Skip to content

M57 / FEDERAL AI ASSURANCE / LOCAL-FIRST

AI assurance that stands up to review.

For federal contractors and federal delivery teams that need to show what an AI system is, which obligations apply, what evidence supports each control, what changed, and who made the decision.

Supports control-level evidence review. It does not certify compliance. It does not accept risk, make a legal determination, or replace an authorized human review.

ASSESSMENTsha256:6f2c…91adcontent addressed
SOURCENIST · OMB
OBLIGATIONFED-IMP-01
CONTROLGV-11
EVIDENCESHA-256
DECISIONHUMAN
Customer-runRoot-confinedIndependent verificationHuman authority retained

THE REVIEW PATH

Every conclusion keeps its receipts.

Evidence confidence is explicit: registered → located → integrity verified → tested → reviewed → attested.
  1. 01
    SOURCENIST · OMB

    Primary-source provenance and effective dates

  2. 02
    OBLIGATIONFED-IMP-01

    Obligation citations are filtered by recorded scope facts

  3. 03
    CONTROLGV-11

    One operational control can map to many obligations

  4. 04
    EVIDENCESHA-256

    Artifacts are located, hashed, tested, and reviewed

  5. 05
    DECISIONHUMAN

    Named people retain approval and risk authority

M57 / ASSURANCELOCAL / READ + PROPOSE

m57-assure verify assurance.json

FEDERAL DOCUMENT ASSISTANTpilot · high impact · acquisition
SATISFIEDGV-11

Impact assessment

SATISFIEDACQ-01

Vendor dossier + test access

LEGAL REVIEWACQ-03

Data rights + portability

PARTIALSS-01

Secure AI lifecycle

NO GLOBAL SCORE · FINDINGS REMAIN INSPECTABLE

ONE CORE / THREE REVIEW SURFACES

The same finding everywhere.

One deterministic engine powers people, CI, and agent workflows. No interface gets a separate compliance story.

  1. HUMAN / TTY

    Interactive TUI

    Navigate scope, findings, evidence confidence, reassessment triggers, and export paths without moving sensitive material into a hosted dashboard.

  2. AGENT / MCP

    Structured MCP

    Root-confined read tools and proposal-only drafts let agents investigate assurance state without signing, accepting risk, or mutating the project record.

  3. REVIEW / BUNDLE

    Immutable assessments

    Content-addressed snapshots, SHA-256 artifact manifests, JSON and Markdown reports, and an OSCAL-oriented preview travel together with independent bundle verification through bundle-verify.

PACK / US-FED / 2026.07

Federal-first. Versioned at the source.

The initial pack supports evidence workflows tied to open federal publications. References provide traceability; they are not claims of endorsement or formal conformance.

OMB M-26-04 is scoped only to recorded federal LLM procurement and carries its stated December 11, 2027 sunset date for mandatory source review.

Each reviewed PDF carries a retrieval date, page count, and SHA-256 digest. The complete pack fails closed for source review after October 19, 2026.

NIST AI RMF 1.0Govern · Map · Measure · Manage
Voluntary risk-management structure
NIST AI 600-1Generative AI Profile
Applied only when generative AI is explicitly recorded
NIST SP 800-218ASecure development
AI-specific software lifecycle practices
OMB M-25-21Federal AI governance
Impact assessment, testing, oversight, monitoring, remedies
OMB M-25-22Federal AI acquisition
Vendor documentation, evaluation access, rollback, portability
OMB M-26-04Federal LLM acquisition
Transparency materials, feedback, evaluation evidence, reviewed contract terms

CERTIFICATION / SCOPE CONTROL

Different assurances answer different questions.

No universal AI compliance certificate exists. The workbench records the applicable path instead of collapsing it into a badge.
PathMeaning

Action

NIST AI RMFNo certification

Use it as voluntary risk-management and evidence structure.

ISO/IEC 42001Organization-level AIMS certification

Use the AIMS readiness drafts only with a licensed standard and qualified review; drafts are not evidence of conformity or certification.

EU AI ActSystem and role-specific conformity

Treat provider, deployer, importer, and other duties as separate dated packs—not a global badge.

FedRAMPHosted cloud security trigger

Relevant if a hosted cloud service processes federal information; not required for this customer-run local toolkit.

CMMCDoD environment trigger

Relevant when a covered contract environment handles FCI or CUI.

BEFORE THE PILOT

Keep authority visible.

Does the workbench certify compliance?

No. It produces control-level evidence findings and preserves the underlying sources, assumptions, and human decisions. It does not certify compliance, issue legal conclusions, or authorize deployment.

What does the MCP server change?

Nothing in the project record. Its tools are read-only or proposal-only. It can draft an evidence link, exception, or review request, but a human must verify and apply any change.

Where does evidence go?

The first release is local-first. Declared files stay within the configured root; URLs are not fetched; manifest and evidence paths are confined after symlink resolution.

What does a pilot produce?

A scoped AI system record, applicability rationale, control mapping, verified evidence inventory, immutable assessment, remediation register, TUI/MCP integration, and buyer-review bundle.

SCOPED ENTRY / ONE SYSTEM

Bring one AI workflow into evidence.

Start with a bounded system. Leave with its inventory, applicability record, verified evidence, findings, remediation path, TUI/MCP integration, and buyer-review bundle.

Start an AI assurance conversation