Securing 2M+ accounts & $15B+ in assets, protected & secure·B5 Secure™ — per data-element authorization for .NET platforms

AI Governance

Trust Center  /  AI Governance
Responsible by design

AI governance

Where B5 Secure applies AI to security operations, it is governed to the NIST AI Risk Management Framework and ISO/IEC 42001, with EU AI Act readiness. The guiding assumption is the same as the rest of the platform: AI systems can be manipulated — so design, monitor, and oversee accordingly.

NIST AI RMF 1.0

The four functions, applied

Govern, Map, Measure, and Manage are operationalized across the model lifecycle and every AI-assisted feature.

GGovern

  • AI governance policy with named owners and an accountable review cadence.
  • Roles, responsibilities, and escalation paths defined for AI risk.
  • Third-party and foundation-model risk assessed before adoption.
ISO/IEC 42001 leadership & planning

MMap

  • Model inventory documenting purpose, data lineage, and intended use.
  • Risk classification by impact and autonomy, per use case.
  • Context, stakeholders, and potential harms identified up front.
Tiered risk classification

MMeasure

  • Bias, drift, robustness, and performance evaluated and tracked.
  • Adversarial and prompt-injection testing on AI surfaces.
  • Explainability sufficient to justify consequential outputs.
Continuous evaluation

MManage

  • Human-in-the-loop on consequential decisions; no unsupervised enforcement.
  • Drift and degradation alerting with rollback paths.
  • Immutable AI audit trails for every decision.
Human oversight & response
Lifecycle controls

How the program runs day to day

01Model inventory & risk tiers

  • Every model and AI-assisted feature is registered with owner, purpose, inputs, and data lineage.
  • Each is assigned a risk tier; higher tiers carry stricter oversight, testing, and approval gates.
  • EU AI Act risk categories are mapped so high-risk uses receive the required documentation.
Maps to: NIST AI RMF Map · ISO 42001 Annex A

02Explainability & traceability

  • Decisions are traceable to inputs, model version, and configuration.
  • Outputs affecting access or security carry a rationale a reviewer can audit.
  • Records support regulatory reporting and customer inquiry.
Maps to: NIST AI RMF Measure

03Human oversight

  • Consequential actions require human confirmation; AI advises, people decide.
  • Clear override and appeal paths for any automated determination.
  • Operators are trained on model limitations and failure modes.
Maps to: NIST AI RMF Manage

04Data & model protection

  • Training and inference data are handled under the same least-privilege and encryption controls as platform data.
  • Prompt-injection and model-manipulation defenses on AI-assisted surfaces.
  • Confidential computing for sensitive inference; tenant isolation preserved.
Maps to: ISO 42001 · NIST AI RMF Govern

Reviewing our AI posture?

Our AI management policy, model register summary, and AI RMF profile are available under NDA.

Scroll to Top