Skip to contentThe Observability LayerSearch

Flagship compendium · Section 16 of 24

Appendix A: Master Control Index

All 112 controls. The AR rows column is the family-level inverse of the Part I taxonomy: the agentic risks (AR-1..AR-16) whose treating-control families include this control's family. It is a navigation aid, not a per-control risk assessment.

Evidence table: ID, Control, Part, AR rows treated (family-level), Objective
IDControlPartAR rows treated (family-level)Objective
GOV-01Board-Approved AI & Autonomy Governance CharterIIAR-1, AR-10, AR-11, AR-14, AR-16Establish board-level accountability for AI use, including an explicit, written risk appetite for agent autonomy.
GOV-02Enterprise AI Management System (AIMS)IIAR-1, AR-10, AR-11, AR-14, AR-16Operate a single, certifiable management system governing the responsible development, provision, and use of AI systems, including agents.
GOV-03Agent Inventory & RegistrationIIAR-1, AR-10, AR-11, AR-14, AR-16Ensure every agent operating in or for the institution is known, uniquely identified, and lifecycle-managed.
GOV-04Named Accountable Owner per AgentIIAR-1, AR-10, AR-11, AR-14, AR-16Guarantee that accountability for every agent's conduct rests with an identified human role at all times.
GOV-05Agentic Systems Within Model Risk Management ScopeIIAR-1, AR-10, AR-11, AR-14, AR-16Subject agentic systems to the institution's model risk management framework with agent-specific scope definitions.
GOV-06Independent Validation & Effective Challenge for AgentsIIAR-1, AR-10, AR-11, AR-14, AR-16Ensure every agent deployment above AT-0 has been independently validated with challenge proportionate to its autonomy and action surface.
GOV-07Autonomy Tier Framework in the Risk AppetiteIIAR-1, AR-10, AR-11, AR-14, AR-16Bound delegated agent authority by a formal, board-approved autonomy tier framework.
GOV-08Autonomy Promotion & Demotion GatesIIAR-1, AR-10, AR-11, AR-14, AR-16Make every change in an agent's delegated authority a controlled, evidenced decision: slow upward, instant downward.
GOV-09Three-Lines Responsibility Assignment for Agentic AIIIAR-1, AR-10, AR-11, AR-14, AR-16Assign every agentic-AI control in the catalog to an accountable line of defense with no orphaned controls.
GOV-10AI Impact Assessment Before Deployment and PromotionIIAR-1, AR-10, AR-11, AR-14, AR-16Ensure the impacts of an agent deployment on customers, the institution, and third parties are assessed and documented before authority is granted or
GOV-11Governance Records & Regulator-Ready DocumentationIIAR-1, AR-10, AR-11, AR-14, AR-16Maintain complete, tamper-evident, retrievable records of agent governance sufficient for internal audit and external examination.
GOV-12Data Quality Management Accountability for Agent-Consumed DataIIAR-1, AR-10, AR-11, AR-14, AR-16Assign management-system accountability for the quality of data agents consume, retrieve, and write, including agent memory.
GOV-13Evidentiary Standards for Oversight & Monitoring ClaimsIIAR-1, AR-10, AR-11, AR-14, AR-16Prevent unproven oversight technology from being booked as effective control coverage in the governance framework.
GOV-14AI Ethics & Escalation Body with Anti-Decoy SafeguardsIIAR-1, AR-10, AR-11, AR-14, AR-16Provide a standing, empowered body for ethical review and escalation of agent deployments, designed so it constrains decisions rather than decorating
DES-01Agent Data Inventory and Governance PlanIII.AAR-5, AR-6, AR-11, AR-14Ensure every dataset that trains, fine-tunes, or is retrievable by an agent is inventoried, owned, and governed before the agent is built.
DES-02Training-Data Provenance Instrumentation and Post-Hoc AuditabilityIII.AAR-5, AR-6, AR-11, AR-14Make it technically possible to answer, after the fact, "was this record (or this copyrighted/confidential source) in the training data?"
DES-03Poisoning-Resistant Data AcquisitionIII.AAR-5, AR-6, AR-11, AR-14Prevent adversarial contamination of the data that shapes agent behavior, at both training and retrieval time.
DES-04Memorization and Training-Data Extraction Risk ControlsIII.AAR-5, AR-6, AR-11, AR-14Prevent agents from leaking memorized training data (customer PII, MNPI, proprietary text) through outputs or tool calls.
DES-05AI System Impact Assessment as a Design GateIII.AAR-5, AR-6, AR-11, AR-14Require a structured, documented impact assessment before any agentic system is approved for build or material change.
DES-06Human-Rights and Customer-Impact Assessment for High-Stakes Agentic ScopeIII.AAR-5, AR-6, AR-11, AR-14Apply a deeper, rights-focused assessment when an agent's action space touches customers' access to credit, insurance, funds, or redress.
DES-07Agent Identity, Ownership, and Lifecycle by DesignIII.AAR-5, AR-6, AR-11, AR-14Ensure every agent is a first-class, individually identifiable principal with a named owner and a bounded lifecycle from the day it is designed.
DES-08Least-Privilege Tool and Permission ScopingIII.AAR-5, AR-6, AR-11, AR-14Grant each agent the minimum tool set, per-tool permissions, and data egress needed for its stated intent, and make the grant enforceable outside the
DES-09Short-Lived, Delegation-Bounded Credential ArchitectureIII.AAR-5, AR-6, AR-11, AR-14Ensure the credentials an agent wields cannot outlive their purpose or exceed the authority of the human they serve.
DES-10User-Level Permission Model: Specify, Derive, EnforceIII.AAR-5, AR-6, AR-11, AR-14Design agent permission systems so that what a user authorizes is faithfully translated into policy and actually enforced at run time: three distinct
DES-11Environmental Constraints as an Oversight SubstrateIII.AAR-5, AR-6, AR-11, AR-14Engineer the agent's environment (access control, network policy, enforced conventions) so oversight and monitoring become materially more effective
DES-12Secure Development and Attestation for the Agent StackIII.AAR-5, AR-6, AR-11, AR-14Hold the software stack that builds and runs agents (pipelines, frameworks, orchestration, serving) to secure software development practice, with at
DES-13Model, Artifact, and Tool Provenance: Signing and Integrity VerificationIII.AAR-5, AR-6, AR-11, AR-14Guarantee that the model weights, adapters, prompts, tool definitions, and datasets an agent loads in production are exactly the artifacts that were a
DES-14Memory and Context Architecture as Designed Control SurfacesIII.AAR-5, AR-6, AR-11, AR-14Treat what an agent remembers, retrieves, and holds in context as deliberate architectural decisions with risk consequences: scoped, provenance-tagge
EVL-01Documented Pre-Deployment Evaluation Plan per Agent SystemIII.BAR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15Ensure every agentic system enters evaluation with a pre-committed, risk-based plan defining what is tested, on what system configuration, and against
EVL-02Multi-Dimensional Capability & Fitness EvaluationIII.BAR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15Measure agent fitness on all dimensions that predict production success, not task accuracy alone.
EVL-03Dangerous-Capability Evaluation ProgrammeIII.BAR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15Detect, before deployment, capabilities that could unlock large-scale harm, in both the frontier register and the financial-enterprise register.
EVL-04Full-Capability Elicitation StandardIII.BAR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15Prevent under-elicitation: ensure measured capability approximates the upper bound available to a motivated user or adversary, not the default configu
EVL-05Sandbagging & Evaluation-Awareness TestingIII.BAR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15Detect whether the evaluated system is underperforming strategically or behaving differently because it recognizes the test.
EVL-06Construct & Ecological Validity ReviewIII.BAR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15Ensure each evaluation measures the construct it claims to measure, under conditions that resemble deployment.
EVL-07Benchmark Integrity: Verifier Hardening & Contamination ControlIII.BAR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15Ensure gate-relevant benchmark scores cannot be achieved by gaming the harness or by memorization of test material.
EVL-08Trajectory-Level Evaluation EvidenceIII.BAR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15Ensure evaluation conclusions rest on inspection of what the agent actually did, not only on whether the outcome scored as a pass.
EVL-09Cross-Benchmark CorroborationIII.BAR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15Prevent any single benchmark score from functioning as a safety or fitness verdict.
EVL-10Adversarial Red-Teaming of Agentic SystemsIII.BAR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15Subject the agent, its tools, and its harness to realistic adversarial attack before deployment, at adversary-realistic scale and persistence.
EVL-11Control Evaluations Under Assumed SubversionIII.BAR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15For high-autonomy agents, establish that the deployment protocol keeps outcomes safe even if the model itself is adversarial.
EVL-12Propensity, Sabotage & Misbehavior EvaluationIII.BAR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15Measure whether the agent tends to take harmful or deceptive actions under realistic incentive and pressure conditions: distinct from whether it *c
EVL-13Privacy & Data-Leakage Evaluation of Agent Tool-ChainsIII.BAR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15Verify before deployment that the agent's tool orchestration and inter-agent channels do not leak confidential or customer data.
EVL-14Independent & Third-Party EvaluationIII.BAR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15Ensure gate decisions rest on evaluation evidence with genuine independence from the team, and the vendor, whose system is being judged.
EVL-15Pre-Committed Pass/Fail Thresholds & Go/No-Go Deployment GateIII.BAR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15Bind evaluation results to the deployment decision through thresholds committed before results exist, so the gate cannot be argued open after the fact
EVL-16Continuous Re-Evaluation TriggersIII.BAR-2, AR-4, AR-7, AR-8, AR-9, AR-12, AR-13, AR-15Ensure the evaluation evidence behind a live deployment remains true of the system actually running, by re-testing on every material change to model,
RUN-01Designated Oversight Mode per Agent DeploymentIII.CAR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16Every production agent operates under an explicitly chosen, documented, and risk-justified human oversight mode.
RUN-02Structured Adversarial Review at Approval GatesIII.CAR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16Human approval of agent actions detects harmful or erroneous output at a measured, acceptable rate, not merely records assent.
RUN-03Oversight Triggers Wired to Observable SignalsIII.CAR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16Escalation to human review is triggered by signals the agent cannot fabricate, never solely by the agent's self-assessment.
RUN-04Graduated Autonomy with Deferral (Act-or-Ask)III.CAR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16Agents earn autonomy per action class, and are architected to defer to humans when risk rises, with incentives that never reward evading oversight.
RUN-05AI-Control Protocol as the Deployment BaselineIII.CAR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16Every material agent deployment runs under a named control protocol designed to remain safe even if the model actively subverts safety measures.
RUN-06Trusted Monitoring of Untrusted Agent ActionsIII.CAR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16Every action proposed by an untrusted agent is scored for suspicion by an independent trusted monitor before or immediately upon execution.
RUN-07Untrusted Monitoring with Collusion SafeguardsIII.CAR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16Where trusted models are too weak to assess a frontier agent's actions, stronger untrusted monitors are used: under explicit anti-collusion controls.
RUN-08Resample and Defer-to-Trusted Protocols for Suspicious ActionsIII.CAR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16Suspicious agent actions are not merely blocked but resampled or rerouted, converting single alerts into accumulating evidence while preserving throug
RUN-09Adaptive Deployment Against Distributed ThreatsIII.CAR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16Runtime protection adapts to accumulated behavioral evidence, defending against harm that accrues across many small actions rather than one catastroph
RUN-10Adversarial Validation of the Monitoring StackIII.CAR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16The institution knows its monitors' real catch rates against refined, adaptive attacks, not just against naive ones, and provisions residual-risk co
RUN-11Sandboxed Execution and Environment ContainmentIII.CAR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16Agents execute in isolated environments whose blast radius is bounded in advance, so that even successful subversion cannot reach systems or data beyo
RUN-12Kill Switch: Tested Emergency Shutdown per AgentIII.CAR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16Any production agent can be halted immediately, by named humans, through a mechanism the agent cannot influence, with a tested and rehearsed procedure
RUN-13Graceful Degradation and Fallback Operating ModesIII.CAR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16When runtime controls fire or dependencies fail, the business process degrades to a safe, lower-autonomy mode instead of failing open or halting the b
RUN-14Hard Budget, Turn, and Spend GuardsIII.CAR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16Every agent run is bounded by non-negotiable limits on money spent, actions taken, turns/steps consumed, tokens/compute used, and wall-clock time: en
RUN-15Call-Time Tool Gating and Permission EnforcementIII.CAR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16Every tool invocation is checked against policy at the moment of the call, with least-privilege scopes, and denied-by-default for anything not explici
RUN-16Chain-Aware Compositional Tool Policies with Taint TrackingIII.CAR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16Tool-call sequences are governed as first-class objects, so that combinations of individually permitted tools cannot compose into a policy violation
RUN-17Approval Workflows for Consequential ActionsIII.CAR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16Actions above defined consequence thresholds cannot execute without an affirmative, authenticated, recorded human approval obtained through a dedicate
RUN-18Runtime Trajectory and Reasoning-Trace CaptureIII.CAR-1, AR-2, AR-3, AR-4, AR-5, AR-6, AR-7, AR-10, AR-11, AR-16Complete agent trajectories (inputs, reasoning traces where available, every tool call and result, monitor scores, and policy decisions) are capture
MON-01Complete, Attributable Agent Action LoggingIII.DAR-1, AR-2, AR-3, AR-4, AR-6, AR-7, AR-8, AR-9, AR-12, AR-16Ensure every consequential action taken by an agent is recorded, attributable to exactly one agent identity, and reconstructable after the fact.
MON-02Reasoning-Trace Capture & RetentionIII.DAR-1, AR-2, AR-3, AR-4, AR-6, AR-7, AR-8, AR-9, AR-12, AR-16Preserve agent (and AI-monitor) reasoning traces so that oversight, collusion detection, and post-incident analysis remain possible.
MON-03Agent Observability Platform & Telemetry TaxonomyIII.DAR-1, AR-2, AR-3, AR-4, AR-6, AR-7, AR-8, AR-9, AR-12, AR-16Provide a single operational pane where agent health, behavior, cost, and control-status signals are collected against a defined telemetry taxonomy.
MON-04Statistical Drift & Performance-Degradation DetectionIII.DAR-1, AR-2, AR-3, AR-4, AR-6, AR-7, AR-8, AR-9, AR-12, AR-16Detect when the statistical world an agent operates in (inputs, outputs, task mix, environment) has shifted away from the conditions it was validate
MON-05Behavioral Baselining & Goal-Drift MonitoringIII.DAR-1, AR-2, AR-3, AR-4, AR-6, AR-7, AR-8, AR-9, AR-12, AR-16Detect when an agent's behavior, as distinct from its statistical inputs/outputs, departs from its mandated goal or established behavioral baselin
MON-06Tool-Use & Environment Anomaly DetectionIII.DAR-1, AR-2, AR-3, AR-4, AR-6, AR-7, AR-8, AR-9, AR-12, AR-16Detect anomalous or malicious agent interactions with tools, integrations, and the execution environment, including compromise of the tool layer itse
MON-07AI-Supervised Monitoring of Agents (Hierarchical Oversight)III.DAR-1, AR-2, AR-3, AR-4, AR-6, AR-7, AR-8, AR-9, AR-12, AR-16Scale oversight beyond human review capacity by deploying AI monitors over production agents, while controlling for monitor collusion and monitor obso
MON-08Monitoring-Latency Budget (Detect-to-Respond SLO)III.DAR-1, AR-2, AR-3, AR-4, AR-6, AR-7, AR-8, AR-9, AR-12, AR-16Ensure the monitoring system detects and responds faster than the agent can cause irreversible harm, because a correct control action that arrives la
MON-09Agentic Incident Classification & Severity TaxonomyIII.DAR-1, AR-2, AR-3, AR-4, AR-6, AR-7, AR-8, AR-9, AR-12, AR-16Classify agentic failures consistently (by mechanism, severity, and regulatory reportability) so response, disclosure, and learning are triggered de
MON-10Agentic Incident Response & ContainmentIII.DAR-1, AR-2, AR-3, AR-4, AR-6, AR-7, AR-8, AR-9, AR-12, AR-16Contain, investigate, and remediate agentic incidents with response actions matched to how agents fail: credential revocation, agent halt, delegation
MON-11Regulatory Incident-Reporting Obligations RegisterIII.DAR-1, AR-2, AR-3, AR-4, AR-6, AR-7, AR-8, AR-9, AR-12, AR-16Meet every external AI incident-reporting duty the institution is subject to (with the correct trigger, recipient, and clock) and never discover a 7
MON-12Safeguard Re-Verification & Feedback into Re-EvaluationIII.DAR-1, AR-2, AR-3, AR-4, AR-6, AR-7, AR-8, AR-9, AR-12, AR-16Treat safeguards as decaying assets: continuously verify that monitoring controls still work, and route production findings back into the evaluation g
MAS-01Multi-Agent System Inventory and Topology RegistrationIII.E/FAR-8, AR-9, AR-10, AR-11, AR-12Ensure every agent, sub-agent, and inter-agent connection in production is inventoried, owned, and known to risk management before it operates.
MAS-02Unique Agent Identity with Attributable Action LoggingIII.E/FAR-8, AR-9, AR-10, AR-11, AR-12Make every consequential action in a multi-agent system attributable to exactly one authenticated agent identity.
MAS-03Authenticated Delegation with Bounded Authority ChainsIII.E/FAR-8, AR-9, AR-10, AR-11, AR-12Ensure authority passed between agents (and from humans to agents) is authenticated, scoped, and never broader than the delegator's own.
MAS-04Short-Lived, Dynamically Issued Agent CredentialsIII.E/FAR-8, AR-9, AR-10, AR-11, AR-12Eliminate standing secrets as an inter-agent attack and persistence surface.
MAS-05Action- and Artifact-Level Monitoring Primacy over Message-Log ReviewIII.E/FAR-8, AR-9, AR-10, AR-11, AR-12Anchor inter-agent oversight on actions and artifacts (diffs, tool calls, side effects), because the message channel itself can be made monitor-proof.
MAS-06Trusted Monitor over Multi-Agent Work ProductsIII.E/FAR-8, AR-9, AR-10, AR-11, AR-12Detect coordinated sabotage in multi-agent pipelines using an independent trusted monitor with a defined false-positive budget.
MAS-07Persistent-State and Cross-Session Sabotage ReviewIII.E/FAR-8, AR-9, AR-10, AR-11, AR-12Close the review gap created by agents that operate across sessions in persistent state, where per-increment review misses distributed attacks by cons
MAS-08Collusion Detection Instrumentation (Ensembled, Never Assumed Solved)III.E/FAR-8, AR-9, AR-10, AR-11, AR-12Instrument for inter-agent collusion with ensembled techniques while treating detection as inherently incomplete.
MAS-09Deployment-Rule Red-Teaming (Institutional Configuration as an Attack Surface)III.E/FAR-8, AR-9, AR-10, AR-11, AR-12Red-team the rules, incentives, and wording that govern a multi-agent deployment, not only the models within it.
MAS-10Cascade and Propagation Containment; Multi-Agent Necessity JustificationIII.E/FAR-8, AR-9, AR-10, AR-11, AR-12Contain error and misinformation propagation across agent networks, and require justification that multi-agent architecture is necessary at all.
TPR-01Model-Provider Due Diligence and Third-Party AI Risk ClassificationIII.E/FAR-15Subject every external model, API, and agent-component provider to due diligence proportionate to criticality before use.
TPR-02Vendor Concentration and Systemic Dependency ManagementIII.E/FAR-15Measure, report, and bound the firm's dependency concentration on frontier-model providers.
TPR-03Upstream Model and Weight Change ManagementIII.E/FAR-15Ensure no upstream model change (version, weights, defaults, deprecation) reaches production agents without detection, re-validation, and approval.
TPR-04Vendor Evaluation Evidence: Demand, Verify, and Do Not Rely Solely on First-Party ClaimsIII.E/FAR-15Base reliance on vendor models on evaluation evidence that is transparent, valid, and at least partly independent.
TPR-05Documentation Artifacts for Third-Party Models and DatasetsIII.E/FAR-15Require complete, current documentation (model cards, dataset documentation, system cards) for every third-party model and dataset before reliance.
TPR-06Third-Party Tool and MCP-Server Supply-Chain SecurityIII.E/FAR-15Prevent third-party agent tools, MCP servers and equivalent tool endpoints, from becoming an unvetted execution and exfiltration channel.
TPR-07API Dependency Resilience, Degradation, and ExitIII.E/FAR-15Ensure the failure, throttling, or withdrawal of an external model API degrades agent-dependent processes gracefully rather than catastrophically.
TPR-08Contractual Controls, Secure Access Tiers, and the Third-Party Assurance EcosystemIII.E/FAR-15Encode the firm's AI supply-chain requirements in enforceable contract terms, and govern any access granted to third parties (evaluators, auditors, ve
ASR-01Documented layered assurance stackIVAR-3, AR-13, AR-14, AR-15, AR-16Ensure the institution can show a complete, unbroken assurance chain from board oversight to independent certification for its AI estate.
ASR-02AI impact assessment as a first-line gateIVAR-3, AR-13, AR-14, AR-15, AR-16Ensure no agentic system reaches production without a documented, standards-aligned impact assessment owned by the deploying business.
ASR-03Independent internal audit of agentic AIIVAR-3, AR-13, AR-14, AR-15, AR-16Provide the board with third-line assurance that agentic AI controls exist and operate, using recognized audit frameworks.
ASR-04End-to-end internal algorithmic audit methodologyIVAR-3, AR-13, AR-14, AR-15, AR-16Ensure internal audits of agentic systems follow a structured, artifact-producing methodology rather than ad-hoc review.
ASR-05Accredited certification of the AI management systemIVAR-3, AR-13, AR-14, AR-15, AR-16Obtain third-party, accreditation-backed certification of the AIMS so that conformity claims do not rest on self-attestation.
ASR-06Conformity-assessment readiness for regulated high-risk usesIVAR-3, AR-13, AR-14, AR-15, AR-16Ensure agentic systems that fall in scope of binding conformity-assessment regimes can pass them without remediation panic.
ASR-07Frontier-safety-framework vendor diligenceIVAR-3, AR-13, AR-14, AR-15, AR-16Make model providers' published safety frameworks a mandatory, structured input to third-party risk assessment of frontier-model vendors.
ASR-08Vendor safety-framework change monitoringIVAR-3, AR-13, AR-14, AR-15, AR-16Detect and assess material changes in providers' safety frameworks over the life of the relationship, not only at onboarding.
ASR-09Transparency artifacts as mandatory audit evidenceIVAR-3, AR-13, AR-14, AR-15, AR-16Require standardized, current documentation artifacts for every agentic system so that audit, validation, and conformity assessment draw on the same e
ASR-10Assurance evidence repositoryIVAR-3, AR-13, AR-14, AR-15, AR-16Preserve all assurance artifacts (assessments, audits, certificates, vendor framework versions, cards) in a trustworthy, examiner-ready repository.
FCO-01Covered-Decision Inventory and Fairness ScopingVIAR-12Ensure every agent action that constitutes or materially influences a covered consumer decision is identified and in scope for fair-lending controls b
FCO-02Constrained Decision Policy for Covered ActionsVIAR-12Prevent an agent from introducing undesigned discrimination by choosing its own features, data sources, or decision steps in covered decisions.
FCO-03Trajectory-Level Disparate-Impact TestingVIAR-12Detect group-differential outcomes produced by the end-to-end agentic flow, including bias no component exhibits in isolation.
FCO-04Less-Discriminatory-Alternative Search and Business-Necessity FileVIAR-12Ensure that where a covered flow produces measurable disparity, less-discriminatory alternatives are searched and the retained configuration is justif
FCO-05Specific and Accurate Adverse-Action Reasons for Agentic DecisionsVIAR-12Guarantee every adverse action taken or driven by an agent carries the specific, accurate statement of reasons the law requires, regardless of flow co
FCO-06Decision Reproducibility and Trajectory Evidence CaptureVIAR-12Preserve a complete, replayable record of every covered agentic decision sufficient to explain, defend, and if necessary reverse it.
FCO-07Production Fairness Monitoring for Agentic FlowsVIAR-12Detect emerging disparities in live covered flows between formal testing cycles, including disparities from behavioral drift rather than code change.
FCO-08Complaint Handling and Human Reopening of Agentic DecisionsVIAR-12Ensure customers aggrieved by an agentic decision have an effective route to human review, and that complaints function as a fairness sensor.
FCO-09Cohort Remediation and Fairness LookbacksVIAR-12Ensure that when a fairness defect is found in an agentic flow, every affected customer, not only complainants, is identified and made whole.
FCO-10Vulnerable-Customer Safeguards in Agent InteractionsVIAR-12Prevent autonomous agents from exploiting, pressuring, or disadvantaging customers with reduced capacity to protect their own interests.