Global AI Assurance · System assurance
AI System Passport
The unit of assurance is not the model. Evaluating a modern system means evaluating the environment it runs in: the agent, the instruction layer, the tools, the tool servers, the data it reaches, the credentials it holds, the permissions it was given, the people who can interrupt it and the jurisdictions that bind it.
The passport is that object written down once, in a form a machine can enforce and a supervisor can read.
Published as reference architecture. Control weights, grading rubrics and the full control set are set per engagement.
Fifteen parts make one AI system
Change any one of them and the assurance position changes, whether or not the model changed.
Model
Which intelligence is doing the work.
Version
The assurance position resets on every version change.
Agent
The acting entity, with its own identity and owner.
Prompt and policy
The instruction layer, versioned like code.
Tools
Every function the agent may invoke.
MCP servers
Tool servers are a supply chain and a trust boundary.
Data
Classes reached, not just the store connected.
Credentials
What the system holds is what an attacker inherits.
Permissions
The envelope: what it may see, read, write, execute, approve.
Environment
Sandbox and production carry different risk from the same model.
Human oversight
Who may interrupt, at what latency, in which jurisdiction.
Jurisdiction
Resolved from the whole chain, never from a hosting location.
Business purpose
The purpose is what makes an action in or out of scope.
Controls
The controls asserted over this system specifically.
Evidence
What can be shown, and where it is held.
The passport record
Machine-readable, versioned, and carrying an expiry. An approval without an expiry becomes a permanent assumption.
System ID
The stable identifier every control, test and incident is written against.
Model and version
Ties the record to a specific artefact so change management has something to compare.
Provider
Carries into supply chain, concentration and sovereignty reads.
Agent ID
Separates the acting entity from the intelligence it uses.
Agent owner
A named person who can be asked why the agent did something.
Business owner
Accountability for the outcome, not the technology.
Purpose
Defines the scope boundary an action can fall outside of.
Risk classification
Drives the control set and the evidence cadence.
Capability profile
Inherited from the model assurance record, re-read in this context.
Tools
Each tool is an action surface with its own authorisation.
MCP servers
Named because a compromised tool server is a compromised agent.
APIs
External reach the institution is answerable for.
Data classes
Determines privacy, residency and localisation duties.
Credentials
Scope and rotation state, because standing credentials are standing risk.
Jurisdictions
All of them: entity, data, user, infrastructure, transaction.
Residency
Where processing and evidence must remain.
Human approval requirements
Which actions cannot proceed without a person, and where that person must be.
Financial authority
Limits expressed as amounts and counterparties, not as descriptions.
Cyber authority
Whether the system may touch infrastructure, secrets or code paths.
Model evaluation state
What has been tested, when, and by whom.
Control state
Pass, conditional or failed, per control, dated.
Incident history
Pattern matters more than any single event.
Assurance score
A composite read, published as a movement rather than a headline number.
ORS contribution
How this system moves the institution's resilience position.
Approval
Who approved, on what evidence, in which forum.
Expiration
An approval without an expiry becomes a permanent assumption.
Why a registry of models is not enough
An inventory of models tells the institution what it bought. A register of AI systems tells it what is running, on whose authority, reaching what, under which law, with what evidence. Only the second one survives a supervisory question.
A passport per system is necessary. It is not sufficient once agents start instructing each other.
See where authority chains break