microsoft

rai-standards

"Consolidated Responsible AI standards reference: NIST AI RMF 1.0, AI STRIDE threat-modeling overlay, EU AI Act risk tiers, and an open-standards catalog with phase mapping"

microsoft 1,367 270 Updated 2mo ago

Resources

1
GitHub

Install

npx skillscat add microsoft/hve-core/rai-standards

Install via the SkillsCat registry.

About this skill

Here's a thinking process: 1.

SKILL.md

RAI Standards Skill

This skill is the reusable standards package for the RAI Planner. It consolidates the embedded NIST AI RMF content, the AI STRIDE threat-modeling overlay, and a paraphrased EU AI Act reference so the phase playbook can stay focused on workflow and orchestration.

Attribution and licensing posture

  • NIST AI RMF 1.0 is a U.S. Government document and is reproduced here as public-domain reference material with attribution.
  • EU AI Act content in this skill is paraphrased and attributed rather than quoted verbatim, consistent with the open legal-text posture used in the repository.
  • The AI STRIDE overlay is Microsoft-authored reference material for threat-modeling reuse in the RAI workflow.

Framework index

NIST AI RMF trustworthiness characteristics

Key Characteristic Description
validReliable Valid and Reliable Base characteristic for correctness, robustness, and stability
safe Safe Safety and harm prevention under normal and adversarial conditions
secureResilient Secure and Resilient Resistance to attack, misuse, and failure
accountableTransparent Accountable and Transparent Governance, auditability, and decision provenance
explainableInterpretable Explainable and Interpretable Understandability of model behavior and outputs
privacyEnhanced Privacy-Enhanced Protection of personal data and confidentiality
fairBiasManaged Fair with Harmful Bias Managed Bias detection, mitigation, and equitable outcomes

Phase-to-framework mapping

RAI phase Primary standards package Notes
Phase 1 Scoping NIST AI RMF Govern + Map Context, purpose, stakeholders, and policy framing
Phase 2 Risk Classification NIST AI RMF Govern Governance culture, DEI&A, and stakeholder engagement
Phase 3 Standards Mapping NIST AI RMF Govern + Measure Core standards mapping and TEVV alignment
Phase 4 Security Model Analysis AI STRIDE overlay + Measure Threat modeling and overlap with security analysis
Phase 5 Impact Assessment NIST AI RMF Manage Risk prioritization, mitigation, and monitoring
Phase 6 Review and Handoff NIST AI RMF Manage + EU AI Act Regulatory review, incident response, and evidence handoff

Customer extension pattern

The default framework remains NIST AI RMF 1.0. When a customer supplies an additional framework, preserve the default NIST mapping as a baseline and layer the custom framework on top with explicit attribution. This keeps the planner interoperable while allowing organizations to add ISO, sector, or regional references without rewriting the core playbook.

Open-standards catalog

Use the links below as the reference catalog for open standards and governance resources. Do not reproduce normative text verbatim when the license posture does not allow it.