Compliance Mapping

NIST AI RMF 1.0 Alignment

This document maps Rigour's deterministic quality gates to the four core functions of the NIST AI Risk Management Framework (AI RMF 1.0). Rigour is an open-source, local-first tool that enforces engineering quality standards on AI-generated code — providing measurable, auditable governance without sending code to external servers.

GOVERN

Policies, Accountability & Culture

Rigour enforces organizational AI policies as deterministic code — not documents that drift. Every quality gate is policy-as-code, version-controlled, and auditable.

GOVERN 1 — Policies for AI risk management
Rigour:rigour.yml configuration defines all quality thresholds, security rules, and architectural boundaries as declarative YAML. Changes are tracked in version control with full git history.
GOVERN 2 — Accountability structures
Rigour:Agent Team Governance enforces strict task ownership — each AI agent registers its scope, and Rigour prevents unauthorized file modifications. Handoff verification ensures context integrity between agents.
GOVERN 3 — Workforce diversity of perspective
Rigour:Multi-agent sessions support cross-agent pattern checking, preventing groupthink. Provenance tags (ai-drift, traditional, security, governance) attribute every violation to its origin, ensuring diverse quality signals.
GOVERN 4 — Organizational commitment to risk culture
Rigour:Industry Presets (healthcare, fintech, government, devsecops) encode risk-aware defaults. One command — rigour init --preset government — applies NIST-aligned strictness across an entire codebase.
MAP

Context, Risk Identification & Categorization

Rigour automatically maps the risk context of AI-generated code — identifying what type of system it is, what regulations apply, and where AI-specific risks exist.

MAP 1 — Intended context of AI system use
Rigour:Project detection automatically identifies the codebase type (API, UI, infrastructure, data pipeline) and applies appropriate quality thresholds. Regulated industry presets further contextualize risk for healthcare (HIPAA), finance (SOC2/PCI), and government (FedRAMP/NIST) systems.
MAP 2 — AI system categorization
Rigour:Provenance tagging categorizes every quality violation by origin: ai-drift (hallucinated imports, unhandled promises), traditional (complexity, file size), security (SQL injection, XSS, hardcoded secrets), and governance (missing documentation, checkpoint failures).
MAP 3 — AI-specific risks identification
Rigour:AI-Native Gates detect risks unique to AI-generated code: hallucinated imports (packages that don't exist in the dependency manifest), floating promises, unsafe async patterns, and context window degradation artifacts — across 6 languages.
MAP 5 — Impact characterization
Rigour:Severity-weighted scoring (Critical: -20, High: -10, Medium: -5, Low: -2) ensures high-impact violations are surfaced first. The Two-Score System separates ai_health_score from structural_score for precise impact attribution.
MEASURE

Metrics, Monitoring & Assessment

Rigour provides continuous, deterministic measurement of AI code quality — not subjective reviews, but repeatable PASS/FAIL gates with full audit trails.

MEASURE 1 — Appropriate methods and metrics
Rigour:12+ built-in quality gates including cyclomatic complexity, function length, parameter count, file size, dependency analysis, architecture boundary enforcement, and security pattern detection. All gates produce deterministic, repeatable results.
MEASURE 2 — AI systems evaluated for trustworthiness
Rigour:Every rigour check produces a scored report (0-100) with severity breakdown, provenance attribution, and per-file violation details. The Two-Score System independently measures AI health and structural quality.
MEASURE 3 — Mechanisms for tracking metrics over time
Rigour:Score Trending records every check result to .rigour/score-history.jsonl. After 3+ runs, trend analysis classifies quality trajectory as improving, stable, or degrading — enabling regression detection and compliance dashboards.
MEASURE 4 — Feedback from internal and external sources
Rigour:Fix Packets provide actionable, structured feedback for every violation — including file path, line number, severity, hint text, and provenance tag. Agents and humans receive identical feedback, ensuring consistency.
MANAGE

Response, Recovery & Communication

Rigour enforces bounded, recoverable AI workflows — preventing runaway agents, limiting blast radius, and providing exportable audit artifacts for compliance reporting.

MANAGE 1 — AI risks managed through response plans
Rigour:Supervised Mode (rigour run-supervised) creates bounded retry loops: run command → check gates → generate fix packet → retry. Max retries prevent infinite loops. Checkpoint Supervision monitors long-running agents with quality thresholds and drift detection.
MANAGE 2 — AI risk response strategies
Rigour:Safety Gates enforce blast radius limits: max_files_changed_per_cycle (default: 10) prevents mass modifications, protected_paths blocks changes to critical files (.github/**, docs/**, rigour.yml), and security gates block commits above severity threshold.
MANAGE 3 — AI risk management processes and outcomes documented
Rigour:Export Audit (rigour export-audit) generates compliance-ready audit packages in JSON or Markdown — including score trends, severity breakdowns, provenance attribution, gate results, and full violation details. Directly consumable by compliance officers and auditors.
MANAGE 4 — AI risks communicated to relevant stakeholders
Rigour:Every quality gate check produces structured output readable by both humans (CLI terminal, Markdown reports) and machines (JSON, Fix Packets, MCP protocol). GitHub PR integration posts results directly into code review workflows.

Coverage Summary

RMF FunctionRigour CapabilitiesKey Features
GOVERNPolicy-as-code, agent governance, provenance attributionrigour.yml, agent_team, industry presets
MAPAuto-detection, risk categorization, AI-specific risk identificationProvenance tags, AI-native gates, severity scoring
MEASUREDeterministic scoring, trend analysis, structured feedbackTwo-score system, score trending, fix packets
MANAGEBounded workflows, blast radius limits, audit exportSupervised mode, safety gates, export-audit

Technical Specifications

Architecture

  • Runtime: 100% local — zero telemetry, no external API calls
  • Integration: MCP (Model Context Protocol), CLI, GitHub App
  • Languages: TypeScript, JavaScript, Python, Go, Rust, Java, C#, C/C++, PHP, Swift, Kotlin
  • Analysis: Tree-sitter AST parsing — no regex pattern matching

Audit Output

  • Formats: JSON (machine-readable), Markdown (human-readable)
  • Scoring: 0-100 with severity-weighted deductions
  • Trending: JSONL append-only history with trend classification
  • Command: rigour export-audit --format json

Get Started

Rigour is open-source and free. Install it in your project and run your first quality gate check in under 60 seconds.

$ npx @rigour-labs/cli init --preset government