
Challenge
A federal agency needed a faster, smarter way to help staff navigate a vast repository of sensitive medical and research content. ICF led the design and development of a secure, AI-powered chatbot—a “digital librarian”—trained on national strategies, internal publications, and research documents. The goal: reduce time spent searching for information and increase staff productivity.
But speed alone wasn’t enough. In a high-stakes mission environment, the tool also needed to be secure, scalable, and aligned with federal standards for data governance and performance.
ICF Fathom in action
The AI RMF includes:
- A systematic way to recognize, evaluate, and reduce AI risks
- A definition of seven "characteristics of trustworthy AI"
- The AI RMF Core, which is made up of four functions: govern, map, measure, and manage
From day one, we embedded adaptive, right-sized governance practices into ICF Fathom’s development—using the NIST AI Risk Management Framework (AI RMF) to accelerate secure deployment and reduce operational risk.
We mapped the framework’s core functions—govern, map, measure, manage—to our delivery process, enabling rapid iteration and responsible scaling. Key safeguards built into the architecture included:
- PII redaction filters
- Audit logs and transparency features
- Human-in-the-loop review to support high-confidence responses
- Targeted monitoring for explainability and output quality
Close collaboration with agency subject matter experts ensured Fathom remained accurate, reliable, and mission-ready—without slowing down innovation.
Impact
The result: A secure, production-ready chatbot that delivers accurate answers, streamlines internal workflows, and aligns with federal expectations for AI oversight. Designed for easy replication, the solution can now be deployed across other agencies to support decision-making at scale.
Final thought
Effective AI doesn’t just reduce workloads—it strengthens mission delivery. With Fathom, ICF helped a federal agency unlock the full potential of its data by combining speed, security, and smart governance.