From voluntary framework to certifiable standard
Turning a voluntary risk-management framework into a certifiable standard, with a bar a tool can be checked against.
The impact of agents
Certifying a user-facing tool or agent requires a standard to certify against, and the standard has to say what passes and what does not. The risk-management frameworks that exist give a shared vocabulary and a sensible structure, but they are voluntary and set no threshold, so two builders can both claim to follow one and mean very different things.
Turning a framework into a defined, auditable standard, one a tool can pass or fail, is the step no jurisdiction has taken.
What must be verified
Government needs a certification regime that rests on a recognized risk-management structure but goes beyond it: a defined, auditable bar that means the same thing across jurisdictions, not just a shared vocabulary. The certifying body must run the assessment and maintain that auditable record.
Protecting access
An all-or-nothing standard excludes by pricing. The small builder for whom full assurance is out of reach stays uncertified, and their sound tool goes unused. Users who would have been best served by that tool are pushed toward whatever else met the bar.
Keeping the path open
- Build graduated tiers on the same framework, so a low-risk tool can reach a meaningful, achievable level instead of failing the only bar on offer.
- State each tier's meaning in plain language, so users can tell what 'certified' did and did not check.
- Make the self-assessment workflow completable with a screen reader and keyboard alone, or a builder who relies on assistive technology can't reach the tier a low-risk tool would otherwise qualify for.
Response surface
A tiered self-assessment turns a tool's coverage of a risk-management framework into the certification level the framework itself leaves undefined.
The framework names the discipline; the tiers make it enforceable. A readiness check that maps to a public pass/fail line is auditable. One that maps to nothing cannot be checked.
Maturity
Emerging. Frameworks exist and are widely used, but they are voluntary, and no jurisdiction has yet implemented a mandatory, auditable certification regime for general-purpose civic technology tools based on them.
Precedents
The NIST AI Risk Management Framework (US). The framework organizes AI risk management around four functions: Govern, Map, Measure, and Manage. The Generative AI Profile addresses generative risks, supply-chain vulnerabilities, and third-party model assessment, and a Cyber AI Profile has reached an initial preliminary draft. The control overlays for AI remain announced and provisional.
The NIST AI Resource Center crosswalks. NIST states that the AI RMF 'is intended for voluntary use' and records that it 'is being revised'. Its AI Resource Center hosts crosswalks submitted by the framework's own user community, including one to ISO/IEC 42001, while stating that inclusion 'does not imply NIST endorsement' of the mapped resource. A crosswalk aligns vocabulary and sets no threshold, and the mapping toward a certifiable standard is being drawn by the user community rather than by the body that wrote the framework.
Australia's national AI assurance framework. The framework for AI assurance in government was agreed by Data and Digital Ministers, and the AI Plan for the Australian Public Service rests on three pillars: Trust covering transparency, ethics and governance, People covering capability building and engagement, and Tools covering access, infrastructure and support. Chief AI Officers are the named leadership mechanism for adoption.
ISO/IEC 42006, requirements for certification bodies. The standard sets what a body must satisfy to audit and certify an AI management system against ISO/IEC 42001, covering competence, impartiality, and audit duration. A voluntary framework becomes certifiable when the bodies assessing it are themselves accredited.
What carries over to agent use
High for risk-management structure; moderate as certification basis. The NIST RMF provides the vocabulary and structure a certification regime would assess against.
A government pattern library should treat the RMF (or its Australian equivalent) as the reference framework and define certification tiers on top of it. The Australian AI Assurance Framework is a useful precedent, having taken a government assurance framework toward exactly this kind of structured, accountable use.
Where things go wrong
The RMF's Govern/Map/Measure/Manage discipline (accountability for each AI use case and risk-based action) is exactly the assurance process a flawed automated decision lacks. Applied as a mandatory, auditable regime, it forces explicit ownership and measurement of the risk. A tool can satisfy the four functions on paper, governance documented, measurement logged, while no action follows when the numbers call for it. What catches that is auditing the self-assessment against the tool's actual practice, not accepting the completed assessment as the certification itself.
Sources
12 references
The instrument, the operating deployment, or the official record itself.
- NIST AI Risk Management Framework
- NIST AI 600-1 — Generative AI Profile
- NIST IR 8596 — Cyber AI Profile (initial preliminary draft)
- NIST AI Resource Center — crosswalk documents
- Australian Public Service AI Plan 2025
- Pilot AI Assurance Framework (Australia)
- National Framework for the Assurance of AI in Government (Australia)
- ISO/IEC 42005:2025 — AI system impact assessment
- ISO/IEC 42006:2025 — requirements for AI management system certification bodies
- ETSI EN 304 223 — baseline cyber security requirements for AI models and systems
- NIST CAISI — AI Agent Standards Initiative
- NIST COSAiS — SP 800-53 control overlays for securing AI systems