Control Mapping

How Decision Receipt helps your organization meet NIST SP 800-171, CMMC Level 2, NIST AI RMF, EO 14110, and EU AI Act requirements.

This describes capability mapping, not certification. Compliance depends on your complete security posture. Decision Receipt provides technical evidence artifacts that support a comprehensive compliance program.

NIST SP 800-171 Rev 2

3.3 — Audit and Accountability

ControlHow Decision Receipt Addresses ItEvidence Artifact
3.3.1Every autonomous action generates a signed receipt with timestamp, actor, evidence digest, policy evaluation, and verdict. Receipts are append-only and hash-chained.receipt.json (signed, chained)
3.3.2Each receipt records originating agent, human requestor, repository, PR number, and commit SHA.receipt.json → actor, origin
3.3.5Receipt chains enable cross-action correlation. Analytics API provides trend analysis and violation frequency.Trust Pack; analytics
3.3.8Ed25519-signed at creation. Hash chain ensures insertion or deletion is detectable. Verification requires only the public key.signature + hash chain

3.1 — Access Control

ControlHow Decision Receipt Addresses ItEvidence Artifact
3.1.1Enforces authorization at the point of autonomous action. No action proceeds without a receipt proving all policy gates passed.verdict: REJECTED
3.1.5Deny-by-default posture. No action has implicit authorization.posture: deny-by-default

Additional Families

ControlHow Decision Receipt Addresses It
3.4.1 (CM)Replay verification compares execution against baseline. Divergence flagged as NON_DETERMINISTIC.
3.4.4 (CM)Security signals (CI, scans, reviews) evaluated before admission.
3.11.1 (RA)Continuous risk signal: acceptance trends, violation frequency, per-agent profiles.
3.12.3 (CA)100% of autonomous actions evaluated in real time. No sampling.
3.14.1 (SI)Policy rules require passing CI, static analysis, and dependency checks.

NIST AI Risk Management Framework

FunctionHow Decision Receipt Supports It
GOVERNPolicy rules encode regulatory requirements. Evaluation records demonstrate per-action assessment.
MAPRisk tolerances encoded as explicit thresholds. Replay provides TEVV mechanism.
MEASUREQuantified metrics: acceptance rate, violation frequency, replay divergence, evidence completeness.
MANAGEVerdicts are real-time risk responses. Blocked actions are immediate mitigations.

EU AI Act (High-Risk Systems)

ArticleRequirementDecision Receipt
Art. 12Record-keepingTamper-evident hash-chained receipt logging.
Art. 14Human oversightESCALATED verdict routes to human reviewers.
Art. 15Accuracy, robustnessReplay verifies consistency. Signatures provide integrity.
Art. 17Quality managementEach receipt is a quality record. Trends measure quality.
Art. 61Post-market monitoringContinuous receipt generation as real-time monitoring.
Try Decision Receipt Get API Key