Mapping AI findings to your exam vocabulary
Author
Audrey
NobleCloak's AI Correspondent · AI-drafted, fact-checked against our sourced evidence before publishing.
Date Published
You ran the scan. You have a list of AI tools, a pile of OAuth grants, a few vendor questionnaires with uncomfortable blanks in them. You did the work. And then you hit the part nobody warns you about: an examiner does not speak in findings. They speak in due diligence, risk assessment, and monitoring. Your evidence is real, but it's in the wrong language, and a good file that can't be read in exam vocabulary scores like a file that doesn't exist.
This playbook is the translator. It's a reusable crosswalk that takes any raw AI finding and maps it to two recognized vocabularies at once: NCUA's 07-CU-13 / SL 07-01 diligence structure (the operative framework for credit unions — NCUA never adopted the 2023 interagency guidance) and the NIST AI RMF's four core functions. Build the crosswalk once, and every future finding drops into a slot an examiner already recognizes.
Why two vocabularies, not one
The two frameworks answer two different questions an examiner is actually holding in their head.
07-CU-13 answers "did you run a reasonable, proportional vendor-oversight process?" Its structure (SL 07-01) is three concepts: Risk Assessment and Planning, Due Diligence, and Risk Measurement, Monitoring and Control — with the depth of each "commensurate with the credit union's size, complexity, and risk profile." That last clause is the whole game: proportionality is written into the rule, so a small shop is expected to do less analysis on a non-complex vendor, not penalized for it.
NIST AI RMF answers "are you thinking about AI risk in a real framework, or improvising?" Its four functions (NIST) are Govern (the cross-cutting policies, roles, and accountability that inform everything else), Map (context, stakeholders, system boundaries, and potential harms), Measure (analyze, assess, benchmark, and monitor risk), and Manage (allocate resources to the risks you mapped and measured). No US regulator mandates the AI RMF — it's voluntary — but it gives your work a spine an examiner recognizes on sight.
Map every finding to both, and you've shown the examiner the two things they most want: a proportional oversight process and a recognized risk framework. Neither on its own is as convincing as the pair.
The crosswalk, in four moves
For any raw finding, ask four questions in order. The answers are your exam-vocabulary translation.
- What did we learn, and how bad is it? → This is Risk Assessment (07-CU-13) and Map + Measure (NIST). You identified a tool, its access, its data exposure, and you rated it. Mapping is naming the thing and its boundary; measuring is assigning it a severity.
- What did we check on the vendor? → This is Due Diligence (07-CU-13) and Measure (NIST). The questionnaire, the SOC 2 review (or the documented absence of one), the sub-processor list.
- What did we do about it? → This is Risk Measurement, Monitoring and Control (07-CU-13) and Manage (NIST). Revoked, restricted, accepted-with-rationale, escalated.
- How do we stay on top of it? → This is Monitoring (07-CU-13) and Manage + Govern (NIST). The re-review date, the cadence, the owner.
Notice that Govern rarely maps to a single finding — it's the layer underneath all of them: your AI-use policy, the fact that you (named person) own this, the cadence you committed to. When an examiner asks "who's responsible for this and how often do you look?", that's a Govern question, and the answer lives in your one-page summary, not in any individual row.
A worked example
Take the canonical finding this whole discipline keeps running into:
> Otter.ai holds Calendar + Drive read for 8 users since March; recordings retained; no SOC 2 on file.
On its own, that sentence is a security observation. Run it through the crosswalk and it becomes an examiner-legible record of a proportional process:
Crosswalk step | What you write | 07-CU-13 concept | NIST AI RMF function |
|---|---|---|---|
What we learned | Otter.ai (transcription AI) holds Calendar + Drive read access for 8 users since March; meeting recordings retained by vendor; touches member-adjacent scheduling and document data | Risk Assessment and Planning | Map (identify tool, scope, data touched) |
How bad | Rated elevated: standing read access to Drive across 8 users, sensitive-adjacent data, indefinite retention | Risk Assessment and Planning | Measure (severity rating) |
What we checked | Requested SOC 2 — none on file; vendor could not confirm retention deletion terms in writing | Due Diligence | Measure (assess vendor controls) |
What we did | Revoked the grant April 2; removed access; notified the 8 users; logged an approved-alternatives note | Risk Measurement, Monitoring and Control | Manage (allocate response to the risk) |
How we stay on top of it | Added Otter.ai to the quarterly grant re-review; owner: compliance officer; next review dated | Risk Measurement, Monitoring and Control | Manage + Govern (cadence + ownership) |
That single table turns one alarming grant into a demonstration that your program found it, sized it, checked the vendor, acted, and set a watch. The examiner reads it in their own language. And the "no SOC 2 on file" line — the part that looks like a weakness — is actually the most credible row, because it proves you asked the hard question rather than the easy one.
Building your reusable version
You don't want to reason this out finding-by-finding forever. Build the crosswalk into a template once:
- Add five columns to your findings tracker: finding, severity, diligence checked, action taken, next review. Those five columns are the crosswalk — they line up left-to-right with Map → Measure → Measure → Manage, and top-to-bottom with 07-CU-13's three concepts.
- Keep a one-line legend at the top of the sheet stating which columns map to which framework term. That legend is a 30-second gift to an examiner and to future-you.
- Reserve the Govern row for the cover page, not the tracker. Policy, owner, and cadence sit in your governance summary (see What an examiner-ready AI evidence binder contains, Tab 1), because Govern is the frame around every finding, not a finding itself.
- Write proportionality down explicitly. For a non-complex, low-access tool, a defensible entry is one line: "low-risk, read-only calendar scope, 2 users, accepted, annual review." 07-CU-13 invites that brevity. Over-documenting a trivial vendor is not diligence; it's noise that buries the findings that matter.
The upstream findings themselves come from the rest of this series — the inventory from How to run an AI data call, the grants from Reading OAuth grants — the shadow-AI map in your Workspace and Entra, the vendor answers from The AI vendor due-diligence questions that actually matter. This crosswalk is the layer that makes those outputs legible, and it feeds straight into the binder's framework-crosswalk tab. For a deeper read on using the NIST functions as a translation layer rather than a build-it-yourself project, see NIST AI RMF for compliance officers who dont build models.
The honest part
A crosswalk makes your work legible; it does not make it complete. Mapping a finding to Govern/Map/Measure/Manage proves you thought in a recognized structure — it does not prove the underlying diligence was deep, or that you found every tool, or that the vendor's answers were true. The frameworks are a common language, not a grade.
Two specific limits worth stating in the file itself. First, 07-CU-13 is a credit-union framework — an RIA or broker-dealer's examiner is reading against Reg S-P's service-provider oversight language instead (see Reg S-P is live — the AI vendor file your examiner expects), so the left column changes even though the four-move logic doesn't. Second, the NIST AI RMF is voluntary; citing it signals rigor, but claiming it as a mandate would be a rule-zero error and an examiner would catch it. Use the crosswalk to translate honest work into recognized terms. It can't manufacture rigor that the work didn't have — and it shouldn't have to, if you ran the scan for real.
Turning a raw scan into a crosswalked, examiner-legible file — severity-rated, diligence-checked, mapped to both 07-CU-13 and the NIST functions — is exactly the labor a Discover scan is built to hand back done. We run the read-only scan with you and return the findings already in crosswalk shape, so you're reviewing and signing the translation, not building the dictionary from scratch.
Request your Discover scan — we run it with you. Or start upstream with How to run an AI data call and bring the findings back to this crosswalk.