{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","contextIds":["risk:ai-accountability-liability","risk:ai-adversarial-poisoning-attacks","risk:ai-agent-unauthorized-actions","risk:ai-bias-discrimination","risk:ai-catastrophic-cyber-misuse","risk:ai-emergent-integration-risk","risk:ai-endpoint-abuse-model-extraction","risk:ai-highrisk-law-enforcement","risk:ai-inaccurate-unreliable-output","risk:ai-inappropriate-task-allocation","risk:ai-insufficient-human-oversight","risk:ai-model-drift-monitoring","risk:ai-model-resilience-fallback-gap","risk:ai-privacy-leakage","risk:ai-safety-harm-to-people","risk:ai-secrets-credential-leakage","risk:aware-user-error-mishandling","risk:config-internet-exposed-misconfig","risk:data-breach-unauthorized-disclosure","risk:data-exfiltration-espionage","risk:data-privacy-program-noncompliance","risk:privacy-cross-border-transfer","risk:sdlc-vulnerabilities-in-software","risk:vuln-inadequate-testing-scanning","risk:vuln-unpatched-known-flaws","uc:UC-AI-05","uc:UC-AI-07","uc:UC-AI-08","uc:UC-AI-18","uc:UC-AI-19","uc:UC-AI-20","uc:UC-DATA-11","uc:UC-VULN-02"],"directIds":["ctrl:nist-ai-tevv-athlon:NIST-TEVV-01","ctrl:nist-ai-tevv-athlon:NIST-TEVV-02","ctrl:nist-ai-tevv-athlon:NIST-TEVV-03","ctrl:nist-ai-tevv-athlon:NIST-TEVV-04","ctrl:nist-ai-tevv-athlon:NIST-TEVV-05","ctrl:nist-ai-tevv-athlon:NIST-TEVV-06","std:nist-ai-tevv-athlon"],"kind":"bundle","metadata":"/assets/agent_metadata.5c7612c9c5b0b455.json","name":"NIST TEVV-Athlon (draft, Aug 2026)","next":"/assets/agent_sources-nist-ai-tevv-athlon-2.23de0a24cb533d3e.json","page":1,"pageSize":40,"records":[{"attributes":{"category":"administrative","framework":"nist-ai-tevv-athlon","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-ai-tevv-athlon/","description":"The framework starts with organizational goals and the system's operational context, then constructs measurement concepts, test events, and tools that address those objectives.","details":{"automation":"hybrid","control_category":"administrative","control_id":"NIST-TEVV-01","control_type":"detective","domains":[],"framework":"nist-ai-tevv-athlon","group":"AI Evaluation and Agent Security Testing","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":0,"source_pages":"NIST AI 200-2 ipd sections 2.1-2.2, pp. 3-6","source_url":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.200-2.ipd.pdf#page=11","statement":"The framework starts with organizational goals and the system's operational context, then constructs measurement concepts, test events, and tools that address those objectives."},"direct":true,"htmlUrl":"/agents/records/ctrl-nist-ai-tevv-athlon-nist-tevv-01-72145876.html","id":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-01","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-ai-tevv-athlon%3ANIST-TEVV-01","sourceIds":["nist-ai-tevv-athlon"],"sourceUrl":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.200-2.ipd.pdf#page=11","title":"NIST-TEVV-01 — Define evaluation objectives, context, and measurements","type":"control","url":"/assets/agent_record-ctrl-nist-ai-tevv-athlon-nist-tevv-01-72145876.75a8e81397e01b5c.json"},{"attributes":{"category":"technical","framework":"nist-ai-tevv-athlon","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-ai-tevv-athlon/","description":"The framework applies the selected tests and synthesizes their results into evidence about system performance, while interrogating the measurements and what the findings support.","details":{"automation":"hybrid","control_category":"technical","control_id":"NIST-TEVV-02","control_type":"detective","domains":[],"framework":"nist-ai-tevv-athlon","group":"AI Evaluation and Agent Security Testing","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":0,"source_pages":"NIST AI 200-2 ipd sections 2.3-2.4, pp. 6-7","source_url":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.200-2.ipd.pdf#page=14","statement":"The framework applies the selected tests and synthesizes their results into evidence about system performance, while interrogating the measurements and what the findings support."},"direct":true,"htmlUrl":"/agents/records/ctrl-nist-ai-tevv-athlon-nist-tevv-02-41057f6e.html","id":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-02","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-ai-tevv-athlon%3ANIST-TEVV-02","sourceIds":["nist-ai-tevv-athlon"],"sourceUrl":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.200-2.ipd.pdf#page=14","title":"NIST-TEVV-02 — Run evaluations and examine results and limitations","type":"control","url":"/assets/agent_record-ctrl-nist-ai-tevv-athlon-nist-tevv-02-41057f6e.310bfda25fcb8306.json"},{"attributes":{"category":"technical","framework":"nist-ai-tevv-athlon","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-ai-tevv-athlon/","description":"The draft discusses testing in settings that better reflect real use, including interactions with users and the operating environment, to complement model tests and benchmarks.","details":{"automation":"hybrid","control_category":"technical","control_id":"NIST-TEVV-03","control_type":"detective","domains":[],"framework":"nist-ai-tevv-athlon","group":"AI Evaluation and Agent Security Testing","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":0,"source_pages":"NIST AI 200-2 ipd section 4.3.2, pp. 14-15; Appendix C, pp. 25-26","source_url":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.200-2.ipd.pdf#page=22","statement":"The draft discusses testing in settings that better reflect real use, including interactions with users and the operating environment, to complement model tests and benchmarks."},"direct":true,"htmlUrl":"/agents/records/ctrl-nist-ai-tevv-athlon-nist-tevv-03-37642a3d.html","id":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-03","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-ai-tevv-athlon%3ANIST-TEVV-03","sourceIds":["nist-ai-tevv-athlon"],"sourceUrl":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.200-2.ipd.pdf#page=22","title":"NIST-TEVV-03 — Evaluate AI systems in realistic operating settings","type":"control","url":"/assets/agent_record-ctrl-nist-ai-tevv-athlon-nist-tevv-03-37642a3d.1b5b86bb1ab332ae.json"},{"attributes":{"category":"technical","framework":"nist-ai-tevv-athlon","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-ai-tevv-athlon/","description":"Appendix B includes confidentiality attacks that test whether an AI system reveals confidential information or internal functionality, including user information and system-prompt leakage.","details":{"automation":"hybrid","control_category":"technical","control_id":"NIST-TEVV-04","control_type":"detective","domains":[],"framework":"nist-ai-tevv-athlon","group":"AI Evaluation and Agent Security Testing","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":0,"source_pages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Confidentiality attacks","source_url":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.200-2.ipd.pdf#page=32","statement":"Appendix B includes confidentiality attacks that test whether an AI system reveals confidential information or internal functionality, including user information and system-prompt leakage."},"direct":true,"htmlUrl":"/agents/records/ctrl-nist-ai-tevv-athlon-nist-tevv-04-14e991d6.html","id":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-04","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-ai-tevv-athlon%3ANIST-TEVV-04","sourceIds":["nist-ai-tevv-athlon"],"sourceUrl":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.200-2.ipd.pdf#page=32","title":"NIST-TEVV-04 — Test for disclosure of confidential information","type":"control","url":"/assets/agent_record-ctrl-nist-ai-tevv-athlon-nist-tevv-04-14e991d6.a25001afa53f6355.json"},{"attributes":{"category":"technical","framework":"nist-ai-tevv-athlon","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-ai-tevv-athlon/","description":"Appendix B includes integrity tests for direct and indirect prompt injection, poisoning, obfuscated inputs, and retrieval weaknesses that could alter intended outputs or outcomes.","details":{"automation":"hybrid","control_category":"technical","control_id":"NIST-TEVV-05","control_type":"detective","domains":[],"framework":"nist-ai-tevv-athlon","group":"AI Evaluation and Agent Security Testing","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":0,"source_pages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Integrity attacks","source_url":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.200-2.ipd.pdf#page=32","statement":"Appendix B includes integrity tests for direct and indirect prompt injection, poisoning, obfuscated inputs, and retrieval weaknesses that could alter intended outputs or outcomes."},"direct":true,"htmlUrl":"/agents/records/ctrl-nist-ai-tevv-athlon-nist-tevv-05-f9e22b30.html","id":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-05","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-ai-tevv-athlon%3ANIST-TEVV-05","sourceIds":["nist-ai-tevv-athlon"],"sourceUrl":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.200-2.ipd.pdf#page=32","title":"NIST-TEVV-05 — Test direct and indirect prompt injection","type":"control","url":"/assets/agent_record-ctrl-nist-ai-tevv-athlon-nist-tevv-05-f9e22b30.b0eb7471f9aab513.json"},{"attributes":{"category":"technical","framework":"nist-ai-tevv-athlon","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-ai-tevv-athlon/","description":"Appendix B includes tests for misuse of connected tools and external actions, including unsafe tool selection, excessive agency, unauthorized action attempts, and harmful task execution.","details":{"automation":"hybrid","control_category":"technical","control_id":"NIST-TEVV-06","control_type":"detective","domains":[],"framework":"nist-ai-tevv-athlon","group":"AI Evaluation and Agent Security Testing","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":0,"source_pages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Agent / tool abuse testing","source_url":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.200-2.ipd.pdf#page=32","statement":"Appendix B includes tests for misuse of connected tools and external actions, including unsafe tool selection, excessive agency, unauthorized action attempts, and harmful task execution."},"direct":true,"htmlUrl":"/agents/records/ctrl-nist-ai-tevv-athlon-nist-tevv-06-6a69659d.html","id":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-06","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-ai-tevv-athlon%3ANIST-TEVV-06","sourceIds":["nist-ai-tevv-athlon"],"sourceUrl":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.200-2.ipd.pdf#page=32","title":"NIST-TEVV-06 — Test agent tool misuse and unauthorized external actions","type":"control","url":"/assets/agent_record-ctrl-nist-ai-tevv-athlon-nist-tevv-06-6a69659d.9e1f063d50264096.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Governance, Policy & Oversight","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["nist-ai-rmf-risk","iso-23894-ai-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-accountability-liability","description":"Ambiguous responsibility across developers, deployers, and operators means no party is clearly accountable when AI causes harm; organizations face reputational damage, regulatory sanctions, and civil liability from AI failures at scale, and operational disruption when AI is unavailable.","details":{"category":"ai_governance","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"ai-accountability-liability","taxonomies":["nist-ai-rmf-risk","iso-23894-ai-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ai-accountability-liability-193b3f72.html","id":"risk:ai-accountability-liability","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-accountability-liability","sourceIds":["aiuc-1","eu-ai-act","iso-42001","nist-ai-agent-identity","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"AI accountability gaps and organizational liability","type":"risk","url":"/assets/agent_record-risk-ai-accountability-liability-193b3f72.db94603754a465dc.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Secure Development (SDLC) & Application Security","Vulnerability & Patch Management"],"inherent_rating":"high","taxonomy":["nist-ai-rmf-risk","iso-23894-ai-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-adversarial-poisoning-attacks","description":"Data-poisoning corrupts training data and embeds backdoors; adversarial evasion, prompt injection, and jailbreaks fool deployed models at inference; model extraction steals proprietary weights/logic — enabling harmful or policy-violating outputs.","details":{"category":"ai_governance","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"ai-adversarial-poisoning-attacks","taxonomies":["nist-ai-rmf-risk","iso-23894-ai-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ai-adversarial-poisoning-attacks-ea7df068.html","id":"risk:ai-adversarial-poisoning-attacks","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-adversarial-poisoning-attacks","sourceIds":["aiuc-1","cobit-2019","eu-ai-act","iso-27001","iso-42001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"Adversarial attacks, data poisoning and prompt injection","type":"risk","url":"/assets/agent_record-risk-ai-adversarial-poisoning-attacks-ea7df068.68e6c6dffe8915fb.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Access Control & Identity Management"],"inherent_rating":"high","taxonomy":["owasp-llm-top10-2025","iso-23894-ai-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-agent-unauthorized-actions","description":"AI agents with excessive permissions or weak action controls execute tool calls, transactions, or code outside their authorized task scope — through prompt injection, misinterpretation, or emergent behaviour — causing data loss, financial loss, or irreversible changes in connected systems.","details":{"category":"ai_governance","impact":"high","inherent_rating":"high","likelihood":"high","risk_id":"ai-agent-unauthorized-actions","taxonomies":["owasp-llm-top10-2025","iso-23894-ai-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ai-agent-unauthorized-actions-194415b8.html","id":"risk:ai-agent-unauthorized-actions","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-agent-unauthorized-actions","sourceIds":["aiuc-1","eu-ai-act","nist-ai-agent-identity","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"Unauthorized or unsafe autonomous agent actions and tool calls","type":"risk","url":"/assets/agent_record-risk-ai-agent-unauthorized-actions-194415b8.5198dd5746cb3c61.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Data Protection & Privacy","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["nist-ai-rmf-risk","iso-23894-ai-risk","nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-bias-discrimination","description":"Models encode/amplify historical bias, producing allocative harm (biased hiring/lending/housing/benefits), representational harm (stereotyping), and evaluation bias masking disparate subgroup performance — systematically disadvantaging protected groups.","details":{"category":"ai_governance","impact":"high","inherent_rating":"high","likelihood":"high","risk_id":"ai-bias-discrimination","taxonomies":["nist-ai-rmf-risk","iso-23894-ai-risk","nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ai-bias-discrimination-35faf209.html","id":"risk:ai-bias-discrimination","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-bias-discrimination","sourceIds":["aiuc-1","eu-ai-act","iso-42001","nist-ai-agent-identity","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"Harmful AI bias and discrimination against protected groups","type":"risk","url":"/assets/agent_record-risk-ai-bias-discrimination-35faf209.7c885bc120fdd613.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance"],"inherent_rating":"high","taxonomy":["nist-ai-rmf-risk","iso-23894-ai-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-catastrophic-cyber-misuse","description":"Users obtain meaningful uplift from an AI system for offensive cyber operations (malware development, vulnerability exploitation, autonomous intrusion) or for biological, chemical, nuclear, or radiological harm, exposing the deploying organization to severe legal, regulatory, and societal consequences.","details":{"category":"ai_governance","impact":"critical","inherent_rating":"high","likelihood":"low","risk_id":"ai-catastrophic-cyber-misuse","taxonomies":["nist-ai-rmf-risk","iso-23894-ai-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ai-catastrophic-cyber-misuse-6bced10d.html","id":"risk:ai-catastrophic-cyber-misuse","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-catastrophic-cyber-misuse","sourceIds":["aiuc-1","eu-ai-act","iso-42001","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"Misuse of AI systems for offensive cyber operations or catastrophic harm","type":"risk","url":"/assets/agent_record-risk-ai-catastrophic-cyber-misuse-6bced10d.bad2a3730a8b7534.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Secure Development (SDLC) & Application Security"],"inherent_rating":"medium","taxonomy":["iso-23894-ai-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-emergent-integration-risk","description":"Large-scale or multi-model pipelines exhibit emergent capabilities/failures not present in any component and not predictable from component testing; integration with legacy systems introduces interface mismatches and configuration errors.","details":{"category":"ai_governance","impact":"high","inherent_rating":"medium","likelihood":"medium","risk_id":"ai-emergent-integration-risk","taxonomies":["iso-23894-ai-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ai-emergent-integration-risk-8490271c.html","id":"risk:ai-emergent-integration-risk","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-emergent-integration-risk","sourceIds":["aiuc-1","cobit-2019","eu-ai-act","iso-27001","iso-42001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","soc1","soc2","sox"],"sourceUrl":null,"title":"Emergent behaviour and unsafe AI system integration","type":"risk","url":"/assets/agent_record-risk-ai-emergent-integration-risk-8490271c.7c427d5d71af8a3d.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Network & Communications Security"],"inherent_rating":"medium","taxonomy":["owasp-llm-top10-2025","nist-ai-rmf-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-endpoint-abuse-model-extraction","description":"Adversaries scrape inference endpoints at scale to extract model behaviour or proprietary data, exhaust compute budgets through unbounded consumption, or harvest system prompts and technical details disclosed in outputs or documentation, degrading service and eroding competitive and security posture.","details":{"category":"ai_governance","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"ai-endpoint-abuse-model-extraction","taxonomies":["owasp-llm-top10-2025","nist-ai-rmf-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ai-endpoint-abuse-model-extraction-a3c97c52.html","id":"risk:ai-endpoint-abuse-model-extraction","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-endpoint-abuse-model-extraction","sourceIds":["aiuc-1","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"AI endpoint abuse, scraping and model extraction","type":"risk","url":"/assets/agent_record-risk-ai-endpoint-abuse-model-extraction-a3c97c52.da508bc3500c6df1.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Data Protection & Privacy","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["eu-ai-act-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-highrisk-law-enforcement","description":"Because AI for individual risk assessment, evidence evaluation, profiling, or predictive policing (Annex III(6)) operates without strict accuracy, human oversight, logging, and fundamental-rights safeguards, it can drive wrongful enforcement action, resulting in unjust detention, profiling harm, and rights violations.","details":{"category":"ai_governance","impact":"critical","inherent_rating":"high","likelihood":"low","risk_id":"ai-highrisk-law-enforcement","taxonomies":["eu-ai-act-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ai-highrisk-law-enforcement-7d4537e1.html","id":"risk:ai-highrisk-law-enforcement","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-highrisk-law-enforcement","sourceIds":["aiuc-1","eu-ai-act","iso-42001","nist-ai-agent-identity","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"Rights violations from AI in law enforcement","type":"risk","url":"/assets/agent_record-risk-ai-highrisk-law-enforcement-7d4537e1.56621939b56634ed.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Risk Assessment & Management"],"inherent_rating":"high","taxonomy":["nist-ai-rmf-risk","iso-23894-ai-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-inaccurate-unreliable-output","description":"AI outputs contain factual errors, hallucinations, or confidently wrong predictions; inappropriate proxy metrics, overfitting/underfitting, or insufficient pre-deployment testing undermine trust in decisions made on their basis.","details":{"category":"ai_governance","impact":"high","inherent_rating":"high","likelihood":"high","risk_id":"ai-inaccurate-unreliable-output","taxonomies":["nist-ai-rmf-risk","iso-23894-ai-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ai-inaccurate-unreliable-output-cf10c86e.html","id":"risk:ai-inaccurate-unreliable-output","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-inaccurate-unreliable-output","sourceIds":["aiuc-1","eu-ai-act","iso-31000","iso-42001","nist-ai-agent-identity","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"Inaccurate, unreliable or hallucinated AI outputs","type":"risk","url":"/assets/agent_record-risk-ai-inaccurate-unreliable-output-cf10c86e.e5b352e1d741db19.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Governance, Policy & Oversight"],"inherent_rating":"medium","taxonomy":["iso-23894-ai-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-inappropriate-task-allocation","description":"Tasks needing contextual judgment, ethics, or accountability are improperly delegated to AI; and decommissioning raises data-persistence in weights, loss of institutional knowledge, and service-continuity gaps.","details":{"category":"ai_governance","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"ai-inappropriate-task-allocation","taxonomies":["iso-23894-ai-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ai-inappropriate-task-allocation-72a18be5.html","id":"risk:ai-inappropriate-task-allocation","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-inappropriate-task-allocation","sourceIds":["aiuc-1","eu-ai-act","iso-42001","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"Inappropriate human/AI task allocation and end-of-life risk","type":"risk","url":"/assets/agent_record-risk-ai-inappropriate-task-allocation-72a18be5.c080cac277213ef1.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Governance, Policy & Oversight"],"inherent_rating":"high","taxonomy":["nist-ai-rmf-risk","iso-23894-ai-risk","eu-ai-act-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-insufficient-human-oversight","description":"Because consequential AI decisions run under full automation with reviewers who lack the authority, information, or AI literacy to intervene, meaningful human control is absent and automation complacency erodes vigilance, so erroneous or harmful automated decisions reach individuals unchecked.","details":{"category":"ai_governance","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"ai-insufficient-human-oversight","taxonomies":["nist-ai-rmf-risk","iso-23894-ai-risk","eu-ai-act-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ai-insufficient-human-oversight-6c4f3dfa.html","id":"risk:ai-insufficient-human-oversight","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-insufficient-human-oversight","sourceIds":["aiuc-1","eu-ai-act","iso-42001","nist-ai-agent-identity","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"Insufficient human oversight and automation complacency","type":"risk","url":"/assets/agent_record-risk-ai-insufficient-human-oversight-6c4f3dfa.175ed6e53f86e774.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Logging, Monitoring & Detection"],"inherent_rating":"high","taxonomy":["nist-ai-rmf-risk","iso-23894-ai-risk","eu-ai-act-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-model-drift-monitoring","description":"Distribution shift between training and deployment data silently degrades accuracy, and without ongoing monitoring, model decay and emerging failure modes go undetected with no trigger to retrain or decommission. Uncontrolled updates alter behaviour and invalidate prior assessments.","details":{"category":"ai_governance","impact":"medium","inherent_rating":"high","likelihood":"high","risk_id":"ai-model-drift-monitoring","taxonomies":["nist-ai-rmf-risk","iso-23894-ai-risk","eu-ai-act-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ai-model-drift-monitoring-15329f38.html","id":"risk:ai-model-drift-monitoring","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-model-drift-monitoring","sourceIds":["aiuc-1","eu-ai-act","iso-42001","nist-ai-agent-identity","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"Model/data drift and inadequate post-deployment monitoring","type":"risk","url":"/assets/agent_record-risk-ai-model-drift-monitoring-15329f38.37fd0328a377be1e.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Business Continuity & Disaster Recovery"],"inherent_rating":"medium","taxonomy":["nist-ai-rmf-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-model-resilience-fallback-gap","description":"AI systems lacking fallback, redundancy, or graceful degradation fail catastrophically under adversarial conditions, infrastructure outages, or out-of-distribution inputs, disrupting dependent business processes.","details":{"category":"ai_governance","impact":"high","inherent_rating":"medium","likelihood":"medium","risk_id":"ai-model-resilience-fallback-gap","taxonomies":["nist-ai-rmf-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ai-model-resilience-fallback-gap-85070995.html","id":"risk:ai-model-resilience-fallback-gap","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-model-resilience-fallback-gap","sourceIds":["aiuc-1","eu-ai-act","iso-42001","nist-ai-agent-identity","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"Insufficient AI resilience and fallback mechanisms","type":"risk","url":"/assets/agent_record-risk-ai-model-resilience-fallback-gap-85070995.b6b2ff0af2a56076.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Data Protection & Privacy"],"inherent_rating":"high","taxonomy":["nist-ai-rmf-risk","nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-privacy-leakage","description":"Model inversion and membership-inference attacks reconstruct training data or reveal individuals in the training set; AI inference re-identifies anonymized data and infers sensitive attributes; training on data without consent/legal basis creates regulatory liability.","details":{"category":"ai_governance","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"ai-privacy-leakage","taxonomies":["nist-ai-rmf-risk","nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ai-privacy-leakage-9aa8d83c.html","id":"risk:ai-privacy-leakage","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-privacy-leakage","sourceIds":["aiuc-1","eu-ai-act","hipaa","iso-27001","iso-42001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"AI privacy leakage and re-identification","type":"risk","url":"/assets/agent_record-risk-ai-privacy-leakage-9aa8d83c.ff6b2a9cfa591fb9.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Risk Assessment & Management"],"inherent_rating":"high","taxonomy":["nist-ai-rmf-risk","iso-23894-ai-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-safety-harm-to-people","description":"AI errors in safety-critical systems (autonomous vehicles, medical devices, industrial controls) cause injury or death; safety-constraint violations by agentic AI, cascading failures across coupled systems, and AI-generated misinformation/deepfakes cause harm.","details":{"category":"ai_governance","impact":"critical","inherent_rating":"high","likelihood":"low","risk_id":"ai-safety-harm-to-people","taxonomies":["nist-ai-rmf-risk","iso-23894-ai-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ai-safety-harm-to-people-d02cb500.html","id":"risk:ai-safety-harm-to-people","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-safety-harm-to-people","sourceIds":["aiuc-1","eu-ai-act","iso-31000","iso-42001","nist-ai-agent-identity","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"AI safety failures causing physical or psychological harm","type":"risk","url":"/assets/agent_record-risk-ai-safety-harm-to-people-d02cb500.c92982c948595fe0.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Data Protection & Privacy","Cryptography & Key Management"],"inherent_rating":"high","taxonomy":["owasp-llm-top10-2025","nist-ai-rmf-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-secrets-credential-leakage","description":"API keys, tokens, private keys, and connection strings pasted into prompts, returned in outputs, hardcoded in generated code, or captured in conversation logs are exposed to unauthorized parties or persisted outside secret management, enabling account takeover and lateral movement.","details":{"category":"ai_governance","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"ai-secrets-credential-leakage","taxonomies":["owasp-llm-top10-2025","nist-ai-rmf-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ai-secrets-credential-leakage-abf1bf77.html","id":"risk:ai-secrets-credential-leakage","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-secrets-credential-leakage","sourceIds":["aiuc-1","nist-ai-agent-identity","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"Credential and secret leakage through AI inputs, outputs, logs and generated code","type":"risk","url":"/assets/agent_record-risk-ai-secrets-credential-leakage-abf1bf77.102567b687c1fc7d.json"},{"attributes":{"category":"operational","domain":["Awareness & Training","Data Protection & Privacy","Logging, Monitoring & Detection"],"inherent_rating":"high","taxonomy":["iso-27005-threat","nist-800-30-threat-event","nist-800-30-threat-source","iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aaware-user-error-mishandling","description":"Authorized users make mistakes — incorrect data entry, misconfiguration, improper procedures, incorrect privilege settings, or spilling/mishandling sensitive information — causing harm to information assets without malicious intent.","details":{"category":"operational","impact":"medium","inherent_rating":"high","likelihood":"high","risk_id":"aware-user-error-mishandling","taxonomies":["iso-27005-threat","nist-800-30-threat-event","nist-800-30-threat-source","iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-aware-user-error-mishandling-149a1d3b.html","id":"risk:aware-user-error-mishandling","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aaware-user-error-mishandling","sourceIds":["aiuc-1","gdpr","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","nist-csf-2","nydfs-500","soc1","soc2"],"sourceUrl":null,"title":"User error and mishandling of sensitive information","type":"risk","url":"/assets/agent_record-risk-aware-user-error-mishandling-149a1d3b.111c3fa544df22a0.json"},{"attributes":{"category":"cyber_security","domain":["Secure Configuration & Change Management","Network & Communications Security","Vulnerability & Patch Management"],"inherent_rating":"high","taxonomy":["nist-800-30-threat-event"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aconfig-internet-exposed-misconfig","description":"Adversary gains access through the Internet to systems not authorized for Internet connectivity or that do not meet configuration requirements, and exploits attacks over unauthorized ports, protocols, and services.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"high","risk_id":"config-internet-exposed-misconfig","taxonomies":["nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-config-internet-exposed-misconfig-61b3613a.html","id":"risk:config-internet-exposed-misconfig","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aconfig-internet-exposed-misconfig","sourceIds":["aiuc-1","iso-27001","nist-800-53","nist-ai-tevv-athlon","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Internet-exposed or misconfigured systems","type":"risk","url":"/assets/agent_record-risk-config-internet-exposed-misconfig-61b3613a.784e8a1bdf681744.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy","Incident Management & Response"],"inherent_rating":"high","taxonomy":["iso-27005-threat","nist-800-30-threat-event","nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-breach-unauthorized-disclosure","description":"Unauthorized disclosure of information to parties not entitled to receive it, whether by insecure controls (insecurity), spillage, or authorized users induced to expose data — resulting in identity theft, economic loss, and loss of trust.","details":{"category":"privacy","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"data-breach-unauthorized-disclosure","taxonomies":["iso-27005-threat","nist-800-30-threat-event","nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-data-breach-unauthorized-disclosure-3b1c296c.html","id":"risk:data-breach-unauthorized-disclosure","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-breach-unauthorized-disclosure","sourceIds":["aiuc-1","ccpa","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","nist-csf-2","soc2"],"sourceUrl":null,"title":"Unauthorized disclosure / breach of sensitive information","type":"risk","url":"/assets/agent_record-risk-data-breach-unauthorized-disclosure-3b1c296c.8431603df36984c8.json"},{"attributes":{"category":"cyber_security","domain":["Data Protection & Privacy","Network & Communications Security","Logging, Monitoring & Detection"],"inherent_rating":"critical","taxonomy":["nist-800-30-threat-event","nist-800-30-threat-source","basel-operational-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-exfiltration-espionage","description":"Adversary (outsider, insider, nation-state, or competitor) installs malware or sniffers to locate and exfiltrate sensitive/proprietary information, or steals data by external actors — including systems-security losses from hacking.","details":{"category":"cyber_security","impact":"critical","inherent_rating":"critical","likelihood":"medium","risk_id":"data-exfiltration-espionage","taxonomies":["nist-800-30-threat-event","nist-800-30-threat-source","basel-operational-risk","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-data-exfiltration-espionage-74803ebc.html","id":"risk:data-exfiltration-espionage","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-exfiltration-espionage","sourceIds":["aiuc-1","cobit-2019","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Data exfiltration and theft of information by attackers","type":"risk","url":"/assets/agent_record-risk-data-exfiltration-espionage-74803ebc.a1ef3e79ab006192.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["nist-privacy-risk","enterprise-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-privacy-program-noncompliance","description":"Failure to honour data-subject rights (access, deletion, portability, restriction) on time, missing lawful-basis/consent documentation, defective consent mechanisms, invalid cross-border transfer mechanisms, or inadequate notices — driving fines and private rights of action.","details":{"category":"privacy","impact":"high","inherent_rating":"high","likelihood":"high","risk_id":"data-privacy-program-noncompliance","taxonomies":["nist-privacy-risk","enterprise-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-data-privacy-program-noncompliance-ec6178fa.html","id":"risk:data-privacy-program-noncompliance","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-privacy-program-noncompliance","sourceIds":["aiuc-1","ccpa","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","soc2"],"sourceUrl":null,"title":"Privacy-program non-compliance (GDPR, CCPA, state laws)","type":"risk","url":"/assets/agent_record-risk-data-privacy-program-noncompliance-ec6178fa.f8a5498a8697316f.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy","Compliance, Audit & Assurance","Third-Party / Supply-Chain Risk"],"inherent_rating":"medium","taxonomy":["nist-privacy-risk","enterprise-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aprivacy-cross-border-transfer","description":"Transferring personal data to jurisdictions lacking equivalent protection without SCCs, BCRs, adequacy decisions, or other recognized mechanisms, exposing individuals and the organization to legal risk.","details":{"category":"privacy","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"privacy-cross-border-transfer","taxonomies":["nist-privacy-risk","enterprise-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-privacy-cross-border-transfer-8fb379b5.html","id":"risk:privacy-cross-border-transfer","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aprivacy-cross-border-transfer","sourceIds":["aiuc-1","ccpa","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","nist-csf-2"],"sourceUrl":null,"title":"Cross-border personal-data transfer without safeguards","type":"risk","url":"/assets/agent_record-risk-privacy-cross-border-transfer-8fb379b5.e026bee45d4ef5d1.json"},{"attributes":{"category":"cyber_security","domain":["Secure Development (SDLC) & Application Security","Vulnerability & Patch Management"],"inherent_rating":"high","taxonomy":["nist-800-30-threat-event","iso-27005-threat"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Asdlc-vulnerabilities-in-software","description":"Inherent weaknesses in programming languages and development environments introduce errors and exploitable vulnerabilities into software products, and software malfunctions cause incorrect outputs, crashes, or security weaknesses.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"high","risk_id":"sdlc-vulnerabilities-in-software","taxonomies":["nist-800-30-threat-event","iso-27005-threat"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-sdlc-vulnerabilities-in-software-10c28b16.html","id":"risk:sdlc-vulnerabilities-in-software","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Asdlc-vulnerabilities-in-software","sourceIds":["cobit-2019","iso-27001","nist-800-53","nist-ai-tevv-athlon","nist-csf-2","pci-dss","sox"],"sourceUrl":null,"title":"Vulnerabilities introduced during software development","type":"risk","url":"/assets/agent_record-risk-sdlc-vulnerabilities-in-software-10c28b16.07c74be6a9324543.json"},{"attributes":{"category":"cyber_security","domain":["Vulnerability & Patch Management","Secure Development (SDLC) & Application Security"],"inherent_rating":"medium","taxonomy":["iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Avuln-inadequate-testing-scanning","description":"Software released without adequate testing, and no regular vulnerability scanning or penetration testing, leaves exploitable defects undiscovered until they manifest — or are exploited — in production.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"vuln-inadequate-testing-scanning","taxonomies":["iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-vuln-inadequate-testing-scanning-ee33b888.html","id":"risk:vuln-inadequate-testing-scanning","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Avuln-inadequate-testing-scanning","sourceIds":["cobit-2019","gdpr","iso-27001","nist-800-53","nist-ai-tevv-athlon","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"Inadequate vulnerability scanning and pre-release testing","type":"risk","url":"/assets/agent_record-risk-vuln-inadequate-testing-scanning-ee33b888.86e78aa5757f5ff1.json"},{"attributes":{"category":"cyber_security","domain":["Vulnerability & Patch Management","Secure Configuration & Change Management"],"inherent_rating":"critical","taxonomy":["iso-27005-vulnerability","nist-800-30-threat-event","iso-27005-threat"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Avuln-unpatched-known-flaws","description":"Use of software with publicly known, unpatched flaws (CVEs) that adversaries readily exploit — including recently discovered vulnerabilities exploited before mitigations are in place, and internal-system vulnerability exploitation.","details":{"category":"cyber_security","impact":"high","inherent_rating":"critical","likelihood":"high","risk_id":"vuln-unpatched-known-flaws","taxonomies":["iso-27005-vulnerability","nist-800-30-threat-event","iso-27005-threat"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-vuln-unpatched-known-flaws-c4a6b075.html","id":"risk:vuln-unpatched-known-flaws","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Avuln-unpatched-known-flaws","sourceIds":["dora","gdpr","iso-27001","nist-800-53","nist-ai-tevv-athlon","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Exploitation of known, unpatched vulnerabilities","type":"risk","url":"/assets/agent_record-risk-vuln-unpatched-known-flaws-c4a6b075.3a21c5668d469a67.json"},{"attributes":{"authority":"guidance","category":"nist-ai-tevv-athlon"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-ai-tevv-athlon/","description":"NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems","details":{"amendmentState":"Initial public draft; public comments close 2026-10-06","authority":"guidance","effectiveDate":null,"note":"Initial public draft of a general AI evaluation framework, applicable to agentic systems. These six selected topics cover evaluation design and agent security testing; they are not a complete crosswalk of the publication. NIST-TEVV identifiers are local catalog references, not NIST control numbers. The confidentiality, injection, and tool-abuse topics relate to the lethal trifecta, but the draft does not prescribe an architecture that makes that combination safe or a required testing frequency.","propositions":[{"id":"NIST-TEVV-01","sourcePages":"NIST AI 200-2 ipd sections 2.1-2.2, pp. 3-6","title":"Define evaluation objectives, context, and measurements"},{"id":"NIST-TEVV-02","sourcePages":"NIST AI 200-2 ipd sections 2.3-2.4, pp. 6-7","title":"Run evaluations and examine results and limitations"},{"id":"NIST-TEVV-03","sourcePages":"NIST AI 200-2 ipd section 4.3.2, pp. 14-15; Appendix C, pp. 25-26","title":"Evaluate AI systems in realistic operating settings"},{"id":"NIST-TEVV-04","sourcePages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Confidentiality attacks","title":"Test for disclosure of confidential information"},{"id":"NIST-TEVV-05","sourcePages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Integrity attacks","title":"Test direct and indirect prompt injection"},{"id":"NIST-TEVV-06","sourcePages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Agent / tool abuse testing","title":"Test agent tool misuse and unauthorized external actions"}],"publicationDate":"2026-08-07","reviewed_at":"2026-09-10","source_url":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.200-2.ipd.pdf","version":"NIST AI 200-2 ipd (Initial Public Draft), August 2026"},"direct":true,"htmlUrl":"/agents/records/std-nist-ai-tevv-athlon-c008775c.html","id":"std:nist-ai-tevv-athlon","mapUrl":"https://controlsmap.com/?v=1&node=std%3Anist-ai-tevv-athlon","sourceIds":["nist-ai-tevv-athlon"],"sourceUrl":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.200-2.ipd.pdf","title":"NIST TEVV-Athlon (draft, Aug 2026)","type":"standard","url":"/assets/agent_record-std-nist-ai-tevv-athlon-c008775c.a3f13fbcc1792b67.json"},{"attributes":{"category":"technical","domain":"AI Governance","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AI-05","description":"Define objectives for responsible AI development, such as fairness, safety, security, transparency, and accountability, and embed them in a documented design and development process. Specify and document requirements for each AI system, including intended purpose, performance criteria, and constraints, before build begins. Evidence includes the development process definition, per-system requirement specifications, and design-stage approvals.","details":{"control_category":"technical","control_type":"preventive","domain":"AI Governance","guidance":[{"propositionId":"NIST-TEVV-01","propositionTitle":"Define evaluation objectives, context, and measurements","source":"nist-ai-tevv-athlon","sourcePages":"NIST AI 200-2 ipd sections 2.1-2.2, pp. 3-6","sourceTitle":"NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems"}],"members":[{"control_id":"A.6.1.2","coverage":"full","framework":"iso-42001","relationship":"superset_of"},{"control_id":"A.6.1.3","coverage":"full","framework":"iso-42001","relationship":"superset_of"},{"control_id":"A.6.2.2","coverage":"full","framework":"iso-42001","relationship":"superset_of"}],"statement":"Define objectives for responsible AI development, such as fairness, safety, security, transparency, and accountability, and embed them in a documented design and development process. Specify and document requirements for each AI system, including intended purpose, performance criteria, and constraints, before build begins. Evidence includes the development process definition, per-system requirement specifications, and design-stage approvals.","title":"Set responsible AI development objectives and requirements","unified_id":"UC-AI-05"},"direct":false,"htmlUrl":"/agents/records/uc-uc-ai-05-d0edecc1.html","id":"uc:UC-AI-05","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AI-05","sourceIds":["iso-42001","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"UC-AI-05 — Set responsible AI development objectives and requirements","type":"unified","url":"/assets/agent_record-uc-uc-ai-05-d0edecc1.56d9e9a5e170f322.json"},{"attributes":{"category":"technical","domain":"AI Governance","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AI-07","description":"Verify and validate each AI system against its requirements and responsible-AI objectives, documenting test plans, acceptance criteria, and results before release approval. Gate deployment on a documented deployment plan and sign-off confirming requirements are met. Route updates, retraining, and other changes through the same assessment and approval process, including impact reassessment where relevant, and retain verification records and deployment and change approvals.","details":{"control_category":"technical","control_type":"preventive","domain":"AI Governance","guidance":[{"propositionId":"NIST-TEVV-01","propositionTitle":"Define evaluation objectives, context, and measurements","source":"nist-ai-tevv-athlon","sourcePages":"NIST AI 200-2 ipd sections 2.1-2.2, pp. 3-6","sourceTitle":"NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems"},{"propositionId":"NIST-TEVV-02","propositionTitle":"Run evaluations and examine results and limitations","source":"nist-ai-tevv-athlon","sourcePages":"NIST AI 200-2 ipd sections 2.3-2.4, pp. 6-7","sourceTitle":"NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems"},{"propositionId":"NIST-TEVV-03","propositionTitle":"Evaluate AI systems in realistic operating settings","source":"nist-ai-tevv-athlon","sourcePages":"NIST AI 200-2 ipd section 4.3.2, pp. 14-15; Appendix C, pp. 25-26","sourceTitle":"NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems"}],"members":[{"control_id":"A.6.2.4","coverage":"full","framework":"iso-42001","relationship":"superset_of"},{"control_id":"A.6.2.5","coverage":"full","framework":"iso-42001","relationship":"superset_of"},{"control_id":"C002","coverage":"full","framework":"aiuc-1","relationship":"superset_of"}],"statement":"Verify and validate each AI system against its requirements and responsible-AI objectives, documenting test plans, acceptance criteria, and results before release approval. Gate deployment on a documented deployment plan and sign-off confirming requirements are met. Route updates, retraining, and other changes through the same assessment and approval process, including impact reassessment where relevant, and retain verification records and deployment and change approvals.","title":"Verify, validate, and control AI deployment and changes","unified_id":"UC-AI-07"},"direct":false,"htmlUrl":"/agents/records/uc-uc-ai-07-9c5c9573.html","id":"uc:UC-AI-07","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AI-07","sourceIds":["aiuc-1","iso-42001","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"UC-AI-07 — Verify, validate, and control AI deployment and changes","type":"unified","url":"/assets/agent_record-uc-uc-ai-07-9c5c9573.237549d1b4b3d490.json"},{"attributes":{"category":"technical","domain":"AI Governance","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AI-08","description":"Ensure AI systems automatically record event logs that enable traceability of operation over the system's lifetime, including events relevant to identifying risk situations and substantial modification. Retain logs for at least the mandated regulatory minimum, or longer where required. Monitor deployed systems against defined performance and behavior metrics with alerting and escalation for anomalies and drift, and retain logs and monitoring reviews as evidence.","details":{"control_category":"technical","control_type":"detective","domain":"AI Governance","guidance":[{"propositionId":"NIST-AGI-05","propositionTitle":"Verifiable agent action logs and authorization traceability","source":"nist-ai-agent-identity","sourcePages":"Concept paper pp. 4, 6: Auditing and non-repudiation; Logging and Transparency","sourceTitle":"NIST NCCoE: Software and AI Agent Identity and Authorization"},{"propositionId":"NIST-TEVV-02","propositionTitle":"Run evaluations and examine results and limitations","source":"nist-ai-tevv-athlon","sourcePages":"NIST AI 200-2 ipd sections 2.3-2.4, pp. 6-7","sourceTitle":"NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems"}],"members":[{"control_id":"A.6.2.6","coverage":"full","framework":"iso-42001","relationship":"superset_of"},{"control_id":"A.6.2.8","coverage":"full","framework":"iso-42001","relationship":"superset_of"},{"control_id":"AIA-Art12","coverage":"full","framework":"eu-ai-act","relationship":"superset_of"},{"control_id":"C008","coverage":"partial","delta":"monitoring keyed to the AI risk taxonomy categories with per-category alert thresholds and response actions","framework":"aiuc-1","relationship":"intersects_with"},{"control_id":"E015","coverage":"full","framework":"aiuc-1","relationship":"superset_of"},{"control_id":"AIA-Art19","coverage":"full","framework":"eu-ai-act","relationship":"superset_of"},{"control_id":"AIA-Art72","coverage":"partial","delta":"a documented post-market monitoring plan, proportionate to the system's risk, that actively collects and analyses lifetime performance data including interaction with other AI systems","framework":"eu-ai-act","relationship":"intersects_with"}],"statement":"Ensure AI systems automatically record event logs that enable traceability of operation over the system's lifetime, including events relevant to identifying risk situations and substantial modification. Retain logs for at least the mandated regulatory minimum, or longer where required. Monitor deployed systems against defined performance and behavior metrics with alerting and escalation for anomalies and drift, and retain logs and monitoring reviews as evidence.","title":"Log and monitor AI system behavior in operation","unified_id":"UC-AI-08"},"direct":false,"htmlUrl":"/agents/records/uc-uc-ai-08-fada68b7.html","id":"uc:UC-AI-08","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AI-08","sourceIds":["aiuc-1","eu-ai-act","iso-42001","nist-ai-agent-identity","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"UC-AI-08 — Log and monitor AI system behavior in operation","type":"unified","url":"/assets/agent_record-uc-uc-ai-08-fada68b7.0dccf36f31d43ffc.json"},{"attributes":{"category":"technical","domain":"AI Governance","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AI-18","description":"Protect the inference and agent interfaces of AI systems with layered input defenses: screen prompts, uploaded content, retrieved data, and tool results for prompt-injection and jailbreak patterns before they reach the model or trigger actions; detect and alert on adversarial-input campaigns; and rate-limit, authenticate, and monitor endpoints to prevent scraping, model extraction, and resource-exhaustion abuse. Tune detections from evaluation findings and retain filter configurations and detection logs as evidence.","details":{"control_category":"technical","control_type":"preventive","domain":"AI Governance","guidance":[{"propositionId":"NIST-AGI-06","propositionTitle":"Prompt-injection prevention and limits on resulting harm","source":"nist-ai-agent-identity","sourcePages":"Concept paper p. 4: Prompt Injection prevention and mitigation","sourceTitle":"NIST NCCoE: Software and AI Agent Identity and Authorization"},{"propositionId":"NIST-TEVV-05","propositionTitle":"Test direct and indirect prompt injection","source":"nist-ai-tevv-athlon","sourcePages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Integrity attacks","sourceTitle":"NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems"}],"members":[{"control_id":"B002","coverage":"full","framework":"aiuc-1","relationship":"superset_of"},{"control_id":"B004","coverage":"full","framework":"aiuc-1","relationship":"superset_of"},{"control_id":"B005","coverage":"full","framework":"aiuc-1","relationship":"superset_of"}],"statement":"Protect the inference and agent interfaces of AI systems with layered input defenses: screen prompts, uploaded content, retrieved data, and tool results for prompt-injection and jailbreak patterns before they reach the model or trigger actions; detect and alert on adversarial-input campaigns; and rate-limit, authenticate, and monitor endpoints to prevent scraping, model extraction, and resource-exhaustion abuse. Tune detections from evaluation findings and retain filter configurations and detection logs as evidence.","title":"Defend AI interfaces against adversarial input, injection, and endpoint abuse","unified_id":"UC-AI-18"},"direct":false,"htmlUrl":"/agents/records/uc-uc-ai-18-f15ac93a.html","id":"uc:UC-AI-18","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AI-18","sourceIds":["aiuc-1","nist-ai-agent-identity","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"UC-AI-18 — Defend AI interfaces against adversarial input, injection, and endpoint abuse","type":"unified","url":"/assets/agent_record-uc-uc-ai-18-f15ac93a.ca79ba4b7f946767.json"},{"attributes":{"category":"technical","domain":"AI Governance","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AI-19","description":"Bound what autonomous agents may do: allow-list the tools, connectors, and actions each agent may invoke; scope its permissions to the task, user, and context; require human approval for irreversible, high-value, or out-of-policy actions; execute agent-generated code only in isolated sandboxes; and scan agent configuration artifacts such as hooks, skills, and rules for injected instructions. Log every tool call with its authorization decision and review denied and escalated calls.","details":{"control_category":"technical","control_type":"preventive","domain":"AI Governance","guidance":[{"propositionId":"NIST-AGI-03","propositionTitle":"Context-sensitive authorization and least privilege","source":"nist-ai-agent-identity","sourcePages":"Concept paper pp. 4, 6: Authorization; Areas of Interest","sourceTitle":"NIST NCCoE: Software and AI Agent Identity and Authorization"},{"propositionId":"NIST-AGI-04","propositionTitle":"Delegated authority and human accountability","source":"nist-ai-agent-identity","sourcePages":"Concept paper pp. 4, 6: Authorization; Access Delegation","sourceTitle":"NIST NCCoE: Software and AI Agent Identity and Authorization"},{"propositionId":"NIST-AGI-06","propositionTitle":"Prompt-injection prevention and limits on resulting harm","source":"nist-ai-agent-identity","sourcePages":"Concept paper p. 4: Prompt Injection prevention and mitigation","sourceTitle":"NIST NCCoE: Software and AI Agent Identity and Authorization"},{"propositionId":"NIST-TEVV-06","propositionTitle":"Test agent tool misuse and unauthorized external actions","source":"nist-ai-tevv-athlon","sourcePages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Agent / tool abuse testing","sourceTitle":"NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems"}],"members":[{"control_id":"B006","coverage":"full","framework":"aiuc-1","relationship":"superset_of"},{"control_id":"D003","coverage":"full","framework":"aiuc-1","relationship":"superset_of"}],"statement":"Bound what autonomous agents may do: allow-list the tools, connectors, and actions each agent may invoke; scope its permissions to the task, user, and context; require human approval for irreversible, high-value, or out-of-policy actions; execute agent-generated code only in isolated sandboxes; and scan agent configuration artifacts such as hooks, skills, and rules for injected instructions. Log every tool call with its authorization decision and review denied and escalated calls.","title":"Constrain agent actions and tool use to authorized scope","unified_id":"UC-AI-19"},"direct":false,"htmlUrl":"/agents/records/uc-uc-ai-19-535f3660.html","id":"uc:UC-AI-19","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AI-19","sourceIds":["aiuc-1","nist-ai-agent-identity","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"UC-AI-19 — Constrain agent actions and tool use to authorized scope","type":"unified","url":"/assets/agent_record-uc-uc-ai-19-535f3660.3f22307bbad552d5.json"},{"attributes":{"category":"technical","domain":"AI Governance","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AI-20","description":"Filter and shape every AI output before release: block or transform content that matches the system's harmful-output taxonomy, keep responses within the declared scope and capabilities, detect agent-specific high-risk outputs and route them to defined responses by severity, ground factual claims in cited sources and verify them to limit hallucination, withhold system prompts, internal data, and other over-exposed information, and sanitize outputs consumed by downstream systems so they cannot carry executable or injected payloads. Measure filter effectiveness and retain configurations, block logs, and review samples as evidence.","details":{"control_category":"technical","control_type":"preventive","domain":"AI Governance","guidance":[{"propositionId":"NIST-TEVV-04","propositionTitle":"Test for disclosure of confidential information","source":"nist-ai-tevv-athlon","sourcePages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Confidentiality attacks","sourceTitle":"NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems"}],"members":[{"control_id":"B009","coverage":"full","framework":"aiuc-1","relationship":"superset_of"},{"control_id":"C003","coverage":"full","framework":"aiuc-1","relationship":"superset_of"},{"control_id":"C004","coverage":"full","framework":"aiuc-1","relationship":"superset_of"},{"control_id":"C005","coverage":"full","framework":"aiuc-1","relationship":"superset_of"},{"control_id":"C006","coverage":"full","framework":"aiuc-1","relationship":"superset_of"},{"control_id":"D001","coverage":"full","framework":"aiuc-1","relationship":"superset_of"}],"statement":"Filter and shape every AI output before release: block or transform content that matches the system's harmful-output taxonomy, keep responses within the declared scope and capabilities, detect agent-specific high-risk outputs and route them to defined responses by severity, ground factual claims in cited sources and verify them to limit hallucination, withhold system prompts, internal data, and other over-exposed information, and sanitize outputs consumed by downstream systems so they cannot carry executable or injected payloads. Measure filter effectiveness and retain configurations, block logs, and review samples as evidence.","title":"Prevent harmful, out-of-scope, hallucinated, and over-exposed AI outputs","unified_id":"UC-AI-20"},"direct":false,"htmlUrl":"/agents/records/uc-uc-ai-20-c0e507ce.html","id":"uc:UC-AI-20","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AI-20","sourceIds":["aiuc-1","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"UC-AI-20 — Prevent harmful, out-of-scope, hallucinated, and over-exposed AI outputs","type":"unified","url":"/assets/agent_record-uc-uc-ai-20-c0e507ce.8527cdade05823b8.json"},{"attributes":{"category":"technical","domain":"Data Protection & Privacy","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-11","description":"Enforce approved authorizations for information flows within and between systems using technical flow-control mechanisms, and deploy data-leakage-prevention measures on systems and channels that could exfiltrate sensitive data. Transfer personal data across borders only under a valid transfer mechanism (adequacy decision, standard contractual clauses, binding corporate rules, or a documented derogation), with the transfer risk assessed and the safeguard recorded.","details":{"control_category":"technical","control_type":"preventive","domain":"Data Protection & Privacy","guidance":[{"propositionId":"NIST-AGI-07","propositionTitle":"Prompt provenance and data-flow tracking","source":"nist-ai-agent-identity","sourcePages":"Concept paper p. 6: Tracking Data Flows of an AI System","sourceTitle":"NIST NCCoE: Software and AI Agent Identity and Authorization"},{"propositionId":"NIST-TEVV-04","propositionTitle":"Test for disclosure of confidential information","source":"nist-ai-tevv-athlon","sourcePages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Confidentiality attacks","sourceTitle":"NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems"}],"members":[{"control_id":"AC-4","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"A.8.12","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"GDPR-Art44-49","coverage":"full","framework":"gdpr","relationship":"superset_of"},{"control_id":"A004","coverage":"partial","delta":"leakage of intellectual property and confidential information through AI system outputs, requiring model-output safeguards beyond network and channel flow controls","framework":"aiuc-1","relationship":"intersects_with"},{"control_id":"A005","coverage":"partial","delta":"tenant isolation inside AI systems: retrieval indexes, memory, fine-tuning data, and caches segregated so one customer's data cannot surface in another customer's outputs","framework":"aiuc-1","relationship":"intersects_with"}],"statement":"Enforce approved authorizations for information flows within and between systems using technical flow-control mechanisms, and deploy data-leakage-prevention measures on systems and channels that could exfiltrate sensitive data. Transfer personal data across borders only under a valid transfer mechanism (adequacy decision, standard contractual clauses, binding corporate rules, or a documented derogation), with the transfer risk assessed and the safeguard recorded.","title":"Control data flows, leakage, and cross-border transfers","unified_id":"UC-DATA-11"},"direct":false,"htmlUrl":"/agents/records/uc-uc-data-11-baf71fe4.html","id":"uc:UC-DATA-11","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-11","sourceIds":["aiuc-1","gdpr","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"UC-DATA-11 — Control data flows, leakage, and cross-border transfers","type":"unified","url":"/assets/agent_record-uc-uc-data-11-baf71fe4.96f57757894b3d77.json"},{"attributes":{"category":"administrative","domain":"Vulnerability & Patch Management","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-VULN-02","description":"Commission penetration tests of systems, applications, and networks at least annually and after material changes, performed by qualified testers independent of the target's operation and governed by documented rules of engagement. Include both internal and external testing perspectives, validate the exploitability of identified weaknesses, and report results to accountable management. Track corrective actions from each exercise to verified closure, and use the results as a separate evaluation of whether security controls are present and functioning.","details":{"control_category":"administrative","control_type":"detective","domain":"Vulnerability & Patch Management","guidance":[{"propositionId":"NIST-TEVV-05","propositionTitle":"Test direct and indirect prompt injection","source":"nist-ai-tevv-athlon","sourcePages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Integrity attacks","sourceTitle":"NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems"},{"propositionId":"NIST-TEVV-06","propositionTitle":"Test agent tool misuse and unauthorized external actions","source":"nist-ai-tevv-athlon","sourcePages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Agent / tool abuse testing","sourceTitle":"NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems"}],"members":[{"control_id":"CA-8","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PCI-Req11","coverage":"partial","delta":"also requires quarterly vulnerability scans, intrusion detection, and change-detection mechanisms","framework":"pci-dss","relationship":"intersects_with"}],"statement":"Commission penetration tests of systems, applications, and networks at least annually and after material changes, performed by qualified testers independent of the target's operation and governed by documented rules of engagement. Include both internal and external testing perspectives, validate the exploitability of identified weaknesses, and report results to accountable management. Track corrective actions from each exercise to verified closure, and use the results as a separate evaluation of whether security controls are present and functioning.","title":"Test security through independent penetration exercises","unified_id":"UC-VULN-02"},"direct":false,"htmlUrl":"/agents/records/uc-uc-vuln-02-8366666b.html","id":"uc:UC-VULN-02","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-VULN-02","sourceIds":["nist-800-53","nist-ai-tevv-athlon","pci-dss"],"sourceUrl":null,"title":"UC-VULN-02 — Test security through independent penetration exercises","type":"unified","url":"/assets/agent_record-uc-uc-vuln-02-8366666b.f5fe7981a3d8389f.json"}],"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0264512ba8737ae70615870338c1da8f7505e26236b538ad90b44393e73d4c29","properties":{},"sourceDetailPath":"/data/v1/records/wf-r13-431c488e.json","sourceId":"wf:R13","targetDetailPath":"/data/v1/records/uc-uc-ai-07-9c5c9573.json","targetId":"uc:UC-AI-07","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:08a77e52e4a5f08c44dd042e1873f0ba3340cd2f51b40b042d3e949552be1ce6","properties":{"rationale":"Pre-release verification/validation against acceptance criteria is the testing control the risk says is insufficient, catching errors before deployment.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-07-9c5c9573.json","sourceId":"uc:UC-AI-07","targetDetailPath":"/data/v1/records/risk-ai-inaccurate-unreliable-output-cf10c86e.json","targetId":"risk:ai-inaccurate-unreliable-output","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:08ecff12261a3a3aff991e1d5c92545f9d51ff8832b3a40eee13455fa6368b8e","properties":{"rationale":"Data-leakage-prevention on systems/channels plus technical flow-control directly block exfiltration of sensitive data.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","sourceId":"uc:UC-DATA-11","targetDetailPath":"/data/v1/records/risk-data-exfiltration-espionage-74803ebc.json","targetId":"risk:data-exfiltration-espionage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0d8a8e0513e244581e4966b0a213a6921bd4968ca250b02e6bbf74c364507cef","properties":{"rationale":"Human approval before high-impact actions keeps an agent from causing physical or financial harm autonomously.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-19-535f3660.json","sourceId":"uc:UC-AI-19","targetDetailPath":"/data/v1/records/risk-ai-safety-harm-to-people-d02cb500.json","targetId":"risk:ai-safety-harm-to-people","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0ffa2def5c469c649f11402c81e8ed1599c552790a44f28df6589a3bc9e41a5a","properties":{"rationale":"Lifetime event logs provide the traceability/audit trail underpinning accountability for AI operation.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-08-fada68b7.json","sourceId":"uc:UC-AI-08","targetDetailPath":"/data/v1/records/risk-ai-accountability-liability-193b3f72.json","targetId":"risk:ai-accountability-liability","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1860d921216e697b2a7b30fde80a4165c79e533acda67a80119ec7688e944d78","properties":{},"sourceDetailPath":"/data/v1/records/wf-d59-b3ddf606.json","sourceId":"wf:D59","targetDetailPath":"/data/v1/records/uc-uc-ai-08-fada68b7.json","targetId":"uc:UC-AI-08","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:19650f905c3993b1cd7338bbfae4eca34bdc5c6541e2122bffa4222140989069","properties":{"rationale":"Verifying safety requirements before release blocks unsafe systems from shipping.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-07-9c5c9573.json","sourceId":"uc:UC-AI-07","targetDetailPath":"/data/v1/records/risk-ai-safety-harm-to-people-d02cb500.json","targetId":"risk:ai-safety-harm-to-people","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:29034087236d0f306681d6531032b1127a372bbe15c8f916be173d3d3292ff1d","properties":{"rationale":"Independent penetration testing is the operative defense against the absence of pen testing, validating exploitability.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-02-8366666b.json","sourceId":"uc:UC-VULN-02","targetDetailPath":"/data/v1/records/risk-vuln-inadequate-testing-scanning-ee33b888.json","targetId":"risk:vuln-inadequate-testing-scanning","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:299bffe8d04b68017b3b1eaa8b396600b899f72a36e67dd257be0d8d5e01044f","properties":{},"sourceDetailPath":"/data/v1/records/wf-g1-14bc355c.json","sourceId":"wf:G1","targetDetailPath":"/data/v1/records/uc-uc-ai-08-fada68b7.json","targetId":"uc:UC-AI-08","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2c12bf8d03b269e1c700c3e9904caa3d973b411be70e32343b0787d88075d72c","properties":{"rationale":"Validating against responsible-AI fairness objectives tests for discriminatory behavior before release.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-07-9c5c9573.json","sourceId":"uc:UC-AI-07","targetDetailPath":"/data/v1/records/risk-ai-bias-discrimination-35faf209.json","targetId":"risk:ai-bias-discrimination","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:33bf89fb2a59caae998679267dfb94f8446e1add332b2f02a3624df3c7de8793","properties":{"rationale":"Performance monitoring detects post-deployment accuracy degradation so wrong outputs are caught in operation.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-08-fada68b7.json","sourceId":"uc:UC-AI-08","targetDetailPath":"/data/v1/records/risk-ai-inaccurate-unreliable-output-cf10c86e.json","targetId":"risk:ai-inaccurate-unreliable-output","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3f3f7bb79607aa821f7ec9d464c1eab2b0d790a7ed2ce1169b16a35f23df9fbe","properties":{"control_id":"NIST-TEVV-06","coverage":"guidance","delta":null,"framework":"nist-ai-tevv-athlon","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Agent / tool abuse testing","source_version":"NIST AI 200-2 ipd (Initial Public Draft), August 2026"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-02-8366666b.json","sourceId":"uc:UC-VULN-02","targetDetailPath":"/data/v1/records/ctrl-nist-ai-tevv-athlon-nist-tevv-06-6a69659d.json","targetId":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-06","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4264bbe574eb6d85a3b16e6bfb401e4a9ceffd042b764dc8e30a8af83eb25957","properties":{"rationale":"Bounding what an agent may invoke limits the blast radius when integrated components behave in unforeseen ways.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-19-535f3660.json","sourceId":"uc:UC-AI-19","targetDetailPath":"/data/v1/records/risk-ai-emergent-integration-risk-8490271c.json","targetId":"risk:ai-emergent-integration-risk","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4296d1258fe3df2deae971269b20e41f48b5c528908d5824ead595af42e7bd26","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-ai-tevv-athlon-nist-tevv-01-72145876.json","sourceId":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-01","targetDetailPath":"/data/v1/records/std-nist-ai-tevv-athlon-c008775c.json","targetId":"std:nist-ai-tevv-athlon","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:473af2d50f306aab40b8828eadf994d85cd90f7ea9a3d57744ad75835c3a65a2","properties":{"rationale":"Harmful-output categories typically include discriminatory content, so output filtering catches some biased responses.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-20-c0e507ce.json","sourceId":"uc:UC-AI-20","targetDetailPath":"/data/v1/records/risk-ai-bias-discrimination-35faf209.json","targetId":"risk:ai-bias-discrimination","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4bd330fae4afb34e8db20955e0846b2b3f4f4ea3cd393f44e9bcf89677e7a987","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","targetId":"uc:UC-DATA-11","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4c7023427aa78e1dd93518e3c17913be0aee17311142a471730fa452498746f1","properties":{"rationale":"Continuous monitoring against performance/behavior metrics with drift and anomaly alerting is the post-deployment detection the risk says is missing.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-08-fada68b7.json","sourceId":"uc:UC-AI-08","targetDetailPath":"/data/v1/records/risk-ai-model-drift-monitoring-15329f38.json","targetId":"risk:ai-model-drift-monitoring","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:509a3297901c350e5b298628bb2276bf66d2215fa3163a16ccd68d92c098fe03","properties":{"rationale":"Embedding fairness as a design objective drives bias prevention upstream, later verified/remediated by UC-07/UC-09.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-05-d0edecc1.json","sourceId":"uc:UC-AI-05","targetDetailPath":"/data/v1/records/risk-ai-bias-discrimination-35faf209.json","targetId":"risk:ai-bias-discrimination","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:52232931104ab49996272de5de1afd101b88928ebffe7e073d310313461781d8","properties":{"rationale":"Grounding, citation, and verification of factual claims directly reduce hallucinated and unreliable outputs.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-20-c0e507ce.json","sourceId":"uc:UC-AI-20","targetDetailPath":"/data/v1/records/risk-ai-inaccurate-unreliable-output-cf10c86e.json","targetId":"risk:ai-inaccurate-unreliable-output","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5522ed4a796ef520de6c41be5b2f846782fa1694b789f63a2f7d8da09f23d2cf","properties":{"rationale":"Valid, documented transfer mechanisms remove the invalid-cross-border-transfer driver of non-compliance.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","sourceId":"uc:UC-DATA-11","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:557c82a7744248c53a3ab7a2d104035ab2b99d4662594126609241c528da791f","properties":{"control_id":"NIST-TEVV-05","coverage":"guidance","delta":null,"framework":"nist-ai-tevv-athlon","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Integrity attacks","source_version":"NIST AI 200-2 ipd (Initial Public Draft), August 2026"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-02-8366666b.json","sourceId":"uc:UC-VULN-02","targetDetailPath":"/data/v1/records/ctrl-nist-ai-tevv-athlon-nist-tevv-05-f9e22b30.json","targetId":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-05","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5716d67c75a6004eabbbd9435e7d4621bd18f0e35b3ed7bc3046274c98c8dd5c","properties":{"control_id":"NIST-TEVV-01","coverage":"guidance","delta":null,"framework":"nist-ai-tevv-athlon","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"NIST AI 200-2 ipd sections 2.1-2.2, pp. 3-6","source_version":"NIST AI 200-2 ipd (Initial Public Draft), August 2026"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-05-d0edecc1.json","sourceId":"uc:UC-AI-05","targetDetailPath":"/data/v1/records/ctrl-nist-ai-tevv-athlon-nist-tevv-01-72145876.json","targetId":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-01","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:57c6d5f9f689d4b775c54e6478619f06f9f30a396267a5a6616557893080ca21","properties":{"rationale":"Scope and harmful-content filters catch part of the misuse surface; the dedicated misuse refusal control is primary.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-20-c0e507ce.json","sourceId":"uc:UC-AI-20","targetDetailPath":"/data/v1/records/risk-ai-catastrophic-cyber-misuse-6bced10d.json","targetId":"risk:ai-catastrophic-cyber-misuse","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:58858e6d493365797505b5dbbc04aef4191da40e2a28f8e44897a597242ed89d","properties":{},"sourceDetailPath":"/data/v1/records/wf-c66-26a4ed19.json","sourceId":"wf:C66","targetDetailPath":"/data/v1/records/uc-uc-ai-20-c0e507ce.json","targetId":"uc:UC-AI-20","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:629deb63d191633ca0dbe5669e4f258edc0469168b578352a61bb274419588de","properties":{"rationale":"Tool allow-lists, task-scoped permissions, approval gates for irreversible actions, and sandboxed execution are the direct inverse of excessive agency.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-19-535f3660.json","sourceId":"uc:UC-AI-19","targetDetailPath":"/data/v1/records/risk-ai-agent-unauthorized-actions-194415b8.json","targetId":"risk:ai-agent-unauthorized-actions","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:661647491f39fef0fd11aa18383026be6fe88b51dffd2de668e2b417d5fc0050","properties":{"rationale":"Acceptance testing can exercise robustness/fallback under out-of-distribution inputs before release.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-07-9c5c9573.json","sourceId":"uc:UC-AI-07","targetDetailPath":"/data/v1/records/risk-ai-model-resilience-fallback-gap-85070995.json","targetId":"risk:ai-model-resilience-fallback-gap","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6e6b074dacca375c431c27e3bc8f8677f0f0d41ce5d70d05ee64f8283b855053","properties":{"rationale":"Enforcing approved information-flow authorizations and DLP directly prevents data leaking to parties not entitled to it.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","sourceId":"uc:UC-DATA-11","targetDetailPath":"/data/v1/records/risk-data-breach-unauthorized-disclosure-3b1c296c.json","targetId":"risk:data-breach-unauthorized-disclosure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6f3f01502f553d7a1f49c50b5c90c0713d99bf34c2b3d26c3c982dcf51c927d5","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-ai-tevv-athlon-nist-tevv-05-f9e22b30.json","sourceId":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-05","targetDetailPath":"/data/v1/records/std-nist-ai-tevv-athlon-c008775c.json","targetId":"std:nist-ai-tevv-athlon","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:77a886da57af2fdca7f194c4bff5074c52422db3dccf311db1e9c540d63fcea7","properties":{"control_id":"NIST-TEVV-04","coverage":"guidance","delta":null,"framework":"nist-ai-tevv-athlon","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Confidentiality attacks","source_version":"NIST AI 200-2 ipd (Initial Public Draft), August 2026"},"sourceDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","sourceId":"uc:UC-DATA-11","targetDetailPath":"/data/v1/records/ctrl-nist-ai-tevv-athlon-nist-tevv-04-14e991d6.json","targetId":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-04","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7839f0f6509978e297122f87fd02a5d5b56a4672ccf7e32b1cad6e3c6df3d1d3","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-ai-tevv-athlon-nist-tevv-04-14e991d6.json","sourceId":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-04","targetDetailPath":"/data/v1/records/std-nist-ai-tevv-athlon-c008775c.json","targetId":"std:nist-ai-tevv-athlon","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:78f1281c5bb694c0085788552e2319c57a19b1ae8e513f96b70d4dace3262c93","properties":{"rationale":"Screening prompts, retrieved content, and tool results for injection and jailbreak patterns, plus adversarial-input detection, is the inference-time defense against prompt injection.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","sourceId":"uc:UC-AI-18","targetDetailPath":"/data/v1/records/risk-ai-adversarial-poisoning-attacks-ea7df068.json","targetId":"risk:ai-adversarial-poisoning-attacks","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7d180e279ef5719d292e1bc83422a93c58145cedb4d5d7c43cbba7304c3a7334","properties":{"rationale":"Documenting intended purpose and constraints bounds what the AI is built to do, limiting over-delegation.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-05-d0edecc1.json","sourceId":"uc:UC-AI-05","targetDetailPath":"/data/v1/records/risk-ai-inappropriate-task-allocation-72a18be5.json","targetId":"risk:ai-inappropriate-task-allocation","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7f84867ba5c5b81b99aad66d6bce3b76b84b2554cf87e3359f2fedb1d44fac7b","properties":{"rationale":"Input screening is where pasted credentials can be caught before they reach the model or its logs.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","sourceId":"uc:UC-AI-18","targetDetailPath":"/data/v1/records/risk-ai-secrets-credential-leakage-abf1bf77.json","targetId":"risk:ai-secrets-credential-leakage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:80401b1fc455d6f7f97f169ba872650376d8c24b213822d2ae08b366462f0f7d","properties":{"control_id":"NIST-TEVV-01","coverage":"guidance","delta":null,"framework":"nist-ai-tevv-athlon","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"NIST AI 200-2 ipd sections 2.1-2.2, pp. 3-6","source_version":"NIST AI 200-2 ipd (Initial Public Draft), August 2026"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-07-9c5c9573.json","sourceId":"uc:UC-AI-07","targetDetailPath":"/data/v1/records/ctrl-nist-ai-tevv-athlon-nist-tevv-01-72145876.json","targetId":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-01","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:80e9af26c29453059d89e2aba17000c854a1989c3ce1528c70e9d7bc1db36e64","properties":{},"sourceDetailPath":"/data/v1/records/wf-c67-2d6bb2c2.json","sourceId":"wf:C67","targetDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","targetId":"uc:UC-AI-18","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:83182948cd2eca1f0384caf3c20d57da97d91af088e16254cae55740f5107918","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-ai-tevv-athlon-nist-tevv-06-6a69659d.json","sourceId":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-06","targetDetailPath":"/data/v1/records/std-nist-ai-tevv-athlon-c008775c.json","targetId":"std:nist-ai-tevv-athlon","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:83346bb04be0f35ed2436f074ad8d5a47d566991b1dd22072527a6cbc5841a57","properties":{"rationale":"Pen tests find and validate exploitable unpatched flaws and track corrective actions to verified closure.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-02-8366666b.json","sourceId":"uc:UC-VULN-02","targetDetailPath":"/data/v1/records/risk-vuln-unpatched-known-flaws-c4a6b075.json","targetId":"risk:vuln-unpatched-known-flaws","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:86c062512addea8a4624ceb2229386143903b633c2e84a1742f2f39a86273909","properties":{"rationale":"Automatic event logging and traceability is the mandated logging control supporting law-enforcement-AI accuracy and oversight requirements.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-08-fada68b7.json","sourceId":"uc:UC-AI-08","targetDetailPath":"/data/v1/records/risk-ai-highrisk-law-enforcement-7d4537e1.json","targetId":"risk:ai-highrisk-law-enforcement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:86f7afc22637529e54c1c36fb50b89c63c209149cf07d381452dc221a540df82","properties":{"rationale":"System-level V&V against requirements exercises the integrated pipeline, catching interface mismatches and emergent failures component testing misses.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-07-9c5c9573.json","sourceId":"uc:UC-AI-07","targetDetailPath":"/data/v1/records/risk-ai-emergent-integration-risk-8490271c.json","targetId":"risk:ai-emergent-integration-risk","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:87af6951dc70c16c823f08e7c20f3c1f870238f25fd0d9743e10b9faaebc275c","properties":{"control_id":"NIST-TEVV-03","coverage":"guidance","delta":null,"framework":"nist-ai-tevv-athlon","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"NIST AI 200-2 ipd section 4.3.2, pp. 14-15; Appendix C, pp. 25-26","source_version":"NIST AI 200-2 ipd (Initial Public Draft), August 2026"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-07-9c5c9573.json","sourceId":"uc:UC-AI-07","targetDetailPath":"/data/v1/records/ctrl-nist-ai-tevv-athlon-nist-tevv-03-37642a3d.json","targetId":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-03","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:91f42bc9024286e881ceea36b6739fd5ea2dae157cd5b2d8d20d4630575eb967","properties":{"rationale":"Routing updates/retraining through reassessment and sign-off prevents the uncontrolled updates the risk names, but does not detect the distribution drift at the risk's core; continuous monitoring (UC-08) is the operative defense.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-07-9c5c9573.json","sourceId":"uc:UC-AI-07","targetDetailPath":"/data/v1/records/risk-ai-model-drift-monitoring-15329f38.json","targetId":"risk:ai-model-drift-monitoring","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:924fea74a8fdabb427518d398540069bea5ebb0c3b0ae30469dc3b77745a61cb","properties":{"control_id":"NIST-TEVV-02","coverage":"guidance","delta":null,"framework":"nist-ai-tevv-athlon","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"NIST AI 200-2 ipd sections 2.3-2.4, pp. 6-7","source_version":"NIST AI 200-2 ipd (Initial Public Draft), August 2026"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-07-9c5c9573.json","sourceId":"uc:UC-AI-07","targetDetailPath":"/data/v1/records/ctrl-nist-ai-tevv-athlon-nist-tevv-02-41057f6e.json","targetId":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-02","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9760a2e3d5658f20413ae22917956617b54802d25bc7c92bb08a1fde6a24e0e8","properties":{"control_id":"NIST-TEVV-04","coverage":"guidance","delta":null,"framework":"nist-ai-tevv-athlon","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Confidentiality attacks","source_version":"NIST AI 200-2 ipd (Initial Public Draft), August 2026"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-20-c0e507ce.json","sourceId":"uc:UC-AI-20","targetDetailPath":"/data/v1/records/ctrl-nist-ai-tevv-athlon-nist-tevv-04-14e991d6.json","targetId":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-04","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:97e0a0b88041de7847c41dfffdc51234db0b1c4d6bdebd7d1ed46f128f8c2cbc","properties":{"rationale":"Anomaly alerting and escalation trigger failure response before dependent business processes break.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-08-fada68b7.json","sourceId":"uc:UC-AI-08","targetDetailPath":"/data/v1/records/risk-ai-model-resilience-fallback-gap-85070995.json","targetId":"risk:ai-model-resilience-fallback-gap","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:98964559bf025c94d81c0fdd464402a6ec07151a97dd2f119659938a49109d2a","properties":{},"sourceDetailPath":"/data/v1/records/wf-c10-29ff1ddb.json","sourceId":"wf:C10","targetDetailPath":"/data/v1/records/uc-uc-vuln-02-8366666b.json","targetId":"uc:UC-VULN-02","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9e0299ea9f795cac555e637bb9ab07ea7399103687cc8f5bac16f60abb53dbcc","properties":{},"sourceDetailPath":"/data/v1/records/wf-c48-1fcd5f42.json","sourceId":"wf:C48","targetDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","targetId":"uc:UC-DATA-11","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9faee45843579a9a938b92cd52105132ce6d1023816230b47999c4ae7f96fff5","properties":{"rationale":"Behavior monitoring with alerting detects unsafe operation for escalation, reducing harm impact.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-08-fada68b7.json","sourceId":"uc:UC-AI-08","targetDetailPath":"/data/v1/records/risk-ai-safety-harm-to-people-d02cb500.json","targetId":"risk:ai-safety-harm-to-people","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a340fde6d9d4f7a36559a15043c17bac883b57bf6dd7bb715a1212a87782ced2","properties":{"rationale":"Rate limiting, authentication, and monitoring of inference endpoints directly stop scraping, extraction, and unbounded-consumption abuse.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","sourceId":"uc:UC-AI-18","targetDetailPath":"/data/v1/records/risk-ai-endpoint-abuse-model-extraction-a3c97c52.json","targetId":"risk:ai-endpoint-abuse-model-extraction","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ab7f64af90f33aad12a67c5ab3f53eea3d13f240ccb483df72f07345b0e34d69","properties":{},"sourceDetailPath":"/data/v1/records/wf-c65-09b9172f.json","sourceId":"wf:C65","targetDetailPath":"/data/v1/records/uc-uc-ai-08-fada68b7.json","targetId":"uc:UC-AI-08","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:abf0c8d3c60aea4c5c085ed0b1fed7e2f864668d00cf8e826fa0a1d4bda95d3e","properties":{},"sourceDetailPath":"/data/v1/records/wf-d59-b3ddf606.json","sourceId":"wf:D59","targetDetailPath":"/data/v1/records/uc-uc-ai-07-9c5c9573.json","targetId":"uc:UC-AI-07","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b38b8f6520f03a9348578e342869825ce8fd97358def7a6558068131911f0f98","properties":{"rationale":"Transferring personal data only under a valid mechanism (adequacy/SCC/BCR/derogation) with recorded safeguards directly prevents unsafeguarded cross-border transfers.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","sourceId":"uc:UC-DATA-11","targetDetailPath":"/data/v1/records/risk-privacy-cross-border-transfer-8fb379b5.json","targetId":"risk:privacy-cross-border-transfer","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b798358969420b3f109b3ffaa3cce3f890eb7e7ba87673c9c66c2fd5e2387db9","properties":{},"sourceDetailPath":"/data/v1/records/wf-c67-2d6bb2c2.json","sourceId":"wf:C67","targetDetailPath":"/data/v1/records/uc-uc-ai-20-c0e507ce.json","targetId":"uc:UC-AI-20","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bf6186db7aa9faa17cdc6db5ca220a4ec52da9e6b1c6ddcff44dbba3b62d91a1","properties":{"control_id":"NIST-TEVV-02","coverage":"guidance","delta":null,"framework":"nist-ai-tevv-athlon","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"NIST AI 200-2 ipd sections 2.3-2.4, pp. 6-7","source_version":"NIST AI 200-2 ipd (Initial Public Draft), August 2026"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-08-fada68b7.json","sourceId":"uc:UC-AI-08","targetDetailPath":"/data/v1/records/ctrl-nist-ai-tevv-athlon-nist-tevv-02-41057f6e.json","targetId":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-02","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c138c9085801d2898819eb46d92df7c34c2d349d2a6ff78019dc55e7cf412342","properties":{"rationale":"Output filtering against the harmful-output taxonomy is the last technical barrier before a harmful response reaches a person.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-20-c0e507ce.json","sourceId":"uc:UC-AI-20","targetDetailPath":"/data/v1/records/risk-ai-safety-harm-to-people-d02cb500.json","targetId":"risk:ai-safety-harm-to-people","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c4e934338e76c382da8f51bf012190f6e98f8310f106befadbbd7acd4e94464c","properties":{"rationale":"Setting intended purpose and performance criteria at design avoids inappropriate proxy metrics, but the operative accuracy defense is pre-release verification (UC-07) and monitoring (UC-08); requirement-setting contributes upstream.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-05-d0edecc1.json","sourceId":"uc:UC-AI-05","targetDetailPath":"/data/v1/records/risk-ai-inaccurate-unreliable-output-cf10c86e.json","targetId":"risk:ai-inaccurate-unreliable-output","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c59b52e616b08f549f872fb76832769ea6adad3fb38cb731b2fde42e7437b8e3","properties":{"rationale":"Blocking injected instructions that try to exfiltrate context reduces one avenue for personal-data leakage.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","sourceId":"uc:UC-AI-18","targetDetailPath":"/data/v1/records/risk-ai-privacy-leakage-9aa8d83c.json","targetId":"risk:ai-privacy-leakage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c6544a91d9d991f1d537b87a1da443b4364e318a48c2eee236c3599a4b2d752b","properties":{"rationale":"Approval gates and reviewed escalations put a human back in the loop for consequential agent actions.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-19-535f3660.json","sourceId":"uc:UC-AI-19","targetDetailPath":"/data/v1/records/risk-ai-insufficient-human-oversight-6c4f3dfa.json","targetId":"risk:ai-insufficient-human-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ceb2c795d78777060307a3a7fbdbd69024f50beb49f3ae22d8c2d348e3a45ac0","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","targetId":"uc:UC-DATA-11","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d187bd5b2bc2f570bf989c371c6bc7ede52d168aa9e8ca5d352d22e2186cc974","properties":{},"sourceDetailPath":"/data/v1/records/wf-g1-14bc355c.json","sourceId":"wf:G1","targetDetailPath":"/data/v1/records/uc-uc-ai-07-9c5c9573.json","targetId":"uc:UC-AI-07","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d484e2ed3ffa0ee8b84a73b3cdab3f7f2f7add4484e33c7f473b6266f1802aff","properties":{"rationale":"DLP on exfiltration channels catches inadvertent user spillage of sensitive information.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","sourceId":"uc:UC-DATA-11","targetDetailPath":"/data/v1/records/risk-aware-user-error-mishandling-149a1d3b.json","targetId":"risk:aware-user-error-mishandling","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d8b80f08aebb53818d702d4d99d8c67750cac06da57d362f51268c30edd793ac","properties":{"control_id":"NIST-TEVV-05","coverage":"guidance","delta":null,"framework":"nist-ai-tevv-athlon","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Integrity attacks","source_version":"NIST AI 200-2 ipd (Initial Public Draft), August 2026"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","sourceId":"uc:UC-AI-18","targetDetailPath":"/data/v1/records/ctrl-nist-ai-tevv-athlon-nist-tevv-05-f9e22b30.json","targetId":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-05","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d8e98edb473b5d39c46ddf7c5ec273d5782f1e65f05be494aaa256fec9e38805","properties":{"rationale":"Withholding internal data and over-exposed content from outputs reduces personal-data leakage at the response boundary.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-20-c0e507ce.json","sourceId":"uc:UC-AI-20","targetDetailPath":"/data/v1/records/risk-ai-privacy-leakage-9aa8d83c.json","targetId":"risk:ai-privacy-leakage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dac1ee58faab32d652d0827247260f7a77b62b41642a16209485a1332b754a49","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-ai-tevv-athlon-nist-tevv-02-41057f6e.json","sourceId":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-02","targetDetailPath":"/data/v1/records/std-nist-ai-tevv-athlon-c008775c.json","targetId":"std:nist-ai-tevv-athlon","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dc87db88dbcacdd22bedfddf5c232620a1bce3a5a6ec97ea456b73ef7db758a3","properties":{},"sourceDetailPath":"/data/v1/records/wf-g1-14bc355c.json","sourceId":"wf:G1","targetDetailPath":"/data/v1/records/uc-uc-ai-05-d0edecc1.json","targetId":"uc:UC-AI-05","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dd1985c48f200577c857cdc6201233fac873348904270b2fbcf71217b4f99714","properties":{},"sourceDetailPath":"/data/v1/records/wf-r13-431c488e.json","sourceId":"wf:R13","targetDetailPath":"/data/v1/records/uc-uc-ai-05-d0edecc1.json","targetId":"uc:UC-AI-05","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dd6e424d14cc32172c325fc0c83ce251db91de1d64582e194ee680e4e84c4f96","properties":{},"sourceDetailPath":"/data/v1/records/wf-c66-26a4ed19.json","sourceId":"wf:C66","targetDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","targetId":"uc:UC-AI-18","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e8713eaa01ce3c2f5711b923ec55bf65142a4dd30de55b8fb9bd1c1cb99ac90a","properties":{"rationale":"Application penetration testing uncovers exploitable software vulnerabilities in built systems.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-02-8366666b.json","sourceId":"uc:UC-VULN-02","targetDetailPath":"/data/v1/records/risk-sdlc-vulnerabilities-in-software-10c28b16.json","targetId":"risk:sdlc-vulnerabilities-in-software","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eafc8058c7fc34f34c19ed416eae2a435d7e142c6b3d7bcca0b4a497a8ebbe4e","properties":{},"sourceDetailPath":"/data/v1/records/wf-d59-b3ddf606.json","sourceId":"wf:D59","targetDetailPath":"/data/v1/records/uc-uc-ai-05-d0edecc1.json","targetId":"uc:UC-AI-05","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f11caf1f1bb12d16344326dccd7d4afb8595b36f64912f7c5fe131c6fb44116e","properties":{},"sourceDetailPath":"/data/v1/records/wf-c66-26a4ed19.json","sourceId":"wf:C66","targetDetailPath":"/data/v1/records/uc-uc-ai-19-535f3660.json","targetId":"uc:UC-AI-19","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f1b4a8472bf97ad9143ae40e4686cb83c55566975085fcda5dc8864209f8d27a","properties":{},"sourceDetailPath":"/data/v1/records/wf-c67-2d6bb2c2.json","sourceId":"wf:C67","targetDetailPath":"/data/v1/records/uc-uc-ai-19-535f3660.json","targetId":"uc:UC-AI-19","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fa29facda9059af8c7dae296732b036c55c71034cfce52f7069f4a40bfee6328","properties":{"control_id":"NIST-TEVV-06","coverage":"guidance","delta":null,"framework":"nist-ai-tevv-athlon","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Agent / tool abuse testing","source_version":"NIST AI 200-2 ipd (Initial Public Draft), August 2026"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-19-535f3660.json","sourceId":"uc:UC-AI-19","targetDetailPath":"/data/v1/records/ctrl-nist-ai-tevv-athlon-nist-tevv-06-6a69659d.json","targetId":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-06","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fa7254ff9326e1d8b51098cf652361ac2c4db07ce12773b31a621554bedccbf1","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-ai-tevv-athlon-nist-tevv-03-37642a3d.json","sourceId":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-03","targetDetailPath":"/data/v1/records/std-nist-ai-tevv-athlon-c008775c.json","targetId":"std:nist-ai-tevv-athlon","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fd93e502fdfb4e7f9ef0a6fc557d02f6b10e37e080f75bef72d5722fcaa80939","properties":{"rationale":"External-perspective testing directly probes and discovers internet-exposed and misconfigured systems.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-02-8366666b.json","sourceId":"uc:UC-VULN-02","targetDetailPath":"/data/v1/records/risk-config-internet-exposed-misconfig-61b3613a.json","targetId":"risk:config-internet-exposed-misconfig","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fee96cbac72815aa2d1c235adae49d22ba272567d8f68712837d95e1d7807258","properties":{"rationale":"Embedding safety objectives in the design/development process reduces unsafe design choices before build begins.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-05-d0edecc1.json","sourceId":"uc:UC-AI-05","targetDetailPath":"/data/v1/records/risk-ai-safety-harm-to-people-d02cb500.json","targetId":"risk:ai-safety-harm-to-people","type":"mitigates"}],"schemaVersion":1,"scope":"sources","total":50}
