"source_id","publisher","title","source_type","publication_or_update_date","canonical_url","accessed_date","evidence_component","safe_supported_statement","scope_or_use_limit","planned_use","access_status" "SRC-01","National Institute of Standards and Technology (NIST)","Artificial Intelligence Risk Management Framework (AI RMF 1.0)","Official government framework publication page","2023-01-26","https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10","2026-07-26","Governance; measurement; operating lifecycle","NIST describes AI RMF 1.0 as a voluntary, rights-preserving, non-sector-specific and use-case-agnostic resource for organizations that design, develop, deploy or use AI systems.","Do not describe the framework as mandatory law or as proof that the IVRIS framework is validated. NIST says AI RMF 1.0 is being revised; recheck at final publication.","Define the external governance baseline and distinguish IVRIS's framework from a standard.","Accessible" "SRC-02","National Institute of Standards and Technology (NIST)","Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1","Official government technical report","2023-01-26","https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf","2026-07-26","Operational; measurement; governance; Learn stage","NIST states that documentation can improve transparency, human review and accountability; it also calls for production monitoring, documented deployment-context measures, documented generalizability limits, and clear human-AI oversight roles.","These are framework outcomes and practices, not evidence that a particular implementation improves revenue or eliminates risk. Cite exact NIST function or subcategory where practical.","Support the minimum artifacts for operational evidence, measurement evidence, governance evidence and the Learn stage.","Accessible" "SRC-03","National Institute of Standards and Technology (NIST)","Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1","Official government technical report","2024-07-26","https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf","2026-07-26","Operational; measurement; provenance; human oversight","NIST's generative-AI profile recommends documenting data origin and content lineage, testing data and content flows, documenting system knowledge limits and human oversight, comparing outputs with known ground truth, and documenting fact-checking techniques.","The profile is voluntary guidance. Do not turn suggested actions into universal legal duties or claim that every GTM use case needs every action.","Support the Sense, Decide and Learn evidence artifacts and the rule that AI-generated facts require verification.","Accessible" "SRC-04","Organisation for Economic Co-operation and Development (OECD)","OECD AI Principles overview","Official intergovernmental principles and definitions","Principles adopted 2019; updated 2024-05","https://oecd.ai/en/principles","2026-07-26","Definition; lifecycle; governance","The OECD defines an AI system as a machine-based system that infers from inputs how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments.","Use as an external definition of AI systems, not as IVRIS's definition of AI-Led Growth. The OECD principles are recommendations, not a performance study.","Opening definition and explanation of why AI output can affect GTM actions.","Accessible" "SRC-05","Organisation for Economic Co-operation and Development (OECD)","Transparency and explainability (OECD AI Principle 1.3)","Official intergovernmental principle","Updated principles 2024-05","https://oecd.ai/en/dashboards/ai-principles/P7","2026-07-26","Operational; governance; contestability","OECD guidance calls for context-appropriate information about AI capabilities and limitations and, where feasible and useful, the data sources, factors, processes or logic behind an output so affected people can understand and challenge it.","Do not imply that full source code or proprietary datasets must always be disclosed; the OECD page expressly notes that transparency is contextual and does not generally require those disclosures.","Support explainability, limitation disclosure and a route to challenge or correct outcomes.","Accessible" "SRC-06","Organisation for Economic Co-operation and Development (OECD)","Accountability (OECD AI Principle 1.5)","Official intergovernmental principle","Updated principles 2024-05","https://oecd.ai/en/dashboards/ai-principles/P9","2026-07-26","Governance; provenance; accountability","OECD guidance says AI actors should be accountable according to their roles and should ensure traceability of datasets, processes and lifecycle decisions so outputs can be analyzed and inquiries answered.","This is a principle whose application depends on role and context. Do not call OECD principles binding law or certification criteria.","Support named ownership, traceability and the correction/escalation path.","Accessible" "SRC-07","World Wide Web Consortium (W3C)","PROV-O: The PROV Ontology","W3C Recommendation","2013-04-30","https://www.w3.org/TR/prov-o/","2026-07-26","Measurement; data lineage; provenance","W3C PROV-O provides a standard vocabulary for representing and exchanging provenance, including entities, activities, agents, derivation, usage, generation and attribution relationships.","The article need not implement RDF or PROV-O. Use it as evidence that source-to-action-to-output lineage can be represented explicitly, not as a claim that one data model fits every GTM stack.","Support the measurement-evidence lineage diagram and artifact definitions.","Accessible" "SRC-08","European Union","Regulation (EU) 2024/1689 (Artificial Intelligence Act)","Official regulation text","2024-07-12","https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng","2026-07-26","Logging; human oversight; post-deployment monitoring","For AI systems within the Regulation's high-risk category, Articles 12 and 14 establish record-keeping and human-oversight requirements; Article 72 addresses post-market monitoring.","Use only as a scoped regulatory example. Do not imply that all AI-led growth systems are high-risk, that these provisions apply to every IVRIS reader, or that this article is legal advice. Recheck applicable dates and jurisdiction before final publication.","Optional legal-scope callout showing that logs and oversight can be formal requirements in defined contexts.","Accessible" "SRC-09","United States Federal Trade Commission (FTC)","FTC Policy Statement Regarding Advertising Substantiation","Official regulator policy statement","1984 (policy statement; underlying notice 1983-03-11)","https://www.ftc.gov/sites/default/files/attachments/training-materials/policy_substantiation.pdf","2026-07-26","Claim evidence","The FTC's policy states that U.S. advertisers and agencies need a reasonable basis for objective express and implied advertising claims before those claims are disseminated; claims that communicate a particular level of support require that level of support.","This is U.S. advertising-substantiation policy, not a universal global rule and not case-specific legal advice. Do not say every business claim requires the same evidence type.","Support the definition of claim evidence and the pre-publication substantiation check.","Accessible" "SRC-10","FinOps Foundation","Capability: Unit Economics","Official foundation framework guidance","Living web guidance; date not stated","https://www.finops.org/framework/capabilities/unit-economics/","2026-07-26","Economic evidence","The FinOps Foundation defines unit economics as connecting technology spending with the value created and distinguishes resource-efficiency units, such as cost per token, from business units, such as cost per transaction or case resolved.","FinOps guidance is not a regulator or peer-reviewed causal study. Use as an operating definition and practice reference, not proof that a metric improves business performance.","Support the economic-evidence component and the distinction between consumption cost and business-value units.","Accessible" "SRC-11","UK Government Digital Service; Information Commissioner's Office; The Alan Turing Institute","Explaining decisions made with AI","Official government-indexed, regulator co-badged guidance","2025-01-27","https://www.gov.uk/data-ethics-guidance/explaining-decisions-made-with-ai","2026-07-26","Explainability; contestability; human responsibility","The guidance addresses how organizations can explain processes, services and decisions delivered or assisted by AI to affected individuals, across the AI lifecycle.","Use as practical UK guidance, not a worldwide legal mandate. Keep references to decisions about individuals scoped to relevant use cases.","Support the human-responsibility section and an affected-person explanation checkpoint.","Accessible"