# NIST AI RMF — Concordia Engineering Controls Mapping

Mapping date: **2026-04-23**

Scope: Phase 179 Concordia task `179.1.3.3`.

This document maps the four functions of the NIST AI Risk Management Framework
(AI RMF 1.0, January 2023) — **Govern, Map, Measure, Manage** — plus the
Generative AI Profile (NIST AI 600-1, July 2024) onto concrete Concordia
engineering controls, Phase 179 task pointers, and per-harm testable acceptance
criteria specific to mediation.

Sources:

- NIST AI Risk Management Framework 1.0:
  https://www.nist.gov/itl/ai-risk-management-framework (fetched 2026-04-23).
- NIST AI RMF Generative AI Profile (NIST AI 600-1):
  https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf (July 2024).

The RMF is non-binding guidance that organizes risk work, not a law Concordia
must satisfy. This mapping is an engineering artifact: it anchors Concordia's
risk work in a shared taxonomy that aligns with AAA / JAMS institutional ADR
posture, EU AI Act expectations
([`eu-ai-act-mapping.md`](./eu-ai-act-mapping.md) §Art. 9), and the UNCITRAL ODR
principles at [`uncitral-odr-mapping.md`](./uncitral-odr-mapping.md).

The four functions apply iteratively: an action taken under `Manage` produces
signals that feed the next `Measure` pass, which updates `Map`, which informs
`Govern` decisions. This is not a one-time compliance exercise.

---

## Table of contents

1. [Mediation-specific harms taxonomy](#mediation-specific-harms-taxonomy)
2. [Govern](#1-govern)
3. [Map](#2-map)
4. [Measure](#3-measure)
5. [Manage](#4-manage)
6. [Generative AI Profile additions](#generative-ai-profile-additions)
7. [Per-harm control matrix](#per-harm-control-matrix)
8. [Living risk register](#living-risk-register)
9. [Named gaps and follow-ups](#named-gaps-and-follow-ups)

---

## Mediation-specific harms taxonomy

NIST AI RMF expects each organization to define its harms taxonomy. Concordia's
is derived from the Phase 179 research corpus (LLMediator, Robots in the Middle,
ProMediate, Mediator.ai self-disclosed risks, Kleros critique) and the
hard-boundary enumeration at §179.1.2.2.

The taxonomy has eight harm families:

| Harm family                    | Short description                                                                                                                                                                              |
| ------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **H1 privacy-leak**            | Private party fields (statements, BATNA, reservation point, confidential concession) leaking across parties, to reviewers without scope, to logs, to training corpora, or to external systems. |
| **H2 preference-misinference** | Concordia infers a utility model that is wrong, unstable, paraphrase-sensitive, order-dependent, or misaligned with the party's actual interests.                                              |
| **H3 strategic-manipulation**  | A party manipulates Concordia through false BATNA, inconsistent statements, collusion, coercion, or prompt injection to obtain a disproportionate outcome.                                     |
| **H4 specification-gaming**    | An agreement scores highly under the utility model but contains brittle, exploitative, vague, unconscionable, or one-sided clauses the utility function does not penalize.                     |
| **H5 unauthorized-acceptance** | Concordia (or an agent Concordia supports) accepts a term outside authority bounds, without required reviewers, or on behalf of a party lacking capacity.                                      |
| **H6 hard-boundary-breach**    | Concordia produces an output it is meant to refuse (custody decisions, medical settlements, coercive-control operationalization, immigration decisions, criminal-matter settlements, etc.).    |
| **H7 biased-outcome**          | Concordia's recommendations systematically favor one party type over another along protected-class or power-asymmetry axes without principled justification.                                   |
| **H8 reliability-failure**     | Concordia is unavailable, produces inconsistent results between runs, fails to reproduce an accepted agreement, or degrades in accuracy / robustness without triggering a release-gate block.  |

Every control below maps back to one or more of these harm families.

---

## 1. Govern

**NIST AI RMF Govern function.** Establish and cultivate a culture of risk
management; policies, roles, accountabilities, and organizational structures
that enable the other three functions.

**Concordia engineering controls.**

- **G-01. Product-boundary policy.** The use-case-class enumeration at
  §179.1.2.1 and the hard-boundary enumeration at §179.1.2.2 are the
  product-boundary policy as code. They name what Concordia will not do, tied to
  testable predicates (`isEligibleForConcordia`, `isRehabilitableByReview`,
  `strictestSeverity`). Relevant harms: H5, H6, H7.
- **G-02. Escalation policy.** The escalation composition at §179.1.2.5 is the
  formal policy mapping case signals to reviewer queues and dual-control
  requirements. Relevant harms: H3, H5, H6.
- **G-03. Consent ledger.** The consent module at §179.1.2.4 enforces
  per-purpose, informed, revocable consent. Relevant harms: H1, H7.
- **G-04. Governance review gate.** §179.10.7 requires governance approval of
  use-case boundaries, high-risk routing, human oversight, audit logging, data
  retention, model cards, and incident response before release. Relevant harms:
  all.
- **G-05. Refresh gate.** The research refresh gate at
  [`../research/refresh-gate.md`](../research/refresh-gate.md) reopens the
  policy surface at every phase transition, pilot launch, and 90-day idle
  interval. Relevant harms: all.
- **G-06. Incident reporting.** §179.5.3.4 incident reporting for unsafe
  recommendations, privacy leaks, biased outcomes, unauthorized acceptance,
  execution mismatch. Feeds the risk register under
  [`risk-register.md`](#living-risk-register). Relevant harms: all.
- **G-07. Kill-switch.** §179.5.5.3 kill-switch and feature-flag controls for
  mediation model routing, autonomous acceptance, smart-contract execution,
  search kernels, and domain adapters. Relevant harms: all.
- **G-08. Role-based access.** §179.2.5.2 RBAC / ABAC policies with tenant and
  case-level isolation. Relevant harms: H1, H5.

---

## 2. Map

**NIST AI RMF Map function.** Establish context; map risks and benefits to the
AI system's intended use, domain, end users, and foreseeable misuse.

**Concordia engineering controls.**

- **M-01. Use-case taxonomy.** The 14 `ConcordiaUseCaseClass` values
  (§179.1.2.1) partition the product surface into explicitly-scoped operational
  contexts. Each class carries a risk tier and required reviewers. Maps to H5,
  H6, H7.
- **M-02. Hard-boundary surface.** The 12 `HardBoundaryKind` values (§179.1.2.2)
  enumerate the categories Concordia refuses to produce autonomously. Maps to
  H5, H6.
- **M-03. Threat model.** §179.5.2.\*, §179.7.6.4, §179.8.3 enumerate the
  adversarial mapping: bluffing BATNA, false evidence, emotional manipulation,
  prompt injection, private-info fishing, hidden side deals, collusion, delay
  tactics, specification gaming, agent collusion, budget escalation,
  side-channel leakage. Maps to H2, H3, H4.
- **M-04. Sensitive-attribute inference posture.** §179.3.3.5 requires that
  cultural / organizational fairness profiles not drive demographic-driven
  disparate treatment. Maps to H7.
- **M-05. Failure-mode enumeration.** §179.3.2.4 preference-stability tests
  (paraphrase, prompt-template, model-version, order-effect, adversarial
  framing) map the known failure modes of LLM-based preference inference. Maps
  to H2.
- **M-06. Third-party model registry.** Concordia integrates third- party GPAI
  models (Anthropic, OpenAI, local via Nous). The registry of which models are
  used where is a follow-up (see named gaps). Maps to H8.
- **M-07. Deployment-context taxonomy.** Per-tenant configuration at §179.6.3.5
  captures legal disclaimers, eligible use cases, model routing, review
  thresholds, data residency, execution adapters, and retention policy. Maps to
  all harms — tenant config is how the organization's context enters the system.

---

## 3. Measure

**NIST AI RMF Measure function.** Use quantitative, qualitative, or mixed-method
tools to analyze, assess, benchmark, and monitor AI risks.

**Concordia engineering controls.**

- **Me-01. Fairness metrics.** §179.3.3.4 — Nash product, utilitarian sum,
  max-min, egalitarian welfare, Kalai-Smorodinsky proportional gains, envy,
  regret, inequality, burden symmetry, procedural dignity. Maps to H7.
- **Me-02. Subjective-value instrument.** §179.8.2.2 — perceived fairness,
  dignity, procedural transparency, relationship preservation, voice, control,
  willingness to use again. Maps to H7.
- **Me-03. Preference-stability tests.** §179.3.2.4 — paraphrase,
  prompt-template, model-version, order-effect, adversarial framing. Maps to H2.
- **Me-04. Uncertainty outputs.** §179.3.2.5 — posterior mean, credible
  interval, comparison count, nearest known comparison, instability warnings.
  Maps to H2.
- **Me-05. Privacy red-team.** §179.5.1.5 — prompt injection, tool exfiltration,
  summary leakage, side-channel inference, shared-explanation leakage. Maps to
  H1.
- **Me-06. Adversarial red-team.** §179.8.3 — bluffing BATNA, false evidence,
  emotional manipulation, prompt injection, private-info fishing, hidden side
  deals, collusion, delay tactics, bad-faith leverage seeking. Maps to H2, H3,
  H4, H7.
- **Me-07. Clause-exploit tests.** §179.8.3.3 — ambiguous deadlines,
  unconstrained waiver, impossible deliverable, unconscionable penalty, hidden
  fee, one-sided confidentiality, assignment trap, perpetual license overreach.
  Maps to H4.
- **Me-08. Benchmark harness.** `testing/concordia/` with synthetic two-party,
  multi-party, procurement, legal-low-stakes, DAO, creative, restorative, and
  agent-to-agent suites (§179.8.1.\*). Maps to H2, H4, H7, H8.
- **Me-09. Outcome metrics.** §179.8.2.\* — agreement rate, Pareto efficiency,
  Nash product, Kalai-Smorodinsky distance, welfare sum, max-min utility, envy,
  regret, candidate diversity, stability under preference uncertainty,
  subjective value, domain-specific metrics (procurement savings, DPO change,
  moderation recurrence, DAO proposal pass rate, creative delivery acceptance),
  cost (model spend, search iterations, human review minutes, latency, GPU
  time), safety (privacy leaks, redline violations, legal-review misses,
  coercion flags, biased outcomes, hallucinated law/policy, unenforceable clause
  rate). Maps to all harms.
- **Me-10. Observability.** §179.6.3.4 — traces per case, scoring cost, model
  latency, candidate diversity, preference uncertainty, agreement rate,
  escalation rate, privacy-gate failures. Maps to H1, H8.
- **Me-11. Reliability and SLO tracking.** Not a Phase 179 task yet; a Phase C
  follow-up for Concordia uptime / latency SLOs consumed by tenant SLAs. Maps to
  H8.

---

## 4. Manage

**NIST AI RMF Manage function.** Allocate risk resources, prioritize and respond
to identified risks, and ensure ongoing treatment. This is where controls become
actions.

**Concordia engineering controls.**

- **Mn-01. Release gates.** §179.10.\* — contract drift (10.1), unit coverage
  (10.2), integration coverage (10.3), Playwright coverage (10.4), privacy
  security tests (10.5), benchmark thresholds (10.6), governance review (10.7),
  pilot success (10.8), repo integration (10.9), authorization automation
  (10.10), consent / evidence tests (10.11), accessibility automation (10.12),
  settlement lifecycle (10.13), training-data gates (10.14). Maps to all harms.
- **Mn-02. Reviewer queues with SLA.** §179.5.5.1 — queue SLA, assignment
  policy, dual-control for high-risk cases, calibration review, audit sampling,
  escalation when no qualified reviewer is available, blocked launch for
  unstaffed gates. Maps to H3, H5, H6, H7.
- **Mn-03. Kill-switch / feature-flag rollback.** §179.5.5.3. Maps to H5, H8.
- **Mn-04. Cooling-off and delayed confirmation.** §179.5.2.5. Maps to H3, H5.
- **Mn-05. Quarantine on consent revocation.** §179.5.4.2 — stop future
  processing, quarantine derived utility models, notify affected reviewers,
  preserve legally-required audit records, explain what cannot be deleted. Maps
  to H1.
- **Mn-06. Model and optimizer version pinning.** §179.5.3.3 — every accepted
  agreement can be reproduced exactly. Maps to H8.
- **Mn-07. Incident response.** §179.5.3.4 feeds the refresh gate (§R5) and the
  risk register. Maps to all harms.
- **Mn-08. Continuous research refresh.** The refresh gate at
  [`../research/refresh-gate.md`](../research/refresh-gate.md). Maps to all
  harms — competitor, regulatory, and academic state change is the "post-market
  data" NIST expects operators to integrate.

---

## Generative AI Profile additions

NIST AI 600-1 Generative AI Profile (July 2024) adds twelve GenAI- specific risk
categories. Concordia's mapping:

| GAI Profile risk                       | Concordia control                                                                                         | Harm family |
| -------------------------------------- | --------------------------------------------------------------------------------------------------------- | ----------- |
| CBRN weapons                           | Not applicable; Concordia refuses via refresh-gate policy review (tenant onboarding)                      | —           |
| Confabulation (hallucination)          | §179.3.2.4 stability, §179.2.3.4 clause validator, §179.4.1.5 candidate filter                            | H2, H4      |
| Dangerous, violent, or hateful content | §179.5.2.\* safety gates, §179.1.2.2 boundaries (DV, coercive control)                                    | H6          |
| Data privacy                           | §179.5.1._ isolation, §179.5.4._ consent and chain-of-custody, §179.1.2.4 consent module                  | H1          |
| Environmental impact                   | Tracked via cost metrics (§179.8.2.4); Phase D follow-up for per-decision carbon accounting               | —           |
| Harmful bias and homogenization        | §179.3.3.4 fairness metrics, §179.3.3.5 fairness profiles                                                 | H7          |
| Human-AI configuration                 | §179.1.2.3 operational-mode banners, §179.5.3.1 reviewer queues, §179.6.1.\* workbench roles              | H5          |
| Information integrity                  | §179.2.3.4 clause validator, §179.5.2.3 adversarial candidate tests, §179.5.4.3 evidence chain-of-custody | H4, H3      |
| Information security                   | §179.5.1.2 envelope encryption, KMS, audit logs; §179.2.5.5 rate limits / abuse throttles                 | H1          |
| Intellectual property                  | §179.7.4.5 Themis Universal Originality Shield integration for IP disputes                                | —           |
| Obscene, degrading, or abusive content | §179.5.2.\* safety gates, tenant onboarding policy                                                        | H6          |
| Value chain and component integration  | §179.5.3.3 version pinning, GPAI model registry (see gaps), §179.5.5.5 training-data governance           | H8          |

---

## Per-harm control matrix

For each mediation-specific harm, the primary controls that mitigate it. This is
the quick-reference the Concordia engineering team uses when a new task touches
a harm family.

**H1 privacy-leak** — G-03 (consent ledger), G-08 (RBAC / ABAC), M-07 (tenant
config), Me-05 (privacy red-team), Me-10 (observability), Mn-05 (quarantine on
revocation).

**H2 preference-misinference** — M-05 (failure-mode enumeration), Me-03
(stability tests), Me-04 (uncertainty outputs), Me-08 (benchmark harness), Mn-08
(continuous refresh).

**H3 strategic-manipulation** — G-02 (escalation policy), M-03 (threat model),
Me-06 (adversarial red-team), Mn-02 (reviewer queues with SLA), Mn-04
(cooling-off).

**H4 specification-gaming** — M-03 (threat model), Me-06 (adversarial red-team),
Me-07 (clause-exploit tests), Me-08 (benchmark harness), Mn-01 (release gates).

**H5 unauthorized-acceptance** — G-01 (product-boundary policy), G-02
(escalation policy), G-07 (kill-switch), G-08 (RBAC / ABAC), M-01 (use-case
taxonomy), M-02 (hard-boundary surface), Mn-02 (reviewer queues).

**H6 hard-boundary-breach** — G-01 (product-boundary policy), M-02
(hard-boundary surface), Mn-01 (release gates), Mn-02 (reviewer queues).

**H7 biased-outcome** — G-03 (consent ledger), M-04 (sensitive-attribute
posture), Me-01 (fairness metrics), Me-02 (subjective-value instrument), Me-06
(adversarial red-team).

**H8 reliability-failure** — M-06 (third-party model registry), Me-10
(observability), Me-11 (SLO tracking), Mn-03 (kill-switch / rollback), Mn-06
(version pinning), Mn-08 (continuous refresh).

---

## Living risk register

The **risk register** is a versioned document Concordia maintains that
enumerates, for each active harm:

- Harm family (H1–H8) and short description.
- Probability estimate (qualitative: low / moderate / high).
- Severity estimate (qualitative: minor / moderate / significant / critical).
- Treatment status (accepted / mitigated / transferred / avoided).
- Controls currently in place (mapped to G-_ / M-_ / Me-_ / Mn-_).
- Last update date.
- Incidents observed that touch this harm (linked to §179.5.3.4 incident
  reports).
- Next review date.

The register is created under `docs/compliance/risk-register.md` as part of this
mapping's follow-up (see gaps). It is updated at every refresh-gate firing
([`../research/refresh-gate.md`](../research/refresh-gate.md) §R1) and at every
pilot launch.

---

## Named gaps and follow-ups

- **risk-register.md** as a living document. Add under `179.1.3.3` (this task's
  natural follow-up). Template:

  ```markdown
  ## R-#### — <short name>

  - Harm family: H<N>
  - Probability / severity: <low|moderate|high> /
    <minor|moderate|significant|critical>
  - Treatment: <accepted | mitigated | transferred | avoided>
  - Controls: [G-01, Me-01, Mn-02]
  - Incidents: [#INC-123, #INC-145]
  - Last update: YYYY-MM-DD
  - Next review: YYYY-MM-DD
  ```

- **Reliability SLO definitions** (Me-11). Not a Phase 179 task today; Phase C
  follow-up.
- **Carbon / environmental cost tracking per decision** (GAI Profile
  environmental impact). Phase D follow-up.
- **GPAI model registry** with AI Act posture and NIST mapping. Add under
  `179.5.5.5`.
- **Per-tenant risk-register overlays** for tenants whose jurisdiction or
  use-case profile adds Concordia-specific harms (e.g., an EU `legal_claim`
  tenant inherits additional AI Act Article 9 risks). Add under `179.6.3.5`.

---

## Refresh policy

The NIST AI RMF and its GenAI Profile are updated periodically; check for new
versions at every refresh-gate firing per
[`../research/refresh-gate.md`](../research/refresh-gate.md) §R3. If NIST
publishes a new profile or revises the four-function definitions, re-run this
mapping and update the per-harm control matrix.
