PegasusCollective
The HOT Framework HOT HumanOrganizationTechnology The Model The Work Standards
The Work · governance & standards

The Four Pillars, mapped to the standards you already answer to.

A direct mapping, not a substitution.

The Four Pillars of GOVERN / ASSURE are the production implementation of what NIST, OWASP, and the Cloud Security Alliance specify in the abstract.

When the conversation opens at "how does this map to NIST AI RMF?" — this page is the answer. It's the canonical reference the governance rail points to.

01 · The position

Operationalize the standard. Don't replace it.

CISOs, auditors, and boards already speak NIST, OWASP, and CSA. The Pillars don't ask them to learn a new vocabulary — they are the production reality those frameworks describe.

Saying "we use the Four Pillars instead of NIST" is the failure mode: what a CISO hears is "we made up our own framework," and the build stalls. Lead with the standard they know, show the mapping, end with the operational reality the Pillars deliver that the framework alone does not.

THE STANDARD · IN THE ABSTRACT NIST AI RMF OWASP LLM 10 CSA AICM operationalized by THE FOUR PILLARS · IN PRODUCTION EVALS LOGS ROLLBACK REVIEW A DEPLOYMENT GATE · CAPPED AT THE LOWEST PILLAR Both layers exist. Neither replaces the other.
Abstract standard, production primitive
02 · The three frameworks anchored

Three references a board already recognizes.

NIST AI RMF
National Institute of Standards and Technology · 2023
The voluntary framework governing risk across the AI lifecycle. The default reference for US federal agencies and the de facto vocabulary of enterprise risk committees.
NIST AI RMF at NIST.gov ↗
OWASP LLM Top 10
OWASP Foundation
The ten most critical failure modes for LLM-backed applications — prompt injection, sensitive-information disclosure, insecure output handling, excessive agency. OWASP names the failures the Pillars catch.
OWASP LLM Top 10 at OWASP.org ↗
CSA AI Controls Matrix
Cloud Security Alliance · July 2025
243 control objectives across 18 domains — the controls superset auditors map directly to ISO 27001, SOC 2, and HIPAA inventories. The Pillars implement, rather than restate, the relevant controls.
AI Controls Matrix at CSA ↗
The parallel · OpenText ADLC
An independent lifecycle discipline has emerged alongside these — OpenText's Agentic Development Lifecycle, governing agent creation, monitoring, safety-testing, and retirement. It maps onto the Four Pillars the same way: when an OpenText-aligned CIO speaks ADLC, translate at the boundary, exactly as with NIST and OWASP.
03 · Per-Pillar mapping

Each Pillar, and what it operationalizes.

Pillar 1
Trusted Evals
NISTThe Measure function — testing, evaluation, validation, monitoring.
OWASPCatches drift surfacing as misbehavior, hallucination, quality degradation.
CSA AICMModel validation, performance monitoring, continuous testing.

Every agent runs continuously against a known, versioned test set. Drift below a quantified threshold — an accuracy floor, an override-rate ceiling — triggers retraining or rollback automatically. An agent without an eval suite is a demo, not a production agent.

Pillar 2
Searchable Logs with Correlation IDs
NISTThe Manage function — transparency, accountability, traceability.
OWASPInsecure output handling and sensitive-information disclosure, caught on inspection.
CSA AICMLogging, audit-trail, and forensic-recovery objectives.

Every decision is recoverable from the audit trail alone — sense, interpret, decide, orchestrate, outcome, chained on a single correlation ID. Logs are immutable, hashed, and signed. Any outcome can be reconstructed and explained without reproducing the run.

Pillar 3
Granular Rollback
NISTThe Manage function — incident response, recovery, lifecycle versioning.
OWASPResponse to insecure output, excessive agency, and overreliance.
CSA AICMConfiguration-management, version-control, and recovery objectives.

Any single agent class is revertible to last week's prompt, last month's model, or last quarter's policy — without taking the rest of the Stack down. Agent versions are treated the way disciplined engineering treats software: traceable, diffable, recoverable. An agent stack without rollback is one you cannot govern.

Pillar 4
Human Review Queue
NISTThe Govern function — accountability, human oversight, decision authority.
OWASPExcessive agency, overreliance, insecure output handling.
CSA AICMHuman-oversight, escalation, and segregation-of-duties objectives.

Anything that touches money, legal text, or a customer-of-record routes to a named human in a queue with SLAs. The queue is staffed, measured, and visible to leadership. Humans above the loop, not in it, on the decisions where a name is required.

04 · The OWASP question

"How do we handle the OWASP LLM Top 10?"

When the security team asks it directly, these are the four failure modes the Pillars catch — and which Pillars carry the catch.

Failure mode
Caught by
Prompt injection
Trusted Evals test for injection-pattern drift · Searchable Logs reveal the injection path on review · Human Review Queue routes high-risk outputs to a person.
Sensitive-information disclosure
Searchable Logs detect the disclosure · Granular Rollback contains the blast radius · Human Review Queue routes sensitive outputs to a human.
Insecure output handling
Trusted Evals test for unsafe output patterns · Searchable Logs capture the output with a correlation ID · Granular Rollback recovers from bad-output propagation.
Excessive agency
Granular Rollback contains the overreach · Human Review Queue routes high-agency decisions to a human · the Permission Envelope and Autonomy Tier bound the agent at the spec.
05 · The board frame

When the audience is the board, lead with Sonnenfeld.

In May 2026, Jeffrey Sonnenfeld's Yale CELI brought the argument to the boardroom: every public-company board needs a formal agentic-governance framework — decision rights, escalation thresholds, fiduciary liability, disclosure — before regulators write one. That quartet maps one-to-one onto the Four Pillars.

Board requirement
Four Pillars implementation
Decision rights
Human Review Queue — who decides, with named owners and SLAs — plus Permission Envelopes and Autonomy Tiers.
Escalation thresholds
Trusted Evals — quantified drift thresholds firing alerts before customers see failure — plus the escalation rules in every agent spec.
Fiduciary liability
The Fiduciary Wedge, made auditable by Searchable Logs with Correlation IDs — every decision recoverable from the trail alone.
Disclosure
Searchable Logs plus Granular Rollback — the incident record is reconstructable, the remediation path demonstrable.
The CFO reframe
Pair the board mapping with the control-plane reframe: GOVERN / ASSURE is a revenue-protection mechanism designed to protect the balance sheet from autonomous operational degradation. The public failures — 120,000 lost orders, 1.6M marketplace errors — are the financialization evidence.
06 · What this mapping is not

Both layers exist for a reason.

The Pillars are operational primitives; the frameworks are the broader risk taxonomies those primitives live inside. The Pillars give you the production reality the frameworks describe in the abstract.

A direct mapping, not a substitution.

It is not a NIST AI RMF self-assessment. If the CISO asks for one, do the self-assessment.
It is not an OWASP threat model. If the security team wants one, build it.
It is not a CSA AICM controls audit. If the auditor asks for AICM evidence, generate the evidence.
The journey starts with a reading

Before the first move, an honest reading of where you stand.

Five minutes across three fronts: your people, your organization, and your technology, each scored against published anchors. No email required; the result is yours to keep.

Run the HOT scan →
← Back to The Work Start the conversation →
The ExO 3.0 framework — MTP, DRIVE, SHAPE, the Intelligence Stack, and the REWRITE playbook — is the work of
Salim Ismail and contributors. OpenExO · The Organizational Singularity ↗