The framework

A Responsible AI Framework built on the standards your auditors already trust

We don't invent a proprietary model. We mirror the GAO AI Accountability Framework — the IG community's own standard — operationalize it with the NIST AI Risk Management Framework, and design every control to meet-or-exceed OMB M-25-21 while honoring the OIG's independence.

Independent by design

USPS is exempt from the FAR and the OMB AI memoranda do not legally bind an independent Inspector General. We treat M-25-21 as a floor to meet-or-exceed — and design the framework around the OIG’s statutory independence, its law-enforcement-sensitive data, and its agentic-AI trajectory, mirroring GAO-21-519SP so the OIG can audit its own AI to the same bar it holds others to.

The problem no one has solved yet

Governing the agents RISC is building right now

RISC has built agent prototypes in LangChain, LangGraph, CrewAI, and AutoGen, with none yet in production, and has not finalized how those agents are credentialed, whether through Entra user-delegated permissions in CoPilot Studio or managed identities and service principals. That open question is the heart of responsible agentic AI, and it is where this framework starts: action allowlists, human-approval gates, agent identity and least privilege, and defensible accountability for autonomous decisions, built for the prototype-to-production crossing RISC is at today.

Retrieval & accuracy
The RAG Triad (context relevance, groundedness, answer relevance), measured rather than assumed.
Logging & monitoring
Every agent action and model decision logged, with drift and performance watched continuously.
Scope, law & regulation compliance
Each use case checked against its legal authority and the boundaries of the OIG mission.

The backbone · GAO-21-519SP

Four accountability principles

This is the framework the OIG would use to audit anyone else’s AI. We build the OIG’s own program to the same bar — so it can be audited to it.

01

Governance

Who is accountable for the AI?

Senior accountability, defined roles, AI policies, and stakeholder engagement from inception.

02

Data

Is the data appropriate?

Quality, representativeness, lineage, PII handling, and documented training/test data.

03

Performance

Does it work as intended?

Testing across subgroups, accuracy/reliability/fairness metrics, and pre-deployment validation.

04

Monitoring

Does it hold over time?

Post-deployment monitoring, drift detection, incident logging, and periodic re-evaluation.

The operating system · NIST AI RMF

Four functions, wired to the platform

GOVERN

Risk-aware culture, policies, approval gates, accountability — the cross-cutting function.

Demonstrated by: AI governance board, risk appetite, escalation, Enhanced TLP

MAP

Context, stakeholders, impacts and data lineage for each AI system.

Demonstrated by: Use-case intake, AI inventory, impact analysis

MEASURE

Analyze and track AI risk with quantitative + qualitative methods.

Demonstrated by: Bias/fairness testing, XAI, drift detection, red-teaming

MANAGE

Prioritize, treat, and respond — including incidents and residual risk.

Demonstrated by: Risk registry, incident playbooks, monitoring logs

Built for the environment RISC runs

We integrate into your stack. We do not replace it.

Confirmed from the OIG’s own solicitation documents, the framework is designed for the systems RISC already operates.

Azure + Microsoft Entra

Deployed inside the OIG tenant, authenticated through Entra and honoring existing RBAC. No HSG-hosted system, and law-enforcement-sensitive data never leaves OIG control.

Databricks Lakehouse

The AI inventory and risk registry read from the model estate, and drift monitoring runs on the inference tables RISC already operates.

AskSage API + Microsoft AI Foundry

The platform you can operate here runs on Claude for the demo; in production every model call routes through the OIG's own sanctioned gateways, AskSage (including its API) and Microsoft AI Foundry, with no external model key introduced.

Power BI

Governance KPIs and drift dashboards land in the OIG's existing BI layer, not a separate tool to learn.

NIST 800-53 · FedRAMP · AS-805-H

The framework aligns to the OIG's existing authorization regime, and our staff onboard at the MBI level required for system access.

Seven workstreams

The SOW, organized

Authorities referenced

GAO-21-519SP
AI Accountability Framework for Federal Agencies
The IG community’s own audit-side standard — we mirror its four principles.
NIST AI RMF 1.0
AI Risk Management Framework
GOVERN · MAP · MEASURE · MANAGE — adopted as voluntary best practice.
NIST AI 600-1
Generative AI Profile (12 risk categories)
Confabulation, harmful bias, data privacy, information integrity, and more.
OMB M-25-21
Accelerating Federal Use of AI (Apr 2025)
We design to meet-or-exceed the High-Impact AI minimum practices.
OMB M-25-22
Driving Efficient Acquisition of AI
Lifecycle monitoring, vendor accountability, no lock-in.
FIRST.org TLP v2.0
Traffic Light Protocol
Extended into the Enhanced TLP for the AI data lifecycle.