Skip to contentThe Observability LayerSearch

Flagship compendium · Section 3 of 24

Reading Map

Evidence table: Part, What it answers, Who reads it first
PartWhat it answersWho reads it first
Part I: FoundationsWhat is categorically new about agentic AI; the AR-1…AR-16 risk taxonomy; the threat model for a financial institutionCRO, CAIRO, board risk committee
Part II: Governance & Accountability (GOV-01–14)Who decides and who answers: board duties, AIMS, MRM extension, three lines, the autonomy ladder and its gatesHead of model risk, CRO, second line
Part III.A: Design-Time Controls (DES-01–14)How to build agents so bad outcomes are structurally difficult: data governance, impact assessment, least privilege, supply chain, memory architectureEngineering lead, security architecture
Part III.B: Pre-Deployment Evaluation (EVL-01–16)What testing proves, what it cannot, and how to make evaluation results decision-grade, including validity, sandbagging, and the go/no-go gateHead of validation, eval team
Part III.C: Runtime Controls (RUN-01–18)What stands between the agent and the ledger while it acts: oversight modes, AI-control protocols, sandboxing, kill switches, hard limits, tool gatingEngineering/platform lead, first line
Part III.D: Monitoring & Post-Deployment (MON-01–12)How to see what agents actually do, detect drift and incidents, and meet external reporting clocksOperations, SOC, compliance
Part III.E/F: Multi-Agent & Third-Party (MAS-01–10, TPR-01–08)What changes when agents interact and when the model belongs to a vendor: identity, delegation, collusion, concentration, upstream changePlatform lead, TPRM, model risk
Part IV: Assurance, Audit & Certification (ASR-01–10)How to prove the controls exist and operate: internal audit, the 42001/42006 certification chain, vendor safety frameworks, transparency artifactsInternal audit, second line
Part V: Regulatory MappingWhich binding obligations attach, per regime, and which control families discharge them: one master tableCompliance, legal, CRO
Part VI: Fairness & Customer Outcomes (FCO-01–10)How agentic flows acquire discrimination and how to prevent, detect, explain, and remediate it in covered decisionsFair-lending compliance, model risk
Part VII: Implementation PlaybookWhere to start and in what order: maturity model M1–M4, RACI, 90-day plan, year-one roadmap, board pack, the ten controls to build firstProgram lead, CRO, everyone once
Appendices A–EMaster control index; crosswalk matrices; glossary; bibliography; incident severity & reporting matrixReference: all readers