Controls that map back to named risks.
Each entry here is a specific mitigating control: what it does, where it fits in the prevent/detect/correct/direct lifecycle, and which risks it addresses. A starting scaffold, not an exhaustive register; it grows as engagements surface more. See how controls map to risks by effectiveness before browsing.
Filter by control type.
22 of 22 controls shown.
Adversarial robustness testing
Structured red-teaming and adversarial testing of an AI system against known attack techniques before deployment and on a recurring cadence after.
AI acceptable use policy
A top-management-approved policy defining what AI use is permitted, what isn't, and where to escalate an edge case.
AI impact assessment process
A mandatory, structured assessment of an AI system's impact on individuals, groups, and society, completed before deployment.
AI incident response and rollback
Defined containment, remediation, and rollback procedure for a detected AI system failure or harmful output.
AI literacy programme
Structured training for staff who operate, rely on, or are affected by an AI system's output, covering its limitations as well as its use.
AI ownership and accountability framework
A named individual or committee accountable for each AI system's risk posture, with defined reporting lines.
AI system monitoring and logging
Continuous telemetry, drift detection, and audit logging of AI system inputs, outputs, and overrides.
AI transparency and disclosure labelling
Consistent, visible labelling of AI-generated content and AI-driven interactions across every surface a person might encounter them.
Automated decision-making safeguards
Process guaranteeing a right to human review, an ability to contest, and a documented rationale for any solely-automated decision with significant effect.
Bias testing and fairness monitoring
Pre-deployment subgroup performance testing plus ongoing production monitoring for disparate outcomes across protected characteristics.
Data minimisation and lawful basis review
A documented check that any personal data used to train, fine-tune, or ground an AI system has a valid lawful basis and is limited to what's necessary.
Factuality and hallucination verification
Automated or human fact-checking of AI-generated output against a trusted source before it is relied on for a consequential decision.
Human-in-the-loop review
Mandatory human approval gate for high-consequence or irreversible AI-generated actions before they take effect.
Important business service impact-tolerance mapping
A maintained map of where AI systems sit within important business services, with an AI-specific impact tolerance defined for each.
Inference usage quotas and rate limiting
Per-user and per-tenant limits on request volume, input length, and context-window usage for an AI system's inference endpoint.
Model artifact signing and integrity verification
Cryptographic signing of trusted model artifacts and verification of that signature before a model is loaded into production.
Output validation and guardrails
Deterministic schema validation and sanitisation of AI-generated output before it reaches any downstream system.
System prompt hardening
Design and testing practice that keeps system prompts free of secrets and resilient to extraction attempts.
Third-party model and vendor due diligence
Pre-procurement and ongoing due-diligence policy for the selection and contractual oversight of third-party AI models and datasets.
Training data provenance checks
Documented verification of the source, licensing, and integrity of any dataset before it is used for training or fine-tuning.
Vector store and embedding access controls
Access control, input validation, and tenant isolation applied to a RAG pipeline's vector store, the same as any other production data store.
Vendor exit strategy and concentration management
A documented, costed exit plan and an actively managed concentration limit for any critical AI vendor dependency.
See how a control becomes an engagement.
Every control here maps to a defined engagement area, scoped against the risks it mitigates.