Global AI Assurance · Model assurance

    Capability to Risk Compiler

    A capability threshold declared by a developer is a statement about a model. It is not yet a statement about an institution. The compiler is what turns one into the other.

    A capability resolves into the risks it makes available, then onto the assets, data, business services, obligations, controls and vendors it can reach, and ends in a residual risk and a movement in the institution's resilience position.

    Published as reference architecture. Control weights, grading rubrics and the full control set are set per engagement.

    CapabilityInstitutional riskWhat it reachesResidualResilience movement

    The same capability compiles differently in every institution, because the reach is different. That is the whole argument for a second, deployment-aware layer.

    Four compiled chains

    Illustrative of a sample estate. Bounded deliberately.

    Advanced autonomous cyber capability

    Institutional risks made available

    • Unauthorised code execution
    • Privileged access misuse
    • Vulnerability exploitation
    • Lateral movement
    • Data exfiltration
    • Supply-chain compromise

    What it can reach

    • Production engineering estate
    • Cloud credentials and secret stores
    • Customer data platforms
    • Payment and settlement services
    • Third-party tool servers

    Residual

    Medium where isolation, tool governance and human escalation all hold; high where any one is conditional.

    Resilience movement

    Cyber resilience and third-party dimensions move together; the board sees one resilience movement, not a model score.

    Long-horizon agentic execution

    Institutional risks made available

    • Action outside approved scope
    • Undetected drift from baseline behaviour
    • Chained privilege escalation across agents
    • Irreversible action without human review

    What it can reach

    • Workflow and case systems
    • Procurement and vendor onboarding
    • Regulatory filing pipelines
    • Internal approval routes

    Residual

    Medium-high until the permission envelope and the delegation graph are both enforced at runtime.

    Resilience movement

    Operational resilience and conduct dimensions; the movement is driven by intervention latency, not capability alone.

    Financial action authority

    Institutional risks made available

    • Unauthorised payment or trade
    • Limit breach
    • Market conduct exposure
    • Reconciliation and settlement failure

    What it can reach

    • Treasury and payment rails
    • Trading and order management
    • Client money accounts
    • Books and records

    Residual

    Low only where per-action limits, dual control and local human approval are evidenced on every path.

    Resilience movement

    Financial infrastructure and conduct dimensions, with a named accountable person attached to each authority.

    Persuasive and generative customer interaction

    Institutional risks made available

    • Unfair or misleading outcome
    • Vulnerable customer harm
    • Unsupported financial promotion
    • Complaint and redress exposure

    What it can reach

    • Service and contact channels
    • Marketing and targeting systems
    • Advice and suitability journeys

    Residual

    Medium; depends on pre-release evaluation coverage and on whether refusals are evidenced.

    Resilience movement

    Conduct and consumer fairness dimensions, with jurisdiction overlays where local rules are stricter.

    What the board is told

    Never a model score. The board receives the change in the institution's operational resilience position, the conditions that produced it, and the person accountable for closing them.

    The compiler needs a subject. That subject is the AI system, not the model.

    See the unit of assurance