Evidence-aware product decisions
Supply chain assurance
AIM evaluates whether the evidence behind software, hardware, cloud, SaaS, AI, and managed-service products is sufficient for an organization's intended use and risk tolerance.

The principle
AIM continuously evaluates products using versioned criteria and traceable evidence, clearly distinguishes verified findings from supplier assertions and unknowns, and applies each organization's risk tolerance to determine whether the available assurance is sufficient for the intended use.
Unknown is not low risk, and missing evidence is never converted into a neutral score.
Why supply-chain risk belongs in modernization
A product can meet functional and security requirements while still introducing unacceptable risk through opaque dependencies, weak update controls, concentrated suppliers, unsupported components, compromised delivery paths, or an impractical exit strategy. Those risks affect governments, hospitals, regulated businesses, critical infrastructure, and commercial enterprises differently.
AIM therefore treats product assurance as a distinct decision dimension. It does not replace cybersecurity, compliance, or vendor-lock-in analysis; it works with those engines to show whether a product is both capable and sufficiently supportable for the proposed mission.
What AIM evaluates
The versioned SCRM rubric contains 13 weighted criteria across these assurance areas:
Supplier governance & ownership
Who controls the product, how accountability is assigned, and whether material ownership changes are visible.
Secure development
Documented secure-development practices, artifact integrity, signing, and release controls.
Component transparency
Product-specific SBOM, VEX, dependency, and fourth-party visibility.
Vulnerability response
Known exploitation, remediation performance, disclosure practices, and incident notification.
Resilience & lifecycle
Operational resilience, supported lifecycle, update continuity, and recovery readiness.
Provenance & chain of custody
The traceability and integrity of software, hardware, firmware, models, and delivery paths.
Exit continuity
Portability, customer-controlled data or keys, transition support, and the ability to leave safely.
How the assurance flow works
- 1
Capture organizational tolerance
The assessment records supply-chain risk tolerance, workload criticality, minimum evidence expectations, concentration tolerance, acceptable disruption duration, and mandatory controls.
- 2
Resolve the exact product
AIM links evidence only after the product, offering, version, CPE, PURL, or supplier document identity is sufficiently specific. Ambiguous matches are quarantined for review.
- 3
Collect traceable evidence
Source-specific collectors preserve evidence from authoritative registries, vulnerability sources, supplier advisories, and reviewed documentation with freshness and provenance.
- 4
Separate fact from assertion
Independent or authoritative findings, supplier assertions, disputed facts, expired evidence, and unknowns remain visibly distinct.
- 5
Calculate a versioned standing
A deterministic rubric produces assurance, confidence, coverage, known adverse risk, conservative bounds, failed gates, and missing evidence—not one unexplained number.
- 6
Apply intended-use context
AIM evaluates whether the available assurance is sufficient for this organization and workload. Critical gates can disqualify a product even when its aggregate score appears strong.
- 7
Monitor for material change
Time-sensitive events can trigger early review. High-impact, stale, or unassessed products are scheduled for monthly review; stable ordinary products are reassessed at least quarterly.
The assessment inputs that change the answer
- Supply-chain risk tolerance
- Workload criticality
- Minimum supplier transparency
- Supplier concentration tolerance
- Acceptable disruption duration
- Required SBOM or VEX
- Signing and provenance requirements
- Incident-notification and remediation thresholds
- Exit plans and customer-controlled keys
- Documented exception rationale
The same product can be acceptable for a low-impact internal workload and unacceptable for a mission-critical or patient-care workload. AIM preserves the policy context used for each decision so the result can be reproduced later.
A seventh RAO dimension—only when defensible
AIM's six core RAO dimensions remain available for every recommendation. Supply Chain Assurance becomes a seventh dimension only when the assessment contains an explicit, non-unknown supply-chain tolerance and the exact product has a current evidence-backed score.
When either condition is absent, AIM does not invent a middle score. It keeps the six-dimensional ranking compatible, identifies the assurance gap, and allows the missing evidence to be addressed through review.
Current capability status
AIM's versioned rubric, assessment fields, conditional RAO integration, evidence ledger, identity matching, review workflow, score history, and scheduled collection foundation are implemented. The catalog has product-level applicability dispositions and is being expanded through reviewed CPE, PURL, registry, and supplier-advisory mappings.
Coverage is not represented as universal. A catalog product without sufficient product-specific evidence remains unassessed or insufficiently evidenced until its identity and findings are reviewed. External pilot validation and broader supplier coverage remain required before AIM claims catalog-wide assurance.