Skip to contentThe Observability LayerSearch

Responsible AI resource directory

Controls & methods

Find the control, method, or reference you need. Each entry opens the relevant section of its source report, with implementation detail and evidence intact.

112 controls14 methods4 referencesFull research reports →

130 resources · showing 20

Open a section in its source report
ControlGOV-01Governance & accountability

Board-Approved AI & Autonomy Governance Charter

Establish board-level accountability for AI use, including an explicit, written risk appetite for agent autonomy.

Evidence and ownership
Expected evidence
Charter and committee minutes; risk appetite statement with autonomy schedule; board reporting packs traceable to inventory records.
Ownership
1st line: operates within the appetite. 2nd line: drafts the appetite schedule, monitors adherence. 3rd line: audits whether reporting to the board reflects the system of record.

Implementation requirements, maturity levels, mappings, sources, and qualifications are retained in the full control.

ControlGOV-02Governance & accountability

Enterprise AI Management System (AIMS)

Operate a single, certifiable management system governing the responsible development, provision, and use of AI systems, including agents.

Evidence and ownership
Expected evidence
AIMS scope statement naming agentic systems; management-review minutes; internal-audit reports; certification records where pursued.
Ownership
1st line: executes AIMS operational controls. 2nd line: owns AIMS design, policy, and performance evaluation. 3rd line: internal audit of the AIMS itself.

Implementation requirements, maturity levels, mappings, sources, and qualifications are retained in the full control.

ControlGOV-03Governance & accountability

Agent Inventory & Registration

Ensure every agent operating in or for the institution is known, uniquely identified, and lifecycle-managed.

Evidence and ownership
Expected evidence
Inventory extract with required fields; credential-issuance logs keyed to registrations; expiry and privilege-review records; reconciliation reports.
Ownership
1st line: registers and maintains entries. 2nd line: sets inventory standards, samples completeness. 3rd line: periodically reconciles inventory to production reality.

Implementation requirements, maturity levels, mappings, sources, and qualifications are retained in the full control.

ControlGOV-04Governance & accountability

Named Accountable Owner per Agent

Guarantee that accountability for every agent's conduct rests with an identified human role at all times.

Evidence and ownership
Expected evidence
Inventory owner fields; transfer and suspension logs; owner attestation records.
Ownership
1st line: owners themselves. 2nd line: verifies owner seniority and coverage. 3rd line: tests the auto-suspension path.

Implementation requirements, maturity levels, mappings, sources, and qualifications are retained in the full control.

ControlGOV-05Governance & accountability

Agentic Systems Within Model Risk Management Scope

Subject agentic systems to the institution's model risk management framework with agent-specific scope definitions.

Evidence and ownership
Expected evidence
MRM policy sections; agent risk-rating records; change-control tickets keyed to configuration hashes; revalidation reports.
Ownership
1st line: declares and documents configurations and changes. 2nd line: owns MRM policy, risk-rates agents, adjudicates materiality. 3rd line: audits scope completeness and change-control adherence.

Implementation requirements, maturity levels, mappings, sources, and qualifications are retained in the full control.

ControlGOV-06Governance & accountability

Independent Validation & Effective Challenge for Agents

Ensure every agent deployment above AT-0 has been independently validated with challenge proportionate to its autonomy and action surface.

Evidence and ownership
Expected evidence
Validation reports; challenge logs and findings registers; tier-gate minutes citing validation sign-off; supplier testing evidence.
Ownership
1st line: remediates findings. 2nd line: performs validation and effective challenge. 3rd line: audits validator independence and coverage.

Implementation requirements, maturity levels, mappings, sources, and qualifications are retained in the full control.

ControlGOV-07Governance & accountability

Autonomy Tier Framework in the Risk Appetite

Bound delegated agent authority by a formal, board-approved autonomy tier framework.

Evidence and ownership
Expected evidence
Risk appetite schedule; per-agent tier records; policy-as-code exports; out-of-tier incident reports.
Ownership
1st line: operates agents at assigned tier. 2nd line: owns the ladder, adjudicates tier assignments. 3rd line: audits tier-enforcement efficacy.

Implementation requirements, maturity levels, mappings, sources, and qualifications are retained in the full control.

ControlGOV-08Governance & accountability

Autonomy Promotion & Demotion Gates

Make every change in an agent's delegated authority a controlled, evidenced decision: slow upward, instant downward.

Evidence and ownership
Expected evidence
Gate minutes and evidence packs; demotion trigger logs; threshold definitions; kill-switch test records.
Ownership
1st line: executes demotions, prepares promotion evidence. 2nd line: chairs gates, owns thresholds. 3rd line: audits gate integrity and searches for bypasses.

Implementation requirements, maturity levels, mappings, sources, and qualifications are retained in the full control.

ControlGOV-09Governance & accountability

Three-Lines Responsibility Assignment for Agentic AI

Assign every agentic-AI control in the catalog to an accountable line of defense with no orphaned controls.

Evidence and ownership
Expected evidence
Responsibility matrix with version history; independence attestations; challenge and audit findings registers.
Ownership
1st line: accepts and operates assigned controls. 2nd line: maintains the matrix, challenges. 3rd line: assures the matrix reflects reality.

Implementation requirements, maturity levels, mappings, sources, and qualifications are retained in the full control.

ControlGOV-10Governance & accountability

AI Impact Assessment Before Deployment and Promotion

Ensure the impacts of an agent deployment on customers, the institution, and third parties are assessed and documented before authority is granted or increased.

Evidence and ownership
Expected evidence
Completed assessments with approvals; gate records referencing them; refresh logs tied to configuration changes.
Ownership
1st line: completes assessments. 2nd line: sets the instrument, quality-assures, approves. 3rd line: audits coverage and rigor.

Implementation requirements, maturity levels, mappings, sources, and qualifications are retained in the full control.

ControlGOV-11Governance & accountability

Governance Records & Regulator-Ready Documentation

Maintain complete, tamper-evident, retrievable records of agent governance sufficient for internal audit and external examination.

Evidence and ownership
Expected evidence
Records inventory and retention schedule; Annex IV-mapped technical files; audit tests of tamper-evidence; capture-review findings.
Ownership
1st line: produces and files records. 2nd line: defines record standards and Annex IV/MRM mapping. 3rd line: tests completeness, immutability, and capture risk.

Implementation requirements, maturity levels, mappings, sources, and qualifications are retained in the full control.

ControlGOV-12Governance & accountability

Data Quality Management Accountability for Agent-Consumed Data

Assign management-system accountability for the quality of data agents consume, retrieve, and write, including agent memory.

Evidence and ownership
Expected evidence
Data ownership register; quality metric reports; memory review/purge logs; validation inputs citing data sign-off.
Ownership
1st line: data owners and agent operators. 2nd line: data-quality standards and oversight. 3rd line: audits ownership coverage and control operation.

Implementation requirements, maturity levels, mappings, sources, and qualifications are retained in the full control.

ControlGOV-13Governance & accountability

Evidentiary Standards for Oversight & Monitoring Claims

Prevent unproven oversight technology from being booked as effective control coverage in the governance framework.

Evidence and ownership
Expected evidence
Approved-monitor register; generalization/specificity test reports; coverage/recall/response-time dashboards; de-crediting decisions.
Ownership
1st line: operates monitors, reports telemetry. 2nd line: adjudicates crediting, owns the register. 3rd line: audits that credited controls carry current evidence.

Implementation requirements, maturity levels, mappings, sources, and qualifications are retained in the full control.

ControlGOV-14Governance & accountability

AI Ethics & Escalation Body with Anti-Decoy Safeguards

Provide a standing, empowered body for ethical review and escalation of agent deployments, designed so it constrains decisions rather than decorating them.

Evidence and ownership
Expected evidence
Charter; case log with decisions and vetoes; gate records showing enforced outcomes; effectiveness/anti-decoy review reports.
Ownership
1st line: submits use cases with complete information. 2nd line: staffs/secretariats the body, integrates decisions into gates. 3rd line: audits its independence and effectiveness (anti-decoy review).

Implementation requirements, maturity levels, mappings, sources, and qualifications are retained in the full control.

ControlDES-01Design & data

Agent Data Inventory and Governance Plan

Ensure every dataset that trains, fine-tunes, or is retrievable by an agent is inventoried, owned, and governed before the agent is built.

Evidence and ownership
Expected evidence
Data-lineage annex; owner attestations; licensing documentation; onboarding change tickets.
Ownership
1st line: product owner and data engineering maintain the inventory. 2nd line: model risk/data governance challenges completeness and fitness. 3rd line: audit tests inventory accuracy against deployed systems.

Implementation requirements, maturity levels, mappings, sources, and qualifications are retained in the full control.

ControlDES-02Design & data

Training-Data Provenance Instrumentation and Post-Hoc Auditability

Make it technically possible to answer, after the fact, "was this record (or this copyrighted/confidential source) in the training data?"

Evidence and ownership
Expected evidence
Provenance test reports in the validation package; pipeline lineage logs; vendor attestation letters.
Ownership
1st line: ML platform instruments pipelines. 2nd line: model validation runs and challenges provenance tests. 3rd line: audit samples provenance claims end-to-end.

Implementation requirements, maturity levels, mappings, sources, and qualifications are retained in the full control.

ControlDES-03Design & data

Poisoning-Resistant Data Acquisition

Prevent adversarial contamination of the data that shapes agent behavior, at both training and retrieval time.

Evidence and ownership
Expected evidence
Ingestion control specs; snapshot hashes; corpus diff logs; poisoning red-team reports.
Ownership
1st line: data engineering operates ingestion controls. 2nd line: information security and model risk set trust-tier policy. 3rd line: audit tests the pipeline against the threat model.

Implementation requirements, maturity levels, mappings, sources, and qualifications are retained in the full control.

ControlDES-04Design & data

Memorization and Training-Data Extraction Risk Controls

Prevent agents from leaking memorized training data (customer PII, MNPI, proprietary text) through outputs or tool calls.

Evidence and ownership
Expected evidence
Memorization risk assessments; extraction-probe results; data-minimization design records.
Ownership
1st line: ML engineering de-identifies and probes. 2nd line: privacy office and validation set thresholds. 3rd line: audit verifies sensitive-corpus handling end-to-end.

Implementation requirements, maturity levels, mappings, sources, and qualifications are retained in the full control.

ControlDES-05Design & data

AI System Impact Assessment as a Design Gate

Require a structured, documented impact assessment before any agentic system is approved for build or material change.

Evidence and ownership
Expected evidence
Completed assessment with disposition; change-triggered re-assessments; challenge records.
Ownership
1st line: product owner completes it. 2nd line: model risk/compliance challenges and dispositions. 3rd line: audit tests trigger discipline, did every material change re-open the assessment?

Implementation requirements, maturity levels, mappings, sources, and qualifications are retained in the full control.

ControlDES-06Design & data

Human-Rights and Customer-Impact Assessment for High-Stakes Agentic Scope

Apply a deeper, rights-focused assessment when an agent's action space touches customers' access to credit, insurance, funds, or redress.

Evidence and ownership
Expected evidence
Assessment reports; stakeholder-input records; remediation tracking.
Ownership
1st line: product/design teams run it. 2nd line: compliance/fair-lending owns methodology and challenge. 3rd line: audit reviews coverage of high-stakes agents.

Implementation requirements, maturity levels, mappings, sources, and qualifications are retained in the full control.