An AI system operates in an ecosystem of functional layers, and trust is established and maintained at each: physical trust (sensors, actuators, the physical infrastructure for data collection), where trust is close to reliability and safety, established by measurement, test, checklists and processes such as sensor calibration; cyber trust (the IT infrastructure, such as cloud services, where data is stored and processed), where the concerns are security needs such as controlling access, together with measures for system integrity and data safety; and social or end-application trust (ML algorithms, expert systems, end-user applications), which requires reliable and safe software framed by verification and validation processes and, given the stochastic nature of ML, fairness of behaviour through the absence of inappropriate bias.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.