Disciplines · Compliance

NIST AI RMF — Concordia Engineering Controls Mapping

1.

11sections12 minread

On this page

Mapping date: 2026-04-23

Scope: Phase 179 Concordia task 179.1.3.3.

This document maps the four functions of the NIST AI Risk Management Framework (AI RMF 1.0, January 2023) — Govern, Map, Measure, Manage — plus the Generative AI Profile (NIST AI 600-1, July 2024) onto concrete Concordia engineering controls, Phase 179 task pointers, and per-harm testable acceptance criteria specific to mediation.

Sources:

  • NIST AI Risk Management Framework 1.0: https://www.nist.gov/itl/ai-risk-management-framework (fetched 2026-04-23).
  • NIST AI RMF Generative AI Profile (NIST AI 600-1): https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf (July 2024).

The RMF is non-binding guidance that organizes risk work, not a law Concordia must satisfy. This mapping is an engineering artifact: it anchors Concordia's risk work in a shared taxonomy that aligns with AAA / JAMS institutional ADR posture, EU AI Act expectations (eu-ai-act-mapping.md §Art. 9), and the UNCITRAL ODR principles at uncitral-odr-mapping.md.

The four functions apply iteratively: an action taken under Manage produces signals that feed the next Measure pass, which updates Map, which informs Govern decisions. This is not a one-time compliance exercise.


Table of contents#

  1. Mediation-specific harms taxonomy
  2. Govern
  3. Map
  4. Measure
  5. Manage
  6. Generative AI Profile additions
  7. Per-harm control matrix
  8. Living risk register
  9. Named gaps and follow-ups

Mediation-specific harms taxonomy#

NIST AI RMF expects each organization to define its harms taxonomy. Concordia's is derived from the Phase 179 research corpus (LLMediator, Robots in the Middle, ProMediate, Mediator.ai self-disclosed risks, Kleros critique) and the hard-boundary enumeration at §179.1.2.2.

The taxonomy has eight harm families:

Harm family Short description
H1 privacy-leak Private party fields (statements, BATNA, reservation point, confidential concession) leaking across parties, to reviewers without scope, to logs, to training corpora, or to external systems.
H2 preference-misinference Concordia infers a utility model that is wrong, unstable, paraphrase-sensitive, order-dependent, or misaligned with the party's actual interests.
H3 strategic-manipulation A party manipulates Concordia through false BATNA, inconsistent statements, collusion, coercion, or prompt injection to obtain a disproportionate outcome.
H4 specification-gaming An agreement scores highly under the utility model but contains brittle, exploitative, vague, unconscionable, or one-sided clauses the utility function does not penalize.
H5 unauthorized-acceptance Concordia (or an agent Concordia supports) accepts a term outside authority bounds, without required reviewers, or on behalf of a party lacking capacity.
H6 hard-boundary-breach Concordia produces an output it is meant to refuse (custody decisions, medical settlements, coercive-control operationalization, immigration decisions, criminal-matter settlements, etc.).
H7 biased-outcome Concordia's recommendations systematically favor one party type over another along protected-class or power-asymmetry axes without principled justification.
H8 reliability-failure Concordia is unavailable, produces inconsistent results between runs, fails to reproduce an accepted agreement, or degrades in accuracy / robustness without triggering a release-gate block.

Every control below maps back to one or more of these harm families.


1. Govern#

NIST AI RMF Govern function. Establish and cultivate a culture of risk management; policies, roles, accountabilities, and organizational structures that enable the other three functions.

Concordia engineering controls.

  • G-01. Product-boundary policy. The use-case-class enumeration at §179.1.2.1 and the hard-boundary enumeration at §179.1.2.2 are the product-boundary policy as code. They name what Concordia will not do, tied to testable predicates (isEligibleForConcordia, isRehabilitableByReview, strictestSeverity). Relevant harms: H5, H6, H7.
  • G-02. Escalation policy. The escalation composition at §179.1.2.5 is the formal policy mapping case signals to reviewer queues and dual-control requirements. Relevant harms: H3, H5, H6.
  • G-03. Consent ledger. The consent module at §179.1.2.4 enforces per-purpose, informed, revocable consent. Relevant harms: H1, H7.
  • G-04. Governance review gate. §179.10.7 requires governance approval of use-case boundaries, high-risk routing, human oversight, audit logging, data retention, model cards, and incident response before release. Relevant harms: all.
  • G-05. Refresh gate. The research refresh gate at ../research/refresh-gate.md reopens the policy surface at every phase transition, pilot launch, and 90-day idle interval. Relevant harms: all.
  • G-06. Incident reporting. §179.5.3.4 incident reporting for unsafe recommendations, privacy leaks, biased outcomes, unauthorized acceptance, execution mismatch. Feeds the risk register under risk-register.md. Relevant harms: all.
  • G-07. Kill-switch. §179.5.5.3 kill-switch and feature-flag controls for mediation model routing, autonomous acceptance, smart-contract execution, search kernels, and domain adapters. Relevant harms: all.
  • G-08. Role-based access. §179.2.5.2 RBAC / ABAC policies with tenant and case-level isolation. Relevant harms: H1, H5.

2. Map#

NIST AI RMF Map function. Establish context; map risks and benefits to the AI system's intended use, domain, end users, and foreseeable misuse.

Concordia engineering controls.

  • M-01. Use-case taxonomy. The 14 ConcordiaUseCaseClass values (§179.1.2.1) partition the product surface into explicitly-scoped operational contexts. Each class carries a risk tier and required reviewers. Maps to H5, H6, H7.
  • M-02. Hard-boundary surface. The 12 HardBoundaryKind values (§179.1.2.2) enumerate the categories Concordia refuses to produce autonomously. Maps to H5, H6.
  • M-03. Threat model. §179.5.2.*, §179.7.6.4, §179.8.3 enumerate the adversarial mapping: bluffing BATNA, false evidence, emotional manipulation, prompt injection, private-info fishing, hidden side deals, collusion, delay tactics, specification gaming, agent collusion, budget escalation, side-channel leakage. Maps to H2, H3, H4.
  • M-04. Sensitive-attribute inference posture. §179.3.3.5 requires that cultural / organizational fairness profiles not drive demographic-driven disparate treatment. Maps to H7.
  • M-05. Failure-mode enumeration. §179.3.2.4 preference-stability tests (paraphrase, prompt-template, model-version, order-effect, adversarial framing) map the known failure modes of LLM-based preference inference. Maps to H2.
  • M-06. Third-party model registry. Concordia integrates third- party GPAI models (Anthropic, OpenAI, local via Nous). The registry of which models are used where is a follow-up (see named gaps). Maps to H8.
  • M-07. Deployment-context taxonomy. Per-tenant configuration at §179.6.3.5 captures legal disclaimers, eligible use cases, model routing, review thresholds, data residency, execution adapters, and retention policy. Maps to all harms — tenant config is how the organization's context enters the system.

3. Measure#

NIST AI RMF Measure function. Use quantitative, qualitative, or mixed-method tools to analyze, assess, benchmark, and monitor AI risks.

Concordia engineering controls.

  • Me-01. Fairness metrics. §179.3.3.4 — Nash product, utilitarian sum, max-min, egalitarian welfare, Kalai-Smorodinsky proportional gains, envy, regret, inequality, burden symmetry, procedural dignity. Maps to H7.
  • Me-02. Subjective-value instrument. §179.8.2.2 — perceived fairness, dignity, procedural transparency, relationship preservation, voice, control, willingness to use again. Maps to H7.
  • Me-03. Preference-stability tests. §179.3.2.4 — paraphrase, prompt-template, model-version, order-effect, adversarial framing. Maps to H2.
  • Me-04. Uncertainty outputs. §179.3.2.5 — posterior mean, credible interval, comparison count, nearest known comparison, instability warnings. Maps to H2.
  • Me-05. Privacy red-team. §179.5.1.5 — prompt injection, tool exfiltration, summary leakage, side-channel inference, shared-explanation leakage. Maps to H1.
  • Me-06. Adversarial red-team. §179.8.3 — bluffing BATNA, false evidence, emotional manipulation, prompt injection, private-info fishing, hidden side deals, collusion, delay tactics, bad-faith leverage seeking. Maps to H2, H3, H4, H7.
  • Me-07. Clause-exploit tests. §179.8.3.3 — ambiguous deadlines, unconstrained waiver, impossible deliverable, unconscionable penalty, hidden fee, one-sided confidentiality, assignment trap, perpetual license overreach. Maps to H4.
  • Me-08. Benchmark harness. testing/concordia/ with synthetic two-party, multi-party, procurement, legal-low-stakes, DAO, creative, restorative, and agent-to-agent suites (§179.8.1.*). Maps to H2, H4, H7, H8.
  • Me-09. Outcome metrics. §179.8.2.* — agreement rate, Pareto efficiency, Nash product, Kalai-Smorodinsky distance, welfare sum, max-min utility, envy, regret, candidate diversity, stability under preference uncertainty, subjective value, domain-specific metrics (procurement savings, DPO change, moderation recurrence, DAO proposal pass rate, creative delivery acceptance), cost (model spend, search iterations, human review minutes, latency, GPU time), safety (privacy leaks, redline violations, legal-review misses, coercion flags, biased outcomes, hallucinated law/policy, unenforceable clause rate). Maps to all harms.
  • Me-10. Observability. §179.6.3.4 — traces per case, scoring cost, model latency, candidate diversity, preference uncertainty, agreement rate, escalation rate, privacy-gate failures. Maps to H1, H8.
  • Me-11. Reliability and SLO tracking. Not a Phase 179 task yet; a Phase C follow-up for Concordia uptime / latency SLOs consumed by tenant SLAs. Maps to H8.

4. Manage#

NIST AI RMF Manage function. Allocate risk resources, prioritize and respond to identified risks, and ensure ongoing treatment. This is where controls become actions.

Concordia engineering controls.

  • Mn-01. Release gates. §179.10.* — contract drift (10.1), unit coverage (10.2), integration coverage (10.3), Playwright coverage (10.4), privacy security tests (10.5), benchmark thresholds (10.6), governance review (10.7), pilot success (10.8), repo integration (10.9), authorization automation (10.10), consent / evidence tests (10.11), accessibility automation (10.12), settlement lifecycle (10.13), training-data gates (10.14). Maps to all harms.
  • Mn-02. Reviewer queues with SLA. §179.5.5.1 — queue SLA, assignment policy, dual-control for high-risk cases, calibration review, audit sampling, escalation when no qualified reviewer is available, blocked launch for unstaffed gates. Maps to H3, H5, H6, H7.
  • Mn-03. Kill-switch / feature-flag rollback. §179.5.5.3. Maps to H5, H8.
  • Mn-04. Cooling-off and delayed confirmation. §179.5.2.5. Maps to H3, H5.
  • Mn-05. Quarantine on consent revocation. §179.5.4.2 — stop future processing, quarantine derived utility models, notify affected reviewers, preserve legally-required audit records, explain what cannot be deleted. Maps to H1.
  • Mn-06. Model and optimizer version pinning. §179.5.3.3 — every accepted agreement can be reproduced exactly. Maps to H8.
  • Mn-07. Incident response. §179.5.3.4 feeds the refresh gate (§R5) and the risk register. Maps to all harms.
  • Mn-08. Continuous research refresh. The refresh gate at ../research/refresh-gate.md. Maps to all harms — competitor, regulatory, and academic state change is the "post-market data" NIST expects operators to integrate.

Generative AI Profile additions#

NIST AI 600-1 Generative AI Profile (July 2024) adds twelve GenAI- specific risk categories. Concordia's mapping:

GAI Profile risk Concordia control Harm family
CBRN weapons Not applicable; Concordia refuses via refresh-gate policy review (tenant onboarding)
Confabulation (hallucination) §179.3.2.4 stability, §179.2.3.4 clause validator, §179.4.1.5 candidate filter H2, H4
Dangerous, violent, or hateful content §179.5.2.* safety gates, §179.1.2.2 boundaries (DV, coercive control) H6
Data privacy §179.5.1._ isolation, §179.5.4._ consent and chain-of-custody, §179.1.2.4 consent module H1
Environmental impact Tracked via cost metrics (§179.8.2.4); Phase D follow-up for per-decision carbon accounting
Harmful bias and homogenization §179.3.3.4 fairness metrics, §179.3.3.5 fairness profiles H7
Human-AI configuration §179.1.2.3 operational-mode banners, §179.5.3.1 reviewer queues, §179.6.1.* workbench roles H5
Information integrity §179.2.3.4 clause validator, §179.5.2.3 adversarial candidate tests, §179.5.4.3 evidence chain-of-custody H4, H3
Information security §179.5.1.2 envelope encryption, KMS, audit logs; §179.2.5.5 rate limits / abuse throttles H1
Intellectual property §179.7.4.5 Themis Universal Originality Shield integration for IP disputes
Obscene, degrading, or abusive content §179.5.2.* safety gates, tenant onboarding policy H6
Value chain and component integration §179.5.3.3 version pinning, GPAI model registry (see gaps), §179.5.5.5 training-data governance H8

Per-harm control matrix#

For each mediation-specific harm, the primary controls that mitigate it. This is the quick-reference the Concordia engineering team uses when a new task touches a harm family.

H1 privacy-leak — G-03 (consent ledger), G-08 (RBAC / ABAC), M-07 (tenant config), Me-05 (privacy red-team), Me-10 (observability), Mn-05 (quarantine on revocation).

H2 preference-misinference — M-05 (failure-mode enumeration), Me-03 (stability tests), Me-04 (uncertainty outputs), Me-08 (benchmark harness), Mn-08 (continuous refresh).

H3 strategic-manipulation — G-02 (escalation policy), M-03 (threat model), Me-06 (adversarial red-team), Mn-02 (reviewer queues with SLA), Mn-04 (cooling-off).

H4 specification-gaming — M-03 (threat model), Me-06 (adversarial red-team), Me-07 (clause-exploit tests), Me-08 (benchmark harness), Mn-01 (release gates).

H5 unauthorized-acceptance — G-01 (product-boundary policy), G-02 (escalation policy), G-07 (kill-switch), G-08 (RBAC / ABAC), M-01 (use-case taxonomy), M-02 (hard-boundary surface), Mn-02 (reviewer queues).

H6 hard-boundary-breach — G-01 (product-boundary policy), M-02 (hard-boundary surface), Mn-01 (release gates), Mn-02 (reviewer queues).

H7 biased-outcome — G-03 (consent ledger), M-04 (sensitive-attribute posture), Me-01 (fairness metrics), Me-02 (subjective-value instrument), Me-06 (adversarial red-team).

H8 reliability-failure — M-06 (third-party model registry), Me-10 (observability), Me-11 (SLO tracking), Mn-03 (kill-switch / rollback), Mn-06 (version pinning), Mn-08 (continuous refresh).


Living risk register#

The risk register is a versioned document Concordia maintains that enumerates, for each active harm:

  • Harm family (H1–H8) and short description.
  • Probability estimate (qualitative: low / moderate / high).
  • Severity estimate (qualitative: minor / moderate / significant / critical).
  • Treatment status (accepted / mitigated / transferred / avoided).
  • Controls currently in place (mapped to G-_ / M-_ / Me-_ / Mn-_).
  • Last update date.
  • Incidents observed that touch this harm (linked to §179.5.3.4 incident reports).
  • Next review date.

The register is created under docs/compliance/risk-register.md as part of this mapping's follow-up (see gaps). It is updated at every refresh-gate firing (../research/refresh-gate.md §R1) and at every pilot launch.


Named gaps and follow-ups#

  • risk-register.md as a living document. Add under 179.1.3.3 (this task's natural follow-up). Template:

    markdown
    ## R-#### — <short name>
    
    - Harm family: H<N>
    - Probability / severity: <low|moderate|high> /
      <minor|moderate|significant|critical>
    - Treatment: <accepted | mitigated | transferred | avoided>
    - Controls: [G-01, Me-01, Mn-02]
    - Incidents: [#INC-123, #INC-145]
    - Last update: YYYY-MM-DD
    - Next review: YYYY-MM-DD
    
  • Reliability SLO definitions (Me-11). Not a Phase 179 task today; Phase C follow-up.

  • Carbon / environmental cost tracking per decision (GAI Profile environmental impact). Phase D follow-up.

  • GPAI model registry with AI Act posture and NIST mapping. Add under 179.5.5.5.

  • Per-tenant risk-register overlays for tenants whose jurisdiction or use-case profile adds Concordia-specific harms (e.g., an EU legal_claim tenant inherits additional AI Act Article 9 risks). Add under 179.6.3.5.


Refresh policy#

The NIST AI RMF and its GenAI Profile are updated periodically; check for new versions at every refresh-gate firing per ../research/refresh-gate.md §R3. If NIST publishes a new profile or revises the four-function definitions, re-run this mapping and update the per-harm control matrix.