Crosswalk pair
FedRAMP Rev5 Class B and NIST AI Risk Management Framework, control by control
1 canonical control in Keel’s library satisfies clauses of both FedRAMP Rev5 Class B and NIST AI Risk Management Framework. Implement each once, attach the evidence once, and it counts toward each standard. The overlap is the work you don’t repeat.
The overlap
What the two libraries have in common
Every figure here counts canonical controls in Keel’s library, not clauses of either standard. Each standard’s own authored count is on its framework page.
1
Controls that satisfy both
Canonical controls that crosswalk to at least one clause of each.
50
In Keel’s library for FedRAMP Rev5 Class B
2% of them also map to NIST AI Risk Management Framework.
27
In Keel’s library for NIST AI Risk Management Framework
4% of them also map to FedRAMP Rev5 Class B.
4
Evidence artifacts expected
Across the shared controls, from Keel’s evidence guidance. Gathered once.
-
1 control of 50 in Keel’s library for FedRAMP Rev5 Class B also maps to NIST AI Risk Management Framework.
-
NIST AI Risk Management Framework 4%
1 control of 27 in Keel’s library for NIST AI Risk Management Framework also maps to FedRAMP Rev5 Class B.
The mapping
Controls that satisfy both
Each row is one control in Keel’s library and the clauses it answers on each side. Do the work once; both columns are then evidenced by the same artifacts.
| Canonical control | FedRAMP Rev5 Class B clauses | NIST AI Risk Management Framework clauses |
|---|---|---|
| Authorization to operate a system A system does not go into service because it is ready; it goes into service because a senior official accountable for the risk has said it may. That official is named for the system, and a senior official is named for the COMMON CONTROLS other systems inherit - the shared platform, identity service, network, logging and facility controls a team does not implement for itself - so the controls somebody else runs on your behalf are authorized by somebody rather than assumed. Before operations begin, the official accepts the common controls the system will inherit, considers the system security and privacy plan, the results of the control assessment and the outstanding weaknesses with their remediation plan, and authorizes the system to operate, records the decision with its date and any conditions attached, or refuses it. The official responsible for common controls authorizes their use for inheritance on the same terms. An authorization is not permanent: it is reviewed and updated on a defined cadence and on the events the organization has decided require it - a significant change to the system or its environment, a serious incident, or a material change in the risk - so an approval given years ago against a system that no longer exists is not still standing. The authorization decisions, and the evidence they rested on, are retained. Where the system is an AI system, the same decision answers two further questions before it is given: whether the system actually achieves its intended purpose and the objectives stated for it, and whether its development or deployment should proceed at all - so "it works well enough to authorize" is a finding on the record rather than an assumption behind it, and not proceeding is one of the answers available. | CA-6 | MANAGE-1.1 |
Beyond the pair
Where else this work counts
A framework is lit when a shared control above also maps to it. Unlit means none of them do, which is an absence rather than a judgment about that standard.
Also reached by this control
- AI Governance Essentials not reached
- Amazon Appstore Child-Directed Apps not reached
- Apple App Store Kids Category not reached
- CIS Critical Security Controls not reached
- COPPA not reached
- ESG Essentials not reached
- EU AI Act not reached
- FedRAMP 20x not reached
- FedRAMP Consolidated Rules not reached
- FedRAMP Rev5 Class C also reached
- FedRAMP Rev5 Class D also reached
- GDPR not reached
- Google Play Families not reached
- HIPAA not reached
- ISO 9001 not reached
- ISO/IEC 27001 not reached
- ISO/IEC 42001 not reached
- NIST Cybersecurity Framework not reached
- NIST SP 800-171 not reached
- NIST SP 800-53 also reached
- PCI DSS not reached
- PIPEDA not reached
- SOC 2 not reached
- SOX (Sarbanes-Oxley) Section 404 not reached
- US Employment Law - Federal Baseline not reached
Nearby pairs
- FedRAMP Rev5 Class B and FedRAMP Rev5 Class C 50 shared controls
- FedRAMP Rev5 Class B and FedRAMP Rev5 Class D 50 shared controls
- FedRAMP Rev5 Class B and NIST SP 800-53 49 shared controls
- FedRAMP Rev5 Class B and ISO/IEC 27001 41 shared controls
- FedRAMP Rev5 Class B and NIST SP 800-171 36 shared controls
- FedRAMP Rev5 Class B and NIST Cybersecurity Framework 32 shared controls
The thesis
Why this is one project, not two
On a crosswalk-native model, NIST AI Risk Management Framework mostly lights up controls you already built for FedRAMP Rev5 Class B. You’re not re-uploading the same screenshot for a second audit. You apply the framework and see the genuine delta worth working. That’s the whole idea behind collect once, comply everywhere.
Next step
Add NIST AI Risk Management Framework to the work you already did
Apply both frameworks in one workspace and see the overlap measured against the controls you already hold.