09

Register 09 · Compliance controls.

Seventy-two regulatory cite-anchors, organized for evidence lookup and review · 72 marks · one of the 17 registers on the Backstaff.

This register is one face of the Backstaff evidence system — the held instrument that holds the measurement engine, maps compliance controls, and engraves every evidence record into a register of record. The full reference library lives at /corpus; the alphabetical view at /corpus/glossary; the operator view at /corpus/switchboard.

API path

Try the evidence path in the sandbox.

The Console shows the sealed evidence and lets anyone verify a record; the Docs carry the endpoints behind it.

01 ·

Marks.

72 source marks in this register.
NIST AI RMF#01 · compliance

NIST AI 100-1 · Govern · Map · Measure · Manage

OMB M-25-21/22#02 · compliance

federal AI risk-management + acquisition

DoW RAI S&IP#03 · compliance

Responsible · Equitable · Traceable · Reliable · Governable

EO 14179#04 · compliance

Removing Barriers to American Leadership in AI (Jan 2025)

ISO/IEC 42001#05 · compliance

international AI management system standard

FIPS 140-3#06 · compliance

crypto module validation · 4 security levels

SHA-256 / FIPS 180-4#07 · compliance

hash algorithm · per-file pinning primitive

SLSA v1.0#08 · compliance

supply-chain levels for software artifacts

SBOM#09 · compliance

software bill of materials · NTIA + CISA

SCITT#10 · compliance

supply-chain integrity, transparency, trust · IETF

C-SCRM#11 · compliance

supply-chain risk · NIST SP 800-161r1

NIST SP 800-53 Rev. 5#12 · compliance

controls baseline · 20 families · AI overlays

CMMC#13 · compliance

Cybersecurity Maturity Model · L1 · L2 · L3

SSDF SP 800-218#14 · compliance

Secure Software Development Framework

ATO#15 · compliance

Authorization to Operate · program-office citation

DoW IL2 / IL4#16 · compliance

DoD Impact Levels · classified delivery

DFARS 252.204-7012#17 · compliance

CUI handling · 72-hour breach reporting

HIPAA#18 · compliance

health privacy · patient data confidentiality

HHS §1557#19 · compliance

ACA non-discrimination in patient-care AI

FDA PCCP / SaMD#20 · compliance

Predetermined Change Control · medical AI

FRE 702#21 · compliance

expert testimony · reliability gatekeeping

ABA Model Rules#22 · compliance

Rule 1.1 · 1.6 · 3.3 · 5.1–5.3 · Op 512

FERPA#23 · compliance

education records · student-data privacy

Title VI#24 · compliance

Civil Rights · disparate-impact disclosure

NIST AI RMF · GOVERN#25 · compliance

Govern function · 6 categories · 19 subcategories · cross-cutting risk culture

NIST AI RMF · MAP#26 · compliance

Map function · context & risk framing · 16 subcategories

NIST AI RMF · MEASURE#27 · compliance

Measure function · TEVV · 19 subcategories · the audit-triad home

NIST AI RMF · MANAGE#28 · compliance

Manage function · risk treatment & prioritization · 10 subcategories

Generative-AI risk profile · companion to the AI RMF

OMB M-25-21#30 · compliance

Federal AI use · Chief AI Officer · high-impact minimum practices (issued 2025-04-03)

OMB M-25-22#31 · compliance

Federal AI acquisition · anti-lock-in · performance/risk monitoring clauses

High-Impact AI#32 · compliance

M-25-21 risk class · 7 minimum practices · the pre-deployment testing obligation

SP 800-218 PS practices · the SLSA-attested subgroup

ISO/IEC 42001 · Annex A#34 · compliance

9 control topics · ~42 AIMS controls · the auditable surface

NIST 800-53 · AU#35 · compliance

Audit & Accountability control family · maps to the evidence record

NIST 800-53 · CA#36 · compliance

Assess/Authorize/Monitor family · maps to the re-run cadence

FedRAMP#37 · compliance

Federal cloud certification · CR26 package evidence + 20x machine-readable KSIs

DoW IL5 / IL6#38 · compliance

Impact Levels 5-6 · NSS + Classified-to-Secret · air-gapped delivery

RMF (SP 800-37)#39 · compliance

Risk Management Framework · the 7-step ATO lifecycle the package follows

ITAR#40 · compliance

USML technical-data control · deemed-export boundary for model artifacts

EAR#41 · compliance

Dual-use export control (EAR99 / CCL) · AI-diffusion chip + weight controls

SCIF / Air-Gap Posture#42 · compliance

Offline / SCIF deployment · evidence check with no network egress

CMS#43 · compliance

Medicare/Medicaid coverage · algorithm cannot be the sole basis to deny care

ONC HTI-1#44 · compliance

predictive-DSI transparency · 31 source attributes · FAVES

DSI Source Attributes#45 · compliance

the 31 predictive-DSI source attributes as an evidence checklist

FDA PCCP#46 · compliance

Predetermined Change Control Plan · drift-bounded model updates

FDA SaMD 510(k)/De Novo#47 · compliance

clearance pathway for AI/ML device software functions

GMLP#48 · compliance

Good Machine Learning Practice · 10 lifecycle principles

HIPAA Security Rule#49 · compliance

ePHI safeguards · 2025 NPRM cyber-modernization (PROPOSED)

FSMB AI / state boards#50 · compliance

physician-responsibility · standard-of-care · state medical-board AI policy

FRE 707 (proposed)#51 · compliance

machine-generated evidence · Rule-702-grade reliability for AI output (PROPOSED)

ABA Formal Op. 512#52 · compliance

generative-AI duties · competence · confidentiality · candor · supervision

AI Citation Sanctions#53 · compliance

hallucinated-authority sanctions wave · Rule 11 / 9011 · candor-to-tribunal

State Bar AI Opinions#54 · compliance

CA · FL · TX · NY · PA · NC bar gen-AI ethics guidance roundup

Section 504#55 · compliance

disability nondiscrimination · FAPE · AI in accommodation determinations

IDEA#56 · compliance

special-ed · IEP integrity · AI in eligibility & service determinations

COPPA#57 · compliance

under-13 data · 2025 amended Rule · ed-tech consent & retention

OCR AI Guidance#58 · compliance

ED Office for Civil Rights · discriminatory-AI nondiscrimination resource

SOPIPA#59 · compliance

student-data-privacy model law · 20+ state adoptions · no-profiling

Proctoring Fairness#60 · compliance

automated proctoring/grading · §504 disparate-impact across cohorts

NYC Local Law 144#61 · compliance

AEDT bias-audit mandate — evidence records an independent auditor can verify

Colorado AI Act#62 · compliance

SB 24-205 → SB 26-189 lineage · high-risk notice/transparency (eff 2027-01-01)

Texas TRAIGA#63 · compliance

HB 149 intent-based AI governance (eff 2026-01-01)

Utah AI Policy Act#64 · compliance

SB 149 / SB 226 disclosure-on-request for generative AI

Illinois HB 3773#65 · compliance

IHRA AI-employment non-discrimination + notice (eff 2026-01-01)

SB 942 + AB 2013 + SB 53 + CCPA ADMT — the CA frontier/transparency stack

EU AI Act#67 · compliance

risk-tiered conformity assessment + post-market monitoring (phased 2025-2027)

EU GPAI Code of Practice#68 · compliance

voluntary interim evidence bridge for general-purpose AI models

UK Pro-Innovation AI#69 · compliance

principles-based, sector-led · AI Bill anticipated 2026

China AI Labelling#70 · compliance

explicit + implicit labelling of AI-generated content (in force 2025-09-01)

India IT Rules (SGI)#71 · compliance

synthetically generated information — labelling, provenance, rapid takedown (in force 2026-02-20)

Korea AI Framework Act#72 · compliance

advance notice of generative AI + output labelling (in force 2026-01-22)

API ·

When a regulator asks for proof, hand over records — not assurances.

record the duty · seal the receipt · verify offline

Planisphere records each duty event — an output marked, a disclosure shown, a review made — and seals it into a receipt that verifies offline against our published keys. You send hashes, never content. A record is evidence a third party can check; it is not a certification and not a legal determination.

See how a record is checked