GOVERN-1.2 | The characteristics of trustworthy AI are integrated into organizational policies, processes, procedures, and practices. | Approval policies, tool sandbox policy, enforcement proxy settings. |
GOVERN-1.5 | Ongoing monitoring and periodic review of the risk management process and its outcomes are planned and organizational roles and responsibilities clearly defined, including determining the frequency of periodic review. | Alert rules and alert history, sampled human review, evaluation runs. |
GOVERN-2.1 | Roles and responsibilities and lines of communication related to mapping, measuring, and managing AI risks are documented and are clear to individuals and teams throughout the organization. | Human approval decisions, operator audit log. Reported configured, not operating, until approvals and audit entries name a person rather than the local default. |
GOVERN-3.2 | Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems. | Approval policies, human approval decisions. |
GOVERN-6.1 | Policies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third-party's intellectual property or other rights. | Enforcement proxy settings, third-party model provider calls. |
MEASURE-2.4 | The functionality and behavior of the AI system and its components – as identified in the map function – are monitored when in production. | Session and tool-call monitoring, alert rules and alert history. |
MEASURE-2.6 | The AI system is evaluated regularly for safety risks – as identified in the map function. | Guardrail events, loop detection, security posture scans. |
MEASURE-2.7 | AI system security and resilience – as identified in the map function – are evaluated and documented. | Hash-chained action log, security posture scans, tool or host use outside an allowlist. |
MEASURE-2.10 | Privacy risk of the AI system – as identified in the map function – is examined and documented. | Personal data, injection and credential content scans. |
MANAGE-2.3 | Procedures are followed to respond to and recover from a previously unknown risk when it is identified. | Alert rules and alert history, emergency stop, SIEM forwarding. |
MANAGE-2.4 | Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use. | Emergency stop, budget blocks, human approval decisions. |
MANAGE-3.1 | AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented. | Third-party model provider calls, budget blocks. |
MANAGE-4.1 | Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management. | Session and tool-call monitoring, human approval decisions, task outcomes, operator audit log, alert rules and alert history. |