Framework / requirementDesigned to support alignment with
NIST AI RMFAI risk identification, governance, measurement, testing, human oversight, lifecycle monitoring
NIST AI 600-1 Generative AI ProfileGrounding, output validation, provenance, model governance, testing and evaluation
NIST SP 800-53 Rev. 5.2.0Security/privacy control architecture, access control, audit, configuration, monitoring and system integrity
NIST SP 800-207 Zero TrustExplicit authentication and authorization before access to protected information
NIST SP 800-171 Rev. 3CUI safeguards for applicable nonfederal systems and contractual environments
Federal Records ActRecords lifecycle, provenance, preservation and disposition governance
M-23-07Electronic records transition and eventual NARA transfer
36 CFR 1236 D/ETemporary and permanent records digitization requirements
NARA AI Guidance AC 11.2026Records-management treatment of qualifying AI-related materials
OMB M-25-21Federal AI adoption, governance and high-impact AI risk management
OMB M-25-22Performance-based and vendor-neutral federal AI acquisition