Controls that map back to named risks.
Each entry here is a specific mitigating control: what it does, where it fits in the prevent/detect/correct/direct lifecycle, and which risks it addresses. A starting scaffold, not an exhaustive register — it grows as engagements surface more.
Filter by control type.
5 of 5 controls shown.
AI incident response and rollback
Defined containment, remediation, and rollback procedure for a detected AI system failure or harmful output.
AI system monitoring and logging
Continuous telemetry, drift detection, and audit logging of AI system inputs, outputs, and overrides.
Human-in-the-loop review
Mandatory human approval gate for high-consequence or irreversible AI-generated actions before they take effect.
Output validation and guardrails
Deterministic schema validation and sanitisation of AI-generated output before it reaches any downstream system.
Third-party model and vendor due diligence
Pre-procurement and ongoing due-diligence policy for the selection and contractual oversight of third-party AI models and datasets.
See how a control becomes an engagement.
Every control here maps to a defined engagement area, scoped against the risks it mitigates.