{"_id":"@csgaglobal/csoai-governance","name":"@csgaglobal/csoai-governance","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@csgaglobal/csoai-governance","version":"1.0.0","description":"CSOAI AI Governance Suite — 25 international framework crosswalks, CASA certification, Partnership Charter, sector compliance, and risk assessment","author":{"name":"CSGA Global — Cyber Security Global Alliance"},"license":"CC0-1.0","repository":{"type":"git","url":"git+https://github.com/csga-global/mcp-servers.git","directory":"packages/csoai-governance"},"homepage":"https://csga-global.org","type":"module","main":"dist/index.js","bin":{"csoai-governance-mcp":"dist/index.js"},"scripts":{"start":"node dist/index.js","dev":"tsc && node dist/index.js","watch":"tsc --watch","build":"tsc"},"dependencies":{"@modelcontextprotocol/sdk":"^1.3.0","zod":"^3.23.0"},"devDependencies":{"@types/node":"^20.0.0","typescript":"^5.3.0"},"publishConfig":{"access":"public"},"engines":{"node":">=18.0.0"},"_id":"@csgaglobal/csoai-governance@1.0.0","gitHead":"c7c0f8605f06b783f4bac5b541f4732ebce8b560","types":"./dist/index.d.ts","bugs":{"url":"https://github.com/csga-global/mcp-servers/issues"},"_nodeVersion":"22.16.0","_npmVersion":"10.9.2","dist":{"integrity":"sha512-gO0dAgdzXiajSMsx0VtM9HXwM//fepoRwwQHIQdUlob09m2hUsXRnRIZjc2lZ8WqEtL+e0fXobBBB8EikEWDWQ==","shasum":"a778aacd8c5f8d8e28df7d74e4ef9c92fdbac560","tarball":"https://registry.npmjs.org/@csgaglobal/csoai-governance/-/csoai-governance-1.0.0.tgz","fileCount":21,"unpackedSize":157851,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCt78yscvcHqojsTNy+s07Zp+S/UIhPf9820Cz2nMmWmgIgVrtdRXHtZ00XmLXAae2XqcqFQsi3wbwgUuqrn3JlApw="}]},"_npmUser":{"name":"csga_global","email":"Nicholastempleman@gmail.com"},"directories":{},"maintainers":[{"name":"csga_global","email":"Nicholastempleman@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/csoai-governance_1.0.0_1772122514780_0.5510410930234433"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-26T16:15:14.685Z","1.0.0":"2026-02-26T16:15:14.956Z","modified":"2026-02-26T16:15:15.196Z"},"maintainers":[{"name":"csga_global","email":"Nicholastempleman@gmail.com"}],"description":"CSOAI AI Governance Suite — 25 international framework crosswalks, CASA certification, Partnership Charter, sector compliance, and risk assessment","homepage":"https://csga-global.org","repository":{"type":"git","url":"git+https://github.com/csga-global/mcp-servers.git","directory":"packages/csoai-governance"},"author":{"name":"CSGA Global — Cyber Security Global Alliance"},"bugs":{"url":"https://github.com/csga-global/mcp-servers/issues"},"license":"CC0-1.0","readme":"# CSOAI AI Governance MCP Server\n\nA production-quality Model Context Protocol (MCP) server implementing the CSOAI AI Governance Suite with comprehensive AI safety, compliance, and risk assessment capabilities.\n\n**Version:** 1.0.0\n**Author:** CSOAI — Council for the Safety of Artificial Intelligence\n**License:** CC0-1.0\n**Homepage:** https://csoai.org\n\n## Overview\n\nThe CSOAI AI Governance MCP Server provides AI governance professionals, developers, and compliance teams with tools to:\n\n- Map AI systems against 25 international governance frameworks\n- Conduct CASA 4-tier AI certification assessments\n- Perform sector-specific compliance analysis\n- Classify AI system risks per EU AI Act categories\n- Respond to AI incidents with structured protocols\n- Reference 52 Partnership Charter principles\n\n## Features\n\n### 25 International Framework Crosswalks\n\nComprehensive mappings for:\n\n- **CW-01:** EU AI Act\n- **CW-02:** ISO/IEC 42001 (AI Management Systems)\n- **CW-03:** NIST AI Risk Management Framework\n- **CW-04:** OECD AI Principles\n- **CW-05:** UNESCO AI Ethics\n- **CW-06:** IEEE 7000 Series (Ethically Aligned Design)\n- **CW-07:** Canadian AIDA\n- **CW-08:** Singapore Model AI Governance\n- **CW-09:** Japan AI Social Principles\n- **CW-10:** China AI Governance\n- **CW-11:** African Union AI Framework\n- **CW-12:** GPAI Code of Conduct\n- **CW-13:** WEF AI Governance\n- **CW-14:** Council of Europe AI Convention\n- **CW-15:** ASEAN Guide on AI Ethics\n- **CW-16:** Saudi Arabia AI Ethics\n- **CW-17:** Brazil AI Framework\n- **CW-18:** Australia AI Ethics Framework\n- **CW-19:** ISO/IEC 23894 (AI Risk Management)\n- **CW-20:** AI Agent Release Certification Standards\n- **CW-21:** NIST AI 600-1 GenAI Profile\n- **CW-22:** OWASP MCP Top 10\n- **CW-23:** OWASP Agentic AI Top 10\n- **CW-24:** Defence/NDAA/CBRN AI Governance\n- **CW-25:** OWASP LLM Top 10\n\nEach crosswalk provides:\n- Framework requirements and principles\n- Mapping to CASA certification tiers\n- Identified compliance gaps\n- Recommended actions for compliance\n\n### CASA 4-Tier Certification Assessment\n\nComprehensive AI system assessment with four certification tiers:\n\n- **Tier 1:** Self-Assessment (organizations assess their own practices)\n- **Tier 2:** Third-Party Audit (independent auditors verify compliance)\n- **Tier 3:** Continuous Monitoring (automated systems monitor ongoing compliance)\n- **Tier 4:** Byzantine Council Review (expert council reviews systemic risks)\n\nReturns:\n- Recommended certification tier\n- Compliance score against governance standards\n- Applicable international frameworks\n- Identified compliance gaps\n- Step-by-step certification pathway\n\n### 52 Partnership Charter Articles\n\nComplete reference for AI governance principles covering:\n- Governance and accountability\n- Risk assessment and management\n- Safety testing and evaluation\n- Human oversight and control\n- Transparency and explainability\n- Data governance and privacy\n- Stakeholder engagement\n- Incident response protocols\n- And 44 additional articles\n\n### Sector-Specific Compliance\n\nCompliance analysis for 8 critical sectors:\n\n1. **Healthcare**\n   - HIPAA, FDA, clinical validation requirements\n   - Diagnostic accuracy, bias testing, human oversight\n   - Post-market surveillance\n\n2. **Financial Services**\n   - Fair lending, capital requirements, AML compliance\n   - Model risk management, explainability\n   - Regulatory audit and reporting\n\n3. **Military/Defense**\n   - National security, CBRN risk mitigation\n   - Autonomous weapons governance, human control\n   - Export controls and foreign involvement restrictions\n\n4. **Education**\n   - Student data protection, FERPA compliance\n   - Equitable access, academic integrity\n   - Bias assessment across student populations\n\n5. **Employment**\n   - Fair hiring, adverse impact analysis\n   - ADA accessibility, discrimination prevention\n   - Salary equity, appeals processes\n\n6. **Criminal Justice**\n   - Due process, racial bias assessment\n   - Transparency and explainability\n   - Constitutional compliance\n\n7. **Transportation**\n   - Autonomous vehicle safety validation\n   - Cybersecurity for vehicles\n   - Occupant and pedestrian protection\n\n8. **Social Media**\n   - Content moderation, misinformation detection\n   - Child safety, algorithmic transparency\n   - Appeals and removal processes\n\n### EU AI Act Risk Classification\n\nRisk assessment using EU AI Act categories:\n\n- **Unacceptable Risk:** Systems prohibited under EU AI Act\n  - Requires non-deployment or major redesign\n  - Significant legal liability\n\n- **High Risk:** Systems requiring strict compliance measures\n  - Comprehensive documentation and testing\n  - Third-party conformity assessment\n  - Human oversight and monitoring\n\n- **Limited Risk:** Systems requiring transparency measures\n  - User disclosure requirements\n  - Basic safety measures\n\n- **Minimal Risk:** Systems with minimal impact\n  - Standard data protection compliance\n\n### AI Incident Response Protocol\n\nStructured incident response with:\n- Severity assessment and classification\n- Immediate actions and escalation procedures\n- Investigation and root cause analysis\n- Stakeholder notification requirements\n- Remediation and recovery steps\n- Preventive measures for future incidents\n\n## Installation\n\n### Prerequisites\n\n- Node.js 18.0.0 or later\n- npm or yarn\n\n### Setup\n\n1. Clone or navigate to the server directory:\n```bash\ncd /sessions/brave-adoring-cerf/mcp-servers/csoai-governance\n```\n\n2. Install dependencies:\n```bash\nnpm install\n```\n\n3. Build the TypeScript:\n```bash\nnpm run build\n```\n\n4. Start the server:\n```bash\nnpm start\n```\n\nOr for development with auto-reload:\n```bash\nnpm run dev\n```\n\n## Usage\n\n### With ChatGPT\n\nConfigure the MCP plugin in ChatGPT settings to connect to the CSOAI server endpoint.\n\n### With Claude\n\nAdd the server to your MCP configuration in Claude desktop:\n\n```json\n{\n  \"mcpServers\": {\n    \"csoai-governance\": {\n      \"command\": \"node\",\n      \"args\": [\"/path/to/dist/index.js\"]\n    }\n  }\n}\n```\n\n### With Cursor\n\nConfigure in Cursor's MCP settings to enable governance analysis in your development workflow.\n\n### With VS Code\n\nInstall the MCP extension and configure to connect to the CSOAI server.\n\n### Direct API Usage\n\nConnect via stdio to any MCP-compatible application:\n\n```bash\nnode dist/index.js\n```\n\n## Tools Reference\n\n### 1. crosswalk_lookup\n\nLook up any of 25 international AI governance framework crosswalks.\n\n**Parameters:**\n- `crosswalk_id` (string): Framework identifier (CW-01 to CW-25)\n\n**Example:**\n```\ncrosswalk_lookup(crosswalk_id=\"CW-01\")\n```\n\n**Returns:**\n- Framework name and version\n- Jurisdiction\n- Key requirements\n- CASA tier mappings\n- Compliance gaps\n- Recommended actions\n\n### 2. charter_lookup\n\nLook up any of the 52 Partnership Charter articles.\n\n**Parameters:**\n- `article_number` (number): Article number (1-52)\n\n**Example:**\n```\ncharter_lookup(article_number=4)\n```\n\n**Returns:**\n- Article title\n- Full content\n- Key principles\n\n### 3. casa_assessment\n\nRun the CASA 4-tier certification assessment.\n\n**Parameters:**\n- `system_name` (string): Name of the AI system\n- `system_description` (string): Detailed system description\n- `deployment_context` (string): Where and how the system is deployed\n\n**Example:**\n```\ncasa_assessment(\n  system_name=\"MedicalDiagnosisAI\",\n  system_description=\"Machine learning system for medical image analysis...\",\n  deployment_context=\"Deployed in 50 hospitals across EU for diagnostic support\"\n)\n```\n\n**Returns:**\n- Recommended CASA tier (1-4)\n- Compliance score (0-100)\n- Applicable crosswalk frameworks\n- Identified compliance gaps\n- Certification pathway with phases\n\n### 4. sector_compliance\n\nPerform sector-specific compliance assessment.\n\n**Parameters:**\n- `sector` (enum): One of healthcare, financial, military, education, employment, criminal_justice, transportation, social_media\n- `system_description` (string): Description of the AI system\n\n**Example:**\n```\nsector_compliance(\n  sector=\"healthcare\",\n  system_description=\"AI diagnostic system for chest X-ray analysis...\"\n)\n```\n\n**Returns:**\n- Compliance requirements for the sector\n- Applicable regulatory frameworks\n- Key risks and mitigation strategies\n- Compliance checklist with status\n\n### 5. risk_assessment\n\nClassify AI system risk per EU AI Act categories.\n\n**Parameters:**\n- `system_name` (string): Name of the AI system\n- `system_description` (string): System description\n- `scope_and_impact` (string): Who is affected and what decisions does it influence\n\n**Example:**\n```\nrisk_assessment(\n  system_name=\"EmploymentScreeningAI\",\n  system_description=\"Automated resume screening for job applications...\",\n  scope_and_impact=\"Used in hiring decisions for technical roles affecting 1000+ applicants annually\"\n)\n```\n\n**Returns:**\n- Risk category (Unacceptable, High, Limited, Minimal)\n- Risk score (0-100)\n- Identified risks with severity\n- Required measures\n- Compliance implications\n- Residual risk assessment\n\n### 6. incident_response\n\nGenerate incident response protocol.\n\n**Parameters:**\n- `incident_name` (string): Brief incident title\n- `incident_description` (string): Detailed incident description\n- `severity_assessment` (enum): Critical, High, Medium, or Low\n\n**Example:**\n```\nincident_response(\n  incident_name=\"Bias in Recruitment AI\",\n  incident_description=\"Analysis revealed the AI rejected 80% of applications from women...\",\n  severity_assessment=\"High\"\n)\n```\n\n**Returns:**\n- Assessed severity level\n- Immediate actions to take\n- Investigation steps\n- Stakeholder notification requirements\n- Remediation steps\n- Preventive measures\n- Estimated resolution timeline\n\n## Resources\n\n### csoai://crosswalks/index\n\nIndex and guide to all 25 international AI framework crosswalks.\n\n### csoai://charter/index\n\nComplete guide to all 52 Partnership Charter articles organized by category.\n\n### csoai://tools/guide\n\nComprehensive guide to all server tools, workflow examples, and best practices.\n\n## Workflow Examples\n\n### Example 1: Assessing a Healthcare AI System\n\n1. Start with risk assessment:\n```\nrisk_assessment(\n  system_name=\"DiagnosticAI\",\n  system_description=\"ML system for pathology slide analysis\",\n  scope_and_impact=\"Used in 20 hospital labs for cancer diagnosis, 10,000+ patients/year\"\n)\n```\nResult: High risk → EU AI Act compliance required\n\n2. Check sector-specific requirements:\n```\nsector_compliance(\n  sector=\"healthcare\",\n  system_description=\"Pathology analysis AI...\"\n)\n```\nResult: HIPAA, FDA, clinical validation requirements\n\n3. Run CASA assessment:\n```\ncasa_assessment(\n  system_name=\"DiagnosticAI\",\n  system_description=\"Pathology analysis AI...\",\n  deployment_context=\"Hospital diagnostic labs in EU and US\"\n)\n```\nResult: Tier 2-3 recommended (third-party audit + continuous monitoring)\n\n4. Review relevant frameworks:\n```\ncrosswalk_lookup(crosswalk_id=\"CW-19\")  # ISO/IEC 23894\ncrosswalk_lookup(crosswalk_id=\"CW-02\")  # ISO/IEC 42001\n```\n\n### Example 2: Evaluating LLM Safety\n\n1. Risk classification:\n```\nrisk_assessment(\n  system_name=\"CompanyLLM\",\n  system_description=\"Large language model for customer service...\",\n  scope_and_impact=\"Used to respond to 100,000 customer queries daily\"\n)\n```\n\n2. Check multiple security frameworks:\n```\ncrosswalk_lookup(crosswalk_id=\"CW-25\")  # OWASP LLM Top 10\ncrosswalk_lookup(crosswalk_id=\"CW-22\")  # OWASP MCP Top 10\ncrosswalk_lookup(crosswalk_id=\"CW-23\")  # OWASP Agentic AI Top 10\n```\n\n3. CASA assessment:\n```\ncasa_assessment(\n  system_name=\"CompanyLLM\",\n  system_description=\"LLM for customer service...\",\n  deployment_context=\"Production customer-facing service\"\n)\n```\n\n### Example 3: Incident Response\n\n1. Generate response protocol:\n```\nincident_response(\n  incident_name=\"LLM Generated Offensive Content\",\n  incident_description=\"System generated offensive content about protected group...\",\n  severity_assessment=\"High\"\n)\n```\n\n2. Reference Charter principles:\n```\ncharter_lookup(article_number=9)   # Fairness and non-discrimination\ncharter_lookup(article_number=14)  # Incident reporting and response\n```\n\n3. Re-assess after remediation:\n```\ncasa_assessment(\n  system_name=\"CompanyLLM\",\n  system_description=\"LLM with improved content filtering...\",\n  deployment_context=\"Production with enhanced safety measures\"\n)\n```\n\n## Architecture\n\n### Directory Structure\n\n```\ncsoai-governance/\n├── src/\n│   ├── index.ts                 # Main MCP server\n│   ├── tools/\n│   │   ├── crosswalk-lookup.ts  # Framework crosswalk tool\n│   │   ├── charter-lookup.ts    # Charter article tool\n│   │   ├── casa-assess.ts       # CASA certification assessment\n│   │   ├── sector-compliance.ts # Sector compliance tool\n│   │   ├── risk-assessment.ts   # Risk classification tool\n│   │   └── incident-response.ts # Incident response protocol\n│   └── resources/\n│       ├── crosswalks.ts        # 25 crosswalk definitions\n│       └── charter.ts           # 52 charter articles\n├── dist/                         # Compiled JavaScript\n├── package.json                 # Dependencies\n├── tsconfig.json                # TypeScript config\n└── README.md                    # This file\n```\n\n### Technology Stack\n\n- **Runtime:** Node.js 18+\n- **Language:** TypeScript 5+\n- **MCP SDK:** @modelcontextprotocol/sdk\n- **Validation:** Zod\n- **Transport:** Stdio (compatible with all MCP clients)\n\n## Best Practices\n\n### 1. Assessment Workflow\n\nAlways follow this sequence for comprehensive analysis:\n1. Risk assessment (understand the risk level)\n2. Sector compliance (check industry-specific requirements)\n3. CASA assessment (determine certification pathway)\n4. Crosswalk lookup (map to specific frameworks)\n5. Charter review (implement governance principles)\n\n### 2. Documentation\n\nKeep detailed documentation of:\n- Assessment results and reasoning\n- Compliance gaps identified\n- Remediation plans with timelines\n- Evidence of compliance measures\n- Monitoring and audit results\n\n### 3. Continuous Monitoring\n\nFor Tier 3-4 systems:\n- Establish continuous monitoring dashboards\n- Set up automated alerts for performance degradation\n- Schedule regular compliance reviews\n- Document and respond to any deviations\n\n### 4. Incident Management\n\nWhen incidents occur:\n- Use incident_response tool immediately\n- Follow recommended notification requirements\n- Document all investigation findings\n- Implement preventive measures\n- Re-assess system risk after resolution\n\n## Integration Examples\n\n### With Python/LangChain\n\n```python\nfrom mcp import McpClient\n\nclient = McpClient(\"csoai-governance\")\n\n# Run CASA assessment\nresult = client.call_tool(\"casa_assessment\", {\n    \"system_name\": \"MyAISystem\",\n    \"system_description\": \"...\",\n    \"deployment_context\": \"...\"\n})\n```\n\n### With JavaScript/Node.js\n\n```javascript\nconst { McpClient } = require(\"@modelcontextprotocol/sdk\");\n\nconst client = new McpClient(\"csoai-governance\");\n\nconst result = await client.callTool(\"risk_assessment\", {\n  system_name: \"MyAISystem\",\n  system_description: \"...\",\n  scope_and_impact: \"...\"\n});\n```\n\n## Performance\n\n- **Instant Response:** All lookups and assessments run locally\n- **Scalable:** Handles assessments for multiple systems simultaneously\n- **Reliable:** Comprehensive error handling and validation\n- **Secure:** All processing occurs on your system\n\n## Support and Contribution\n\nFor questions, issues, or contributions:\n- Visit: https://csoai.org\n- Issues and pull requests welcome\n- Adopt the Charter principles in your AI governance\n\n## License\n\nThis server is released under the CC0-1.0 license, placing it in the public domain. You are free to use, modify, and distribute it for any purpose.\n\n## Disclaimer\n\nThis tool provides information and guidance for AI governance and compliance. It should not be considered legal advice. Consult with legal experts and compliance specialists for your specific situation and jurisdiction.\n\n## Acknowledgments\n\nThe CSOAI AI Governance MCP Server builds upon work from:\n- European Commission (EU AI Act)\n- NIST (AI Risk Management Framework)\n- OWASP (LLM Top 10, Agentic AI, MCP Top 10)\n- ISO/IEC (AI Standards)\n- UNESCO (AI Ethics)\n- IEEE (Ethically Aligned Design)\n- And many international organizations advancing AI safety\n\n---\n\n**CSOAI — Council for the Safety of Artificial Intelligence**\nAdvancing responsible development and deployment of AI systems through governance, standards, and cooperation.\n","readmeFilename":"README.md","_rev":"1-00a00334dc6e228f473670056cc748be"}