What is this course about?
Authorization is where agency AI projects stall, usually because the boundary was never properly defined and the model sits outside it. This course covers boundary definition when a model is in the loop, the NIST 800-53 control families that generative AI strains most, continuous monitoring when the vendor updates the model, and where self-hosting shortens the path.
Who is this course for?
- Information system security officers and managers
- Authorizing officials and their staff
- Agency CIOs and CISOs
- Compliance and assessment contractors
What do I need before starting?
- Familiarity with the RMF or an equivalent authorization process
- Experience with control assessment
What will I be able to do afterwards?
- Define an authorization boundary when a model is in the processing path
- Select and tailor the NIST 800-53 controls generative AI strains most
- Design continuous monitoring for a system whose model changes underneath it
- Assess third-party model risk inside a federal boundary
- Assemble the SSP artifacts an assessor will ask for
What does each module cover?
What authorization path applies to your AI system?
45 minFedRAMP, agency ATO, and state equivalents, and how the choice constrains architecture.
Objectives
- Determine which authorization path applies
- Understand how the path constrains deployment options
- Estimate timeline and effort realistically
Topics
Activity. Determine the applicable path for one planned AI system and estimate the timeline.
Where does the boundary go when a model is in the loop?
55 minBoundary definition, the step that determines whether authorization is achievable at all.
Objectives
- Define the authorization boundary precisely
- Determine whether the model is inside or outside
- Handle external service dependencies
Topics
Activity. Draw the boundary for one AI system and defend every inclusion and exclusion.
Which 800-53 control families does generative AI strain?
55 minThe control families where a non-deterministic component does not fit the existing assumption.
Objectives
- Identify the strained control families
- Tailor controls for a non-deterministic component
- Document tailoring rationale defensibly
Topics
Activity. Tailor five strained controls for an AI system with written rationale.
What happens to your ATO when the model updates?
50 minContinuous monitoring for a system whose core component changes on the vendor's schedule.
Objectives
- Design monitoring that detects model change
- Determine what constitutes a significant change
- Plan reauthorization triggers
Topics
Activity. Write the significant-change criteria for a model-backed system.
How do you assess third-party model risk?
50 minSupply chain risk when the model weights come from outside the agency.
Objectives
- Assess model provenance and integrity
- Evaluate supply chain risk for weights and adapters
- Determine acceptable sources
Topics
Activity. Perform a supply chain assessment for one model you plan to deploy.
Where does self-hosting shorten the path?
45 minAn honest comparison of authorization effort for hosted versus agency-controlled deployment.
Objectives
- Compare authorization effort across deployment models
- Identify where self-hosting genuinely reduces scope
- Recognize where it adds agency burden instead
Topics
Activity. Compare the control inheritance and effort for two deployment options.
What artifacts will an assessor ask for?
50 minAssembling the SSP components specific to an AI system before assessment.
Objectives
- Assemble the AI-specific SSP components
- Produce evidence for the tailored controls
- Anticipate assessor questions
Topics
Activity. Assemble the AI section of an SSP and have a colleague assess it.
Building the control mapping and boundary diagram
60 minThe workshop module: a complete boundary diagram and control mapping for one agent.
Objectives
- Produce a defensible boundary diagram
- Complete the control mapping
- Identify the remaining gaps
Topics
Activity. Complete the diagram and mapping, then review with an authorizing official.
What is the capstone project?
Authorization package for one AI system
Produce the authorization artifacts for a real planned AI system: boundary diagram, tailored control set with written rationale, continuous monitoring plan with significant-change criteria, supply chain assessment, and the AI section of the SSP.
Deliverable: An authorization package an assessor could review and an authorizing official could act on.
How are learners assessed?
- Boundary diagram defended inclusion by inclusion
- Control tailoring rationale reviewed for defensibility
- Significant-change criteria tested against a real model version update
What ships with the course?
Facilitator guide
Session-by-session running order, discussion prompts, and the questions that reliably derail a room.
Learner workbook
Exercises, checklists, and the templates each module's activity produces.
Hands-on lab environment
A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.
Assessment bank
Scenario questions and rubric criteria mapped to each stated learning outcome.
Source bibliography
Every primary regulation and standard cited on this page, linked and dated.
Which AI agents does this course use?
The hands-on modules run against agents already deployable on the ibl.ai platform for government.
Where does the course material come from?
Every module is grounded in primary sources — the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.
- FedRAMP
FedRAMP PMO
Authorization process and baseline requirements.
- NIST SP 800-53 Rev. 5
NIST
The control catalog tailored throughout the course.
- AI Risk Management Framework
NIST
AI-specific risk considerations mapped into the control set.
- Artificial Intelligence
CISA
Federal guidance on securing AI systems.
Delivery notes
Binding guidance for anyone preparing and delivering this course.
- Module 2 is the module that determines project success. Boundary errors discovered at assessment cost months, and most agency AI projects make one.
- Module 4's significant-change problem has no settled answer across agencies. Present the options and the reasoning rather than asserting a single correct approach.
- Module 6 must be honest that self-hosting shifts rather than eliminates burden. Agencies without operational capacity may be worse off, and the course should say so.
- Have an experienced ISSO review the whole course. Authorization practice varies by agency and generic RMF content will not survive contact with a real assessment.
- Re-verify FedRAMP process details at each revision — the program's requirements and templates change.
Why run AI training on a platform you own?
You own the course, not a licence to it
Course content, learner data, and the platform run inside your perimeter — you own all the code and the data.
Model-agnostic delivery
Run the course's AI components on any LLM — Claude, GPT, Llama, Gemini, Command — and switch anytime.
No per-seat training licences
Usage-based or self-hosted, so cost tracks actual use rather than headcount.
Deploy anywhere
Cloud, private VPC, on-premise, or fully air-gapped — including for cohorts that cannot use public AI tools.
Frequently asked questions
What does the Getting an AI System Authorized: FedRAMP and NIST 800-53 course cover?
Authorization is where agency AI projects stall, usually because the boundary was never properly defined and the model sits outside it. This course covers boundary definition when a model is in the loop, the NIST 800-53 control families that generative AI strains most, continuous monitoring when the vendor updates the model, and where self-hosting shortens the path. It runs 6.5 hours across 8 modules across 8 modules, at advanced level, and closes with a capstone: Authorization package for one AI system.
Who should take Getting an AI System Authorized: FedRAMP and NIST 800-53?
It is written for Information system security officers and managers, Authorizing officials and their staff, Agency CIOs and CISOs, Compliance and assessment contractors. Prerequisites: Familiarity with the RMF or an equivalent authorization process; Experience with control assessment.
Can we run this course on our own infrastructure?
Yes. ibl.ai is model-agnostic and deploy-anywhere — cloud, private VPC, on-premise, or fully air-gapped — and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for government teams that cannot send work to a public AI tool.
How do we get access to Getting an AI System Authorized: FedRAMP and NIST 800-53?
Request access and we will set it up for your cohort — hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.
How much does AI training for government cost on ibl.ai?
There is no per-seat pricing — you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.