Skip to contentThe Observability LayerSearch

Flagship compendium · Section 5 of 24

Part II: Governance & Accountability

Governance is the part of agentic AI that boards believe they already do, vendors assure them is handled, and examiners discover is missing. An autonomous agent is the first technology asset a bank has ever operated that can read its own audit findings, so the governance structure had better be one that survives being read. This Part sets out who is accountable for what: board duties, the AI management system (ISO/IEC 42001), the extension of model risk management (SR 11-7 vocabulary) to systems that act rather than merely estimate, three lines of defense for agents, and a formal risk appetite for autonomy expressed as tiers and approval gates. It closes with controls GOV-01 through GOV-14.

2.1 Board duties for AI: the governing-body lens

The governing body of a financial institution does not operate agents; it governs the use of them. ISO/IEC 38507 (Governance implications of the use of artificial intelligence by organizations) frames this as the extension of existing governance-of-IT duties (strategy, value, risk, and oversight of delegated authority) to AI specifically [practice guidance: not directly source-backed: ISO/IEC 38507 is not in the sources cited here; the framing below is anchored to the cited research sources cited].

What the cited research does establish is the shape of the duty. The GAO accountability framework is written as a framework an overseer (auditor, board, third party) can hold an entity to, not a checklist the entity self-attests (gao.gov/products/gao-21-519sp, T1: https://www.gao.gov/products/gao-21-519sp). Deloitte's board-effectiveness roadmap makes the boardroom-side point: AI oversight is a full-board and committee-structure question, not a delegated technical detail (deloitte.com/us/en/programs/center-for-board-effectiveness/articles/board-of-directors-governance-framework-artificial-intelligence.html, T3). The DHS Roles and Responsibilities Framework shows the pattern regulators increasingly expect: responsibilities enumerated by named role in the AI value chain, so a failure has a specific accountable party rather than a diffuse "the organization" (dhs.gov/sites/default/files/2024-11/24_1114_dhs_ai-roles-and-responsibilities-framework-508.pdf, T1, https://www.dhs.gov/sites/default/files/2024-11/24_1114_dhs_ai-roles-and-responsibilities-framework-508.pdf).

For agentic systems, four board duties follow:

  1. Set the risk appetite for autonomy. The board approves, in the risk appetite statement, the maximum autonomy tier permitted per business activity (Section 2.5). Delegating an action to an agent is a delegation of authority; boards govern delegations of authority. This is the single duty most institutions have not yet performed.
  2. Demand an accountable human owner for every agent. the cited research's practitioner baseline is that each agent needs "a defined owner, a clear intent, a bounded scope of access, and an explicit lifecycle" (helpnetsecurity.com/2026/06/12/nist-iso-frameworks-govern-ai-agents, T3: https://www.helpnetsecurity.com/2026/06/12/nist-iso-frameworks-govern-ai-agents/). Ownerless agents are orphaned service accounts, with a plan.
  3. Require management-system evidence, not narrative assurance. The board should receive AIMS performance reporting (Section 2.2), validation coverage against the agent inventory, and incident/near-miss trends: artifacts, not adjectives.
  4. Guard against accountability theater. Accountability structures can become "decoys" (visible mechanisms that absorb scrutiny without constraining the system (doi.org/10.1145/3805689.3806739, T2) https://doi.org/10.1145/3805689.3806739), and record-keeping regimes can themselves capture oversight, answering the questions the audited party prefers (ojs.aaai.org/index.php/aies/article/view/36570, T2: https://ojs.aaai.org/index.php/AIES/article/view/36570). The countermeasure is independence: second-line challenge and third-line audit that select their own evidence.

One conceptual caution belongs at board level: anthropomorphic framing obscures rather than resolves accountability, agency in the machine does not create accountability in the machine; it remains with the humans and institutions that deployed it (proceedings.mlr.press/v235/dai24a.html, T2, https://proceedings.mlr.press/v235/dai24a.html). "The agent decided" is a description of a control failure, not an accountability answer.

2.2 The AI management system: ISO/IEC 42001

Board duties need an operating chassis. That chassis is the AI management system. ISO's public description is precise about what the standard specifies:

"An AI management system, as specified in ISO/IEC 42001, is a set of interrelated or interacting elements of an organization intended to establish policies and objectives, as well as processes to achieve those objectives, in relation to the responsible development, provision or use of AI systems." (ISO public description (iso.org/standard/42001, T1) https://www.iso.org/standard/42001)

ISO describes 42001 as "the world's first AI management system standard," specifying requirements for "establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS)" (iso.org/standard/42001, T1: https://www.iso.org/standard/42001; catalogue entry: iso.org/standard/81230.html, T1, https://www.iso.org/standard/81230.html). Per secondary-sourced structural summaries in the cited research (not verbatim ISO text), 42001 follows the Annex SL / Plan-Do-Check-Act shape across Clauses 4–10, context, leadership, planning, support, operation, performance evaluation, improvement, with an Annex A of reference controls; exact clause and control wording is paywalled and not quoted here.

For a financial institution, three implementation points matter:

  • The AIMS is the integration layer, not a new silo. NIST's own crosswalk maps the AI RMF's functions to 42001's requirements (airc.nist.gov/docs/nist_ai_rmf_to_iso_iec_42001_crosswalk.pdf, T2: https://airc.nist.gov/docs/NIST_AI_RMF_to_ISO_IEC_42001_Crosswalk.pdf): one management system, both frameworks evidenced. Bolt the AIMS onto the existing risk taxonomy and ISO 27001-style machinery rather than duplicating either.
  • An AIMS certificate does not automatically cover an agent fleet. the cited research's practitioner analysis flags that 42001 was not written for autonomous agents, with inventory/ownership and behavioral-monitoring gaps; the delta controls are agent registration/onboarding, automatic expiration for temporary agents, complete audit trails attributing every meaningful action to a specific identity, and recurring privilege-creep assessments (helpnetsecurity.com/2026/06/12/nist-iso-frameworks-govern-ai-agents, T3: https://www.helpnetsecurity.com/2026/06/12/nist-iso-frameworks-govern-ai-agents/). GOV-03, GOV-04, and GOV-12 codify that delta.
  • The AIMS supplies the testing hook. ISO/IEC TS 42119-2 applies the ISO/IEC/IEEE 29119 software-testing series to AI systems using a "risk-based approach" deriving test practices from the risks of the AI system and its development (iso.org/standard/84127.html, T1, https://www.iso.org/standard/84127.html). A TS is guidance, not a certifiable requirement, but it gives second line a citable, vendor-neutral basis to demand risk-based testing evidence from builders and vendors.

Supporting management-system standards slot in beneath: ISO/IEC 5259-3 for data quality management requirements in analytics and ML (iso.org/standard/81092.html, T1, https://www.iso.org/standard/81092.html), and ISO 30301 for records management systems (iso.org/standard/74292.html, T2, https://www.iso.org/standard/74292.html), relevant because agent action logs are records, and regulators will treat them as such.

2.3 Extending model risk management to agentic systems: SR 11-7 vocabulary

US banking institutions already possess the most battle-tested AI governance regime in existence: model risk management under SR 11-7 / OCC Bulletin 2011-12 (federalreserve.gov/supervisionreg/srletters/sr1107.htm, T1, https://www.federalreserve.gov/supervisionreg/srletters/sr1107.htm; occ.gov/news-issuances/bulletins/2011/bulletin-2011-12.html, T1, https://www.occ.gov/news-issuances/bulletins/2011/bulletin-2011-12.html), revised as SR 26-2 / OCC Bulletin 2026-13 (federalreserve.gov/supervisionreg/srletters/sr2602.htm, T1, https://www.federalreserve.gov/supervisionreg/srletters/SR2602.htm; occ.gov/news-issuances/bulletins/2026/bulletin-2026-13.html, T1, https://www.occ.gov/news-issuances/bulletins/2026/bulletin-2026-13.html). The correct posture is not a parallel "agent risk framework" but extending MRM vocabulary, model definition, inventory, development standards, independent validation, effective challenge, ongoing monitoring, use restrictions, to systems that act. The interagency application of MRM to BSA/AML systems (federalreserve.gov/supervisionreg/srletters/sr2108.htm, T1: https://www.federalreserve.gov/supervisionreg/srletters/SR2108.htm) is the precedent for stretching MRM across an operational, workflow-embedded class of systems.

Five extensions are required, because agents break MRM assumptions in specific places:

  • Scope. An agentic system is a model plus an action surface: tools, credentials, memory, orchestration. The unit of inventory and validation is the deployed agent configuration (model version + system prompt + toolset + permissions + autonomy tier), not the base model. Two deployments of one model with different toolsets are different risk objects.
  • Model use. SR 11-7's concern with incorrect use of model output becomes concern with execution: the agent uses its own output. The gap between "model error" and "business loss", traditionally filled by a human user, closes to zero at higher autonomy tiers, so validation must cover the action pathway, not just output quality.
  • Effective challenge. Challenge must extend to behavior: scope adherence under adversarial input, safe degradation, monitor evasion. the cited research's control-research framing treats a deployed agent as a potential insider threat and prescribes defense-in-depth protections that hold even if the agent is misaligned (deepmind.google/blog/securing-the-future-of-ai-agents, T1: https://deepmind.google/blog/securing-the-future-of-ai-agents/). Effective challenge for agents is insider-threat challenge.
  • Ongoing monitoring. Static periodic revalidation fails for systems whose behavior shifts with context, memory, and upstream model updates. Key risk to autonomy, permission breadth, and data sensitivity, with real-time permission revocation and behavioral-drift detection (helpnetsecurity.com/2026/06/12/nist-iso-frameworks-govern-ai-agents, T3: https://www.helpnetsecurity.com/2026/06/12/nist-iso-frameworks-govern-ai-agents/).
  • Documentation. For EU-facing high-risk deployments, produce the EU AI Act Article 11 / Annex IV technical documentation (artificialintelligenceact.eu/article/11, T1, https://artificialintelligenceact.eu/article/11/) from the same evidence base as the SR 11-7-style model documentation package, one file, two regulator-facing views.

A validation caveat the second line must internalize: do not accept vendor "pre-action intent detection" or white-box probe claims as compensating controls without adversarial proof. the cited research's negative results show internal-state probes "read the situation, not the action": a fine-tune-direction probe crossed its threshold on 0/143 audited pre-assistant-turn contexts, and domain-decoding features gave "only +5.1 pp accuracy lift over majority" for future behavior; monitor claims must "survive both scenario/action generalization and concept-specificity controls" (arxiv.org/abs/2606.30449, T2, https://arxiv.org/abs/2606.30449). GOV-13 makes this a standing validation requirement.

2.4 Three lines of defense for agents

The three-lines model maps onto agentic AI cleanly, provided each line's object of work is stated precisely (practice guidance; no specific source cited, T3: corpus canon index entry, no public URL; gao.gov/products/gao-21-519sp, T1, https://www.gao.gov/products/gao-21-519sp).

The idea, step by step

Who owns the controls, and who challenges them?

Explore the roles in the compendium’s assurance model. Ownership and independent challenge have different jobs.

Board oversight

The board and risk committee oversee the direction and accountability of AI use.

Reference in the report: ISO/IEC 38507.

Read every element as text

Board oversight

The board and risk committee oversee the direction and accountability of AI use.

Reference in the report: ISO/IEC 38507.

First line: build and operate

Product and engineering teams own and operate the controls for the systems they deliver.

Control accountability remains with the first line.

Second line: risk and challenge

AI risk and model risk functions challenge decisions and examine how risk is assessed and managed.

References in the report: ISO/IEC 42001, 23894, 42005, and SR 11-7.

Third line: internal audit

Internal audit provides assurance with greater separation from day-to-day product ownership.

Reference in the report: the IIA AI framework.

External assurance

Certification bodies, regulators, and examiners have distinct external roles. Their involvement does not transfer the organization’s accountability.

The report includes ISO/IEC 42006 in its certification discussion.

Explore the complete reference diagram

The original keeps its full size. Scroll within the frame to inspect it, or open it separately.

Who owns the controls, and who challenges them?
Open the original SVG ↗

Conceptual modelSource edition: July 2026 · adapted September 7, 2026

Conceptual role map. Independence is qualitative, not a measured scale; naming these roles does not demonstrate effective oversight.

Figure 2. Three-lines assurance stack.

  • First line: owns and operates. The business and AI engineering teams that build, configure, and run agents: agent inventory records, per-agent owner assignments, runtime guardrails, action logs, incident response. In the cited research's control-roadmap terms, first line operates the detection and prevention machinery: trusted supervisors monitoring agent reasoning, actions, and plans, and blocking harmful actions before execution (deepmind.google/blog/securing-the-future-of-ai-agents, T1, https://deepmind.google/blog/securing-the-future-of-ai-agents/).
  • Second line: sets standards and challenges. Model risk, AI risk, compliance: the MRM-for-agents policy (Section 2.3), the autonomy-tier framework and gates (Section 2.5), independent validation, the effective-challenge record. Second line also measures first-line control performance: coverage, recall, and response-time metrics, per the roadmap's performance-measurement pillar (deepmind.google/blog/securing-the-future-of-ai-agents, T1, https://deepmind.google/blog/securing-the-future-of-ai-agents/).
  • Third line: independent assurance. Internal audit assesses whether the first two lines actually function: inventory completeness, gate bypasses, whether evidence comes from the system of record or was assembled retrospectively. The methodological lineage is the algorithmic audit itself: the discipline established by Gender Shades, whose authors documented of the commercial systems they audited that "the description of classification methodology lacked detail and there was no mention of what training data was used" (proceedings.mlr.press/v81/buolamwini18a.html, T1, https://proceedings.mlr.press/v81/buolamwini18a.html). Auditors of agentic systems should expect the same opacity and insist on primary evidence.

Two design notes. First, for the highest-risk evaluations the cited research supports a deliberate split between internal assurance and external/public bodies, based on case studies of other high-risk industries (ojs.aaai.org/index.php/aies/article/view/31733, T2, https://ojs.aaai.org/index.php/AIES/article/view/31733), plan for external evaluation touchpoints. Second, agents increasingly assist the very oversight decisions humans make about them, and the cited research catalogues structural challenges of AI-assisted decision-making, including miscalibrated reliance (doi.org/10.1177/17456916231181102, T2: https://doi.org/10.1177/17456916231181102). An approver who rubber-stamps agent-drafted justifications is not a line of defense; they are latency.

2.5 Risk appetite for autonomy: tiers and approval gates

Autonomy is not a binary and must not be governed as one. the cited research's control roadmap scales control intensity to model capability along explicit milestone axes, detection-evasion (D1–D4) and harm-execution (R1–R3), escalating from delayed asynchronous review toward real-time synchronous prevention as capability grows (deepmind.google/blog/securing-the-future-of-ai-agents, T1: https://deepmind.google/blog/securing-the-future-of-ai-agents/). The enterprise mirror is an autonomy ladder: discrete tiers of delegated authority, each with entry criteria, standing controls, and demotion triggers, approved against the board's risk appetite. The specific tier boundaries below are [practice guidance: not directly source-backed]; the capability-scaled escalation principle is corpus-anchored as cited.

Evidence table: Tier, Delegated authority, Human oversight mode, Standing controls (minimum), Promotion gate (who approves, on what evidence), Automatic demotion triggers
TierDelegated authorityHuman oversight modeStanding controls (minimum)Promotion gate (who approves, on what evidence)Automatic demotion triggers
AT-0: Observe & draftAgent produces drafts, analyses, recommendations. No execution; no external side effects.Human performs every action.Action logging of drafts; scope-bounded read access; agent registered in inventory (GOV-03).Default entry tier for any new agent. Owner sign-off + inventory registration.n/a (floor tier).
AT-1: Execute with per-action approvalAgent may execute individual actions, each gated on explicit human approval.Synchronous human-in-the-loop per action.AT-0 controls + tool allowlist; short-lived, dynamically issued credentials narrower than the sponsoring human's (helpnetsecurity.com/2026/06/12/nist-iso-frameworks-govern-ai-agents, T3).Agent owner + second-line review of validation report covering the enabled toolset.Any attempt to act outside the allowlist; approval-bypass attempt.
AT-2: Bounded autonomous execution, post-hoc reviewAgent executes a defined class of low-materiality, reversible actions without per-action approval.Asynchronous review of sampled/flagged actions within a defined SLA.AT-1 controls + automated supervisor monitoring of actions and plans with pre-execution blocking of policy violations (deepmind.google/blog/securing-the-future-of-ai-agents, T1) + budget/turn/rate limits + kill switch.Second-line validation incl. adversarial testing; sustained AT-1 track record with error rate under threshold; CAIRO/model-risk committee approval.Monitoring coverage or recall degradation below threshold; unexplained behavioral drift; any Sev-2+ incident.
AT-3: Autonomous within mandateAgent plans and executes multi-step workflows within a written mandate (scope, counterparties, monetary/materiality caps), including limited irreversible actions.Human oversight by exception: escalations, threshold breaches, periodic mandate review.AT-2 controls + independent runtime supervisor distinct from the agent's own stack; real-time permission revocation (helpnetsecurity.com/2026/06/12/nist-iso-frameworks-govern-ai-agents, T3); dual control for actions near mandate caps.Committee approval against board-approved risk appetite; independent validation refresh; internal-audit review of the gate evidence itself.Any mandate breach; monitoring evasion indicators; upstream model change not yet revalidated (auto-drop to AT-2 pending review).
AT-4: Open-ended autonomySelf-directed goal pursuit, self-modification of scope/permissions, autonomy over its own oversight.Not permitted. Outside risk appetite for a regulated financial institution at current control maturity; revisit only via board-level appetite change.n/a.

Rules that make the ladder real rather than decorative:

  1. Tier is a property of the deployed agent configuration, recorded in the inventory. Changing the toolset, model version, or mandate resets the gate.
  2. Promotion is earned on evidence; demotion is instant on incident. Gates upward are slow and committee-owned; transitions downward are automatic and first-line-executable, terminating at the kill switch.
  3. Every gate produces an artifact (validation report, approval minute, mandate document) filed where third line and the examiner can find it. An impact assessment in the style of ISO/IEC 42005 (webstore.iec.ch/en/publication/107659, T1: https://webstore.iec.ch/en/publication/107659) or the Canadian AIA's tiered scoring (canada.ca/en/government/system/digital-government/digital-government-innovations/responsible-use-ai/algorithmic-impact-assessment.html, T1, https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/responsible-use-ai/algorithmic-impact-assessment.html) is the natural gate-entry document.

2.6 Governance controls (GOV-01 – GOV-14)

GOV-01: Board-Approved AI & Autonomy Governance Charter

Objective. Establish board-level accountability for AI use, including an explicit, written risk appetite for agent autonomy.

Control. The board (or a designated committee with charter authority) approves an AI governance charter that names the accountable executive, defines the maximum permissible autonomy tier per business activity, and mandates periodic reporting on AIMS performance, agent inventory coverage, and incidents. No agent may be deployed under an activity with no board-approved autonomy ceiling.

Implementation (financial enterprise). Amend the enterprise risk appetite statement with an autonomy schedule (Section 2.5 table as template); assign a Chief AI Risk Officer or equivalent; add AI/agent items to the risk committee's standing agenda with quarterly cadence; align committee structure per board-governance roadmaps (Deloitte).

Maturity. Baseline: charter + named executive + annual reporting → Enhanced: autonomy schedule per business line, quarterly evidence-based reporting → Frontier: board dashboard fed directly from the agent inventory and gate records, with appetite breaches auto-escalated.

Ownership. 1st line: operates within the appetite. 2nd line: drafts the appetite schedule, monitors adherence. 3rd line: audits whether reporting to the board reflects the system of record.

Evidence. Charter and committee minutes; risk appetite statement with autonomy schedule; board reporting packs traceable to inventory records.

Mappings. NIST AI RMF GOVERN; ISO/IEC 42001 AIMS (leadership clause, secondary-sourced structure); EU AI Act, ; SR 11-7/OCC 2011-12 board & senior management oversight of MRM framework; DORA [practice guidance: not directly source-backed] ICT risk governance analog.

Sources. gao.gov/products/gao-21-519sp (T1): https://www.gao.gov/products/gao-21-519sp; deloitte.com/us/en/programs/center-for-board-effectiveness/articles/board-of-directors-governance-framework-artificial-intelligence.html (T3), https://www.deloitte.com/us/en/programs/center-for-board-effectiveness/articles/board-of-directors-governance-framework-artificial-intelligence.html; federalreserve.gov/supervisionreg/srletters/sr1107.htm (T1), https://www.federalreserve.gov/supervisionreg/srletters/sr1107.htm

GOV-02: Enterprise AI Management System (AIMS)

Objective. Operate a single, certifiable management system governing the responsible development, provision, and use of AI systems, including agents.

Control. An AIMS conforming to ISO/IEC 42001 is established, implemented, maintained, and continually improved, with agentic systems explicitly in scope, and is integrated with (not parallel to) the enterprise risk and information-security management systems.

Implementation (financial enterprise). Scope the AIMS to cover all agent deployments; use the NIST AI RMF ↔ 42001 crosswalk to evidence both frameworks from one control set; reuse 27001-style audit machinery; close the documented agent-fleet gaps (registration, expiry, per-identity audit trails, privilege-creep reviews) as AIMS controls rather than side procedures.

Maturity. Baseline: documented AIMS, self-assessed → Enhanced: internal audit against 42001; agent-fleet delta controls operating → Frontier: third-party certification with agent deployments inside the certified scope.

Ownership. 1st line: executes AIMS operational controls. 2nd line: owns AIMS design, policy, and performance evaluation. 3rd line: internal audit of the AIMS itself.

Evidence. AIMS scope statement naming agentic systems; management-review minutes; internal-audit reports; certification records where pursued.

Mappings. NIST AI RMF GOVERN/MAP/MEASURE/MANAGE via crosswalk; ISO/IEC 42001 AIMS (Clauses 4–10, secondary-sourced structure); EU AI Act, ; SR 11-7/OCC 2011-12 MRM framework as embedded subsystem; DORA, .

Sources. iso.org/standard/42001 (T1), https://www.iso.org/standard/42001; iso.org/standard/81230.html (T1), https://www.iso.org/standard/81230.html; airc.nist.gov/docs/nist_ai_rmf_to_iso_iec_42001_crosswalk.pdf (T2), https://airc.nist.gov/docs/NIST_AI_RMF_to_ISO_IEC_42001_Crosswalk.pdf; helpnetsecurity.com/2026/06/12/nist-iso-frameworks-govern-ai-agents (T3), https://www.helpnetsecurity.com/2026/06/12/nist-iso-frameworks-govern-ai-agents/

GOV-03: Agent Inventory & Registration

Objective. Ensure every agent operating in or for the institution is known, uniquely identified, and lifecycle-managed.

Control. No agent executes in production without prior registration in an authoritative inventory recording: unique identity, owner, intent/mandate, model version, toolset and permissions, data access, autonomy tier, deployment date, and expiry/review date. Temporary agents expire automatically. Control of record: GOV-03 (with GOV-04 for ownership) is the control of record for agent inventory and registration; DES-07 enforces it at design time on the IAM stack, and MAS-01 extends it with delegation-topology registration.

Implementation (financial enterprise). Extend the SR 11-7-style model inventory rather than building a rival register; the inventory unit is the deployed agent configuration (model + prompt + tools + permissions + tier); enforce registration technically at the identity layer: unregistered identities receive no credentials; run recurring privilege-creep assessments against inventory entries.

Maturity. Baseline: manual register, quarterly attestation → Enhanced: registration enforced at credential issuance; auto-expiry live → Frontier: inventory reconciled continuously against observed runtime identities; drift alarms.

Ownership. 1st line: registers and maintains entries. 2nd line: sets inventory standards, samples completeness. 3rd line: periodically reconciles inventory to production reality.

Evidence. Inventory extract with required fields; credential-issuance logs keyed to registrations; expiry and privilege-review records; reconciliation reports.

Mappings. NIST AI RMF MAP/GOVERN; ISO/IEC 42001 AIMS (agent-fleet delta per corpus analysis); EU AI Act, ; SR 11-7/OCC 2011-12 model inventory; DORA [practice guidance: not directly source-backed] ICT asset register analog.

Sources. helpnetsecurity.com/2026/06/12/nist-iso-frameworks-govern-ai-agents (T3), https://www.helpnetsecurity.com/2026/06/12/nist-iso-frameworks-govern-ai-agents/; federalreserve.gov/supervisionreg/srletters/sr1107.htm (T1), https://www.federalreserve.gov/supervisionreg/srletters/sr1107.htm; iso.org/standard/42001 (T1): https://www.iso.org/standard/42001

GOV-04: Named Accountable Owner per Agent

Objective. Guarantee that accountability for every agent's conduct rests with an identified human role at all times.

Control. Every registered agent has "a defined owner, a clear intent, a bounded scope of access, and an explicit lifecycle" (helpnetsecurity.com, quoted). Ownership transfers are recorded; an agent whose owner leaves the role without transfer is automatically suspended to AT-0. Accountability may never be attributed to the agent itself.

Implementation (financial enterprise). Owner must be a named role of sufficient seniority in the business (not in the AI platform team) for business-facing agents; wire owner assignment into HR leaver/mover processes exactly as for high-privilege system accounts; owner responsibilities enumerated by role in a responsibilities framework, following the DHS by-role pattern.

Maturity. Baseline: owner field populated in inventory → Enhanced: auto-suspension on ownerless state; owner attestation cycle → Frontier: owner console showing the agent's live mandate, actions, and gate history.

Ownership. 1st line: owners themselves. 2nd line: verifies owner seniority and coverage. 3rd line: tests the auto-suspension path.

Evidence. Inventory owner fields; transfer and suspension logs; owner attestation records.

Mappings. NIST AI RMF GOVERN; ISO/IEC 42001 AIMS (roles & responsibilities, leadership clause, secondary-sourced); EU AI Act, ; SR 11-7/OCC 2011-12 clear roles/responsibilities within MRM; DORA, .

Sources. helpnetsecurity.com/2026/06/12/nist-iso-frameworks-govern-ai-agents (T3), https://www.helpnetsecurity.com/2026/06/12/nist-iso-frameworks-govern-ai-agents/; dhs.gov/sites/default/files/2024-11/24_1114_dhs_ai-roles-and-responsibilities-framework-508.pdf (T1), https://www.dhs.gov/sites/default/files/2024-11/24_1114_dhs_ai-roles-and-responsibilities-framework-508.pdf; proceedings.mlr.press/v235/dai24a.html (T2): https://proceedings.mlr.press/v235/dai24a.html

GOV-05: Agentic Systems Within Model Risk Management Scope

Objective. Subject agentic systems to the institution's model risk management framework with agent-specific scope definitions.

Control. The MRM policy explicitly defines agentic systems as in scope; the risk object is the deployed agent configuration (model version + prompts + tools + permissions + memory + autonomy tier); any change to that configuration is a model change triggering change-control and, where material, revalidation and tier reset.

Implementation (financial enterprise). Update the MRM policy under the revised supervisory guidance (SR 26-2 / OCC 2026-13); tier agent risk ratings on autonomy, permission breadth, and data sensitivity; apply the BSA/AML interagency precedent for extending MRM to operational, workflow-embedded systems; require upstream model-version changes from vendors to enter the same change-control gate.

Maturity. Baseline: agents entered in MRM inventory with risk ratings → Enhanced: configuration-hash-based change detection triggers review automatically → Frontier: continuous conformance between validated configuration and running configuration, with drift blocking.

Ownership. 1st line: declares and documents configurations and changes. 2nd line: owns MRM policy, risk-rates agents, adjudicates materiality. 3rd line: audits scope completeness and change-control adherence.

Evidence. MRM policy sections; agent risk-rating records; change-control tickets keyed to configuration hashes; revalidation reports.

Mappings. NIST AI RMF MAP/MANAGE; ISO/IEC 42001 AIMS (operation clause, secondary-sourced); EU AI Act Art. 11/Annex IV documentation linkage; SR 11-7/OCC 2011-12 & SR 26-2/OCC 2026-13 scope, inventory, change control; DORA, .

Sources. federalreserve.gov/supervisionreg/srletters/sr1107.htm (T1), https://www.federalreserve.gov/supervisionreg/srletters/sr1107.htm; federalreserve.gov/supervisionreg/srletters/sr2602.htm (T1), https://www.federalreserve.gov/supervisionreg/srletters/SR2602.htm; occ.gov/news-issuances/bulletins/2026/bulletin-2026-13.html (T1), https://www.occ.gov/news-issuances/bulletins/2026/bulletin-2026-13.html; federalreserve.gov/supervisionreg/srletters/sr2108.htm (T1), https://www.federalreserve.gov/supervisionreg/srletters/SR2108.htm

GOV-06: Independent Validation & Effective Challenge for Agents

Objective. Ensure every agent deployment above AT-0 has been independently validated with challenge proportionate to its autonomy and action surface.

Control. Independent validation (organizationally separate from development) covers output quality and behavioral properties: scope adherence under adversarial input, safe degradation, tool-use correctness, and monitorability. Validation follows a risk-based testing approach in the manner of ISO/IEC TS 42119-2, and treats the agent as a potential insider threat whose controls must hold under misalignment. Validation sign-off is a precondition of every tier promotion gate.

Implementation (financial enterprise). House agent validation in the existing model validation function, upskilled with red-team capability; require suppliers to evidence risk-based testing per TS 42119-2 in due diligence; scope challenge scenarios to the enabled toolset and mandate, not generic benchmarks; record effective-challenge outcomes and management responses.

Maturity. Baseline: pre-deployment validation report per agent → Enhanced: adversarial/red-team scenarios standard; revalidation on configuration change → Frontier: continuous validation harness re-running challenge suites against production configurations.

Ownership. 1st line: remediates findings. 2nd line: performs validation and effective challenge. 3rd line: audits validator independence and coverage.

Evidence. Validation reports; challenge logs and findings registers; tier-gate minutes citing validation sign-off; supplier testing evidence.

Mappings. NIST AI RMF MEASURE; ISO/IEC 42001 AIMS (performance evaluation clause, secondary-sourced); EU AI Act Art. 11/Annex IV (testing documentation); SR 11-7/OCC 2011-12 independent validation & effective challenge; DORA, .

Sources. federalreserve.gov/supervisionreg/srletters/sr1107.htm (T1), https://www.federalreserve.gov/supervisionreg/srletters/sr1107.htm; iso.org/standard/84127.html (T1), https://www.iso.org/standard/84127.html; deepmind.google/blog/securing-the-future-of-ai-agents (T1): https://deepmind.google/blog/securing-the-future-of-ai-agents/

GOV-07: Autonomy Tier Framework in the Risk Appetite

Objective. Bound delegated agent authority by a formal, board-approved autonomy tier framework.

Control. A documented autonomy ladder (per Section 2.5) defines, for each tier: delegated authority, oversight mode, minimum standing controls, promotion gate, and automatic demotion triggers. Every production agent carries exactly one current tier recorded in the inventory; operating outside tier is a reportable incident. Control intensity scales with capability, consistent with capability-milestone escalation.

Implementation (financial enterprise). Publish the ladder as a schedule to the risk appetite statement (GOV-01); map each business use case to a maximum tier; encode tier as machine-readable policy consumed by the permissioning layer so tier limits are enforced, not merely documented.

Maturity. Baseline: ladder documented; tiers assigned manually → Enhanced: tier enforced technically at the tool/credential layer → Frontier: tier posture adjusts automatically to capability-evaluation results and monitoring health, within board-set ceilings.

Ownership. 1st line: operates agents at assigned tier. 2nd line: owns the ladder, adjudicates tier assignments. 3rd line: audits tier-enforcement efficacy.

Evidence. Risk appetite schedule; per-agent tier records; policy-as-code exports; out-of-tier incident reports.

Mappings. NIST AI RMF GOVERN/MANAGE; ISO/IEC 42001 AIMS (planning clause, secondary-sourced); EU AI Act, ; SR 11-7/OCC 2011-12 use restrictions & limitations of model use; DORA, .

Sources. deepmind.google/blog/securing-the-future-of-ai-agents (T1), https://deepmind.google/blog/securing-the-future-of-ai-agents/; helpnetsecurity.com/2026/06/12/nist-iso-frameworks-govern-ai-agents (T3), https://www.helpnetsecurity.com/2026/06/12/nist-iso-frameworks-govern-ai-agents/; gao.gov/products/gao-21-519sp (T1): https://www.gao.gov/products/gao-21-519sp

GOV-08: Autonomy Promotion & Demotion Gates

Objective. Make every change in an agent's delegated authority a controlled, evidenced decision: slow upward, instant downward.

Control. Tier promotion requires: current independent validation (GOV-06), a clean operating track record at the current tier against defined thresholds, an impact assessment (GOV-10), and approval by the designated committee against the risk appetite. Demotion triggers (mandate breach, monitoring degradation, unrevalidated upstream change, qualifying incident) execute automatically without committee action, terminating at kill switch.

Implementation (financial enterprise). Run gates through the model risk committee with quorum rules; define quantitative promotion thresholds per use case (error rates, escalation rates, monitor coverage/recall); implement demotion as a first-line runbook with technical enforcement (credential narrowing, tool removal, suspension); log every gate transit.

Maturity. Baseline: documented gate checklist, committee minutes → Enhanced: automated demotion triggers wired to monitoring → Frontier: gate evidence packs generated automatically from the systems of record at request time.

Ownership. 1st line: executes demotions, prepares promotion evidence. 2nd line: chairs gates, owns thresholds. 3rd line: audits gate integrity and searches for bypasses.

Evidence. Gate minutes and evidence packs; demotion trigger logs; threshold definitions; kill-switch test records.

Mappings. NIST AI RMF MANAGE; ISO/IEC 42001 AIMS (improvement clause, secondary-sourced); EU AI Act, ; SR 11-7/OCC 2011-12 model approval & ongoing monitoring; DORA, .

Sources. deepmind.google/blog/securing-the-future-of-ai-agents (T1), https://deepmind.google/blog/securing-the-future-of-ai-agents/; federalreserve.gov/supervisionreg/srletters/sr1107.htm (T1), https://www.federalreserve.gov/supervisionreg/srletters/sr1107.htm; canada.ca/en/government/system/digital-government/digital-government-innovations/responsible-use-ai/algorithmic-impact-assessment.html (T1): https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/responsible-use-ai/algorithmic-impact-assessment.html

GOV-09: Three-Lines Responsibility Assignment for Agentic AI

Objective. Assign every agentic-AI control in the catalog to an accountable line of defense with no orphaned controls.

Control. A maintained responsibility matrix maps each control (GOV/DES/EVL/RUN/MON/MAS/TPR/ASR/FCO) to first-line ownership, second-line standard-setting and challenge, and third-line assurance. Second line is organizationally independent of agent-building teams; third line selects its own evidence and does not rely on first-line-curated packs.

Implementation (financial enterprise). Extend the existing MRM three-lines assignment rather than drafting anew; publish the matrix in the AIMS; review at each reorganization; expose second-line performance metrics (validation backlog, challenge findings aging) to the risk committee.

Maturity. Baseline: matrix exists and is current → Enhanced: line-2 challenge metrics reported quarterly → Frontier: control-health telemetry per line feeding the board dashboard (GOV-01).

Ownership. 1st line: accepts and operates assigned controls. 2nd line: maintains the matrix, challenges. 3rd line: assures the matrix reflects reality.

Evidence. Responsibility matrix with version history; independence attestations; challenge and audit findings registers.

Mappings. NIST AI RMF GOVERN; ISO/IEC 42001 AIMS (support/roles, secondary-sourced); EU AI Act, ; SR 11-7/OCC 2011-12 governance, policies, and controls; DORA, .

Sources. practice guidance; no specific source cited (T3): corpus canon index entry, no public URL; gao.gov/products/gao-21-519sp (T1), https://www.gao.gov/products/gao-21-519sp; occ.gov/news-issuances/bulletins/2011/bulletin-2011-12.html (T1), https://www.occ.gov/news-issuances/bulletins/2011/bulletin-2011-12.html

GOV-10: AI Impact Assessment Before Deployment and Promotion

Objective. Ensure the impacts of an agent deployment on customers, the institution, and third parties are assessed and documented before authority is granted or increased.

Control. A documented AI system impact assessment, following ISO/IEC 42005 or an equivalent structured instrument such as the Canadian Algorithmic Impact Assessment, is completed and approved before initial deployment and at every tier-promotion gate, and is refreshed on material configuration change. Control of record: GOV-10 is the requirement-of-record for the AI impact assessment; DES-05 executes it at design time with agent-specific extensions, and ASR-02 assures that it operates.

Implementation (financial enterprise). Use a tiered scoring instrument (the Canadian AIA pattern) so assessment depth scales with risk; integrate with existing compliance assessments (fair lending, privacy, conduct) to avoid duplicate questionnaires; store assessments in the same evidence repository as validation reports so gates draw one file.

Maturity. Baseline: assessment template mandated, manually tracked → Enhanced: assessment completion technically blocks gate transit → Frontier: living assessments updated from monitoring data, not just at gates.

Ownership. 1st line: completes assessments. 2nd line: sets the instrument, quality-assures, approves. 3rd line: audits coverage and rigor.

Evidence. Completed assessments with approvals; gate records referencing them; refresh logs tied to configuration changes.

Mappings. NIST AI RMF MAP; ISO/IEC 42001 AIMS (planning: AI impact assessment, secondary-sourced structure); EU AI Act Art. 11/Annex IV adjacency for documentation; SR 11-7/OCC 2011-12 model development documentation; DORA, .

Sources. webstore.iec.ch/en/publication/107659 (T1): https://webstore.iec.ch/en/publication/107659; canada.ca/en/government/system/digital-government/digital-government-innovations/responsible-use-ai/algorithmic-impact-assessment.html (T1), https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/responsible-use-ai/algorithmic-impact-assessment.html; iso.org/standard/42001 (T1), https://www.iso.org/standard/42001

GOV-11: Governance Records & Regulator-Ready Documentation

Objective. Maintain complete, tamper-evident, retrievable records of agent governance sufficient for internal audit and external examination.

Control. Agent governance artifacts (inventory entries, mandates, assessments, validation reports, gate minutes, action-log attestations) are managed as records under a records-management system (ISO 30301 discipline), with retention meeting supervisory expectations; for EU high-risk deployments, technical documentation satisfies EU AI Act Article 11 / Annex IV and is generated from the same evidence base as SR 11-7-style model documentation. Record-keeping design is periodically reviewed for oversight capture, i.e., whether the records answer overseers' questions or only the operator's.

Implementation (financial enterprise). Single evidence repository with immutability controls; map each artifact type to Annex IV headings and to MRM documentation standards once, then render regulator-specific views; include the "accountability capture" review in third-line audit scope so documentation scope is not solely author-defined.

Maturity. Baseline: central repository, defined retention → Enhanced: tamper-evidence and completeness monitoring → Frontier: examiner-ready packs assembled on demand from source systems with provenance.

Ownership. 1st line: produces and files records. 2nd line: defines record standards and Annex IV/MRM mapping. 3rd line: tests completeness, immutability, and capture risk.

Evidence. Records inventory and retention schedule; Annex IV-mapped technical files; audit tests of tamper-evidence; capture-review findings.

Mappings. NIST AI RMF GOVERN/MAP; ISO/IEC 42001 AIMS (documented information, secondary-sourced); EU AI Act Art. 11/Annex IV; SR 11-7/OCC 2011-12 documentation standards; DORA, .

Sources. artificialintelligenceact.eu/article/11 (T1), https://artificialintelligenceact.eu/article/11/; iso.org/standard/74292.html (T2), https://www.iso.org/standard/74292.html; ojs.aaai.org/index.php/aies/article/view/36570 (T2), https://ojs.aaai.org/index.php/AIES/article/view/36570; federalreserve.gov/supervisionreg/srletters/sr1107.htm (T1), https://www.federalreserve.gov/supervisionreg/srletters/sr1107.htm

GOV-12: Data Quality Management Accountability for Agent-Consumed Data

Objective. Assign management-system accountability for the quality of data agents consume, retrieve, and write, including agent memory.

Control. Data used by agents (training/tuning data where applicable, retrieval corpora, tool-returned data, persistent agent memory) falls under a data quality management regime consistent with ISO/IEC 5259-3 requirements, with named data owners, quality criteria, and remediation paths; agent memory stores are treated as governed data assets with review and purge procedures.

Implementation (financial enterprise). Extend existing BCBS-style data governance ownership to agent retrieval corpora and memory [practice guidance: not directly source-backed for the BCBS analog]; require data-quality sign-off as an input to validation (GOV-06); log provenance of data entering agent context where feasible.

Maturity. Baseline: data owners named for agent corpora → Enhanced: quality metrics monitored; memory review/purge operating → Frontier: provenance tracking of context inputs with quarantine of untrusted sources.

Ownership. 1st line: data owners and agent operators. 2nd line: data-quality standards and oversight. 3rd line: audits ownership coverage and control operation.

Evidence. Data ownership register; quality metric reports; memory review/purge logs; validation inputs citing data sign-off.

Mappings. NIST AI RMF MAP/MEASURE; ISO/IEC 42001 AIMS (data-for-AI control domain, secondary-sourced Annex A structure); EU AI Act, ; SR 11-7/OCC 2011-12 data quality within model development; DORA, .

Sources. iso.org/standard/81092.html (T1), https://www.iso.org/standard/81092.html; iso.org/standard/42001 (T1), https://www.iso.org/standard/42001; helpnetsecurity.com/2026/06/12/nist-iso-frameworks-govern-ai-agents (T3): https://www.helpnetsecurity.com/2026/06/12/nist-iso-frameworks-govern-ai-agents/

GOV-13: Evidentiary Standards for Oversight & Monitoring Claims

Objective. Prevent unproven oversight technology from being booked as effective control coverage in the governance framework.

Control. No monitoring or oversight mechanism (internal-state probes, "pre-action intent detection," supervisor models, vendor guardrails) may be recorded as a mitigating control in risk assessments or tier gates unless its efficacy claims have survived scenario/action generalization and concept-specificity testing, with measured coverage, recall, and response-time performance. Unproven mechanisms may operate, but at zero credited risk reduction.

Implementation (financial enterprise). Second line maintains an approved-monitor register with test evidence per mechanism; procurement language requires vendors to demonstrate the generalization/specificity checks; monitor performance metrics are re-measured on model or configuration change; white-box methods are credited for offline audit use, not runtime approval paths, until proven otherwise.

Maturity. Baseline: monitor register with pass/fail status → Enhanced: standing red-team refresh of monitor efficacy → Frontier: continuous monitor-performance telemetry with automatic de-crediting on degradation.

Ownership. 1st line: operates monitors, reports telemetry. 2nd line: adjudicates crediting, owns the register. 3rd line: audits that credited controls carry current evidence.

Evidence. Approved-monitor register; generalization/specificity test reports; coverage/recall/response-time dashboards; de-crediting decisions.

Mappings. NIST AI RMF MEASURE; ISO/IEC 42001 AIMS (performance evaluation, secondary-sourced); EU AI Act, ; SR 11-7/OCC 2011-12 effective challenge applied to compensating controls; DORA, .

Sources. arxiv.org/abs/2606.30449 (T2), https://arxiv.org/abs/2606.30449; deepmind.google/blog/securing-the-future-of-ai-agents (T1), https://deepmind.google/blog/securing-the-future-of-ai-agents/; iso.org/standard/84127.html (T1): https://www.iso.org/standard/84127.html

GOV-14: AI Ethics & Escalation Body with Anti-Decoy Safeguards

Objective. Provide a standing, empowered body for ethical review and escalation of agent deployments, designed so it constrains decisions rather than decorating them.

Control. A chartered AI ethics/review board (or equivalent committee mandate) reviews high-impact and novel agent use cases pre-deployment, holds veto or escalation authority documented in the gate process, and reports outcomes to the board committee (GOV-01). Its design is periodically evaluated against decoy-accountability failure modes: it must have decision rights, independent information access, and a public record of decisions internally; where warranted for the highest-risk evaluations, external or public-body evaluation is engaged rather than relying solely on internal review.

Implementation (financial enterprise). Model the body on documented corporate practice (e.g., IBM's AI Ethics Board) adapted to financial-services committee governance; give it a lane in the tier-gate workflow for designated use-case classes (credit, conduct-sensitive, customer-facing autonomy); track its decisions and overrides; commission periodic independent review of whether its interventions changed outcomes.

Maturity. Baseline: chartered body meeting on cadence with minutes → Enhanced: veto authority exercised and tracked in gates → Frontier: effectiveness reviews with external evaluation for the highest-risk classes.

Ownership. 1st line: submits use cases with complete information. 2nd line: staffs/secretariats the body, integrates decisions into gates. 3rd line: audits its independence and effectiveness (anti-decoy review).

Evidence. Charter; case log with decisions and vetoes; gate records showing enforced outcomes; effectiveness/anti-decoy review reports.

Mappings. NIST AI RMF GOVERN; ISO/IEC 42001 AIMS (leadership & internal organization, secondary-sourced); EU AI Act, ; SR 11-7/OCC 2011-12 governance framework; DORA, .

Sources. ibm.com/impact/ai-ethics (T1), https://www.ibm.com/impact/ai-ethics; doi.org/10.1145/3805689.3806739 (T2), https://doi.org/10.1145/3805689.3806739; ojs.aaai.org/index.php/aies/article/view/31733 (T2): https://ojs.aaai.org/index.php/AIES/article/view/31733; practice guidance; no specific source cited (T3), corpus canon index entry, no public URL

2.7 What Part II hands to the rest of the Compendium

Part II establishes who decides and who answers. Design-time controls (Part III.A) inherit the impact-assessment and data-accountability hooks (GOV-10, GOV-12); pre-deployment evaluation (Part III.B) operationalizes GOV-06 and GOV-13; runtime controls (Part III.C) implement the standing controls each autonomy tier requires (GOV-07, GOV-08); the assurance stack (Part IV) audits it all through GOV-09. A control elsewhere in this Compendium with no governance anchor here is a defect. Report it to the second line, which this Part has just made someone accountable for staffing.