AI Assurance · Readiness

    Readiness measured the way it will be examined

    Maturity models grade an institution against a consultancy's ladder. Supervisors do not use that ladder. These twelve dimensions are written in the language an examiner uses, each one answerable with an artefact rather than an assertion.

    Board

    D01

    Can the board evidence it understood the AI risk it accepted?

    Evidence
    Board minute with the AI risk appetite statement and the paper it was decided against.

    EU AI Act Art. 26
    SMCR
    OSFI E-23

    Regulator

    D02

    Can a supervisor be answered without a project being started?

    Evidence
    Standing regulator pack generated from the live evidence vault, not assembled on request.

    SR 11-7
    SS1/23
    JFSA supervisory dialogue

    Audit

    D03

    Has internal audit tested the AI control set independently?

    Evidence
    Third-line audit report on AI controls with management response and closure evidence.

    IIA three lines
    FINRA 3120

    Cyber

    D04

    Are AI-specific attack paths in the cyber control set?

    Evidence
    Adversarial and prompt-injection test results mapped to the cyber control library.

    NYDFS Part 500
    NIST AI RMF
    DORA

    Operational

    D05

    Does an AI failure degrade a business service within tolerance?

    Evidence
    Impact tolerance test where the AI dependency is the failure mode.

    PRA/FCA operational resilience
    DORA Art. 11

    Legal

    D06

    Is the legal basis for every model and dataset documented?

    Evidence
    Licence, consent basis and transfer mechanism register per dataset and model.

    GDPR
    APPI
    EU AI Act Art. 10

    Compliance

    D07

    Are AI outputs supervised where they touch a regulated activity?

    Evidence
    Supervision procedure covering AI-influenced recommendations and communications.

    FINRA 3110
    FCA Consumer Duty

    Model

    D08

    Is validation independent, current and consequential?

    Evidence
    Validation report with independence attestation and a case where findings blocked release.

    SR 11-7
    OCC 2011-12
    E-23

    Agent

    D09

    Is agent authority bounded, logged and refusable?

    Evidence
    Agent registry with authority envelope plus a test showing an out-of-envelope action refused.

    EU AI Act Art. 14
    internal assurance kernel

    Data

    D10

    Is provenance reconstructable for a sampled model version?

    Evidence
    End-to-end lineage trace from source system to inference output.

    BCBS 239
    EU AI Act Art. 10

    Resilience

    D11

    Can the institution operate if the model or provider is withdrawn?

    Evidence
    Exit and fallback test evidence for the primary model provider.

    DORA Art. 28
    OSFI B-10

    Third-Party

    D12

    Does assurance extend into embedded and sub-processor models?

    Evidence
    Vendor AI attestation with sub-processor model disclosure and right-to-test clause.

    Interagency third-party guidance
    DORA
    B-10

    Continuously current, not annual

    A readiness position that is refreshed once a year is a historical document by the time it is read. Each dimension here is recomputed as evidence changes, and the result rolls into the Operational Resilience Score rather than sitting beside it. The dimension map is published; the weighting and grading rubric are institutional IP and are not.