{"$schema":"https://stackrail.io/aprf/spec-schema/0.7","id":"aprf","name":"AI Production Readiness Framework","question":"Can this AI application safely operate in production?","governance":{"version":"0.11.0","status":"working-draft","releaseName":"Hybrid Check rewrites, mandatory→recommended RFCs, collector hardening","publishedAt":"2026-08-02","publisher":{"name":"StackRail","role":"working-draft-publisher","url":"https://stackrail.io"},"intendedSteward":{"model":"neutral-working-group","description":"Multi-stakeholder technical oversight (vendors, practitioners, OWASP/CNCF-adjacent participants) with public RFCs — not a single commercial owner.","currentPhase":"working-draft","processPath":"/aprf/rfc/"},"versioning":{"scheme":"semver","rules":["MAJOR: breaking changes to domain IDs, check IDs, or gate semantics","MINOR: new domains, pillars, or checks; non-breaking field additions","PATCH: editorial clarifications to prose, artifacts, or pass conditions"],"stableIdPolicy":"Pillar IDs (APRF-NN) and check IDs (e.g. AUTHN-M1) are immutable once published in a MINOR+. Deprecate; do not reuse."},"schemaVersioning":{"frameworkSemVer":"APRF_GOVERNANCE.version — semantic version of the normative framework, check catalog, profiles, and scoring semantics.","specSchemaId":"https://stackrail.io/aprf/spec-schema/0.7 — JSON Schema for the machine-readable APRF document shape; may lag framework SemVer when only content changes.","attestationSchemaId":"https://stackrail.io/aprf/attestation-schema/0.6 — JSON Schema for aprf-self-attestation exports.","note":"Do not equate schema path versions (0.7 / 0.6) with APRF framework SemVer (e.g. 0.11.0). Validators and conformance claims should cite both."},"deprecation":{"policy":"Deprecated checks and pillars remain in the spec for at least one MINOR cycle (N−1), marked deprecated, with a replacement ID.","supportWindow":"N-1 minor versions"},"extension":{"lenses":"Formal lenses (RAG, Agents, Voice, Coding agents) add mandatory checks under existing pillars. Claim lenses in assessments and attestations when those system types apply.","customNamespace":"Organizations MAY add private checks with IDs prefixed x- (e.g. x-ACME-M1). Custom checks MUST NOT claim APRF conformance by themselves."},"certification":{"levels":[{"id":"self-attestation","name":"Self-attestation","description":"Organization publishes assessment results + evidence index against a pinned APRF version. No third-party validation."},{"id":"third-party","name":"Third-party assessment","description":"Independent assessor verifies gate blockers and samples evidence. Intended for Tier 3 and regulated use."}],"badges":"Conformance statements MUST cite APRF version, criticality tier, attained capability level, profile (if any), and list any open blockers. No single percentage badge.","referenceAssessment":{"path":"/aprf/assess/","exportFormat":"aprf-self-attestation","schema":"https://stackrail.io/aprf/attestation-schema/0.6","description":"Reference self-assessment for Core or Regulated profiles with optional lenses: one question per gate, on-screen gate result, and client download of aprf-self-attestation JSON conforming to the attestation schema. AGN/HUM/TOL/MEM gates may be marked N/A with rationale. Unanswered checks count as failed."}},"compatibility":{"crosswalks":["NIST AI RMF","ISO/IEC 42001","SOC 2 Trust Services Criteria (evidence reuse)","OWASP LLM Top 10 (with AISVS bridges)","OWASP AISVS","OWASP ASVS 5.0","OpenCRE","CSA MAESTRO","OWASP FIASSE / SSEM","AWS Well-Architected (conceptual)","SLSA / supply-chain"],"note":"Machine-readable maps for NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10 (incl. AISVS relatedPeerControlIds), AISVS, ASVS, OpenCRE, MAESTRO, FIASSE, SOC 2, AWS Well-Architected, and SLSA ship in the APRF spec under crosswalks[]. Informative alignment only — not certification."},"stewardshipRef":"aprf-stewardship","draftCapabilityFloor":3},"stewardship":{"id":"aprf-stewardship","charter":{"purpose":"Evolve APRF into a ratifiable, vendor-neutral production-readiness standard for AI systems through open technical consensus—not through a single commercial owner.","principles":["Neutrality: no single vendor or publisher holds permanent veto over normative content.","Open process: substantive changes go through public RFCs with recorded decisions.","Evidence over marketing: checks stay measurable (artifact + pass condition); no vanity scores.","Stable identifiers: pillar and check IDs are immutable once published in a MINOR+; deprecate, do not reuse.","Separability: StackRail may publish implementations and services without owning the standard long-term.","Inclusive participation: vendors, practitioners, researchers, and OWASP/CNCF-adjacent contributors welcome."],"nonGoals":["Replacing NIST AI RMF, ISO/IEC 42001, SOC 2, or OWASP as peer frameworks.","Granting certification authority to the working-draft publisher by default.","Locking the taxonomy behind proprietary tooling or paywalled normative text."]},"phases":[{"id":"working-draft","name":"Working draft","summary":"StackRail publishes the draft, hosts the machine-readable spec, and accepts RFCs. Normative intent is public; stewardship is not yet transferred.","current":true},{"id":"interim-advisory","name":"Interim advisory board","summary":"Multi-org advisors review RFCs and release plans. Publisher still ships releases but commits to advisory consensus for MAJOR/MINOR.","current":false},{"id":"neutral-working-group","name":"Neutral working group","summary":"Standing technical WG owns the roadmap, RFC decisions, and release approvals. Publisher becomes one participant among peers.","current":false},{"id":"foundation-home","name":"Foundation / SDO home","summary":"Optional later home under a foundation or standards body with IP assignment, trademark, and formal membership rules.","current":false}],"interimAdvisory":{"status":"recruiting","targetSeats":5,"minimumIndependentOrgs":3,"seats":[{"category":"Independent security / AppSec practitioner"},{"category":"AI platform or model vendor (non-publisher)"},{"category":"Production AI operator (practitioner)"},{"category":"Standards / SDO-adjacent participant (e.g. OWASP/CNCF)"},{"category":"Researcher or academic"}],"openCall":"StackRail is recruiting an interim advisory board (≥3 independent organizations) before MAJOR/MINOR releases require advisory consensus. Volunteer via the interim contact; a seat does not grant commercial preference or veto over peer RFCs.","decisionLog":"RFC decisions and rationales are published on /aprf/rfc/ and in the machine-readable `rfcs` index in /aprf/spec/. Until seats are filled, working-draft quorum applies: publisher decides after the review window with public rationale.","credibilityNote":"Single-vendor publication is temporary and explicit. Normative text and the machine-readable catalog remain freely available; transfer triggers and requirements are published; certification programs (if any) stay separate from normative stewardship."},"transfer":{"triggers":["At least three independent organizations actively reviewing RFCs for two consecutive MINOR cycles.","Published interim charter signed by advisory participants.","Public RFC backlog with decisions recorded for ≥90 days.","Willingness of a neutral host (foundation, consortium, or multi-party WG) to accept stewardship."],"requirements":["Machine-readable APRF spec remains freely available under a permissive documentation license.","Check and pillar ID stability policy preserved.","StackRail (or any implementer) retains rights to build products against APRF without preferential gatekeeping.","Certification programs, if any, are separated from normative stewardship."],"ipIntent":"Normative APRF text and machine-readable catalogs are intended to transfer with stewardship. Product trademarks and commercial services remain with their owners."},"participation":{"who":["AI platform and model vendors","Practitioners running production AI systems","Security, SRE, and compliance specialists","Researchers and standards practitioners","Adjacent communities (e.g. OWASP GenAI, CNCF security TAG participants)"],"how":["File an RFC using the template and checklist.","Comment on open RFCs during the review window.","Propose lenses, crosswalks, or editorial fixes via PATCH/MINOR RFCs.","Volunteer for an interim advisory seat (open call while status is recruiting)."],"contact":{"emailHint":"anu.v.apps@gmail.com (interim; transfers with steward)","processPath":"/aprf/rfc/","site":"https://stackrail.io/aprf/rfc/","machineReadable":"stewardship in /aprf/spec/","normativeRepository":"https://github.com/stackrail-io/APRF"}},"rfc":{"name":"APRF Request for Comments","numbering":"APRF-RFC-NNNN (zero-padded, monotonic; 0000 is the template)","minimumReviewDays":14,"decisionQuorum":"Working-draft phase: publisher decides after review window, with public rationale. Interim advisory+: majority of active advisors; ties escalate to published deadlock procedure.","stages":[{"id":"draft","name":"Draft","summary":"Author iterating privately or in a PR; not yet open for formal review."},{"id":"proposed","name":"Proposed","summary":"Submitted with checklist complete; awaiting scheduling into review."},{"id":"in-review","name":"In review","summary":"Public comment open for at least the minimum review window."},{"id":"accepted","name":"Accepted","summary":"Will ship in a named SemVer release; implementation PR linked."},{"id":"rejected","name":"Rejected","summary":"Will not ship as proposed; rationale recorded; may be revised and resubmitted."},{"id":"withdrawn","name":"Withdrawn","summary":"Author withdrew before decision."},{"id":"superseded","name":"Superseded","summary":"Replaced by a later RFC."}],"submissionChecklist":["Problem statement and who is affected","Proposed change (pillars, checks, profiles, lenses, crosswalks, scoring, or governance)","SemVer impact: MAJOR / MINOR / PATCH (with rationale)","Backward compatibility and deprecation plan if IDs change","Evidence that checks remain measurable (artifact + pass condition)","Crosswalk impact (if any)","Security / safety considerations","Open questions for reviewers"],"decisionCriteria":["Improves production readiness signal without diluting gate semantics","Does not introduce vanity scoring or unauditable prose-only controls","Fits taxonomy (prefer lenses/profiles over new top-level domains)","Preserves ID stability or provides a deprecation path","Feasible for adopters at the claimed criticality tier"],"template":{"id":"APRF-RFC-0000","fields":["Title","Status","Author(s)","Created","SemVer impact","Problem","Proposal","Alternatives considered","Compatibility","Security considerations","Open questions","Checklist"]}}},"rfcs":[{"id":"APRF-RFC-0001","number":1,"title":"Establish working-draft RFC process and public Open RFCs list","status":"in-review","created":"2026-07-24","semverImpact":"MINOR","summary":"Editorial RFC that ratifies the stewardship RFC stages on the site, publishes this index, and records the first open review window—no taxonomy changes.","slug":"0001-working-draft-rfc-process","href":"/aprf/rfc/0001-working-draft-rfc-process/","markdownPath":"/aprf/rfc/0001-working-draft-rfc-process.md"},{"id":"APRF-RFC-0002","number":2,"title":"Demote incident-readiness INC-M3 and INC-M4 to recommended","status":"accepted","created":"2026-08-01","semverImpact":"MINOR","summary":"Demotes INC-M3→INC-R2 and INC-M4→INC-R4; documents pre-release exception for removing IDs without deprecated stubs before the first tagged version.","slug":"0002-incident-readiness-mandatory-to-recommended","href":"/aprf/rfc/0002-incident-readiness-mandatory-to-recommended/","markdownPath":"/aprf/rfc/0002-incident-readiness-mandatory-to-recommended.md"},{"id":"APRF-RFC-0003","number":3,"title":"Demote observability OBS-M2 to recommended (OBS-R4)","status":"accepted","created":"2026-08-01","semverImpact":"MINOR","summary":"Demotes OBS-M2→OBS-R4 (token/cost attribution); removes from Core/Regulated mandatories; pre-release ID-removal exception.","slug":"0003-observability-obs-m2-to-recommended","href":"/aprf/rfc/0003-observability-obs-m2-to-recommended/","markdownPath":"/aprf/rfc/0003-observability-obs-m2-to-recommended.md"},{"id":"APRF-RFC-0004","number":4,"title":"Split PERF-M2 dashboards — metrics stay mandatory; dashboards → PERF-R4","status":"accepted","created":"2026-08-01","semverImpact":"MINOR","summary":"Rewrites PERF-M2 as mandatory ops metrics; adds PERF-R4 for near-real-time dashboards as recommended maturity.","slug":"0004-performance-slo-perf-m2-dashboards-to-recommended","href":"/aprf/rfc/0004-performance-slo-perf-m2-dashboards-to-recommended/","markdownPath":"/aprf/rfc/0004-performance-slo-perf-m2-dashboards-to-recommended.md"},{"id":"APRF-RFC-0005","number":5,"title":"Demote reliability-continuity REL-M4 to recommended (REL-R3)","status":"accepted","created":"2026-08-01","semverImpact":"MINOR","summary":"Demotes REL-M4→REL-R3 (process continuity options with owners); pre-release ID-removal exception.","slug":"0005-reliability-continuity-rel-m4-to-recommended","href":"/aprf/rfc/0005-reliability-continuity-rel-m4-to-recommended/","markdownPath":"/aprf/rfc/0005-reliability-continuity-rel-m4-to-recommended.md"},{"id":"APRF-RFC-0006","number":6,"title":"Demote reliability-continuity REL-M7 to recommended (REL-R5)","status":"accepted","created":"2026-08-01","semverImpact":"MINOR","summary":"Demotes REL-M7→REL-R5 (AI-dependency chaos); removes from Regulated mandatories; pre-release ID-removal exception.","slug":"0006-reliability-continuity-rel-m7-to-recommended","href":"/aprf/rfc/0006-reliability-continuity-rel-m7-to-recommended/","markdownPath":"/aprf/rfc/0006-reliability-continuity-rel-m7-to-recommended.md"},{"id":"APRF-RFC-0007","number":7,"title":"Demote reliability-continuity REL-M8 to recommended (REL-R7)","status":"accepted","created":"2026-08-01","semverImpact":"MINOR","summary":"Demotes REL-M8→REL-R7 (multi-provider Level-5 continuity); removes from Regulated mandatories; pre-release ID-removal exception.","slug":"0007-reliability-continuity-rel-m8-to-recommended","href":"/aprf/rfc/0007-reliability-continuity-rel-m8-to-recommended/","markdownPath":"/aprf/rfc/0007-reliability-continuity-rel-m8-to-recommended.md"},{"id":"APRF-RFC-0008","number":8,"title":"Demote explainability EXP-M4 to recommended (EXP-R3)","status":"accepted","created":"2026-08-01","semverImpact":"MINOR","summary":"Demotes EXP-M4→EXP-R3 (change/counterfactual summaries); removes from Regulated mandatories; pre-release ID-removal exception.","slug":"0008-explainability-exp-m4-to-recommended","href":"/aprf/rfc/0008-explainability-exp-m4-to-recommended/","markdownPath":"/aprf/rfc/0008-explainability-exp-m4-to-recommended.md"},{"id":"APRF-RFC-0009","number":9,"title":"Demote adversarial-security SEC-M5 to recommended (SEC-R3)","status":"accepted","created":"2026-08-01","semverImpact":"MINOR","summary":"Demotes SEC-M5→SEC-R3 (exfiltration detection; canaries optional among equivalents); removes from Regulated mandatories; pre-release ID-removal exception.","slug":"0009-adversarial-security-sec-m5-to-recommended","href":"/aprf/rfc/0009-adversarial-security-sec-m5-to-recommended/","markdownPath":"/aprf/rfc/0009-adversarial-security-sec-m5-to-recommended.md"},{"id":"APRF-RFC-0010","number":10,"title":"Fine-grained peer crosswalks (AISVS, ASVS, OpenCRE, MAESTRO, FIASSE)","status":"accepted","created":"2026-08-10","semverImpact":"MINOR","summary":"Adds informative section-level crosswalks for OWASP AISVS 1.0 (`aisvs:v1.0-C*.*`), ASVS, OpenCRE, MAESTRO, and FIASSE; enriches OWASP LLM Top 10 controls with AISVS `relatedPeerControlIds` bridges.","slug":"0010-peer-crosswalks-aisvs-asvs-opencre-maestro-fiasse","href":"/aprf/rfc/0010-peer-crosswalks-aisvs-asvs-opencre-maestro-fiasse/","markdownPath":"/aprf/rfc/0010-peer-crosswalks-aisvs-asvs-opencre-maestro-fiasse.md"},{"id":"APRF-RFC-0011","number":11,"title":"Evidence Assurance Tiers (E0–E5)","status":"accepted","created":"2026-08-11","semverImpact":"MINOR","summary":"Adds normative Evidence Assurance Tiers (E0–E5) and Check `evidencePolicy.minimumTier` so PASS requires evidence at or above a declared floor; UNVERIFIED is a verification outcome on PARTIAL, not a sixth control status.","slug":"0011-evidence-assurance-tiers","href":"/aprf/rfc/0011-evidence-assurance-tiers/","markdownPath":"/aprf/rfc/0011-evidence-assurance-tiers.md"},{"id":"APRF-RFC-0012","number":12,"title":"Cognitive Assurance Experimental Extension (COG)","status":"draft","created":"2026-08-16","semverImpact":"MINOR","summary":"Proposes an optional future Cognitive Assurance (COG) Experimental Extension for long-lived persistent autonomous agents—objective governance, memory lineage, policy evolution, decision provenance, and behavioral continuity—without changing APRF 1.x Core/Regulated philosophy or Checks.","slug":"0012-cognitive-assurance","href":"/aprf/rfc/0012-cognitive-assurance/","markdownPath":"/aprf/rfc/0012-cognitive-assurance.md"},{"id":"APRF-RFC-0013","number":13,"title":"Assessment Target Kinds and Framework Profile","status":"draft","created":"2026-08-18","semverImpact":"MINOR","summary":"Adds systemType classification, official aprf-profile-framework, applicationCapabilities→lenses, and resolveAssessmentTarget() so assessments select Checks from framework-definition SoT without mislabeling frameworks as Core.","slug":"0013-assessment-target-kinds","href":"/aprf/rfc/0013-assessment-target-kinds/","markdownPath":"/aprf/rfc/0013-assessment-target-kinds.md"},{"id":"APRF-RFC-0014","number":14,"title":"Threat Composition from Multi-Kind Signals","status":"draft","created":"2026-08-26","semverImpact":"MINOR","summary":"Adds a signal registry (production-mechanism kinds) and threat-first composition with a formal evaluator; Checks remain the sole gate unit; threats drive suspected/confirmed exposure only.","slug":"0014-threat-composition-from-signals","href":"/aprf/rfc/0014-threat-composition-from-signals/","markdownPath":"/aprf/rfc/0014-threat-composition-from-signals.md"}],"scope":{"vendors":["OpenAI","Anthropic","Gemini","Llama","DeepSeek","Mistral","Self-hosted models"],"systemTypes":["Chatbots","AI Agents","MCP Servers","A2A Systems","RAG","Multi-agent systems","Coding Agents","Voice AI","Autonomous systems"],"peerStandards":["AWS Well-Architected Framework","OWASP Top 10","CIS Benchmarks","Google SRE Workbook","NIST AI RMF","ISO/IEC 42001"]},"taxonomy":{"domains":[{"id":"security","name":"Security","summary":"Adversarial resistance, identity, authorization, secrets, tool mediation, supply chain, and hardened runtime for AI systems.","pillarSlugs":["ai-security","authentication","authorization","secrets","tool-safety","supply-chain","infrastructure"]},{"id":"safety","name":"Safety & Responsible AI","summary":"Harm prevention, content safety, fairness, and transparency—NIST trustworthiness characteristics distinct from adversarial security.","pillarSlugs":["safety-responsible-ai","explainability"]},{"id":"data","name":"Data","summary":"Privacy, corpus and index governance, data quality, and memory integrity across AI pipelines.","pillarSlugs":["data-privacy","data-governance","memory-management"]},{"id":"model-lifecycle","name":"Model & Prompt Lifecycle","summary":"Model selection and versioning, prompt and context as production artifacts, and continuous evaluation gates.","pillarSlugs":["model-governance","prompt-engineering","context-engineering","evaluation"]},{"id":"agents","name":"Agents & Autonomy","summary":"Agent charters, autonomy limits, A2A trust, and human oversight for high-impact actions.","pillarSlugs":["agent-governance","human-approval"]},{"id":"reliability","name":"Reliability & Operations","summary":"Observability, performance SLOs, graceful degradation and continuity, change management with rollback, and incident readiness.","pillarSlugs":["observability","performance-slo","reliability-continuity","change-management","incident-readiness"]},{"id":"cost","name":"Cost","summary":"Spend bounds, attribution, caching, routing, and denial-of-wallet controls for AI workloads.","pillarSlugs":["cost-optimization"]},{"id":"governance","name":"Governance & Compliance","summary":"Organizational AI policy, ownership, risk acceptance, and auditable evidence of controls—without equating compliance with readiness.","pillarSlugs":["organizational-governance","compliance"]}],"crossCutting":{"id":"cross-cutting","name":"Cross-cutting concerns","summary":"Concerns that apply across every domain. They are not peer domains; they enable safe delivery of all other pillars.","pillarSlugs":["platform-engineering"]}},"maturity":{"capabilityLevels":[{"level":1,"name":"Initial","summary":"Ad-hoc practices. Works in demos; controls are informal or absent. Acceptable only for Tier 0 sandboxes.","entryCriteria":["No claim of production readiness","Changes may be undocumented console edits","Failures do not trigger organizational incident process","Spend and rate limits are owner-watched at best"]},{"level":2,"name":"Managed","summary":"Basic repeatable controls: auth, logging, spend caps, secret hygiene. Suitable baseline for Tier 1 (internal) systems.","entryCriteria":["Authenticated access for non-public surfaces","Request/cost logging exists","Hard spend or rate ceilings prevent runaway usage","Secrets are not hardcoded in production prompts or clients"]},{"level":3,"name":"Defined","summary":"Documented, enforced controls across critical domains. Mandatory checks for Tier 2 (customer production) are met.","entryCriteria":["Promotion path and rollback for prompts, models, and tools","Server-side authz, tool mediation, and eval gates on releases","Traces reconstruct model → tool → outcome paths","AI-specific incident playbooks and named owners exist"]},{"level":4,"name":"Quantitatively Managed","summary":"SLOs, audited evidence, formal governance, and measured quality/safety signals. Expected floor for many Tier 3 systems.","entryCriteria":["Published SLOs for latency, availability, and at least one quality/safety signal","Auditable evidence packs for critical controls","Change control and ownership across teams","Privacy/compliance obligations mapped to technical controls"]},{"level":5,"name":"Optimizing","summary":"Continuous improvement: automated gates, dual-control for irreversible actions, chaos/continuity drills, near-zero blast-radius ambiguity.","entryCriteria":["Dual-control (or equivalent) for irreversible high-impact actions","Continuous evaluation blocks unsafe releases automatically","Continuity and failure drills on a defined cadence with recorded results","Blast radius for every tool, agent, and data path is documented and enforced"]}],"criticalityTiers":[{"tier":0,"name":"Sandbox","summary":"Non-customer experiments. Failures are contained to the builder’s environment.","requiredCapability":1,"examples":["Hackathon prototype","Local notebook agent","Throwaway prompt playground"]},{"tier":1,"name":"Internal","summary":"Employee-only or tightly gated internal use. Organizational impact only.","requiredCapability":2,"examples":["Internal knowledge assistant","Employee coding agent on non-prod systems"]},{"tier":2,"name":"Production","summary":"Customer- or partner-facing. Material product, privacy, or financial impact if it fails.","requiredCapability":3,"examples":["Customer support chatbot","SaaS RAG feature","MCP tools touching customer data"]},{"tier":3,"name":"Mission Critical","summary":"High blast radius: safety, regulated decisions, large financial movement, or critical infrastructure dependency.","requiredCapability":4,"examples":["Medical triage assistant","Autonomous trading or payments agent","Life-safety or critical-infrastructure copilots"]}]},"profiles":[{"id":"aprf-profile-core","name":"Core (Tier 2 Production)","summary":"Minimum mandatory gates for customer- or partner-facing AI. Pass this gate before claiming production readiness. Tier 3 and regulated systems must still assess the Regulated profile or full catalog.","targetCriticality":2,"targetCapability":3,"mandatoryCheckIds":["AUTHN-M1","AUTHN-M2","AUTHN-M3","AUTHZ-M1","AUTHZ-M2","SEC2-M1","SEC2-M2","SEC-M1","SEC-M3","TOL-M1","TOL-M2","TOL-M3","SCI-M2","INF-M1","SAF-M1","SAF-M2","SAF-M3","PRI-M1","PRI-M2","MEM-M1","PRM-M1","PRM-M2","MOD-M1","EVL-M1","EVL-M2","AGN-M2","HUM-M1","HUM-M3","OBS-M1","PERF-M1","REL-M1","REL-M2","DEP-M1","CHG-M1","CHG-M3","INC-M1","INC-M2","COST-M1","COST-M3"],"rationale":["Identity and authorization before any customer traffic (AUTHN/AUTHZ).","Secrets and injection/tool mediation to prevent common AI incidents (SEC/TOL).","Safety policy + eval gates so quality/harm regressions cannot silently ship (SAF/EVL).","Pinned prompts/models with promotion evidence (PRM/MOD).","Observability, timeouts, degraded mode, and tested rollback (OBS/REL/CHG).","Spend ceilings to prevent denial-of-wallet (COST)."]},{"id":"aprf-profile-regulated","name":"Regulated (Tier 3)","summary":"Core Profile plus Tier-3-only mandatories for mission-critical or regulated AI (residency, fairness, dual control, signed supply chain, chaos/continuity, independent assessment). Target capability Level 5.","targetCriticality":3,"targetCapability":5,"mandatoryCheckIds":["AUTHN-M1","AUTHN-M2","AUTHN-M3","AUTHZ-M1","AUTHZ-M2","SEC2-M1","SEC2-M2","SEC-M1","SEC-M3","TOL-M1","TOL-M2","TOL-M3","SCI-M2","INF-M1","SAF-M1","SAF-M2","SAF-M3","PRI-M1","PRI-M2","MEM-M1","PRM-M1","PRM-M2","MOD-M1","EVL-M1","EVL-M2","AGN-M2","HUM-M1","HUM-M3","OBS-M1","PERF-M1","REL-M1","REL-M2","DEP-M1","CHG-M1","CHG-M3","INC-M1","INC-M2","COST-M1","COST-M3","REL-M5","CMP-M2","AUTHN-M4","AUTHZ-M4","TOL-M5","SCI-M4","INF-M4","SAF-M4","PRI-M3","MEM-M4","EVL-M4","HUM-M4"],"rationale":["Includes every Core gate — regulated systems must still clear production minimums.","Adds residency, fairness, dual control, and signed admission for regulated blast radius.","Requires chaos/continuity drills and independent assessment sampling.","Target capability Level 5 — Tier 3 is not Core with a different label."]},{"id":"aprf-profile-framework","name":"Framework / SDK (primitives)","summary":"Mandatory gates for agent/orchestration SDKs and libraries: execution bounds, tool allowlist/schema hooks, injection mediation, secrets hygiene, and supply chain. This is NOT an APRF Core or Regulated production-readiness gate — assess the customer application with Core/Regulated for that claim.","targetCriticality":2,"targetCapability":3,"mandatoryCheckIds":["AGN-M2","TOL-M2","TOL-M4","SEC-M1","SEC2-M1","SEC2-M2","SCI-M2"],"rationale":["SDK runtimes must enforce finite step/time/spawn bounds (AGN-M2).","Tool allowlists and argument schema validation are framework primitives (TOL-M2/M4).","Untrusted input must not authorize privileged actions via framework mediation (SEC-M1).","Package secrets hygiene and supply-chain review remain library concerns (SEC2/SCI).","Charters, spend, SLOs, and org AuthN/Z are application concerns — not on this profile."]}],"lenses":[{"id":"aprf-lens-rag","name":"RAG","summary":"Retrieval-augmented generation: corpus ownership, context labeling, memory isolation, and retrieval-quality gates.","appliesTo":["RAG","Chatbots","AI Agents"],"recommendedBaseProfileId":"aprf-profile-core","targetCapability":3,"additionalMandatoryCheckIds":["DG-M1","DG-M2","DG-M3","CTX-M1","CTX-M2","CTX-M3","MEM-M1","MEM-M2","MEM-M3","PRI-M1","EVL-M1","EVL-M2","SEC-M1","OBS-M1"],"rationale":["Retrieval corpora need owners, versioning, and promotion controls (DG).","Retrieved content must be sized, labeled, and access-controlled in context (CTX).","Vector/memory stores inherit tenant isolation and retention (MEM).","Eval gates must cover retrieval quality and grounding regressions (EVL)."]},{"id":"aprf-lens-agents","name":"Agents","summary":"Autonomous and tool-using agents: charters, step budgets, tool mediation, human gates, and kill switches.","appliesTo":["AI Agents","Multi-agent systems","MCP Servers","A2A Systems","Coding Agents","Autonomous systems"],"recommendedBaseProfileId":"aprf-profile-core","targetCapability":3,"additionalMandatoryCheckIds":["AGN-M1","AGN-M2","AGN-M3","AGN-M4","TOL-M1","TOL-M2","TOL-M3","TOL-M4","HUM-M1","HUM-M2","HUM-M3","AUTHZ-M1","AUTHZ-M2","AUTHN-M2","COST-M3","OBS-M1","REL-M1","REL-M3"],"rationale":["Every production agent needs a charter and hard step/time limits (AGN).","Tools fail closed with allowlists and schema validation (TOL).","High-impact actions require non-bypassable human approval (HUM).","Agent identities stay least-privilege; loops cannot burn unbounded spend (AUTHZ/COST)."]},{"id":"aprf-lens-voice","name":"Voice","summary":"Voice and telephony AI: session identity, privacy of recordings, latency SLOs, safety, and escalation paths.","appliesTo":["Voice AI","Chatbots"],"recommendedBaseProfileId":"aprf-profile-core","targetCapability":3,"additionalMandatoryCheckIds":["AUTHN-M1","AUTHN-M2","PRI-M1","PRI-M2","OBS-M1","OBS-M2","PERF-M1","PERF-M2","REL-M1","REL-M2","SAF-M1","SAF-M2","HUM-M1","INC-M1","COST-M1","TOL-M1"],"rationale":["Telephony sessions must authenticate before privileged tools (AUTHN).","Call audio and transcripts are sensitive personal data (PRI).","Latency and degraded mode matter more under real-time constraints (PERF/REL).","Safety refusals and human escalation must work on voice channels (SAF/HUM)."]},{"id":"aprf-lens-coding","name":"Coding agents","summary":"IDE and repo-connected coding agents: sandboxing, secret hygiene, tool allowlists, supply chain, and human gates for destructive changes.","appliesTo":["Coding Agents","AI Agents","MCP Servers"],"recommendedBaseProfileId":"aprf-profile-core","targetCapability":3,"additionalMandatoryCheckIds":["AGN-M1","AGN-M3","AGN-M4","TOL-M4","HUM-M2","SEC-M2","SEC-M4","SCI-M1","SCI-M3","PRM-M3","AUTHZ-M3","DX-M1","DX-M2","INF-M2"],"rationale":["Coding agents need explicit charters, kill switches, and peer auth for multi-agent hops (AGN).","Shell/file tools require schema validation and fail-closed allowlists (TOL).","Repo and cloud credentials must stay out of prompts; model path stays bounded (SEC).","Dependency and model supply chain plus platform sandboxes reduce blast radius (SCI/DX/INF)."]}],"crosswalks":[{"id":"nist-ai-rmf","name":"NIST AI Risk Management Framework","peerVersion":"1.0 (2023)","url":"https://www.nist.gov/itl/ai-risk-management-framework","disclaimer":"Informative alignment only. Does not constitute certification, accreditation, or official endorsement.","controls":[{"id":"nist-ai-rmf:govern","ref":"GOVERN","title":"Govern","summary":"Culture, policies, accountability, and continuous improvement for AI risk."},{"id":"nist-ai-rmf:map","ref":"MAP","title":"Map","summary":"Context, intended use, impacts, and risk categorization."},{"id":"nist-ai-rmf:measure","ref":"MEASURE","title":"Measure","summary":"Quantitative and qualitative assessment of AI risks and trustworthiness."},{"id":"nist-ai-rmf:manage","ref":"MANAGE","title":"Manage","summary":"Prioritize, respond to, and recover from AI risks in operation."},{"id":"nist-ai-rmf:safe","ref":"Safe","title":"Safe","summary":"Trustworthiness characteristic — avoid harmful outcomes under intended use."},{"id":"nist-ai-rmf:secure-resilient","ref":"Secure & Resilient","title":"Secure and Resilient"},{"id":"nist-ai-rmf:explainable","ref":"Explainable","title":"Explainable and Interpretable"},{"id":"nist-ai-rmf:privacy","ref":"Privacy-Enhanced","title":"Privacy-Enhanced"},{"id":"nist-ai-rmf:fair","ref":"Fair","title":"Fair — Harmful Bias Managed"},{"id":"nist-ai-rmf:accountable","ref":"Accountable","title":"Accountable and Transparent"}],"mappings":[{"peerControlId":"nist-ai-rmf:govern","aprfPillarSlugs":["organizational-governance","compliance","model-governance","human-approval"],"aprfCheckIds":["ORG-M1","ORG-R2","ORG-R4","CMP-M1","HUM-M1"],"relation":"supports"},{"peerControlId":"nist-ai-rmf:map","aprfPillarSlugs":["model-governance","data-governance","context-engineering","explainability"],"aprfCheckIds":["MOD-M1","DG-M1","CTX-M1","EXP-M1"],"relation":"supports"},{"peerControlId":"nist-ai-rmf:measure","aprfPillarSlugs":["evaluation","observability","performance-slo","safety-responsible-ai"],"aprfCheckIds":["EVL-M1","EVL-M2","OBS-M1","PERF-M1","SAF-M2"],"relation":"supports"},{"peerControlId":"nist-ai-rmf:manage","aprfPillarSlugs":["incident-readiness","change-management","reliability-continuity","tool-safety","agent-governance"],"aprfCheckIds":["INC-M1","INC-M2","CHG-M1","REL-M1","TOL-M1","AGN-M2"],"relation":"supports"},{"peerControlId":"nist-ai-rmf:safe","aprfPillarSlugs":["safety-responsible-ai","evaluation","human-approval"],"aprfCheckIds":["SAF-M1","SAF-M2","SAF-M3","HUM-M3"],"relation":"aligns-with"},{"peerControlId":"nist-ai-rmf:secure-resilient","aprfPillarSlugs":["ai-security","authentication","authorization","secrets","tool-safety","supply-chain","infrastructure","reliability-continuity"],"relation":"aligns-with"},{"peerControlId":"nist-ai-rmf:explainable","aprfPillarSlugs":["explainability","observability"],"aprfCheckIds":["EXP-M1","EXP-M2","OBS-R4"],"relation":"aligns-with"},{"peerControlId":"nist-ai-rmf:privacy","aprfPillarSlugs":["data-privacy","memory-management","context-engineering"],"aprfCheckIds":["PRI-M1","PRI-M2","MEM-M1"],"relation":"aligns-with"},{"peerControlId":"nist-ai-rmf:fair","aprfPillarSlugs":["safety-responsible-ai","evaluation","data-governance"],"aprfCheckIds":["SAF-M3","EVL-M2","DG-M2"],"relation":"partial","note":"APRF covers fairness eval gates; organizational bias programs may need extra controls."},{"peerControlId":"nist-ai-rmf:accountable","aprfPillarSlugs":["organizational-governance","human-approval","explainability","change-management"],"aprfCheckIds":["ORG-R2","HUM-M1","EXP-M3","CHG-M3"],"relation":"supports"}]},{"id":"iso-42001","name":"ISO/IEC 42001","peerVersion":"2023 (clause-level conceptual)","url":"https://www.iso.org/standard/81230.html","disclaimer":"Informative alignment only. Does not constitute certification, accreditation, or official endorsement. Not a substitute for a certified AI management system.","controls":[{"id":"iso-42001:4","ref":"§4","title":"Context of the organization"},{"id":"iso-42001:5","ref":"§5","title":"Leadership"},{"id":"iso-42001:6","ref":"§6","title":"Planning"},{"id":"iso-42001:7","ref":"§7","title":"Support"},{"id":"iso-42001:8","ref":"§8","title":"Operation"},{"id":"iso-42001:9","ref":"§9","title":"Performance evaluation"},{"id":"iso-42001:10","ref":"§10","title":"Improvement"},{"id":"iso-42001:a","ref":"Annex A","title":"AI system controls (selected themes)","summary":"Mapped thematically to APRF domains — not clause-by-clause Annex A enumeration."}],"mappings":[{"peerControlId":"iso-42001:4","aprfPillarSlugs":["organizational-governance","compliance","data-governance"],"aprfCheckIds":["ORG-M1","CMP-M1","DG-M1"],"relation":"aligns-with"},{"peerControlId":"iso-42001:5","aprfPillarSlugs":["organizational-governance","human-approval"],"aprfCheckIds":["ORG-R2","HUM-M1"],"relation":"supports"},{"peerControlId":"iso-42001:6","aprfPillarSlugs":["organizational-governance","safety-responsible-ai","evaluation","cost-optimization"],"aprfCheckIds":["ORG-R4","SAF-M1","EVL-M1","COST-M1"],"relation":"partial","note":"Risk/objectives planning spans org process plus safety and eval gates."},{"peerControlId":"iso-42001:7","aprfPillarSlugs":["platform-engineering","secrets","infrastructure"],"aprfCheckIds":["DX-M1","SEC2-M1","INF-M1"],"relation":"partial","note":"Competence/awareness are org processes; APRF emphasizes platform & secrets support."},{"peerControlId":"iso-42001:8","aprfPillarSlugs":["prompt-engineering","model-governance","change-management","tool-safety","agent-governance","data-privacy"],"relation":"supports"},{"peerControlId":"iso-42001:9","aprfPillarSlugs":["evaluation","observability","performance-slo","compliance"],"aprfCheckIds":["EVL-M1","EVL-M2","OBS-M1","PERF-M1","CMP-M2"],"relation":"supports"},{"peerControlId":"iso-42001:10","aprfPillarSlugs":["incident-readiness","organizational-governance","change-management"],"aprfCheckIds":["INC-M2","ORG-R4","CHG-M1"],"relation":"aligns-with"},{"peerControlId":"iso-42001:a","aprfPillarSlugs":["ai-security","safety-responsible-ai","data-privacy","data-governance","model-governance","human-approval","supply-chain"],"relation":"partial","note":"Annex A themes → APRF security, safety, data, model, human oversight, supply chain."}]},{"id":"owasp-llm-top-10","name":"OWASP Top 10 for Large Language Model Applications","peerVersion":"2025","url":"https://genai.owasp.org/llm-top-10/","disclaimer":"Informative alignment only. Does not constitute certification, accreditation, or official endorsement.","controls":[{"id":"owasp-llm:01","ref":"LLM01","title":"Prompt Injection","relatedPeerControlIds":["aisvs:v1.0-C2.1","aisvs:v1.0-C7.3","aisvs:v1.0-C9.3","aisvs:v1.0-C11.1","aisvs:v1.0-C11.4"]},{"id":"owasp-llm:02","ref":"LLM02","title":"Sensitive Information Disclosure","relatedPeerControlIds":["aisvs:v1.0-C5.2","aisvs:v1.0-C7.3","aisvs:v1.0-C8.1","aisvs:v1.0-C12.1"]},{"id":"owasp-llm:03","ref":"LLM03","title":"Supply Chain","relatedPeerControlIds":["aisvs:v1.0-C6.1","aisvs:v1.0-C6.2","aisvs:v1.0-C3.1"]},{"id":"owasp-llm:04","ref":"LLM04","title":"Data and Model Poisoning","relatedPeerControlIds":["aisvs:v1.0-C1.1","aisvs:v1.0-C1.3","aisvs:v1.0-C3.2","aisvs:v1.0-C11.1"]},{"id":"owasp-llm:05","ref":"LLM05","title":"Improper Output Handling","relatedPeerControlIds":["aisvs:v1.0-C7.1","aisvs:v1.0-C7.2","aisvs:v1.0-C7.3"]},{"id":"owasp-llm:06","ref":"LLM06","title":"Excessive Agency","relatedPeerControlIds":["aisvs:v1.0-C9.1","aisvs:v1.0-C9.2","aisvs:v1.0-C9.3","aisvs:v1.0-C9.5","aisvs:v1.0-C9.6"]},{"id":"owasp-llm:07","ref":"LLM07","title":"System Prompt Leakage","relatedPeerControlIds":["aisvs:v1.0-C2.1","aisvs:v1.0-C5.1","aisvs:v1.0-C7.3"]},{"id":"owasp-llm:08","ref":"LLM08","title":"Vector and Embedding Weaknesses","relatedPeerControlIds":["aisvs:v1.0-C8.1","aisvs:v1.0-C8.2","aisvs:v1.0-C8.3"]},{"id":"owasp-llm:09","ref":"LLM09","title":"Misinformation","relatedPeerControlIds":["aisvs:v1.0-C7.2","aisvs:v1.0-C7.4","aisvs:v1.0-C11.1"]},{"id":"owasp-llm:10","ref":"LLM10","title":"Unbounded Consumption","relatedPeerControlIds":["aisvs:v1.0-C9.1","aisvs:v1.0-C12.3","aisvs:v1.0-C4.1"]}],"mappings":[{"peerControlId":"owasp-llm:01","aprfPillarSlugs":["ai-security","prompt-engineering","tool-safety"],"aprfCheckIds":["SEC-M1","SEC-M3","PRM-M1","TOL-M1"],"relation":"supports"},{"peerControlId":"owasp-llm:02","aprfPillarSlugs":["data-privacy","context-engineering","secrets","memory-management"],"aprfCheckIds":["PRI-M1","PRI-M2","SEC2-M1","MEM-M1"],"relation":"supports"},{"peerControlId":"owasp-llm:03","aprfPillarSlugs":["supply-chain","model-governance","infrastructure"],"aprfCheckIds":["SCI-M1","SCI-M2","MOD-M1"],"relation":"supports"},{"peerControlId":"owasp-llm:04","aprfPillarSlugs":["data-governance","memory-management","model-governance","evaluation"],"aprfCheckIds":["DG-M2","MEM-M2","MOD-R4","EVL-M1"],"relation":"supports"},{"peerControlId":"owasp-llm:05","aprfPillarSlugs":["ai-security","tool-safety","safety-responsible-ai"],"aprfCheckIds":["SEC-M3","TOL-M2","SAF-M1"],"relation":"supports"},{"peerControlId":"owasp-llm:06","aprfPillarSlugs":["tool-safety","agent-governance","human-approval","authorization"],"aprfCheckIds":["TOL-M1","TOL-M2","TOL-M3","AGN-M2","HUM-M1","AUTHZ-M1"],"relation":"supports"},{"peerControlId":"owasp-llm:07","aprfPillarSlugs":["prompt-engineering","ai-security","secrets"],"aprfCheckIds":["PRM-M2","SEC-M1","SEC2-M2"],"relation":"aligns-with"},{"peerControlId":"owasp-llm:08","aprfPillarSlugs":["memory-management","context-engineering","data-governance"],"aprfCheckIds":["MEM-M1","MEM-M3","CTX-M2","DG-M3"],"relation":"supports"},{"peerControlId":"owasp-llm:09","aprfPillarSlugs":["safety-responsible-ai","evaluation","explainability"],"aprfCheckIds":["SAF-M2","EVL-M2","EXP-M1"],"relation":"aligns-with"},{"peerControlId":"owasp-llm:10","aprfPillarSlugs":["cost-optimization","reliability-continuity","performance-slo"],"aprfCheckIds":["COST-M1","COST-M3","REL-M1","PERF-M1"],"relation":"supports","note":"Denial-of-wallet and resource exhaustion — spend ceilings + timeouts."}]},{"id":"aisvs","name":"OWASP AI Application Security Verification Standard (AISVS)","peerVersion":"1.0","url":"https://github.com/OWASP/AISVS/tree/main/1.0/en","disclaimer":"Informative alignment only. Does not constitute certification, accreditation, or official endorsement. Peer control IDs cite OWASP AISVS 1.0 section tags (aisvs:v1.0-C*.*) from the locked 1.0/en tree.","controls":[{"id":"aisvs:v1.0-C1.1","ref":"v1.0-C1.1","title":"Training Data Origin & Data Security"},{"id":"aisvs:v1.0-C1.2","ref":"v1.0-C1.2","title":"Data Labeling and Annotation Security"},{"id":"aisvs:v1.0-C1.3","ref":"v1.0-C1.3","title":"Training Data Quality and Security Assurance"},{"id":"aisvs:v1.0-C2.1","ref":"v1.0-C2.1","title":"Prompt Injection Defenses"},{"id":"aisvs:v1.0-C2.2","ref":"v1.0-C2.2","title":"Content & Policy Screening"},{"id":"aisvs:v1.0-C3.1","ref":"v1.0-C3.1","title":"Model Authorization & Integrity"},{"id":"aisvs:v1.0-C3.2","ref":"v1.0-C3.2","title":"Model Validation & Testing"},{"id":"aisvs:v1.0-C3.3","ref":"v1.0-C3.3","title":"Controlled Deployment & Rollback"},{"id":"aisvs:v1.0-C3.4","ref":"v1.0-C3.4","title":"Secure Development Practices"},{"id":"aisvs:v1.0-C3.5","ref":"v1.0-C3.5","title":"Pipeline Fine-Tuning"},{"id":"aisvs:v1.0-C4.1","ref":"v1.0-C4.1","title":"AI Workload Sandboxing & Validation"},{"id":"aisvs:v1.0-C4.2","ref":"v1.0-C4.2","title":"AI Hardware Security"},{"id":"aisvs:v1.0-C4.3","ref":"v1.0-C4.3","title":"Edge & Distributed AI Security"},{"id":"aisvs:v1.0-C5.1","ref":"v1.0-C5.1","title":"Authentication"},{"id":"aisvs:v1.0-C5.2","ref":"v1.0-C5.2","title":"AI Resource Authorization & Classification"},{"id":"aisvs:v1.0-C5.3","ref":"v1.0-C5.3","title":"Multi-Tenant Isolation"},{"id":"aisvs:v1.0-C6.1","ref":"v1.0-C6.1","title":"Model Artifact Integrity"},{"id":"aisvs:v1.0-C6.2","ref":"v1.0-C6.2","title":"AI BOM & Supply Chain Monitoring"},{"id":"aisvs:v1.0-C7.1","ref":"v1.0-C7.1","title":"Output Format Enforcement"},{"id":"aisvs:v1.0-C7.2","ref":"v1.0-C7.2","title":"Hallucination Detection & Mitigation"},{"id":"aisvs:v1.0-C7.3","ref":"v1.0-C7.3","title":"Output Safety"},{"id":"aisvs:v1.0-C7.4","ref":"v1.0-C7.4","title":"Source Attribution & Citation Integrity"},{"id":"aisvs:v1.0-C8.1","ref":"v1.0-C8.1","title":"Access Controls on Memory & RAG Indices"},{"id":"aisvs:v1.0-C8.2","ref":"v1.0-C8.2","title":"Embedding Sanitization & Validation"},{"id":"aisvs:v1.0-C8.3","ref":"v1.0-C8.3","title":"Memory Expiry & Revocation"},{"id":"aisvs:v1.0-C9.1","ref":"v1.0-C9.1","title":"Execution Budgets, Loop Control, and Circuit Breakers"},{"id":"aisvs:v1.0-C9.2","ref":"v1.0-C9.2","title":"High-Impact Action Approval and Irreversibility Controls"},{"id":"aisvs:v1.0-C9.3","ref":"v1.0-C9.3","title":"Component Isolation and Tool Authorization"},{"id":"aisvs:v1.0-C9.4","ref":"v1.0-C9.4","title":"Agent and Orchestrator Identity"},{"id":"aisvs:v1.0-C9.5","ref":"v1.0-C9.5","title":"Agent Authorization, Delegation, and Continuous Enforcement"},{"id":"aisvs:v1.0-C9.6","ref":"v1.0-C9.6","title":"Shutdown and Graceful Degradation"},{"id":"aisvs:v1.0-C10.1","ref":"v1.0-C10.1","title":"Component Integrity"},{"id":"aisvs:v1.0-C10.2","ref":"v1.0-C10.2","title":"Authentication & Authorization"},{"id":"aisvs:v1.0-C10.3","ref":"v1.0-C10.3","title":"Secure Transport"},{"id":"aisvs:v1.0-C10.4","ref":"v1.0-C10.4","title":"Schema, Message, and Input Validation"},{"id":"aisvs:v1.0-C11.1","ref":"v1.0-C11.1","title":"Model Alignment, Safety, and Robustness Testing and Training"},{"id":"aisvs:v1.0-C11.2","ref":"v1.0-C11.2","title":"Membership-Inference and Model-Inversion Mitigation"},{"id":"aisvs:v1.0-C11.3","ref":"v1.0-C11.3","title":"Model-Extraction Defense"},{"id":"aisvs:v1.0-C11.4","ref":"v1.0-C11.4","title":"Model Runtime Anomaly Detection"},{"id":"aisvs:v1.0-C12.1","ref":"v1.0-C12.1","title":"Request & Response Logging"},{"id":"aisvs:v1.0-C12.2","ref":"v1.0-C12.2","title":"Detection and Alerting"},{"id":"aisvs:v1.0-C12.3","ref":"v1.0-C12.3","title":"Model, Data, and Performance Drift Detection"},{"id":"aisvs:v1.0-C12.4","ref":"v1.0-C12.4","title":"Proactive Security Behavior Monitoring"},{"id":"aisvs:v1.0-C12.5","ref":"v1.0-C12.5","title":"Training Data & Model Lifecycle Audit"}],"mappings":[{"peerControlId":"aisvs:v1.0-C1.1","relation":"supports","aprfPillarSlugs":["data-governance","evaluation","memory-management","model-governance"],"aprfCheckIds":["DG-M2","EVL-M1","MEM-M2","MOD-R4"]},{"peerControlId":"aisvs:v1.0-C1.2","relation":"partial","aprfPillarSlugs":["data-governance","evaluation"],"aprfCheckIds":["DG-M2","EVL-M1"]},{"peerControlId":"aisvs:v1.0-C1.3","relation":"supports","aprfPillarSlugs":["data-governance","evaluation","memory-management","model-governance"],"aprfCheckIds":["DG-M2","EVL-M1","MEM-M2","MOD-R4"]},{"peerControlId":"aisvs:v1.0-C2.1","relation":"supports","aprfPillarSlugs":["ai-security","prompt-engineering","tool-safety","secrets"],"aprfCheckIds":["SEC-M1","PRM-M1","SEC-M3","TOL-M1","PRM-M2","SEC2-M2"]},{"peerControlId":"aisvs:v1.0-C2.2","relation":"partial","aprfPillarSlugs":["ai-security","prompt-engineering"],"aprfCheckIds":["SEC-M1","PRM-M1"]},{"peerControlId":"aisvs:v1.0-C3.1","relation":"supports","aprfPillarSlugs":["model-governance","evaluation","supply-chain","infrastructure"],"aprfCheckIds":["MOD-M1","EVL-M1","SCI-M1","SCI-M2"]},{"peerControlId":"aisvs:v1.0-C3.2","relation":"supports","aprfPillarSlugs":["model-governance","evaluation","data-governance","memory-management"],"aprfCheckIds":["MOD-M1","EVL-M1","DG-M2","MEM-M2","MOD-R4"]},{"peerControlId":"aisvs:v1.0-C3.3","relation":"partial","aprfPillarSlugs":["model-governance","evaluation"],"aprfCheckIds":["MOD-M1","EVL-M1"]},{"peerControlId":"aisvs:v1.0-C3.4","relation":"partial","aprfPillarSlugs":["model-governance","evaluation"],"aprfCheckIds":["MOD-M1","EVL-M1"]},{"peerControlId":"aisvs:v1.0-C3.5","relation":"partial","aprfPillarSlugs":["model-governance","evaluation"],"aprfCheckIds":["MOD-M1","EVL-M1"]},{"peerControlId":"aisvs:v1.0-C4.1","relation":"partial","aprfPillarSlugs":["infrastructure","platform-engineering"],"aprfCheckIds":["INF-M1","INF-M2"]},{"peerControlId":"aisvs:v1.0-C4.2","relation":"partial","aprfPillarSlugs":["infrastructure","platform-engineering"],"aprfCheckIds":["INF-M1","INF-M2"]},{"peerControlId":"aisvs:v1.0-C4.3","relation":"partial","aprfPillarSlugs":["infrastructure","platform-engineering"],"aprfCheckIds":["INF-M1","INF-M2"]},{"peerControlId":"aisvs:v1.0-C5.1","relation":"aligns-with","aprfPillarSlugs":["authentication","authorization","secrets","prompt-engineering","ai-security"],"aprfCheckIds":["AUTHN-M1","AUTHZ-M1","SEC2-M1","PRM-M2","SEC-M1","SEC2-M2"]},{"peerControlId":"aisvs:v1.0-C5.2","relation":"supports","aprfPillarSlugs":["authentication","authorization","secrets","data-privacy","context-engineering","memory-management"],"aprfCheckIds":["AUTHN-M1","AUTHZ-M1","SEC2-M1","PRI-M1","PRI-M2","MEM-M1"]},{"peerControlId":"aisvs:v1.0-C5.3","relation":"partial","aprfPillarSlugs":["authentication","authorization","secrets"],"aprfCheckIds":["AUTHN-M1","AUTHZ-M1","SEC2-M1"]},{"peerControlId":"aisvs:v1.0-C6.1","relation":"supports","aprfPillarSlugs":["supply-chain","model-governance","infrastructure"],"aprfCheckIds":["SCI-M1","MOD-M1","SCI-M2"]},{"peerControlId":"aisvs:v1.0-C6.2","relation":"supports","aprfPillarSlugs":["supply-chain","model-governance","infrastructure"],"aprfCheckIds":["SCI-M1","MOD-M1","SCI-M2"]},{"peerControlId":"aisvs:v1.0-C7.1","relation":"supports","aprfPillarSlugs":["safety-responsible-ai","ai-security","tool-safety"],"aprfCheckIds":["SAF-M1","SEC-M3","TOL-M2"]},{"peerControlId":"aisvs:v1.0-C7.2","relation":"supports","aprfPillarSlugs":["safety-responsible-ai","ai-security","tool-safety","evaluation","explainability"],"aprfCheckIds":["SAF-M1","SEC-M3","TOL-M2","SAF-M2","EVL-M2","EXP-M1"]},{"peerControlId":"aisvs:v1.0-C7.3","relation":"supports","aprfPillarSlugs":["safety-responsible-ai","ai-security","prompt-engineering","tool-safety","data-privacy","context-engineering","secrets","memory-management"],"aprfCheckIds":["SAF-M1","SEC-M3","SEC-M1","PRM-M1","TOL-M1","PRI-M1","PRI-M2","SEC2-M1","MEM-M1","TOL-M2","PRM-M2","SEC2-M2"]},{"peerControlId":"aisvs:v1.0-C7.4","relation":"aligns-with","aprfPillarSlugs":["safety-responsible-ai","ai-security","evaluation","explainability"],"aprfCheckIds":["SAF-M1","SEC-M3","SAF-M2","EVL-M2","EXP-M1"]},{"peerControlId":"aisvs:v1.0-C8.1","relation":"supports","aprfPillarSlugs":["memory-management","context-engineering","data-privacy","secrets","data-governance"],"aprfCheckIds":["MEM-M1","CTX-M2","PRI-M1","PRI-M2","SEC2-M1","MEM-M3","DG-M3"]},{"peerControlId":"aisvs:v1.0-C8.2","relation":"supports","aprfPillarSlugs":["memory-management","context-engineering","data-governance"],"aprfCheckIds":["MEM-M1","CTX-M2","MEM-M3","DG-M3"]},{"peerControlId":"aisvs:v1.0-C8.3","relation":"supports","aprfPillarSlugs":["memory-management","context-engineering","data-governance"],"aprfCheckIds":["MEM-M1","CTX-M2","MEM-M3","DG-M3"]},{"peerControlId":"aisvs:v1.0-C9.1","relation":"supports","aprfPillarSlugs":["agent-governance","tool-safety","human-approval","cost-optimization","reliability-continuity","performance-slo","authorization"],"aprfCheckIds":["AGN-M2","TOL-M1","HUM-M1","COST-M1","COST-M3","REL-M1","PERF-M1","TOL-M2","TOL-M3","AUTHZ-M1"]},{"peerControlId":"aisvs:v1.0-C9.2","relation":"supports","aprfPillarSlugs":["agent-governance","tool-safety","human-approval","authorization"],"aprfCheckIds":["AGN-M2","TOL-M1","HUM-M1","TOL-M2","TOL-M3","AUTHZ-M1"]},{"peerControlId":"aisvs:v1.0-C9.3","relation":"supports","aprfPillarSlugs":["agent-governance","tool-safety","human-approval","ai-security","prompt-engineering","authorization"],"aprfCheckIds":["AGN-M2","TOL-M1","HUM-M1","SEC-M1","SEC-M3","PRM-M1","TOL-M2","TOL-M3","AUTHZ-M1"]},{"peerControlId":"aisvs:v1.0-C9.4","relation":"partial","aprfPillarSlugs":["agent-governance","tool-safety","human-approval"],"aprfCheckIds":["AGN-M2","TOL-M1","HUM-M1"]},{"peerControlId":"aisvs:v1.0-C9.5","relation":"supports","aprfPillarSlugs":["agent-governance","tool-safety","human-approval","authorization"],"aprfCheckIds":["AGN-M2","TOL-M1","HUM-M1","TOL-M2","TOL-M3","AUTHZ-M1"]},{"peerControlId":"aisvs:v1.0-C9.6","relation":"supports","aprfPillarSlugs":["agent-governance","tool-safety","human-approval","authorization"],"aprfCheckIds":["AGN-M2","TOL-M1","HUM-M1","TOL-M2","TOL-M3","AUTHZ-M1"]},{"peerControlId":"aisvs:v1.0-C10.1","relation":"partial","aprfPillarSlugs":["tool-safety","authentication","authorization","ai-security"],"aprfCheckIds":["TOL-M1","TOL-M2","AUTHN-M1","AUTHZ-M1","SEC-M1"]},{"peerControlId":"aisvs:v1.0-C10.2","relation":"partial","aprfPillarSlugs":["tool-safety","authentication","authorization","ai-security"],"aprfCheckIds":["TOL-M1","TOL-M2","AUTHN-M1","AUTHZ-M1","SEC-M1"]},{"peerControlId":"aisvs:v1.0-C10.3","relation":"partial","aprfPillarSlugs":["tool-safety","authentication","authorization","ai-security"],"aprfCheckIds":["TOL-M1","TOL-M2","AUTHN-M1","AUTHZ-M1","SEC-M1"]},{"peerControlId":"aisvs:v1.0-C10.4","relation":"partial","aprfPillarSlugs":["tool-safety","authentication","authorization","ai-security"],"aprfCheckIds":["TOL-M1","TOL-M2","AUTHN-M1","AUTHZ-M1","SEC-M1"]},{"peerControlId":"aisvs:v1.0-C11.1","relation":"supports","aprfPillarSlugs":["ai-security","safety-responsible-ai","model-governance","evaluation","prompt-engineering","tool-safety","data-governance","memory-management","explainability"],"aprfCheckIds":["SEC-M3","SEC-M4","SAF-M1","SAF-M2","EVL-M1","MOD-M1","SEC-M1","PRM-M1","TOL-M1","DG-M2","MEM-M2","MOD-R4","EVL-M2","EXP-M1"]},{"peerControlId":"aisvs:v1.0-C11.2","relation":"partial","aprfPillarSlugs":["ai-security","safety-responsible-ai","model-governance","evaluation"],"aprfCheckIds":["SEC-M3","SEC-M4","SAF-M1","SAF-M2","EVL-M1","MOD-M1"]},{"peerControlId":"aisvs:v1.0-C11.3","relation":"partial","aprfPillarSlugs":["ai-security","safety-responsible-ai","model-governance","evaluation"],"aprfCheckIds":["SEC-M3","SEC-M4","SAF-M1","SAF-M2","EVL-M1","MOD-M1"]},{"peerControlId":"aisvs:v1.0-C11.4","relation":"supports","aprfPillarSlugs":["ai-security","safety-responsible-ai","model-governance","evaluation","prompt-engineering","tool-safety"],"aprfCheckIds":["SEC-M3","SEC-M4","SAF-M1","SAF-M2","EVL-M1","MOD-M1","SEC-M1","PRM-M1","TOL-M1"]},{"peerControlId":"aisvs:v1.0-C12.1","relation":"supports","aprfPillarSlugs":["observability","incident-readiness","data-privacy","context-engineering","secrets","memory-management"],"aprfCheckIds":["OBS-M1","INC-M1","PRI-M1","PRI-M2","SEC2-M1","MEM-M1"]},{"peerControlId":"aisvs:v1.0-C12.2","relation":"partial","aprfPillarSlugs":["observability","incident-readiness"],"aprfCheckIds":["OBS-M1","INC-M1"]},{"peerControlId":"aisvs:v1.0-C12.3","relation":"partial","aprfPillarSlugs":["observability","incident-readiness"],"aprfCheckIds":["OBS-M1","INC-M1"]},{"peerControlId":"aisvs:v1.0-C12.4","relation":"partial","aprfPillarSlugs":["observability","incident-readiness"],"aprfCheckIds":["OBS-M1","INC-M1"]},{"peerControlId":"aisvs:v1.0-C12.5","relation":"partial","aprfPillarSlugs":["observability","incident-readiness"],"aprfCheckIds":["OBS-M1","INC-M1"]}]},{"id":"asvs","name":"OWASP Application Security Verification Standard","peerVersion":"5.0","url":"https://owasp.org/www-project-application-security-verification-standard/","disclaimer":"Informative alignment only. Does not constitute certification, accreditation, or official endorsement.","controls":[{"id":"asvs:V1.1","ref":"V1.1","title":"Encoding and Sanitization Architecture","summary":"Architectural requirements for the order and placement of encoding, escaping, and decoding operations."},{"id":"asvs:V1.2","ref":"V1.2","title":"Injection Prevention","summary":"Output encoding and escaping requirements to prevent injection into interpreters (SQL, HTML, JS, OS, LDAP, etc.)."},{"id":"asvs:V1.3","ref":"V1.3","title":"Sanitization","summary":"Requirements for sanitizing untrusted HTML and dynamic content when encoding is not applicable."},{"id":"asvs:V1.4","ref":"V1.4","title":"Memory, String, and Unmanaged Code","summary":"Requirements for safe memory handling and string operations in unmanaged or low-level code."},{"id":"asvs:V1.5","ref":"V1.5","title":"Safe Deserialization","summary":"Requirements for safely deserializing data from untrusted or external sources."},{"id":"asvs:V10.1","ref":"V10.1","title":"Generic OAuth and OIDC Security","summary":"General security requirements applicable to all OAuth and OIDC implementations."},{"id":"asvs:V10.2","ref":"V10.2","title":"OAuth Client","summary":"Security requirements for applications acting as an OAuth client."},{"id":"asvs:V10.3","ref":"V10.3","title":"OAuth Resource Server","summary":"Security requirements for APIs acting as an OAuth resource server."},{"id":"asvs:V10.4","ref":"V10.4","title":"OAuth Authorization Server","summary":"Security requirements for OAuth authorization servers that issue tokens."},{"id":"asvs:V10.5","ref":"V10.5","title":"OIDC Client","summary":"Security requirements for applications acting as an OIDC relying party (client)."},{"id":"asvs:V10.6","ref":"V10.6","title":"OpenID Provider","summary":"Security requirements for OpenID Providers that authenticate users and issue ID tokens."},{"id":"asvs:V10.7","ref":"V10.7","title":"Consent Management","summary":"Requirements for managing and recording user consent in OAuth and OIDC flows."},{"id":"asvs:V11.1","ref":"V11.1","title":"Cryptographic Inventory and Documentation","summary":"Requirements for documenting and inventorying cryptographic implementations."},{"id":"asvs:V11.2","ref":"V11.2","title":"Secure Cryptography Implementation","summary":"Requirements for correctly implementing cryptographic operations using vetted libraries."},{"id":"asvs:V11.3","ref":"V11.3","title":"Encryption Algorithms","summary":"Requirements for selecting and configuring approved encryption algorithms."},{"id":"asvs:V11.4","ref":"V11.4","title":"Hashing and Hash-based Functions","summary":"Requirements for selecting approved hash functions and HMAC constructions."},{"id":"asvs:V11.5","ref":"V11.5","title":"Random Values","summary":"Requirements for generating cryptographically secure random values."},{"id":"asvs:V11.6","ref":"V11.6","title":"Public Key Cryptography","summary":"Requirements for using public key cryptography for signing and asymmetric encryption."},{"id":"asvs:V11.7","ref":"V11.7","title":"In-Use Data Cryptography","summary":"Requirements for cryptographic protections applied to data while it is actively being used."},{"id":"asvs:V12.1","ref":"V12.1","title":"General TLS Security Guidance","summary":"General requirements for TLS configuration including protocol versions, cipher suites, and certificate management."},{"id":"asvs:V12.2","ref":"V12.2","title":"HTTPS Communication with External Facing Services","summary":"Requirements for HTTPS on externally accessible services, including publicly trusted certificates."},{"id":"asvs:V12.3","ref":"V12.3","title":"General Service to Service Communication Security","summary":"Requirements for encrypted and authenticated communication between internal services and backends."},{"id":"asvs:V13.1","ref":"V13.1","title":"Configuration Documentation","summary":"Requirements for documenting security-relevant configuration decisions."},{"id":"asvs:V13.2","ref":"V13.2","title":"Backend Communication Configuration","summary":"Requirements for securely configuring the application's outbound backend connections."},{"id":"asvs:V13.3","ref":"V13.3","title":"Secret Management","summary":"Requirements for securely storing, accessing, and rotating application secrets and credentials."},{"id":"asvs:V13.4","ref":"V13.4","title":"Unintended Information Leakage","summary":"Requirements for preventing the application from leaking sensitive information through errors, headers, or responses."},{"id":"asvs:V14.1","ref":"V14.1","title":"Data Protection Documentation","summary":"Requirements for identifying, classifying, and documenting protection requirements for sensitive data."},{"id":"asvs:V14.2","ref":"V14.2","title":"General Data Protection","summary":"Requirements for protecting sensitive data from unauthorized access, leakage, and excessive exposure."},{"id":"asvs:V14.3","ref":"V14.3","title":"Client-side Data Protection","summary":"Requirements for protecting sensitive data stored or processed on client devices and browsers."},{"id":"asvs:V15.1","ref":"V15.1","title":"Secure Coding and Architecture Documentation","summary":"Requirements for documenting dependency risk, dangerous functionality, and remediation policies."},{"id":"asvs:V15.2","ref":"V15.2","title":"Security Architecture and Dependencies","summary":"Requirements for dependency management, supply chain security, and architectural isolation of risky components."},{"id":"asvs:V15.3","ref":"V15.3","title":"Defensive Coding","summary":"Requirements for defensive coding practices in security-sensitive code paths."},{"id":"asvs:V15.4","ref":"V15.4","title":"Safe Concurrency","summary":"Requirements for safe concurrency to prevent race conditions and data corruption in multi-threaded code."},{"id":"asvs:V16.1","ref":"V16.1","title":"Security Logging Documentation","summary":"Requirements for documenting logging decisions and defining which events must be recorded."},{"id":"asvs:V16.2","ref":"V16.2","title":"General Logging","summary":"General requirements for what application logs should record and how."},{"id":"asvs:V16.3","ref":"V16.3","title":"Security Events","summary":"Requirements for logging security-relevant events such as authentication, authorization failures, and sensitive actions."},{"id":"asvs:V16.4","ref":"V16.4","title":"Log Protection","summary":"Requirements for protecting log data from tampering, injection, and unauthorized access."},{"id":"asvs:V16.5","ref":"V16.5","title":"Error Handling","summary":"Requirements for handling errors safely without leaking sensitive information to users."},{"id":"asvs:V17.1","ref":"V17.1","title":"TURN Server","summary":"Security requirements for TURN server deployments used in WebRTC applications."},{"id":"asvs:V17.2","ref":"V17.2","title":"Media","summary":"Security requirements for WebRTC media servers handling real-time audio and video streams."},{"id":"asvs:V17.3","ref":"V17.3","title":"Signaling","summary":"Security requirements for WebRTC signaling servers that coordinate peer connections."},{"id":"asvs:V2.1","ref":"V2.1","title":"Validation and Business Logic Documentation","summary":"Requirements for documenting expected inputs and business logic rules."},{"id":"asvs:V2.2","ref":"V2.2","title":"Input Validation","summary":"Requirements for validating input data at application boundaries."},{"id":"asvs:V2.3","ref":"V2.3","title":"Business Logic Security","summary":"Requirements for securing business workflows against manipulation, skipping steps, or race conditions."},{"id":"asvs:V2.4","ref":"V2.4","title":"Anti-automation","summary":"Requirements for protecting against automated abuse, scraping, and excessive requests."},{"id":"asvs:V3.1","ref":"V3.1","title":"Web Frontend Security Documentation","summary":"Requirements for documenting frontend security decisions and browser security configurations."},{"id":"asvs:V3.2","ref":"V3.2","title":"Unintended Content Interpretation","summary":"Requirements to prevent browsers from misinterpreting response content types."},{"id":"asvs:V3.3","ref":"V3.3","title":"Cookie Setup","summary":"Requirements for securely configuring cookie attributes."},{"id":"asvs:V3.4","ref":"V3.4","title":"Browser Security Mechanism Headers","summary":"Requirements for HTTP security headers that instruct browsers to enforce security policies."},{"id":"asvs:V3.5","ref":"V3.5","title":"Browser Origin Separation","summary":"Requirements for enforcing origin boundaries and preventing cross-origin attacks in browsers."},{"id":"asvs:V3.6","ref":"V3.6","title":"External Resource Integrity","summary":"Requirements for verifying the integrity of externally loaded resources."},{"id":"asvs:V3.7","ref":"V3.7","title":"Other Browser Security Considerations","summary":"Miscellaneous browser security requirements not covered by other V3 sections."},{"id":"asvs:V4.1","ref":"V4.1","title":"Generic Web Service Security","summary":"General security requirements applicable to all HTTP-based web services."},{"id":"asvs:V4.2","ref":"V4.2","title":"HTTP Message Structure Validation","summary":"Requirements for validating the structure and fields of HTTP messages."},{"id":"asvs:V4.3","ref":"V4.3","title":"GraphQL","summary":"Security requirements specific to GraphQL APIs."},{"id":"asvs:V4.4","ref":"V4.4","title":"WebSocket","summary":"Security requirements for WebSocket connections and message handling."},{"id":"asvs:V5.1","ref":"V5.1","title":"File Handling Documentation","summary":"Requirements for documenting file handling expectations and security decisions."},{"id":"asvs:V5.2","ref":"V5.2","title":"File Upload and Content","summary":"Requirements for securely accepting and validating user-uploaded files."},{"id":"asvs:V5.3","ref":"V5.3","title":"File Storage","summary":"Requirements for securely storing files and preventing path traversal or server-side execution."},{"id":"asvs:V5.4","ref":"V5.4","title":"File Download","summary":"Requirements for securely serving files to users for download."},{"id":"asvs:V6.1","ref":"V6.1","title":"Authentication Documentation","summary":"Requirements for documenting authentication decisions and mechanisms."},{"id":"asvs:V6.2","ref":"V6.2","title":"Password Security","summary":"Requirements for securely handling user passwords, including storage, policies, and breach detection."},{"id":"asvs:V6.3","ref":"V6.3","title":"General Authentication Security","summary":"General security requirements for all authentication mechanisms."},{"id":"asvs:V6.4","ref":"V6.4","title":"Authentication Factor Lifecycle and Recovery","summary":"Requirements for managing authentication factor enrollment, recovery, and revocation."},{"id":"asvs:V6.5","ref":"V6.5","title":"General Multi-factor Authentication Requirements","summary":"General requirements for implementing multi-factor authentication."},{"id":"asvs:V6.6","ref":"V6.6","title":"Out-of-Band Authentication Mechanisms","summary":"Requirements for authentication mechanisms that use a separate out-of-band channel."},{"id":"asvs:V6.7","ref":"V6.7","title":"Cryptographic Authentication Mechanism","summary":"Requirements for cryptographic authentication mechanisms such as WebAuthn, passkeys, and client certificates."},{"id":"asvs:V6.8","ref":"V6.8","title":"Authentication with an Identity Provider","summary":"Requirements for authenticating users via an external identity provider using federated protocols."},{"id":"asvs:V7.1","ref":"V7.1","title":"Session Management Documentation","summary":"Requirements for documenting session management decisions."},{"id":"asvs:V7.2","ref":"V7.2","title":"Fundamental Session Management Security","summary":"Foundational requirements for creating and issuing secure session tokens."},{"id":"asvs:V7.3","ref":"V7.3","title":"Session Timeout","summary":"Requirements for limiting session duration and implementing idle or absolute timeouts."},{"id":"asvs:V7.4","ref":"V7.4","title":"Session Termination","summary":"Requirements for securely terminating sessions on logout or credential change."},{"id":"asvs:V7.5","ref":"V7.5","title":"Defenses Against Session Abuse","summary":"Requirements for detecting and preventing session theft, fixation, and hijacking."},{"id":"asvs:V7.6","ref":"V7.6","title":"Federated Re-authentication","summary":"Requirements for session management in federated identity and SSO scenarios."},{"id":"asvs:V8.1","ref":"V8.1","title":"Authorization Documentation","summary":"Requirements for documenting authorization rules and decision factors."},{"id":"asvs:V8.2","ref":"V8.2","title":"General Authorization Design","summary":"Requirements for function-level, data-level, and field-level access control enforcement."},{"id":"asvs:V8.3","ref":"V8.3","title":"Operation Level Authorization","summary":"Requirements for enforcing authorization at the correct service tier and handling permission changes promptly."},{"id":"asvs:V8.4","ref":"V8.4","title":"Other Authorization Considerations","summary":"Additional authorization requirements for multi-tenant systems and administrative interfaces."},{"id":"asvs:V9.1","ref":"V9.1","title":"Token Source and Integrity","summary":"Requirements for verifying the source, signature, and integrity of self-contained tokens."},{"id":"asvs:V9.2","ref":"V9.2","title":"Token Content","summary":"Requirements for the content, claims, and lifetime of self-contained tokens."}],"mappings":[{"peerControlId":"asvs:V1.1","relation":"partial","aprfCheckIds":["SEC-M1","PRM-M1"]},{"peerControlId":"asvs:V1.2","relation":"partial","aprfCheckIds":["SEC-M1","PRM-M1"]},{"peerControlId":"asvs:V1.3","relation":"partial","aprfCheckIds":["SEC-M1","PRM-M1"]},{"peerControlId":"asvs:V1.4","relation":"partial","aprfCheckIds":["SEC-M1","PRM-M1"]},{"peerControlId":"asvs:V1.5","relation":"partial","aprfCheckIds":["SEC-M1","PRM-M1"]},{"peerControlId":"asvs:V10.1","relation":"aligns-with","aprfCheckIds":["AUTHN-M1","AUTHZ-M1"]},{"peerControlId":"asvs:V10.2","relation":"aligns-with","aprfCheckIds":["AUTHN-M1","AUTHZ-M1"]},{"peerControlId":"asvs:V10.3","relation":"aligns-with","aprfCheckIds":["AUTHN-M1","AUTHZ-M1"]},{"peerControlId":"asvs:V10.4","relation":"aligns-with","aprfCheckIds":["AUTHN-M1","AUTHZ-M1"]},{"peerControlId":"asvs:V10.5","relation":"aligns-with","aprfCheckIds":["AUTHN-M1","AUTHZ-M1"]},{"peerControlId":"asvs:V10.6","relation":"aligns-with","aprfCheckIds":["AUTHN-M1","AUTHZ-M1"]},{"peerControlId":"asvs:V10.7","relation":"aligns-with","aprfCheckIds":["AUTHN-M1","AUTHZ-M1"]},{"peerControlId":"asvs:V11.1","relation":"partial","aprfCheckIds":["SEC2-M1","INF-M2"]},{"peerControlId":"asvs:V11.2","relation":"partial","aprfCheckIds":["SEC2-M1","INF-M2"]},{"peerControlId":"asvs:V11.3","relation":"partial","aprfCheckIds":["SEC2-M1","INF-M2"]},{"peerControlId":"asvs:V11.4","relation":"partial","aprfCheckIds":["SEC2-M1","INF-M2"]},{"peerControlId":"asvs:V11.5","relation":"partial","aprfCheckIds":["SEC2-M1","INF-M2"]},{"peerControlId":"asvs:V11.6","relation":"partial","aprfCheckIds":["SEC2-M1","INF-M2"]},{"peerControlId":"asvs:V11.7","relation":"partial","aprfCheckIds":["SEC2-M1","INF-M2"]},{"peerControlId":"asvs:V12.1","relation":"aligns-with","aprfCheckIds":["INF-M1","INF-M2"]},{"peerControlId":"asvs:V12.2","relation":"aligns-with","aprfCheckIds":["INF-M1","INF-M2"]},{"peerControlId":"asvs:V12.3","relation":"aligns-with","aprfCheckIds":["INF-M1","INF-M2"]},{"peerControlId":"asvs:V13.1","relation":"partial","aprfCheckIds":["INF-M1","CHG-M1"]},{"peerControlId":"asvs:V13.2","relation":"partial","aprfCheckIds":["INF-M1","CHG-M1"]},{"peerControlId":"asvs:V13.3","relation":"partial","aprfCheckIds":["INF-M1","CHG-M1"]},{"peerControlId":"asvs:V13.4","relation":"partial","aprfCheckIds":["INF-M1","CHG-M1"]},{"peerControlId":"asvs:V14.1","relation":"aligns-with","aprfCheckIds":["PRI-M1","DG-M1"]},{"peerControlId":"asvs:V14.2","relation":"aligns-with","aprfCheckIds":["PRI-M1","DG-M1"]},{"peerControlId":"asvs:V14.3","relation":"aligns-with","aprfCheckIds":["PRI-M1","DG-M1"]},{"peerControlId":"asvs:V15.1","relation":"partial","aprfCheckIds":["SEC-M1","CHG-M1"]},{"peerControlId":"asvs:V15.2","relation":"partial","aprfCheckIds":["SEC-M1","CHG-M1"]},{"peerControlId":"asvs:V15.3","relation":"partial","aprfCheckIds":["SEC-M1","CHG-M1"]},{"peerControlId":"asvs:V15.4","relation":"partial","aprfCheckIds":["SEC-M1","CHG-M1"]},{"peerControlId":"asvs:V16.1","relation":"aligns-with","aprfCheckIds":["OBS-M1","INC-M1"]},{"peerControlId":"asvs:V16.2","relation":"aligns-with","aprfCheckIds":["OBS-M1","INC-M1"]},{"peerControlId":"asvs:V16.3","relation":"aligns-with","aprfCheckIds":["OBS-M1","INC-M1"]},{"peerControlId":"asvs:V16.4","relation":"aligns-with","aprfCheckIds":["OBS-M1","INC-M1"]},{"peerControlId":"asvs:V16.5","relation":"aligns-with","aprfCheckIds":["OBS-M1","INC-M1"]},{"peerControlId":"asvs:V17.1","relation":"partial","aprfCheckIds":["INF-M1","REL-M1"]},{"peerControlId":"asvs:V17.2","relation":"partial","aprfCheckIds":["INF-M1","REL-M1"]},{"peerControlId":"asvs:V17.3","relation":"partial","aprfCheckIds":["INF-M1","REL-M1"]},{"peerControlId":"asvs:V2.1","relation":"partial","aprfCheckIds":["SEC-M1","TOL-M2"]},{"peerControlId":"asvs:V2.2","relation":"partial","aprfCheckIds":["SEC-M1","TOL-M2"]},{"peerControlId":"asvs:V2.3","relation":"partial","aprfCheckIds":["SEC-M1","TOL-M2"]},{"peerControlId":"asvs:V2.4","relation":"partial","aprfCheckIds":["SEC-M1","TOL-M2"]},{"peerControlId":"asvs:V3.1","relation":"partial","aprfCheckIds":["SEC-M3","TOL-M2"]},{"peerControlId":"asvs:V3.2","relation":"partial","aprfCheckIds":["SEC-M3","TOL-M2"]},{"peerControlId":"asvs:V3.3","relation":"partial","aprfCheckIds":["SEC-M3","TOL-M2"]},{"peerControlId":"asvs:V3.4","relation":"partial","aprfCheckIds":["SEC-M3","TOL-M2"]},{"peerControlId":"asvs:V3.5","relation":"partial","aprfCheckIds":["SEC-M3","TOL-M2"]},{"peerControlId":"asvs:V3.6","relation":"partial","aprfCheckIds":["SEC-M3","TOL-M2"]},{"peerControlId":"asvs:V3.7","relation":"partial","aprfCheckIds":["SEC-M3","TOL-M2"]},{"peerControlId":"asvs:V4.1","relation":"aligns-with","aprfCheckIds":["AUTHZ-M1","SEC-M1"]},{"peerControlId":"asvs:V4.2","relation":"aligns-with","aprfCheckIds":["AUTHZ-M1","SEC-M1"]},{"peerControlId":"asvs:V4.3","relation":"aligns-with","aprfCheckIds":["AUTHZ-M1","SEC-M1"]},{"peerControlId":"asvs:V4.4","relation":"aligns-with","aprfCheckIds":["AUTHZ-M1","SEC-M1"]},{"peerControlId":"asvs:V5.1","relation":"partial","aprfCheckIds":["INF-M1","DG-M3"]},{"peerControlId":"asvs:V5.2","relation":"partial","aprfCheckIds":["INF-M1","DG-M3"]},{"peerControlId":"asvs:V5.3","relation":"partial","aprfCheckIds":["INF-M1","DG-M3"]},{"peerControlId":"asvs:V5.4","relation":"partial","aprfCheckIds":["INF-M1","DG-M3"]},{"peerControlId":"asvs:V6.1","relation":"aligns-with","aprfCheckIds":["AUTHN-M1","AUTHN-M3","SEC2-M1"]},{"peerControlId":"asvs:V6.2","relation":"aligns-with","aprfCheckIds":["AUTHN-M1","AUTHN-M3","SEC2-M1"]},{"peerControlId":"asvs:V6.3","relation":"aligns-with","aprfCheckIds":["AUTHN-M1","AUTHN-M3","SEC2-M1"]},{"peerControlId":"asvs:V6.4","relation":"aligns-with","aprfCheckIds":["AUTHN-M1","AUTHN-M3","SEC2-M1"]},{"peerControlId":"asvs:V6.5","relation":"aligns-with","aprfCheckIds":["AUTHN-M1","AUTHN-M3","SEC2-M1"]},{"peerControlId":"asvs:V6.6","relation":"aligns-with","aprfCheckIds":["AUTHN-M1","AUTHN-M3","SEC2-M1"]},{"peerControlId":"asvs:V6.7","relation":"aligns-with","aprfCheckIds":["AUTHN-M1","AUTHN-M3","SEC2-M1"]},{"peerControlId":"asvs:V6.8","relation":"aligns-with","aprfCheckIds":["AUTHN-M1","AUTHN-M3","SEC2-M1"]},{"peerControlId":"asvs:V7.1","relation":"aligns-with","aprfCheckIds":["AUTHN-M1","AUTHZ-M1"]},{"peerControlId":"asvs:V7.2","relation":"aligns-with","aprfCheckIds":["AUTHN-M1","AUTHZ-M1"]},{"peerControlId":"asvs:V7.3","relation":"aligns-with","aprfCheckIds":["AUTHN-M1","AUTHZ-M1"]},{"peerControlId":"asvs:V7.4","relation":"aligns-with","aprfCheckIds":["AUTHN-M1","AUTHZ-M1"]},{"peerControlId":"asvs:V7.5","relation":"aligns-with","aprfCheckIds":["AUTHN-M1","AUTHZ-M1"]},{"peerControlId":"asvs:V7.6","relation":"aligns-with","aprfCheckIds":["AUTHN-M1","AUTHZ-M1"]},{"peerControlId":"asvs:V8.1","relation":"aligns-with","aprfCheckIds":["AUTHZ-M1","AUTHZ-M2"]},{"peerControlId":"asvs:V8.2","relation":"aligns-with","aprfCheckIds":["AUTHZ-M1","AUTHZ-M2"]},{"peerControlId":"asvs:V8.3","relation":"aligns-with","aprfCheckIds":["AUTHZ-M1","AUTHZ-M2"]},{"peerControlId":"asvs:V8.4","relation":"aligns-with","aprfCheckIds":["AUTHZ-M1","AUTHZ-M2"]},{"peerControlId":"asvs:V9.1","relation":"aligns-with","aprfCheckIds":["AUTHN-M2","SEC2-M1"]},{"peerControlId":"asvs:V9.2","relation":"aligns-with","aprfCheckIds":["AUTHN-M2","SEC2-M1"]}]},{"id":"opencre","name":"OpenCRE (Open Common Requirements Enumeration)","peerVersion":"CWE bridge set","url":"https://www.opencre.org/","disclaimer":"Informative alignment only. Does not constitute certification, accreditation, or official endorsement.","controls":[{"id":"opencre:CWE-16","ref":"CWE-16","title":"Configuration","summary":"Security misconfiguration occurs when applications, frameworks, or infrastructure use insecure defaults, unnecessary features, or improperly configured security controls. OpenCRE: 180-488, 462-245, 623-347"},{"id":"opencre:CWE-200","ref":"CWE-200","title":"Exposure of Sensitive Information","summary":"Sensitive information exposure occurs when applications inadvertently reveal data that can be used by attackers — through error messages, logs, API responses, or verbose configurations. OpenCRE: 713-683, 743-110, 227-045"},{"id":"opencre:CWE-22","ref":"CWE-22","title":"Path Traversal","summary":"Path traversal occurs when user-controlled input is used to construct file paths without canonicalization, allowing access to files outside intended directories. OpenCRE: 675-168"},{"id":"opencre:CWE-287","ref":"CWE-287","title":"Improper Authentication","summary":"Improper authentication allows attackers to bypass identity verification, impersonate users, or access protected resources without valid credentials. OpenCRE: 813-610, 605-735, 816-631"},{"id":"opencre:CWE-327","ref":"CWE-327","title":"Use of a Broken or Risky Cryptographic Algorithm","summary":"Use of broken or risky cryptographic algorithms undermines data confidentiality and integrity, allowing attackers to decrypt, forge, or tamper with protected data. OpenCRE: 742-431, 002-801, 504-340"},{"id":"opencre:CWE-352","ref":"CWE-352","title":"Cross-Site Request Forgery (CSRF)","summary":"CSRF forces authenticated users to submit unintended requests, enabling attackers to perform state-changing actions on behalf of victims. OpenCRE: 464-084, 060-472"},{"id":"opencre:CWE-384","ref":"CWE-384","title":"Session Fixation","summary":"Session fixation allows attackers to set a victim's session identifier before authentication, then hijack the authenticated session. OpenCRE: 002-630"},{"id":"opencre:CWE-502","ref":"CWE-502","title":"Deserialization of Untrusted Data","summary":"Deserialization of untrusted data can lead to remote code execution, object injection, or denial of service when applications reconstruct objects from attacker-controlled serialized input. OpenCRE: 831-563, 736-554, 762-616"},{"id":"opencre:CWE-778","ref":"CWE-778","title":"Insufficient Logging","summary":"Insufficient logging prevents detection of security breaches, hinders forensic analysis, and delays incident response when critical security events go unrecorded. OpenCRE: 184-284, 841-710, 555-048"},{"id":"opencre:CWE-78","ref":"CWE-78","title":"OS Command Injection","summary":"OS command injection occurs when untrusted data is passed to system shell commands without proper sanitization, allowing attackers to run arbitrary commands. OpenCRE: 857-718, 683-722"},{"id":"opencre:CWE-79","ref":"CWE-79","title":"Cross-site Scripting (XSS)","summary":"Cross-site scripting occurs when untrusted data is included in web output without proper encoding, allowing attackers to run scripts in victim browsers. OpenCRE: 366-835"},{"id":"opencre:CWE-798","ref":"CWE-798","title":"Use of Hard-coded Credentials","summary":"Hard-coded credentials in source code, configuration files, or system prompts can be extracted by attackers to gain unauthorized access to systems and services. OpenCRE: 551-054, 774-888, 340-375"},{"id":"opencre:CWE-89","ref":"CWE-89","title":"SQL Injection","summary":"SQL injection occurs when untrusted data is sent to a database interpreter as part of a query, allowing attackers to read, modify, or delete data. OpenCRE: 064-808, 732-873"}],"mappings":[{"peerControlId":"opencre:CWE-16","relation":"partial","aprfPillarSlugs":["infrastructure","change-management"],"aprfCheckIds":["INF-M1","CHG-M1"]},{"peerControlId":"opencre:CWE-200","relation":"aligns-with","aprfPillarSlugs":["data-privacy","secrets"],"aprfCheckIds":["PRI-M1","SEC2-M1","SEC2-M2"]},{"peerControlId":"opencre:CWE-22","relation":"partial","aprfPillarSlugs":["ai-security","tool-safety"],"aprfCheckIds":["SEC-M1","TOL-M1"]},{"peerControlId":"opencre:CWE-287","relation":"aligns-with","aprfPillarSlugs":["authentication"],"aprfCheckIds":["AUTHN-M1","AUTHN-M2","AUTHN-M3"]},{"peerControlId":"opencre:CWE-327","relation":"partial","aprfPillarSlugs":["secrets","infrastructure"],"aprfCheckIds":["SEC2-M1","INF-M2"]},{"peerControlId":"opencre:CWE-352","relation":"partial","aprfPillarSlugs":["authentication","authorization"],"aprfCheckIds":["AUTHN-M1","AUTHZ-M1"]},{"peerControlId":"opencre:CWE-384","relation":"partial","aprfPillarSlugs":["authentication","authorization"],"aprfCheckIds":["AUTHN-M1","AUTHZ-M2"]},{"peerControlId":"opencre:CWE-502","relation":"partial","aprfPillarSlugs":["tool-safety","ai-security"],"aprfCheckIds":["TOL-M2","SEC-M1"]},{"peerControlId":"opencre:CWE-778","relation":"aligns-with","aprfPillarSlugs":["observability","incident-readiness"],"aprfCheckIds":["OBS-M1","INC-M1"]},{"peerControlId":"opencre:CWE-78","relation":"aligns-with","aprfPillarSlugs":["tool-safety","ai-security"],"aprfCheckIds":["TOL-M1","TOL-M2","SEC-M1"]},{"peerControlId":"opencre:CWE-79","relation":"partial","aprfPillarSlugs":["ai-security","tool-safety"],"aprfCheckIds":["SEC-M3","TOL-M2"]},{"peerControlId":"opencre:CWE-798","relation":"aligns-with","aprfPillarSlugs":["secrets"],"aprfCheckIds":["SEC2-M1","SEC2-M2"]},{"peerControlId":"opencre:CWE-89","relation":"partial","aprfPillarSlugs":["tool-safety","data-governance"],"aprfCheckIds":["TOL-M1","DG-M3"]}]},{"id":"maestro","name":"CSA MAESTRO (Multi-Agentic Threat Model)","peerVersion":"7-layer architecture + extended multi-agent threats","url":"https://cloudsecurityalliance.org/","disclaimer":"Informative alignment only. Does not constitute certification, accreditation, or official endorsement.","controls":[{"id":"maestro:L1","ref":"L1","title":"Foundation Models","summary":"Core LLMs, model APIs, inference engines."},{"id":"maestro:L2","ref":"L2","title":"Data Operations","summary":"Memory stores, vector databases, RAG pipelines, context management."},{"id":"maestro:L3","ref":"L3","title":"Agent Frameworks","summary":"Orchestration logic, agent-tool bindings, routing decisions."},{"id":"maestro:L4","ref":"L4","title":"Deployment & Infrastructure","summary":"Containers, orchestration, cloud/on-premise resources."},{"id":"maestro:L5","ref":"L5","title":"Evaluation & Observability","summary":"Monitoring, metrics, anomaly detection, performance tracking."},{"id":"maestro:L6","ref":"L6","title":"Security & Compliance","summary":"Cross-cutting security controls and compliance frameworks."},{"id":"maestro:L7","ref":"L7","title":"Agent Ecosystem","summary":"User-facing applications, agent marketplace, business integrations."},{"id":"maestro:reasoning-collapse","ref":"reasoning-collapse","title":"Reasoning Collapse","summary":"Chain-of-thought breakdowns across agent delegation."},{"id":"maestro:emergent-covert-coordination","ref":"emergent-covert-coordination","title":"Emergent Covert Coordination","summary":"Autonomous symbolic protocol development between agents."},{"id":"maestro:heterogeneous-multi-agent-exploits","ref":"heterogeneous-multi-agent-exploits","title":"Heterogeneous Multi-Agent Exploits","summary":"Coordinated attacks using diverse agent capabilities."},{"id":"maestro:goal-drift","ref":"goal-drift","title":"Goal Drift in Delegated Chains","summary":"Intent mutation through agent handoffs."},{"id":"maestro:trust-misuse","ref":"trust-misuse","title":"Trust Misuse Between Legitimate Agents","summary":"Strategic misreporting within valid roles."}],"mappings":[{"peerControlId":"maestro:L1","relation":"supports","aprfPillarSlugs":["model-governance","ai-security","supply-chain"],"aprfCheckIds":["MOD-M1","SCI-M1","SEC-M3"]},{"peerControlId":"maestro:L2","relation":"supports","aprfPillarSlugs":["memory-management","context-engineering","data-governance"],"aprfCheckIds":["MEM-M1","MEM-M3","CTX-M2","DG-M3"]},{"peerControlId":"maestro:L3","relation":"supports","aprfPillarSlugs":["agent-governance","tool-safety"],"aprfCheckIds":["AGN-M1","AGN-M2","TOL-M1","TOL-M3"]},{"peerControlId":"maestro:L4","relation":"supports","aprfPillarSlugs":["infrastructure","platform-engineering","supply-chain"],"aprfCheckIds":["INF-M1","INF-M2","SCI-M2"]},{"peerControlId":"maestro:L5","relation":"supports","aprfPillarSlugs":["observability","evaluation","performance-slo"],"aprfCheckIds":["OBS-M1","EVL-M1","PERF-M1"]},{"peerControlId":"maestro:L6","relation":"supports","aprfPillarSlugs":["ai-security","compliance","organizational-governance"],"aprfCheckIds":["SEC-M1","SEC-M4","CMP-M1"]},{"peerControlId":"maestro:L7","relation":"supports","aprfPillarSlugs":["agent-governance","human-approval","authorization"],"aprfCheckIds":["AGN-M1","HUM-M1","AUTHZ-M1"]},{"peerControlId":"maestro:reasoning-collapse","relation":"aligns-with","aprfPillarSlugs":["agent-governance","evaluation","explainability"],"aprfCheckIds":["AGN-M2","EVL-M2","EXP-M1"]},{"peerControlId":"maestro:emergent-covert-coordination","relation":"aligns-with","aprfPillarSlugs":["agent-governance","ai-security","observability"],"aprfCheckIds":["AGN-M1","SEC-M4","OBS-M1"]},{"peerControlId":"maestro:heterogeneous-multi-agent-exploits","relation":"aligns-with","aprfPillarSlugs":["agent-governance","tool-safety","ai-security"],"aprfCheckIds":["AGN-M1","TOL-M1","SEC-M1","SEC-M3"]},{"peerControlId":"maestro:goal-drift","relation":"aligns-with","aprfPillarSlugs":["agent-governance","human-approval","evaluation"],"aprfCheckIds":["AGN-M2","HUM-M1","EVL-M1"]},{"peerControlId":"maestro:trust-misuse","relation":"aligns-with","aprfPillarSlugs":["agent-governance","authorization","observability"],"aprfCheckIds":["AGN-M1","AUTHZ-M1","OBS-M1"]}]},{"id":"fiasse","name":"OWASP FIASSE / SSEM","peerVersion":"1.0.4","url":"https://owasp.org/www-project-fiasse/","disclaimer":"Informative alignment only. Does not constitute certification, accreditation, or official endorsement.","controls":[{"id":"fiasse:S1.1","ref":"S1.1","title":"The Application Security Challenge","summary":"The core challenge: organizations invest significantly in AppSec yet often see limited outcomes. Shift-left has underdelivered, AI code generation amplifies risk, and developers lack deep security expertise."},{"id":"fiasse:S1.2","ref":"S1.2","title":"Document Purpose and Scope","summary":"Defines FIASSE as the overarching strategic framework and SSEM as the design language model within it. Introduces the deliberate term 'securable' over 'secure'."},{"id":"fiasse:S2.1","ref":"S2.1","title":"The Securable Paradigm: No Static Secure State","summary":"There is no static state of secure. Software must be built with inherent qualities that enable it to adapt to evolving threats."},{"id":"fiasse:S2.2","ref":"S2.2","title":"Resiliently Add Computing Value","summary":"The primary directive: resiliently add computing value -- code that is robust enough to withstand change, stress, and attack."},{"id":"fiasse:S2.3","ref":"S2.3","title":"Security Mission: Reducing Material Impact","summary":"The core mission is to reduce the probability of material impact of a cyber event. Security strategies must align with business objectives."},{"id":"fiasse:S2.4","ref":"S2.4","title":"Aligning Security with Development","summary":"Security and development are complementary disciplines. True alignment uses established software engineering terms and engages AppSec early (Participation over Assessment)."},{"id":"fiasse:S2.5","ref":"S2.5","title":"The Transparency Principle","summary":"Transparency is a foundational engineering strategy: designing systems so internal state and behavior are observable and understandable to authorized parties."},{"id":"fiasse:S2.6","ref":"S2.6","title":"The Principle of Least Astonishment","summary":"Systems should behave in ways that are intuitive and predictable. POLA supports Analyzability, Modifiability, and clearer security boundaries; it works in concert with the Transparency Principle."},{"id":"fiasse:S3.1","ref":"S3.1","title":"Model Overview and Design Language","summary":"SSEM provides a design language using established software engineering terms. Ten attributes grouped into three pillars (Maintainability, Trustworthiness, Reliability)."},{"id":"fiasse:S3.2.1.1","ref":"S3.2.1.1","title":"Analyzability","summary":"The ability to locate the cause of a behavior within the code. Drives the speed and accuracy of vulnerability remediation."},{"id":"fiasse:S3.2.1.2","ref":"S3.2.1.2","title":"Modifiability","summary":"The ability to change code without breaking existing functionality or introducing new vulnerabilities. Enables rapid response to evolving threats."},{"id":"fiasse:S3.2.1.3","ref":"S3.2.1.3","title":"Testability","summary":"The ability to write a test for a piece of code without modifying the code under test. Enables continuous verification of security controls."},{"id":"fiasse:S3.2.1.4","ref":"S3.2.1.4","title":"Observability","summary":"The degree to which the internal state of a system can be inferred from its external outputs. Achieved through code-level instrumentation: structured logging, monitoring, instrumentation, and UI feedback."},{"id":"fiasse:S3.2.1","ref":"S3.2.1","title":"Maintainability","summary":"Maintainability encompasses Analyzability, Modifiability, Testability, and Observability -- the ability to evolve, correct, adapt, and observe software in operation."},{"id":"fiasse:S3.2.2.1","ref":"S3.2.2.1","title":"Confidentiality","summary":"Property that information is not disclosed to unauthorized individuals, entities, or processes. Achieved through inherent protective qualities, not overlaid controls alone."},{"id":"fiasse:S3.2.2.2","ref":"S3.2.2.2","title":"Accountability","summary":"Every action within a system is attributable to a specific, identified entity. Enables auditing and incident response."},{"id":"fiasse:S3.2.2.3","ref":"S3.2.2.3","title":"Authenticity","summary":"The property that an entity is what it claims to be. Includes Defendable Authentication, digital signatures, and supporting non-repudiation."},{"id":"fiasse:S3.2.2","ref":"S3.2.2","title":"Trustworthiness","summary":"Trustworthiness encompasses Confidentiality, Accountability, and Authenticity -- the ability to meet stakeholder expectations in a verifiable way."},{"id":"fiasse:S3.2.3.1","ref":"S3.2.3.1","title":"Availability","summary":"Property of being accessible and usable on demand by authorized entities, including during adverse circumstances."},{"id":"fiasse:S3.2.3.2","ref":"S3.2.3.2","title":"Integrity","summary":"Property of accuracy and completeness. Applies at both system and data levels; supported by the Derived Integrity Principle (Section 4.4.1.2)."},{"id":"fiasse:S3.2.3.3","ref":"S3.2.3.3","title":"Resilience","summary":"The ability of a system to continue operating during and after failure, and to recover. Includes fault tolerance, defensive coding, and strong trust boundaries."},{"id":"fiasse:S3.2.3","ref":"S3.2.3","title":"Reliability","summary":"Reliability encompasses Availability, Integrity, and Resilience -- consistent and predictable operation under adverse conditions."},{"id":"fiasse:S3.2","ref":"S3.2","title":"Core Securable Attributes","summary":"The building blocks of securable software: tangible characteristics that contribute directly to a system's security and resilience."},{"id":"fiasse:S4.1.1","ref":"S4.1.1","title":"Proactive Communication","summary":"Inform development teams about new initiatives, demonstrate tools, and maintain regular synchronization to sustain partnership."},{"id":"fiasse:S4.1.2","ref":"S4.1.2","title":"Integrating Security into Requirements","summary":"Active AppSec participation in requirements gathering. Key deliverables: Security Features, Threat Scenarios, and Security Acceptance Criteria."},{"id":"fiasse:S4.1","ref":"S4.1","title":"Establishing Clear Expectations","summary":"Clear expectations through proactive communication and integrating security into requirements (features, threat scenarios, acceptance criteria)."},{"id":"fiasse:S4.2.1","ref":"S4.2.1","title":"Code-Level Threat Awareness","summary":"Lightweight, continuous practice of asking 'What can go wrong?' at the code level. Findings that reveal design-level concerns must escalate into the formal threat model."},{"id":"fiasse:S4.2.2","ref":"S4.2.2","title":"Threat Modeling Solution Framework","summary":"Use SSEM (especially Trustworthiness and Reliability) to find inherent architectural solutions; gaps that cannot be addressed inherently become explicit security requirements."},{"id":"fiasse:S4.2","ref":"S4.2","title":"Threat Modeling","summary":"Two distinct activities: formal Threat Modeling at the system/feature level, and continuous lightweight Threat Awareness at the code level."},{"id":"fiasse:S4.3","ref":"S4.3","title":"The Boundary Control Principle","summary":"Flexibility within the interior is an engineering asset; control at every trust boundary is a security requirement. Harden the shell, keep the interior flexible. (Formerly called 'The Flexibility Principle'.)"},{"id":"fiasse:S4.4.1.1","ref":"S4.4.1.1","title":"The Request Surface Minimization Principle","summary":"Process only the specific named values expected. Log or reject deviations; in sensitive contexts, log-and-reject is the more defensible posture."},{"id":"fiasse:S4.4.1.2","ref":"S4.4.1.2","title":"The Derived Integrity Principle","summary":"Any value critical to system or business-logic integrity must be derived in a trusted context, never accepted from a client. The client expresses intent; the server enforces integrity."},{"id":"fiasse:S4.4.1","ref":"S4.4.1","title":"Canonical Input Handling","summary":"Apply minimum acceptable range at the point of input through canonicalization/normalization, validation, and sanitization."},{"id":"fiasse:S4.4","ref":"S4.4","title":"Resilient Coding","summary":"Defensive coding practices that produce predictable, recoverable behavior: strong typing, input validation, output encoding, safe resource management, graceful and secure failure, and least privilege at the code level."},{"id":"fiasse:S4.5","ref":"S4.5","title":"Dependency Management","summary":"Evaluate dependencies against SSEM attributes before introduction. Minimize dependencies, update regularly, go beyond CVE scanning."},{"id":"fiasse:S4.6","ref":"S4.6","title":"Dependency Stewardship","summary":"The ongoing application of SSEM attributes to dependency selection, integration, monitoring, and lifecycle management. Stewardship asks: would this dependency be responsible, maintainable, and trustworthy now and over time?"},{"id":"fiasse:S5.1","ref":"S5.1","title":"Natively Extending Development Processes","summary":"Integrate security into existing workflows rather than imposing separate gates. Security as partner in design, not external assessor."},{"id":"fiasse:S5.2","ref":"S5.2","title":"The Role of Merge Reviews","summary":"Merge reviews are an effective scaling point for securable review and knowledge transfer. SSEM attributes provide a shared review basis."},{"id":"fiasse:S5.3","ref":"S5.3","title":"Early Integration: Planning and Requirements","summary":"Set security expectations at planning and requirements. Active AppSec participation in requirements (Section 4.1.2) is the primary mechanism."},{"id":"fiasse:S6.1.1","ref":"S6.1.1","title":"Ineffective Vulnerability Reporting","summary":"Avoid routing raw scanner output to development. Validate true positives, identify root causes, prioritize impact, and verify fixes."},{"id":"fiasse:S6.1.2","ref":"S6.1.2","title":"Pitfalls of Exploit-First Training","summary":"Training centered on exploitation does not equip developers with the engineering principles needed to build inherently securable systems."},{"id":"fiasse:S6.1","ref":"S6.1","title":"The Shoveling Left Phenomenon","summary":"Shoveling Left: supplying impractical information to developers. The corrective discipline is the Actionable Security Intelligence Principle."},{"id":"fiasse:S6.2","ref":"S6.2","title":"Strategic Use of Security Output","summary":"Scanning and testing output must be converted into engineering-grounded direction tied to requirements and acceptance criteria, not handed to developers as finished intelligence."},{"id":"fiasse:S7.1","ref":"S7.1","title":"The Role of the Security Team","summary":"Security metrics measure partnership effectiveness, not developer adherence. The security team's effectiveness is limited by software quality."},{"id":"fiasse:S7.2","ref":"S7.2","title":"Senior Software Engineers","summary":"Senior engineers drive security requirements, lead SSEM-based merge reviews, maintain prompt engineering standards for AI-assisted generation, and mentor peers."},{"id":"fiasse:S7.3","ref":"S7.3","title":"Developing Software Engineers","summary":"Developing engineers benefit from SSEM mental models. Focus on engineering fundamentals, defensive coding, trust boundaries, and scrutinizing AI-generated code."},{"id":"fiasse:S7.4","ref":"S7.4","title":"Product Owners and Managers","summary":"FIASSE-literate Product Owners assess backlog items for securability implications, validate security acceptance criteria, and recognize when scope cuts erode securable attributes."},{"id":"fiasse:S8","ref":"S8","title":"Organizational Adoption of FIASSE","summary":"Six-step adoption path: assess practices, integrate SSEM terminology, identify influencers, educate teams, foster collaboration, and monitor continuously."},{"id":"fiasse:SA.1.1","ref":"SA.1.1","title":"Measuring Analyzability","summary":"Quantitative and qualitative measures for Analyzability."},{"id":"fiasse:SA.1.2","ref":"SA.1.2","title":"Measuring Modifiability","summary":"Quantitative and qualitative measures for Modifiability."},{"id":"fiasse:SA.1.3","ref":"SA.1.3","title":"Measuring Testability","summary":"Quantitative and qualitative measures for Testability."},{"id":"fiasse:SA.1.4","ref":"SA.1.4","title":"Measuring Observability","summary":"Quantitative and qualitative measures for Observability, including structured logging review, instrumentation audits, and failure-path observability."},{"id":"fiasse:SA.1","ref":"SA.1","title":"Measuring Maintainability","summary":"Quantitative and qualitative measurement approaches for Analyzability, Modifiability, Testability, and Observability."},{"id":"fiasse:SA.2.1","ref":"SA.2.1","title":"Measuring Confidentiality","summary":"Quantitative and qualitative measures for Confidentiality."},{"id":"fiasse:SA.2.2","ref":"SA.2.2","title":"Measuring Accountability","summary":"Quantitative and qualitative measures for Accountability."},{"id":"fiasse:SA.2.3","ref":"SA.2.3","title":"Measuring Authenticity","summary":"Quantitative and qualitative measures for Authenticity."},{"id":"fiasse:SA.2","ref":"SA.2","title":"Measuring Trustworthiness","summary":"Quantitative and qualitative measurement approaches for Confidentiality, Accountability, and Authenticity."},{"id":"fiasse:SA.3.1","ref":"SA.3.1","title":"Measuring Availability","summary":"Quantitative and qualitative measures for Availability."},{"id":"fiasse:SA.3.2","ref":"SA.3.2","title":"Measuring Integrity","summary":"Quantitative and qualitative measures for Integrity."},{"id":"fiasse:SA.3.3","ref":"SA.3.3","title":"Measuring Resilience","summary":"Quantitative and qualitative measures for Resilience."},{"id":"fiasse:SA.3","ref":"SA.3","title":"Measuring Reliability","summary":"Quantitative and qualitative measurement approaches for Availability, Integrity, and Resilience."}],"mappings":[{"peerControlId":"fiasse:S1.1","relation":"partial","aprfCheckIds":["ORG-M1","CMP-M1"]},{"peerControlId":"fiasse:S1.2","relation":"partial","aprfCheckIds":["ORG-M1","CMP-M1"]},{"peerControlId":"fiasse:S2.1","relation":"partial","aprfCheckIds":["ORG-M1","CHG-M1"]},{"peerControlId":"fiasse:S2.2","relation":"partial","aprfCheckIds":["ORG-M1","CHG-M1"]},{"peerControlId":"fiasse:S2.3","relation":"partial","aprfCheckIds":["ORG-M1","CHG-M1"]},{"peerControlId":"fiasse:S2.4","relation":"partial","aprfCheckIds":["ORG-M1","CHG-M1"]},{"peerControlId":"fiasse:S2.5","relation":"partial","aprfCheckIds":["ORG-M1","CHG-M1"]},{"peerControlId":"fiasse:S2.6","relation":"partial","aprfCheckIds":["ORG-M1","CHG-M1"]},{"peerControlId":"fiasse:S3.1","relation":"aligns-with","aprfCheckIds":["CHG-M1","INF-M1"]},{"peerControlId":"fiasse:S3.2.1.1","relation":"aligns-with","aprfCheckIds":["CHG-M1","INF-M1"]},{"peerControlId":"fiasse:S3.2.1.2","relation":"aligns-with","aprfCheckIds":["CHG-M1","INF-M1"]},{"peerControlId":"fiasse:S3.2.1.3","relation":"aligns-with","aprfCheckIds":["CHG-M1","INF-M1"]},{"peerControlId":"fiasse:S3.2.1.4","relation":"aligns-with","aprfCheckIds":["CHG-M1","INF-M1"]},{"peerControlId":"fiasse:S3.2.1","relation":"aligns-with","aprfCheckIds":["CHG-M1","INF-M1"]},{"peerControlId":"fiasse:S3.2.2.1","relation":"aligns-with","aprfCheckIds":["CHG-M1","INF-M1"]},{"peerControlId":"fiasse:S3.2.2.2","relation":"aligns-with","aprfCheckIds":["CHG-M1","INF-M1"]},{"peerControlId":"fiasse:S3.2.2.3","relation":"aligns-with","aprfCheckIds":["CHG-M1","INF-M1"]},{"peerControlId":"fiasse:S3.2.2","relation":"aligns-with","aprfCheckIds":["CHG-M1","INF-M1"]},{"peerControlId":"fiasse:S3.2.3.1","relation":"aligns-with","aprfCheckIds":["CHG-M1","INF-M1"]},{"peerControlId":"fiasse:S3.2.3.2","relation":"aligns-with","aprfCheckIds":["CHG-M1","INF-M1"]},{"peerControlId":"fiasse:S3.2.3.3","relation":"aligns-with","aprfCheckIds":["CHG-M1","INF-M1"]},{"peerControlId":"fiasse:S3.2.3","relation":"aligns-with","aprfCheckIds":["CHG-M1","INF-M1"]},{"peerControlId":"fiasse:S3.2","relation":"aligns-with","aprfCheckIds":["CHG-M1","INF-M1"]},{"peerControlId":"fiasse:S4.1.1","relation":"partial","aprfCheckIds":["SEC-M1","SCI-M1"]},{"peerControlId":"fiasse:S4.1.2","relation":"partial","aprfCheckIds":["SEC-M1","SCI-M1"]},{"peerControlId":"fiasse:S4.1","relation":"partial","aprfCheckIds":["SEC-M1","SCI-M1"]},{"peerControlId":"fiasse:S4.2.1","relation":"partial","aprfCheckIds":["SEC-M1","SCI-M1"]},{"peerControlId":"fiasse:S4.2.2","relation":"partial","aprfCheckIds":["SEC-M1","SCI-M1"]},{"peerControlId":"fiasse:S4.2","relation":"partial","aprfCheckIds":["SEC-M1","SCI-M1"]},{"peerControlId":"fiasse:S4.3","relation":"partial","aprfCheckIds":["SEC-M1","SCI-M1"]},{"peerControlId":"fiasse:S4.4.1.1","relation":"partial","aprfCheckIds":["SEC-M1","SCI-M1"]},{"peerControlId":"fiasse:S4.4.1.2","relation":"partial","aprfCheckIds":["SEC-M1","SCI-M1"]},{"peerControlId":"fiasse:S4.4.1","relation":"partial","aprfCheckIds":["SEC-M1","SCI-M1"]},{"peerControlId":"fiasse:S4.4","relation":"partial","aprfCheckIds":["SEC-M1","SCI-M1"]},{"peerControlId":"fiasse:S4.5","relation":"partial","aprfCheckIds":["SEC-M1","SCI-M1"]},{"peerControlId":"fiasse:S4.6","relation":"partial","aprfCheckIds":["SEC-M1","SCI-M1"]},{"peerControlId":"fiasse:S5.1","relation":"partial","aprfCheckIds":["EVL-M1","OBS-M1"]},{"peerControlId":"fiasse:S5.2","relation":"partial","aprfCheckIds":["EVL-M1","OBS-M1"]},{"peerControlId":"fiasse:S5.3","relation":"partial","aprfCheckIds":["EVL-M1","OBS-M1"]},{"peerControlId":"fiasse:S6.1.1","relation":"partial","aprfCheckIds":["INC-M1","OBS-M1"]},{"peerControlId":"fiasse:S6.1.2","relation":"partial","aprfCheckIds":["INC-M1","OBS-M1"]},{"peerControlId":"fiasse:S6.1","relation":"partial","aprfCheckIds":["INC-M1","OBS-M1"]},{"peerControlId":"fiasse:S6.2","relation":"partial","aprfCheckIds":["INC-M1","OBS-M1"]},{"peerControlId":"fiasse:S7.1","relation":"partial","aprfCheckIds":["ORG-M1","CMP-M1"]},{"peerControlId":"fiasse:S7.2","relation":"partial","aprfCheckIds":["ORG-M1","CMP-M1"]},{"peerControlId":"fiasse:S7.3","relation":"partial","aprfCheckIds":["ORG-M1","CMP-M1"]},{"peerControlId":"fiasse:S7.4","relation":"partial","aprfCheckIds":["ORG-M1","CMP-M1"]},{"peerControlId":"fiasse:S8","relation":"partial","aprfCheckIds":["REL-M1","INF-M1"]},{"peerControlId":"fiasse:SA.1.1","relation":"aligns-with","aprfCheckIds":["EVL-M1","OBS-M1"]},{"peerControlId":"fiasse:SA.1.2","relation":"aligns-with","aprfCheckIds":["EVL-M1","OBS-M1"]},{"peerControlId":"fiasse:SA.1.3","relation":"aligns-with","aprfCheckIds":["EVL-M1","OBS-M1"]},{"peerControlId":"fiasse:SA.1.4","relation":"aligns-with","aprfCheckIds":["EVL-M1","OBS-M1"]},{"peerControlId":"fiasse:SA.1","relation":"aligns-with","aprfCheckIds":["EVL-M1","OBS-M1"]},{"peerControlId":"fiasse:SA.2.1","relation":"aligns-with","aprfCheckIds":["EVL-M1","OBS-M1"]},{"peerControlId":"fiasse:SA.2.2","relation":"aligns-with","aprfCheckIds":["EVL-M1","OBS-M1"]},{"peerControlId":"fiasse:SA.2.3","relation":"aligns-with","aprfCheckIds":["EVL-M1","OBS-M1"]},{"peerControlId":"fiasse:SA.2","relation":"aligns-with","aprfCheckIds":["EVL-M1","OBS-M1"]},{"peerControlId":"fiasse:SA.3.1","relation":"aligns-with","aprfCheckIds":["EVL-M1","OBS-M1"]},{"peerControlId":"fiasse:SA.3.2","relation":"aligns-with","aprfCheckIds":["EVL-M1","OBS-M1"]},{"peerControlId":"fiasse:SA.3.3","relation":"aligns-with","aprfCheckIds":["EVL-M1","OBS-M1"]},{"peerControlId":"fiasse:SA.3","relation":"aligns-with","aprfCheckIds":["EVL-M1","OBS-M1"]}]},{"id":"soc2-tsc","name":"SOC 2 Trust Services Criteria","peerVersion":"2017 (with 2022 revisions) — evidence reuse","url":"https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2","disclaimer":"Informative alignment only. Does not constitute certification, accreditation, or official endorsement. Passing APRF does not imply SOC 2 compliance.","controls":[{"id":"soc2:cc1","ref":"CC1","title":"Control Environment"},{"id":"soc2:cc3","ref":"CC3","title":"Risk Assessment"},{"id":"soc2:cc5","ref":"CC5","title":"Control Activities"},{"id":"soc2:cc6","ref":"CC6","title":"Logical and Physical Access"},{"id":"soc2:cc7","ref":"CC7","title":"System Operations"},{"id":"soc2:cc8","ref":"CC8","title":"Change Management"},{"id":"soc2:cc9","ref":"CC9","title":"Risk Mitigation"},{"id":"soc2:a1","ref":"A1","title":"Availability"},{"id":"soc2:c1","ref":"C1","title":"Confidentiality"},{"id":"soc2:pi1","ref":"PI1","title":"Processing Integrity"},{"id":"soc2:p","ref":"P-series","title":"Privacy (selected)"}],"mappings":[{"peerControlId":"soc2:cc1","aprfPillarSlugs":["organizational-governance","compliance"],"aprfCheckIds":["ORG-M1","ORG-R2","CMP-M1"],"relation":"evidence-for"},{"peerControlId":"soc2:cc3","aprfPillarSlugs":["organizational-governance","safety-responsible-ai","evaluation"],"aprfCheckIds":["ORG-R4","SAF-M1","EVL-M1"],"relation":"evidence-for"},{"peerControlId":"soc2:cc5","aprfPillarSlugs":["tool-safety","human-approval","platform-engineering"],"aprfCheckIds":["TOL-M1","HUM-M1","DX-M2"],"relation":"evidence-for"},{"peerControlId":"soc2:cc6","aprfPillarSlugs":["authentication","authorization","secrets","infrastructure"],"aprfCheckIds":["AUTHN-M1","AUTHN-M2","AUTHZ-M1","SEC2-M1","INF-M1"],"relation":"evidence-for"},{"peerControlId":"soc2:cc7","aprfPillarSlugs":["observability","incident-readiness","reliability-continuity"],"aprfCheckIds":["OBS-M1","OBS-R4","INC-M1","INC-M2","REL-M2"],"relation":"evidence-for"},{"peerControlId":"soc2:cc8","aprfPillarSlugs":["change-management","model-governance","prompt-engineering"],"aprfCheckIds":["DEP-M1","CHG-M1","CHG-M3","MOD-M1","PRM-M1"],"relation":"evidence-for"},{"peerControlId":"soc2:cc9","aprfPillarSlugs":["supply-chain","ai-security","reliability-continuity"],"aprfCheckIds":["SCI-M2","SEC-M1","REL-M1"],"relation":"evidence-for"},{"peerControlId":"soc2:a1","aprfPillarSlugs":["reliability-continuity","performance-slo","infrastructure"],"aprfCheckIds":["REL-M1","REL-M2","PERF-M1","INF-M2"],"relation":"evidence-for"},{"peerControlId":"soc2:c1","aprfPillarSlugs":["data-privacy","secrets","memory-management"],"aprfCheckIds":["PRI-M1","PRI-M2","SEC2-M1","MEM-M1"],"relation":"evidence-for"},{"peerControlId":"soc2:pi1","aprfPillarSlugs":["evaluation","observability","change-management"],"aprfCheckIds":["EVL-M1","EVL-M2","OBS-M1","CHG-M3"],"relation":"evidence-for"},{"peerControlId":"soc2:p","aprfPillarSlugs":["data-privacy","data-governance","compliance"],"aprfCheckIds":["PRI-M1","PRI-R2","DG-M1","CMP-M3"],"relation":"partial","note":"Privacy TSC is broader than APRF privacy checks; use as AI evidence pack only."}]},{"id":"aws-well-architected","name":"AWS Well-Architected Framework","peerVersion":"WA Framework pillars + Generative AI Lens (conceptual)","url":"https://aws.amazon.com/architecture/well-architected/","disclaimer":"Informative alignment only. Does not constitute certification, accreditation, or official endorsement. Not an AWS Well-Architected Lens review or AWS certification.","controls":[{"id":"aws-wa:ops","ref":"Operational Excellence","title":"Operational Excellence","summary":"Run and monitor systems; continually improve processes."},{"id":"aws-wa:sec","ref":"Security","title":"Security","summary":"Protect data, systems, and assets."},{"id":"aws-wa:rel","ref":"Reliability","title":"Reliability","summary":"Recover from failures and meet demand."},{"id":"aws-wa:perf","ref":"Performance Efficiency","title":"Performance Efficiency","summary":"Use resources efficiently and adapt to demand."},{"id":"aws-wa:cost","ref":"Cost Optimization","title":"Cost Optimization","summary":"Avoid unnecessary cost; manage spend."},{"id":"aws-wa:sus","ref":"Sustainability","title":"Sustainability","summary":"Minimize environmental impact of cloud workloads."},{"id":"aws-wa:genai","ref":"Generative AI Lens","title":"Generative AI Lens (themes)","summary":"Responsible AI, agent/tool safety, eval, and model lifecycle themes."}],"mappings":[{"peerControlId":"aws-wa:ops","aprfPillarSlugs":["observability","incident-readiness","change-management","platform-engineering","organizational-governance"],"aprfCheckIds":["OBS-M1","INC-M1","CHG-M1","ORG-R2"],"relation":"aligns-with"},{"peerControlId":"aws-wa:sec","aprfPillarSlugs":["authentication","authorization","secrets","ai-security","tool-safety","infrastructure","supply-chain"],"aprfCheckIds":["AUTHN-M1","AUTHZ-M1","SEC2-M1","SEC-M1","TOL-M1","INF-M1","SCI-M2"],"relation":"aligns-with"},{"peerControlId":"aws-wa:rel","aprfPillarSlugs":["reliability-continuity","performance-slo","incident-readiness"],"aprfCheckIds":["REL-M1","REL-M2","PERF-M1","INC-M2"],"relation":"aligns-with"},{"peerControlId":"aws-wa:perf","aprfPillarSlugs":["performance-slo","observability","context-engineering"],"aprfCheckIds":["PERF-M1","OBS-R4"],"relation":"partial"},{"peerControlId":"aws-wa:cost","aprfPillarSlugs":["cost-optimization"],"aprfCheckIds":["COST-M1","COST-M3"],"relation":"supports"},{"peerControlId":"aws-wa:sus","aprfPillarSlugs":["cost-optimization","model-governance"],"aprfCheckIds":["COST-M1","MOD-M1"],"relation":"partial","note":"APRF does not define sustainability metrics; cost/routing and model selection are nearest proxies."},{"peerControlId":"aws-wa:genai","aprfPillarSlugs":["safety-responsible-ai","evaluation","agent-governance","human-approval","prompt-engineering","model-governance","data-privacy"],"aprfCheckIds":["SAF-M1","EVL-M1","AGN-M2","HUM-M1","PRM-M1","MOD-M1","PRI-M1"],"relation":"aligns-with"}]},{"id":"slsa","name":"SLSA (Supply-chain Levels for Software Artifacts)","peerVersion":"v1.0 — conceptual levels / provenance","url":"https://slsa.dev/","disclaimer":"Informative alignment only. Does not constitute certification, accreditation, or official endorsement. APRF alignment does not confer a SLSA level attestation.","controls":[{"id":"slsa:l1","ref":"Level 1","title":"Build process documented","summary":"Scripted build with provenance documentation."},{"id":"slsa:l2","ref":"Level 2","title":"Hosted build + signed provenance","summary":"Version-controlled, hosted build service; authenticated provenance."},{"id":"slsa:l3","ref":"Level 3","title":"Hardened builds","summary":"Hardened build platform; non-falsifiable provenance."},{"id":"slsa:provenance","ref":"Provenance","title":"Artifact provenance","summary":"Who built what from which source, verifiable at deploy."},{"id":"slsa:verify","ref":"Verify-on-deploy","title":"Verification before use","summary":"Consumers verify signatures/provenance before production use."}],"mappings":[{"peerControlId":"slsa:l1","aprfPillarSlugs":["supply-chain","change-management","model-governance"],"aprfCheckIds":["SCI-M2","DEP-M1","MOD-M1"],"relation":"partial"},{"peerControlId":"slsa:l2","aprfPillarSlugs":["supply-chain","infrastructure","change-management"],"aprfCheckIds":["SCI-M2","SCI-R1","INF-M1","CHG-M1"],"relation":"aligns-with"},{"peerControlId":"slsa:l3","aprfPillarSlugs":["supply-chain","infrastructure","platform-engineering"],"aprfCheckIds":["SCI-M4","SCI-R1","INF-M1","DX-M2"],"relation":"partial","note":"APRF SCI-M4 / hardened admission approximate L3 themes; not a full SLSA L3 claim."},{"peerControlId":"slsa:provenance","aprfPillarSlugs":["supply-chain","model-governance"],"aprfCheckIds":["SCI-M2","SCI-R2","MOD-M1"],"relation":"supports"},{"peerControlId":"slsa:verify","aprfPillarSlugs":["supply-chain","infrastructure","change-management"],"aprfCheckIds":["SCI-R1","INF-M1","CHG-M3"],"relation":"supports"}]}],"scoring":{"methodology":{"name":"APRF gated evaluation","forbids":["A single averaged “readiness score” across all pillars","Trading a failed mandatory check against strong recommended scores","Conformance badges that omit open blockers or APRF version","Claiming Tier 3 / regulated readiness from Core Profile alone"],"steps":[{"id":"classify","title":"Classify criticality","detail":"Assign Tier 0–3. This sets the required capability floor."},{"id":"profile","title":"Choose catalog, profile, and lenses","detail":"Startups may assess Core Profile (Tier 2 minimum). Add formal lenses (RAG, Agents, Voice, Coding agents) when those system types apply. Full catalog for Tier 3 / enterprise / regulated."},{"id":"collect","title":"Collect evidence","detail":"For each applicable check, produce the named artifact and evaluate the pass condition."},{"id":"gate","title":"Evaluate the gate","detail":"All in-scope mandatory checks must pass or be formally marked notApplicable (N/A) with rationale. Failures and unanswered checks are blockers. Profile∪lens assessments only gate on the union of those check IDs. N/A is intended for agent, human-approval, tool-safety, and memory gates when those system types do not apply — not as a substitute for incomplete evidence."},{"id":"attainment","title":"Compute capability attainment","detail":"Per pillar: highest level L where all mandatory checks ≤ L pass. System attainment = minimum across pillars."},{"id":"recommended","title":"Score recommended controls per domain","detail":"Optional 0–100 domain scores from recommended checks, weighted by pillar severity. Never folded into the gate."},{"id":"report","title":"Report","detail":"Publish: APRF version, tier, profile (if any), lenses (if any), required capability, gate pass/fail, critical blockers, capability attained, per-domain recommended scores, evidence index."}]},"severityWeights":{"critical":4,"high":3,"medium":2,"low":1}},"pillars":[{"id":"APRF-01","slug":"ai-security","name":"Adversarial Security","summary":"Prevent prompt injection, jailbreaks, exfiltration, and model/tool abuse from becoming a production incident.","domain":"security","crossCutting":false,"severity":"critical","riskLevel":"critical","purpose":"Establish controls that prevent adversarial misuse of models, prompts, tools, and outputs from compromising confidentiality, integrity, or availability—distinct from content-safety and responsible-AI harms covered in the Safety domain.","engineeringPhilosophy":"Treat the model as an untrusted co-processor inside a zero-trust boundary. Security controls belong in the application and platform layers—never solely in prompt wording. Defense in depth spans input validation, output filtering, tool mediation, identity, and runtime isolation.","whyItMatters":"AI surfaces expand the attack surface: prompt injection, data exfiltration via tools, jailbreaks, model theft, and poisoned retrieval. A chatbot that 'mostly works' can still become an incident response event when an attacker turns natural language into a privileged API.","commonFailures":["Relying on system prompts alone to enforce security policy","Passing untrusted retrieval or user content into privileged tool contexts","Logging full prompts/completions that contain secrets or PII","No output schema enforcement—free-form text executes downstream logic","Missing abuse rate limits distinct from normal product quotas"],"mandatoryChecks":[{"id":"SEC-M1","requirement":"Untrusted input (including model-generated text) shall never authorize privileged tool or side-effect actions without server-side policy—so prompt injection and privilege escalation cannot bypass the control plane.","artifact":"Server-side policy mediating privileged tool/actions (not prompt-only) + Versioned injection/privilege-escalation corpus + CI gate report + Policy-engine deny sample logs or harness results (denyRatePct + modelTextPrivilegeGrants)","passCondition":"≥95% of corpus cases that attempt privilege escalation via untrusted input are denied; 0 cases where model text alone granted a privileged tool call in the suite (measuredAt ≤90 days). If production AI cannot invoke tools or privileged side effects, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"SEC-M2","requirement":"High-risk model outputs shall be schema-validated or policy-filtered before any write, irreversible, or financial side effect—so non-conforming output cannot drive privileged downstream actions.","artifact":"Coverage inventory of high-risk side-effect paths (write/irreversible/financial) + Schema or policy filter definitions applied before those side effects + Contract test results showing non-conforming output rejected on 100% of inventoried paths","passCondition":"100% of high-risk side-effect paths (impact tier write/irreversible/financial) reject non-conforming model output in contract tests; coverage inventory lists every such path (measuredAt ≤90 days). If production AI cannot drive write, irreversible, or financial side effects, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"SEC-M3","requirement":"Customer-facing releases shall run an abuse/jailbreak/injection security suite—with those case classes present—as a blocking gate, or record a time-boxed waiver (owner + expiry ≤30 days) when the gate does not pass.","artifact":"Abuse/jailbreak/injection suite definition covering those case classes + CI/release gate configuration that blocks promote on suite fail + Last 30 days of release reports showing gate=pass, or owned waivers (expiry ≤30 days)","passCondition":"100% of production releases in the last 30 days show an abuse/jailbreak/injection suite gate = pass (suite must include those case classes), or a time-boxed waiver with owner and expiry ≤30 days (measuredAt ≤90 days). If no customer-facing / production AI releases exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"SEC-M4","requirement":"Network and identity boundaries shall prevent the model/tool runtime path from becoming a universal proxy to internal systems—so the model identity reaches only allowlisted destinations and has 0 unrestricted routes to internal admin APIs or data stores.","artifact":"Architecture diagram of model/tool trust boundaries + Network policy or egress allowlist export for the model/tool runtime identity + Automated or reviewed probe results (allowlisted-only reachability; unrestricted internal admin/data-store routes = 0)","passCondition":"Automated or reviewed probe shows the model/tool runtime can reach only allowlisted destinations; 0 unrestricted routes to internal admin APIs or data stores from the model identity (measuredAt ≤90 days). If no model or tool runtime can initiate network calls, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2}],"recommendedChecks":[{"id":"SEC-R1","requirement":"Production systems that use multi-turn dialogue, RAG, or MCP should run a versioned red-team suite with ≥10 multi-turn and ≥10 indirect RAG/MCP injection cases—so single-turn jailbreak tests alone cannot claim coverage.","artifact":"Versioned red-team suite covering multi-turn and indirect RAG/MCP injection + Case counts (≥10 multi-turn, ≥10 indirect RAG/MCP) with documented pass thresholds + Latest scored run report ≤90 days with retention ≥90 days","passCondition":"Suite includes ≥10 multi-turn and ≥10 indirect RAG/MCP injection cases; latest run ≤90 days meets documented pass thresholds; report retained ≥90 days (measuredAt ≤90 days). If the system has no multi-turn, RAG, or MCP surfaces, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"SEC-R2","requirement":"Where production AI accepts multimodal inputs (images, files, or similar), content-safety and malware scanners should run before model ingest—so unscanned media cannot reach the model path.","artifact":"Multimodal input content-safety and/or malware scanner config (pre-model-ingest) + Inventory of image/file types accepted in production + Latest CI or batch scan report ≤90 days showing type coverage and 0 unscanned production paths","passCondition":"Where multimodal inputs are accepted, scanner runs before model ingest; last report ≤90 days shows coverage of image/file types in use and 0 unscanned production paths (measuredAt ≤90 days). If multimodal inputs are not accepted, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"SEC-R3","requirement":"Sensitive AI contexts should have mechanisms to detect data exfiltration attempts—canary/honeytokens are one strong implementation; equivalent DLP, SIEM/UEBA, egress monitoring, or similar controls also satisfy when validated.","artifact":"Documented exfiltration-detection mechanism for sensitive AI contexts (mechanism class named) + Coverage of production-sensitive AI paths (inventory or mapping) + Latest validation ≤90 days (detection test, alert-rule exercise, or equivalent) with expected alerts / 0 silent misses","passCondition":"Sensitive AI contexts have a documented exfiltration-detection mechanism (canary/honeytoken, DLP, SIEM/UEBA, egress monitoring, or equivalent); latest validation ≤90 days shows expected detection/alerts for covered paths with 0 silent misses in the validation suite or review (measuredAt ≤90 days). If no sensitive AI contexts exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2}],"evidenceRequired":["Threat model covering LLM-specific attack paths","Records of injection/jailbreak test suites and results","Architecture diagram showing trust boundaries around model and tools","Incident playbooks referencing AI-specific abuse scenarios"],"engineeringBestPractices":["Separate instruction channels from data channels; never concatenate untrusted data into system instructions without mediation","Apply least privilege to every tool and retrieval corpus the model can touch","Fail closed on policy violations; prefer refusal over silent degradation for security decisions","Version and review security policies the same way you review firewall rules"],"automaticValidations":["CI security tests for known injection payloads against critical flows","Runtime policy engines rejecting disallowed tool calls","Schema validation on structured model outputs","Anomaly detection on tool-call volume and destination"],"manualValidations":["Periodic adversarial review of new tools and prompts","Architecture review of trust boundaries before Level 3 launch","Tabletop exercises for data-exfiltration via the AI path"],"examples":["A support agent refuses to call refund APIs when the refund amount exceeds policy, regardless of user phrasing","RAG documents containing 'ignore previous instructions' cannot elevate privileges","MCP servers expose only scoped tools with server-side authorization independent of the model"],"references":[{"title":"OWASP Top 10 for Large Language Model Applications","url":"https://owasp.org/www-project-top-10-for-large-language-model-applications/"},{"title":"NIST AI Risk Management Framework","url":"https://www.nist.gov/itl/ai-risk-management-framework"},{"title":"CIS Controls (select mappings for AI workloads)","url":"https://www.cisecurity.org/controls"}],"futureEvolution":"Expect standardized machine-readable AI threat taxonomies, portable policy packs across providers, and attestation of model-path controls analogous to cloud security posture management."},{"id":"APRF-10","slug":"authentication","name":"Authentication","summary":"Strong identity for users, services, agents, and MCP callers.","domain":"security","crossCutting":false,"severity":"critical","riskLevel":"critical","purpose":"Ensure every actor that can invoke AI capabilities—humans, services, agents, MCP clients—is authenticated with appropriate assurance.","engineeringPhilosophy":"AI endpoints are privileged application surfaces. Anonymous or shared credentials for agents and MCP are incompatible with production readiness beyond Level 1.","whyItMatters":"Unauthenticated model and tool endpoints become public compute and data exfiltration oracles. Agent impersonation enables privilege abuse across systems.","commonFailures":["Public API keys embedded in clients calling powerful agents","MCP servers listening without auth","Service accounts shared across many agents","No MFA for admin consoles controlling prompts and tools"],"mandatoryChecks":[{"id":"AUTHN-M1","requirement":"Customer-facing AI HTTP/RPC APIs shall reject callers that present no valid credentials—so anonymous traffic cannot invoke model, tool, retrieval, or other privileged AI surfaces.","artifact":"Production AI HTTP/RPC route catalog + unauthenticated auth-probe report (401/403) matching the catalog","passCondition":"100% of declared production AI HTTP/RPC routes in the probe inventory return 401/403 without credentials; every declared AI route in the production route catalog was probed (measuredAt ≤90 days). If no customer-facing AI HTTP/RPC APIs exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"AUTHN-M2","requirement":"Production MCP and AI service-to-service connections shall authenticate with a named machine identity—so anonymous access and shared long-lived static keys cannot stand in for workload or federated identity.","artifact":"Production MCP/AI S2S connection inventory + auth config (secrets redacted) + scored report","passCondition":"0 production MCP or AI S2S connections accept anonymous access or shared long-lived static keys; each connection has a named machine identity (measuredAt ≤90 days). If no production MCP or AI S2S connections exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"AUTHN-M3","requirement":"Administrative access to AI control planes shall require strong authentication including MFA—so operators who can change prompts, tools, models, or deployments cannot rely on password-only or shared credentials.","artifact":"IdP MFA policy export for AI control-plane admin roles + break-glass inventory with monitoring","passCondition":"100% of AI control-plane admin roles enforce MFA; break-glass accounts ≤ documented maximum and have monitoring enabled (measuredAt ≤90 days). If no AI control-plane admin access exists, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"AUTHN-M4","requirement":"Where AI systems execute tools, agents, workflows, or delegated actions, the end-user (or documented service) subject shall remain bound through every privileged hop—so agentic chains cannot act as anonymous or ambient privilege.","artifact":"Identity-propagation design + sample traces showing end-user/service subject on privileged tool/agent/workflow calls","passCondition":"100% of sampled privileged tool/agent/workflow calls in the latest review carry an end-user (or documented service) subject; 0 anonymous privileged hops (measuredAt ≤90 days). If the system has no tools, agents, workflows, or delegated actions, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":5,"minCriticality":3}],"recommendedChecks":[{"id":"AUTHN-R1","requirement":"Agent and tool credentials used in production should be short-lived (TTL ≤1h, or a named exception ≤30 days), and production prompts/config should embed 0 long-lived static API keys—so leaked prompts and agent configs cannot mint durable privileged access.","artifact":"Agent/tool credential inventory with TTL/exceptions + secret-scan of prompts/config (0 long-lived static API keys)","passCondition":"100% of inventoried agent/tool credentials have TTL ≤1h (or a named exception with owner and expiry ≤30 days); secret scan of production prompts/config finds 0 long-lived static API keys (measuredAt ≤90 days). If no agent/tool credentials appear in production prompts/config, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"AUTHN-R2","requirement":"Every self-hosted model runtime in production should authenticate via workload identity (SPIFFE, cloud IAM role, or equivalent)—so inference nodes and model servers do not rely on shared static keys.","artifact":"Self-hosted model runtime inventory + workload-identity bindings + sample authenticated call traces (0 static shared keys)","passCondition":"Every self-hosted model runtime in production authenticates via workload identity (SPIFFE/IAM role/equivalent); 0 static shared keys in the runtime inventory; sample authenticated calls (or harness) present (measuredAt ≤90 days). If no self-hosted model runtimes exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2}],"evidenceRequired":["Auth architecture for AI and MCP surfaces","Evidence that anonymous access is disabled in production","Admin access controls documentation"],"engineeringBestPractices":["Prefer OAuth2/OIDC or workload identity over static API keys","Issue distinct identities per agent class","Rotate credentials automatically; detect leaked keys in repos and prompts","Authenticate both directions for A2A where feasible"],"automaticValidations":["Integration tests rejecting unauthenticated calls","Secret scanning for exposed AI API keys","Config checks that MCP auth is enabled"],"manualValidations":["Identity design review for new agent entry points","Periodic access review of AI admin roles"],"examples":["An MCP server requires OAuth for every client; local-dev uses a distinct non-prod issuer","A voice AI channel authenticates the telephony session before invoking tools"],"references":[{"title":"OWASP Authentication Cheat Sheet","url":"https://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html"},{"title":"CIS Benchmarks — Identity controls","url":"https://www.cisecurity.org/cis-benchmarks"}],"futureEvolution":"Standard agent identity profiles and passport-like credentials for cross-org A2A."},{"id":"APRF-11","slug":"authorization","name":"Authorization","summary":"Enforce who/what may invoke which models, tools, data, and actions.","domain":"security","crossCutting":false,"severity":"critical","riskLevel":"critical","purpose":"Enforce fine-grained authorization over models, prompts, corpora, tools, and actions so authenticated actors only receive the capabilities they are entitled to.","engineeringPhilosophy":"Authentication without authorization is incomplete. Authorization decisions must be made outside the model and must apply to retrieved data and tool effects, not only to the HTTP route.","whyItMatters":"Confused-deputy and over-permissioned agents are primary causes of data breaches in AI systems. A model that can see everything can leak everything.","commonFailures":["Authorization checked at UI only; API and agent paths bypass it","Retrieval without document-level ACLs","Tools inheriting broad service roles","Tenant isolation bugs in multi-tenant AI products"],"mandatoryChecks":[{"id":"AUTHZ-M1","requirement":"Privileged AI feature, tool, and retrieval entry points shall enforce authorization server-side—so authenticated callers lacking required permission or scope cannot invoke those surfaces.","artifact":"Inventory of privileged AI feature/tool/retrieval entry points + server-side authz policy + authz suite (authenticated-but-unauthorized denied)","passCondition":"100% of privileged AI feature, tool, and retrieval entry points enforce authorization server-side; 0 successful requests from authenticated callers lacking required permission or scope in the authz suite (measuredAt ≤90 days). If no privileged AI feature, tool, or retrieval entry points exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"AUTHZ-M2","requirement":"Multi-tenant AI data and memory paths shall deny unauthorized cross-tenant reads and writes—proven by an automated attack suite, not by tenant filters in code alone.","artifact":"Inventory of multi-tenant AI data/memory paths + cross-tenant attack suite (≥10 cases) + scored report","passCondition":"0 successful unauthorized cross-tenant reads/writes across ≥10 automated attack cases on AI data and memory paths (measuredAt ≤90 days). If no multi-tenant AI data or memory paths exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"AUTHZ-M3","requirement":"Production agent and automation identities shall appear in a role matrix with non-admin default roles—and a ≤90-day access review shall record 0 unexplained privilege escalations.","artifact":"Inventory of production agent/automation identities + role matrix/IAM export + ≤90-day access-review record","passCondition":"100% of production agent/automation identities appear in the role matrix with non-admin default roles; quarterly (or ≤90-day) access review recorded with 0 unexplained privilege escalations (measuredAt ≤90 days). If no production agent or automation identities exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"AUTHZ-M4","requirement":"Sensitive document classes used by AI retrieval or grounding shall be enumerated and governed by attribute-based policy (subject/resource attributes)—with tests proving unauthorized class access is denied and the inventory matching production classes.","artifact":"Sensitive document-class inventory + ABAC/policy config + deny-test results matching production","passCondition":"Sensitive document classes are enumerated; attribute-based policy (subject/resource attributes) denies unauthorized class access in tests; inventory matches production classes (measuredAt ≤90 days). If no sensitive document classes are in scope for AI retrieval or grounding, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":5,"minCriticality":3}],"recommendedChecks":[{"id":"AUTHZ-R1","requirement":"Tool and model access rules shall be expressed as code (OPA, Cedar, IAM-as-code, or equivalent) and enforced in CI or admission—with a ≤90-day failing-to-passing policy change that shows a deny for an unauthorized tool or model.","artifact":"Policy-as-code for tool/model access + CI/admission policy-check + ≤90-day deny evidence","passCondition":"Tool and model access rules are expressed as code and enforced in CI or admission; last failing-to-passing policy change ≤90 days shows a deny for unauthorized tool/model (measuredAt ≤90 days). If no production tools or models subject to access control exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"AUTHZ-R2","requirement":"Every high-privilege agent identity shall be reviewed ≤90 days ago, with ≥1 revoke or scope-reduction in the last two cycles—or a signed attestation that none were warranted.","artifact":"High-privilege agent inventory + ≤90-day access-review report with keep/revoke/modify + revoke or none-warranted evidence","passCondition":"Every high-privilege agent identity was reviewed ≤90 days ago; ≥1 revoke or scope-reduction appears in the last two cycles (or attestation that none were warranted with reviewer sign-off) (measuredAt ≤90 days). If no high-privilege agent identities exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2}],"evidenceRequired":["Authorization model documentation","Tenant isolation test results","Role matrices for agents and tools"],"engineeringBestPractices":["Propagate user context into tool calls; avoid confused deputy","Deny by default for new tools and corpora","Re-check authorization at each hop in multi-agent workflows","Separate read and write capabilities aggressively"],"automaticValidations":["Automated cross-tenant access attempt tests","CI policy checks for IAM/tool scopes","Runtime denials logged and alertable"],"manualValidations":["Security review of new high-impact tools","Periodic privilege creep audits"],"examples":["A sales agent can query CRM records for the caller's accounts only","An internal coding agent cannot access production secrets vaults"],"references":[{"title":"OWASP Access Control Cheat Sheet","url":"https://cheatsheetseries.owasp.org/cheatsheets/Access_Control_Cheat_Sheet.html"},{"title":"NIST AI RMF — Manage","url":"https://www.nist.gov/itl/ai-risk-management-framework"}],"futureEvolution":"Portable authorization tokens that travel with agent tasks across organizational boundaries."},{"id":"APRF-12","slug":"secrets","name":"Secrets","summary":"Eliminate secret leakage into prompts, logs, tools, and client surfaces.","domain":"security","crossCutting":false,"severity":"critical","riskLevel":"critical","purpose":"Prevent API keys, credentials, tokens, and other secrets from entering prompts, completions, logs, training/fine-tuning corpora, or client-visible surfaces.","engineeringPhilosophy":"Secrets never belong in context windows as data. Treat any path that can echo or store model I/O as a potential secret exfiltration channel.","whyItMatters":"Models and logs are high-bandwidth leak channels. A single leaked provider key or cloud credential can escalate into full environment compromise and unbounded spend.","commonFailures":["API keys in frontend code or mobile apps","Secrets pasted into prompts for 'debugging'","Tool results returning credentials into context","Fine-tuning on datasets that include secrets"],"mandatoryChecks":[{"id":"SEC2-M1","requirement":"Production secrets shall resolve from a secrets manager at runtime and must not appear in repos, prompt registries, or client bundles—proven by secrets-manager wiring plus a fresh secret-scan covering prompts/fixtures, not by CI ${{ secrets.* }} alone.","artifact":"Secrets-manager / sealed-secrets / cloud secret-ref wiring for production runtime; CI/repo secret-scan config covering prompts and fixtures; Latest secret-scan report with 0 privileged findings (measuredAt ≤90 days); Attest or inventory showing 100% of production runtime secrets resolve from the secrets manager","passCondition":"Secrets-manager wiring covers production runtime secrets; 100% of those secrets resolve from the secrets manager; the latest secret scan covering repos, prompt registries, and client bundles finds 0 privileged production secrets (measuredAt ≤90 days). If no production runtime secrets exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":2,"minCriticality":1},{"id":"SEC2-M2","requirement":"Logging and tracing pipelines shall redact secret-like patterns—proven by redaction/masking config plus a fresh canary harness that injects API key/bearer/AWS-key patterns and shows 100% redaction in persisted logs/traces, not by filter code alone.","artifact":"Redaction/masking config for logging and/or tracing pipelines; Synthetic secret-injection canary harness covering API key/bearer/AWS-key patterns; Canary results showing 100% detection/redaction in persisted logs/traces (measuredAt ≤90 days)","passCondition":"Logging/tracing secret-redaction config is present; a canary harness injects synthetic API key/bearer/AWS-key patterns and shows 100% redaction in persisted logs/traces (measuredAt ≤90 days). If no production logging or tracing pipelines exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"SEC2-M3","requirement":"Provider and cloud keys shall be rotatable and least-privilege scoped, and client apps shall not hold privileged keys—proven by a key inventory with scope and rotation evidence plus a client-bundle/scan report, not by secrets-manager presence alone.","artifact":"Inventory of production provider/cloud keys with least-privilege scope; Rotation dates or provider-managed short-lived credential evidence within policy; Client bundle/scan report showing 0 privileged provider/cloud keys (measuredAt ≤90 days)","passCondition":"Inventory of production provider/cloud keys exists; 0 privileged provider/cloud keys are embedded in client apps; 100% of production keys have a documented least-privilege scope and are within rotation policy (≤90 days or provider-managed short-lived credentials) (measuredAt ≤90 days). If no production provider/cloud keys exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2}],"recommendedChecks":[{"id":"SEC2-R1","requirement":"Pre-commit and CI secret scanning shall cover application code, prompts, and fixtures and block on high-confidence secrets—proven by scanner config plus a fresh green main-branch (or PR-merge) scan ≤7 days, not by a secrets-manager or a single ≤90-day content scan alone.","artifact":"Pre-commit secret-scan hook/config covering prompts and fixtures; CI secret-scan workflow covering prompts and fixtures; Proof scanning blocks on high-confidence secrets; Latest green main-branch or PR-merge secret-scan evidence (measuredAt ≤7 days)","passCondition":"Pre-commit and CI secret scanning are configured; both cover application code, prompts, and fixtures; scanning blocks on high-confidence secrets; the latest green main-branch scan (or last PR-merge scan evidence) is ≤7 days (measuredAt ≤7 days). If no application code, prompts, or fixtures exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"SEC2-R2","requirement":"Egress controls shall limit where runtime credentials can be used—proven by an allowlist/policy for runtimes that hold credentials plus ≥1 observed deny event in test or production logs within 90 days, not by secrets-manager presence or model-path trust-boundary docs alone.","artifact":"Egress allowlist/policy config for runtimes that hold credentials; Documented allowed destinations for those credentials; Sample deny (and optionally allow) logs proving enforcement (measuredAt ≤90 days)","passCondition":"Egress allowlist/policy is configured for production runtimes that hold credentials; destinations are documented; ≥1 deny event is observed in test or production logs proving enforcement (measuredAt ≤90 days). If no production runtimes hold credentials, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"SEC2-R3","requirement":"Fine-tune and eval corpora shall be scanned for secrets/PII before publish—proven by a publish-blocking scan gate plus linked scan reports for 100% of corpora published in the last 90 days, not by dataset cards or repo secret scanning alone.","artifact":"Dataset secret/PII scan gate config before fine-tune or eval corpus publish; Proof publish is blocked when critical findings are open; Linked scan reports covering 100% of fine-tune/eval corpora published in the last 90 days (measuredAt ≤90 days)","passCondition":"A secret/PII scan gate is configured before fine-tune or eval corpus publish; publish is blocked when critical findings are open; 100% of fine-tune/eval corpora published in the last 90 days have a linked scan report (measuredAt ≤90 days). If no fine-tune or eval corpus publish exists, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2}],"evidenceRequired":["Secrets management design","Redaction configuration evidence","Key rotation records"],"engineeringBestPractices":["Use short-lived credentials for tools","Strip Authorization headers and env dumps from error payloads to models","Educate builders: never ask the model to 'remember' a key","Separate build-time and runtime secrets"],"automaticValidations":["Secret scanners in CI and image builds","Runtime detectors blocking known secret formats in prompts","Alerts on anomalous provider API key usage"],"manualValidations":["Review of new logging fields for secret risk","Incident drills for leaked model API keys"],"examples":["A developer tool refuses to send .env contents into an LLM chat","Tracing middleware redacts AWS keys and bearer tokens before persistence"],"references":[{"title":"OWASP Secrets Management Cheat Sheet","url":"https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html"},{"title":"CIS Benchmarks — credential hygiene","url":"https://www.cisecurity.org/cis-benchmarks"}],"futureEvolution":"Native provider APIs that never accept raw secrets in prompt fields, with automatic scrubbing attestations."},{"id":"APRF-05","slug":"tool-safety","name":"Tool Safety","summary":"Make tool/MCP invocation fail closed with least privilege and side-effect control.","domain":"security","crossCutting":false,"severity":"critical","riskLevel":"critical","purpose":"Ensure every tool, function call, MCP server, and external action invoked by a model is authorized, scoped, observable, and reversible or gated when impact is high.","engineeringPhilosophy":"The model proposes; the platform disposes. Tools are privileged APIs. Never let natural language become an unrestricted remote control over production systems.","whyItMatters":"Tool misuse converts language model errors into real-world damage—deleted data, fraudulent transactions, leaked secrets, or lateral movement through MCP and A2A bridges.","commonFailures":["Tools run with service-wide credentials instead of user-scoped tokens","No allowlist of tools per agent or environment","Destructive tools without confirmation or dry-run modes","MCP servers exposed without authentication"],"mandatoryChecks":[{"id":"TOL-M1","requirement":"Every production tool invocation shall be authorized server-side by an independent authz decision—proven by coverage of production tool-invocation paths plus automated deny tests at 100%, not by prompt instructions, client-side checks, or model-proposed tool name/args alone.","artifact":"Inventory or mapping of production tool-invocation paths (or attested gateway covering 100%); Tool gateway / tool-runtime authz enforcement config (server-side)","passCondition":"100% of production tool-invocation paths are covered by server-side tool authz (gateway or runtime); automated tests show tool calls without a valid authz decision are denied at 100%; model-proposed tool name/args alone never bypass the gateway/runtime (measuredAt ≤90 days). If no production agents/workloads invoke tools, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"TOL-M2","requirement":"Production agents and workloads shall have an explicit tool allowlist, and unknown or model-invented tool names shall be rejected at runtime—proven by an inventory of production agents that can invoke tools, 100% allowlist coverage, automated unknown-tool deny tests, and runtime rejection of invented names—not by open MCP \"all tools\" bindings, prompt-only restrictions, or a deny suite that covers only a subset of agents.","artifact":"Inventory of production agents/workloads that can invoke tools; Per-agent/workload tool allowlist configuration covering 100% of those agents","passCondition":"Inventory covers 100% of production agents/workloads that can invoke tools; each has an explicit tool allowlist; automated tests deny unknown-tool requests at 100%; unknown or model-invented tool names are rejected at runtime (measuredAt ≤90 days). If no production agents/workloads invoke tools, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"TOL-M3","requirement":"Tools rated write, irreversible, or financial shall require an additional gate beyond base tool authz/allowlist—human approval, dual control, or a policy engine—proven by a complete impact-tiered inventory of production high-impact tools, 100% gate coverage, and automated tests that ungated execution is impossible—not by prompt \"ask a human\" text, base allowlists, or a bypass suite that covers only a subset of high-impact tools.","artifact":"Impact-tiered tool inventory marking write/irreversible/financial tools in production; Gate configuration (approval, dual control, or policy engine) for 100% of those tools","passCondition":"Impact-tiered inventory covers 100% of production write/irreversible/financial tools; 100% of those tools have a configured additional gate (approval, dual control, or policy engine); automated tests show ungated execution is impossible for those tools (measuredAt ≤90 days). If no write/irreversible/financial tools exist in production, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"TOL-M4","requirement":"Production tools shall declare argument schemas and reject invalid or malicious payloads before side effects—proven by an inventory of production tools, 100% schema coverage, and contract tests at 100% rejection—not by prompt-only \"follow the schema\" instructions, customer-API OpenAPI alone, or a reject suite that covers only a subset of tools.","artifact":"Inventory of production tools that accept arguments; JSON Schema (or equivalent) per inventoried production tool","passCondition":"Inventory covers 100% of production tools; each has a declared argument schema; invalid/malicious argument fixtures are rejected at 100% before side effects (measuredAt ≤90 days). If no production tools exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"TOL-M5","requirement":"Production MCP and agent tool catalogs shall be signed (or equivalently integrity-verified) and supply-chain reviewed before use—proven by an inventory of production catalogs, verify-on-load that rejects unsigned/unapproved catalogs on 100% of load paths, plus a review ≤90 days or since last catalog change—not by SCI-M2 inventory pins alone or a reject config that covers only a subset of catalog loaders.","artifact":"Inventory of production MCP/agent tool catalogs; Signed (or integrity-verified) catalogs + verify-on-load / reject-unsigned for catalog consumers","passCondition":"Inventory covers 100% of production MCP/agent tool catalogs; catalog loaders reject unsigned or unapproved catalogs; last supply-chain review is ≤90 days or since the last catalog change (measuredAt ≤90 days). If no production MCP/agent tool catalogs are loaded, score NOT_APPLICABLE. (Level-5 / regulated advanced scope.)","method":"hybrid","minimumTier":"E3","requiredFromLevel":5,"minCriticality":3}],"recommendedChecks":[{"id":"TOL-R1","requirement":"Destructive tools should expose dry-run or simulation in non-production environments, and the last promotion of a destructive tool should include a dry-run evidence link ≤90 days old—proven by an inventory of destructive tools, 100% dry-run coverage in non-prod, and promotion linkage—not by prompt-only \"dry-run\" flags, production confirmation dialogs, or promotion evidence without a complete destructive-tool inventory.","artifact":"Inventory/catalog of destructive tools marking dry-run/simulation support; Sample lower-env dry-run logs or promotion evidence links ≤90 days","passCondition":"Inventory covers 100% of tools classified destructive; each exposes dry-run or simulation in non-prod; the last promotion of a destructive tool includes a dry-run evidence link ≤90 days old (measuredAt ≤90 days). If no destructive tools exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"TOL-R2","requirement":"High-impact tools should have documented QPS/daily caps and max-affected-entities budgets, with ≥1 limit hit or synthetic enforcement test in the last 30 days—proven by an inventory of high-impact tools, 100% rate+blast budget coverage, and ≤30d enforcement proof—not by global API gateway limits alone, docs without enforcement, or budgets that cover only a subset of high-impact tools.","artifact":"Inventory of high-impact tools requiring rate and blast-radius budgets; Per-tool rate-limit and blast-radius policy config for those tools","passCondition":"Inventory covers 100% of high-impact tools; each has a documented QPS or daily cap and a max-affected-entities (or equivalent) blast-radius budget; ≥1 limit hit or synthetic test proves enforcement in the last 30 days (measuredAt ≤90 days). If no high-impact tools exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2}],"evidenceRequired":["Tool inventory with owners, scopes, and impact ratings","Authorization policy examples","Logs of denied tool invocations"],"engineeringBestPractices":["Map each tool to an impact tier (read, write, irreversible, financial)","Pass user identity into tools; avoid god-mode service accounts where possible","Return structured errors; do not leak internal stack traces into the model context","Treat MCP and A2A endpoints as public-facing APIs with the same hardening"],"automaticValidations":["Contract tests for tool schemas","Policy-as-code denying unauthorized tool calls","CI scanning for overly broad tool permissions"],"manualValidations":["Impact rating review for new tools before production","Penetration testing focused on tool and MCP surfaces"],"examples":["A coding agent can run tests but cannot push to main without human approval","An MCP file server exposes only a workspace directory, not the host filesystem"],"references":[{"title":"Model Context Protocol security considerations","url":"https://modelcontextprotocol.io/"},{"title":"OWASP LLM — Excessive Agency","url":"https://owasp.org/www-project-top-10-for-large-language-model-applications/"}],"futureEvolution":"Standardized tool impact taxonomies and portable capability tokens for agent tool use."},{"id":"APRF-24","slug":"supply-chain","name":"Supply Chain Integrity","summary":"Prove provenance and integrity of models, containers, MCP servers, and AI dependencies.","domain":"security","crossCutting":false,"severity":"critical","riskLevel":"high","purpose":"Ensure model artifacts, inference images, tools, MCP servers, and third-party AI dependencies are authenticated, reviewed, and verifiable—applying SLSA-style integrity to the AI stack.","engineeringPhilosophy":"An AI system is only as trustworthy as the artifacts it loads. Unsigned weights, unverified MCP hosts, and opaque tool catalogs are supply-chain defects, not product features.","whyItMatters":"Poisoned models, compromised MCP servers, and tampered tool plugins bypass application-layer controls and can exfiltrate data or execute attacker-chosen actions at scale.","commonFailures":["Downloading open-weight models from unverified mirrors without checksum or signature verification","MCP servers installed without source review or pinned versions","No SBOM/MBOM for inference images and agent runtimes","Fine-tuned adapters pulled from untrusted registries into production"],"mandatoryChecks":[{"id":"SCI-M1","requirement":"Production model and container artifacts shall have verified provenance/integrity—proven by signature, attestation, or digest verification with unverified pulls blocked, not by digest pins in Dockerfiles alone.","artifact":"Signature / attestation / provenance / checksum verification config (cosign, Notation, SLSA, OCI, or equivalent); Digest or signature verification logs for production model/container pulls in the sample window; Proof unverified pulls are blocked (admission policy, registry policy, or deploy gate; measuredAt ≤90 days)","passCondition":"Provenance/integrity verification is configured for production model and/or container artifacts (signature, attestation, OCI provenance, and/or checksum/ digest); 100% of production model/container pulls in the sample window verify against expected digest or signature; unverified pulls are blocked (measuredAt ≤90 days). If no production model or container artifacts are pulled, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"SCI-M2","requirement":"Production external AI tools, MCP servers, agent plugins, and high-impact integrations shall be inventoried with version pins, named owners, and recurring review—proven by an inventory covering those surfaces with 0 unpinned “latest”/floating entries, not by CI Action SHA pins or package lockfiles alone.","artifact":"Inventory of production external AI tools, MCP servers, agent plugins, and high-impact integrations with version pins, owners, review dates ≤180 days, and 0 unpinned latest/floating entries (measuredAt ≤90 days)","passCondition":"100% of production external AI tools, MCP servers, agent plugins, and high-impact integrations have version pin + owner + review date ≤180 days; 0 unpinned “latest” (or floating) entries in production (inventory evidence measuredAt ≤90 days). If none of those surfaces exist in production, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"SCI-M3","requirement":"Production AI artifacts—including language dependencies, OCI/container images, serverless packages, and model-serving runtimes—shall be scanned for vulnerabilities before promotion, with organization-defined critical findings blocking deploy unless waived with owner and expiry—not by scanning app deps while skipping inference servers or CUDA stacks.","artifact":"Vulnerability scanner config + promote-path critical block (org policy) + retained scan results with 100% coverage and 0 skipped scans for production AI artifacts (measuredAt ≤90 days); critical waivers with owner + expiry ≤14 days","passCondition":"100% of production AI artifacts in the sample window (language dependencies, OCI/container images, serverless packages, and model-serving runtimes including inference servers and accelerator libraries in scope) were vulnerability-scanned with no skipped scans; findings that are critical per organizational policy block promotion unless waived with named owner and expiry ≤14 days; scan results are retained (evidence measuredAt ≤90 days). If no production AI artifacts are built or deployed, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"SCI-M4","requirement":"Production deployment policy shall enforce blocking of unsigned, unapproved, and revoked-signature AI artifacts on the deploy path—proven by policy plus deny/verification logs, not by signing in CI or digest pins alone. Applies via Kubernetes admission, pipeline gates, cloud deploy policies, artifact registry rules, or AI-platform promote gates—not Kubernetes-only.","artifact":"Deployment policy configuration (admission, pipeline, cloud deploy policy, registry, or AI-platform gate) + deny/verification logs for unsigned, unapproved, and revoked/untrusted signatures (measuredAt ≤90 days)","passCondition":"Production deployment policy is enforced on AI artifact deploy/promote paths; unsigned artifacts are blocked; unapproved artifacts are blocked; revoked or untrusted signatures are rejected; deployment or admission deny/ verification logs prove enforcement (measuredAt ≤90 days). If no production AI artifacts are deployed (models/containers/serverless AI packages), score NOT_APPLICABLE. Required from capability Level 5 (advanced mandatory)—not a Tier 2/Core baseline.","method":"hybrid","minimumTier":"E3","requiredFromLevel":5,"minCriticality":3}],"recommendedChecks":[{"id":"SCI-R1","requirement":"Production model and container (or equivalent AI package) deploys should verify signatures or attestations at deploy/promote time and reject unsigned artifacts—proven by the last successful verified deploy plus a recorded unsigned-reject test or canary, not by CI signing or digest pins alone.","artifact":"Verify-on-deploy / promote-path policy + last production deploy verification log (signature/attestation success) + recorded unsigned-reject test/canary/deny log (measuredAt ≤90 days)","passCondition":"The last production model/container (or equivalent AI package) deploy verified a signature or attestation successfully; an unsigned artifact is rejected in a recorded test, canary, or deny log within 90 days (evidence measuredAt ≤90 days). If no production model/container AI artifacts are deployed, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"SCI-R2","requirement":"Each production model pin should have a machine-readable MBOM (or SBOM plus model-specific metadata) retained ≥90 days and linked from the model registry—proven by registry linkage and retained artifacts, not by a container-image SBOM that omits model weights and serving components.","artifact":"Machine-readable MBOM (preferred) or SBOM + model-specific metadata per production model pin; registry links; retention ≥90 days; coverage export (measuredAt ≤90 days)","passCondition":"100% of production model pins have a machine-readable MBOM (or SBOM plus model-specific metadata covering weights/adapters/tokenizers and serving stack as applicable) retained ≥90 days and linked from the model registry entry (coverage evidence measuredAt ≤90 days). If no production model pins exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2}],"evidenceRequired":["Artifact signing/verification configuration","MCP and tool inventory with review records","Image/model scan reports for production releases"],"engineeringBestPractices":["Prefer private registries for production models and adapters","Treat MCP hosts as supply-chain surfaces equal to npm/PyPI packages","Separate build and serving identities; never use developer credentials in prod pulls","Record provenance in release evidence packs"],"automaticValidations":["CI verification of artifact digests against expected values","Admission controller or gateway denials for unsigned artifacts","SBOM generation and CVE gates on AI images"],"manualValidations":["Source review for new MCP servers and tool plugins","Periodic audit of model download sources"],"examples":["Inference pods only pull images signed by the org signing key","An MCP catalog requires peer review and a pinned commit before agents can call it"],"references":[{"title":"SLSA — Supply-chain Levels for Software Artifacts","url":"https://slsa.dev/"},{"title":"CNCF Software Supply Chain Best Practices","url":"https://www.cncf.io/"},{"title":"OWASP LLM — Supply Chain Vulnerabilities","url":"https://owasp.org/www-project-top-10-for-large-language-model-applications/"}],"futureEvolution":"Portable MBOM formats and cross-vendor attestation for hosted and self-hosted models."},{"id":"APRF-20","slug":"infrastructure","name":"Infrastructure","summary":"Harden runtime, network, isolation, and supply chain for AI workloads.","domain":"security","crossCutting":false,"severity":"high","riskLevel":"high","purpose":"Provide secure, reliable runtime and network infrastructure for model serving, gateways, vector stores, agents, and MCP—including supply-chain integrity.","engineeringPhilosophy":"AI workloads inherit cloud security and SRE fundamentals, then add GPU/runtime and model-artifact supply-chain concerns. There is no AI exception to patching, isolation, or least privilege.","whyItMatters":"Compromised gateways, exposed vector DBs, or poisoned model artifacts undermine every application-layer control.","commonFailures":["Vector databases publicly reachable","Unpatched inference runtimes","Unsigned model artifacts from unverified sources","Overly broad network paths from agents to internal services"],"mandatoryChecks":[{"id":"INF-M1","requirement":"AI data stores and control planes shall not be publicly reachable without authentication—proven by a current CSPM or network scan plus authenticated edge controls or private-only exposure, not by private-subnet intent alone.","artifact":"Inventory of in-scope AI data stores and control-plane endpoints; CSPM/network scan covering those surfaces (measuredAt ≤90 days); Authenticated edge-control config, or private-only exposure proven by the scan; Open high/critical public-exposure findings closed or waived with owner and expiry","passCondition":"Inventory of in-scope AI data stores and control-plane endpoints exists; 0 of those endpoints are publicly reachable without authentication in the latest CSPM/network scan; findings severity ≥ high are closed or waived with owner and expiry; authenticated edge controls are configured or private-only exposure is proven by the scan (measuredAt ≤90 days). If no AI data stores or control planes exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"INF-M2","requirement":"Production AI runtime environments shall comply with the organization's documented patching SLA—or hold approved time-boxed waivers—proven by inventory plus vulnerability/age evidence, not by image-tag pinning alone.","artifact":"Documented patching SLA for production AI runtime environments; Inventory of production AI runtime environments (containers, VMs, serverless, managed AI platforms, or equivalent); Vulnerability scan and/or image/runtime age report covering that inventory (measuredAt ≤90 days); CVE/patch backlog disposition + waiver register for any SLA exceptions (owner and expiry)","passCondition":"Inventory of production AI runtime environments exists; a documented patching SLA covers those environments; 100% comply with that SLA or approved time-boxed waivers exist with owner and expiry; report shows 0 SLA breaches without such waivers and vulnerability/age evidence covers the inventory (measuredAt ≤90 days). If no production AI runtime environments exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"INF-M3","requirement":"Agent and tool runtimes shall communicate only with documented dependencies required for their intended function—enforced by least-privilege network and/or identity controls, not by open east-west access inside the environment.","artifact":"Inventory of agent/tool runtimes and their documented required dependencies; Least-privilege connectivity controls for those runtimes (network policy, security groups, service mesh, workload identity, egress gateway, private endpoints, or equivalent); Probe or reviewed test showing unauthorized internal-service access is blocked (measuredAt ≤90 days)","passCondition":"Inventory of agent/tool runtimes and their documented required dependencies exists; those runtimes can communicate only with those dependencies; attempts to access unauthorized internal services are blocked by network and/or identity controls (measuredAt ≤90 days). If no agent or tool runtimes exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"INF-M4","requirement":"Shared AI accelerator infrastructure shall enforce tenant isolation and noisy-neighbor controls—proven by documented isolation design plus a fresh isolation/capacity test meeting stated limits—not by GPU presence alone.","artifact":"Scope note: shared AI accelerator infrastructure present (or explicit N/A for managed-API/CPU-only/single-tenant/dedicated); Isolation design (GPU scheduling, MIG/vGPU, resource quotas, tenant QoS, or equivalent); Isolation and/or capacity test report meeting stated limits (measuredAt ≤90 days)","passCondition":"Inventory or explicit scope confirms shared AI accelerator infrastructure; isolation and noisy-neighbor controls are documented; and the latest isolation/capacity test (measuredAt ≤90 days) meets stated limits. If the organization does not operate shared AI accelerator infrastructure (e.g. managed-API-only, CPU-only, single-tenant, or dedicated GPU per workload), score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":5,"minCriticality":3}],"recommendedChecks":[{"id":"INF-R1","requirement":"Deprecated: superseded by SCI-R1 (SLSA-aligned signed model/container verify-on-deploy). Retained for N−1 readers; new assessments should use the supply-chain successor Check.","artifact":"Cluster/admission controller config requiring signed images + last failed-unsigned admission event or drill","passCondition":"Unsigned model/container images cannot schedule in production namespaces; policy verified by a failed admission test within 90 days. Prefer scoring SCI-R1 instead.","method":"manual","minimumTier":"E1","requiredFromLevel":4,"minCriticality":2,"deprecated":true,"replacedBy":"SCI-R1","deprecationNote":"Superseded by SCI-R1 (SLSA-aligned signed model/container verify-on-deploy). Retained for N−1 readers; new assessments should use SCI-R1."},{"id":"INF-R3","requirement":"Production AI infrastructure shall be declared in infrastructure-as-code with CIS-aligned (or equivalent) policy checks on every apply/PR—proven by IaC modules, policy-scan config, and a fresh production-stack report—not by console-built stacks alone.","artifact":"IaC modules covering production AI infrastructure; CIS-aligned (or equivalent) policy-scan config wired to apply/PR; Latest policy-scan report for production stacks (measuredAt ≤90 days); Critical findings closed or waived with owner and expiry","passCondition":"Production AI infrastructure is declared in IaC; CIS-aligned (or equivalent) policy checks run on every apply/PR; critical findings for production stacks are 0 or have dated exceptions with owner and expiry (measuredAt ≤90 days). If no production AI infrastructure is managed by the organization, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2}],"evidenceRequired":["Network diagrams for AI components","Patch and image scan reports","Artifact signing/verification configuration"],"engineeringBestPractices":["Prefer private networking to providers where available","Harden MCP hosts as internet-facing services","Separate training/fine-tune clusters from serving","Apply CIS benchmarks to hosts and Kubernetes where used"],"automaticValidations":["CSPM/misconfiguration scanning","Image CVE gates in CI","Admission controllers verifying signatures"],"manualValidations":["Architecture review for new inference deployments","Supply-chain review for third-party model downloads"],"examples":["A self-hosted Llama deployment sits behind a private gateway with mTLS","Vector DB accepts connections only from the RAG service identity"],"references":[{"title":"CIS Benchmarks","url":"https://www.cisecurity.org/cis-benchmarks"},{"title":"CNCF security technical advisory guidance","url":"https://www.cncf.io/"},{"title":"AWS Well-Architected — Security","url":"https://aws.amazon.com/architecture/well-architected/"}],"futureEvolution":"Attested inference environments and standardized model artifact signing ecosystems."},{"id":"APRF-25","slug":"safety-responsible-ai","name":"Safety & Responsible AI","summary":"Prevent harmful content and unfair outcomes—NIST trustworthiness beyond adversarial security.","domain":"safety","crossCutting":false,"severity":"critical","riskLevel":"high","purpose":"Define and enforce content-safety, harm-prevention, fairness/bias, and user-facing AI disclosure requirements appropriate to the product domain and risk tier.","engineeringPhilosophy":"Safety is not a synonym for security. Adversarial controls stop attackers; safety controls stop harmful or unfair outcomes for users and society. Both are required for production readiness.","whyItMatters":"Systems can be “secure” yet produce toxic, discriminatory, or undisclosed AI-generated content that creates regulatory, brand, and user harm.","commonFailures":["No domain-specific AI safety policy (harm categories + refusal/escalation)","Safety filters only on output, not on tool-mediated side effects","No fairness or disparity testing for high-stakes decisions","Users not informed when they interact with AI"],"mandatoryChecks":[{"id":"SAF-M1","requirement":"Product domains shall maintain a versioned, owned AI safety policy that includes domain-specific harm categories with refuse-vs-escalate actions for each—so safety filters and human escalation are grounded in explicit policy, not ad-hoc judgment.","artifact":"Approved domain-specific AI safety policy (versioned, owned) including harm categories and refusal/escalation + Evidence each domain-minimum harm category maps refuse vs escalate + Last review record ≤12 months with named owner","passCondition":"Domain-specific AI safety policy has version, owner, and review date ≤12 months; maps ≥ domain-minimum harm categories with explicit refuse vs escalate actions for each (measuredAt ≤90 days). If the product has no AI user- or tool-facing behavior in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"SAF-M2","requirement":"In-scope releases shall run an automated safety evaluation suite with numeric thresholds that blocks promote on fail—unless a time-boxed waiver (expiry ≤14 days) with a named owner is recorded.","artifact":"Safety suite definition with numeric thresholds + CI/gate reports covering in-scope releases in the last 30 days (100%) + Waiver register for gate failures (owner + expiry ≤14 days) when used","passCondition":"Safety gate executed on 100% of in-scope releases in the last 30 days; fail blocks promote unless a time-boxed waiver (expiry ≤14 days) with owner is recorded (measuredAt ≤90 days). If no in-scope AI releases exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"SAF-M3","requirement":"Where policy or law requires it, in-scope user surfaces shall disclose that the user is interacting with AI—so people are not misled about automated vs human counterparts.","artifact":"Disclosure UX inventory of in-scope user surfaces (policy checklist) + Latest screenshot/checklist audit showing coverage + critical-surface status","passCondition":"AI-interaction disclosure present on 100% of in-scope user surfaces per policy checklist; 0 critical surfaces missing disclosure in the latest audit (measuredAt ≤90 days). If policy or law does not require AI-interaction disclosure for in-scope surfaces, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"SAF-M4","requirement":"When AI influences or automates high-stakes decisions (rights, opportunities, or access to essential services), those paths shall be inventoried and covered by a retained fairness/disparity evaluation with numeric thresholds and named owners. If the system has no such paths, score NOT_APPLICABLE.","artifact":"Scope attestation: whether AI influences/automates high-stakes decisions + Inventory of in-scope high-stakes decision paths (when applicable) + Fairness/disparity eval methodology + latest run report with thresholds and owners (≤90 days)","passCondition":"If the system influences or automates high-stakes decision paths, those paths are inventoried and the latest fairness/disparity eval (≤90 days) is retained with thresholds and named owners (measuredAt ≤90 days). If no high-stakes decision paths exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":3}],"recommendedChecks":[{"id":"SAF-R1","requirement":"Production systems should sample safety edge cases on a defined cadence (≥ monthly or per release), with a retained review packet that dispositions each fail/edge case and links backlog items when needed.","artifact":"Safety edge-case sampling plan (sample size + cadence) + Last review packet ≤90 days (labels, dispositions, reviewer names, backlog links when needed)","passCondition":"Defined sample size and cadence (≥ monthly or per release); last packet ≤90 days includes disposition for each fail/edge case and links to backlog items when needed, with reviewer names (measuredAt ≤90 days). If no production AI with safety-relevant outputs exists, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"SAF-R2","requirement":"Production systems should run a jailbreak-to-harm red-team suite—distinct from security injection corpora—that covers documented harm categories, meets refusal/safety thresholds on a run ≤90 days old, and routes findings into the safety backlog with owners.","artifact":"Jailbreak-to-harm red-team suite definition (explicitly distinct from security injection suite) + Latest scored run report ≤90 days vs refusal/safety thresholds + Safety backlog items for findings with named owners","passCondition":"A jailbreak-to-harm red-team suite (distinct from the security injection suite) covers documented harm categories; the latest run ≤90 days meets refusal/safety thresholds; findings feed the safety backlog with named owners (measuredAt ≤90 days). If no production AI with user- or tool-facing generation exists, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2}],"evidenceRequired":["Domain-specific AI safety policy document","Safety eval suite definitions and recent gate results","Disclosure UX or policy evidence"],"engineeringBestPractices":["Separate safety eval datasets from adversarial security corpora","Fail closed on high-severity harm categories","Align safety thresholds to criticality tier, not headcount","Log safety refusals for measurement without storing unnecessary sensitive content"],"automaticValidations":["CI safety-gate failures block release","Online monitoring of refusal rates and safety classifier signals","Regression tests for known harmful prompt classes"],"manualValidations":["Domain expert review of the AI safety policy and harm categories","Periodic calibration of automated safety graders vs human labels"],"examples":["A tutoring agent refuses self-harm content and escalates to a human protocol","A lending assistant reports group disparity metrics before each model promotion"],"references":[{"title":"NIST AI RMF — Trustworthiness characteristics","url":"https://www.nist.gov/itl/ai-risk-management-framework"},{"title":"ISO/IEC 42001 — AI management systems","url":"https://www.iso.org/standard/81230.html"}],"futureEvolution":"Shared harm taxonomies and portable safety scorecards across model providers."},{"id":"APRF-26","slug":"explainability","name":"Explainability & Transparency","summary":"Make AI decisions reconstructable for operators, users, and auditors—not only for debugging.","domain":"safety","crossCutting":false,"severity":"high","riskLevel":"medium","purpose":"Provide appropriate explanations, citations, and decision traces so users, operators, and auditors can understand why the system produced an outcome.","engineeringPhilosophy":"Observability serves operators; explainability serves people affected by decisions and those who govern them. Production AI must support both audiences.","whyItMatters":"Opaque decisions block dispute resolution, regulatory review, and user trust—especially in high-stakes or regulated contexts.","commonFailures":["No citations for RAG answers that claim factual authority","Tool-driven actions with no human-readable rationale","Explanations that leak sensitive internal data","No audit-facing decision summary for contested outcomes"],"mandatoryChecks":[{"id":"EXP-M1","requirement":"High-stakes or factual RAG answers shall include ≥1 valid source ID or citation that resolves to an authorized corpus document—so operators and users can verify where the claim came from.","artifact":"Factual/high-stakes RAG eval suite measuring citation presence + Eval report showing ≥90% answers with ≥1 resolvable citation/source ID + Sample production traces with citations (supporting evidence)","passCondition":"On the factual/high-stakes RAG eval set, ≥90% of answers include ≥1 valid source ID/citation that resolves to an authorized corpus document (measuredAt ≤90 days). If no factual or high-stakes RAG outputs exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"EXP-M2","requirement":"Operators shall reconstruct the production decision path (model→retrieval/tools→outcome) for sampled traces within a documented time budget—so incidents and disputes can be explained from retained evidence, not guesswork.","artifact":"Operator reconstruction procedure with documented time budget + Timed drill record covering ≥3 sampled production traces (≤90 days) + Evidence each sample reconstructed model→retrieval/tools→outcome within budget","passCondition":"On-call or operator successfully reconstructs model→retrieval/tools→outcome for 3/3 sampled production traces within the documented time budget (e.g. ≤15 minutes each; measuredAt ≤90 days). If no production AI outcomes with reconstructable paths exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"EXP-M3","requirement":"Explanation payloads (user-facing rationales, operator reconstructions, citation snippets) shall redact or block secrets and unauthorized data—so explainability does not become a leak path.","artifact":"Explanation redaction/blocking policy covering explanation payloads + Automated test showing 100% redaction/block of synthetic secret/PII fixtures + Production explanation sample scan with 0 privileged secret pattern hits (≤90 days)","passCondition":"Synthetic secret/PII fixtures in explanation paths are redacted or blocked at 100% in tests; latest production explanation sample scan shows 0 privileged secret pattern hits (measuredAt ≤90 days). If no explanation payloads exist (user rationale, operator reconstruction, citation snippets, or equivalent), score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2}],"recommendedChecks":[{"id":"EXP-R1","requirement":"Material automated decisions should return a user-facing rationale (API field or UI explanation) so affected people can understand why the system acted—not only operators reconstructing traces after the fact.","artifact":"Material automated-decision catalog (decision types marked material) + ≥20-case sample showing user-facing rationale for each material type (100% coverage) + Gap list with named owners for any missing rationale","passCondition":"100% of decision types marked material in the catalog return a rationale field or UI explanation in a ≥20-case sample; gaps are tracked with named owners (measuredAt ≤90 days). If no material automated decisions exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"EXP-R2","requirement":"Every regulated AI feature should list the required explanation type and evidence in a maintained matrix—so compliance obligations are explicit, owned, and reviewable rather than implied by adjacent controls.","artifact":"Explainability requirements matrix (feature × regulation/obligation) + Last compliance review record ≤12 months with named owner","passCondition":"Every regulated AI feature lists required explanation type and evidence; the matrix was reviewed ≤12 months ago with a named owner (attest measuredAt ≤90 days). If no regulated AI features exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"EXP-R3","requirement":"Material model or prompt promotions should retain a change or counterfactual summary describing what differed and expected impact—so operators can explain version-to-version behavior without archaeology.","artifact":"Change/counterfactual summary tooling or template for model/prompt promotions + Retained summary for the last material model or prompt promotion (≤90 days)","passCondition":"The last material model or prompt promotion includes a retained change or counterfactual summary (measuredAt ≤90 days). If no material model or prompt promotions occur, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":5,"minCriticality":3}],"evidenceRequired":["Example cited answers (redacted)","Operator reconstruction procedure","Policy for explanation disclosure vs confidentiality"],"engineeringBestPractices":["Prefer source-grounded answers over free-form claims when stakes are high","Separate debug traces (privileged) from user explanations (minimized)","Version explanation formats with the product"],"automaticValidations":["Eval gates for citation presence/accuracy on RAG suites","Tests that explanation redaction strips secrets"],"manualValidations":["Legal/compliance review of explanation content for regulated flows","UX review of explanation clarity"],"examples":["A support bot cites knowledge-base article IDs with every policy answer","An underwriting assistant produces an auditor-facing feature contribution summary"],"references":[{"title":"NIST AI RMF — Explainability and Interpretability","url":"https://www.nist.gov/itl/ai-risk-management-framework"}],"futureEvolution":"Standard explanation schemas for agentic and tool-mediated decisions."},{"id":"APRF-18","slug":"data-privacy","name":"Data Privacy","summary":"Minimize, classify, and protect data flowing through AI pipelines.","domain":"data","crossCutting":false,"severity":"critical","riskLevel":"high","purpose":"Minimize collection and exposure of personal and sensitive data across prompts, retrieval, memory, logs, and third-party model providers.","engineeringPhilosophy":"Privacy by design for AI means data minimization, purpose limitation, residency awareness, and contractual/technical controls on processors—not only a privacy policy page.","whyItMatters":"AI pipelines concentrate sensitive data. Over-collection and uncontrolled provider sharing create regulatory, contractual, and trust failures even when 'security' looks fine.","commonFailures":["Sending full customer records to external models when aggregates would do","No data classification for prompt contents","Training or eval sets with uncleared personal data","Ignoring residency requirements when choosing providers"],"mandatoryChecks":[{"id":"PRI-M1","requirement":"Every production path that sends data to models shall apply a documented classification scheme covering AI payload classes, and every sensitive class shall have written handling rules (allow, redact, block, or equivalent).","artifact":"Data classification scheme covering AI/model-bound payload classes + Handling rules for each sensitive class (allow / redact / block or equivalent) + Automated or sampled audit showing 100% of sampled production model requests tagged, with sensitive handling matching policy","passCondition":"A classification scheme covers AI payload classes; ≥1 automated or sampled audit shows 100% of sampled production model requests tagged with a class; sensitive-class handling matches documented policy (audit/scheme measuredAt ≤90 days). If no production traffic sends data to models, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"PRI-M2","requirement":"Where regulation or policy requires it, users or tenants shall have documented deletion and/or export paths that cover AI memory (conversation, durable, or retrieval-augmented stores) and in-scope AI logs, with a tested completion within a published SLA.","artifact":"Deletion/export procedure or API covering AI memory and in-scope AI logs + Successful test execution record for a sample tenant/user with measured duration vs SLA","passCondition":"Documented API/runbook covers AI memory and in-scope logs; a test shows deletion/export completes within SLA for a sample tenant/user with measured duration recorded (test evidence measuredAt ≤90 days). If neither memory nor in-scope logs exist, or deletion/export is not required, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"PRI-M3","requirement":"Regulated workloads shall be labeled, and model/tool routing shall keep 100% of sampled regulated requests in approved regions—enforced by policy or gateway controls, not prompt instructions alone.","artifact":"Routing policy config naming approved regions for regulated tenants/workloads + Sample routing decisions (or deny logs) showing 100% of sampled regulated requests stayed in approved regions","passCondition":"Regulated workloads are labeled; 100% of sampled regulated requests stay in approved regions (routing sample/policy evidence measuredAt ≤90 days). If no regulated workloads or tenants are in scope, or residency constraints do not apply, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":3}],"recommendedChecks":[{"id":"PRI-R1","requirement":"Production paths that send data to models should tokenize or redact documented high-sensitivity fields before the model call, with fail-closed behavior when redaction errors.","artifact":"Inventory or policy listing high-sensitivity fields subject to pre-model tokenization/redaction + Pre-model tokenization/redaction pipeline config with fail-closed on redaction errors + Sample of ≥50 production model requests showing 0 cleartext hits for those fields","passCondition":"Documented high-sensitivity fields never appear in cleartext in ≥50 sampled production model requests; the pre-model tokenization/redaction pipeline fails closed on errors (sample/pipeline evidence measuredAt ≤90 days). If production does not send data to models or no high-sensitivity fields are in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"PRI-R2","requirement":"Every production third-party model provider should have a dated review of processing terms covering training use and retention, with a named owner; reviews older than 12 months should be treated as missing.","artifact":"Inventory of production model providers + Vendor terms review records (DPA/training/retention) with date and owner per provider","passCondition":"100% of production model providers have a review record ≤12 months covering training use and retention; 0 unreviewed providers in the inventory (inventory measuredAt ≤90 days; each review dated ≤365 days). If all models are fully self-hosted with no third-party processing, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"PRI-R3","requirement":"Every major in-scope AI feature should have a completed DPIA/PIA (or equivalent privacy assessment) with owner sign-off before production traffic.","artifact":"Inventory of major in-scope AI features in or entering production + Completed DPIA/PIA (or equivalent) with owner sign-off per feature, dated before production traffic","passCondition":"100% of major in-scope AI features have a completed DPIA/PIA (or equivalent) with owner sign-off dated before production traffic (inventory/assessment evidence measuredAt ≤90 days). If no major in-scope AI features exist (or are entering production), score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2}],"evidenceRequired":["Data flow diagrams for AI features","Provider DPA/terms review records","Deletion/export procedure evidence"],"engineeringBestPractices":["Default to least data in context","Separate privacy tiers of models (e.g., self-hosted for sensitive)","Ban pasting production data into consumer AI tools for debugging","Review eval datasets for personal data before publication"],"automaticValidations":["DLP scanning on outbound model payloads where feasible","Policy checks preventing disallowed data classes from leaving the VPC","Automated deletion job verification"],"manualValidations":["Privacy review for new AI features","Vendor assessments for new model providers"],"examples":["Support transcripts are redacted before being sent to an external LLM","A healthcare workload uses a residency-locked or self-hosted model path"],"references":[{"title":"NIST AI RMF — privacy considerations","url":"https://www.nist.gov/itl/ai-risk-management-framework"},{"title":"OWASP LLM — Sensitive Information Disclosure","url":"https://owasp.org/www-project-top-10-for-large-language-model-applications/"}],"futureEvolution":"Machine-readable privacy labels for model endpoints and agent capabilities."},{"id":"APRF-27","slug":"data-governance","name":"Data Governance & Quality","summary":"Govern corpora, indexes, labels, and feedback loops—distinct from privacy controls.","domain":"data","crossCutting":false,"severity":"high","riskLevel":"high","purpose":"Own lineage, quality, labeling, retrieval-index governance, and train/serve consistency for data that shapes AI behavior.","engineeringPhilosophy":"Privacy asks who may see data; governance asks whether the data is fit for purpose. Bad corpora and poisoned indexes create silent production failures.","whyItMatters":"Hallucinations, biased outcomes, and retrieval failures often originate in unmanaged data—not in the model alone.","commonFailures":["RAG indexes with no freshness or ownership","Eval and fine-tune sets without label quality review","Feedback loops that reinforce errors into memory or training","No lineage from production answer to source document version"],"mandatoryChecks":[{"id":"DG-M1","requirement":"Every production retrieval corpus and index shall have a named owner, a version ID, and a refresh cadence; indexes stale beyond cadence shall be flagged or rebuilt.","artifact":"Corpus/index inventory listing production indexes with owner, version ID, and refresh schedule + Evidence stale-beyond-cadence indexes are flagged or rebuilt","passCondition":"100% of production indexes have owner + version ID + refresh cadence; 0 indexes missing any field; stale beyond cadence are flagged or rebuilt (inventory measuredAt ≤90 days). If no production retrieval corpora or vector indexes exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"DG-M2","requirement":"Every dataset used in production eval gates or fine-tunes shall have documented provenance and quality criteria, and promotion shall be blocked when those are missing.","artifact":"Dataset cards or registry entries for eval/fine-tune sets covering provenance and quality criteria + CI or review-checklist evidence that promotion is blocked when cards are missing","passCondition":"100% of datasets used in production gates or fine-tunes have provenance + quality criteria documented; promotion is blocked if missing (CI or review checklist evidence; inventory measuredAt ≤90 days). If no in-scope evaluation or fine-tuning datasets exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"DG-M3","requirement":"Every path that promotes user feedback or working memory into durable memory or training data shall require a policy check or human approval, and ungated promotion shall be denied by test.","artifact":"Promotion policy listing feedback/memory→durable/training write paths + Write-path controls (policy engine or human approval) on those paths + Automated tests showing ungated promotion is denied","passCondition":"100% of feedback→durable-memory/training promotion paths require a policy check or human approval; automated tests show ungated promotion is denied (deny evidence measuredAt ≤90 days). If no such write path exists, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2}],"recommendedChecks":[{"id":"DG-R1","requirement":"Each critical corpus shall have a documented freshness SLO, ≥95% of sampled docs shall meet that SLO in the last 7 days, and an alert shall fire on freshness breach.","artifact":"Freshness SLO definitions for each critical corpus ID + Dashboard or job report showing ≥95% SLO compliance over the last 7 days + Alert config (or firing proof) covering freshness breaches","passCondition":"Each critical corpus has a documented freshness SLO (e.g. max age hours); ≥95% of sampled docs meet the SLO in the last 7 days; an alert fires on freshness breach (sample/alert evidence measuredAt ≤7 days). If no critical production corpora/indexes exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"DG-R2","requirement":"Every production embedding or feature pipeline shall run a train/serve skew job within the last 7 days, document at least one skew threshold, and open a tracked ticket or page on breach.","artifact":"Skew monitor config covering each production embedding/feature pipeline + Last weekly (or ≤7-day) skew report comparing train vs serve distributions + Threshold definition plus ticket/page routing on breach","passCondition":"A skew job ran within the last 7 days for every production embedding/feature pipeline; at least one documented threshold exists; breach creates a tracked ticket or page (job/alert evidence measuredAt ≤7 days). If no production embedding or feature pipelines exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"DG-R3","requirement":"Every major eval or fine-tune set used in production promotion shall have a dataset card covering purpose, source, PII handling, and a last-updated date within 12 months.","artifact":"Dataset cards (or registry metadata) for each major eval and fine-tune corpus + Fields covering purpose, source, PII handling, and last-updated date","passCondition":"100% of major eval/fine-tune sets used in production promotion have a dataset card with purpose, source, PII handling, and last-updated date ≤12 months (inventory measuredAt ≤90 days; card last-updated ≤365 days). If no major eval or fine-tune sets are used in production promotion, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2}],"evidenceRequired":["Corpus/index inventory with owners","Data quality criteria and sample reviews","Lineage examples from answer to source version"],"engineeringBestPractices":["Treat indexes as release artifacts with version IDs","Separate experimental corpora from production indexes","Review user-generated feedback before it becomes training signal"],"automaticValidations":["Index build pipelines emit version and checksum","Alerts on stale critical corpora","CI checks that eval datasets meet schema/quality gates"],"manualValidations":["Periodic corpus content audits","Label quality sampling"],"examples":["A policy RAG index is rebuilt nightly with a new version ID and canary before cutover","Fine-tune data requires dual review before entering the training set"],"references":[{"title":"NIST AI RMF — Map and Measure (data)","url":"https://www.nist.gov/itl/ai-risk-management-framework"},{"title":"ML systems engineering — data quality practices","url":"https://ml-ops.org/"}],"futureEvolution":"Portable dataset and index manifests with integrity proofs across vendors."},{"id":"APRF-04","slug":"memory-management","name":"Memory Management","summary":"Control retention, isolation, and poisoning of short- and long-term memory.","domain":"data","crossCutting":false,"severity":"high","riskLevel":"high","purpose":"Govern what the system remembers across turns and sessions—including user memory, agent state, and shared multi-agent memory—with retention, isolation, and integrity controls.","engineeringPhilosophy":"Memory is persistent attack surface and privacy liability. Default to minimal retention, strict tenancy isolation, and verifiable write paths. Memory that cannot be deleted or audited is not production-ready.","whyItMatters":"Poisoned or leaked memory causes lasting incorrect behavior, cross-tenant data exposure, and compliance failures. Autonomous agents amplify memory risk by writing their own state.","commonFailures":["Shared memory stores without tenant isolation","No user-facing or admin deletion path","Agents write unverified 'facts' into long-term memory","Memory reused across products without re-consent or reclassification"],"mandatoryChecks":[{"id":"MEM-M1","requirement":"AI memory stores (conversation, durable, and retrieval/vector memory) shall enforce tenant isolation—and user isolation where policy requires it—proven by automated attack tests with zero successful unauthorized reads or writes.","artifact":"Inventory or scope note of in-scope AI memory APIs (conversation, durable, vector/retrieval) + Cross-tenant (and cross-user where required) isolation attack suite results for those memory APIs","passCondition":"0 successful cross-tenant (and cross-user where required) memory reads/writes across ≥10 automated attack cases covering in-scope memory APIs (suite evidence measuredAt ≤90 days). If no tenant or user AI memory is retained (conversation, durable, or vector/retrieval), score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"MEM-M2","requirement":"Every in-scope AI memory class shall have a documented retention period and an executable TTL or deletion job; a test shall show sample records older than retention are absent after the job runs.","artifact":"Retention policy naming periods per AI memory class (conversation, durable, vector/retrieval, or equivalent) + TTL or deletion job config covering those memory classes + Successful deletion/TTL test record showing older-than-retention samples absent after job run","passCondition":"Policy documents retention periods per memory class; a TTL/deletion job succeeds in test and sample records older than retention are absent after the job run (policy/job/test evidence measuredAt ≤90 days). If no in-scope AI memory class is retained (conversation, durable, vector/retrieval, or equivalent), score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"MEM-M3","requirement":"Writes to durable/long-term AI memory shall be gated by a policy that enumerates allowed writers and content classes; unauthorized writers shall be denied at 100% in automated tests.","artifact":"Write policy for durable/long-term memory naming allowed writers and content classes + Write-policy enforcement config (middleware, gateway, or store gate) + Automated deny tests showing 100% rejection of unauthorized writers","passCondition":"Policy enumerates allowed writers and content classes for durable/long-term memory; unauthorized writers are denied at 100% in automated tests (policy/test evidence measuredAt ≤90 days). If no durable/long-term AI memory exists (ephemeral session context alone does not count), score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"MEM-M4","requirement":"Critical AI memory classes shall be inventoried and protected with cryptographic or signed integrity controls; the latest verification for those classes shall succeed.","artifact":"Inventory of critical AI memory classes requiring integrity protection + Integrity/signing design or config for those classes (MAC, signature, sealed object, or equivalent) + Latest verification sample showing successful integrity/signature checks for inventoried classes","passCondition":"Critical memory classes are inventoried; cryptographic verification or signature checks succeed for 100% of those classes in the latest check (inventory/verification evidence measuredAt ≤90 days). If no AI memory classes are designated critical, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":5,"minCriticality":3}],"recommendedChecks":[{"id":"MEM-R1","requirement":"The adversarial or memory eval suite should include at least five memory poisoning scenarios—including cross-tenant write, prompt-in-memory, and stale trusted fact—executed within 90 days, with critical fails blocking promotion or requiring documented risk acceptance.","artifact":"Memory-poisoning cases in the adversarial/eval suite covering the required scenario types + Latest suite run report with pass/fail per case and gate or risk-acceptance disposition for critical fails","passCondition":"≥5 memory-poisoning scenarios are executed (including cross-tenant write, prompt-in-memory, and stale trusted fact); critical fails block promotion or have documented risk acceptance (suite evidence measuredAt ≤90 days). If no poisonable AI memory exists (conversation, durable, or vector/retrieval), score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"MEM-R3","requirement":"Working (short-lived) memory should be separated from durable memory; promotion into durable stores should require an explicit rule; recent promotions should record rule ID and actor; and TTL should differ by memory class.","artifact":"Memory architecture doc or config showing distinct working vs durable stores + Promotion rules that gate working→durable writes + Sample promotion audit (≥10 recent promotions with rule ID and actor) and TTL config differing by memory class","passCondition":"Working memory cannot silently become durable without a promotion rule; the last 10 promotions show rule ID and actor; TTL differs by memory class (architecture/audit evidence measuredAt ≤90 days). If only one class exists with no promotion path, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2}],"evidenceRequired":["Data retention schedule for AI memory stores","Isolation test results","Deletion and export procedure evidence"],"engineeringBestPractices":["Classify memory types: ephemeral session, user profile, agent scratchpad, org knowledge","Require confidence or human confirmation before promoting scratch facts to durable memory","Encrypt memory at rest; restrict operational access","Log memory writes for audit without logging raw sensitive values when avoidable"],"automaticValidations":["Automated tenant isolation tests","TTL enforcement jobs","Write-policy middleware on memory APIs"],"manualValidations":["Privacy review of memory schemas","Red-team attempts to poison shared agent memory"],"examples":["A personal assistant forgets user preferences on request within SLA","Multi-agent systems use namespaced memory; one agent cannot read another's private scratchpad"],"references":[{"title":"NIST AI RMF — Govern and Manage","url":"https://www.nist.gov/itl/ai-risk-management-framework"},{"title":"OWASP LLM — Training Data Poisoning / Vector and Embedding Weaknesses","url":"https://owasp.org/www-project-top-10-for-large-language-model-applications/"}],"futureEvolution":"Portable memory consent receipts and cross-vendor memory export formats with integrity proofs."},{"id":"APRF-07","slug":"model-governance","name":"Model Governance","summary":"Own model selection, versioning, deprecation, and capability boundaries.","domain":"model-lifecycle","crossCutting":false,"severity":"high","riskLevel":"high","purpose":"Control which models (hosted or self-hosted) may be used in which environments, how they are versioned, evaluated, deprecated, and constrained by capability.","engineeringPhilosophy":"Models are dependencies with behavioral contracts. Pin versions, document capabilities and known failure modes, and never silently change the production model under a customer-facing workload.","whyItMatters":"Provider default model changes, shadow upgrades, and unvetted open weights introduce quality, cost, security, and compliance regressions that teams discover only after incidents.","commonFailures":["Using 'latest' model aliases in production","No inventory of models and where they run","Self-hosted models without supply-chain or license review","Routing to cheaper models without eval coverage for those routes"],"mandatoryChecks":[{"id":"MOD-M1","requirement":"Critical production AI paths shall reference immutable, pinned model identifiers, and shall not use floating aliases such as “latest” (or equivalent provider defaults that can change without a deploy).","artifact":"Production model pin config (or registry) listing immutable model IDs on critical paths + Lint or CI rule that rejects “latest”/floating aliases on those paths","passCondition":"0 “latest”/floating aliases on critical production paths; 100% of those paths reference immutable model IDs; lint or CI rejects floating aliases (pin evidence measuredAt ≤90 days). If no production AI paths call hosted or self-hosted models, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"MOD-M2","requirement":"Every production model promotion (version bump, pin change, or registry cutover) shall link a passing eval artifact, and the promotion path shall block promote-without-eval—not rely on informal review alone.","artifact":"Promotion policy or CI/registry rule requiring an eval pass artifact on model version bumps + Promotion log (or CI matrix) for the last 30 days showing linked eval pass artifacts; 0 promote-without-eval","passCondition":"100% of production model promotions in the last 30 days have linked eval pass artifacts; promote-without-eval is blocked by gate (promotion evidence measuredAt ≤90 days). If no production model promotions occur (pin changes, registry cutovers, or version bumps), score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2}],"recommendedChecks":[{"id":"MOD-R1","requirement":"Production systems should publish a deprecation and sunset policy for models and embeddings that defines notice periods and forced-sunset rules, record sunset dates for superseded production pins in the registry, and keep undocumented pins past sunset at zero (exceptions time-boxed).","artifact":"Model/embedding deprecation and sunset policy (notice period + forced-sunset rules) + Registry export showing sunset dates for superseded pins; query of undocumented pins past sunset = 0","passCondition":"Policy defines notice period and forced-sunset rules; ≥1 superseded production model/embedding has a sunset date in the registry; undocumented pins past sunset = 0 without exception (deprecation evidence measuredAt ≤90 days). If production uses no hosted or self-hosted models/embeddings that can be superseded, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"MOD-R2","requirement":"Each production AI workload should declare an explicit allowlist of model capabilities it may use (for example code execution, vision, browsing, or tool-calling modes), and denied capability attempts should be recorded in test or production within 90 days.","artifact":"Per-workload capability allowlist config (code execution, vision, browsing, etc.) + Deny log or test fixture showing a denied capability attempt within 90 days","passCondition":"Each production workload has an explicit capability allowlist; ≥1 denied capability attempt is recorded in test or prod within 90 days (allowlist evidence measuredAt ≤90 days). If models are text-only with no optional capabilities, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"MOD-R3","requirement":"Every open-weight or fine-tuned model in production should have a completed license and provenance review ≤12 months old, and any blocked or restricted licenses should carry a documented exception with owner and expiry.","artifact":"License/provenance review checklist (or registry fields) for open-weight and fine-tuned models + Completed reviews ≤12 months old for each such production model; exceptions for blocked licenses with expiry","passCondition":"100% of open-weight/fine-tuned production models have a license+provenance review ≤12 months old; blocked licenses have documented exceptions with expiry (review evidence measuredAt ≤90 days). If all production models are proprietary hosted APIs with no local/fine-tuned weights, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"MOD-R4","requirement":"Production AI systems should keep a queryable model inventory (or registry) in which every production model records a named owner, data-residency constraint, and intended use—with zero incomplete rows on those fields.","artifact":"Model inventory / registry export listing production models + Query or attestation showing 0 incomplete owner/residency/intended-use rows","passCondition":"100% of production models have owner, residency, and intended-use fields; inventory query returns 0 incomplete rows (inventory evidence measuredAt ≤90 days). If no production AI paths call hosted or self-hosted models, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2}],"evidenceRequired":["Model inventory and version pins","Change records for model promotions","Eval comparisons for model swaps"],"engineeringBestPractices":["Abstract provider SDKs behind an internal model gateway with policy","Track embedding model versions separately—index rebuilds are part of change","Document fallback models and degraded modes","Separate experimental models into non-production projects"],"automaticValidations":["Config lint rejecting unpinned model IDs in production configs","Gateway deny rules for unapproved models","CI requiring eval artifact for model version bumps"],"manualValidations":["Architecture review when introducing a new model family","Legal/compliance review for data-processing terms of new providers"],"examples":["Production chat uses provider-model-2025-03-01; canaries test the next pin before cutover","A coding agent is restricted to models that meet internal code-exfiltration evals"],"references":[{"title":"NIST AI RMF — Map","url":"https://www.nist.gov/itl/ai-risk-management-framework"},{"title":"AWS Well-Architected — Operational Excellence (change management parallels)","url":"https://aws.amazon.com/architecture/well-architected/"}],"futureEvolution":"Model bill of materials (MBOM) standards and portable evaluation attestations across vendors."},{"id":"APRF-02","slug":"prompt-engineering","name":"Prompt Engineering","summary":"Treat prompts as versioned production artifacts with regression control.","domain":"model-lifecycle","crossCutting":false,"severity":"high","riskLevel":"high","purpose":"Manage system, developer, and tool prompts as first-class production artifacts—versioned, reviewed, tested, and rolled back like application code.","engineeringPhilosophy":"Prompts are code. They change behavior, create regressions, and carry security and cost implications. Informal edits in dashboards without lineage are an anti-pattern for production AI.","whyItMatters":"Silent prompt drift is a leading cause of quality and safety regressions. Without versioning and eval gates, teams cannot answer what changed when production behavior breaks.","commonFailures":["Editing production prompts directly in a vendor console with no history","No golden-set regression tests when prompts change","Mixing business logic, safety policy, and tone in one unmaintainable blob","Different prompts per environment with no promotion path"],"mandatoryChecks":[{"id":"PRM-M1","requirement":"Every production prompt shall carry an immutable version identifier and a named owner in a registry (or equivalent versioned store)—with zero unversioned production prompts and zero prompts missing an owner.","artifact":"Prompt registry (or versioned prompt store) listing production prompts with immutable version IDs + Owner field populated for each production prompt; query showing 0 unversioned / 0 missing-owner","passCondition":"100% of production prompts have an immutable version ID and named owner; 0 unversioned production prompts (registry evidence measuredAt ≤90 days). If the system ships no production prompts (templates, system prompts, or managed prompt configs), score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"PRM-M2","requirement":"Production prompt releases shall go through human (or equivalent) review and link a passing eval artifact before promotion, with promote-without-review-and-eval blocked on the release path.","artifact":"Change records linking prompt versions to review IDs and eval pass artifacts + CI/registry gate (or equivalent) blocking promote without review + eval","passCondition":"100% of production prompt releases in the last 30 days have a review ID and eval pass artifact; promote-without-both is blocked (release evidence measuredAt ≤90 days). If no production prompt releases occur, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"PRM-M3","requirement":"Production systems shall restore a prior prompt version within a documented RTO without a full application redeploy—proven by a timed restore test in the last 90 days.","artifact":"Prompt rollback procedure documenting RTO and restore without full app redeploy + Timed restore test record showing prior prompt version restored within RTO (≤90 days)","passCondition":"Prior prompt version restored in ≤ documented RTO without full app redeploy; demonstrated in the last 90 days (restore evidence measuredAt ≤90 days). If no production prompts exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2}],"recommendedChecks":[{"id":"PRM-R1","requirement":"Production prompt templates should parameterize variable inputs and contain zero hardcoded secrets and zero hardcoded customer PII fields.","artifact":"Prompt template inventory showing parameterized slots for variable inputs + Static analysis or review finding zero hardcoded secrets and zero hardcoded customer PII","passCondition":"100% of production prompt templates are parameterized for variable inputs; scan of templates finds 0 secrets and 0 hardcoded customer PII fields (hygiene evidence measuredAt ≤90 days). If no production prompt templates exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":2,"minCriticality":1},{"id":"PRM-R2","requirement":"Production prompt changes should run blocking lint on every PR for length limits, secrets patterns, injection-prone constructs, and unbounded user concatenation—with a recent failing lint example retained.","artifact":"Prompt-lint CI config covering length, secrets patterns, injection-prone constructs, unbounded user concatenation + Proof lint is required on prompt-change PRs + retained example of a failing lint","passCondition":"Lint runs on every prompt change PR; blocking rules exist for length limits, secrets patterns, injection-prone constructs, and unbounded user concatenation; last failing lint example retained (lint evidence measuredAt ≤90 days). If no production prompts, including managed prompt configs, exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"PRM-R3","requirement":"High-traffic production prompt changes should run A/B or shadow evaluation with pre-registered metrics, and promotion should require non-inferiority (or better) on safety and the primary quality SLI.","artifact":"A/B or shadow-eval config for high-traffic prompt changes + Last experiment report with quality/safety deltas + non-inferiority promotion gate","passCondition":"Last high-traffic prompt change used A/B or shadow eval with pre-registered metrics; promotion required non-inferiority (or better) on safety and primary quality SLI (experiment evidence measuredAt ≤90 days). If no high-traffic prompt change is in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2}],"evidenceRequired":["Prompt registry with versions, owners, and change history","Eval reports linked to prompt releases","Rollback procedure documentation"],"engineeringBestPractices":["Store prompts in source control or a versioned registry with CI promotion","Separate safety/policy prompts from product/UX prompts where possible","Measure token cost impact of prompt changes alongside quality","Document intended failure modes and refusal behavior in the prompt contract"],"automaticValidations":["CI blocks deploy if prompt hash lacks associated eval pass","Diff reviews in pull requests for prompt files","Token budget checks against historical baselines"],"manualValidations":["Peer review of safety-critical prompt sections","Product review of tone and policy alignment for major releases"],"examples":["A coding agent system prompt is tagged v47; a quality drop triggers rollback to v46 in minutes","Marketing copy prompts and refund-policy prompts live in separate modules with different owners"],"references":[{"title":"Google SRE Workbook — Managing Risk (change management parallels)","url":"https://sre.google/workbook/"},{"title":"OWASP LLM Prompt Injection guidance","url":"https://owasp.org/www-project-top-10-for-large-language-model-applications/"}],"futureEvolution":"Industry-standard prompt manifests (SBOM-like) and signed prompt releases for regulated environments."},{"id":"APRF-03","slug":"context-engineering","name":"Context Engineering","summary":"Bound and structure what the model is allowed to see and use.","domain":"model-lifecycle","crossCutting":false,"severity":"high","riskLevel":"high","purpose":"Design how context windows are filled—retrieval, history, tool results, and system state—so the model receives necessary, authorized, and bounded information.","engineeringPhilosophy":"Context is a scarce, trusted resource. Overstuffing, under-filtering, and leaking privileged context are engineering defects, not model quirks. Structure beats volume.","whyItMatters":"Poor context design causes hallucinations, privacy leaks, prompt injection via retrieved content, and unbounded cost. Agents fail when context is noisy or when critical constraints are buried.","commonFailures":["Dumping entire conversation history without summarization or TTL","Retrieving documents without ACL enforcement at query time","No provenance: model cannot distinguish user text from retrieved policy","Tool results concatenated without size or sensitivity limits"],"mandatoryChecks":[{"id":"CTX-M1","requirement":"Every production context builder shall enforce a finite max token/byte budget and documented prioritization rules so oversized inputs are truncated or rejected—never silently overflowing the model window.","artifact":"Context-budget config (max tokens/bytes) for each production context builder + Unit/integration tests showing truncate/reject per priority rules with 0 silent overflows","passCondition":"100% of production context builders enforce a max token/byte budget; tests show oversized inputs are truncated/rejected per priority rules with 0 silent overflows (budget evidence measuredAt ≤90 days). If no production AI paths assemble model context (RAG, chat history, tool results, or prompt templates), score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"CTX-M2","requirement":"Retrieved and tool-sourced content shall receive a source label/type and an access check before inclusion in assembled model context—unauthorized chunks must be excluded.","artifact":"Context assembly code enforcing source labels on retrieved and tool-sourced chunks + Automated tests showing ACL exclusion of unauthorized chunks at 100% and labels on included chunks","passCondition":"Automated tests: unauthorized retrieval/tool chunks are excluded at 100%; included chunks carry a source label/type field in 100% of sampled assembled contexts (label/ACL evidence measuredAt ≤90 days). If context is prompt-only with no retrieval/tools, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"CTX-M3","requirement":"Production context assembly shall apply a documented inclusion policy that enumerates sensitive classes—including secrets and regulated data—with allow/deny rules, and shall strip or block disallowed classes before they enter the model context.","artifact":"Data-class inclusion policy enumerating sensitive classes with allow/deny rules + Enforcement tests or DLP hooks showing ≥95% strip/block on the sensitive-class fixture suite","passCondition":"Policy enumerates sensitive classes and allow/deny rules; tests show disallowed classes are stripped or blocked at ≥95% on the sensitive-class fixture suite (policy/suite evidence measuredAt ≤90 days). If context is purely static non-sensitive templates with no such paths, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2}],"recommendedChecks":[{"id":"CTX-R1","requirement":"Production AI requests should emit per-request context-budget usage metrics, and operators should be alerted when usage saturates a documented share of max context—or when hard-truncate rate exceeds a defined threshold.","artifact":"Per-request context token/budget usage metrics (dashboard or telemetry export) + Alert rule for context saturation and/or hard-truncate rate with notify proof","passCondition":"≥99% of production requests in a 24h sample emit context-budget usage; an alert fires when usage exceeds the documented % of max context (or hard truncate rate exceeds threshold) (metrics/alert evidence measuredAt ≤90 days). If no production AI requests assemble model context, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"CTX-R2","requirement":"When production context uses summarization or compaction, teams should run a critical-fact eval set and retain facts at or above a documented threshold; the last run should be ≤90 days old and regressions should block context-pipeline releases.","artifact":"Compaction/summarization eval set of critical facts with documented retention threshold + Latest information-loss / retention report ≤90 days with release-blocking gate evidence","passCondition":"Critical-fact retention ≥ documented threshold after compaction on the eval set; last run ≤90 days; regressions block context-pipeline releases (eval evidence measuredAt ≤90 days). If no compaction path exists, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"CTX-R3","requirement":"Production context assemblers should emit labeled structured sections (for example JSON or XML blocks) that keep instructions distinct from untrusted data, and untrusted data should not be able to overwrite the instruction section.","artifact":"Context assembly schema/spec separating instruction vs data blocks + sample rendered request + Red-team or unit test showing untrusted data cannot overwrite the instruction section","passCondition":"Production assembler emits labeled structured sections (e.g. JSON/XML); untrusted data cannot overwrite the instruction section in a red-team or unit test (structure/test evidence measuredAt ≤90 days). If context is a single trusted static template with no untrusted sections, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2}],"evidenceRequired":["Context assembly design document","ACL enforcement evidence on retrieval paths","Samples of labeled context structures (redacted)"],"engineeringBestPractices":["Design explicit context slots: instructions, user, memory, retrieval, tools","Prefer citations and IDs over pasting large documents when possible","Apply the same authorization checks to context as to API responses","Test adversarial documents in the corpus as first-class fixtures"],"automaticValidations":["Unit tests for context builders and ACL filters","Metrics on context token composition by source","Guards rejecting oversized tool payloads"],"manualValidations":["Review of retrieval corpora for injection and oversharing risk","Spot checks that production traces show expected context structure"],"examples":["A RAG system includes document IDs and ACL tags; the model only sees chunks the user may access","Agent tool output is truncated and classified before re-entering the context window"],"references":[{"title":"NIST AI RMF — Map and Measure functions","url":"https://www.nist.gov/itl/ai-risk-management-framework"},{"title":"OWASP LLM — Sensitive Information Disclosure","url":"https://owasp.org/www-project-top-10-for-large-language-model-applications/"}],"futureEvolution":"Standard context schemas across agent frameworks and portable ACL-aware retrieval protocols."},{"id":"APRF-08","slug":"evaluation","name":"Evaluation","summary":"Continuously prove quality, safety, and task success before and after release.","domain":"model-lifecycle","crossCutting":false,"severity":"critical","riskLevel":"high","purpose":"Institutionalize offline and online evaluation so releases are gated on measured quality, safety, and task success—not intuition or demo success.","engineeringPhilosophy":"If you cannot measure it, you cannot claim production readiness. Evaluation is a product dependency equal to tests in traditional software, extended for stochastic systems.","whyItMatters":"LLMs regress silently. Without evals, teams ship prompt or model changes that increase hallucination, toxicity, tool errors, or task failure rates under real traffic.","commonFailures":["Only manual spot checks before release","Eval sets that do not match production task distribution","No online monitoring of quality after deploy","Safety and quality evals owned by nobody"],"mandatoryChecks":[{"id":"EVL-M1","requirement":"Every journey marked critical shall have a versioned offline eval suite, and every relevant production change in the last 30 days shall have triggered that suite—or carry a documented waiver ≤14 days.","artifact":"Eval suite registry mapping critical journeys to versioned offline suites + CI (or equivalent) runs on prompt/model/tool changes for the last 30 days, or waivers ≤14 days","passCondition":"100% of journeys marked critical have a versioned offline suite; 100% of relevant production changes in the last 30 days triggered the suite (or documented waiver ≤14 days) (suite/CI evidence measuredAt ≤90 days). If no journeys are marked critical, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"EVL-M2","requirement":"Production release gates shall require numeric minimum thresholds for at least one quality metric and one safety metric on every critical journey, and shall block deploy in CI when those thresholds are not met.","artifact":"Gate config listing metric names and numeric thresholds per critical journey (quality + safety) + CI evidence that a failing gate blocks deploy (or equivalent required check)","passCondition":"Each critical journey has ≥1 quality and ≥1 safety metric with numeric threshold; failing gate blocks deploy in CI (gate evidence measuredAt ≤90 days). If no journeys are marked critical, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"EVL-M3","requirement":"Production AI workloads shall emit live metrics for task success and failure and for safety refusals, with a defined alert or review cadence and dashboard freshness no older than 24 hours.","artifact":"Dashboard or metric exports for task success/failure rates on production AI workloads + Dashboard or metric exports for safety refusal rates + Alert rule or documented review cadence; proof dashboard freshness ≤24 hours","passCondition":"Online metrics exist and are updating for task success/failure and safety refusals; alert or review cadence defined; freshness ≤24 hours on the dashboard (metrics evidence measuredAt ≤90 days). If no production AI workloads complete user-visible tasks or apply safety refusals, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"EVL-M4","requirement":"High-risk AI production cutovers shall run a shadow or canary with a retained eval comparison against the incumbent, and shall promote to 100% traffic only after documented promotion criteria are met.","artifact":"Shadow/canary eval config for high-risk AI cutovers (promotion criteria documented) + Comparison report for the last high-risk cutover showing criteria met before full traffic","passCondition":"The last high-risk AI cutover retained a shadow/canary eval comparison that met promotion criteria before 100% traffic (cutover evidence measuredAt ≤90 days). If no high-risk AI cutover is in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":5,"minCriticality":3}],"recommendedChecks":[{"id":"EVL-R1","requirement":"Production AI systems should maintain three distinct offline eval tracks—regression, adversarial, and distribution-shift—each with its own corpus and named owner, and each should have run successfully on the last production model or prompt promotion.","artifact":"Eval catalog listing separate tracks for regression, adversarial, and distribution-shift with owners and corpora + Latest CI (or equivalent) matrix showing each track succeeded on the last production promotion","passCondition":"All three tracks (regression, adversarial, distribution-shift) exist with distinct corpora and named owners; each track ran successfully on the last production model/prompt promotion (catalog/CI evidence measuredAt ≤90 days). If no production AI model/prompt promotions exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"EVL-R2","requirement":"Production AI systems should run human preference or expert-review sampling on a documented cadence and sample size, covering production-like prompts, with disagreements adjudicated and recorded.","artifact":"Human preference / expert-review sampling protocol (cadence + sample size) + Last scored sample set with production-like prompts and inter-rater / adjudication notes","passCondition":"Cadence and sample size are defined; last sample ≤90 days covers production-like prompts; disagreements have adjudication recorded (sampling evidence measuredAt ≤90 days). If no production AI prompts/outputs exist for review, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2}],"evidenceRequired":["Eval suite definitions and ownership","Gate thresholds and recent pass/fail reports","Dashboards for online quality metrics"],"engineeringBestPractices":["Version eval datasets; treat label quality as seriously as code quality","Include tool-use and multi-turn scenarios, not only single-shot Q&A","Budget for eval compute as part of CI cost","Correlate eval failures to traces for fast debugging"],"automaticValidations":["CI pipelines blocking on eval gate failures","Scheduled regression runs against production prompts/models","Drift detection when online metrics diverge from offline baselines"],"manualValidations":["Periodic calibration of automated graders vs human labels","Product review of eval coverage gaps"],"examples":["A RAG support bot cannot ship a prompt change unless citation accuracy stays above threshold","An agent fails CI when tool-selection accuracy drops on the golden set"],"references":[{"title":"NIST AI RMF — Measure","url":"https://www.nist.gov/itl/ai-risk-management-framework"},{"title":"Google SRE — Monitoring Distributed Systems (measurement culture)","url":"https://sre.google/sre-book/monitoring-distributed-systems/"}],"futureEvolution":"Shared public eval protocols for agentic and MCP workloads, with portable scorecards."},{"id":"APRF-06","slug":"agent-governance","name":"Agent Governance","summary":"Constrain goals, autonomy, loops, and escalation for agents and A2A.","domain":"agents","crossCutting":false,"severity":"critical","riskLevel":"critical","purpose":"Define and enforce how autonomous agents set goals, plan, loop, escalate, and collaborate with other agents so autonomy never exceeds authorized operational bounds.","engineeringPhilosophy":"Autonomy is a dial, not a virtue. Production agents have explicit charters: allowed goals, max steps, escalation paths, and kill switches. Multi-agent and A2A systems require governance of the mesh, not only of each node.","whyItMatters":"Unconstrained agents loop, spend unbounded budget, escalate privileges across A2A links, or pursue goals that conflict with business and safety policy. Governance failures look like 'the agent went rogue' but are usually missing product controls.","commonFailures":["No finite execution bounds (iteration, duration, recursion/delegation when supported) for agent runtimes","Agents that can redefine or pursue conflicting goals without a pre-tool policy gate","A2A trust assumed by network presence alone (no peer auth or scoped capabilities)","No operator kill switch, cancellation of in-flight/queued work, or drill evidence","Agent behavior promotions without a linked sandbox/simulation run","Orphan agent or AI-system IDs without Responsible/Accountable ownership"],"mandatoryChecks":[{"id":"AGN-M1","requirement":"Each production agent (any autonomous or semi-autonomous runtime that plans, loops, or invokes tools on behalf of a product capability—including in-process agents, MCP clients/servers acting as agents, and A2A participants) shall be represented in a version-controlled inventory with a current charter covering purpose, owner, production identifier, lifecycle status, approved tool policy, data scope, autonomy boundaries, change control, review metadata, and structured approval. Runtime configuration shall be consistent with the approved charter; material deviations require charter review before deployment. Applies to deployed production agent runtimes, not to agent frameworks, SDKs, or libraries in isolation.","artifact":"Version-controlled agent inventory listing every production agent with owner, production identifier, lifecycle status, and charter URI/id + Per-agent charter documents (or equivalent structured records) covering purpose, owner, production identifier, lifecycle status, approved tool policy reference, data scope, autonomy boundaries, change justification or revision history, review date, last updated, charter version, and structured approval (approvedBy, approvalDate, approvalStatus) + Inventory completeness evidence: runtime registry, deployment manifest, CMDB, platform registry, or approved attestation with measuredAt ≤90 days","passCondition":"Every production agent is represented in a version-controlled inventory. Each inventory entry references a current charter containing purpose, owner, production identifier (environment, system, application, or deployment id), lifecycle status (Active, Deprecated, Retired, or Experimental), approved tool policy, data scope, autonomy boundaries, change justification or revision history, review date, last updated, charter version, and structured approval (approvedBy, approvalDate, approvalStatus). Inventory completeness is demonstrated by at least one of: runtime registry, deployment manifest, CMDB, platform registry, or approved attestation (coversAllProductionAgents with measuredAt ≤90 days). Named exceptions include business justification, approver, expiry ≤90 days, and compensating controls. No production agent is missing required governance metadata. Runtime configuration is consistent with the approved charter.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"AGN-M2","requirement":"Every production agent runtime shall enforce finite execution bounds including reasoning/tool iterations, execution duration, and recursive delegation depth where supported. Bounds shall be enforced by runtime or platform controls rather than prompts or model instructions. Exceeding any bound shall terminate or safely abort execution so the agent cannot continue planning or dispatch further side effects after abort. Applies to agent frameworks, orchestration frameworks, workflow engines with agent loops, MCP clients, MCP servers acting autonomously, A2A runtimes, and multi-agent systems. Not applicable to simple chat-completion APIs, single-inference endpoints, embeddings, classifiers, or rerankers without multi-step / tool / delegation autonomy.","artifact":"Runtime/platform configuration declaring finite iteration and duration bounds for each production agent runtime (plus recursion/delegation depth when that capability is supported) + Enforcement test results showing abort/fail-closed when each applicable bound is exceeded, including proof the agent cannot continue execution after abort + Runtime logs (or equivalent telemetry) showing execution terminated due to a configured bound (preferred; measuredAt ≤90 days when used for PASS)","passCondition":"Every production agent runtime enforces finite execution bounds appropriate to its execution model. These include bounded reasoning/tool iterations, bounded execution duration, and bounded recursive delegation where supported. Enforcement is implemented by the runtime or platform and verified through tests (and preferably runtime logs) that demonstrate safe termination when each configured bound is exceeded, with no continued planning or background side-effect dispatch after abort. No production agent relies solely on prompts or model instructions to enforce execution limits. Recursion/delegation depth is required when the runtime supports recursive delegation, agent spawning, or sub-agent execution; otherwise that bound is NOT_APPLICABLE for that runtime.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"AGN-M3","requirement":"Authorized operators shall be able to pause or terminate production agent runs through a control-plane action that stops further planning and in-flight or queued tool/MCP/A2A side effects within a documented time-to-effect SLO. The control must not depend on the model cooperating and must not be disableable by the agent runtime itself.","artifact":"Kill-switch/pause runbook: who may invoke, scope (run / agent type / fleet), expected effect, and numeric time-to-effect SLO + Successful drill or production use record (≤90 days) with timestamps for invoke → effect, covering at least one production agent path + Cancellation suite or import proving queued work, running tasks, and child agents stop without new dispatch","passCondition":"Documented pause/terminate control exists for production agents; control is restricted to authorized operators (not end-user-only and not model-invoked); ≥1 successful pause or terminate action in drill or production in the last 90 days shows recorded time-to-effect ≤ documented numeric SLO; evidence shows further tool/MCP/A2A side effects for that run (and its spawned children, if any) were stopped or drained without requiring the model to refuse.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"AGN-M4","requirement":"Every production agent-to-agent (A2A) or multi-agent handoff path shall authenticate the peer identity and authorize a scoped capability set (tools, data, actions) independent of network presence. Unauthenticated, spoofed, or over-scoped handoffs shall be denied by the platform—not by prompt instructions alone.","artifact":"Inventory of production A2A/multi-agent handoff paths with authn/authz mechanism per path + Capability token/schema (or equivalent) examples showing scoped grants for handoffs + Negative test results: unauthenticated, forged identity, and over-scoped capability cases denied at 100%","passCondition":"100% of production A2A/multi-agent handoff paths require authenticated peers and scoped capabilities; negative tests show unauthenticated, forged-peer, and over-scoped handoffs denied at 100%; 0 production handoff paths that accept anonymous or network-presence-only trust (deny evidence measuredAt ≤90 days). If no production A2A or multi-agent handoffs exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2}],"recommendedChecks":[{"id":"AGN-R1","requirement":"Production agent planners should run policy checks for goal conflicts and disallowed goals before invoking side-effecting tools. Checks must be enforced by the platform or planner runtime—not by prompt wording alone— and denied plans must leave an observable deny/allow trace.","artifact":"Versioned pre-execution policy rules (goal-conflict / disallowed-goal) with named owner + Sample deny/allow traces showing the planner gated side-effecting tools + ≥1 synthetic conflict deny record (test or prod) ≤90 days","passCondition":"Agent planner runs policy checks for goal conflicts / disallowed goals before side-effecting tools; ≥1 synthetic conflict is denied in test or production logs within the last 90 days with retained deny/allow traces; the policy rule set has a named owner. If no production agents plan or invoke side-effecting tools, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"AGN-R2","requirement":"New or materially changed production agent behaviors should be exercised in a sandbox or simulation environment before promotion, with recorded pass/fail criteria. The last such promotion should link to a sandbox run completed within 30 days before release.","artifact":"Sandbox/simulation environment config (or equivalent) for agent behaviors + Last pre-prod simulation/sandbox report for a behavior change, linked to the production promotion + Recorded pass/fail criteria and outcome for that run (≤30 days before release)","passCondition":"Last new agent behavior promoted to production has a linked sandbox or simulation run completed ≤30 days before release with pass/fail criteria recorded; the sandbox/simulation environment used for agent behaviors is documented or configured. If agents never change behavior after initial deploy, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"AGN-R3","requirement":"Every production AI system and production agent should appear in a versioned RACI or ownership register that names Responsible and Accountable parties (and Consulted/Informed where used) across the teams that operate the agent fleet. Inventory queries should return 0 orphan system or agent IDs missing required ownership fields.","artifact":"Versioned RACI or ownership register covering production AI systems / agents + Required ownership fields defined (at minimum Responsible + Accountable) + Inventory export or query result showing 0 orphans for those fields","passCondition":"Every production AI system ID (and production agent ID in scope) has non-empty Responsible and Accountable owner fields for the organization’s required domains/roles; inventory query returns 0 orphans (register/export measuredAt ≤90 days). If no production agents/systems, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2}],"evidenceRequired":["Versioned agent inventory with charters and owners (AGN-M1)","Runtime execution bounds (iteration + duration; recursion/delegation when supported) + abort-on-exceed evidence (AGN-M2)","Kill-switch/pause runbook, cancellation suite, and ≤90-day drill record (AGN-M3)","A2A/multi-agent handoff inventory with peer auth, scoped capabilities, and deny tests (AGN-M4)","Goal-conflict / disallowed-goal plan policy with named owner and synthetic deny traces (AGN-R1)","Agent sandbox/simulation environment config and linked ≤30-day pre-release sim reports (AGN-R2)","Agent/AI-system RACI register with Responsible + Accountable and 0 orphans (AGN-R3)"],"engineeringBestPractices":["Prefer narrow agents composed into workflows over one universal agent","Log plans and intermediate decisions for reconstructability","Escalate to humans on ambiguity or high-impact branches","Treat agent-to-agent messages as untrusted until verified","Gate agent-behavior promotions on a linked sandbox/sim report ≤30 days before release","Keep a versioned RACI with Responsible and Accountable for every production agent ID"],"automaticValidations":["Runtime enforcement of execution bounds (iteration, duration, recursion/delegation when supported) with abort-on-exceed and no continue-after-abort","Denial of unauthenticated, forged-peer, and over-scoped A2A handoffs","Kill-switch cancellation suite (queued, running, and child-agent paths)","Goal-conflict / disallowed-goal policy gate before side-effecting tools","Alerts on loop detection and repeated identical tool calls"],"manualValidations":["Charter and inventory completeness review for each production agent class","Architecture review that agents cannot disable their own kill path","RACI ownership review across teams for production AI systems and agents","Tabletop of multi-agent failure cascades and kill-switch drill within SLO"],"examples":["A research agent may browse and summarize but cannot send email; a separate approved workflow handles outreach","A2A task delegation includes expiring capability tokens, not open network trust","On-call invokes an authenticated pause API; queued tools cancel and child agents terminate within the time-to-effect SLO","A synthetic goal-conflict fixture is denied by plan policy before any write tool runs"],"references":[{"title":"OWASP LLM — Excessive Agency","url":"https://owasp.org/www-project-top-10-for-large-language-model-applications/"},{"title":"NIST AI RMF — Govern","url":"https://www.nist.gov/itl/ai-risk-management-framework"}],"futureEvolution":"Interoperable agent identity and capability attestation standards for A2A ecosystems; shared sandbox/sim scorecards and portable RACI/inventory exports for assessments."},{"id":"APRF-17","slug":"human-approval","name":"Human Approval","summary":"Require human gates for high-impact or irreversible actions.","domain":"agents","crossCutting":false,"severity":"critical","riskLevel":"high","purpose":"Insert human approval and oversight where AI-proposed actions have high impact, irreversibility, or regulatory sensitivity.","engineeringPhilosophy":"Human-in-the-loop is not a product apology—it is a control. The goal is calibrated oversight: humans approve what machines should not decide alone.","whyItMatters":"Autonomous execution of irreversible actions (money movement, data deletion, external communications, code deploy) without approval creates unacceptable blast radius.","commonFailures":["Rubber-stamp UIs that hide tool args, diffs, or confidence","Approval only in UI while API/agent/job paths bypass it","No dual control for Level 5 irreversible actions","Approvals without attributable audit trail","High-impact classes missing from the approval inventory","Approval queue backlog without SLA driving unsafe workarounds"],"mandatoryChecks":[{"id":"HUM-M1","requirement":"Every high-impact action class an AI system or agent can invoke in production (write/irreversible/financial/external-comms/privileged side effects) shall be listed in a versioned inventory and blocked until a human approval gate succeeds. Ungated execution of inventoried classes shall fail closed.","artifact":"Versioned high-impact action inventory (class, risk tier, gate id/owner) + Gate wiring evidence (policy/config) mapping each class to an approval control + Ungated execution test results showing 100% deny/fail-closed for inventoried classes","passCondition":"100% of inventoried high-impact action classes have an approval gate in production; ungated execution tests for those classes fail at 100% (inventory/deny evidence measuredAt ≤90 days). If no high-impact action classes apply (writes, irreversible, financial, external communications, privileged admin), score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"HUM-M2","requirement":"Every human approval or denial of a gated high-impact action shall be recorded with actor identity, action context (what was proposed), and approve/deny outcome in a durable audit log that passes schema validation.","artifact":"Approval audit log schema (actor, context, outcome, timestamp) as code or documented contract + Sample approval records from the last 30 days covering required fields + Schema validation test or import proving samples conform","passCondition":"100% of sampled approvals in the last 30 days include actor ID, action context, and approve/deny outcome; schema validation for the approval audit log passes. If no gated approvals exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"HUM-M3","requirement":"Human approval gates for high-impact actions shall apply on every entry path (UI, API, agent/tool, batch/job)—not only the primary console. Alternate-path bypass tests shall show 0 successful ungated high-impact executions.","artifact":"Bypass-path threat model or test matrix across UI, API, and agent/job entry points + Test results showing 0 successful ungated high-impact executions","passCondition":"Automated or reviewed bypass tests cover alternate UI, API, and agent/job entry points for inventoried high-impact actions; 0 successful ungated high-impact executions in those tests (bypass evidence measuredAt ≤90 days).","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"HUM-M4","requirement":"Irreversible actions in Level 5 (regulated / highest capability) systems shall require dual control: two distinct authorized humans must approve before execution. Sampled executions shall show dual approval with 0 single-approver completes.","artifact":"Inventory of Level 5 irreversible action classes requiring dual control + Dual-control workflow configuration (two distinct approvers) + Sample approval records showing dual approval and 0 single-approver completes","passCondition":"Level 5 irreversible action classes are inventoried; 100% of sampled executions of those classes show dual approval by two distinct actors; 0 single-approver completes in the sample (sample/config measuredAt ≤90 days). If not in Level 5 scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":5,"minCriticality":3}],"recommendedChecks":[{"id":"HUM-R1","requirement":"High-impact approval experiences should present tool arguments, a change diff (or equivalent preview), and confidence/risk context before the human approves or denies—so decisions are informed, not rubber-stamped.","artifact":"Approval UI/spec showing tool args, diff/preview, and confidence/risk fields + ≥10 sampled approval records (≤90 days) with those fields populated","passCondition":"High-impact approvals display tool args, change diff (or equivalent), and confidence/risk; ≥10 sampled approvals in the last 90 days show those fields populated.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"HUM-R3","requirement":"Approval queues for high-impact actions should have a documented service level (for example p95 queue age) and measured performance for the last 30 days within that SLA—or open exceptions with named owners and expiry—so operators do not bypass gates under backlog pressure.","artifact":"Documented approval-queue SLA (metric, threshold, owner) + Queue age/metrics evidence for the last 30 days (dashboard export or report) + Open exception register with owners and expiry when SLA is breached","passCondition":"A documented approval-queue SLA (e.g. p95 queue age) exists; measured p95 for the last 30 days is within SLA, or every open exception has a named owner and expiry ≤90 days.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2}],"evidenceRequired":["Versioned high-impact action inventory + gate wiring + ungated deny suite (HUM-M1)","Approval audit log schema and ≤30-day samples with actor/context/outcome (HUM-M2)","Bypass-path tests across UI/API/agent with 0 ungated successes (HUM-M3)","Dual-control workflow and samples for Level 5 irreversible actions (HUM-M4)","Approval UI/spec showing tool args, diffs, and confidence + ≥10 samples (HUM-R1)","Approval-queue SLA definition + ≤30-day queue metrics (HUM-R3)"],"engineeringBestPractices":["Classify actions by impact tier with default gates","Enforce approval in a shared execution layer used by UI, API, and agents","Allow break-glass with heightened logging for emergencies","Never ask the model to pretend approval was granted","Design approvals for voice and async channels, not only web UI","Publish a numeric approval-queue SLA and alert on burn"],"automaticValidations":["Ungated execution tests fail at 100% for inventoried high-impact classes","Bypass suites across UI/API/agent show 0 successful ungated executions","Schema validation for approval audit logs (actor, context, outcome)","Dual-approval enforcement with 0 single-approver completes for Level 5 irreversible actions","Monitoring of approval bypass attempts and abnormal approval velocity"],"manualValidations":["Inventory completeness review for high-impact action classes","Process review of approval fatigue and queue SLA exceptions","Spot-check that approval UI context matches what approvers saw"],"examples":["Send-email and wire-transfer tool classes are inventoried and blocked without an approval token","API and agent entry points deny the same high-impact class when approval is omitted","Level 5 irreversible delete requires two distinct approvers before execution","Approvers see tool args, a diff preview, and confidence before the approve control enables"],"references":[{"title":"NIST AI RMF — Govern and Manage (human oversight)","url":"https://www.nist.gov/itl/ai-risk-management-framework"},{"title":"OWASP LLM — Excessive Agency","url":"https://owasp.org/www-project-top-10-for-large-language-model-applications/"}],"futureEvolution":"Portable approval evidence packs (inventory, ungated/bypass suites, audit samples, dual-control and queue SLA exports) and shared HITL UX patterns across agent platforms."},{"id":"APRF-09","slug":"observability","name":"Observability","summary":"Make every decision path reconstructable: traces, prompts, tools, costs, outcomes.","domain":"reliability","crossCutting":false,"severity":"high","riskLevel":"high","purpose":"Provide end-to-end observability across prompts, model calls, retrieval, tools, agents, costs, and outcomes so incidents and regressions are diagnosable.","engineeringPhilosophy":"AI systems without reconstructable traces are not operable. Observability must cover the cognitive path, not only HTTP latency—while respecting privacy redaction.","whyItMatters":"When quality drops or a tool fires incorrectly, teams need to replay what the model saw and did. Blind production AI creates unresolvable incidents and slow learning loops.","commonFailures":["Logging only final user-visible answers","No correlation IDs across model, tool, and app spans","Storing raw sensitive prompts indefinitely","Cost metrics disconnected from product features"],"mandatoryChecks":[{"id":"OBS-M1","requirement":"Production AI paths must emit distributed traces that connect the parent user/request ID through model spans, tool spans, and the request outcome.","artifact":"Tracing config (or equivalent) instrumenting request → model → tool → outcome + Canary or 24h sampled traces showing ≥95% linked coverage (redacted)","passCondition":"Canary or sampled traces show parent request ID linking model spans, tool spans, and outcome in ≥95% of canary requests over 24 hours (trace evidence measuredAt ≤90 days). If no production AI request path is in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"OBS-M2","requirement":"When production traces can contain secrets or regulated/sensitive data (API keys, JWTs, passwords, customer PII/PHI, financial data), those fields must be redacted, masked, tokenized, or access-controlled before reaching the tracing backend.","artifact":"Scope attestation: whether traces can contain secrets or regulated/sensitive data + Trace redaction/masking/tokenization or ACL config for sensitive span fields + Synthetic sensitive-field test showing 100% redaction or unauthorized-access denial","passCondition":"If traces contain (or are designed to contain) secrets or regulated/sensitive data, those fields are redacted, masked, tokenized, or access-controlled before reaching the tracing backend—proven by synthetic sensitive-field tests at 100% (evidence measuredAt ≤90 days). If traces demonstrably cannot carry secrets or regulated/sensitive data, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2}],"recommendedChecks":[{"id":"OBS-R1","requirement":"On-call should be able to replay a failed AI trace in a restricted environment within a documented RTO, with a drill or real replay in the last 90 days.","artifact":"Secure/restricted replay tooling config for failed AI traces + Documented RTO for replay + Drill or real replay sample ≤90 days (redacted)","passCondition":"On-call can replay a failed AI trace in a restricted environment within the documented RTO; last drill or real replay ≤90 days old (replay evidence measuredAt ≤90 days). If no production AI tracing with failed traces is in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"OBS-R2","requirement":"Annotators should be able to attach quality labels to production traces in a secure tool, with ≥50 annotations in the last 90 days feeding an eval or review loop.","artifact":"Trace annotation schema and secure tooling for quality labels on spans + Last-90-day count ≥50 annotations feeding an eval or review loop","passCondition":"Annotators can attach quality labels to production traces in a secure tool; ≥50 annotations in the last 90 days feed an eval or review loop (annotation evidence measuredAt ≤90 days). If no production AI traces are in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"OBS-R3","requirement":"Critical AI journeys should have named SLOs with numeric targets for latency, error, and quality burn, plus burn-rate alerts and a dashboard retained for review.","artifact":"Named SLO targets for critical AI journeys covering latency, error, and quality burn + Burn-rate alert config + dashboard screenshot or URL with retention note","passCondition":"Named SLOs with numeric targets cover latency, error, and quality burn for each critical AI journey; burn-rate alerts fire when burn exceeds the documented threshold (SLO evidence measuredAt ≤90 days). If no critical AI journeys are in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"OBS-R4","requirement":"Billed model calls should carry request, feature, and tenant (or equivalent) attribution labels so spend and usage can be reconstructed per path.","artifact":"Cost/token metrics schema with request, feature, and tenant (or equivalent) labels + 24h sample showing ≥95% attributed billed model calls","passCondition":"≥95% of billed model calls in a 24h sample carry request ID + feature + tenant (or equivalent) attribution labels (attribution evidence measuredAt ≤90 days). If no billed model calls are in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2}],"evidenceRequired":["Example traces (redacted) showing full path","Cost attribution dashboards","Access control policy for prompt/completion logs"],"engineeringBestPractices":["Adopt OpenTelemetry-compatible tracing for LLM spans where possible","Capture tool names, latency, and status codes consistently","Separate debug retention from long-term analytics retention","Alert on silent quality degradation, not only 5xx rates"],"automaticValidations":["Synthetic checks that traces are emitted for canary requests","Alerts on missing cost telemetry","PII scanners on log pipelines"],"manualValidations":["Incident retrospectives verify traces were sufficient","Privacy review of observability data stores"],"examples":["An on-call engineer opens a trace and sees which retrieved chunk caused an incorrect refund recommendation","Finance reconciles model spend by product SKU using request-level cost tags"],"references":[{"title":"Google SRE Workbook — Observability","url":"https://sre.google/workbook/observability/"},{"title":"OpenTelemetry","url":"https://opentelemetry.io/"}],"futureEvolution":"Standard LLM span semantics across providers and agent frameworks."},{"id":"APRF-28","slug":"performance-slo","name":"Performance & SLO Engineering","summary":"Latency, throughput, and error budgets for AI features—SRE discipline applied to GenAI.","domain":"reliability","crossCutting":false,"severity":"high","riskLevel":"medium","purpose":"Define SLIs/SLOs for AI latency, availability, and quality signals; manage error budgets so AI features meet user experience and capacity targets.","engineeringPhilosophy":"If it is not measured with an SLO, it is not operationally owned. Stochastic systems still need latency and quality budgets.","whyItMatters":"Unbounded TTFT, streaming stalls, and silent quality burn destroy UX and hide regressions that “availability” alone will not catch.","commonFailures":["No p95/p99 latency targets for model calls","Quality treated as a one-time eval, not an online SLO","No error budget for AI feature releases","Capacity planning ignores bursty agent tool loops"],"mandatoryChecks":[{"id":"PERF-M1","requirement":"Every journey marked critical must have documented numeric availability and latency-percentile SLO targets in a maintained catalog.","artifact":"SLO catalog listing critical AI journeys with numeric availability and latency targets + Coverage showing 100% of marked-critical journeys have both target types","passCondition":"100% of journeys marked critical have availability % and latency percentile targets recorded in an SLO catalog (catalog evidence measuredAt ≤90 days). If no AI journey is marked critical, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"PERF-M2","requirement":"Production AI services must collect and make available operational metrics for latency, error rate, and at least one AI-specific quality or task-success indicator.","artifact":"Metric definitions or exporters covering latency, error rate, and ≥1 AI quality/task-success signal + Proof metrics are queryable/available for operational monitoring","passCondition":"Metrics for latency, error rate, and at least one AI-specific quality or task-success indicator are collected and available for operational monitoring (metrics evidence measuredAt ≤90 days). If no production AI services are in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"PERF-M3","requirement":"Every critical AI journey SLO must have burn-rate (or equivalent) alert policies, and a test or documented fire must prove the notification path works.","artifact":"Burn-rate or SLO alert policies covering each critical AI journey SLO + Alert test or documented fire proving notification path","passCondition":"Alert policies exist for each critical journey SLO; an alert test or documented fire demonstrates the notification path works (alert evidence measuredAt ≤90 days). If no critical AI journeys with SLOs are in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2}],"recommendedChecks":[{"id":"PERF-R1","requirement":"When a critical AI journey's error budget is exhausted, release velocity should be blocked or require explicit risk acceptance, with ≥1 gated event or drill in the last 90 days.","artifact":"Error-budget policy linking AI SLOs to release freezes or risk acceptance + Last budget-burn gated release or drill ≤90 days","passCondition":"When error budget for a critical AI journey is exhausted, release velocity is blocked or requires explicit risk acceptance; ≥1 gated event or drill in 90 days (gate evidence measuredAt ≤90 days). If no critical AI journeys with error budgets are in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"PERF-R2","requirement":"Capacity and load tests should include adversarial long-prompt and multi-step agent-loop scenarios within 90 days, with p95 latency and error rate staying within SLO under documented concurrency.","artifact":"Load-test plan including long-prompt and agent-loop scenarios + Latest capacity test report ≤90 days showing p95/error within SLO at documented concurrency","passCondition":"Last capacity test ≤90 days includes adversarial long prompts and multi-step agent loops; p95 latency and error rate stay within SLO under documented concurrency (capacity evidence measuredAt ≤90 days). If no production AI paths with capacity risk are in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"PERF-R3","requirement":"Each streaming AI surface should expose TTFT and inter-token latency SLIs, with alerts on documented thresholds and metric series retained ≥30 days.","artifact":"Streaming SLI definitions/dashboard for TTFT and inter-token latency + Alert config on documented thresholds + retention ≥30 days","passCondition":"TTFT and inter-token latency SLIs exist for each streaming AI surface; alerts fire on documented thresholds; series retained ≥30 days (streaming evidence measuredAt ≤90 days). If no streaming AI surfaces (SSE/WebSocket/token streams) are in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"PERF-R4","requirement":"Near-real-time operational dashboards should visualize latency, error rate, throughput, resource utilization, and AI quality metrics for production services.","artifact":"Dashboard URL/config covering latency, error rate, throughput, resource utilization, and AI quality + Near-real-time refresh evidence (e.g. panel freshness ≤15 minutes)","passCondition":"Near-real-time operational dashboards visualize latency, error rate, throughput, resource utilization, and AI quality metrics for production services (dashboard evidence measuredAt ≤90 days). If no production AI services with ops metrics are in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2}],"evidenceRequired":["SLO definitions for AI journeys","Dashboard and alert configuration","Recent burn-rate or incident examples (redacted)"],"engineeringBestPractices":["Separate SLOs for AI features vs core non-AI paths","Budget tokens and wall-clock together","Correlate performance regressions with model/prompt version changes"],"automaticValidations":["Synthetic latency probes","Burn-rate alerts","CI performance budgets for critical paths where feasible"],"manualValidations":["Quarterly SLO review with product owners","Post-incident SLO recalibration"],"examples":["Chat p95 TTFT < 1.5s with error-budget policy that freezes prompt experiments when burned","Agent task-success rate tracked as a quality SLO alongside HTTP availability"],"references":[{"title":"Google SRE — Service Level Objectives","url":"https://sre.google/sre-book/service-level-objectives/"},{"title":"AWS Well-Architected — Performance Efficiency","url":"https://aws.amazon.com/architecture/well-architected/"}],"futureEvolution":"Standard GenAI SLI catalogs (TTFT, tool-loop duration, citation accuracy) across ecosystems."},{"id":"APRF-14","slug":"reliability-continuity","name":"Reliability & Continuity","summary":"Survive provider outages and partial failures, and preserve critical AI capabilities under sustained disruption.","domain":"reliability","crossCutting":false,"severity":"high","riskLevel":"high","purpose":"Design graceful degradation for short failures and documented continuity options for sustained disruption—so AI-dependent journeys fail safely and recover within defined RTO/RPO.","engineeringPhilosophy":"Assume providers fail. Timeouts, circuit breakers, and degraded modes handle minutes; backups, failover, and human procedures handle hours and days. Safety properties must hold in every degraded mode.","whyItMatters":"Naive retries and single-provider dependency turn rate limits into outages; automation without continuity plans leaves the business stranded when AI is unavailable.","commonFailures":["No timeout on model calls","Infinite retries that worsen rate limits","No fallback when the primary model is unavailable","Agent continues after a failed critical tool as if it succeeded","No manual fallback for AI-automated workflows","Single provider with no contractual or technical alternative","Backups that exclude vector indexes and prompt registries","Untested continuity plans"],"mandatoryChecks":[{"id":"REL-M1","requirement":"Every production model and tool client call site shall declare a finite timeout and a finite max-retry bound—verified by static analysis or integration test—so hung providers and retry storms cannot cascade.","artifact":"Client config or code declaring finite timeout and max-retry for model/tool call sites + Static analysis report or integration test covering 100% of in-scope call sites","passCondition":"100% of production model/tool client call sites have a finite timeout and a finite max-retry bound; verified by static check or integration test (measuredAt ≤90 days). If no production model or tool clients exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"REL-M2","requirement":"Every critical user journey that depends on AI shall document degraded behavior when the AI dependency fails, and a failover test shall show a non-AI or safe fallback activates—not a blank error or silent hang.","artifact":"Degraded-mode specification covering each critical AI-dependent journey + Feature-flag, circuit-breaker, or fallback test proving safe activation when AI fails","passCondition":"100% of critical AI-dependent journeys document degraded behavior; a failover test shows non-AI or safe fallback activates when the AI dependency fails (measuredAt ≤90 days). If no critical AI-dependent user journeys exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"REL-M3","requirement":"Tool-using AI workflows shall detect partial tool failures (success then failure mid-sequence, truncated results, or failed side effects) and must not report overall success without explicit compensation, rollback, retry, or human approval.","artifact":"Agent/tool error-handling policy or code that detects partial tool failure + Test evidence (integration, chaos, e2e, replay, contract, simulator, or equivalent) showing no false-success without compensation/rollback/retry/approval","passCondition":"Test evidence demonstrates that when a tool partially succeeds and a later step fails, the workflow does not report overall success without explicit compensation, rollback, retry, or human approval (measuredAt ≤90 days). If no tool-using agents or workflows exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"REL-M4","requirement":"Backup inventories shall include the AI control-plane artifacts required to restore service (prompt registry, policies, indexes, and other declared dependencies), and a restore test of a sample artifact set shall succeed within 90 days.","artifact":"Backup job or inventory covering required AI control-plane artifacts (prompt registry, policies, indexes, as applicable) + Restore test report for a sample artifact set","passCondition":"Backup inventory includes required AI control-plane artifacts; a restore test in the last 90 days succeeds for a sample artifact set (measuredAt ≤90 days). If no AI control-plane artifacts exist in scope (prompt registry, policies, vector/index state, or equivalent), score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"REL-M5","requirement":"Every business-critical AI service must have numeric RTO and RPO documented in continuity, service-catalog, or disaster-recovery materials and linked to a tested restore or failover procedure.","artifact":"Business continuity, service-catalog, or disaster-recovery documentation with numeric RTO and RPO for business-critical AI services + Linkage from each in-scope service to a tested restore/failover procedure","passCondition":"100% of business-critical AI services have numeric RTO and RPO documented and linked to a tested restore/failover procedure (continuity evidence measuredAt ≤90 days). If no business-critical AI services are in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":3}],"recommendedChecks":[{"id":"REL-R1","requirement":"Production AI/provider clients should isolate failures with circuit breakers (open under sustained failure) and bulkheads (finite concurrency per dependency)—so one slow or down provider cannot exhaust the whole fleet.","artifact":"Client library/config showing circuit breakers around model/provider calls + Bulkhead or concurrency limit per provider dependency + Breaker trip evidence: induced-failure test or production trip log","passCondition":"Circuit breakers are configured around AI/provider clients and open under induced failure in test or an observed production trip within 90 days; bulkheads limit concurrent calls per provider dependency (measuredAt ≤90 days). If no production AI/provider clients exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"REL-R2","requirement":"Production AI paths should have a configured multi-provider or multi-region fallback that was exercised within 90 days, with an eval comparing primary vs fallback quality and safety—not connectivity alone—so failover does not silently degrade outcomes.","artifact":"Multi-provider or multi-region fallback configuration + Evidence the fallback path was exercised ≤90 days + Eval report comparing primary vs fallback quality/safety against minimum bars","passCondition":"A multi-provider or multi-region fallback path is configured and was exercised ≤90 days; a retained eval comparing primary vs fallback meets documented minimum quality/safety bars (not connectivity-only; measuredAt ≤90 days). If no production AI paths that warrant fallback are in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"REL-R3","requirement":"Every process marked critical-AI-dependent should have at least one documented continuity option (failover, manual procedure, alternate provider, or equivalent) with a named owner—so operators know how to keep the process running when the primary AI path fails.","artifact":"Continuity options documentation per critical AI-dependent process (failover, manual, alternate provider, or equivalent) + Named owner for each continuity option","passCondition":"100% of processes marked critical-AI-dependent have ≥1 documented continuity option with a named owner (continuity evidence measuredAt ≤90 days). If no processes marked critical-AI-dependent exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"REL-R4","requirement":"Production AI systems should run periodic continuity drills that include provider loss (or equivalent), measure RTO/RPO outcomes, and retain a report—so recovery objectives are proven under rehearsal, not assumed from documents alone.","artifact":"Continuity drill calendar covering provider-loss (or equivalent) scenarios + Last provider-loss drill report with RTO/RPO results (≤90 days) + Named owner + expiry for any RTO/RPO miss","passCondition":"A provider-loss (or equivalent) continuity drill completed ≤90 days with retained RTO/RPO results that met objectives or have named owners and expiry (measuredAt ≤90 days). If no production AI provider dependencies exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"REL-R5","requirement":"Production systems should run chaos experiments that cover AI dependency failure modes (provider, model, tool, or gateway outages) and retain an after-action with tracked actions.","artifact":"Chaos experiment plan covering AI provider/tool/gateway failure modes + Dated after-action report with retained actions","passCondition":"At least one AI-dependency chaos exercise completed in the last 180 days with retained after-action actions (attest measuredAt ≤90 days). If no production AI dependencies exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":5,"minCriticality":3},{"id":"REL-R6","requirement":"Where critical workloads depend on self-hosted inference, a warm standby should exist with capacity for declared peak load and a recent failover test that met documented RTO—so self-hosted model loss does not strand the service.","artifact":"Warm-standby inference architecture for self-hosted critical workloads + Last failover test report with RTO result (≤90 days) + Standby capacity sizing covering declared peak","passCondition":"For in-scope self-hosted inference, failover to warm standby completed within documented RTO in a test ≤90 days, and standby capacity covers declared peak for critical workloads (measuredAt ≤90 days). If self-hosted inference does not serve critical workloads, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":5,"minCriticality":3},{"id":"REL-R7","requirement":"Level-5 workloads should have a documented alternate provider or path (contractual and technical) and a successful failover test within 180 days.","artifact":"Provider contract summary or equivalent documenting alternate provider/path options + Technical failover design + successful failover test evidence","passCondition":"Level-5 workloads have a documented alternate provider/path and a successful failover test ≤180 days (attest measuredAt ≤90 days). If no Level-5 / mission-critical AI workloads are in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":5,"minCriticality":3}],"evidenceRequired":["Timeout/retry configuration","Degraded-mode UX and behavior documentation","Postmortems referencing resilience controls where applicable","Continuity plans for critical journeys","Backup/restore test records","RTO/RPO definitions"],"engineeringBestPractices":["Idempotent tools where retries are possible","Queue and backpressure for bursty AI workloads","Fail safe: prefer refusal over incorrect action under uncertainty","Separate availability SLOs for AI features vs core non-AI paths","Identify which AI features are critical vs optional","Design human-operated fallback procedures before full automation","Replicate prompt registries and policies, not only databases","Align continuity with resilience and rollback pillars"],"automaticValidations":["Synthetic canaries against providers","Alerts on elevated timeout and 429 rates","Integration tests for fallback paths","Scheduled backup success checks","Restore tests in isolated environments","Health checks on standby providers"],"manualValidations":["Game days simulating provider outage","Review of agent compensation logic after tool failure","Business impact analysis for AI features","Executive review of continuity acceptance risk"],"examples":["If the LLM provider is down, search falls back to keyword results with a clear banner","An agent aborts a payment flow when the ledger tool times out rather than guessing success","If the LLM provider fails, claims adjusters switch to a documented manual checklist","Prompt registry backups restore a prior known-good configuration in a DR region"],"references":[{"title":"Google SRE Book — Addressing Cascading Failures","url":"https://sre.google/sre-book/addressing-cascading-failures/"},{"title":"AWS Well-Architected — Reliability","url":"https://aws.amazon.com/architecture/well-architected/"},{"title":"Google SRE — Disaster Recovery","url":"https://sre.google/sre-book/disaster-recovery/"}],"futureEvolution":"Portable health/degradation protocols and multi-provider continuity playbooks for AI workloads."},{"id":"APRF-15","slug":"change-management","name":"Change Management & Release","summary":"Repeatable promotion of models, prompts, tools, and agents—with tested, fast rollback.","domain":"reliability","crossCutting":false,"severity":"critical","riskLevel":"high","purpose":"Promote AI artifacts (models, prompts, tools, agents, indexes) through controlled environments, and enable immediate rollback when production behavior regresses.","engineeringPhilosophy":"If you cannot roll back, you cannot safely roll forward. AI change management treats prompts and model pins as release units with the same discipline as application code.","whyItMatters":"Uncontrolled hot-edits and untested rollbacks create drift, unreproducible incidents, and long mean-time-to-recover when quality or safety collapses after a change.","commonFailures":["Hot-editing production prompts","Indexes rebuilt manually with no version tag","Tools registered in prod without staging soak","Environment config drift for model pins","No previous prompt version retained","Model pin changed with no path back","Schema migrations that break old tool clients irreversibly","Rollback untested until an incident"],"mandatoryChecks":[{"id":"CHG-M1","requirement":"Production systems shall retain at least N prior production versions of each in-scope artifact type (prompts and/or model pins) per policy (minimum N=2) and prove a restore dry-run that loads the immediate prior version in staging or a prod-adjacent environment.","artifact":"Version retention policy + registry listing of prior production prompt and/or model-pin versions (for artifact types in use) + Restore dry-run record showing immediate prior version loaded in staging or prod-adjacent env","passCondition":"≥N prior production versions retained per policy (minimum N=2) for each in-scope artifact type (prompts and/or model pins); restore dry-run successfully loads the immediate prior version in staging or prod-adjacent env (retention evidence measuredAt ≤90 days). If no production prompts or model pins are used, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"CHG-M2","requirement":"Production systems shall maintain a rollback runbook with exact commands or UI steps and named owners, and prove ≥1 on-call engineer completed a walkthrough or drill in the last 90 days with recorded time-to-execute.","artifact":"Rollback runbook listing exact commands/UI steps and owners + On-call acknowledgment or drill checklist with recorded time-to-execute (≤90 days)","passCondition":"Runbook lists exact commands/UI steps and owners; ≥1 on-call engineer completed a walkthrough or drill in the last 90 days with recorded time-to-execute (operability evidence measuredAt ≤90 days). If no production AI changes may need rollback, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"CHG-M3","requirement":"Production systems shall complete ≥1 successful rollback (drill or real incident) in the last 90 days with measured time-to-restore ≤ documented RTO.","artifact":"Documented RTO for AI/prompt/model/deploy rollback + Drill or incident record with timestamps, outcome, and measured time-to-restore","passCondition":"≥1 successful rollback (drill or real) in the last 90 days with measured time-to-restore ≤ documented RTO (drill evidence measuredAt ≤90 days). If no production AI changes may need rollback, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"DEP-M1","requirement":"Production prompt, model, and tool releases must flow through a documented non-prod→prod promotion path, with no production hot-edits lacking a linked change record.","artifact":"Pipeline/runbook documenting non-prod→prod promotion for prompts, models, and tools + Last-30-day release coverage showing path adherence + 0 hot-edits without change records","passCondition":"100% of production prompt/model/tool releases in the last 30 days flowed through the documented promotion path; 0 production hot-edits without a linked change record (promotion evidence measuredAt ≤90 days). If no production prompt/model/tool releases exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"DEP-M2","requirement":"Every production AI artifact change should record who changed what and when, and link to a review (PR, ticket, or approval ID).","artifact":"Change log or ticket export for AI artifact releases + Last-30-day coverage showing who/what/when + review link on every change","passCondition":"100% of production AI artifact changes in the last 30 days have who/what/when fields and a review link (PR, ticket, or approval ID) (change-record evidence measuredAt ≤90 days). If no production AI artifact changes exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"DEP-M3","requirement":"Production AI gateway, model pins, tool catalogs, and prompts should be declared in IaC or equivalent declarative config, with drift checks showing no unmanaged resources and live pins matching declared versions.","artifact":"IaC/config repo paths for AI gateway, model pins, tool catalogs, and prompts + Drift check showing 0 unmanaged AI config resources + 100% live-pin match","passCondition":"Drift check shows 0 unmanaged production AI config resources outside declarative sources; sample of live pins matches declared versions at 100% (drift evidence measuredAt ≤90 days). If no production AI config exists (gateway, model pins, tool catalogs, or prompts), score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2}],"recommendedChecks":[{"id":"CHG-R1","requirement":"AI release units (prompts, model pins, tool configs, or AI deploys) should roll back with a single documented command or action, proven by an exercise or real rollback in the last 90 days completed within documented RTO.","artifact":"One-command or one-click rollback script/action for AI release units + Last rollback exercise or real event log showing completion within documented RTO (≤90 days)","passCondition":"AI release unit can be rolled back with a single documented command/action; exercise or real rollback ≤90 days completed within documented RTO (exercise evidence measuredAt ≤90 days). If no AI release units ship, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"CHG-R2","requirement":"New agent behaviors should ship behind feature flags, flag state changes should be audited, and the kill/disable path should be tested within the last 90 days.","artifact":"Feature-flag config covering new agent behaviors + Sample flag-change audit trail + kill/disable path test record (≤90 days)","passCondition":"New agent behaviors ship behind flags; flag state changes are audited; kill/disable path tested ≤90 days ago (flag evidence measuredAt ≤90 days). If no production agents with shippable behaviors exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"CHG-R3","requirement":"AI releases should wire quality SLO burn to automated rollback—or to page + runbook with measured MTTA—and prove a test or drill of that path in the last 90 days.","artifact":"Rollback automation (or page+runbook) config tied to quality SLO burn signals + Sample trigger/test or drill evidence of that path within ≤90 days","passCondition":"Quality SLO burn is wired to automated rollback (or page+runbook with measured MTTA) and a test/drill occurred ≤90 days (automation evidence measuredAt ≤90 days). If no AI releases with quality SLOs exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":5,"minCriticality":3},{"id":"DEP-R1","requirement":"High-traffic AI changes should roll out via canary or progressive delivery with automated rollback criteria, and the last such release within 90 days should include a canary metrics link.","artifact":"Progressive delivery/canary config for high-traffic AI changes + Last canary promotion log with metrics link (≤90 days)","passCondition":"High-traffic AI changes use canary or progressive rollout with automated rollback criteria; last such release ≤90 days includes canary metrics link (canary evidence measuredAt ≤90 days). If no high-traffic AI changes exist in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"DEP-R2","requirement":"Prod and staging model pins and tool catalogs should match except documented deltas, proven by a parity scan within the last 30 days with zero unexplained drifts.","artifact":"Environment parity checklist for model pins and tool catalogs + Last parity scan across envs with 0 unexplained drifts (≤30 days)","passCondition":"Prod vs staging model pins and tool catalogs match except documented deltas; last parity scan ≤30 days with 0 unexplained drifts (parity evidence measuredAt ≤90 days). If neither model pins nor tool catalogs exist across prod and staging, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"DEP-R3","requirement":"Embedding and index version upgrades should run via automated migration with validation gates, and the last upgrade within 12 months should succeed without dual-write gaps—or an N/A attestation when no upgrade occurred.","artifact":"Embedding/index migration runbook with validation gates + Last automated migration job log and validation (≤12 months) or no-upgrade attestation","passCondition":"Index/embedding version upgrades run via automated migration with validation gates; last upgrade ≤12 months (or N/A attestation if no upgrade) succeeded without dual-write gaps (migration evidence measuredAt ≤90 days). If no production embeddings or vector indexes exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2}],"evidenceRequired":["Deployment pipeline documentation","Sample change records","Environment inventory","Rollback runbook","Evidence of tested rollback","Version retention policy"],"engineeringBestPractices":["Bundle related prompt/model/tool versions as a release unit when they interact","Keep staging data representative without copying unnecessary production secrets","Automate smoke tests post-deploy including one eval canary","Document freeze windows for peak business periods","Keep rollback independent of full application redeploy when possible","Version tool schemas with compatibility windows","Avoid one-way data migrations tied to prompt experiments","Measure time-to-rollback as an operational KPI"],"automaticValidations":["Pipeline gates requiring eval and security checks","Drift detection between declared and live config","Post-deploy smoke test automation","CI verifying previous artifacts remain fetchable","Synthetic rollback dry-runs in staging","Alerts recommending rollback on quality burn"],"manualValidations":["Release readiness review for major agent launches","Spot audits of console-only changes","On-call drills executing rollback","Post-incident verification that rollback path was used or improved"],"examples":["A release train ships prompt v12 + model pin + tool schema together after staging soak","Index rebuilds produce a new version ID switched via config flip","Quality drop after a prompt release is reversed in under five minutes via registry rollback","A new tool schema is dual-published so clients can fall back"],"references":[{"title":"Google SRE Workbook — Configuration Management","url":"https://sre.google/workbook/"},{"title":"AWS Well-Architected — Operational Excellence","url":"https://aws.amazon.com/architecture/well-architected/"},{"title":"Google SRE — Emergency Response","url":"https://sre.google/sre-book/emergency-response/"},{"title":"AWS Well-Architected — Reliability","url":"https://aws.amazon.com/architecture/well-architected/"}],"futureEvolution":"Unified release manifests covering prompts, models, tools, eval attestations, and automatic quality-triggered rollbacks."},{"id":"APRF-21","slug":"incident-readiness","name":"Incident Readiness","summary":"Detect, contain, and learn from AI-specific production incidents.","domain":"reliability","crossCutting":false,"severity":"high","riskLevel":"high","purpose":"Prepare people, playbooks, and tooling to detect, contain, communicate, and learn from AI-specific incidents—including abuse, quality collapse, and unsafe tool actions.","engineeringPhilosophy":"Incidents will happen. Readiness means AI-aware detection, clear ownership, containment that includes pausing agents, and blameless learning that improves pillars.","whyItMatters":"Traditional SEV playbooks miss prompt injection campaigns, model outages, and agentic damage. Without AI-specific readiness, mean time to contain balloons.","commonFailures":["No playbook for model abuse or data leakage via chat","On-call cannot pause agents or roll back prompts","Customer communication templates ignore AI failure modes","No post-incident action tracking into evals and controls"],"mandatoryChecks":[{"id":"INC-M1","requirement":"Production AI systems must maintain incident playbooks for abuse, data leakage, bad agent/tool actions, and provider outage—each with a named owner and a review date within the last 12 months.","artifact":"Playbook set covering abuse, leakage, bad actions, and provider outage with owners + Review dates ≤12 months for each of the four playbooks","passCondition":"Four playbooks present (abuse, leakage, bad actions, provider outage), each with owner and review date ≤12 months (playbook evidence measuredAt ≤90 days). If no production AI system is in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"INC-M2","requirement":"On-call must be able to pause agents, disable tools, and roll back prompts or models, proven by a drill in the last 90 days completed within documented time budgets.","artifact":"Containment runbook covering pause agents, disable tools, and prompt/model rollback + Drill record ≤90 days showing all three actions within documented time budgets","passCondition":"Drill in last 90 days successfully demonstrated pause agents, disable tools, and roll back prompt/model within documented time budgets (drill evidence measuredAt ≤90 days). If no production agents, tools, or prompt/model release units exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2}],"recommendedChecks":[{"id":"INC-R1","requirement":"On-call should receive page-worthy alerts for at least two non-infra AI safety/quality signals, each with a documented threshold and owner, and a policy reviewed within 90 days.","artifact":"On-call alert policy export listing safety/quality pages + Last 90 days of triggered incidents or drill tickets for those pages","passCondition":"At least two non-infra signals (e.g. refusal-rate spike, eval-score drop, toxicity/jailbreak hit rate) page an on-call; each has a documented threshold and owner; policy reviewed ≤90 days ago (alert evidence measuredAt ≤90 days). If no production AI system is in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"INC-R2","requirement":"SEV-eligible AI incidents should receive a post-incident review with at least one tracked action mapped to an APRF pillar—or an explicit no-action rationale.","artifact":"Post-incident review template requiring APRF pillar mapping + Last-90-day coverage: SEV-eligible AI reviews with tracked actions or no-action rationale","passCondition":"100% of SEV-eligible AI incidents in last 90 days have a review with ≥1 tracked action mapped to an APRF pillar or explicit “no action” rationale (review evidence measuredAt ≤90 days). If no SEV-eligible AI incidents exist in the last 90 days, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"INC-R3","requirement":"Teams should maintain criteria that map AI event types to notify / no-notify decisions, and show a drill or real notification ≤12 months that followed those criteria with timestamps.","artifact":"Customer notification criteria for AI-related events + Last drill or real notification sample ≤12 months with timestamps","passCondition":"Criteria map event types (safety incident, widespread quality fail, data exposure) to notify / no-notify; last drill or incident ≤12 months followed the criteria with timestamps (notification evidence measuredAt ≤90 days). If no customer-facing or externally disclosed AI system is in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"INC-R4","requirement":"Teams should complete an AI-focused incident tabletop at least every 180 days and retain an after-action report with actions and owners.","artifact":"Tabletop plan for an AI-specific incident scenario + Dated after-action report ≤180 days with retained actions and owners","passCondition":"An AI-focused tabletop completed ≤180 days with retained actions and owners (tabletop evidence measuredAt ≤90 days). If no production AI system is in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":3}],"evidenceRequired":["Playbooks and ownership roster","Alert configuration samples","Post-incident review examples (redacted)"],"engineeringBestPractices":["Define SEV classifications for AI harm (financial, privacy, safety, reputation)","Preserve traces for forensics under legal hold when needed","Train support and on-call on AI failure literacy","Link incidents to eval fixtures so regressions cannot silently return"],"automaticValidations":["Alert routing tests","Automated creation of incident tickets from critical signals","Verification that kill switches remain reachable"],"manualValidations":["Tabletop exercises","After-action review quality checks"],"examples":["A spike in tool denials pages on-call; the agent is paused while injection is investigated","A postmortem adds a new adversarial eval case that fails CI until fixed"],"references":[{"title":"Google SRE — Managing Incidents","url":"https://sre.google/sre-book/managing-incidents/"},{"title":"NIST AI RMF — Manage","url":"https://www.nist.gov/itl/ai-risk-management-framework"}],"futureEvolution":"Shared AI incident taxonomies and anonymized industry learning feeds."},{"id":"APRF-13","slug":"cost-optimization","name":"Cost Optimization","summary":"Bound spend with budgets, caching, routing, and abuse controls.","domain":"cost","crossCutting":false,"severity":"high","riskLevel":"high","purpose":"Keep AI spend predictable and attributable through budgets, caching, model routing, quota enforcement, and abuse prevention.","engineeringPhilosophy":"Cost is a reliability and security property. Unbounded token spend is a denial-of-wallet attack surface and a business continuity risk.","whyItMatters":"Agent loops, recursive tool use, and prompt bloat can create sudden five-figure bills. Without controls, AI features become financially unsafe to operate.","commonFailures":["No per-tenant or per-feature budgets","Retry storms that multiply completions","Sending huge contexts when retrieval would suffice","Using frontier models for trivial classification tasks","Soft cost dashboards without enforce-on-exceed","CI concurrency or generic HTTP limits mistaken for AI spend ceilings","Cost dashboards without budget-burn or anomaly alert policies","Alert definitions with no proven page/notify path","Unbounded maxRetries or missing backoff on AI/model clients","Relying on AGN-M2 alone while non-agent clients retry without bound","Cache library present without enabled idempotent paths or safety exclusions","No hit-rate/savings report for ≥30 days","All traffic on frontier models with no low-risk task-class routing","Cheap routing without eval coverage or misroute monitoring","Aggregate spend dashboards without per-product unit-cost metrics","FinOps reviews without named owners for cost outliers"],"mandatoryChecks":[{"id":"COST-M1","requirement":"Production AI workloads shall enforce finite hard spend ceilings and/or request rate limits (provider, gateway, or application) that deny or throttle when exceeded—not soft dashboards or prompt-only budgets alone.","artifact":"Gateway/provider/application config declaring finite spend ceiling and/or rate limit (TPM/RPM/$, tokens) + Enforcement evidence: automated exceed test or ≤90-day production deny/throttle event log","passCondition":"A finite hard spend ceiling and/or rate limit is configured for production AI workloads; enforcement demonstrably denies or throttles when the limit is exceeded (automated test or production event log measuredAt ≤90 days). If no production AI/model/agent traffic exists, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":2,"minCriticality":1},{"id":"COST-M2","requirement":"Production AI spend shall be monitored with alert policies for budget burn and spend anomaly that notify operators per runbook—not dashboards alone.","artifact":"Cost/spend dashboard or telemetry views covering production AI workloads + Alert policies for budget burn and spend anomaly (IaC, provider, or gateway) + Notify proof: alert test or documented fire ≤90 days with page/notify outcome","passCondition":"Alerts exist for both budget burn and spend anomaly covering production AI spend; a synthetic or historical burn/anomaly event would page/notify per runbook (alert test or documented fire measuredAt ≤90 days). If no production AI spend exists, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"COST-M3","requirement":"Production AI clients shall enforce finite retry/backoff and loop budgets so forced failures cannot amplify completions without bound—covering HTTP/SDK clients and agent loops, not prompt-only “try again” guidance.","artifact":"Retry/backoff config (finite maxRetries + backoff) for production AI/model clients + Agent or client loop budget config where applicable (finite iterations/steps) + Amplification test results: forced failure/retry hits a bounded token or $ ceiling (≤90 days)","passCondition":"Max retries and max agent/client loops are finite for 100% of production AI clients; amplification tests show cost cannot grow without bound under forced failure/retry (bounded token or $ ceiling; test measuredAt ≤90 days). If no production AI/model clients exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2}],"recommendedChecks":[{"id":"COST-R1","requirement":"Production AI systems should cache prompt/response results for documented idempotent or repeated paths, with explicit exclusions for sensitive or personalized prompts, and report hit-rate and savings for ≥30 days.","artifact":"Prompt/response cache config naming idempotent paths and safety exclusions + Hit-rate and savings report covering ≥30 days (import or dashboard export)","passCondition":"Cache is enabled for documented idempotent/repeated prompt paths; sensitive/personalized prompts are excluded; hit-rate and savings are reported for a window of ≥30 days (report measuredAt within the last 90 days). If no production AI traffic with potentially cacheable prompts exists, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"COST-R2","requirement":"Production AI systems should route documented low-risk task classes to cheaper models by default, with eval coverage proving quality within tolerance of a premium baseline and misroute rate monitored ≤30 days.","artifact":"Model-routing policy mapping low-risk task classes to cheap vs premium models + Eval coverage report for low-risk routed tasks vs premium baseline + Misroute-rate monitoring evidence covering ≤30 days","passCondition":"Documented low-risk task classes route to cheaper models by default; eval shows quality within tolerance versus a premium baseline; misroute rate is monitored for a window of ≤30 days (report measuredAt within the last 90 days). If a single fixed model with no routing surface, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"COST-R3","requirement":"Each customer-facing AI product should publish unit-cost metrics (e.g. cost per successful task or journey) for the last quarter and undergo a FinOps review ≤90 days with named owners for outliers above documented thresholds.","artifact":"Per-product AI unit-economics report (cost per successful task / journey) for the last quarter + FinOps review minutes ≤90 days with outlier owners and thresholds","passCondition":"Each customer-facing AI product has unit-cost metrics for the last quarter; a FinOps review occurred within the last 90 days with named owners for outliers above documented thresholds (review measuredAt ≤90 days). If no customer-facing AI products exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2}],"evidenceRequired":["Enforce-on-exceed deny/throttle evidence (≤90 days)","Hard spend/rate limit config for production AI workloads","Budget and quota configuration","Cost dashboards and alert policies","Documented retry/loop limits"],"engineeringBestPractices":["Attribute cost to tenant and feature tags","Prefer embeddings + retrieval over stuffing large corpora","Set timeouts on model and tool calls","Load-test cost under adversarial long prompts"],"automaticValidations":["Gateway enforcement of quotas","Anomaly detection on token spend","CI checks estimating token cost of prompt changes","Repo spend/rate-limit config heuristics (ai-spend-limits collector)","Imported enforce-on-exceed suite under imports/ai-spend-limits/","Repo budget-burn / spend-anomaly alert heuristics (ai-cost-alerts collector)","Imported notify proof under imports/ai-cost-alerts/","Repo retry/loop budget heuristics (ai-retry-amplification collector)","Imported amplification suite under imports/ai-retry-amplification/","Repo prompt-cache heuristics (ai-prompt-cache collector)","Imported ≥30-day hit-rate/savings under imports/ai-prompt-cache/","Repo model-routing heuristics (ai-model-routing collector)","Imported eval + misroute suite under imports/ai-model-routing/","Repo FinOps/unit-economics heuristics (ai-finops-unit-economics collector)","Imported quarterly metrics + review under imports/ai-finops-unit-economics/"],"manualValidations":["Quarterly cost architecture review","Abuse scenario walkthroughs"],"examples":["A free-tier chatbot hard-stops after N tokens/day per user","An agent aborts when projected step cost exceeds remaining budget"],"references":[{"title":"AWS Well-Architected — Cost Optimization","url":"https://aws.amazon.com/architecture/well-architected/"},{"title":"FinOps Foundation practices","url":"https://www.finops.org/"}],"futureEvolution":"Standard cost telemetry schemas for multi-provider AI gateways."},{"id":"APRF-29","slug":"organizational-governance","name":"Organizational Governance","summary":"AI policy, ownership, risk acceptance, and continual improvement—ISO 42001-style management system.","domain":"governance","crossCutting":false,"severity":"high","riskLevel":"medium","purpose":"Establish organizational AI policy, clear ownership/RACI, risk-acceptance authority, and continual improvement so technical pillars have accountable stewards.","engineeringPhilosophy":"Technical controls without organizational governance drift. A production-ready AI program names owners, accepts residual risk explicitly, and improves from incidents and audits.","whyItMatters":"Enterprises fail AI readiness when no one owns a pillar, exceptions are informal, and leadership cannot see residual risk.","commonFailures":["AI features ship with no named owner for safety or eval gates","Exceptions granted in chat with no expiry","No AI policy covering acceptable use and prohibited applications","Compliance theater without leadership review of risk"],"mandatoryChecks":[{"id":"ORG-M1","requirement":"An approved AI policy shall exist with version, named owner, and review date ≤12 months, and shall include both acceptable-use and prohibited-application sections.","artifact":"Approved AI acceptable-use / prohibited-applications policy with version, owner, and review date + Confirmation that both acceptable-use and prohibited-application sections are present","passCondition":"Policy has version, owner, and review date ≤12 months; includes both acceptable-use and prohibited-application sections (policy evidence measuredAt ≤90 days). If AI is not used at all, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2}],"recommendedChecks":[{"id":"ORG-R1","requirement":"Leadership should review AI risk posture and APRF capability attained within the last 90 days; every open action from that review should have an owner and due date.","artifact":"Leadership AI risk / APRF maturity review minutes (or board pack excerpt) with review date + Action log showing owners and due dates for open items","passCondition":"Leadership reviewed AI risk posture and APRF capability attained ≤90 days ago; open actions have owners and due dates (review evidence measuredAt ≤90 days). If the organization does not run production AI systems, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"ORG-R2","requirement":"Every production AI system should name owners for each org-declared required critical APRF domain (commonly security, safety, data, reliability, and model/governance) in a system inventory, with zero systems missing a required domain owner.","artifact":"Production AI system inventory listing the org-declared required critical-domain owner fields + Query/report showing 0 systems missing required domain owners","passCondition":"0 production AI systems missing any required critical-domain owner in the inventory; inventory covers all production AI system IDs; required domain set is declared (inventory evidence measuredAt ≤90 days). If no production AI systems exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"ORG-R3","requirement":"Sev-1/2 AI incidents and critical eval failures in the last quarter should produce improvement backlog items (≥80%); ≥50% of those items should be closed or have a dated plan.","artifact":"Improvement backlog (tickets) linked from Sev-1/2 AI incidents and critical eval failures + Quarterly sample showing linkage rate ≥80% and closed-or-planned rate ≥50%","passCondition":"≥80% of Sev-1/2 AI incidents and critical eval fails in the last quarter produced a backlog item; ≥50% of those items closed or have a dated plan (backlog evidence measuredAt ≤90 days). If the organization does not use AI, or no Sev-1/2 AI incidents or critical eval fails are in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"ORG-R4","requirement":"Every open control-gap waiver (risk acceptance) shall record a named owner and expiry date; every expired waiver shall have an escalation record—or be closed—before it remains unowned.","artifact":"Risk-acceptance / control-gap waiver register for in-scope AI systems + Confirmation that open waivers have owner+expiry and expired waivers have escalation (or are closed)","passCondition":"100% of open control-gap waivers have owner + expiry; 0 expired waivers without an escalation record (register evidence measuredAt ≤90 days). If the organization has no open or expired control-gap waivers and no AI control gaps in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":3},{"id":"ORG-R5","requirement":"On an org-wide cadence, internal audit or independent assessment should sample APRF evidence; the last sampling report shall be ≤12 months old and list sampled Check IDs and findings. This is organizational sampling—not the same as CMP-R3 coverage of every capability Level 5 system.","artifact":"Independent assessment or internal-audit sampling report against APRF evidence (org cadence) + Sampled Check IDs and findings from the last ≤12 month cycle","passCondition":"Last org sampling report age ≤12 months; lists sampled Check IDs and findings (report evidence measuredAt ≤90 days). If no AI systems are in production assessment scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":5,"minCriticality":3}],"evidenceRequired":["AI policy document","Ownership/RACI for production AI systems","Risk-acceptance register samples"],"engineeringBestPractices":["Map APRF domains to teams; avoid orphan pillars","Time-box exceptions; auto-escalate expired waivers","Tie promotions and funding to measurable maturity for high-criticality systems"],"automaticValidations":["Inventory systems missing owners","Alerts on expired risk acceptances"],"manualValidations":["Annual policy review","Leadership tabletop on AI risk acceptance"],"examples":["A risk register entry accepts a missing multi-provider fallback until Q3 with CTO sign-off","Each agent product lists owners for Security, Safety, Evaluation, and Reliability"],"references":[{"title":"ISO/IEC 42001 — AI management systems","url":"https://www.iso.org/standard/81230.html"},{"title":"NIST AI RMF — Govern","url":"https://www.nist.gov/itl/ai-risk-management-framework"}],"futureEvolution":"Machine-readable organizational control catalogs mapped to APRF domains and ISO 42001 clauses."},{"id":"APRF-19","slug":"compliance","name":"Compliance","summary":"Produce auditable evidence of controls without equating compliance with readiness.","domain":"governance","crossCutting":false,"severity":"high","riskLevel":"medium","purpose":"Map regulatory and contractual obligations to concrete AI controls and produce auditable evidence—while recognizing compliance alone does not prove production readiness.","engineeringPhilosophy":"Compliance is necessary evidence, not sufficient engineering. APRF treats compliance as a pillar that packages proof of other pillars for auditors and customers.","whyItMatters":"Enterprises cannot buy or deploy AI systems that cannot demonstrate control evidence. Conversely, checkbox compliance without engineering depth still fails in production.","commonFailures":["Claiming 'we are compliant' without control-to-evidence mapping","Policies that do not match runtime behavior","No audit trail for model and prompt changes","Ignoring sector-specific AI obligations until late"],"mandatoryChecks":[{"id":"CMP-M1","requirement":"Every production AI system shall have applicable legal/regulatory/contractual obligations identified in a register with a named owner, or an explicit “none in scope” attestation with owner and review date within 12 months.","artifact":"Inventory of production AI system IDs in scope + Obligations register mapping each system to obligations (or none-in-scope) with owner and review date","passCondition":"Every production AI system ID has ≥1 mapped obligation entry or an explicit “none in scope” attestation with owner and review date ≤12 months (register evidence measuredAt ≤90 days). If no production AI systems exist, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"CMP-M2","requirement":"Every in-scope obligation shall map to at least one evidence artifact ID (APRF Check or internal control ID) in a control→evidence matrix reviewed within 12 months, with zero orphan obligations lacking an evidence pointer.","artifact":"Control→evidence matrix linking in-scope obligations to APRF Checks or internal control/evidence IDs + Matrix review date (≤12 months) and confirmation of zero orphan obligation rows","passCondition":"100% of in-scope obligations map to ≥1 evidence artifact ID; matrix review date ≤12 months; 0 orphan obligations without an evidence pointer (matrix evidence measuredAt ≤90 days). If no obligations are in scope (all none-in-scope), score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":3},{"id":"CMP-M3","requirement":"Critical AI control-plane changes shall be written to an audit log retained at least as long as policy requires (for example ≥365 days); a synthetic change shall appear in the log within ≤5 minutes and remain queryable after a retention smoke check.","artifact":"Audit log retention config for critical AI control-plane change events (policy minimum documented) + Synthetic control-plane change test showing ≤5 minute appearance and queryability after retention smoke check","passCondition":"Retention is configured ≥ policy minimum (e.g. ≥365 days); a synthetic control-plane change appears in the audit log within ≤5 minutes and remains queryable after a retention smoke check (config/smoke evidence measuredAt ≤90 days). If no critical AI control plane is in scope (model/prompt/tool promotion, policy, kill-switch, or equivalent), score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2}],"recommendedChecks":[{"id":"CMP-R1","requirement":"Documented AI/compliance controls for production systems shall be tested on the published schedule within the last cycle (≤90 days default); every open exception shall name an owner, expiry, and compensating control.","artifact":"Control-testing schedule + latest test results pack for in-scope AI/compliance controls + Exceptions register with owner, expiry, and compensating control for every open exception","passCondition":"Documented controls due in the last cycle were tested on schedule (cycle age ≤90 days default); every open exception has owner, expiry, and compensating control (testing/exceptions evidence measuredAt ≤90 days). If none are in scope, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"CMP-R2","requirement":"Customer-facing trust/security documentation for production AI systems shall cover identity, safety/eval, data handling, and incident contact at minimum; include an explicit APRF pillar or Core Profile mapping table; and show a last-updated date within 12 months.","artifact":"Customer-facing trust/security doc with published URL and last-updated date + Explicit APRF pillar or Core Profile mapping table covering identity, safety/eval, data handling, and incident contact","passCondition":"Public trust doc covers identity, safety/eval, data handling, and incident contact; pillar/Core mapping table is explicit; last-updated ≤12 months (trust-doc evidence measuredAt ≤90 days). If no customer-facing production AI surface, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"CMP-R3","requirement":"Every AI system that claims or attains APRF capability maturity Level 5 (Optimizing—typically Regulated / highest-discipline production) shall be covered by an independent assessment or internal-audit report ≤12 months old that samples APRF gates and lists sampled Check IDs, findings, and remediation owners. Level 5 is capability maturity, not criticality tier (tiers are 0–3).","artifact":"Independent assessment or internal-audit report sampling capability Level-5 AI systems against APRF gates + Coverage proof that every capability Level-5 system ID was in scope, with findings and remediation owners","passCondition":"Last assessment age ≤12 months; covers every system that claims or attains capability Level 5; lists sampled Check IDs, findings, and remediation owners (assessment evidence measuredAt ≤90 days). If no systems claim or attain capability Level 5, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":5,"minCriticality":3}],"evidenceRequired":["Obligations register for the AI product","Evidence packs per critical control","Audit log retention configuration"],"engineeringBestPractices":["Derive technical tickets from obligations; avoid orphan policies","Reuse APRF pillar evidence for multiple frameworks where mappings exist","Keep compliance language accurate: readiness ≠ certification","Version compliance artifacts with product releases"],"automaticValidations":["Continuous control monitoring where automatable","Alerts on audit log pipeline failure","CI attaching evidence artifacts to releases"],"manualValidations":["Internal audit sampling","Legal review of external AI claims"],"examples":["A SOC 2 narrative points to APRF eval gates and access reviews as evidence","Change tickets for prompt releases satisfy audit sampling requests"],"references":[{"title":"NIST AI RMF","url":"https://www.nist.gov/itl/ai-risk-management-framework"},{"title":"ISO/IEC 42001 (AI management systems) — conceptual alignment","url":"https://www.iso.org/standard/81230.html"}],"futureEvolution":"Common control catalogs mapping APRF pillars to regional AI regulations."},{"id":"APRF-23","slug":"platform-engineering","name":"Platform Engineering","summary":"Make the safe path the easy path—paved roads that apply across every APRF domain.","domain":null,"crossCutting":true,"severity":"medium","riskLevel":"medium","purpose":"Provide builders with paved roads—SDKs, templates, local evals, guardrails, and documentation—so secure and operable defaults are the path of least resistance across all domains.","engineeringPhilosophy":"Platform engineering is a cross-cutting control, not a peer readiness domain. Friction on unsafe paths and speed on safe ones determine whether other pillars are actually followed.","whyItMatters":"If the approved gateway is hard and the raw provider key is easy, builders will bypass controls. DX debt becomes security and reliability debt.","commonFailures":["No internal AI platform or golden paths","Docs that explain policy but not how to comply","Slow security review with no self-serve checklists","Local development that cannot run evals or policy checks","Stale or ownerless golden-path wiki without annual review","Generic service deploy docs missing AI auth/secrets/evals/promote sections"],"mandatoryChecks":[{"id":"DX-M1","requirement":"Builders shall have a versioned, owned golden-path document for deploying AI features to production that covers authentication, secrets, evals, and promote steps, reviewed within the last 12 months.","artifact":"Golden-path documentation from scaffold to production with version and owner + Evidence the doc covers auth, secrets, evals, and promote steps + Review attestation or changelog showing review within 12 months","passCondition":"A golden-path document exists with version and owner; it covers authentication, secrets, evals, and promote steps for AI features; last review is within 12 months (review measuredAt ≤365 days). If the organization does not build or deploy AI features, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2},{"id":"DX-M2","requirement":"The default AI golden-path pipeline (local and/or CI) shall run authentication, secret-scan, and basic eval checks, and failing any of them shall block merge or promote.","artifact":"CI and/or local check config covering auth, secret-scan, and basic evals + Evidence those checks are required (blocking) on merge/promote for the AI golden-path template","passCondition":"The default AI pipeline runs auth, secret-scan, and basic eval checks; failing any blocks merge or promote in the golden-path template (blocking evidence measuredAt ≤90 days). If no AI build/promote surface, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":3,"minCriticality":2}],"recommendedChecks":[{"id":"DX-R1","requirement":"Scaffolding templates shall exist for agents, RAG, and MCP with authentication, secrets, and logging defaults enabled, and either ≥1 new service used a template in the last 90 days or an adoption target is documented.","artifact":"Scaffolding template repo/catalog covering agents, RAG, and MCP + Evidence auth, secrets, and logging defaults are enabled in those templates + Adoption metrics (≥1 use in 90 days) or documented adoption target","passCondition":"Templates exist for agents, RAG, and MCP with auth, secrets, and logging defaults on; ≥1 new service used a template in the last 90 days or an adoption target is documented (adoption proof measuredAt ≤90 days). If none planned and no AI surface, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"DX-R2","requirement":"Developers shall be able to run the core AI eval subset locally or via a one-command inner loop before opening a PR, and the last sampled AI PR (≤30 days) shall show pre-PR eval evidence or a documented waiver.","artifact":"Local/inner-loop eval runner docs and package or script entrypoint + Evidence the core eval subset runs in one command (or documented equivalent) + Sample AI PR (≤30 days) with pre-PR eval evidence or documented waiver","passCondition":"A local or one-command inner-loop runner exists for the core AI eval subset; the last sampled AI PR (≤30 days) shows pre-PR eval evidence or a documented waiver (sample/waiver measuredAt ≤30 days). If no AI eval surface, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2},{"id":"DX-R3","requirement":"Time-to-safe-production and policy-bypass rate shall be defined with formulas, published for ≥30 consecutive days, and bypass rate shall have an alert or review threshold with a named owner.","artifact":"Definitions/formulas for time-to-safe-production and policy-bypass rate + Dashboard or weekly report with ≥30 consecutive days of series + Bypass-rate alert or review threshold with named owner","passCondition":"Both metrics are defined with formulas; published for ≥30 consecutive days; bypass rate has an alert or review threshold with a named owner (series / ownership proof measuredAt ≤90 days). If the organization lacks an AI platform or paved road with enough traffic to measure the required metrics, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":5,"minCriticality":3},{"id":"DX-R4","requirement":"A named owner team and a support channel shall exist for the AI platform / paved road, with either a published response SLA proven by a recent test ping or a listed on-call rotation.","artifact":"Platform ownership record naming the owner team for the AI paved road + Support channel (Slack, ticket queue, or equivalent) documented + Test-ping within published SLA (≤90 days) or listed on-call rotation","passCondition":"Named owner team and support channel are documented for the AI platform / paved road; either a test ping met the published SLA within 90 days, or an on-call rotation is listed (support proof measuredAt ≤90 days). If the organization operates neither an AI platform nor a paved road, score NOT_APPLICABLE.","method":"hybrid","minimumTier":"E3","requiredFromLevel":4,"minCriticality":2}],"evidenceRequired":["Review attestation within 12 months","Versioned AI golden-path documentation with owner","Golden path documentation","Template/repository inventory","Support ownership for AI platform"],"engineeringBestPractices":["Default SDKs inject tracing, auth, and budget headers","Provide copy-paste threat model and APRF checklist stubs","Measure and reduce friction for approved tools","Celebrate teams that use paved roads in readiness reviews"],"automaticValidations":["Template CI that fails if safe defaults are removed","Telemetry on gateway vs direct-provider usage","Lint rules guiding builders to approved libraries","Repo golden-path doc heuristics (platform-golden-path collector)","Imported review attestation under imports/platform-golden-path/"],"manualValidations":["Builder interviews on friction points","Periodic DX reviews with security and platform teams"],"examples":["create-agent CLI scaffolds an agent with budgets, authz hooks, and eval stubs","A PR template links to the APRF pillar checklist for the feature type"],"references":[{"title":"Google SRE Workbook — Soft skills / platform thinking parallels","url":"https://sre.google/workbook/"},{"title":"CNCF platforms white papers — paved roads concept","url":"https://www.cncf.io/"}],"futureEvolution":"Shared open-source APRF linters, project templates, and inner-loop conformance checks adopted across ecosystems."}],"stats":{"domainCount":8,"pillarCount":27,"mandatoryCheckCount":92,"recommendedCheckCount":85,"deprecatedCheckCount":1,"checkCount":178,"ruleEngine":{"package":"@stackrail-io/aprf-engine","note":"Normative rule bodies live in packages/aprf-engine/rules/; pillars hydrate checks at load time."},"profileCount":3,"coreProfileCheckCount":39,"crosswalkCount":11,"crosswalkMappingCount":261,"lensCount":4,"lensCheckCount":50},"metadata":{"compatibility":{"crosswalks":["NIST AI RMF","ISO/IEC 42001","SOC 2 Trust Services Criteria (evidence reuse)","OWASP LLM Top 10 (with AISVS bridges)","OWASP AISVS","OWASP ASVS 5.0","OpenCRE","CSA MAESTRO","OWASP FIASSE / SSEM","AWS Well-Architected (conceptual)","SLSA / supply-chain"],"note":"Machine-readable maps for NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10 (incl. AISVS relatedPeerControlIds), AISVS, ASVS, OpenCRE, MAESTRO, FIASSE, SOC 2, AWS Well-Architected, and SLSA ship in the APRF spec under crosswalks[]. Informative alignment only — not certification."}}}