Controls that map back to named risks.

Each entry here is a specific mitigating control: what it does, where it fits in the prevent/detect/correct/direct lifecycle, and which risks it addresses. A starting scaffold, not an exhaustive register; it grows as engagements surface more. See how controls map to risks by effectiveness before browsing.

Filter by control type.

22 of 22 controls shown.

preventive

Adversarial robustness testing

Structured red-teaming and adversarial testing of an AI system against known attack techniques before deployment and on a recurring cadence after.

directive

AI acceptable use policy

A top-management-approved policy defining what AI use is permitted, what isn't, and where to escalate an edge case.

directive

AI impact assessment process

A mandatory, structured assessment of an AI system's impact on individuals, groups, and society, completed before deployment.

corrective

AI incident response and rollback

Defined containment, remediation, and rollback procedure for a detected AI system failure or harmful output.

directive

AI literacy programme

Structured training for staff who operate, rely on, or are affected by an AI system's output, covering its limitations as well as its use.

directive

AI ownership and accountability framework

A named individual or committee accountable for each AI system's risk posture, with defined reporting lines.

detective

AI system monitoring and logging

Continuous telemetry, drift detection, and audit logging of AI system inputs, outputs, and overrides.

directive

AI transparency and disclosure labelling

Consistent, visible labelling of AI-generated content and AI-driven interactions across every surface a person might encounter them.

directive

Automated decision-making safeguards

Process guaranteeing a right to human review, an ability to contest, and a documented rationale for any solely-automated decision with significant effect.

detective

Bias testing and fairness monitoring

Pre-deployment subgroup performance testing plus ongoing production monitoring for disparate outcomes across protected characteristics.

directive

Data minimisation and lawful basis review

A documented check that any personal data used to train, fine-tune, or ground an AI system has a valid lawful basis and is limited to what's necessary.

detective

Factuality and hallucination verification

Automated or human fact-checking of AI-generated output against a trusted source before it is relied on for a consequential decision.

preventive

Human-in-the-loop review

Mandatory human approval gate for high-consequence or irreversible AI-generated actions before they take effect.

directive

Important business service impact-tolerance mapping

A maintained map of where AI systems sit within important business services, with an AI-specific impact tolerance defined for each.

preventive

Inference usage quotas and rate limiting

Per-user and per-tenant limits on request volume, input length, and context-window usage for an AI system's inference endpoint.

preventive

Model artifact signing and integrity verification

Cryptographic signing of trusted model artifacts and verification of that signature before a model is loaded into production.

preventive

Output validation and guardrails

Deterministic schema validation and sanitisation of AI-generated output before it reaches any downstream system.

preventive

System prompt hardening

Design and testing practice that keeps system prompts free of secrets and resilient to extraction attempts.

directive

Third-party model and vendor due diligence

Pre-procurement and ongoing due-diligence policy for the selection and contractual oversight of third-party AI models and datasets.

preventive

Training data provenance checks

Documented verification of the source, licensing, and integrity of any dataset before it is used for training or fine-tuning.

preventive

Vector store and embedding access controls

Access control, input validation, and tenant isolation applied to a RAG pipeline's vector store, the same as any other production data store.

directive

Vendor exit strategy and concentration management

A documented, costed exit plan and an actively managed concentration limit for any critical AI vendor dependency.

See how a control becomes an engagement.

Every control here maps to a defined engagement area, scoped against the risks it mitigates.