# Getting an AI System Authorized: FedRAMP and NIST 800-53

> Government · AI Course · GOV-1
> Source: https://ibl.ai/solutions/government/course/authorizing-ai-fedramp-nist-800-53
> Last updated: 2026-08-25

**The authorization path for AI in a federal or state agency — control selection, boundary definition, and why an LLM complicates the system security plan.**

## The Short Answer

**Agency AI projects stall at authorization because the model sits outside a boundary nobody defined properly. ibl.ai can be deployed entirely inside the agency's authorization boundary — you own all the code and the data, so the model, weights, and inference are agency-controlled assets rather than an external dependency requiring separate authorization.**

On ibl.ai you own all the code and the data, run it model-agnostic across any LLM, and pay with no per-seat pricing — so you can deploy anywhere, from your own cloud to a fully air-gapped network.

[Request Access](https://ibl.ai/contact) · [Explore Government](https://ibl.ai/solutions/government)

## Course facts

- **Level:** Advanced
- **Duration:** 6.5 hours across 8 modules
- **Format:** Cohort workshop producing authorization artifacts
- **Modules:** 8
- **Catalog code:** GOV-1
- **Frameworks covered:** FedRAMP, NIST SP 800-53, NIST AI RMF, NIST SP 800-171

## What is this course about?

Authorization is where agency AI projects stall, usually because the boundary was never properly defined and the model sits outside it. This course covers boundary definition when a model is in the loop, the NIST 800-53 control families that generative AI strains most, continuous monitoring when the vendor updates the model, and where self-hosting shortens the path.

## Who is this course for?

- Information system security officers and managers
- Authorizing officials and their staff
- Agency CIOs and CISOs
- Compliance and assessment contractors

### What do I need before starting?

- Familiarity with the RMF or an equivalent authorization process
- Experience with control assessment

## What will I be able to do afterwards?

- Define an authorization boundary when a model is in the processing path
- Select and tailor the NIST 800-53 controls generative AI strains most
- Design continuous monitoring for a system whose model changes underneath it
- Assess third-party model risk inside a federal boundary
- Assemble the SSP artifacts an assessor will ask for

## What does each module cover?

### Module 1 — What authorization path applies to your AI system?

FedRAMP, agency ATO, and state equivalents, and how the choice constrains architecture. _(45 min)_

**Objectives**

- Determine which authorization path applies
- Understand how the path constrains deployment options
- Estimate timeline and effort realistically

**Topics:** FedRAMP · Agency ATO · State equivalents · Path selection

**Activity:** Determine the applicable path for one planned AI system and estimate the timeline.

### Module 2 — Where does the boundary go when a model is in the loop?

Boundary definition, the step that determines whether authorization is achievable at all. _(55 min)_

**Objectives**

- Define the authorization boundary precisely
- Determine whether the model is inside or outside
- Handle external service dependencies

**Topics:** Boundary definition · Model placement · External dependencies · Interconnection agreements

**Activity:** Draw the boundary for one AI system and defend every inclusion and exclusion.

### Module 3 — Which 800-53 control families does generative AI strain?

The control families where a non-deterministic component does not fit the existing assumption. _(55 min)_

**Objectives**

- Identify the strained control families
- Tailor controls for a non-deterministic component
- Document tailoring rationale defensibly

**Topics:** Access control · Audit and accountability · System and information integrity · Tailoring rationale

**Activity:** Tailor five strained controls for an AI system with written rationale.

### Module 4 — What happens to your ATO when the model updates?

Continuous monitoring for a system whose core component changes on the vendor's schedule. _(50 min)_

**Objectives**

- Design monitoring that detects model change
- Determine what constitutes a significant change
- Plan reauthorization triggers

**Topics:** Change detection · Significant change determination · Reauthorization triggers · Vendor notification

**Activity:** Write the significant-change criteria for a model-backed system.

### Module 5 — How do you assess third-party model risk?

Supply chain risk when the model weights come from outside the agency. _(50 min)_

**Objectives**

- Assess model provenance and integrity
- Evaluate supply chain risk for weights and adapters
- Determine acceptable sources

**Topics:** Model provenance · Weight integrity · Supply chain risk · Source acceptability

**Activity:** Perform a supply chain assessment for one model you plan to deploy.

### Module 6 — Where does self-hosting shorten the path?

An honest comparison of authorization effort for hosted versus agency-controlled deployment. _(45 min)_

**Objectives**

- Compare authorization effort across deployment models
- Identify where self-hosting genuinely reduces scope
- Recognize where it adds agency burden instead

**Topics:** Effort comparison · Scope reduction · Inherited controls · Added agency burden

**Activity:** Compare the control inheritance and effort for two deployment options.

### Module 7 — What artifacts will an assessor ask for?

Assembling the SSP components specific to an AI system before assessment. _(50 min)_

**Objectives**

- Assemble the AI-specific SSP components
- Produce evidence for the tailored controls
- Anticipate assessor questions

**Topics:** SSP components · Evidence packages · Assessor expectations · Common findings

**Activity:** Assemble the AI section of an SSP and have a colleague assess it.

### Module 8 — Building the control mapping and boundary diagram

The workshop module: a complete boundary diagram and control mapping for one agent. _(60 min)_

**Objectives**

- Produce a defensible boundary diagram
- Complete the control mapping
- Identify the remaining gaps

**Topics:** Boundary diagram · Control mapping · Gap identification · Remediation planning

**Activity:** Complete the diagram and mapping, then review with an authorizing official.

## What is the capstone project?

**Authorization package for one AI system.** Produce the authorization artifacts for a real planned AI system: boundary diagram, tailored control set with written rationale, continuous monitoring plan with significant-change criteria, supply chain assessment, and the AI section of the SSP.

_Deliverable:_ An authorization package an assessor could review and an authorizing official could act on.

## How are learners assessed?

- Boundary diagram defended inclusion by inclusion
- Control tailoring rationale reviewed for defensibility
- Significant-change criteria tested against a real model version update

## What ships with the course?

- **Facilitator guide.** Session-by-session running order, discussion prompts, and the questions that reliably derail a room.
- **Learner workbook.** Exercises, checklists, and the templates each module's activity produces.
- **Hands-on lab environment.** A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.
- **Assessment bank.** Scenario questions and rubric criteria mapped to each stated learning outcome.
- **Source bibliography.** Every primary regulation and standard cited on this page, linked and dated.

## Which AI agents does this course use?

- [Security Agent](https://ibl.ai/solutions/government/agent/security-agent)
- [Compliance Agent](https://ibl.ai/solutions/government/agent/compliance-agent)
- [IT Help Desk Agent](https://ibl.ai/solutions/government/agent/it-help-desk-agent)
- [Knowledge Agent](https://ibl.ai/solutions/government/agent/knowledge-agent)

## Where does the course material come from?

Every module is grounded in primary sources — the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.

- [FedRAMP](https://www.fedramp.gov/) — FedRAMP PMO. Authorization process and baseline requirements.
- [NIST SP 800-53 Rev. 5](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final) — NIST. The control catalog tailored throughout the course.
- [AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework) — NIST. AI-specific risk considerations mapped into the control set.
- [Artificial Intelligence](https://www.cisa.gov/ai) — CISA. Federal guidance on securing AI systems.

## Delivery notes

Binding guidance for anyone preparing and delivering this course:

- Module 2 is the module that determines project success. Boundary errors discovered at assessment cost months, and most agency AI projects make one.
- Module 4's significant-change problem has no settled answer across agencies. Present the options and the reasoning rather than asserting a single correct approach.
- Module 6 must be honest that self-hosting shifts rather than eliminates burden. Agencies without operational capacity may be worse off, and the course should say so.
- Have an experienced ISSO review the whole course. Authorization practice varies by agency and generic RMF content will not survive contact with a real assessment.
- Re-verify FedRAMP process details at each revision — the program's requirements and templates change.

## Why run AI training on a platform you own?

- **You own the course, not a licence to it.** Course content, learner data, and the platform run inside your perimeter — you own all the code and the data.
- **Model-agnostic delivery.** Run the course's AI components on any LLM — Claude, GPT, Llama, Gemini, Command — and switch anytime.
- **No per-seat training licences.** Usage-based or self-hosted, so cost tracks actual use rather than headcount.
- **Deploy anywhere.** Cloud, private VPC, on-premise, or fully air-gapped — including for cohorts that cannot use public AI tools.

## Frequently asked questions

### What does the Getting an AI System Authorized: FedRAMP and NIST 800-53 course cover?

Authorization is where agency AI projects stall, usually because the boundary was never properly defined and the model sits outside it. This course covers boundary definition when a model is in the loop, the NIST 800-53 control families that generative AI strains most, continuous monitoring when the vendor updates the model, and where self-hosting shortens the path. It runs 6.5 hours across 8 modules across 8 modules, at advanced level, and closes with a capstone: Authorization package for one AI system.

### Who should take Getting an AI System Authorized: FedRAMP and NIST 800-53?

It is written for Information system security officers and managers, Authorizing officials and their staff, Agency CIOs and CISOs, Compliance and assessment contractors. Prerequisites: Familiarity with the RMF or an equivalent authorization process; Experience with control assessment.

### Can we run this course on our own infrastructure?

Yes. ibl.ai is model-agnostic and deploy-anywhere — cloud, private VPC, on-premise, or fully air-gapped — and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for government teams that cannot send work to a public AI tool.

### How do we get access to Getting an AI System Authorized: FedRAMP and NIST 800-53?

Request access and we will set it up for your cohort — hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.

### How much does AI training for government cost on ibl.ai?

There is no per-seat pricing — you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

## More Government courses

- [Sovereign and Air-Gapped AI for Public Agencies](https://ibl.ai/solutions/government/course/sovereign-air-gapped-ai-public-agencies): Run capable AI with no internet egress — model selection, air-gapped update paths, and the operational realities of a disconnected deployment.
- [Citizen Service Agents: Design, Escalation, and Accessibility](https://ibl.ai/solutions/government/course/citizen-service-agents): Public-facing AI where the user has no alternative provider — plain language, Section 508 conformance, language access, and escalation that never traps a constituent.
- [AI in Public Procurement: Writing an RFP That Gets Real Bids](https://ibl.ai/solutions/government/course/ai-in-public-procurement): Specify AI in a solicitation so you get comparable, honest proposals — required disclosures, evaluation criteria, and contract terms that preserve agency control.
- [Records, FOIA, and AI: Retention When an Agent Writes](https://ibl.ai/solutions/government/course/records-foia-and-ai): What happens to public records law when an AI drafts the memo — retention, prompt logs as records, and responding to a request that reaches an AI system.
- [AI Governance Inside a Public Agency](https://ibl.ai/solutions/government/course/ai-governance-public-agency): Stand up an agency AI governance program — inventory, use-case review board, impact assessment, and public transparency reporting.
- [Legislative and Policy Analysis with AI](https://ibl.ai/solutions/government/course/legislative-policy-analysis-with-ai): Bill tracking, fiscal note support, and comparative policy research — with the verification discipline that keeps a wrong summary out of a member's briefing.
