Module · AI Controls Library

    The market has AI policies. It does not have AI controls.

    A policy states an intention. A control has an objective, a statement, a test procedure, an evidence artefact and a jurisdiction it answers to. This library is written once and mapped many times — the same control satisfies the EU AI Act, SR 11-7 and JFSA, with the delta each supervisor adds recorded rather than rediscovered.

    164
    AI controls
    9
    Control domains
    10
    Jurisdiction sets
    3
    Test methods

    Domain

    Jurisdiction

    AIG-01

    A named executive is accountable for every AI system in production.

    Each AI system carries a single named accountable executive, recorded in the inventory, with the accountability reviewed whenever ownership or materiality changes.

    Method
    Examine · Interview

    Evidence
    AI system inventory extract showing accountable owner, with board or committee minute approving the allocation.

    Jurisdiction delta

    • European UnionArticle 26 deployer obligations require assigned human oversight with competence and authority evidenced.
    • United KingdomSMCR requires the accountability be traceable to a Senior Manager Function with a Statement of Responsibilities.
    • United States — prudentialSR 11-7 requires model ownership distinct from independent validation ownership.
    • CanadaE-23 requires the accountable party be documented in the enterprise model risk framework.
    • JapanJFSA expects accountability documented in Japanese for the parent board, even where the system is deployed offshore.
    • International standardsISO/IEC 42001 Clause 5.3 — roles, responsibilities and authorities within the AI management system.

    AI Governance & Accountability

    AIG-04

    Every AI system is risk-classified per jurisdiction, not once globally.

    AI systems are classified against each applicable jurisdictional risk taxonomy, and the highest applicable classification drives the control set applied.

    Method
    Examine · Test

    Evidence
    Per-system classification record with jurisdiction, classification, rationale and reviewer.

    Jurisdiction delta

    • European UnionAnnex III high-risk determination with prohibited-practice screen under Article 5.
    • United States — marketsNo statutory taxonomy — classification is driven by investor-impact and supervisory-examination exposure.
    • SingaporeMAS FEAT materiality assessment across fairness, ethics, accountability and transparency.
    • CanadaE-23 risk rating drives validation depth and frequency.
    • Gulf sovereignNational AI charter classification where the system touches citizen services or sovereign data.

    AI Governance & Accountability

    AIG-09

    Human oversight is a recorded point in the decision path, not a stated intention.

    For every material AI-influenced decision, the system records who could override, whether an override was available at the time, and whether one occurred.

    Method
    Examine · Test

    Evidence
    Decision log sample showing oversight point, reviewer identity and override disposition.

    Jurisdiction delta

    • European UnionArticle 14 requires oversight measures be built into the system design, not applied procedurally afterwards.
    • United KingdomFCA Consumer Duty requires oversight adequate to evidence good customer outcomes.
    • United States — prudentialEffective challenge must be demonstrable, with evidence the challenger could have changed the outcome.
    • JapanMETI guidelines expect oversight capability proportionate to societal impact.

    AI Governance & Accountability

    MDL-02

    No model reaches production without independent validation.

    Validation is performed by a party independent of development, covers conceptual soundness, outcomes analysis and ongoing monitoring design, and is signed before deployment.

    Method
    Examine · Interview · Test

    Evidence
    Validation report with independence attestation and pre-deployment sign-off date preceding the release record.

    Jurisdiction delta

    • United States — prudentialSR 11-7 core requirement; validation scope and independence are examined directly.
    • CanadaE-23 requires validation depth to scale with the assigned risk rating.
    • European UnionArticle 17 quality management system evidences equivalent pre-market conformity.
    • United KingdomSS1/23 requires the validation function have sufficient standing to challenge.
    • International standardsISO/IEC 42001 Clause 8 operational planning and control.

    Model Lifecycle

    MDL-07

    Drift is detected before it becomes a supervisory finding.

    Performance, population and concept drift are monitored on a defined cadence against pre-set thresholds, with breach triggering revalidation rather than a note.

    Method
    Examine · Test

    Evidence
    Drift monitoring output with threshold definitions and a worked example of a breach-triggered revalidation.

    Jurisdiction delta

    • United States — prudentialOngoing monitoring is an explicit SR 11-7 pillar alongside validation.
    • European UnionArticle 72 post-market monitoring plan for high-risk systems.
    • SingaporeMAS expects monitoring proportionate to the FEAT materiality assessment.
    • CanadaE-23 requires monitoring results feed the model risk report to senior management.

    Model Lifecycle

    MDL-11

    Retirement is as controlled as deployment.

    Model decommissioning follows a defined path covering dependency discovery, evidence retention, downstream notification and inventory closure.

    Method
    Examine

    Evidence
    Decommission record with dependency map and retention schedule reference.

    Jurisdiction delta

    • European UnionArticle 18 requires documentation retained for ten years after placing on the market.
    • United States — marketsBooks-and-records retention applies where the model informed a recommendation.
    • JapanAPPI retention and deletion obligations apply to the training and inference data held.

    Model Lifecycle

    DAT-03

    Training and inference data lineage is reconstructable.

    Each dataset used for training, fine-tuning or retrieval carries a provenance record covering source, licence, consent basis, transformation history and residency.

    Method
    Examine · Test

    Evidence
    Dataset provenance record traced end to end for a sampled model version.

    Jurisdiction delta

    • European UnionArticle 10 data governance for high-risk systems; GDPR Article 6 lawful basis alongside.
    • JapanAPPI requires purpose-of-use disclosure and consent handling for personal data at source.
    • New York StatePart 500 requires the data inventory extend to non-public information used in AI systems.
    • Gulf sovereignResidency constraints may prohibit training data leaving the jurisdiction entirely.
    • International standardsISO/IEC 23894 data quality and representativeness guidance.

    Data & Provenance

    DAT-08

    Cross-border AI processing is mapped and lawful.

    Every cross-border transfer arising from model training, hosting or inference is mapped to a transfer mechanism, with the mechanism re-tested when the hosting region changes.

    Method
    Examine · Interview

    Evidence
    Transfer register with mechanism, region and last review date per data flow.

    Jurisdiction delta

    • European UnionChapter V transfer mechanism required; model hosting region is a transfer trigger.
    • JapanAPPI Article 28 third-country transfer disclosure to the data subject.
    • CanadaOSFI B-10 expects the transfer be reflected in the third-party risk assessment.
    • Gulf sovereignSovereign residency may require in-country inference with no egress.

    Data & Provenance

    AGT-01

    Agent authority is bounded and enumerable.

    Each autonomous or semi-autonomous agent has a declared authority envelope listing the systems it may reach, the actions it may take and the value or volume ceilings that stop it.

    Method
    Examine · Test

    Evidence
    Agent registry entry with authority envelope and a test showing an out-of-envelope action refused.

    Jurisdiction delta

    • European UnionArticle 14 oversight must remain effective where the system operates autonomously.
    • United States — marketsSupervisory obligations under FINRA 3110 extend to activity initiated by an agent.
    • United KingdomSMCR accountability is not discharged by delegating the action to an agent.
    • United States — prudentialAgent actions constitute model output for SR 11-7 purposes where they influence decisions.

    Agentic Systems

    AGT-05

    Every agent action is attributable and reversible where material.

    Agent actions write an immutable log entry carrying the initiating principal, the authority basis, the tool invoked and the reversal path where the action is materially consequential.

    Method
    Examine · Test

    Evidence
    Immutable log sample with reversal executed against a test transaction.

    Jurisdiction delta

    • United States — marketsBooks-and-records treatment applies to agent-initiated communications and orders.
    • European UnionArticle 12 automatic logging over the lifetime of the high-risk system.
    • SingaporeMAS expects auditability sufficient for a supervisor to reconstruct the decision.

    Agentic Systems

    AGT-09

    Agent-to-agent chains do not launder accountability.

    Where one agent invokes another, the accountability chain is preserved end to end and the weakest authority in the chain governs the action.

    Method
    Examine · Test

    Evidence
    Chain trace for a multi-agent workflow showing the effective authority applied.

    Jurisdiction delta

    • European UnionDeployer remains accountable regardless of the number of intermediating systems.
    • United KingdomSenior Manager accountability persists across delegated automated chains.
    • United States — prudentialChained models are in scope of the model inventory individually and as a system.

    Agentic Systems

    GEN-02

    System prompts are governed artefacts.

    System prompts, guardrail instructions and retrieval configurations are version-controlled, change-approved and tested as controls in their own right.

    Method
    Examine · Test

    Evidence
    Prompt version history with approval record and regression test results per version.

    Jurisdiction delta

    • European UnionForms part of the Article 17 quality management system for high-risk systems.
    • United States — prudentialPrompt changes constitute model change and trigger the change-management path.
    • SingaporeFEAT transparency expects the behavioural constraints be documented.

    GenAI & Prompt Controls

    GEN-06

    Output is constrained where it could constitute advice or a representation.

    Generated output that could be read as regulated advice, a price, a term or a commitment passes a constraint layer with a recorded disposition before reaching a customer.

    Method
    Examine · Test

    Evidence
    Constraint layer configuration plus sampled outputs with dispositions.

    Jurisdiction delta

    • United States — marketsCommunications with the public rules apply to generated content unchanged.
    • United KingdomConsumer Duty and financial promotion rules apply to the output, not the technology.
    • European UnionArticle 50 transparency where a person interacts with an AI system.
    • JapanJFSA expects suitability obligations survive automation of the interaction.

    GenAI & Prompt Controls

    CYB-21

    Adversarial exposure is tested, not assumed.

    Prompt injection, jailbreak, data-poisoning and model-extraction exposure are tested on a defined cadence and after material change, with findings tracked to closure.

    Method
    Test · Examine

    Evidence
    Red-team report with findings, severity, owner and closure evidence.

    Jurisdiction delta

    • New York StatePart 500 penetration testing and vulnerability management extend to AI-enabled systems.
    • European UnionArticle 15 accuracy, robustness and cybersecurity for high-risk systems; DORA TLPT where applicable.
    • United KingdomOperational resilience testing expected to cover AI-dependent important business services.
    • Gulf sovereignSAMA cyber framework testing cadence applies to the AI stack as a technology asset.

    AI Cyber & Adversarial

    CYB-27

    Model and weight access is privileged access.

    Access to model weights, fine-tuning pipelines and vector stores is treated as privileged, recertified on cycle and monitored for anomalous retrieval volume.

    Method
    Examine · Test

    Evidence
    Access recertification record and anomaly alert sample for the model estate.

    Jurisdiction delta

    • New York StatePart 500.7 access privilege management, with 500.12 multifactor requirements.
    • European UnionDORA ICT access management for critical or important functions.
    • International standardsISO/IEC 42001 Annex A control on AI system resources.

    AI Cyber & Adversarial

    TPR-21

    Foundation-model providers are assessed as critical third parties.

    Model and API providers are risk-assessed, contractually bound on change notification and audit access, and assessed for substitutability before dependency deepens.

    Method
    Examine · Interview

    Evidence
    Provider assessment with contract clause map and substitutability rating.

    Jurisdiction delta

    • European UnionDORA critical ICT third-party provisions plus AI Act value-chain obligations under Article 25.
    • CanadaOSFI B-10 material arrangement treatment with concentration analysis.
    • United States — prudentialInteragency third-party guidance applies across the full relationship lifecycle.
    • United KingdomPRA critical third-party regime where the provider is designated.

    AI Third-Party & Supply Chain

    TPR-26

    Silent model change is detected.

    Provider-side model version changes are detected through fingerprinting or contractual notification, and trigger revalidation before continued reliance.

    Method
    Test · Examine

    Evidence
    Version-change detection log with the revalidation that followed.

    Jurisdiction delta

    • United States — prudentialAn undisclosed version change is a model change and reopens validation obligations.
    • European UnionArticle 25 obligations shift where substantial modification occurs.
    • SingaporeMAS expects reliance on external models be re-evidenced after change.

    AI Third-Party & Supply Chain

    RES-21

    AI dependency sits inside the impact tolerance, not beside it.

    Important business services that depend on AI carry an impact tolerance covering AI unavailability and degraded-quality output, with a tested manual or fallback path.

    Method
    Examine · Test

    Evidence
    Impact tolerance statement plus fallback test evidence with elapsed recovery time.

    Jurisdiction delta

    • European UnionDORA impact tolerance and scenario testing include ICT third-party AI dependencies.
    • United KingdomPRA/FCA operational resilience impact tolerances apply where the service is important.
    • CanadaOSFI E-21 operational resilience expectations extend to AI-dependent processes.
    • United States — marketsReg SCI availability standards apply where the system is SCI-covered.

    AI Resilience & Continuity

    RES-27

    Concentration on a single model provider is a board-visible position.

    Provider and model concentration is measured across the estate and reported to the board with the exit horizon for each material dependency.

    Method
    Examine

    Evidence
    Concentration report with exit horizon per provider and board minute.

    Jurisdiction delta

    • European UnionDORA concentration risk assessment for critical ICT providers.
    • CanadaB-10 concentration considerations at enterprise level.
    • United KingdomSectoral concentration is a supervisory question, not only a firm-level one.

    AI Resilience & Continuity

    DSC-02

    Disclosure obligations are met per jurisdiction, from one record.

    Customer, market and supervisory disclosure obligations arising from AI use are mapped per jurisdiction and satisfied from a single underlying evidence record.

    Method
    Examine

    Evidence
    Disclosure matrix per jurisdiction with the evidence artefact satisfying each entry.

    Jurisdiction delta

    • European UnionArticle 50 transparency to natural persons; Article 53 for general-purpose model providers.
    • United States — marketsDisclosure of material AI use and the associated risk factors in filings.
    • JapanDisclosure in Japanese to the parent board and, where applicable, to JFSA.
    • SingaporeFEAT transparency to affected customers on material AI-driven decisions.
    • United KingdomConsumer Duty communications standards apply to the disclosure itself.

    AI Disclosure & Evidence

    DSC-07

    The evidence set is supervisor-ready without a project.

    AI control evidence is continuously collected and assembled into a scoped, time-stamped pack that can be produced on request without a remediation exercise first.

    Method
    Examine · Test

    Evidence
    Generated evidence pack with scope, period and integrity hash.

    Jurisdiction delta

    • European UnionArticle 18 documentation and Article 19 automatically generated log retention.
    • United States — prudentialExamination readiness — evidence produced within the examiner's request window.
    • United States — marketsProduction must be complete and consistent with books-and-records obligations.
    • Gulf sovereignEvidence must be producible in-jurisdiction where residency constraints apply.

    AI Disclosure & Evidence

    DSC-11

    Incidents involving AI are reported on the correct clock.

    AI-related incidents are triaged against every applicable reporting clock simultaneously, with the shortest clock governing the notification path.

    Method
    Examine · Test

    Evidence
    Incident record with per-regime clock assessment and notification timestamps.

    Jurisdiction delta

    • European UnionAI Act serious incident reporting alongside DORA and NIS2 clocks.
    • New York StatePart 500.17 seventy-two-hour notification to the Superintendent.
    • United States — marketsItem 1.05 material cybersecurity incident disclosure within four business days.
    • JapanJFSA and PPC notification paths run in parallel with differing thresholds.
    • CanadaOSFI technology and cyber incident reporting within twenty-four hours.

    AI Disclosure & Evidence

    This is a published sample. Full test procedures, evidence specifications and the effectiveness rubric behind each control are institutional IP, released under engagement.

    Request the full AI control set