Skip to content

CDFI Framework v1.4

Choose a tag to compare

@mj3b mj3b released this 30 May 20:40
· 73 commits to main since this release
5a9bb20

CDFI Framework v1.4

AI Governance Framework Alignments and Security Documentation

This release adds three governance documents that position the CDFI Framework
within the major secular AI governance standards and documents the LLM-as-judge
security surface for the first time.


What was added

docs/governance/nist-rmf-mapping.md
Alignment with NIST AI RMF 1.0 (January 2023) and the NIST AI 600-1 GenAI
Profile (2024). All four functions mapped: GOVERN, MAP, MEASURE, MANAGE.
24 sub-functions assessed — all partially or fully satisfied. Maps CDCF
criteria to NIST RMF functions for U.S. Catholic institutional reviewers.

docs/governance/eu-ai-act-mapping.md
Alignment with Regulation (EU) 2024/1689 (EU AI Act). Articles 9–15 assessed
for Catholic formation and education AI deployment. Articles 11, 13, and 14
satisfied. Articles 9, 10, 12, and 15 partially satisfied. Fundamental rights
impact assessment and conformity assessment documented as open institutional
obligations. August 2026 high-risk compliance deadline documented.

docs/governance/security-considerations.md
Three attack surfaces documented with OWASP LLM Top 10 (2025) and MITRE ATLAS
mapping:

  • Surface 1: Judge prompt injection (LLM01)
  • Surface 2: Scoring pipeline integrity (LLM04, LLM08)
  • Surface 3: Authority level classification manipulation (LLM09)

Current mitigations documented. Remediations planned for v1.5.


What was updated

  • README.md — status badge updated to v1.4; three new badges added
    (NIST AI RMF, EU AI Act, OWASP LLM Top 10); directory tree updated;
    L7 security limitation added
  • CITATION.cff — version updated to 1.4
  • LIMITATIONS.md — version updated to v1.4; L7 added
  • CHANGELOG.md — full v1.4 entry with active links throughout

Frameworks considered for this release

Framework Decision
NIST AI RMF 1.0 Mapped
EU AI Act (2024) Mapped
OWASP LLM Top 10 (2025) Referenced in security doc
MITRE ATLAS Referenced in security doc
ISO/IEC 42001:2023 Deferred to v1.5
ISO/IEC 23894:2023 Deferred to v1.5

DOI: 10.5281/zenodo.20467497