Claims ladder
Allowed
- ✓ produces evidence aligned to FS AI RMF
- ✓ readiness for voluntary control objectives
- ✓ scoped SDLC / change-management slice
Not allowed
- — FS AI RMF certified
- — required by FS AI RMF
- — covers all 230 objectives
Grounded mapping (Jul 2026), crosswalked to the official Risk & Control Matrix v1.0. Voluntary framework — produces evidence for; not certified by. Scope: SDLC, change-management, and audit-trail themes for agent-assisted software changes.
Framework: FS AI RMF (Feb 2026, CRI/FSSCC). Mapped to official FS AI RMF Risk & Control Matrix v1.0 reference IDs — scoped to the SDLC/change-management slice, not the full 230 objectives.
| Theme | Function | RCM ref | Control need | SSX360 artifact |
|---|---|---|---|---|
| Change authorization | Manage | MG-4.1.4 | Agent-assisted merges to protected branches are authorized and attributable | Signed commit envelope (provenance.actor, provenance.tool, provenance.scope) |
| Integrity before deploy | Manage | MG-1.1.2 | Changes are verified before production paths update | Scroll Gate CI result per PR (ssx360 check --pr) |
| Tamper-evident record | Govern | GV-1.4.3 | Audit trail survives independent review | Ed25519 signature on envelope — offline verify in CLI or browser |
| Export for review | Govern | GV-1.4.2 | Evidence consumable without trusting SSX360 | ssx360-ledger --export → ssx360.evidence-pack.v1 JSON |
| Agent registry | Govern | GV-1.6.1 | Declared agents/tools tracked over time | Approved-agent registry snapshot in evidence pack |
| Payments / ledger paths | Govern | GV-1.6.2 | Financial-infra code paths gated | Policy preset financial-infra on payments/**, ledger/** |
RCM IDs are real Risk & Control Matrix v1.0 control-objective references. The theme column is SSX360's own paraphrase of each control's scope, not a verbatim quote of CRI's text.
| RCM ID | Control objective theme | Evidence SSX360 produces |
|---|---|---|
| MG-4.1.4 | Change management for AI systems — updates run through structured, documented, trackable processes | Envelope provenance.actor_type, provenance.tool on every agent-assisted merge |
| MG-1.1.2 | Go/No-Go decision criteria — clear thresholds gate whether a change proceeds, pauses, or is rejected | Scroll Gate blocked / review events in ledger |
| GV-1.4.3 | Documentation repository with access controls, kept ready for oversight and audit | Signed evidence pack + detached signature |
| GV-1.6.1 | Inventory of systems/tooling with responsible owners and dependencies tracked | MCP / hook metadata in envelope (declared tool identity) |
| GV-1.6.2 | High-risk / mission-critical systems get enhanced oversight, control, and reporting | financial-infra policy rule outcomes on payments/**, ledger/** |
| GV-1.4.2 | Documentation standards covering monitoring and change-management activity | compliance_mappings[] includes FS AI RMF entry |
| MS-2.1.3 | Centralized, version-controlled, access-controlled repository enabling independent review | matrixscroll verify / browser verifier at ssx360.com/verify |
Same change-management evidence class — FS AI RMF opens the conversation; PCI and SOC 2 close where assessors write the invoice.
| PCI need | SSX360 evidence |
|---|---|
| Authorized custom software changes | Protected-branch Scroll Gate |
| Trace agent-assisted edits | Signed envelope per commit |
| Assessor review | Evidence pack sample + offline verify |
Allowed
Not allowed
We welcome feedback on this draft mapping — email mission@ssx360.com or use the contact form.
Send mapping feedback