AI-01 · Control 1
AI inventory
Every material model, agent, and Copilot-style tool has an owner and purpose.
- Accountable owner
- AI governance or product risk lead
- Review cadence
- Review at least annually and after a material change.
Maturity path
- Foundational: Establish ownership, a documented workflow, and initial evidence for ai inventory.
- Developing: Run ai inventory consistently with review cadence, metrics, and exception handling.
- Advanced: Continuously improve ai inventory through automation, testing, and executive reporting.
Test method: Review current evidence with the accountable owner and record exceptions.
Evidence to look for
- ✓AI system register
- ✓Use-case owner record
- ✓Data dependency map
AI-02 · Control 2
Risk tiering
Review effort matches impact instead of treating every experiment equally.
- Accountable owner
- AI governance lead with system owner
- Review cadence
- Review at least annually and after a material change.
Maturity path
- Foundational: Establish ownership, a documented workflow, and initial evidence for risk tiering.
- Developing: Run risk tiering consistently with review cadence, metrics, and exception handling.
- Advanced: Continuously improve risk tiering through automation, testing, and executive reporting.
Test method: Review current evidence with the accountable owner and record exceptions.
Evidence to look for
- ✓Risk classification
- ✓Impact assessment
- ✓Approval and exception log
AI-03 · Control 3
Dependencies and vendors
Data, models, providers, subprocessors, and access paths are visible before they become hidden risk.
- Accountable owner
- AI system owner with procurement and security
- Review cadence
- Review at least annually and after a material change.
Maturity path
- Foundational: Establish ownership, a documented workflow, and initial evidence for dependencies and vendors.
- Developing: Run dependencies and vendors consistently with review cadence, metrics, and exception handling.
- Advanced: Continuously improve dependencies and vendors through automation, testing, and executive reporting.
Test method: Review current evidence with the accountable owner and record exceptions.
Evidence to look for
- ✓Model and vendor inventory
- ✓Data dependency map
- ✓Subprocessor and transfer review
AI-04 · Control 4
Usage controls
People know which tools and data uses are permitted, restricted, or prohibited.
- Accountable owner
- Security, legal, or responsible AI lead
- Review cadence
- Review at least annually and after a material change.
Maturity path
- Foundational: Establish ownership, a documented workflow, and initial evidence for usage controls.
- Developing: Run usage controls consistently with review cadence, metrics, and exception handling.
- Advanced: Continuously improve usage controls through automation, testing, and executive reporting.
Test method: Review current evidence with the accountable owner and record exceptions.
Evidence to look for
- ✓Acceptable-use policy
- ✓Approved-tool register
- ✓Training and acknowledgement
AI-05 · Control 5
Human oversight
People with appropriate authority can review, challenge, and stop consequential AI-assisted decisions.
- Accountable owner
- Business owner with privacy or risk lead
- Review cadence
- Review at least annually and after a material change.
Maturity path
- Foundational: Establish ownership, a documented workflow, and initial evidence for human oversight.
- Developing: Run human oversight consistently with review cadence, metrics, and exception handling.
- Advanced: Continuously improve human oversight through automation, testing, and executive reporting.
Test method: Review current evidence with the accountable owner and record exceptions.
Evidence to look for
- ✓Human review procedure
- ✓Decision and override record
- ✓Escalation path
AI-06 · Control 6
Evaluation and monitoring
AI systems are tested for quality, safety, bias, privacy, and performance before and after release.
- Accountable owner
- Technical system owner
- Review cadence
- Review at least annually and after a material change.
Maturity path
- Foundational: Establish ownership, a documented workflow, and initial evidence for evaluation and monitoring.
- Developing: Run evaluation and monitoring consistently with review cadence, metrics, and exception handling.
- Advanced: Continuously improve evaluation and monitoring through automation, testing, and executive reporting.
Test method: Review current evidence with the accountable owner and record exceptions.
Evidence to look for
- ✓Evaluation plan and results
- ✓Monitoring dashboard
- ✓Release acceptance record
AI-07 · Control 7
Runtime assurance
High-risk systems are monitored after launch, not only approved once.
- Accountable owner
- System owner with security lead
- Review cadence
- Review at least annually and after a material change.
Maturity path
- Foundational: Establish ownership, a documented workflow, and initial evidence for runtime assurance.
- Developing: Run runtime assurance consistently with review cadence, metrics, and exception handling.
- Advanced: Continuously improve runtime assurance through automation, testing, and executive reporting.
Test method: Review current evidence with the accountable owner and record exceptions.
Evidence to look for
- ✓Human oversight record
- ✓Access and usage logs
- ✓Periodic control review
AI-08 · Control 8
Incident and drift response
The organization can detect, contain, investigate, and learn from unsafe output or material system change.
- Accountable owner
- AI system owner with incident lead
- Review cadence
- Review at least annually and after a material change.
Maturity path
- Foundational: Establish ownership, a documented workflow, and initial evidence for incident and drift response.
- Developing: Run incident and drift response consistently with review cadence, metrics, and exception handling.
- Advanced: Continuously improve incident and drift response through automation, testing, and executive reporting.
Test method: Review current evidence with the accountable owner and record exceptions.
Evidence to look for
- ✓AI incident playbook
- ✓Drift or change log
- ✓Rollback and corrective-action record