Purpose
Establish organizational AI policy, clear ownership/RACI, risk-acceptance authority, and continual improvement so technical pillars have accountable stewards.
Mandatory checks
Gate controls. Each check is pass/fail via artifact + pass condition. Expected from the annotated capability level when the system meets the minimum criticality tier.
An approved AI policy shall exist with version, named owner, and review date ≤12 months, and shall include both acceptable-use and prohibited-application sections.
- Artifact
- Approved AI acceptable-use / prohibited-applications policy with version, owner, and review date + Confirmation that both acceptable-use and prohibited-application sections are present
- Pass condition
- Policy has version, owner, and review date ≤12 months; includes both acceptable-use and prohibited-application sections (policy evidence measuredAt ≤90 days). If AI is not used at all, score NOT_APPLICABLE.
Why this control exists
Threat mapEstablish the organization's binding boundary for acceptable and prohibited AI use.
Threats mitigated
Insider MisuseHarmful Content GenerationShadow AgentsProtects
UsersAudit TrailSafetyMITRE: no technique mapped — this control addresses governance or assurance rather than a specific adversary technique.
Without a stated policy there is no basis for declaring a use unacceptable or for acting when someone crosses the line. This is foundational governance with no adversary technique mapping.
Informative threat context — mappings reduce exposure and do not guarantee mitigation; not certification.
Evidence required
- AI policy document
- Ownership/RACI for production AI systems
- Risk-acceptance register samples
Recommended checks
Strengthen posture beyond the gate. Same measurable structure; non-blocking unless elevated by organizational policy.
Leadership should review AI risk posture and APRF capability attained within the last 90 days; every open action from that review should have an owner and due date.
- Artifact
- Leadership AI risk / APRF maturity review minutes (or board pack excerpt) with review date + Action log showing owners and due dates for open items
- Pass condition
- Leadership reviewed AI risk posture and APRF capability attained ≤90 days ago; open actions have owners and due dates (review evidence measuredAt ≤90 days). If the organization does not run production AI systems, score NOT_APPLICABLE.
Why this control exists
Threat mapKeep AI risk posture visible to the leadership that can fund and mandate remediation.
Threats mitigated
Shadow AgentsProtects
Audit TrailSafetyMITRE: no technique mapped — this control addresses governance or assurance rather than a specific adversary technique.
Periodic leadership review is what allocates the funding and authority needed to close control gaps. This is organizational governance with no adversary technique mapping.
Informative threat context — mappings reduce exposure and do not guarantee mitigation; not certification.
Every production AI system should name owners for each org-declared required critical APRF domain (commonly security, safety, data, reliability, and model/governance) in a system inventory, with zero systems missing a required domain owner.
- Artifact
- Production AI system inventory listing the org-declared required critical-domain owner fields + Query/report showing 0 systems missing required domain owners
- Pass condition
- 0 production AI systems missing any required critical-domain owner in the inventory; inventory covers all production AI system IDs; required domain set is declared (inventory evidence measuredAt ≤90 days). If no production AI systems exist, score NOT_APPLICABLE.
Why this control exists
Threat mapAssign named owners to the APRF domains that matter for each production AI system.
Threats mitigated
Shadow AgentsRepudiationProtects
Audit TrailSafetyMITRE: no technique mapped — this control addresses governance or assurance rather than a specific adversary technique.
Controls without named owners decay because no one is accountable for their upkeep. Ownership is an accountability control with no adversary technique mapping.
Informative threat context — mappings reduce exposure and do not guarantee mitigation; not certification.
Sev-1/2 AI incidents and critical eval failures in the last quarter should produce improvement backlog items (≥80%); ≥50% of those items should be closed or have a dated plan.
- Artifact
- Improvement backlog (tickets) linked from Sev-1/2 AI incidents and critical eval failures + Quarterly sample showing linkage rate ≥80% and closed-or-planned rate ≥50%
- Pass condition
- ≥80% of Sev-1/2 AI incidents and critical eval fails in the last quarter produced a backlog item; ≥50% of those items closed or have a dated plan (backlog evidence measuredAt ≤90 days). If the organization does not use AI, or no Sev-1/2 AI incidents or critical eval fails are in scope, score NOT_APPLICABLE.
Why this control exists
Threat mapFeed incidents and evaluation failures into a tracked improvement backlog.
Threats mitigated
RepudiationProtects
Audit TrailSafetyMITRE: no technique mapped — this control addresses governance or assurance rather than a specific adversary technique.
A backlog fed by real failures is what converts lessons into control changes rather than documents. This is a continual improvement control with no adversary technique mapping.
Informative threat context — mappings reduce exposure and do not guarantee mitigation; not certification.
Every open control-gap waiver (risk acceptance) shall record a named owner and expiry date; every expired waiver shall have an escalation record—or be closed—before it remains unowned.
- Artifact
- Risk-acceptance / control-gap waiver register for in-scope AI systems + Confirmation that open waivers have owner+expiry and expired waivers have escalation (or are closed)
- Pass condition
- 100% of open control-gap waivers have owner + expiry; 0 expired waivers without an escalation record (register evidence measuredAt ≤90 days). If the organization has no open or expired control-gap waivers and no AI control gaps in scope, score NOT_APPLICABLE.
Why this control exists
Threat mapRecord accepted control gaps with an owner and an expiry rather than leaving them implicit.
Threats mitigated
RepudiationInsider MisuseProtects
Audit TrailSafetyMITRE: no technique mapped — this control addresses governance or assurance rather than a specific adversary technique.
Time-bounded, owned risk acceptance prevents indefinite silent gaps and forces each exception back onto the agenda. This is governance accountability with no adversary technique mapping.
Informative threat context — mappings reduce exposure and do not guarantee mitigation; not certification.
On an org-wide cadence, internal audit or independent assessment should sample APRF evidence; the last sampling report shall be ≤12 months old and list sampled Check IDs and findings. This is organizational sampling—not the same as CMP-R3 coverage of every capability Level 5 system.
- Artifact
- Independent assessment or internal-audit sampling report against APRF evidence (org cadence) + Sampled Check IDs and findings from the last ≤12 month cycle
- Pass condition
- Last org sampling report age ≤12 months; lists sampled Check IDs and findings (report evidence measuredAt ≤90 days). If no AI systems are in production assessment scope, score NOT_APPLICABLE.
Why this control exists
Threat mapIndependently sample APRF evidence to confirm that claimed controls are real.
Threats mitigated
RepudiationInsider MisuseProtects
Audit TrailMITRE: no technique mapped — this control addresses governance or assurance rather than a specific adversary technique.
Evidence that is never sampled tends to drift from what the system actually does. Independent sampling keeps assessment results trustworthy; no adversary technique maps.
Informative threat context — mappings reduce exposure and do not guarantee mitigation; not certification.
More detailPhilosophy, failures, practices, validations, examples, crosswalks, and evolution
Engineering philosophy
Technical controls without organizational governance drift. A production-ready AI program names owners, accepts residual risk explicitly, and improves from incidents and audits.
Why it matters
Enterprises fail AI readiness when no one owns a pillar, exceptions are informal, and leadership cannot see residual risk.
Common failures
- AI features ship with no named owner for safety or eval gates
- Exceptions granted in chat with no expiry
- No AI policy covering acceptable use and prohibited applications
- Compliance theater without leadership review of risk
Severity & risk
- Severity
- high
- Impact if violated
- Risk level
- medium
- Typical residual risk (impact × likelihood)
Engineering best practices
- Map APRF domains to teams; avoid orphan pillars
- Time-box exceptions; auto-escalate expired waivers
- Tie promotions and funding to measurable maturity for high-criticality systems
Automatic validations
- Inventory systems missing owners
- Alerts on expired risk acceptances
Manual validations
- Annual policy review
- Leadership tabletop on AI risk acceptance
Examples
- A risk register entry accepts a missing multi-provider fallback until Q3 with CTO sign-off
- Each agent product lists owners for Security, Safety, Evaluation, and Reliability
References
Crosswalks
GOVERN Govern
NIST AI Risk Management Framework · supports
Accountable Accountable and Transparent
NIST AI Risk Management Framework · supports
§4 Context of the organization
ISO/IEC 42001 · aligns-with
§5 Leadership
ISO/IEC 42001 · supports
§6 Planning
ISO/IEC 42001 · partial
§10 Improvement
ISO/IEC 42001 · aligns-with
L6 Security & Compliance
CSA MAESTRO (Multi-Agentic Threat Model) · supports
CC1 Control Environment
SOC 2 Trust Services Criteria · evidence-for
CC3 Risk Assessment
SOC 2 Trust Services Criteria · evidence-for
Operational Excellence Operational Excellence
AWS Well-Architected Framework · aligns-with
Future evolution
Machine-readable organizational control catalogs mapped to APRF domains and ISO 42001 clauses.