Board
D01Can the board evidence it understood the AI risk it accepted?
Evidence
Board minute with the AI risk appetite statement and the paper it was decided against.
AI Assurance · Readiness
Maturity models grade an institution against a consultancy's ladder. Supervisors do not use that ladder. These twelve dimensions are written in the language an examiner uses, each one answerable with an artefact rather than an assertion.
Can the board evidence it understood the AI risk it accepted?
Evidence
Board minute with the AI risk appetite statement and the paper it was decided against.
Can a supervisor be answered without a project being started?
Evidence
Standing regulator pack generated from the live evidence vault, not assembled on request.
Has internal audit tested the AI control set independently?
Evidence
Third-line audit report on AI controls with management response and closure evidence.
Are AI-specific attack paths in the cyber control set?
Evidence
Adversarial and prompt-injection test results mapped to the cyber control library.
Does an AI failure degrade a business service within tolerance?
Evidence
Impact tolerance test where the AI dependency is the failure mode.
Is the legal basis for every model and dataset documented?
Evidence
Licence, consent basis and transfer mechanism register per dataset and model.
Are AI outputs supervised where they touch a regulated activity?
Evidence
Supervision procedure covering AI-influenced recommendations and communications.
Is validation independent, current and consequential?
Evidence
Validation report with independence attestation and a case where findings blocked release.
Is agent authority bounded, logged and refusable?
Evidence
Agent registry with authority envelope plus a test showing an out-of-envelope action refused.
Is provenance reconstructable for a sampled model version?
Evidence
End-to-end lineage trace from source system to inference output.
Can the institution operate if the model or provider is withdrawn?
Evidence
Exit and fallback test evidence for the primary model provider.
Does assurance extend into embedded and sub-processor models?
Evidence
Vendor AI attestation with sub-processor model disclosure and right-to-test clause.
A readiness position that is refreshed once a year is a historical document by the time it is read. Each dimension here is recomputed as evidence changes, and the result rolls into the Operational Resilience Score rather than sitting beside it. The dimension map is published; the weighting and grading rubric are institutional IP and are not.