Reader paths
- Chief Risk Officer / Chief AI Risk Officer. Read this Executive Summary, Part I (through the AR taxonomy table), Section 2.5 (the autonomy ladder), Part V's master mapping table (V.10), and Part VII's board-pack checklist. Delegate the rest, but keep the five decisions above on your own desk.
- Head of Model Risk / Validation. Part II (MRM extension, Sections 2.3–2.6), then Part III.B in full. It is the crown jewel and the deepest change to your discipline: effective challenge now extends to the evaluation harness itself. Then EVL-15/EVL-16 gate mechanics, GOV-13 (evidentiary standards for monitoring claims), and Part VII's RACI.
- Engineering / Platform Lead. Part III.A (DES) and Part III.C (RUN) are your build spec; Part III.D (MON) is your operations spec. Start with DES-07/DES-08 (identity, least privilege), RUN-14/RUN-15 (hard limits, tool gating), and RUN-18/MON-01 (trajectory capture). Part III.E/F applies the moment one agent invokes another or a vendor model sits upstream, which is to say, immediately.
- Internal Audit. Part IV in full, especially IV.2 and ASR-03/ASR-04; then the Evidence line of every control in scope for your audit universe. The recurring audit questions this document equips you to ask: "show me the trail" and "prove the alarm still rings."
- Compliance / Legal. Part V in full, MON-11 (the incident-reporting obligations register and its clocks), and Part VI: the FCO controls operationalize ECOA/Reg B, the Colorado ADMT human-review right, and GDPR Article 22 for flows where an agent, not a scorecard, drove the decision.
Citation conventions
- Corpus-sourced claims cite a source reference with its evidence tier (T1 strongest → T4) and a URL, e.g.
arxiv.org/abs/2504.10374 (T1). Verbatim quotations come only from the cited primary sources; everything else is paraphrase. [practice guidance: not directly source-backed]marks statements the drafters believe are sound practice but that the cited research does not directly support: recommended thresholds, cadences, and implementation specifics. They are labeled so you can weight them accordingly; they are not lesser advice, only differently warranted.- Provisional claims are not established evidence. Examples include the AR-10 shutdown-resistance claim, figures available only in abstracts, and legal dates contingent on enacted text. Consult the cited primary source before relying on them.
- Where a section does not cite the primary text of a regime, the mapping is stated at instrument level and labeled; article-level regulatory citation authority lives in Part V.
Control schema legend
Every control uses the same eight-field block:
| Field | What it tells you |
|---|---|
| Objective | The risk outcome, in one sentence. |
| Control | The normative, testable requirement: what must be true or enforced. |
| Implementation (financial enterprise) | How to build and operate it in a bank/insurer/asset manager: systems, teams, thresholds. |
| Maturity | Baseline → Enhanced → Frontier, one line each; calibrate against Part VII's M1–M4 model. |
| Ownership | First-line / second-line / third-line responsibilities (the RACI in Part VII aggregates these). |
| Evidence | Artifacts an examiner or internal audit accepts. |
| Mappings | NIST AI RMF function; ISO/IEC 42001; EU AI Act article where sourced; SR 11-7/OCC 2011-12 aspect; DORA aspect where relevant. |
| Sources | Corpus citations, slug (Tier): URL. |
Control IDs (e.g., GOV-03, EVL-15, RUN-14) are stable. Cite them in policies, findings, test plans, and board papers; Appendix A is the master index of all 112.