{
  "standard": "HEVIDS",
  "version": "1.1.0",
  "status": "published",
  "canonical_url": "https://hevids.org",
  "doi_concept": "10.5281/zenodo.21045472",
  "license": "CC-BY-SA-4.0",
  "steward": "DRADPA LLC",
  "trademark": "HEVIDS is a trademark of DRADPA LLC (U.S. Serial No. 99376104)",
  "functions": [
    {
      "id": "HA",
      "name": "Harmony",
      "theme": "Governs whether an AI system's outcomes are equitably distributed across the stakeholders it affects, and whether the incentive structure surrounding the system rewards cooperative rather than extractive behavior.",
      "subcategories": [
        {
          "id": "HEVIDS HA-1",
          "outcome_statement": "AI-mediated decisions affecting multiple stakeholder groups are evaluated for distributional fairness using a defined value-allocation method prior to deployment.",
          "mappings": {
            "nist_ai_rmf": [
              "MAP 1.1, MAP 3.1"
            ],
            "eu_ai_act": [
              "Art. 9.2(b) — examination of risks to affected persons/groups"
            ],
            "iso_iec_42001": [
              "Annex A.5 — AI impact assessment"
            ],
            "note": "informative only — function-level crosswalk per Section 5"
          }
        },
        {
          "id": "HEVIDS HA-2",
          "outcome_statement": "Organizations identify and document the full set of internal and external stakeholders materially affected by an AI system's outputs.",
          "mappings": {
            "nist_ai_rmf": [
              "MAP 1.1, MAP 3.1"
            ],
            "eu_ai_act": [
              "Art. 9.2(b) — examination of risks to affected persons/groups"
            ],
            "iso_iec_42001": [
              "Annex A.5 — AI impact assessment"
            ],
            "note": "informative only — function-level crosswalk per Section 5"
          }
        },
        {
          "id": "HEVIDS HA-3",
          "outcome_statement": "Incentive structures governing AI agent behavior are designed so that cooperative, non-zero-sum outcomes are the rational default across interacting agents and principals.",
          "mappings": {
            "nist_ai_rmf": [
              "MAP 1.1, MAP 3.1"
            ],
            "eu_ai_act": [
              "Art. 9.2(b) — examination of risks to affected persons/groups"
            ],
            "iso_iec_42001": [
              "Annex A.5 — AI impact assessment"
            ],
            "note": "informative only — function-level crosswalk per Section 5"
          }
        }
      ]
    },
    {
      "id": "ET",
      "name": "Ethics",
      "theme": "Governs the boundary of actions an AI system is permitted to take, established prior to deployment rather than discovered through post-hoc review.",
      "subcategories": [
        {
          "id": "HEVIDS ET-1",
          "outcome_statement": "The set of actions an AI system is permitted to take is explicitly bounded and documented prior to deployment.",
          "mappings": {
            "nist_ai_rmf": [
              "MAP 5.1, MEASURE 2.3"
            ],
            "eu_ai_act": [
              "Art. 9.2(d), Art. 10 — data and bias provisions"
            ],
            "iso_iec_42001": [
              "Clause 8.2; Annex A.5.2"
            ],
            "note": "informative only — function-level crosswalk per Section 5"
          }
        },
        {
          "id": "HEVIDS ET-2",
          "outcome_statement": "AI systems affecting protected classes undergo documented disparate-impact testing prior to deployment, with results retained as evidence.",
          "mappings": {
            "nist_ai_rmf": [
              "MAP 5.1, MEASURE 2.3"
            ],
            "eu_ai_act": [
              "Art. 9.2(d), Art. 10 — data and bias provisions"
            ],
            "iso_iec_42001": [
              "Clause 8.2; Annex A.5.2"
            ],
            "note": "informative only — function-level crosswalk per Section 5"
          }
        },
        {
          "id": "HEVIDS ET-3",
          "outcome_statement": "Organizations define and document escalation thresholds at which an AI-recommended action exits the admissible action space and requires human authorization.",
          "mappings": {
            "nist_ai_rmf": [
              "MAP 5.1, MEASURE 2.3"
            ],
            "eu_ai_act": [
              "Art. 9.2(d), Art. 10 — data and bias provisions"
            ],
            "iso_iec_42001": [
              "Clause 8.2; Annex A.5.2"
            ],
            "note": "informative only — function-level crosswalk per Section 5"
          }
        }
      ]
    },
    {
      "id": "VE",
      "name": "Veracity",
      "theme": "Governs whether truthful, accurate disclosure is the AI system's dominant strategy — not merely its stated intent.",
      "subcategories": [
        {
          "id": "HEVIDS VE-1",
          "outcome_statement": "Governance mechanisms are designed such that truthful reporting and disclosure is the AI agent's dominant strategy, evaluated against the formal condition that expected penalty exceeds expected gain from deception.",
          "mappings": {
            "nist_ai_rmf": [
              "MEASURE 2.7; GOVERN 4.1"
            ],
            "eu_ai_act": [
              "Art. 13 — transparency; Art. 50 — disclosure"
            ],
            "iso_iec_42001": [
              "Clause 8.2; Annex A.6"
            ],
            "note": "informative only — function-level crosswalk per Section 5"
          }
        },
        {
          "id": "HEVIDS VE-2",
          "outcome_statement": "AI system outputs presented as factual, policy-bound, or authoritative are traceable to a verifiable source or are clearly flagged as generated or unverified.",
          "mappings": {
            "nist_ai_rmf": [
              "MEASURE 2.7; GOVERN 4.1"
            ],
            "eu_ai_act": [
              "Art. 13 — transparency; Art. 50 — disclosure"
            ],
            "iso_iec_42001": [
              "Clause 8.2; Annex A.6"
            ],
            "note": "informative only — function-level crosswalk per Section 5"
          }
        },
        {
          "id": "HEVIDS VE-3",
          "outcome_statement": "Organizations maintain a documented process for detecting and remediating AI outputs that misrepresent system capability, certainty, or authority.",
          "mappings": {
            "nist_ai_rmf": [
              "MEASURE 2.7; GOVERN 4.1"
            ],
            "eu_ai_act": [
              "Art. 13 — transparency; Art. 50 — disclosure"
            ],
            "iso_iec_42001": [
              "Clause 8.2; Annex A.6"
            ],
            "note": "informative only — function-level crosswalk per Section 5"
          }
        }
      ]
    },
    {
      "id": "IN",
      "name": "Integrity",
      "theme": "Governs whether an AI system's behavior remains consistent and aligned as the system, its inputs, and its operating context change over time.",
      "subcategories": [
        {
          "id": "HEVIDS IN-1",
          "outcome_statement": "AI system behavior is tested for consistency across monitored and unmonitored operational contexts at intervals defined by a documented review protocol.",
          "mappings": {
            "nist_ai_rmf": [
              "MANAGE 2.2; MEASURE 2.5"
            ],
            "eu_ai_act": [
              "Art. 9.1 — continuous risk management; Art. 15 — robustness"
            ],
            "iso_iec_42001": [
              "Clause 9.1; Clause 9.3"
            ],
            "note": "informative only — function-level crosswalk per Section 5"
          }
        },
        {
          "id": "HEVIDS IN-2",
          "outcome_statement": "Material updates to an AI system — retraining, fine-tuning, or model substitution — trigger a defined re-validation process before continued deployment.",
          "mappings": {
            "nist_ai_rmf": [
              "MANAGE 2.2; MEASURE 2.5"
            ],
            "eu_ai_act": [
              "Art. 9.1 — continuous risk management; Art. 15 — robustness"
            ],
            "iso_iec_42001": [
              "Clause 9.1; Clause 9.3"
            ],
            "note": "informative only — function-level crosswalk per Section 5"
          }
        },
        {
          "id": "HEVIDS IN-3",
          "outcome_statement": "Organizations document and retain evidence of behavioral invariance testing sufficient to detect emergent misalignment following narrow-task optimization.",
          "mappings": {
            "nist_ai_rmf": [
              "MANAGE 2.2; MEASURE 2.5"
            ],
            "eu_ai_act": [
              "Art. 9.1 — continuous risk management; Art. 15 — robustness"
            ],
            "iso_iec_42001": [
              "Clause 9.1; Clause 9.3"
            ],
            "note": "informative only — function-level crosswalk per Section 5"
          }
        }
      ]
    },
    {
      "id": "DI",
      "name": "Discernment",
      "theme": "Governs whether meaningful human judgment is preserved and resourced as an AI system's autonomy and authority increase.",
      "subcategories": [
        {
          "id": "HEVIDS DI-1",
          "outcome_statement": "High-stakes AI-supported decisions retain a documented, resourced, and authorized human review function capable of overriding system output.",
          "mappings": {
            "nist_ai_rmf": [
              "GOVERN 3.2; MAP 1.5"
            ],
            "eu_ai_act": [
              "Art. 14 — human oversight"
            ],
            "iso_iec_42001": [
              "Clause 5.2; Clause 5.3"
            ],
            "note": "informative only — function-level crosswalk per Section 5"
          }
        },
        {
          "id": "HEVIDS DI-2",
          "outcome_statement": "Organizations define named roles accountable for AI-supported decisions, with documented authority and escalation pathways.",
          "mappings": {
            "nist_ai_rmf": [
              "GOVERN 3.2; MAP 1.5"
            ],
            "eu_ai_act": [
              "Art. 14 — human oversight"
            ],
            "iso_iec_42001": [
              "Clause 5.2; Clause 5.3"
            ],
            "note": "informative only — function-level crosswalk per Section 5"
          }
        },
        {
          "id": "HEVIDS DI-3",
          "outcome_statement": "Oversight mechanisms scale with system autonomy: as an AI system's authorized action space expands, corresponding human review and intervention capacity is documented and verified to expand correspondingly.",
          "mappings": {
            "nist_ai_rmf": [
              "GOVERN 3.2; MAP 1.5"
            ],
            "eu_ai_act": [
              "Art. 14 — human oversight"
            ],
            "iso_iec_42001": [
              "Clause 5.2; Clause 5.3"
            ],
            "note": "informative only — function-level crosswalk per Section 5"
          }
        }
      ]
    },
    {
      "id": "SA",
      "name": "Safeguards",
      "theme": "Governs whether the constraint mechanisms surrounding an AI system remain stable under adversarial, boundary, and resource-exhaustion conditions.",
      "subcategories": [
        {
          "id": "HEVIDS SA-1",
          "outcome_statement": "Governance constraint functions are implemented as continuous, graduated penalty structures rather than binary pass/fail thresholds, to preserve system stability under adversarial or boundary conditions.",
          "mappings": {
            "nist_ai_rmf": [
              "MANAGE 1.1; GOVERN 5.1"
            ],
            "eu_ai_act": [
              "Art. 9 — risk management system; Art. 15 — robustness"
            ],
            "iso_iec_42001": [
              "Clause 8.2; Annex A.7"
            ],
            "note": "informative only — function-level crosswalk per Section 5"
          }
        },
        {
          "id": "HEVIDS SA-2",
          "outcome_statement": "Organizations define and enforce a financial or resource ceiling on autonomous AI system operation, with automated alerting prior to threshold breach.",
          "mappings": {
            "nist_ai_rmf": [
              "MANAGE 1.1; GOVERN 5.1"
            ],
            "eu_ai_act": [
              "Art. 9 — risk management system; Art. 15 — robustness"
            ],
            "iso_iec_42001": [
              "Clause 8.2; Annex A.7"
            ],
            "note": "informative only — function-level crosswalk per Section 5"
          }
        },
        {
          "id": "HEVIDS SA-3",
          "outcome_statement": "Monitoring of AI system behavior employs unpredictable or randomized inspection patterns sufficient to deter strategic, monitoring-aware non-compliance.",
          "mappings": {
            "nist_ai_rmf": [
              "MANAGE 1.1; GOVERN 5.1"
            ],
            "eu_ai_act": [
              "Art. 9 — risk management system; Art. 15 — robustness"
            ],
            "iso_iec_42001": [
              "Clause 8.2; Annex A.7"
            ],
            "note": "informative only — function-level crosswalk per Section 5"
          }
        }
      ]
    }
  ]
}