Trust Center / AI Governance
Responsible by design
AI governance
Where B5 Secure applies AI to security operations, it is governed to the NIST AI Risk Management Framework and ISO/IEC 42001, with EU AI Act readiness. The guiding assumption is the same as the rest of the platform: AI systems can be manipulated — so design, monitor, and oversee accordingly.
NIST AI RMF 1.0
The four functions, applied
Govern, Map, Measure, and Manage are operationalized across the model lifecycle and every AI-assisted feature.
GGovern
- AI governance policy with named owners and an accountable review cadence.
- Roles, responsibilities, and escalation paths defined for AI risk.
- Third-party and foundation-model risk assessed before adoption.
ISO/IEC 42001 leadership & planning
MMap
- Model inventory documenting purpose, data lineage, and intended use.
- Risk classification by impact and autonomy, per use case.
- Context, stakeholders, and potential harms identified up front.
Tiered risk classification
MMeasure
- Bias, drift, robustness, and performance evaluated and tracked.
- Adversarial and prompt-injection testing on AI surfaces.
- Explainability sufficient to justify consequential outputs.
Continuous evaluation
MManage
- Human-in-the-loop on consequential decisions; no unsupervised enforcement.
- Drift and degradation alerting with rollback paths.
- Immutable AI audit trails for every decision.
Human oversight & response
Lifecycle controls
How the program runs day to day
01Model inventory & risk tiers
- Every model and AI-assisted feature is registered with owner, purpose, inputs, and data lineage.
- Each is assigned a risk tier; higher tiers carry stricter oversight, testing, and approval gates.
- EU AI Act risk categories are mapped so high-risk uses receive the required documentation.
Maps to: NIST AI RMF Map · ISO 42001 Annex A
02Explainability & traceability
- Decisions are traceable to inputs, model version, and configuration.
- Outputs affecting access or security carry a rationale a reviewer can audit.
- Records support regulatory reporting and customer inquiry.
Maps to: NIST AI RMF Measure
03Human oversight
- Consequential actions require human confirmation; AI advises, people decide.
- Clear override and appeal paths for any automated determination.
- Operators are trained on model limitations and failure modes.
Maps to: NIST AI RMF Manage
04Data & model protection
- Training and inference data are handled under the same least-privilege and encryption controls as platform data.
- Prompt-injection and model-manipulation defenses on AI-assisted surfaces.
- Confidential computing for sensitive inference; tenant isolation preserved.
Maps to: ISO 42001 · NIST AI RMF Govern
Reviewing our AI posture?
Our AI management policy, model register summary, and AI RMF profile are available under NDA.