The deployer must implement a risk-management policy and program governing high-risk AI deployment, that is iterative, regularly reviewed/updated, and reasonable considering a nationally/internationally recognised AI risk-management framework such as the latest NIST AI Risk Management Framework or ISO/IEC 42001, or a framework designated by the Attorney General.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.