Global AI Assurance · Model assurance
Capability to Risk Compiler
A capability threshold declared by a developer is a statement about a model. It is not yet a statement about an institution. The compiler is what turns one into the other.
A capability resolves into the risks it makes available, then onto the assets, data, business services, obligations, controls and vendors it can reach, and ends in a residual risk and a movement in the institution's resilience position.
Published as reference architecture. Control weights, grading rubrics and the full control set are set per engagement.
The same capability compiles differently in every institution, because the reach is different. That is the whole argument for a second, deployment-aware layer.
Four compiled chains
Illustrative of a sample estate. Bounded deliberately.
Advanced autonomous cyber capability
Institutional risks made available
- Unauthorised code execution
- Privileged access misuse
- Vulnerability exploitation
- Lateral movement
- Data exfiltration
- Supply-chain compromise
What it can reach
- Production engineering estate
- Cloud credentials and secret stores
- Customer data platforms
- Payment and settlement services
- Third-party tool servers
Residual
Medium where isolation, tool governance and human escalation all hold; high where any one is conditional.
Resilience movement
Cyber resilience and third-party dimensions move together; the board sees one resilience movement, not a model score.
Long-horizon agentic execution
Institutional risks made available
- Action outside approved scope
- Undetected drift from baseline behaviour
- Chained privilege escalation across agents
- Irreversible action without human review
What it can reach
- Workflow and case systems
- Procurement and vendor onboarding
- Regulatory filing pipelines
- Internal approval routes
Residual
Medium-high until the permission envelope and the delegation graph are both enforced at runtime.
Resilience movement
Operational resilience and conduct dimensions; the movement is driven by intervention latency, not capability alone.
Financial action authority
Institutional risks made available
- Unauthorised payment or trade
- Limit breach
- Market conduct exposure
- Reconciliation and settlement failure
What it can reach
- Treasury and payment rails
- Trading and order management
- Client money accounts
- Books and records
Residual
Low only where per-action limits, dual control and local human approval are evidenced on every path.
Resilience movement
Financial infrastructure and conduct dimensions, with a named accountable person attached to each authority.
Persuasive and generative customer interaction
Institutional risks made available
- Unfair or misleading outcome
- Vulnerable customer harm
- Unsupported financial promotion
- Complaint and redress exposure
What it can reach
- Service and contact channels
- Marketing and targeting systems
- Advice and suitability journeys
Residual
Medium; depends on pre-release evaluation coverage and on whether refusals are evidenced.
Resilience movement
Conduct and consumer fairness dimensions, with jurisdiction overlays where local rules are stricter.
What the board is told
Never a model score. The board receives the change in the institution's operational resilience position, the conditions that produced it, and the person accountable for closing them.
The compiler needs a subject. That subject is the AI system, not the model.
See the unit of assurance