Apply privacy and records management per NIST SP 800-63-4. Privacy requirements per Section 7 of each Volume require (a) purpose limitation + minimisation + storage limitation + lawful basis per applicable jurisdiction, (b) Privacy Impact Assessment per agency obligations, (c) Privacy Act + GDPR + state law + sectoral compliance, (d) subscriber notice + consent + redress, (e) limits on biometric retention and reuse beyond original purpose. Records retention per Volume A Section 4.8 + Volume B Section 6.7 + Volume C Section 10 covering chain of custody for evidence + biometrics + transcripts + lifecycle events as required by agency policy + statute. User-controlled wallets (NEW in Rev 4) per emerging guidance: when issuing or accepting credentials held in user-controlled wallets (mDL + verifiable credentials + decentralised identifiers) (a) define the trust framework + revocation mechanism + binding to subscriber + privacy properties + recovery model, (b) align with NIST SP 800-63-4 attribute model and federation patterns where applicable, (c) preserve user control over disclosure.
This control maps to 33 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 33 it maps to, and the evidence behind each claim, over MCP and REST.