Global AI Assurance · System assurance

    AI System Passport

    The unit of assurance is not the model. Evaluating a modern system means evaluating the environment it runs in: the agent, the instruction layer, the tools, the tool servers, the data it reaches, the credentials it holds, the permissions it was given, the people who can interrupt it and the jurisdictions that bind it.

    The passport is that object written down once, in a form a machine can enforce and a supervisor can read.

    Published as reference architecture. Control weights, grading rubrics and the full control set are set per engagement.

    Fifteen parts make one AI system

    Change any one of them and the assurance position changes, whether or not the model changed.

    01

    Model

    Which intelligence is doing the work.

    02

    Version

    The assurance position resets on every version change.

    03

    Agent

    The acting entity, with its own identity and owner.

    04

    Prompt and policy

    The instruction layer, versioned like code.

    05

    Tools

    Every function the agent may invoke.

    06

    MCP servers

    Tool servers are a supply chain and a trust boundary.

    07

    Data

    Classes reached, not just the store connected.

    08

    Credentials

    What the system holds is what an attacker inherits.

    09

    Permissions

    The envelope: what it may see, read, write, execute, approve.

    10

    Environment

    Sandbox and production carry different risk from the same model.

    11

    Human oversight

    Who may interrupt, at what latency, in which jurisdiction.

    12

    Jurisdiction

    Resolved from the whole chain, never from a hosting location.

    13

    Business purpose

    The purpose is what makes an action in or out of scope.

    14

    Controls

    The controls asserted over this system specifically.

    15

    Evidence

    What can be shown, and where it is held.

    The passport record

    Machine-readable, versioned, and carrying an expiry. An approval without an expiry becomes a permanent assumption.

    System ID

    The stable identifier every control, test and incident is written against.

    Model and version

    Ties the record to a specific artefact so change management has something to compare.

    Provider

    Carries into supply chain, concentration and sovereignty reads.

    Agent ID

    Separates the acting entity from the intelligence it uses.

    Agent owner

    A named person who can be asked why the agent did something.

    Business owner

    Accountability for the outcome, not the technology.

    Purpose

    Defines the scope boundary an action can fall outside of.

    Risk classification

    Drives the control set and the evidence cadence.

    Capability profile

    Inherited from the model assurance record, re-read in this context.

    Tools

    Each tool is an action surface with its own authorisation.

    MCP servers

    Named because a compromised tool server is a compromised agent.

    APIs

    External reach the institution is answerable for.

    Data classes

    Determines privacy, residency and localisation duties.

    Credentials

    Scope and rotation state, because standing credentials are standing risk.

    Jurisdictions

    All of them: entity, data, user, infrastructure, transaction.

    Residency

    Where processing and evidence must remain.

    Human approval requirements

    Which actions cannot proceed without a person, and where that person must be.

    Financial authority

    Limits expressed as amounts and counterparties, not as descriptions.

    Cyber authority

    Whether the system may touch infrastructure, secrets or code paths.

    Model evaluation state

    What has been tested, when, and by whom.

    Control state

    Pass, conditional or failed, per control, dated.

    Incident history

    Pattern matters more than any single event.

    Assurance score

    A composite read, published as a movement rather than a headline number.

    ORS contribution

    How this system moves the institution's resilience position.

    Approval

    Who approved, on what evidence, in which forum.

    Expiration

    An approval without an expiry becomes a permanent assumption.

    Why a registry of models is not enough

    An inventory of models tells the institution what it bought. A register of AI systems tells it what is running, on whose authority, reaching what, under which law, with what evidence. Only the second one survives a supervisory question.

    A passport per system is necessary. It is not sufficient once agents start instructing each other.

    See where authority chains break