidents and errors are communicated)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM03: Supply Chain (CVEs in inference frameworks and SOUP libraries)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-07 (Vulnerability Remediation Schedule)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-09 (Vulnerability Management Reporting)"
         }
        ]
       }
      ]
     },
     {
      "id": "l5-insurance",
      "class": "srf-vertical",
      "title": "L5 — Insurance",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "insurance"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/insurance-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "ins-srf-l5-dev-001",
        "class": "srf-vertical-control",
        "title": "Model Card with Intended Line-of-Business Statement",
        "params": [
         {
          "id": "ins-srf-l5-dev-001-p1",
          "label": "model_card_current",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-material-change"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: current model card exists, covers all required fields, and was updated within 30 days of the last material model change."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-DEV-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "suspend-model-from-new-deployments; require-model-card-update; notify-chief-actuary"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact. Model card is a required artifact in the model documentation package."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l5-dev-001_stmt",
          "name": "statement",
          "prose": "Every AI model used in insurance underwriting, rating, or claims must have a current model card that includes: intended lines of business, training data summary, known performance limitations, bias evaluation results, recommended use and out-of-scope uses, and the vendor's accountability contact. Model cards must be updated within 30 days of any material model change."
         },
         {
          "id": "ins-srf-l5-dev-001_obj",
          "name": "objective",
          "prose": "Maintain model_card_current == {{ insert: param, ins-srf-l5-dev-001-p1 }} over window per-material-change. Breach action: suspend-model-from-new-deployments; require-model-card-update; notify-chief-actuary."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 3.7 (narrative description of the model's intended goals and objectives)"
         },
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 4, Item 1.3(c)(i) (inventories and descriptions of Predictive Models and AI Systems)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit C, Ref 1 (AI System model name and version number)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit C, Ref 10 (use cases and purpose of model)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(A)(9) (detailed description of each ECDIS, algorithm, and predictive model, their clearly stated purposes, and the outputs generated through their use)"
         },
         {
          "href": "#c59939b3-2e4d-575b-878c-2a4ff0ee3ea1",
          "rel": "reference",
          "text": "Section III.B, paragraph 29(b)-(c) (up-to-date inventory of AIS, description of how each AIS operates)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 11 (technical documentation for high-risk AI systems)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 13 (transparency and provision of information to deployers)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 2.2 (information about the AI system knowledge limits is documented); MEASURE 2.8 (transparency and accountability are examined)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-03 (Model Documentation)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-04 (Model Documentation Requirements)"
         }
        ]
       },
       {
        "id": "ins-srf-l5-dev-002",
        "class": "srf-vertical-control",
        "title": "Model Artifact Signing and Supply-Chain Provenance",
        "params": [
         {
          "id": "ins-srf-l5-dev-002-p1",
          "label": "unsigned_model_artifact_deployment_count",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "0"
          ],
          "guidelines": [
           {
            "prose": "Zero-tolerance: no model artifact may be deployed without a verified cryptographic signature from the model provider."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-DEV-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design-development"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-deployment; alert-security-team; investigate-supply-chain-integrity"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "security_finding (2001): deployment pipeline emits findings when signature verification fails. Attribute: finding.type_id = 'unsigned_model_artifact'."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finding.type_id == 'unsigned_model_artifact' AND status_id == 'new'"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-naic-model-bulletin",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-naic-eval-tool",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-co-reg-10-1-1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nydfs-cl7",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l5-dev-002_stmt",
          "name": "statement",
          "prose": "Model artifacts deployed in insurance AI infrastructure must be cryptographically signed by the model provider, and the insurer must verify signatures before deployment. A software bill of materials (SBOM) or equivalent supply-chain provenance document must accompany each model artifact. Signature verification must be automated in the deployment pipeline."
         },
         {
          "id": "ins-srf-l5-dev-002_obj",
          "name": "objective",
          "prose": "Maintain unsigned_model_artifact_deployment_count == {{ insert: param, ins-srf-l5-dev-002-p1 }} over window per-deployment. Breach action: block-deployment; alert-security-team; investigate-supply-chain-integrity."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 15 (cybersecurity, model integrity and supply-chain security)"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM03 (Supply Chain)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 3.1 (AI risks from third-party resources are monitored); MEASURE 2.7 (security and resilience are evaluated)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-09 (Model Signing/Ownership Verification)"
         }
        ]
       },
       {
        "id": "ins-srf-l5-val-001",
        "class": "srf-vertical-control",
        "title": "Pre-Deployment Fairness Evaluation by Line of Business",
        "params": [
         {
          "id": "ins-srf-l5-val-001-p1",
          "label": "pre_deployment_fairness_eval_completed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Zero-tolerance: no model may be deployed in a covered line of business without a completed, documented fairness evaluation for that line."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-VAL-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "validation-testing"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-deployment; require-fairness-evaluation; escalate-to-chief-actuary-and-chief-compliance-officer"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact for fairness evaluation results. Candidate: audit_activity (3002) if model validation platform logs evaluation completion."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l5-val-001_stmt",
          "name": "statement",
          "prose": "Before any model is deployed in underwriting, rating, or claims for a given line of business, the model provider or insurer must complete a documented fairness evaluation assessing the model's performance across protected class proxies for that specific line. The evaluation must follow a documented methodology, produce findings, and result in either a clearance determination or a documented remediation plan before deployment is authorized."
         },
         {
          "id": "ins-srf-l5-val-001_obj",
          "name": "objective",
          "prose": "Maintain pre_deployment_fairness_eval_completed == {{ insert: param, ins-srf-l5-val-001-p1 }} over window per-deployment. Breach action: block-deployment; require-fairness-evaluation; escalate-to-chief-actuary-and-chief-compliance-officer."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 3.4 (validating and testing AI System outputs upon implementation)"
         },
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 1.7 (AIS Program addresses all life-cycle phases including validation before implementation)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit C, Ref 8 (testing model outputs for unfair discrimination prior to deployment)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(A)(11) (quantitative testing to detect unfair discrimination with respect to race, prior to and during use)"
         },
         {
          "href": "#c59939b3-2e4d-575b-878c-2a4ff0ee3ea1",
          "rel": "reference",
          "text": "Section II.C, paragraph 17 (testing prior to production)"
         },
         {
          "href": "#c59939b3-2e4d-575b-878c-2a4ff0ee3ea1",
          "rel": "reference",
          "text": "Section II.B, paragraph 15 (comprehensive three-step assessment)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (risk management system, pre-deployment risk assessment for high-risk AI)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.11 (fairness and bias are evaluated and documented)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "GRC-10 (AI Impact Assessment)"
         }
        ]
       },
       {
        "id": "ins-srf-l5-val-002",
        "class": "srf-vertical-control",
        "title": "Independent Model Validation",
        "params": [
         {
          "id": "ins-srf-l5-val-002-p1",
          "label": "independent_model_validation_completed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: independent validation completed, findings documented and reviewed, open findings addressed or risk-accepted with documented rationale, before production deployment."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-VAL-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "validation-testing"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-deployment; require-independent-validation; escalate-to-chief-risk-officer"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact. Validation report is a required exam artifact."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l5-val-002_stmt",
          "name": "statement",
          "prose": "Models used in underwriting, rating, or claims must undergo independent validation (conducted by a function or party independent of model development) before production deployment. Validation must assess conceptual soundness, data quality, performance, and limitations. Findings must be reviewed by the accountable officer and addressed before deployment. This control supports the insurer's ability to demonstrate due diligence to examiners."
         },
         {
          "id": "ins-srf-l5-val-002_obj",
          "name": "objective",
          "prose": "Maintain independent_model_validation_completed == {{ insert: param, ins-srf-l5-val-002-p1 }} over window per-deployment. Breach action: block-deployment; require-independent-validation; escalate-to-chief-risk-officer."
         },
         {
          "id": "ins-srf-l5-val-002_gdn",
          "name": "guidance",
          "prose": "accountable-persona-note: Independent validation is conducted by the insurer's validation function or a third party acting on the insurer's behalf. The model-provider is the subject of validation. Accountability for commissioning and completing validation sits with the insurer."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 2.3(c) (independence of decision-makers and lines of defense at successive stages of the AI System life cycle)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit B (Narrative), Q3a (validation and testing procedures on internally-developed AI Systems)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit B (Narrative), Q3b (validation and testing procedures on third-party vendor-supplied AI Systems)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(A)(6) (documented policies and processes ensuring ECDIS, algorithms, and predictive models are documented, tested, and validated - independence of the reviewing function is not specified)"
         },
         {
          "href": "#c59939b3-2e4d-575b-878c-2a4ff0ee3ea1",
          "rel": "reference",
          "text": "Section III.C, paragraph 32 (standards for model development, implementation, use, and validation, independent review and effective challenge)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (risk management system, testing procedures for high-risk AI - not itself the conformity-assessment provision)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 1.3 (independent assessors are involved in TEVV)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "A&A-02 (Independent Assessments)"
         }
        ]
       },
       {
        "id": "ins-srf-l5-mon-001",
        "class": "srf-vertical-control",
        "title": "Post-Deployment Performance and Drift Disclosure SLA from Vendors",
        "params": [
         {
          "id": "ins-srf-l5-mon-001-p1",
          "label": "vendor_perf_disclosure_sla_breach_count",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "TIER_VENDOR_DISCLOSURE_WINDOW"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "0"
          ],
          "guidelines": [
           {
            "prose": "Count of SLA breaches: vendor failed to notify within the contractual disclosure window of material performance degradation or drift event. Tier-configurable disclosure window."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-MON-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "notify-vendor; escalate-to-vendor-accountable-officer; assess-model-suspension; factor-into-vendor-risk-rating"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "detection_finding (2004): vendor SLA monitoring system emits findings on missed disclosure deadlines."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finding.type_id == 'vendor_sla_breach' AND sla_type == 'performance_disclosure'"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-nydfs-cl7",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l5-mon-001_stmt",
          "name": "statement",
          "prose": "Vendors providing AI models used in underwriting, rating, or claims must contractually commit to a performance monitoring and disclosure SLA covering: notification of material performance degradation within the configured window, PSI drift reports on a defined cadence, and advance notice of planned model updates. The insurer must enforce this SLA in vendor contracts and monitor compliance."
         },
         {
          "id": "ins-srf-l5-mon-001_obj",
          "name": "objective",
          "prose": "Maintain vendor_perf_disclosure_sla_breach_count == {{ insert: param, ins-srf-l5-mon-001-p1 }} over window TIER_VENDOR_DISCLOSURE_WINDOW. Breach action: notify-vendor; escalate-to-vendor-accountable-officer; assess-model-suspension; factor-into-vendor-risk-rating."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 3.3(c) (Model Drift)"
         },
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 4.1 (third-party due diligence)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit C, Ref 8 (how model performance is monitored on an ongoing basis)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(A)(12) (ongoing monitoring of algorithm and predictive model performance, including model drift)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 72 (post-market monitoring obligations, reporting to deployers)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 6.1 (policies address AI risks associated with third-party entities); MANAGE 4.1 (post-deployment monitoring plans are implemented)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-10 (Model Continuous Monitoring)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-11 (Supply Chain Agreement Review)"
         }
        ]
       },
       {
        "id": "ins-srf-l5-mon-002",
        "class": "srf-vertical-control",
        "title": "CVE Vulnerability Disclosure SLA from Model Provider",
        "params": [
         {
          "id": "ins-srf-l5-mon-002-p1",
          "label": "cve_disclosure_sla_breach_count",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "TIER_CVE_DISCLOSURE_WINDOW"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "0"
          ],
          "guidelines": [
           {
            "prose": "Count of vendor CVE or security vulnerability notifications not received within the contractual disclosure SLA window."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-MON-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ongoing-monitoring"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "notify-vendor; escalate-to-security-team; assess-emergency-patch; factor-into-vendor-risk-rating"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "security_finding (2001): vulnerability management platform correlates vendor CVE notifications with the insurer's contractual SLA. Breach emitted as finding."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "finding.type_id == 'vendor_cve_sla_breach'"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-naic-model-bulletin",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-naic-eval-tool",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-co-reg-10-1-1",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nydfs-cl7",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 7: Continuous Vulnerability Management"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l5-mon-002_stmt",
          "name": "statement",
          "prose": "Model providers must contractually commit to notifying the insurer within the configured SLA window of any CVE or material security vulnerability in model infrastructure, training pipeline, or inference API that could affect the insurer's production deployment. The insurer must have a documented patch response procedure triggered by vendor notifications."
         },
         {
          "id": "ins-srf-l5-mon-002_obj",
          "name": "objective",
          "prose": "Maintain cve_disclosure_sla_breach_count == {{ insert: param, ins-srf-l5-mon-002-p1 }} over window TIER_CVE_DISCLOSURE_WINDOW. Breach action: notify-vendor; escalate-to-security-team; assess-emergency-patch; factor-into-vendor-risk-rating."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 72 (post-market monitoring, vulnerability disclosure obligations)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 3.1 (AI risks from third-party resources are monitored); MANAGE 4.3 (incidents and errors are communicated)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-07 (Vulnerability Remediation Schedule)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-09 (Vulnerability Management Reporting)"
         }
        ]
       },
       {
        "id": "ins-srf-l5-tpo-001",
        "class": "srf-vertical-control",
        "title": "Vendor Model Due-Diligence Evidence Package (NAIC Third-Party Oversight)",
        "params": [
         {
          "id": "ins-srf-l5-tpo-001-p1",
          "label": "vendor_model_due_diligence_package_complete",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual-review"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: due-diligence evidence package assembled, all component artifacts present and current, and package reviewed by the accountable officer within the prior annual cycle."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-TPO-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "insurance"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Vendor-Model"
         },
         {
          "name": "insurance-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "third-party-oversight"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "identify-missing-artifacts; engage-vendor; escalate-to-chief-risk-officer; assess-model-suspension-if-package-cannot-be-completed"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Document management artifact. Due-diligence package is a required exam artifact. Candidate: audit_activity (3002) if document management system logs package completeness checks."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 15: Service Provider Management"
         }
        ],
        "parts": [
         {
          "id": "ins-srf-l5-tpo-001_stmt",
          "name": "statement",
          "prose": "For each third-party AI model used in underwriting, rating, or claims, the insurer must assemble and retain a due-diligence evidence package covering: model card (SRF-L5-DEV-001), independent validation results (SRF-L5-VAL-002), fairness evaluation (SRF-L5-VAL-001), artifact signing (SRF-L5-DEV-002), and performance SLA (SRF-L5-MON-001). This package is the primary artifact for demonstrating third-party model oversight to examiners."
         },
         {
          "id": "ins-srf-l5-tpo-001_obj",
          "name": "objective",
          "prose": "Maintain vendor_model_due_diligence_package_complete == {{ insert: param, ins-srf-l5-tpo-001-p1 }} over window annual-review. Breach action: identify-missing-artifacts; engage-vendor; escalate-to-chief-risk-officer; assess-model-suspension-if-package-cannot-be-completed."
         },
         {
          "id": "ins-srf-l5-tpo-001_gdn",
          "name": "guidance",
          "prose": "accountable-persona-note: Assembly of the due-diligence package is the insurer's responsibility (ai-system-governance at L1). The model-provider supplies the required documentation. Both parties are accountable for their respective contributions."
         }
        ],
        "links": [
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 3, Guideline 4.1-4.3 (third-party due diligence, contract terms, performance of contractual audit rights)"
         },
         {
          "href": "#52431089-8acf-5d26-bf45-b32bd1b97e77",
          "rel": "reference",
          "text": "Section 4, Item 2.1-2.3 (third-party due diligence, contracts, and audit documentation)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit C (model development, vendor name, risk classification, testing)"
         },
         {
          "href": "#3ebdb912-a63d-5056-a2c2-35254b8088f9",
          "rel": "reference",
          "text": "Exhibit D (third-party data source and vendor name fields)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(A)(13) (process for selecting external resources and third-party vendors)"
         },
         {
          "href": "#85fdd33e-cac4-547a-9bf2-df01201e297a",
          "rel": "reference",
          "text": "Section 5(B) (insurer remains responsible for Section 5(A) requirements)"
         },
         {
          "href": "#c59939b3-2e4d-575b-878c-2a4ff0ee3ea1",
          "rel": "reference",
          "text": "Section III.B, paragraph 29 (comprehensive documentation for AIS and ECDIS, whether developed internally or supplied by third parties)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 11 (technical documentation)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 25 (responsibilities along the AI value chain)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 6.1 (policies address AI risks associated with third-party entities); MANAGE 3.1 (third-party resource risks are monitored)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-11 (Supply Chain Agreement Review)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-14 (Supply Chain Governance Review)"
         }
        ]
       }
      ]
     },
     {
      "id": "l5-defense",
      "class": "srf-vertical",
      "title": "L5 — Defense",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "defense"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/defense-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "def-srf-l5-acq-001",
        "class": "srf-vertical-control",
        "title": "Model Transparency Card per DoDI 5000.90",
        "params": [
         {
          "id": "def-srf-l5-acq-001-p1",
          "label": "transparency_card_delivered",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-model-version"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a transparency card has been delivered for every AI system subject to DoDI 5000.90 and is current for the deployed model version."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-ACQ-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Traceable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "contractor"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-deployment; notify-contracting-officer; request-card-from-vendor"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Transparency card is a contractual deliverable; delivery event maps to audit_activity (3002)."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l5-acq-001_stmt",
          "name": "statement",
          "prose": "The model provider must deliver a transparency card documenting the model's intended use, training data scope, known limitations, performance bounds, failure modes, and version identifier. The card must be delivered before contract award for AI systems subject to DoDI 5000.90 and updated when the model is significantly updated."
         },
         {
          "id": "def-srf-l5-acq-001_obj",
          "name": "objective",
          "prose": "Maintain transparency_card_delivered == {{ insert: param, def-srf-l5-acq-001-p1 }} over window per-model-version. Breach action: block-deployment; notify-contracting-officer; request-card-from-vendor."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Traceable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 3.2.1 (Product Toolkit: AI Data Cards and Model Cards with detailed instructions)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.6"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-03 (Model Documentation)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-04 (Model Documentation Requirements)"
         }
        ]
       },
       {
        "id": "def-srf-l5-ops-002",
        "class": "srf-vertical-control",
        "title": "Vendor Model Drift Disclosure SLA",
        "params": [
         {
          "id": "def-srf-l5-ops-002-p1",
          "label": "drift_disclosure_sla_compliance_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "rolling-12-month"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_DRIFT_DISCLOSURE_SLA_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of model updates where the vendor provided timely disclosure within the contractual SLA window."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-OPS-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Traceable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "notify-contracting-officer; initiate-contract-remedy; trigger-re-validation"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance artifact. Vendor disclosure records and disclosure receipt timestamps map to audit_activity (3002)."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l5-ops-002_stmt",
          "name": "statement",
          "prose": "The vendor or model provider must contractually commit to disclosing any model updates or behavioral changes that may affect performance, accuracy, or safety within the defined disclosure window. The component must monitor for drift and trigger re-validation when a disclosure is received."
         },
         {
          "id": "def-srf-l5-ops-002_obj",
          "name": "objective",
          "prose": "Maintain drift_disclosure_sla_compliance_pct >= {{ insert: param, def-srf-l5-ops-002-p1 }} over window rolling-12-month. Breach action: notify-contracting-officer; initiate-contract-remedy; trigger-re-validation."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Reliable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 2.2.3 (guidance for monitoring AI system performance after fielding)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.8"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-10 (Model Continuous Monitoring)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-11 (Supply Chain Agreement Review)"
         }
        ]
       },
       {
        "id": "def-srf-l5-acq-003",
        "class": "srf-vertical-control",
        "title": "Model Artifact Signing and Bill of AI Materials",
        "params": [
         {
          "id": "def-srf-l5-acq-003-p1",
          "label": "boaim_current_and_signed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a current BoAIM exists for every production model, artifact signatures are verified, and the BoAIM was reviewed within the prior annual cycle."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-ACQ-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Traceable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.14.3"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "notify-PM; re-verify-signatures; update-BoAIM-within-30-days"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Signature verification events map to audit_activity (3002) or software_info (1006)."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l5-acq-003_stmt",
          "name": "statement",
          "prose": "All AI model artifacts deployed on DoD platforms must be cryptographically signed by the provider. The component must maintain a Bill of AI Materials (BoAIM) listing model identifiers, version hashes, training data provenance, and third-party component dependencies for every model in production."
         },
         {
          "id": "def-srf-l5-acq-003_obj",
          "name": "objective",
          "prose": "Maintain boaim_current_and_signed == {{ insert: param, def-srf-l5-acq-003-p1 }} over window annual. Breach action: notify-PM; re-verify-signatures; update-BoAIM-within-30-days."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Traceable principle"
         },
         {
          "href": "#289aed16-d1f7-58b5-b179-0353578d8705",
          "rel": "reference",
          "text": "Section 3.4.c(4) (software assurance and anti-counterfeit practices for mission-critical functions per DoDI 5200.44)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "SI.L2-3.14.3 (monitor security alerts and advisories and take action)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "SI.L3-3.14.1e (verify software integrity using root of trust mechanisms or cryptographic signatures - Level 3)"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.14.3"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 5.1"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM03: Supply Chain"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-09 (Model Signing/Ownership Verification)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-08 (Model Integrity Checks)"
         }
        ]
       },
       {
        "id": "def-srf-l5-ops-004",
        "class": "srf-vertical-control",
        "title": "Vulnerability Disclosure SLA and Patch Cadence",
        "params": [
         {
          "id": "def-srf-l5-ops-004-p1",
          "label": "critical_vuln_patch_timeliness_pct",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "rolling-90-day"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_CRITICAL_PATCH_TIMELINESS_PCT"
          ],
          "guidelines": [
           {
            "prose": "Percentage of critical model vulnerabilities patched or mitigated within the contractual window from vendor disclosure."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-OPS-004"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.14.1"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "notify-ISSO; apply-emergency-patch; report-to-AO"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "vulnerability_finding (2002). Patch events must log CVE or finding ID, disclosure date, patch date, and applier identity."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l5-ops-004_stmt",
          "name": "statement",
          "prose": "The model or platform provider must commit to a vulnerability disclosure SLA and patch release cadence in the contract. Critical vulnerabilities must be disclosed within 24 hours of discovery and patched or mitigated within the contractual window. The component must apply patches within its own remediation timeline after vendor release."
         },
         {
          "id": "def-srf-l5-ops-004_obj",
          "name": "objective",
          "prose": "Maintain critical_vuln_patch_timeliness_pct >= {{ insert: param, def-srf-l5-ops-004-p1 }} over window rolling-90-day. Breach action: notify-ISSO; apply-emergency-patch; report-to-AO."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Reliable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 3.1.1 (standard AI contract language including immediate remediation methods)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "SI.L2-3.14.1 (identify, report, and correct system flaws in a timely manner)"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.14.1"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 2.4"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-07 (Vulnerability Remediation Schedule)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-09 (Vulnerability Management Reporting)"
         }
        ]
       },
       {
        "id": "def-srf-l5-acq-005",
        "class": "srf-vertical-control",
        "title": "Model Portability to Avoid Vendor Lock-In",
        "params": [
         {
          "id": "def-srf-l5-acq-005-p1",
          "label": "portability_plan_approved",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-contract"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_PORTABILITY_PLAN_APPROVED"
          ],
          "guidelines": [
           {
            "prose": "Binary: a portability plan or portability exercise result is documented and approved in the program record."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-ACQ-005"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "notify-contracting-officer; add-portability-clause-at-next-modification"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Portability plan is a program management record."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l5-acq-005_stmt",
          "name": "statement",
          "prose": "Contracts for AI systems must include data rights and model portability provisions that allow the component to transition to an alternative model without losing operational capability. Portability must be verified through a portability exercise or documented portability plan approved by the program manager."
         },
         {
          "id": "def-srf-l5-acq-005_obj",
          "name": "objective",
          "prose": "Maintain portability_plan_approved == {{ insert: param, def-srf-l5-acq-005-p1 }} over window per-contract. Breach action: notify-contracting-officer; add-portability-clause-at-next-modification."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Governable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 3.1.3 (open architecture, data rights, and avoidance of proprietary lock-in)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.6"
         }
        ]
       },
       {
        "id": "def-srf-l5-ops-006",
        "class": "srf-vertical-control",
        "title": "Re-Validation Trigger on Model Version Change",
        "params": [
         {
          "id": "def-srf-l5-ops-006-p1",
          "label": "revalidation_completed_before_deployment",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-model-version"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a re-validation record exists for every model version change, proportional to change scope, completed before production deployment."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-OPS-006"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Traceable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-deployment; notify-PM; complete-revalidation"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Re-validation records and version change events map to audit_activity (3002)."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l5-ops-006_stmt",
          "name": "statement",
          "prose": "Any change to the deployed model version must trigger a re-validation cycle proportional to the scope of the change. The re-validation plan must be documented before the new version is deployed to operational environments. Major version changes require full TEVV; minor updates require at minimum a regression test against the prior TEVV acceptance criteria."
         },
         {
          "id": "def-srf-l5-ops-006_obj",
          "name": "objective",
          "prose": "Maintain revalidation_completed_before_deployment == {{ insert: param, def-srf-l5-ops-006-p1 }} over window per-model-version. Breach action: block-deployment; notify-PM; complete-revalidation."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Reliable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 4.2.2 (continuous testing and validation consistent with iterative acquisition)"
         },
         {
          "href": "#8613c5f9-9d01-5ebc-8cc6-19adffb697fe",
          "rel": "reference",
          "text": "Section 4.4.d (OTA testing of capability upgrades and alterations that materially change system performance after initial fielding)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 3.1"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-10 (Model Continuous Monitoring)"
         }
        ]
       },
       {
        "id": "def-srf-l5-acq-007",
        "class": "srf-vertical-control",
        "title": "Personnel Security Clearance for IL6 Model Infrastructure Access",
        "params": [
         {
          "id": "def-srf-l5-acq-007-p1",
          "label": "uncleared_il6_access_events",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "continuous"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "zero-tolerance"
           }
          ],
          "values": [
           "TIER_UNCLEARED_IL6_ACCESS"
          ],
          "guidelines": [
           {
            "prose": "Number of IL6 model infrastructure access events by personnel without a verified active clearance. Zero-tolerance."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-ACQ-007"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "nss"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.9.1"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.9.2"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "revoke-access; notify-security-officer; open-security-incident; report-to-AO"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "access_activity (3001). Access events must log user identity, clearance verification status, and access granted or denied."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l5-acq-007_stmt",
          "name": "statement",
          "prose": "Personnel with administrative or maintenance access to AI model infrastructure in IL6 classified environments must hold the required personnel security clearance. The component must verify clearance levels before granting access and review access rosters quarterly. Access must be terminated immediately upon clearance lapse."
         },
         {
          "id": "def-srf-l5-acq-007_obj",
          "name": "objective",
          "prose": "Maintain uncleared_il6_access_events == {{ insert: param, def-srf-l5-acq-007-p1 }} over window continuous. Breach action: revoke-access; notify-security-officer; open-security-incident; report-to-AO."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Responsible principle"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "PS.L2-3.9.1 (screen individuals prior to authorizing access)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "PS.L2-3.9.2 (protect CUI during and after personnel actions)"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.9.1"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.6"
         },
         {
          "href": "#c5d89a8d-2be1-526a-977f-3cc51013206f",
          "rel": "reference",
          "text": "CSP SRG Section 4.1 (IL6 facility and personnel clearances authorized by DCSA)"
         },
         {
          "href": "#c5d89a8d-2be1-526a-977f-3cc51013206f",
          "rel": "reference",
          "text": "CSP SRG Section 5.5.2 (CSP Personnel Requirements)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "IAM-16 (Authorization Mechanisms)"
         }
        ]
       },
       {
        "id": "def-srf-l5-acq-008",
        "class": "srf-vertical-control",
        "title": "Supply Chain Risk Assessment for AI Components and Foundation Model Providers",
        "params": [
         {
          "id": "def-srf-l5-acq-008-p1",
          "label": "model_scrm_assessment_complete",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "annual"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a supply chain risk assessment for each model provider has been completed before contract award and updated within the prior annual cycle."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-ACQ-008"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Responsible"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "dod-component"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "cmmc-practices",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "3.11.1"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "acquisition"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "block-contract-award; notify-PM; complete-assessment"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Assessment completion maps to audit_activity (3002)."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-89",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l5-acq-008_stmt",
          "name": "statement",
          "prose": "Before selecting a foundation model or AI component provider, the component must assess supply chain risk covering country of origin of training data and model weights, ownership structure, export control status, and any foreign government relationships. Assessments must be updated when ownership or control of the provider changes."
         },
         {
          "id": "def-srf-l5-acq-008_obj",
          "name": "objective",
          "prose": "Maintain model_scrm_assessment_complete == {{ insert: param, def-srf-l5-acq-008-p1 }} over window annual. Breach action: block-contract-award; notify-PM; complete-assessment."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Responsible principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "LOE 2.1.7 (AI security guidance leveraging supply chain security best practices)"
         },
         {
          "href": "#289aed16-d1f7-58b5-b179-0353578d8705",
          "rel": "reference",
          "text": "Section 3.4.c(1)-(2) (foreign ownership, control, or influence in supplier risk management)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "RA.L2-3.11.1 (periodic risk assessments)"
         },
         {
          "href": "#c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
          "rel": "reference",
          "text": "RA.L3-3.11.6e (assess, respond to, and monitor supply chain risks - Level 3)"
         },
         {
          "href": "#6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
          "rel": "reference",
          "text": "3.11.1"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 5.1"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM03: Supply Chain"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-14 (Supply Chain Governance Review)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-11 (Supply Chain Agreement Review)"
         }
        ]
       },
       {
        "id": "def-srf-l5-tevv-009",
        "class": "srf-vertical-control",
        "title": "Model Behavioral Baseline Documented Before Initial Deployment",
        "params": [
         {
          "id": "def-srf-l5-tevv-009-p1",
          "label": "model_behavioral_baseline_documented",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-model-version"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Binary: a model behavioral baseline document is on file in the TEVV package and referenced in the BoAIM before the model is promoted to any operational environment. Known limitations and failure modes are explicitly listed."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-TEVV-009"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "defense"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Agent-Ops"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Program-Embedded"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Reliable"
         },
         {
          "name": "dod-rai-principles",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Traceable"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "nss-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL4"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL5"
         },
         {
          "name": "il-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "IL6"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "tevv"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Block promotion to operational environment. Model provider or program team must complete baseline documentation and update BoAIM."
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact"
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-dodi-5000-90",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cmmc-2-0",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-800-171",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cc-srg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "def-srf-l5-tevv-009_stmt",
          "name": "statement",
          "prose": "Before a model is promoted to any operational environment, the model provider or program team must document a behavioral baseline: key performance metrics on representative test sets, accuracy and reliability measurements at the target operating conditions, and known limitations and failure modes. The baseline must be retained in the TEVV package and the BoAIM. Subsequent model versions must be compared against this baseline to detect significant behavioral drift before re-deployment."
         },
         {
          "id": "def-srf-l5-tevv-009_obj",
          "name": "objective",
          "prose": "Maintain model_behavioral_baseline_documented == {{ insert: param, def-srf-l5-tevv-009-p1 }} over window per-model-version. Breach action: Block promotion to operational environment. Model provider or program team must complete baseline documentation and update BoAIM.."
         }
        ],
        "links": [
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Reliable principle"
         },
         {
          "href": "#27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
          "rel": "reference",
          "text": "Traceable principle"
         },
         {
          "href": "#8613c5f9-9d01-5ebc-8cc6-19adffb697fe",
          "rel": "reference",
          "text": "Section 5.2 (DT&E Activities: characterize system capabilities, limitations, and deficiencies)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 1.1"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-03 (Model Documentation)"
         }
        ]
       }
      ]
     },
     {
      "id": "l5-manufacturing",
      "class": "srf-vertical",
      "title": "L5 — Manufacturing",
      "props": [
       {
        "name": "vertical",
        "ns": "https://aisharedresponsibility.com/ns/oscal",
        "value": "manufacturing"
       }
      ],
      "links": [
       {
        "href": "https://aisharedresponsibility.com/data/manufacturing-controls.json",
        "rel": "source"
       }
      ],
      "controls": [
       {
        "id": "mfg-srf-l5-val-001",
        "class": "srf-vertical-control",
        "title": "EU AI Act Technical File Completeness - Model Supplier Obligations",
        "params": [
         {
          "id": "mfg-srf-l5-val-001-p1",
          "label": "supplier_technical_file_complete",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-supplier-engagement"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Model supplier technical file includes declaration of conformity, technical documentation, and conformity assessment record before deployment."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-VAL-001"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model and Supplier"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Product-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "equipment-oem"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "request-missing-documentation; delay-deployment; escalate-to-procurement"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Supplier technical file completeness checklist with review sign-off."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Article TBD (technical file requirements)",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-62443",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l5-val-001_stmt",
          "name": "statement",
          "prose": "The model provider (AI model vendor or equipment OEM supplying an AI-enabled system) must provide a complete technical file including: the EU declaration of conformity, technical documentation per Annex IV, information on training methodology and data, and the conformity assessment record. For high-risk systems, the declaration of conformity must be signed by an authorized representative. Deploying manufacturers must verify completeness of supplier documentation before market placement."
         },
         {
          "id": "mfg-srf-l5-val-001_obj",
          "name": "objective",
          "prose": "Maintain supplier_technical_file_complete == {{ insert: param, mfg-srf-l5-val-001-p1 }} over window per-supplier-engagement. Breach action: request-missing-documentation; delay-deployment; escalate-to-procurement."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 11 (technical documentation)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 47 (EU declaration of conformity)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Annex IV"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 1.3"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-04 (Model Documentation Requirements)"
         }
        ]
       },
       {
        "id": "mfg-srf-l5-ops-002",
        "class": "srf-vertical-control",
        "title": "Model Drift and Performance Degradation Monitoring",
        "params": [
         {
          "id": "mfg-srf-l5-ops-002-p1",
          "label": "model_performance_vs_baseline",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": ">="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "TIER_MODEL_MONITORING_WINDOW"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_MODEL_PERFORMANCE_FLOOR"
          ],
          "guidelines": [
           {
            "prose": "Model primary task metric relative to the validated baseline performance. Drift threshold set by operating model and process criticality."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-OPS-002"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model and Supplier"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "alert-model-provider; investigate-drift-cause; consider-retraining-or-fallback"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "api_activity (6003) or model monitoring log. Source: model performance monitoring tool."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "observables.performance_metric; time; metadata.baseline_value"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-62443",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l5-ops-002_stmt",
          "name": "statement",
          "prose": "The model provider must supply or specify a monitoring mechanism for model drift and performance degradation. For OT-edge AI, the monitoring interval must be calibrated to the process criticality and the acceptable lag between degradation onset and detection. Performance metrics must include at minimum the primary task metric (e.g., classification accuracy for quality inspection, MAE for predictive maintenance) and a statistical drift indicator. Degradation events must trigger an alert and investigation."
         },
         {
          "id": "mfg-srf-l5-ops-002_obj",
          "name": "objective",
          "prose": "Maintain model_performance_vs_baseline >= {{ insert: param, mfg-srf-l5-ops-002-p1 }} over window TIER_MODEL_MONITORING_WINDOW. Breach action: alert-model-provider; investigate-drift-cause; consider-retraining-or-fallback."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 72 (post-market monitoring)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (risk management, ongoing monitoring)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.5"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-10 (Model Continuous Monitoring)"
         }
        ]
       },
       {
        "id": "mfg-srf-l5-chg-003",
        "class": "srf-vertical-control",
        "title": "Model Version Change Management Trigger",
        "params": [
         {
          "id": "mfg-srf-l5-chg-003-p1",
          "label": "model_change_record_completeness",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-change"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Percentage of model version change events with a completed change record and re-validation determination before deployment."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-CHG-003"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model and Supplier"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Product-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL1"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "change"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "create-change-record; conduct-revalidation-assessment; delay-deployment"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Change record with re-validation determination signed off by responsible engineer."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l5-chg-003_stmt",
          "name": "statement",
          "prose": "Every model version change must generate a change record before deployment. For high-risk AI systems, model version changes must trigger a re-validation assessment to determine whether the change requires a new conformity assessment under EU AI Act Article 43. OT-edge deployments require an additional safety impact assessment and version freeze coordination. The model provider must document the change scope and re-validation determination in the change record."
         },
         {
          "id": "mfg-srf-l5-chg-003_obj",
          "name": "objective",
          "prose": "Maintain model_change_record_completeness == {{ insert: param, mfg-srf-l5-chg-003-p1 }} over window per-change. Breach action: create-change-record; conduct-revalidation-assessment; delay-deployment."
         },
         {
          "id": "mfg-srf-l5-chg-003_gdn",
          "name": "guidance",
          "prose": "mapping-status-note: IEC 61508 clause reference requires verification against primary text."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 43 (conformity assessment re-evaluation trigger)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 17 (quality management, change control)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-2-1 (part-level)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 2.2"
         },
         {
          "href": "#baa4cf26-6159-56d6-a26d-4cb096e75b6c",
          "rel": "reference",
          "text": "IEC 61508 (edition-level)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-10 (Model Continuous Monitoring)"
         }
        ]
       },
       {
        "id": "mfg-srf-l5-ops-004",
        "class": "srf-vertical-control",
        "title": "Vulnerability Disclosure SLA for AI Model Supplier",
        "params": [
         {
          "id": "mfg-srf-l5-ops-004-p1",
          "label": "vuln_sla_days_critical",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "<="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-vulnerability"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "tier-configurable"
           }
          ],
          "values": [
           "TIER_VULN_SLA_DAYS_CRITICAL"
          ],
          "guidelines": [
           {
            "prose": "Maximum days from confirmed critical vulnerability to patch availability for AI model components."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-OPS-004"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model and Supplier"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Product-Embedded"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-vendor"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL1"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ops"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "escalate-to-vendor; implement-compensating-control; notify-ot-security"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Vendor VDP or SLA document. Patch availability date records."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-cis",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "CIS Control 7: Continuous Vulnerability Management"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l5-ops-004_stmt",
          "name": "statement",
          "prose": "The model provider must publish and honor a vulnerability disclosure SLA specifying: the channel for receiving vulnerability reports, the acknowledgment timeline, the assessment and severity classification timeline, and the patch availability timeline by severity level. For OT-edge AI, the SLA must account for the OT change management cycle; critical vulnerabilities must include a compensating control recommendation when immediate patching is infeasible."
         },
         {
          "id": "mfg-srf-l5-ops-004_obj",
          "name": "objective",
          "prose": "Maintain vuln_sla_days_critical <= {{ insert: param, mfg-srf-l5-ops-004-p1 }} over window per-vulnerability. Breach action: escalate-to-vendor; implement-compensating-control; notify-ot-security."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (risk management, security vulnerability management)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-2-1 (part-level)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MANAGE 3.1"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-07 (Vulnerability Remediation Schedule)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "TVM-09 (Vulnerability Management Reporting)"
         }
        ]
       },
       {
        "id": "mfg-srf-l5-des-005",
        "class": "srf-vertical-control",
        "title": "BoAIM and Model Artifact Signing",
        "params": [
         {
          "id": "mfg-srf-l5-des-005-p1",
          "label": "model_artifact_signed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Model artifact signature verified before deployment. BoAIM present and current for every artifact deployed to OT or product environments."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-DES-005"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model and Supplier"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Product-Embedded"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-vendor"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL3"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "obtain-boaim; verify-signature; halt-deployment-if-verification-fails"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. BoAIM document and artifact signature verification record."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l5-des-005_stmt",
          "name": "statement",
          "prose": "The model provider must supply a Bill of AI Materials (BoAIM) for each AI model artifact, listing model architecture, training framework versions, base model or pre-trained weights sources, and fine-tuning dataset provenance. Model artifacts must be signed with a verifiable digital signature before distribution. The deploying manufacturer must verify artifact signatures before deployment to OT or product environments."
         },
         {
          "id": "mfg-srf-l5-des-005_obj",
          "name": "objective",
          "prose": "Maintain model_artifact_signed == {{ insert: param, mfg-srf-l5-des-005-p1 }} over window per-deployment. Breach action: obtain-boaim; verify-signature; halt-deployment-if-verification-fails."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Annex IV (technical documentation, model description)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-2-1 (part-level)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MAP 5.2"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM03 (Supply Chain)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-09 (Model Signing/Ownership Verification)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "MDS-08 (Model Integrity Checks)"
         }
        ]
       },
       {
        "id": "mfg-srf-l5-val-006",
        "class": "srf-vertical-control",
        "title": "Functional Safety Validation for AI in Safety-Instrumented Systems",
        "params": [
         {
          "id": "mfg-srf-l5-val-006-p1",
          "label": "sil_validation_completed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-deployment"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "SIL-appropriate functional safety validation completed and safety case documented before commissioning. Document custodian: functional safety engineer."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-VAL-006"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model and Supplier"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "shared"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ot-only"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "high-risk"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL2"
         },
         {
          "name": "iec-62443-sls",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SL3"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "validation"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "engage-functional-safety-engineer; complete-sil-assessment; document-safety-case"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Safety case document (access restricted; maintained by functional safety engineer). SIL assessment record (access restricted)."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-iso-42001",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l5-val-006_stmt",
          "name": "statement",
          "prose": "Where an AI system is integrated into or provides inputs to a safety-instrumented system (SIS), the model provider and deploying manufacturer must complete a safety validation appropriate to the Safety Integrity Level (SIL) of the SIS. Safety validation must follow IEC 61508 or a sector-equivalent standard. Safety case documents and SIL assessment records are classified documents: note document type and custodian role (functional safety engineer, plant safety officer); do not publish document URLs. Validation must be completed before commissioning."
         },
         {
          "id": "mfg-srf-l5-val-006_obj",
          "name": "objective",
          "prose": "Maintain sil_validation_completed == {{ insert: param, mfg-srf-l5-val-006-p1 }} over window per-deployment. Breach action: engage-functional-safety-engineer; complete-sil-assessment; document-safety-case."
         },
         {
          "id": "mfg-srf-l5-val-006_gdn",
          "name": "guidance",
          "prose": "mapping-status-note: All IEC 61508 clause references marked TBD. Citation must reference IEC 61508 part numbers (IEC 61508-1 through IEC 61508-7) only, not specific clause numbers, pending verification against primary text."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 9 (risk management, safety validation)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Annex IV (safety testing documentation)"
         },
         {
          "href": "#5f62c959-7f28-53d4-b324-ca1206fc7e66",
          "rel": "reference",
          "text": "Annex I item 5 (safety components with self-evolving behaviour)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-3-3 (part-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "MEASURE 2.2"
         },
         {
          "href": "#baa4cf26-6159-56d6-a26d-4cb096e75b6c",
          "rel": "reference",
          "text": "IEC 61508 (edition-level)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "A&A-02 (Independent Assessments)"
         }
        ]
       },
       {
        "id": "mfg-srf-l5-des-007",
        "class": "srf-vertical-control",
        "title": "Model Portability and Lock-In Avoidance Documentation",
        "params": [
         {
          "id": "mfg-srf-l5-des-007-p1",
          "label": "portability_documentation_provided",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-supplier-engagement"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Model portability documentation provided before contract signature, covering export formats and OT re-deployment capability."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-DES-007"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model and Supplier"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-SaaS"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "AI-PaaS"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "ai-vendor"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "request-portability-documentation; evaluate-lock-in-risk; escalate-to-procurement"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Portability documentation from supplier."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-ai-act",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-62443",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         },
         {
          "name": "mapping-owasp-llm",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l5-des-007_stmt",
          "name": "statement",
          "prose": "The model provider must document the model export capability, the supported export formats, and the migration path to an alternative platform. For OT-edge AI, the export documentation must specify whether the model can be re-deployed on alternative OT-compatible hardware without retraining. Model portability documentation must be provided before contract signature and updated when the provider's platform capabilities change."
         },
         {
          "id": "mfg-srf-l5-des-007_obj",
          "name": "objective",
          "prose": "Maintain portability_documentation_provided == {{ insert: param, mfg-srf-l5-des-007-p1 }} over window per-supplier-engagement. Breach action: request-portability-documentation; evaluate-lock-in-risk; escalate-to-procurement."
         }
        ],
        "links": [
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 6.2"
         }
        ]
       },
       {
        "id": "mfg-srf-l5-des-008",
        "class": "srf-vertical-control",
        "title": "Model Supplier Due Diligence and Supply Chain Risk Assessment",
        "params": [
         {
          "id": "mfg-srf-l5-des-008-p1",
          "label": "supplier_due_diligence_completed",
          "props": [
           {
            "name": "operator",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "=="
           },
           {
            "name": "window",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "per-supplier-engagement"
           },
           {
            "name": "param-type",
            "ns": "https://aisharedresponsibility.com/ns/oscal",
            "value": "verification"
           }
          ],
          "values": [
           "true"
          ],
          "guidelines": [
           {
            "prose": "Supplier due diligence record completed, reviewed by procurement and OT security lead, and retained before contract signature."
           }
          ]
         }
        ],
        "props": [
         {
          "name": "srf-id",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "SRF-L5-DES-008"
         },
         {
          "name": "vertical",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturing"
         },
         {
          "name": "layer",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "L5"
         },
         {
          "name": "component",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Model and Supplier"
         },
         {
          "name": "accountable-persona",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "model-provider"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "OT-Edge"
         },
         {
          "name": "operating-model",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Product-Embedded"
         },
         {
          "name": "responsibility-split",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "manufacturer"
         },
         {
          "name": "ot-applicability",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "both"
         },
         {
          "name": "eu-ai-act-risk-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A"
         },
         {
          "name": "lifecycle-stage",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "design"
         },
         {
          "name": "breach-action",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "complete-due-diligence; obtain-ot-security-review; delay-contract-signature"
         },
         {
          "name": "ocsf-class",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "Governance document artifact. Supplier due diligence report with review sign-off."
         },
         {
          "name": "ocsf-attribute",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD"
         },
         {
          "name": "ocsf-version",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "1.8.0"
         },
         {
          "name": "mapping-eu-machinery-reg",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-iec-61508",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "N/A",
          "class": "unresolved"
         },
         {
          "name": "mapping-nist-cyber-ai",
          "ns": "https://aisharedresponsibility.com/ns/oscal",
          "value": "TBD",
          "class": "unresolved"
         }
        ],
        "parts": [
         {
          "id": "mfg-srf-l5-des-008_stmt",
          "name": "statement",
          "prose": "Before contracting a model supplier for an OT-edge or product-embedded AI system, the model provider evaluation must include: financial stability and support horizon, security disclosure history, jurisdictional risk (data residency, export control), EU AI Act compliance status for high-risk models, and OT environment compatibility. The due diligence record must be reviewed by procurement and the OT security lead and retained with the supplier record."
         },
         {
          "id": "mfg-srf-l5-des-008_obj",
          "name": "objective",
          "prose": "Maintain supplier_due_diligence_completed == {{ insert: param, mfg-srf-l5-des-008-p1 }} over window per-supplier-engagement. Breach action: complete-due-diligence; obtain-ot-security-review; delay-contract-signature."
         }
        ],
        "links": [
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 28 (third-party provider obligations)"
         },
         {
          "href": "#51bbabe9-02b8-5813-994d-891f4c95ef21",
          "rel": "reference",
          "text": "Article 16 (provider due diligence)"
         },
         {
          "href": "#01f21329-1e0e-552c-a9a1-76432e1fd8a1",
          "rel": "reference",
          "text": "ISA/IEC 62443-2-1 (part-level)"
         },
         {
          "href": "#42ceecfa-0c80-5ecf-b832-45f0beb1184a",
          "rel": "reference",
          "text": "ISO/IEC 42001:2023 (edition-level)"
         },
         {
          "href": "#c00b1cec-7990-5779-b1cf-10a2e792f026",
          "rel": "reference",
          "text": "GOVERN 6.1"
         },
         {
          "href": "#c403b49d-9023-519a-a9f4-fefbab79a3ce",
          "rel": "reference",
          "text": "LLM03 (Supply Chain)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-14 (Supply Chain Governance Review)"
         },
         {
          "href": "#97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
          "rel": "reference",
          "text": "STA-11 (Supply Chain Agreement Review)"
         }
        ]
       }
      ]
     }
    ]
   }
  ],
  "back-matter": {
   "resources": [
    {
     "uuid": "97cd3d25-cf40-53a0-9616-8ce8875cdc2f",
     "title": "CSA AI Controls Matrix",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "aicm"
      }
     ],
     "rlinks": [
      {
       "href": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix"
      }
     ]
    },
    {
     "uuid": "85fdd33e-cac4-547a-9bf2-df01201e297a",
     "title": "Colorado 3 CCR 702-10, Regulation 10-1-1 (Insurance AI Governance)",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "co_reg_10_1_1"
      }
     ],
     "rlinks": [
      {
       "href": "https://doi.colorado.gov/announcements/notice-of-adoption-amended-regulation-10-1-1-governance-and-risk-management-framework"
      }
     ]
    },
    {
     "uuid": "c749265b-4f91-5a8d-a8d0-366cdfd9ea2b",
     "title": "Cybersecurity Maturity Model Certification (CMMC) 2.0",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "cmmc_2_0"
      }
     ],
     "rlinks": [
      {
       "href": "https://dodcio.defense.gov/cmmc/"
      }
     ]
    },
    {
     "uuid": "c5d89a8d-2be1-526a-977f-3cc51013206f",
     "title": "DoD Cloud Computing SRGs (Mission Owner SRG and CSP SRG V1R2, January 2025)",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "cc_srg"
      }
     ],
     "rlinks": [
      {
       "href": "https://public.cyber.mil/dccs/"
      }
     ]
    },
    {
     "uuid": "27bd17b5-97b5-5d65-8009-3cf0b5c3faff",
     "title": "DoD Responsible AI Strategy and Implementation Pathway",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "dod_rai_strategy"
      }
     ],
     "rlinks": [
      {
       "href": "https://media.defense.gov/2022/Jun/22/2003022604/-1/-1/0/Department-of-Defense-Responsible-Artificial-Intelligence-Strategy-and-Implementation-Pathway.PDF"
      }
     ]
    },
    {
     "uuid": "8613c5f9-9d01-5ebc-8cc6-19adffb697fe",
     "title": "DoDI 5000.89 — Test and Evaluation",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "dodi_5000_89"
      }
     ],
     "rlinks": [
      {
       "href": "https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/500089p.pdf"
      }
     ]
    },
    {
     "uuid": "289aed16-d1f7-58b5-b179-0353578d8705",
     "title": "DoDI 5000.90 — Cybersecurity for Acquisition Decision Authorities",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "dodi_5000_90"
      }
     ],
     "rlinks": [
      {
       "href": "https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/500090p.pdf"
      }
     ]
    },
    {
     "uuid": "51bbabe9-02b8-5813-994d-891f4c95ef21",
     "title": "EU Artificial Intelligence Act (Regulation (EU) 2024/1689)",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "eu_ai_act"
      }
     ],
     "rlinks": [
      {
       "href": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689"
      }
     ]
    },
    {
     "uuid": "5f62c959-7f28-53d4-b324-ca1206fc7e66",
     "title": "EU Machinery Regulation (Regulation (EU) 2023/1230)",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "eu_machinery_reg"
      }
     ],
     "rlinks": [
      {
       "href": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32023R1230"
      }
     ]
    },
    {
     "uuid": "5c236a56-0fd8-52fc-880b-5e213d233a3f",
     "title": "FDA Predetermined Change Control Plan Guidance",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "fda_pccp"
      }
     ],
     "rlinks": [
      {
       "href": "https://www.fda.gov/regulatory-information/search-fda-guidance-documents/marketing-submission-recommendations-predetermined-change-control-plan-artificial-intelligence-enabled-device-software-functions"
      }
     ]
    },
    {
     "uuid": "df7383c9-314e-55e0-97c8-40d19485fcd7",
     "title": "FDA Total Product Lifecycle for AI/ML-Based SaMD",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "fda_tplc"
      }
     ],
     "rlinks": [
      {
       "href": "https://www.fda.gov/medical-devices/software-medical-device-samd/artificial-intelligence-and-machine-learning-software-medical-device"
      }
     ]
    },
    {
     "uuid": "42d3a8ce-e217-5de0-a841-81b227deb27b",
     "title": "FINOS AI Governance Framework",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "finos_aigf"
      }
     ],
     "rlinks": [
      {
       "href": "https://air-governance-framework.finos.org/"
      }
     ]
    },
    {
     "uuid": "aec75536-9650-52f9-bd36-918743c7b0a5",
     "title": "FedRAMP 20x Key Security Indicators (Consolidated Rules for 2026)",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "fedramp_20x_ksi"
      }
     ],
     "rlinks": [
      {
       "href": "https://www.fedramp.gov/2026/"
      }
     ]
    },
    {
     "uuid": "8d9146e5-7a72-5eac-a274-e74a728227e7",
     "title": "HIPAA (Health Insurance Portability and Accountability Act)",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "hipaa"
      }
     ],
     "rlinks": [
      {
       "href": "https://www.hhs.gov/hipaa/index.html"
      }
     ]
    },
    {
     "uuid": "baa4cf26-6159-56d6-a26d-4cb096e75b6c",
     "title": "IEC 61508 — Functional Safety",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "iec_61508"
      }
     ],
     "rlinks": [
      {
       "href": "https://www.iec.ch/functional-safety"
      }
     ]
    },
    {
     "uuid": "8670371b-4bcd-57ff-860c-f76b86fe9aef",
     "title": "IEC 62304 — Medical Device Software Lifecycle Processes",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "iec_62304"
      }
     ],
     "rlinks": [
      {
       "href": "https://webstore.iec.ch/publication/22794"
      }
     ]
    },
    {
     "uuid": "01f21329-1e0e-552c-a9a1-76432e1fd8a1",
     "title": "ISA/IEC 62443 — Industrial Automation and Control Systems Security",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "iec_62443"
      }
     ],
     "rlinks": [
      {
       "href": "https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards"
      }
     ]
    },
    {
     "uuid": "9b4bdb6c-5956-583c-a67b-554142092ad9",
     "title": "ISO 14971 — Application of Risk Management to Medical Devices",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "iso_14971"
      }
     ],
     "rlinks": [
      {
       "href": "https://www.iso.org/standard/72704.html"
      }
     ]
    },
    {
     "uuid": "42ceecfa-0c80-5ecf-b832-45f0beb1184a",
     "title": "ISO/IEC 42001 — AI Management Systems",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "iso_42001"
      }
     ],
     "rlinks": [
      {
       "href": "https://www.iso.org/standard/81230.html"
      }
     ]
    },
    {
     "uuid": "3ebdb912-a63d-5056-a2c2-35254b8088f9",
     "title": "NAIC AI Systems Evaluation Tool 4.0 (DRAFT, pilot pre-adoption)",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "naic_eval_tool"
      }
     ],
     "rlinks": [
      {
       "href": "https://content.naic.org/sites/default/files/inline-files/AI%20Systems%20Evaluation%20Tool%204.0%20(Clean).pdf"
      }
     ]
    },
    {
     "uuid": "52431089-8acf-5d26-bf45-b32bd1b97e77",
     "title": "NAIC Model Bulletin on the Use of AI Systems by Insurers",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "naic_model_bulletin"
      }
     ],
     "rlinks": [
      {
       "href": "https://content.naic.org/sites/default/files/inline-files/2023-12-4%20Model%20Bulletin_Adopted_0.pdf"
      }
     ]
    },
    {
     "uuid": "c00b1cec-7990-5779-b1cf-10a2e792f026",
     "title": "NIST AI Risk Management Framework",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "nist_ai_rmf"
      }
     ],
     "rlinks": [
      {
       "href": "https://www.nist.gov/itl/ai-risk-management-framework"
      }
     ]
    },
    {
     "uuid": "6ad9542e-0cd4-52bb-9a0e-4902b8f6b3ab",
     "title": "NIST SP 800-171 — Protecting Controlled Unclassified Information",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "nist_800_171"
      }
     ],
     "rlinks": [
      {
       "href": "https://csrc.nist.gov/pubs/sp/800/171/r3/final"
      }
     ]
    },
    {
     "uuid": "c59939b3-2e4d-575b-878c-2a4ff0ee3ea1",
     "title": "NYDFS Insurance Circular Letter No. 7 (2024)",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "nydfs_cl7"
      }
     ],
     "rlinks": [
      {
       "href": "https://www.dfs.ny.gov/industry-guidance/circular-letters/cl2024-07"
      }
     ]
    },
    {
     "uuid": "84dc5e0b-1ce3-5738-b78c-60e2d87d6b42",
     "title": "OMB M-25-21 — Accelerating Federal Use of AI",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "m_25_21"
      }
     ],
     "rlinks": [
      {
       "href": "https://www.whitehouse.gov/wp-content/uploads/2025/02/M-25-21-Accelerating-Federal-Use-of-AI-through-Innovation-Governance-and-Public-Trust.pdf"
      }
     ]
    },
    {
     "uuid": "ae7bd07d-92c3-5ea1-915d-6542ebb67973",
     "title": "OMB M-25-22 — Driving Efficient Acquisition of AI in Government",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "m_25_22"
      }
     ],
     "rlinks": [
      {
       "href": "https://www.whitehouse.gov/wp-content/uploads/2025/02/M-25-22-Driving-Efficient-Acquisition-of-Artificial-Intelligence-in-Government.pdf"
      }
     ]
    },
    {
     "uuid": "8e4fc90b-6135-5c7a-81da-30efe01e36ad",
     "title": "ONC HTI-1 Final Rule (45 CFR 170.315)",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "onc_hti1"
      }
     ],
     "rlinks": [
      {
       "href": "https://www.healthit.gov/topic/laws-regulation-and-policy/health-data-technology-and-interoperability"
      }
     ]
    },
    {
     "uuid": "c403b49d-9023-519a-a9f4-fefbab79a3ce",
     "title": "OWASP Top 10 for Large Language Model Applications",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "owasp_llm"
      }
     ],
     "rlinks": [
      {
       "href": "https://owasp.org/www-project-top-10-for-large-language-model-applications/"
      }
     ]
    },
    {
     "uuid": "3f564f95-c419-5856-82e2-62e4a8215e87",
     "title": "SR 26-2 — Revised Guidance on Model Risk Management",
     "props": [
      {
       "name": "framework-key",
       "ns": "https://aisharedresponsibility.com/ns/oscal",
       "value": "sr26_2"
      }
     ],
     "rlinks": [
      {
       "href": "https://www.federalreserve.gov/supervisionreg/srletters/SR2602.htm"
      }
     ]
    }
   ]
  }
 }
}
