All 112 controls. The AR rows column is the family-level inverse of the Part I taxonomy: the agentic risks (AR-1..AR-16) whose treating-control families include this control's family. It is a navigation aid, not a per-control risk assessment.
| ID | Control | Part | AR rows treated (family-level) | Objective |
|---|---|---|---|---|
| GOV-01 | Board-Approved AI & Autonomy Governance Charter | II | AR-1, AR-10, AR-11, AR-14, AR-16 | Establish board-level accountability for AI use, including an explicit, written risk appetite for agent autonomy. |
| GOV-02 | Enterprise AI Management System (AIMS) | II | AR-1, AR-10, AR-11, AR-14, AR-16 | Operate a single, certifiable management system governing the responsible development, provision, and use of AI systems, including agents. |
| GOV-03 | Agent Inventory & Registration | II | AR-1, AR-10, AR-11, AR-14, AR-16 | Ensure every agent operating in or for the institution is known, uniquely identified, and lifecycle-managed. |
| GOV-04 | Named Accountable Owner per Agent | II | AR-1, AR-10, AR-11, AR-14, AR-16 | Guarantee that accountability for every agent's conduct rests with an identified human role at all times. |
| GOV-05 | Agentic Systems Within Model Risk Management Scope | II | AR-1, AR-10, AR-11, AR-14, AR-16 | Subject agentic systems to the institution's model risk management framework with agent-specific scope definitions. |
| GOV-06 | Independent Validation & Effective Challenge for Agents | II | AR-1, AR-10, AR-11, AR-14, AR-16 | Ensure every agent deployment above AT-0 has been independently validated with challenge proportionate to its autonomy and action surface. |
| GOV-07 | Autonomy Tier Framework in the Risk Appetite | II | AR-1, AR-10, AR-11, AR-14, AR-16 | Bound delegated agent authority by a formal, board-approved autonomy tier framework. |
| GOV-08 | Autonomy Promotion & Demotion Gates | II | AR-1, AR-10, AR-11, AR-14, AR-16 | Make every change in an agent's delegated authority a controlled, evidenced decision: slow upward, instant downward. |
| GOV-09 | Three-Lines Responsibility Assignment for Agentic AI | II | AR-1, AR-10, AR-11, AR-14, AR-16 | Assign every agentic-AI control in the catalog to an accountable line of defense with no orphaned controls. |
| GOV-10 | AI Impact Assessment Before Deployment and Promotion | II | AR-1, AR-10, AR-11, AR-14, AR-16 | Ensure the impacts of an agent deployment on customers, the institution, and third parties are assessed and documented before authority is granted or |
| GOV-11 | Governance Records & Regulator-Ready Documentation | II | AR-1, AR-10, AR-11, AR-14, AR-16 | Maintain complete, tamper-evident, retrievable records of agent governance sufficient for internal audit and external examination. |
| GOV-12 | Data Quality Management Accountability for Agent-Consumed Data | II | AR-1, AR-10, AR-11, AR-14, AR-16 | Assign management-system accountability for the quality of data agents consume, retrieve, and write, including agent memory. |
| GOV-13 | Evidentiary Standards for Oversight & Monitoring Claims | II | AR-1, AR-10, AR-11, AR-14, AR-16 | Prevent unproven oversight technology from being booked as effective control coverage in the governance framework. |
| GOV-14 | AI Ethics & Escalation Body with Anti-Decoy Safeguards | II | AR-1, AR-10, AR-11, AR-14, AR-16 | Provide a standing, empowered body for ethical review and escalation of agent deployments, designed so it constrains decisions rather than decorating |
| DES-01 | Agent Data Inventory and Governance Plan | III.A | AR-5, AR-6, AR-11, AR-14 | Ensure every dataset that trains, fine-tunes, or is retrievable by an agent is inventoried, owned, and governed before the agent is built. |
| DES-02 | Training-Data Provenance Instrumentation and Post-Hoc Auditability | III.A | AR-5, AR-6, AR-11, AR-14 | Make it technically possible to answer, after the fact, "was this record (or this copyrighted/confidential source) in the training data?" |
| DES-03 | Poisoning-Resistant Data Acquisition | III.A | AR-5, AR-6, AR-11, AR-14 | Prevent adversarial contamination of the data that shapes agent behavior, at both training and retrieval time. |
| DES-04 | Memorization and Training-Data Extraction Risk Controls | III.A | AR-5, AR-6, AR-11, AR-14 | Prevent agents from leaking memorized training data (customer PII, MNPI, proprietary text) through outputs or tool calls. |
| DES-05 | AI System Impact Assessment as a Design Gate | III.A | AR-5, AR-6, AR-11, AR-14 | Require a structured, documented impact assessment before any agentic system is approved for build or material change. |
| DES-06 | Human-Rights and Customer-Impact Assessment for High-Stakes Agentic Scope | III.A | AR-5, AR-6, AR-11, AR-14 | Apply a deeper, rights-focused assessment when an agent's action space touches customers' access to credit, insurance, funds, or redress. |
| DES-07 | Agent Identity, Ownership, and Lifecycle by Design | III.A | AR-5, AR-6, AR-11, AR-14 | Ensure every agent is a first-class, individually identifiable principal with a named owner and a bounded lifecycle from the day it is designed. |
| DES-08 | Least-Privilege Tool and Permission Scoping | III.A | AR-5, AR-6, AR-11, AR-14 | Grant each agent the minimum tool set, per-tool permissions, and data egress needed for its stated intent, and make the grant enforceable outside the |
| DES-09 | Short-Lived, Delegation-Bounded Credential Architecture | III.A | AR-5, AR-6, AR-11, AR-14 | Ensure the credentials an agent wields cannot outlive their purpose or exceed the authority of the human they serve. |
| DES-10 | User-Level Permission Model: Specify, Derive, Enforce | III.A | AR-5, AR-6, AR-11, AR-14 | Design agent permission systems so that what a user authorizes is faithfully translated into policy and actually enforced at run time: three distinct |
| DES-11 | Environmental Constraints as an Oversight Substrate | III.A | AR-5, AR-6, AR-11, AR-14 | Engineer the agent's environment (access control, network policy, enforced conventions) so oversight and monitoring become materially more effective |
| DES-12 | Secure Development and Attestation for the Agent Stack | III.A | AR-5, AR-6, AR-11, AR-14 | Hold the software stack that builds and runs agents (pipelines, frameworks, orchestration, serving) to secure software development practice, with at |
| DES-13 | Model, Artifact, and Tool Provenance: Signing and Integrity Verification | III.A | AR-5, AR-6, AR-11, AR-14 | Guarantee that the model weights, adapters, prompts, tool definitions, and datasets an agent loads in production are exactly the artifacts that were a |
| DES-14 | Memory and Context Architecture as Designed Control Surfaces | III.A | AR-5, AR-6, AR-11, AR-14 | Treat what an agent remembers, retrieves, and holds in context as deliberate architectural decisions with risk consequences: scoped, provenance-tagge |
| EVL-01 | Documented Pre-Deployment Evaluation Plan per Agent System | III.B | AR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15 | Ensure every agentic system enters evaluation with a pre-committed, risk-based plan defining what is tested, on what system configuration, and against |
| EVL-02 | Multi-Dimensional Capability & Fitness Evaluation | III.B | AR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15 | Measure agent fitness on all dimensions that predict production success, not task accuracy alone. |
| EVL-03 | Dangerous-Capability Evaluation Programme | III.B | AR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15 | Detect, before deployment, capabilities that could unlock large-scale harm, in both the frontier register and the financial-enterprise register. |
| EVL-04 | Full-Capability Elicitation Standard | III.B | AR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15 | Prevent under-elicitation: ensure measured capability approximates the upper bound available to a motivated user or adversary, not the default configu |
| EVL-05 | Sandbagging & Evaluation-Awareness Testing | III.B | AR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15 | Detect whether the evaluated system is underperforming strategically or behaving differently because it recognizes the test. |
| EVL-06 | Construct & Ecological Validity Review | III.B | AR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15 | Ensure each evaluation measures the construct it claims to measure, under conditions that resemble deployment. |
| EVL-07 | Benchmark Integrity: Verifier Hardening & Contamination Control | III.B | AR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15 | Ensure gate-relevant benchmark scores cannot be achieved by gaming the harness or by memorization of test material. |
| EVL-08 | Trajectory-Level Evaluation Evidence | III.B | AR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15 | Ensure evaluation conclusions rest on inspection of what the agent actually did, not only on whether the outcome scored as a pass. |
| EVL-09 | Cross-Benchmark Corroboration | III.B | AR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15 | Prevent any single benchmark score from functioning as a safety or fitness verdict. |
| EVL-10 | Adversarial Red-Teaming of Agentic Systems | III.B | AR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15 | Subject the agent, its tools, and its harness to realistic adversarial attack before deployment, at adversary-realistic scale and persistence. |
| EVL-11 | Control Evaluations Under Assumed Subversion | III.B | AR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15 | For high-autonomy agents, establish that the deployment protocol keeps outcomes safe even if the model itself is adversarial. |
| EVL-12 | Propensity, Sabotage & Misbehavior Evaluation | III.B | AR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15 | Measure whether the agent tends to take harmful or deceptive actions under realistic incentive and pressure conditions: distinct from whether it *c |
| EVL-13 | Privacy & Data-Leakage Evaluation of Agent Tool-Chains | III.B | AR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15 | Verify before deployment that the agent's tool orchestration and inter-agent channels do not leak confidential or customer data. |
| EVL-14 | Independent & Third-Party Evaluation | III.B | AR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15 | Ensure gate decisions rest on evaluation evidence with genuine independence from the team, and the vendor, whose system is being judged. |
| EVL-15 | Pre-Committed Pass/Fail Thresholds & Go/No-Go Deployment Gate | III.B | AR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15 | Bind evaluation results to the deployment decision through thresholds committed before results exist, so the gate cannot be argued open after the fact |
| EVL-16 | Continuous Re-Evaluation Triggers | III.B | AR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15 | Ensure the evaluation evidence behind a live deployment remains true of the system actually running, by re-testing on every material change to model, |
| RUN-01 | Designated Oversight Mode per Agent Deployment | III.C | AR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16 | Every production agent operates under an explicitly chosen, documented, and risk-justified human oversight mode. |
| RUN-02 | Structured Adversarial Review at Approval Gates | III.C | AR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16 | Human approval of agent actions detects harmful or erroneous output at a measured, acceptable rate, not merely records assent. |
| RUN-03 | Oversight Triggers Wired to Observable Signals | III.C | AR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16 | Escalation to human review is triggered by signals the agent cannot fabricate, never solely by the agent's self-assessment. |
| RUN-04 | Graduated Autonomy with Deferral (Act-or-Ask) | III.C | AR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16 | Agents earn autonomy per action class, and are architected to defer to humans when risk rises, with incentives that never reward evading oversight. |
| RUN-05 | AI-Control Protocol as the Deployment Baseline | III.C | AR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16 | Every material agent deployment runs under a named control protocol designed to remain safe even if the model actively subverts safety measures. |
| RUN-06 | Trusted Monitoring of Untrusted Agent Actions | III.C | AR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16 | Every action proposed by an untrusted agent is scored for suspicion by an independent trusted monitor before or immediately upon execution. |
| RUN-07 | Untrusted Monitoring with Collusion Safeguards | III.C | AR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16 | Where trusted models are too weak to assess a frontier agent's actions, stronger untrusted monitors are used: under explicit anti-collusion controls. |
| RUN-08 | Resample and Defer-to-Trusted Protocols for Suspicious Actions | III.C | AR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16 | Suspicious agent actions are not merely blocked but resampled or rerouted, converting single alerts into accumulating evidence while preserving throug |
| RUN-09 | Adaptive Deployment Against Distributed Threats | III.C | AR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16 | Runtime protection adapts to accumulated behavioral evidence, defending against harm that accrues across many small actions rather than one catastroph |
| RUN-10 | Adversarial Validation of the Monitoring Stack | III.C | AR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16 | The institution knows its monitors' real catch rates against refined, adaptive attacks, not just against naive ones, and provisions residual-risk co |
| RUN-11 | Sandboxed Execution and Environment Containment | III.C | AR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16 | Agents execute in isolated environments whose blast radius is bounded in advance, so that even successful subversion cannot reach systems or data beyo |
| RUN-12 | Kill Switch: Tested Emergency Shutdown per Agent | III.C | AR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16 | Any production agent can be halted immediately, by named humans, through a mechanism the agent cannot influence, with a tested and rehearsed procedure |
| RUN-13 | Graceful Degradation and Fallback Operating Modes | III.C | AR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16 | When runtime controls fire or dependencies fail, the business process degrades to a safe, lower-autonomy mode instead of failing open or halting the b |
| RUN-14 | Hard Budget, Turn, and Spend Guards | III.C | AR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16 | Every agent run is bounded by non-negotiable limits on money spent, actions taken, turns/steps consumed, tokens/compute used, and wall-clock time: en |
| RUN-15 | Call-Time Tool Gating and Permission Enforcement | III.C | AR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16 | Every tool invocation is checked against policy at the moment of the call, with least-privilege scopes, and denied-by-default for anything not explici |
| RUN-16 | Chain-Aware Compositional Tool Policies with Taint Tracking | III.C | AR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16 | Tool-call sequences are governed as first-class objects, so that combinations of individually permitted tools cannot compose into a policy violation |
| RUN-17 | Approval Workflows for Consequential Actions | III.C | AR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16 | Actions above defined consequence thresholds cannot execute without an affirmative, authenticated, recorded human approval obtained through a dedicate |
| RUN-18 | Runtime Trajectory and Reasoning-Trace Capture | III.C | AR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16 | Complete agent trajectories (inputs, reasoning traces where available, every tool call and result, monitor scores, and policy decisions) are capture |
| MON-01 | Complete, Attributable Agent Action Logging | III.D | AR-1, AR-2, AR-3, AR-4, AR-6, AR-7, AR-8, AR-9, AR-12, AR-16 | Ensure every consequential action taken by an agent is recorded, attributable to exactly one agent identity, and reconstructable after the fact. |
| MON-02 | Reasoning-Trace Capture & Retention | III.D | AR-1, AR-2, AR-3, AR-4, AR-6, AR-7, AR-8, AR-9, AR-12, AR-16 | Preserve agent (and AI-monitor) reasoning traces so that oversight, collusion detection, and post-incident analysis remain possible. |
| MON-03 | Agent Observability Platform & Telemetry Taxonomy | III.D | AR-1, AR-2, AR-3, AR-4, AR-6, AR-7, AR-8, AR-9, AR-12, AR-16 | Provide a single operational pane where agent health, behavior, cost, and control-status signals are collected against a defined telemetry taxonomy. |
| MON-04 | Statistical Drift & Performance-Degradation Detection | III.D | AR-1, AR-2, AR-3, AR-4, AR-6, AR-7, AR-8, AR-9, AR-12, AR-16 | Detect when the statistical world an agent operates in (inputs, outputs, task mix, environment) has shifted away from the conditions it was validate |
| MON-05 | Behavioral Baselining & Goal-Drift Monitoring | III.D | AR-1, AR-2, AR-3, AR-4, AR-6, AR-7, AR-8, AR-9, AR-12, AR-16 | Detect when an agent's behavior, as distinct from its statistical inputs/outputs, departs from its mandated goal or established behavioral baselin |
| MON-06 | Tool-Use & Environment Anomaly Detection | III.D | AR-1, AR-2, AR-3, AR-4, AR-6, AR-7, AR-8, AR-9, AR-12, AR-16 | Detect anomalous or malicious agent interactions with tools, integrations, and the execution environment, including compromise of the tool layer itse |
| MON-07 | AI-Supervised Monitoring of Agents (Hierarchical Oversight) | III.D | AR-1, AR-2, AR-3, AR-4, AR-6, AR-7, AR-8, AR-9, AR-12, AR-16 | Scale oversight beyond human review capacity by deploying AI monitors over production agents, while controlling for monitor collusion and monitor obso |
| MON-08 | Monitoring-Latency Budget (Detect-to-Respond SLO) | III.D | AR-1, AR-2, AR-3, AR-4, AR-6, AR-7, AR-8, AR-9, AR-12, AR-16 | Ensure the monitoring system detects and responds faster than the agent can cause irreversible harm, because a correct control action that arrives la |
| MON-09 | Agentic Incident Classification & Severity Taxonomy | III.D | AR-1, AR-2, AR-3, AR-4, AR-6, AR-7, AR-8, AR-9, AR-12, AR-16 | Classify agentic failures consistently (by mechanism, severity, and regulatory reportability) so response, disclosure, and learning are triggered de |
| MON-10 | Agentic Incident Response & Containment | III.D | AR-1, AR-2, AR-3, AR-4, AR-6, AR-7, AR-8, AR-9, AR-12, AR-16 | Contain, investigate, and remediate agentic incidents with response actions matched to how agents fail: credential revocation, agent halt, delegation |
| MON-11 | Regulatory Incident-Reporting Obligations Register | III.D | AR-1, AR-2, AR-3, AR-4, AR-6, AR-7, AR-8, AR-9, AR-12, AR-16 | Meet every external AI incident-reporting duty the institution is subject to (with the correct trigger, recipient, and clock) and never discover a 7 |
| MON-12 | Safeguard Re-Verification & Feedback into Re-Evaluation | III.D | AR-1, AR-2, AR-3, AR-4, AR-6, AR-7, AR-8, AR-9, AR-12, AR-16 | Treat safeguards as decaying assets: continuously verify that monitoring controls still work, and route production findings back into the evaluation g |
| MAS-01 | Multi-Agent System Inventory and Topology Registration | III.E/F | AR-8, AR-9, AR-10, AR-11, AR-12 | Ensure every agent, sub-agent, and inter-agent connection in production is inventoried, owned, and known to risk management before it operates. |
| MAS-02 | Unique Agent Identity with Attributable Action Logging | III.E/F | AR-8, AR-9, AR-10, AR-11, AR-12 | Make every consequential action in a multi-agent system attributable to exactly one authenticated agent identity. |
| MAS-03 | Authenticated Delegation with Bounded Authority Chains | III.E/F | AR-8, AR-9, AR-10, AR-11, AR-12 | Ensure authority passed between agents (and from humans to agents) is authenticated, scoped, and never broader than the delegator's own. |
| MAS-04 | Short-Lived, Dynamically Issued Agent Credentials | III.E/F | AR-8, AR-9, AR-10, AR-11, AR-12 | Eliminate standing secrets as an inter-agent attack and persistence surface. |
| MAS-05 | Action- and Artifact-Level Monitoring Primacy over Message-Log Review | III.E/F | AR-8, AR-9, AR-10, AR-11, AR-12 | Anchor inter-agent oversight on actions and artifacts (diffs, tool calls, side effects), because the message channel itself can be made monitor-proof. |
| MAS-06 | Trusted Monitor over Multi-Agent Work Products | III.E/F | AR-8, AR-9, AR-10, AR-11, AR-12 | Detect coordinated sabotage in multi-agent pipelines using an independent trusted monitor with a defined false-positive budget. |
| MAS-07 | Persistent-State and Cross-Session Sabotage Review | III.E/F | AR-8, AR-9, AR-10, AR-11, AR-12 | Close the review gap created by agents that operate across sessions in persistent state, where per-increment review misses distributed attacks by cons |
| MAS-08 | Collusion Detection Instrumentation (Ensembled, Never Assumed Solved) | III.E/F | AR-8, AR-9, AR-10, AR-11, AR-12 | Instrument for inter-agent collusion with ensembled techniques while treating detection as inherently incomplete. |
| MAS-09 | Deployment-Rule Red-Teaming (Institutional Configuration as an Attack Surface) | III.E/F | AR-8, AR-9, AR-10, AR-11, AR-12 | Red-team the rules, incentives, and wording that govern a multi-agent deployment, not only the models within it. |
| MAS-10 | Cascade and Propagation Containment; Multi-Agent Necessity Justification | III.E/F | AR-8, AR-9, AR-10, AR-11, AR-12 | Contain error and misinformation propagation across agent networks, and require justification that multi-agent architecture is necessary at all. |
| TPR-01 | Model-Provider Due Diligence and Third-Party AI Risk Classification | III.E/F | AR-15 | Subject every external model, API, and agent-component provider to due diligence proportionate to criticality before use. |
| TPR-02 | Vendor Concentration and Systemic Dependency Management | III.E/F | AR-15 | Measure, report, and bound the firm's dependency concentration on frontier-model providers. |
| TPR-03 | Upstream Model and Weight Change Management | III.E/F | AR-15 | Ensure no upstream model change (version, weights, defaults, deprecation) reaches production agents without detection, re-validation, and approval. |
| TPR-04 | Vendor Evaluation Evidence: Demand, Verify, and Do Not Rely Solely on First-Party Claims | III.E/F | AR-15 | Base reliance on vendor models on evaluation evidence that is transparent, valid, and at least partly independent. |
| TPR-05 | Documentation Artifacts for Third-Party Models and Datasets | III.E/F | AR-15 | Require complete, current documentation (model cards, dataset documentation, system cards) for every third-party model and dataset before reliance. |
| TPR-06 | Third-Party Tool and MCP-Server Supply-Chain Security | III.E/F | AR-15 | Prevent third-party agent tools, MCP servers and equivalent tool endpoints, from becoming an unvetted execution and exfiltration channel. |
| TPR-07 | API Dependency Resilience, Degradation, and Exit | III.E/F | AR-15 | Ensure the failure, throttling, or withdrawal of an external model API degrades agent-dependent processes gracefully rather than catastrophically. |
| TPR-08 | Contractual Controls, Secure Access Tiers, and the Third-Party Assurance Ecosystem | III.E/F | AR-15 | Encode the firm's AI supply-chain requirements in enforceable contract terms, and govern any access granted to third parties (evaluators, auditors, ve |
| ASR-01 | Documented layered assurance stack | IV | AR-3, AR-13, AR-14, AR-15, AR-16 | Ensure the institution can show a complete, unbroken assurance chain from board oversight to independent certification for its AI estate. |
| ASR-02 | AI impact assessment as a first-line gate | IV | AR-3, AR-13, AR-14, AR-15, AR-16 | Ensure no agentic system reaches production without a documented, standards-aligned impact assessment owned by the deploying business. |
| ASR-03 | Independent internal audit of agentic AI | IV | AR-3, AR-13, AR-14, AR-15, AR-16 | Provide the board with third-line assurance that agentic AI controls exist and operate, using recognized audit frameworks. |
| ASR-04 | End-to-end internal algorithmic audit methodology | IV | AR-3, AR-13, AR-14, AR-15, AR-16 | Ensure internal audits of agentic systems follow a structured, artifact-producing methodology rather than ad-hoc review. |
| ASR-05 | Accredited certification of the AI management system | IV | AR-3, AR-13, AR-14, AR-15, AR-16 | Obtain third-party, accreditation-backed certification of the AIMS so that conformity claims do not rest on self-attestation. |
| ASR-06 | Conformity-assessment readiness for regulated high-risk uses | IV | AR-3, AR-13, AR-14, AR-15, AR-16 | Ensure agentic systems that fall in scope of binding conformity-assessment regimes can pass them without remediation panic. |
| ASR-07 | Frontier-safety-framework vendor diligence | IV | AR-3, AR-13, AR-14, AR-15, AR-16 | Make model providers' published safety frameworks a mandatory, structured input to third-party risk assessment of frontier-model vendors. |
| ASR-08 | Vendor safety-framework change monitoring | IV | AR-3, AR-13, AR-14, AR-15, AR-16 | Detect and assess material changes in providers' safety frameworks over the life of the relationship, not only at onboarding. |
| ASR-09 | Transparency artifacts as mandatory audit evidence | IV | AR-3, AR-13, AR-14, AR-15, AR-16 | Require standardized, current documentation artifacts for every agentic system so that audit, validation, and conformity assessment draw on the same e |
| ASR-10 | Assurance evidence repository | IV | AR-3, AR-13, AR-14, AR-15, AR-16 | Preserve all assurance artifacts (assessments, audits, certificates, vendor framework versions, cards) in a trustworthy, examiner-ready repository. |
| FCO-01 | Covered-Decision Inventory and Fairness Scoping | VI | AR-12 | Ensure every agent action that constitutes or materially influences a covered consumer decision is identified and in scope for fair-lending controls b |
| FCO-02 | Constrained Decision Policy for Covered Actions | VI | AR-12 | Prevent an agent from introducing undesigned discrimination by choosing its own features, data sources, or decision steps in covered decisions. |
| FCO-03 | Trajectory-Level Disparate-Impact Testing | VI | AR-12 | Detect group-differential outcomes produced by the end-to-end agentic flow, including bias no component exhibits in isolation. |
| FCO-04 | Less-Discriminatory-Alternative Search and Business-Necessity File | VI | AR-12 | Ensure that where a covered flow produces measurable disparity, less-discriminatory alternatives are searched and the retained configuration is justif |
| FCO-05 | Specific and Accurate Adverse-Action Reasons for Agentic Decisions | VI | AR-12 | Guarantee every adverse action taken or driven by an agent carries the specific, accurate statement of reasons the law requires, regardless of flow co |
| FCO-06 | Decision Reproducibility and Trajectory Evidence Capture | VI | AR-12 | Preserve a complete, replayable record of every covered agentic decision sufficient to explain, defend, and if necessary reverse it. |
| FCO-07 | Production Fairness Monitoring for Agentic Flows | VI | AR-12 | Detect emerging disparities in live covered flows between formal testing cycles, including disparities from behavioral drift rather than code change. |
| FCO-08 | Complaint Handling and Human Reopening of Agentic Decisions | VI | AR-12 | Ensure customers aggrieved by an agentic decision have an effective route to human review, and that complaints function as a fairness sensor. |
| FCO-09 | Cohort Remediation and Fairness Lookbacks | VI | AR-12 | Ensure that when a fairness defect is found in an agentic flow, every affected customer, not only complainants, is identified and made whole. |
| FCO-10 | Vulnerable-Customer Safeguards in Agent Interactions | VI | AR-12 | Prevent autonomous agents from exploiting, pressuring, or disadvantaging customers with reduced capacity to protect their own interests. |