# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-08-29T17:44:39Z", "synthesisSha256": "6ec120a8f78682cc067e03cc468620f2cecbf2747b2e6131971c6e1bec8fd7cf", "providerMode": "single-provider-waiver", "providers": [ "Claude" ], "waivedProviders": [ "Grok" ] }, "metaModel": { "id": "WM-AI-008", "registryId": "vr.wm-ai-008", "name": "AI Safety / Governance Assessment", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "aggregate", "family": "World Models", "category": "Information and virtual systems", "industry": [ "Cross-industry" ], "domain": [ "INF.AI.GOV" ], "tags": [ "ai", "safety", "governance", "assessment", "inf.ai.gov" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-ai-008-ai-safety-governance-assessment/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-ai-008", "model": { "registry_id": "vr.wm-ai-008", "model_id": "WM-AI-008", "name": "AI Safety / Governance Assessment", "entry_kind": "aggregate", "purpose": "Provide the format-neutral context an agent needs to create, inspect and operate a governance or safety assessment record for a specific AI system: what was assessed, under which obligation regime, against which risks and safeguards, on what evidence, with what residual risk, and what was decided by whom.", "scope_statement": "This model describes one assessment record: a bounded, dated, signed judgement about the safety, risk and regulatory position of a named AI system version. It owns the assessment's own identity, scope, method, applicability determinations, risk and impact analysis, declared safeguards, evidence citations, residual-risk position, decision, conditions, record lifecycle and disclosure tiering. It carries references and subject-specific bindings to externally owned records (risk register items, evaluation runs, incident cases, certificates, dataset documentation) but never reproduces those records' lifecycles, execution semantics or audit trails. It is storage- and interface-neutral: JSON, YAML, Markdown, HTML, Git, MCP and MongoDB are projections of the same semantics.", "in_scope": [ "Assessment record identity, revision and mandate", "Binding to a specific assessed AI system version, configuration and component boundary", "Intended purpose, foreseeable misuse, deployment context and system classification profile", "Operator role and applicable regulatory, contractual and internal regime determination", "Risk-tier or category determination and its documented justification", "Applicability statement over normative requirements and selected safeguards", "AI-specific risk taxonomy tagging and stakeholder impact analysis", "Adversarial threat-surface and data-provenance findings for the assessed subject", "Declared human-oversight arrangement and capability-threshold safeguard tier", "Evidence citations with integrity, currency and sufficiency judgements", "Metric and acceptance-threshold declarations plus measurement-validity caveats", "Residual-risk position, decision, conditions and reassessment triggers", "Accountable ownership, sign-off and independence declarations", "Record lifecycle states, supersession provenance, retention and disclosure tiering", "Crosswalks asserting alignment to external frameworks with conflict notes" ], "out_of_scope": [ "The risk and opportunity register's own item lifecycle, scoring methodology, treatment workflow and closure states, owned by WM-KNW-015", "Full technical documentation of the AI system (architecture, training procedure, dataset inventories) which belongs to a separate AI system technical record", "Execution of evaluations, benchmarks or red-team runs; this model cites results and never owns harness configuration, run orchestration or scoring semantics", "Runtime guardrail, filter or policy-enforcement engines and their decision semantics", "Incident case management, triage, notification workflow and regulator correspondence", "Operational audit trails of control execution; only point-in-time assessor judgements are held here", "Conformity assessment procedures, notified-body activity, certification issue and CE marking, which are cited as external attestations only", "Organisation-level AI management system clauses (leadership, competence, internal audit programme, management review) which sit above a single assessment", "Dataset creation, labelling, consent capture and data-subject rights handling", "Model training, fine-tuning, deployment automation and release engineering", "Personal data processing records and DPIA execution, which are cited as separate assessments", "Legal advice, litigation position and regulatory enforcement outcomes" ], "boundary_notes": [ { "neighbor": "WM-KNW-015 risk and opportunity register", "distinction": "This model cites register items as risk evidence and may add assessment-scoped parameters (AI risk taxonomy code, trustworthiness characteristic, assessment-local severity view) on the binding. It must not carry register-item state, scoring method, treatment plans, register owner assignment or register review cadence.", "source_refs": [ "SRC-007", "SRC-001" ] }, { "neighbor": "AI system technical record (EU AI Act Annex IV technical documentation)", "distinction": "Annex IV documentation is a distinct, provider-maintained artefact describing the system itself. This model references it and records whether it exists and is adequate, not its content.", "source_refs": [ "SRC-003" ] }, { "neighbor": "AI evaluation run record and evaluation harness", "distinction": "Harnesses such as Inspect own task, solver, scorer and log semantics. This model stores the run reference, subject version, integrity digest and an adequacy judgement only.", "source_refs": [ "SRC-012" ] }, { "neighbor": "AI incident and hazard record", "distinction": "Incident definition, case management and authority notification are owned by the incident register and the applicable reporting regime. This model records which incidents were considered as inputs and what they changed in the assessment.", "source_refs": [ "SRC-010", "SRC-003" ] }, { "neighbor": "AI management system (ISO/IEC 42001 AIMS)", "distinction": "Organisation-level policy, resourcing, internal audit programme and management review belong to the management system. A single assessment instance is an output of that system, not the system itself.", "source_refs": [ "SRC-006" ] }, { "neighbor": "Conformity assessment body and certification record", "distinction": "Certificates, notified-body decisions and CE marking are external attestations. This model cites their identifiers and scope and must not assert conformance without cited evidence.", "source_refs": [ "SRC-003" ] }, { "neighbor": "WM-ACT-037 parent model", "distinction": "The registry declares WM-ACT-037 as parent. Generic assessment-activity scheduling, workflow and actor mechanics are expected to sit there; only AI-specific assessment content is specialised here. The parent's exact surface is unverified and is recorded as an open boundary.", "source_refs": [ "SRC-006" ] }, { "neighbor": "Runtime guardrail and policy-enforcement engine", "distinction": "A safeguard declared and judged here may be enforced by a runtime engine. Referencing that engine grants no ownership of its evaluation, enforcement or logging semantics.", "source_refs": [ "SRC-011", "SRC-005" ] } ] }, "sources": [ { "id": "SRC-001", "title": "AI Risk Management Framework (AI RMF 1.0) — AI RMF Core", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://airc.nist.gov/airmf-resources/airmf/5-sec-core/", "version_or_date": "AI RMF 1.0, published 26 January 2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T09:10:00Z", "relevance": "Defines the GOVERN, MAP, MEASURE and MANAGE functions and their categories, which anchor the assessment's applicability, analysis, measurement and treatment layers." }, { "id": "SRC-002", "title": "AI Risk Management Framework — AI Risks and Trustworthiness", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://airc.nist.gov/airmf-resources/airmf/3-sec-characteristics/", "version_or_date": "AI RMF 1.0, published 26 January 2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T09:12:00Z", "relevance": "Enumerates the seven trustworthiness characteristics used as the assessment's characteristic tagging vocabulary and harm framing." }, { "id": "SRC-003", "title": "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)", "organization": "European Union (Official Journal, EUR-Lex)", "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202401689", "version_or_date": "Adopted 13 June 2024; OJ L, 2024/1689, 12 July 2024", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T09:05:00Z", "relevance": "Normative source for operator roles, prohibited practices, high-risk classification and Annex III, risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and robustness, fundamental rights impact assessment, post-market monitoring and serious incident reporting." }, { "id": "SRC-004", "title": "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1)", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence", "version_or_date": "NIST AI 600-1, 26 July 2024", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T09:20:00Z", "relevance": "Supplies the twelve generative-AI risk categories (including CBRN information, confabulation, information integrity, information security and value chain) used for AI-specific risk taxonomy tagging." }, { "id": "SRC-005", "title": "Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2 E2025)", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://csrc.nist.gov/pubs/ai/100/2/e2025/final", "version_or_date": "NIST AI 100-2 E2025, March 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T09:35:00Z", "relevance": "Provides the attack-class vocabulary (evasion, poisoning, privacy, abuse, prompt injection), attacker goals, capability and knowledge assumptions, and lifecycle attack stages used in the threat-surface finding." }, { "id": "SRC-006", "title": "ISO/IEC 42001:2023 Information technology — Artificial intelligence — Management system", "organization": "International Organization for Standardization / International Electrotechnical Commission", "url": "https://www.iso.org/standard/42001", "version_or_date": "First edition, December 2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T09:15:00Z", "relevance": "Establishes the AI management system, the Annex A control objectives and controls, the Statement of Applicability concept and impact-assessment obligations that the applicability and control layers align to." }, { "id": "SRC-007", "title": "ISO/IEC 23894:2023 Information technology — Artificial intelligence — Guidance on risk management", "organization": "International Organization for Standardization / International Electrotechnical Commission", "url": "https://www.iso.org/standard/77304", "version_or_date": "First edition, February 2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T09:16:00Z", "relevance": "Adapts ISO 31000 risk management to AI, grounding the separation between the risk register (identification, analysis, evaluation, treatment) and an assessment that consumes it as evidence." }, { "id": "SRC-008", "title": "ISO/IEC 42005:2025 Information technology — Artificial intelligence — AI system impact assessment", "organization": "International Organization for Standardization / International Electrotechnical Commission", "url": "https://www.iso.org/standard/42005", "version_or_date": "First edition, May 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T09:18:00Z", "relevance": "Guidance on documenting AI system impact assessments across the lifecycle, including affected individuals and societies, intended use, and when to update the assessment." }, { "id": "SRC-009", "title": "General-Purpose AI Code of Practice", "organization": "European Commission, Directorate-General for Communications Networks, Content and Technology", "url": "https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai", "version_or_date": "Published 10 July 2025", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-29T09:25:00Z", "relevance": "Defines the Transparency, Copyright, and Safety and Security chapters, the Model Documentation Form and the systemic-risk practices that inform disclosure tiering and safeguards reporting for advanced models." }, { "id": "SRC-010", "title": "Defining AI incidents and related terms (OECD Artificial Intelligence Papers No. 16)", "organization": "Organisation for Economic Co-operation and Development (OECD)", "url": "https://www.oecd.org/en/publications/2024/05/defining-ai-incidents-and-related-terms_88d089ec.html", "version_or_date": "OECD AI Papers No. 16, May 2024", "source_type": "public-authority", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-29T09:40:00Z", "relevance": "Supplies interoperable definitions of AI incident, serious AI incident, AI hazard and serious AI hazard used for the operational-signal binding vocabulary." }, { "id": "SRC-011", "title": "Anthropic Responsible Scaling Policy", "organization": "Anthropic", "url": "https://www.anthropic.com/rsp", "version_or_date": "Version 3.4, effective 8 July 2026", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 3, "accessed_at": "2026-08-29T09:28:00Z", "relevance": "Working example of capability thresholds, tiered safeguard standards, capability assessments with elicitation caveats, and redacted risk and safeguards reporting to external reviewers." }, { "id": "SRC-012", "title": "Inspect: an open-source framework for large language model evaluations", "organization": "UK AI Security Institute", "url": "https://inspect.aisi.org.uk/", "version_or_date": "Current documentation, accessed 29 August 2026", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-29T09:32:00Z", "relevance": "Shows that evaluation semantics (datasets, solvers, scorers, tasks, sandboxes, logs) are owned by the harness, supporting the boundary that this model cites run references rather than owning evaluation execution." }, { "id": "SRC-013", "title": "OECD Framework for the Classification of AI Systems (OECD Digital Economy Papers No. 323)", "organization": "Organisation for Economic Co-operation and Development (OECD)", "url": "https://www.oecd.org/content/dam/oecd/en/publications/reports/2022/02/oecd-framework-for-the-classification-of-ai-systems_336a8b57/cb6d9eca-en.pdf", "version_or_date": "No. 323, February 2022, DOI 10.1787/cb6d9eca-en", "source_type": "classifier", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-29T09:45:00Z", "relevance": "Provides the five classification dimensions (People and Planet, Economic Context, Data and Input, AI Model, Task and Output) used for the system classification profile." } ], "structure": { "bundles": [ { "id": "bd-assessment-frame", "name": "Assessment Frame", "description": "What is being assessed, in which context, and what this particular assessment record is.", "rationale": "Every downstream determination is only interpretable against a fixed subject version, a declared intended purpose and an explicit assessment scope and method. ISO/IEC 42005 and AI Act Annex IV both require the assessed system and its intended purpose to be pinned before analysis.", "source_refs": [ "SRC-003", "SRC-008", "SRC-013" ], "layers": [ { "id": "ly-subject-and-context", "name": "Subject and Context", "description": "Binding to the assessed AI system version and the declared purpose, context and classification profile.", "source_refs": [ "SRC-003", "SRC-013", "SRC-001" ], "findings": [ { "id": "fd-subject-system-binding", "name": "Assessed subject binding", "description": "The identity of the exact AI system, model version, configuration and component boundary that this assessment judges. The binding must be reproducible so that a later reader can tell whether a given deployed artefact is covered.", "source_refs": [ "SRC-003", "SRC-011", "SRC-001" ], "questions": [ { "id": "q-subject-exact-version", "text": "Which exact AI system, model version and deployment configuration does this assessment bind to?", "kind": "identity", "answer_data": [ "Subject system identifier from the authoritative master system", "Model or build version designation", "Configuration or checkpoint reference" ] }, { "id": "q-subject-boundary-parts", "text": "Which components, upstream models and third-party services fall inside the assessed system boundary?", "kind": "composition", "answer_data": [ "Component inventory references", "Third-party model or API dependencies", "Explicitly excluded components" ] }, { "id": "q-subject-binding-origin", "text": "Which system of record issued the subject identifier and when was the binding captured?", "kind": "provenance", "answer_data": [ "Issuing system name", "Identifier scheme", "Binding observation timestamp" ] }, { "id": "q-subject-invalidating-change", "text": "What changes to the subject invalidate this binding and require a fresh assessment?", "kind": "constraint", "answer_data": [ "Change classes that break coverage", "Tolerance for fine-tuned derivatives", "Pointer to the reassessment trigger set" ] } ], "data_elements": [ { "id": "de-subject-identifier", "name": "Subject system identifier", "description": "Authoritative identifier of the assessed AI system or model.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-003" ] }, { "id": "de-subject-version", "name": "Subject version designation", "description": "Version, build or checkpoint label distinguishing the assessed artefact.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-011" ] }, { "id": "de-subject-component-ref", "name": "In-boundary component reference", "description": "Reference to a component, dataset or third-party service inside the assessed boundary.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "de-subject-binding-observed-at", "name": "Binding observation time", "description": "Time at which the subject binding was observed and recorded.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "The binding is pure reference and identifier data pointing at an externally owned AI system technical record; producing a separate document here would duplicate that record and create two competing descriptions of the same subject." }, { "id": "fd-purpose-and-classification", "name": "Intended purpose and system classification profile", "description": "The declared intended purpose, reasonably foreseeable misuse, deployment setting and a coded classification profile of the system along recognised classification dimensions.", "source_refs": [ "SRC-003", "SRC-013", "SRC-008" ], "questions": [ { "id": "q-purpose-declared-scope", "text": "What is the declared intended purpose of the system and which uses are explicitly excluded?", "kind": "definition", "answer_data": [ "Intended purpose statement", "Excluded or prohibited use list", "Reasonably foreseeable misuse scenarios" ] }, { "id": "q-classification-dimensions", "text": "How is the system profiled along the recognised classification dimensions of people and planet, economic context, data and input, model and task and output?", "kind": "classification", "answer_data": [ "Coded value per classification dimension", "Autonomy level code", "Output type and action space" ] }, { "id": "q-deployment-geography", "text": "In which jurisdictions, sectors and organisational or physical settings is the system deployed?", "kind": "spatial", "answer_data": [ "Jurisdiction codes", "Sector codes", "Deployment environment descriptor" ] }, { "id": "q-affected-parties-map", "text": "Which user groups, affected persons and non-user third parties interact with or are subject to the system?", "kind": "relationship", "answer_data": [ "User role list", "Affected population descriptors", "Non-user third parties in scope" ] } ], "data_elements": [ { "id": "de-intended-purpose", "name": "Intended purpose statement", "description": "Declared purpose for which the system is designed and supplied.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-003" ] }, { "id": "de-foreseeable-misuse", "name": "Foreseeable misuse scenario", "description": "A reasonably foreseeable misuse considered during assessment.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-classification-dimension-value", "name": "Classification dimension value", "description": "Coded value assigned on one classification dimension.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "de-deployment-jurisdiction", "name": "Deployment jurisdiction", "description": "Jurisdiction in which the system is placed on the market or put into service.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "This is a coded profile over controlled vocabularies plus short declarative statements; it is consumed as structured fields by tier determination and applicability logic rather than read as a document." } ] }, { "id": "ly-assessment-record-frame", "name": "Assessment Record Frame", "description": "The identity, revision, mandate, scope and method of the assessment itself.", "source_refs": [ "SRC-006", "SRC-008" ], "findings": [ { "id": "fd-assessment-identity", "name": "Assessment identity, revision and mandate", "description": "Identifiers, revision designation, temporal anchors and the authority under which the assessment was opened.", "source_refs": [ "SRC-006", "SRC-008", "SRC-003" ], "questions": [ { "id": "q-assessment-record-id", "text": "Which identifier uniquely designates this assessment record and its revision?", "kind": "identity", "answer_data": [ "Assessment identifier from the master system", "Revision designator", "Identifier scheme in use" ] }, { "id": "q-assessment-time-anchors", "text": "What are the evidence cut-off time and the record creation time for this assessment?", "kind": "temporal", "answer_data": [ "Evidence cut-off timestamp", "Record creation timestamp", "Assessment reference period" ] }, { "id": "q-assessment-revision-rule", "text": "How are assessment revisions numbered and which revision is authoritative right now?", "kind": "lifecycle", "answer_data": [ "Revision numbering rule", "Current authoritative revision", "Superseded revision references" ] }, { "id": "q-assessment-mandate-basis", "text": "Under whose mandate and on which basis was this assessment opened?", "kind": "authority", "answer_data": [ "Mandate basis code such as regulatory, contractual, policy or voluntary", "Commissioning body", "Authorising reference" ] } ], "data_elements": [ { "id": "de-assessment-identifier", "name": "Assessment identifier", "description": "Primary identifier of the assessment record.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "de-assessment-revision", "name": "Assessment revision designator", "description": "Revision or version label of this assessment record.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "de-evidence-cutoff-at", "name": "Evidence cut-off time", "description": "Point in time after which no further evidence was considered.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "de-mandate-basis", "name": "Mandate basis", "description": "Coded basis on which the assessment was commissioned.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "Identity, revision and temporal anchors are key fields that must be queryable and stable across every projection; wrapping them in an artefact would hide the primary key behind a document body." }, { "id": "fd-scope-and-method", "name": "Assessment scope, exclusions and method", "description": "What kind of assessment this is, what question it answers, what it deliberately excludes, and the method, criteria and sampling used to reach findings.", "source_refs": [ "SRC-008", "SRC-006", "SRC-001" ], "questions": [ { "id": "q-assessment-type-question", "text": "What assessment type is this and what specific question is it answering?", "kind": "definition", "answer_data": [ "Assessment type code such as impact assessment, safety case, conformity readiness or internal audit", "Assessment question statement", "Criteria set referenced" ] }, { "id": "q-scope-exclusions", "text": "Which parts of the system, lifecycle stage or use context are explicitly excluded from this assessment?", "kind": "constraint", "answer_data": [ "Excluded subsystems", "Excluded lifecycle stages", "Excluded use contexts with reasons" ] }, { "id": "q-method-and-sampling", "text": "Which method, criteria and sampling approach produced the findings?", "kind": "process", "answer_data": [ "Method description", "Sampling approach", "Criteria or control set references" ] }, { "id": "q-assurance-depth", "text": "What depth of assurance does this method support and what could it not establish?", "kind": "quality", "answer_data": [ "Assurance level statement", "Claims not supported by the method", "Known method limitations" ] } ], "data_elements": [ { "id": "de-assessment-type", "name": "Assessment type code", "description": "Coded type of assessment performed.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "de-scope-exclusion", "name": "Scope exclusion entry", "description": "A declared exclusion from assessment scope with justification.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-assurance-level", "name": "Assurance depth statement", "description": "Declared strength of assurance the method can support.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-001" ] } ], "artifacts": [ { "id": "art-scope-method-statement", "name": "Assessment scope and method statement", "description": "Narrative statement fixing the assessment question, boundary, criteria, method, sampling and assurance limits, referenced by every finding in the assessment.", "media_or_form": [ "narrative document", "structured record" ], "serial": false, "identity_strategy": "Master-system document identifier of the assessment, suffixed with the revision designator; fall back to a Dimension-minted ULID plus content digest.", "source_refs": [ "SRC-008", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bd-obligation-frame", "name": "Obligation and Applicability Frame", "description": "Which role the organisation holds, which regimes apply, which risk tier the system falls into, and which requirements therefore bind.", "rationale": "Obligations are role-dependent and tier-dependent. The AI Act assigns different duties to providers and deployers and requires documented justification when an Annex III system is claimed not to be high-risk; ISO/IEC 42001 requires a documented Statement of Applicability over its Annex A controls.", "source_refs": [ "SRC-003", "SRC-006" ], "layers": [ { "id": "ly-role-and-regime", "name": "Role and Regime", "description": "Operator role determination and the set of legal, contractual and internal regimes asserted to apply.", "source_refs": [ "SRC-003", "SRC-009" ], "findings": [ { "id": "fd-role-and-regime-applicability", "name": "Operator role and applicable regime set", "description": "Which role the assessed organisation holds for this system in each market, which regimes apply on what territorial basis, and which exemptions are relied on.", "source_refs": [ "SRC-003", "SRC-009", "SRC-006" ], "questions": [ { "id": "q-operator-role-per-market", "text": "Which operator role does the assessed organisation hold for this system in each market it serves?", "kind": "classification", "answer_data": [ "Role code per market such as provider, deployer, importer, distributor or authorised representative", "Market or jurisdiction key", "Role change triggers such as substantial modification or rebranding" ] }, { "id": "q-regime-applicability-basis", "text": "Which legal, regulatory, contractual and internal regimes are asserted to apply and on what territorial basis?", "kind": "authority", "answer_data": [ "Regime references with version", "Territorial applicability basis", "Effective and transition dates per regime" ] }, { "id": "q-value-chain-dependencies", "text": "Which other operators in the value chain hold obligations that this assessment relies on?", "kind": "relationship", "answer_data": [ "Upstream and downstream operator references", "Obligations relied upon", "Contractual instrument references" ] }, { "id": "q-claimed-exemptions", "text": "Which exemptions, derogations or research exclusions are claimed and how is each justified?", "kind": "exception", "answer_data": [ "Claimed exemption code", "Justification text", "Evidence reference supporting the claim" ] } ], "data_elements": [ { "id": "de-operator-role-code", "name": "Operator role code", "description": "Coded operator role held for the assessed system in a given market.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003" ] }, { "id": "de-applicable-regime-ref", "name": "Applicable regime reference", "description": "Reference to a legal, regulatory, contractual or internal regime asserted to apply.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003" ] }, { "id": "de-claimed-exemption", "name": "Claimed exemption", "description": "An exemption or derogation relied on, with justification.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "Role and regime applicability is a set of coded determinations with justification strings that must drive automated obligation selection; keeping it inline preserves machine evaluability and avoids a second narrative source of truth." } ] }, { "id": "ly-tier-and-obligations", "name": "Risk Tier and Obligation Set", "description": "The risk-tier determination and the resulting applicability statement over normative requirements.", "source_refs": [ "SRC-003", "SRC-006", "SRC-001" ], "findings": [ { "id": "fd-risk-tier-determination", "name": "Risk tier or category determination", "description": "The classification of the system into a risk tier or category under each applicable regime, with the reasoning and evidence that supports it, including any documented not-high-risk derogation.", "source_refs": [ "SRC-003", "SRC-013", "SRC-009" ], "questions": [ { "id": "q-tier-per-regime", "text": "Which risk tier or category does the system fall into under each applicable regime?", "kind": "classification", "answer_data": [ "Tier code per regime", "Triggering annex, list entry or threshold", "Systemic-risk designation for general-purpose models" ] }, { "id": "q-tier-justification-evidence", "text": "What reasoning and evidence support the tier determination, including any claim that a listed system is not high-risk?", "kind": "evidence", "answer_data": [ "Justification narrative", "Evidence references", "Derogation condition relied upon" ] }, { "id": "q-tier-decision-authority", "text": "Who determined the tier and when must that determination be revisited?", "kind": "decision", "answer_data": [ "Determining role and person reference", "Determination timestamp", "Review-by date or trigger" ] }, { "id": "q-tier-cross-regime-mapping", "text": "How does the tier under one regime map onto tiers or thresholds under the others?", "kind": "interoperability", "answer_data": [ "Cross-regime mapping table", "Mapping confidence", "Unmapped or conflicting cases" ] } ], "data_elements": [ { "id": "de-risk-tier-code", "name": "Risk tier code", "description": "Coded risk tier or category assigned under a specific regime.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003" ] }, { "id": "de-tier-trigger-ref", "name": "Tier trigger reference", "description": "The annex entry, use-case listing or capability threshold that triggered the tier.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-tier-determined-at", "name": "Tier determination time", "description": "Event time at which the tier determination was made.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-003" ] } ], "artifacts": [ { "id": "art-risk-tier-determination-record", "name": "Risk tier determination record", "description": "Documented determination of risk tier per regime, including the assessment justifying any claim that a listed system is not high-risk, kept available to authorities on request.", "media_or_form": [ "structured record", "narrative document" ], "serial": false, "identity_strategy": "Master-system identifier of the determination; otherwise the assessment identifier plus a determination sequence key, with a content digest.", "source_refs": [ "SRC-003" ] } ], "inline_only_rationale": null }, { "id": "fd-obligation-applicability", "name": "Requirement applicability statement", "description": "The enumerated normative requirements that apply given role and tier, those excluded with justification, and the party responsible for each.", "source_refs": [ "SRC-006", "SRC-003", "SRC-001" ], "questions": [ { "id": "q-requirements-in-force", "text": "Which individual normative requirements apply to this system given its role and tier?", "kind": "requirement", "answer_data": [ "Requirement identifiers with source version", "Applicability status per requirement", "Mapping to the risk or purpose that makes it relevant" ] }, { "id": "q-requirement-exclusion-basis", "text": "Which requirements are excluded and what justification is recorded for each exclusion?", "kind": "composition", "answer_data": [ "Excluded requirement identifiers", "Exclusion justification", "Approver of the exclusion" ] }, { "id": "q-requirement-responsibility", "text": "Which party is responsible for satisfying each applicable requirement?", "kind": "ownership", "answer_data": [ "Responsible party reference", "Internal owning function", "Contractual flow-down reference" ] }, { "id": "q-requirement-deduplication", "text": "How are overlapping requirements from different regimes deduplicated without losing traceability to each source?", "kind": "interoperability", "answer_data": [ "Canonical requirement key", "Source requirement references merged into it", "Residual differences preserved" ] } ], "data_elements": [ { "id": "de-requirement-ref", "name": "Requirement reference", "description": "Identifier of a normative requirement together with the version of its source.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "de-applicability-status", "name": "Applicability status", "description": "Whether a requirement is applicable, excluded or deferred.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "de-responsible-party-ref", "name": "Responsible party reference", "description": "Reference to the party accountable for satisfying a requirement.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [ { "id": "art-obligation-applicability-statement", "name": "Requirement applicability statement", "description": "Enumerated statement of applicable and excluded requirements with justification and responsibility, equivalent in role to a Statement of Applicability.", "media_or_form": [ "tabular matrix", "structured record" ], "serial": false, "identity_strategy": "Assessment identifier plus revision designator; content digest recorded so that exclusions cannot be altered silently.", "source_refs": [ "SRC-006", "SRC-003" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bd-risk-and-impact", "name": "Risk, Impact and Threat Analysis", "description": "AI-specific risk tagging, stakeholder impact analysis, the binding to externally owned risk items, and the adversarial and data-provenance findings.", "rationale": "AI risk analysis needs a domain taxonomy (generative-AI risks, trustworthiness characteristics), an impact view covering affected persons and society, and a security view of adversarial attack classes. The register of risks themselves is owned by a sibling model and only referenced here.", "source_refs": [ "SRC-004", "SRC-002", "SRC-005", "SRC-008" ], "layers": [ { "id": "ly-harm-and-impact", "name": "Harm and Impact", "description": "Taxonomy assignment, stakeholder impact characterisation and risk-evidence binding.", "source_refs": [ "SRC-004", "SRC-008", "SRC-007" ], "findings": [ { "id": "fd-risk-taxonomy-assignment", "name": "AI risk taxonomy assignment", "description": "Assignment of AI-specific risk category codes and trustworthiness characteristics to the assessed subject, including entries explicitly considered and ruled out.", "source_refs": [ "SRC-004", "SRC-002", "SRC-001" ], "questions": [ { "id": "q-risk-categories-implicated", "text": "Which AI-specific risk categories and trustworthiness characteristics are implicated by this system?", "kind": "classification", "answer_data": [ "Risk category codes such as confabulation, information integrity or CBRN information", "Trustworthiness characteristic codes", "Rationale per assignment" ] }, { "id": "q-taxonomy-scheme-version", "text": "Which taxonomy scheme and version supplies the code list used for each tag?", "kind": "definition", "answer_data": [ "Scheme identifier", "Scheme version or edition", "Local extension codes and their definitions" ] }, { "id": "q-tag-to-register-mapping", "text": "How does each risk tag map onto the referenced risk register items?", "kind": "relationship", "answer_data": [ "Tag to register item mapping", "Many-to-many resolution rule", "Unmapped tags flagged for register creation" ] }, { "id": "q-ruled-out-categories", "text": "Which taxonomy entries were considered and explicitly ruled out, and on what basis?", "kind": "quality", "answer_data": [ "Ruled-out category codes", "Basis for exclusion", "Evidence reference or reasoning" ] } ], "data_elements": [ { "id": "de-risk-category-code", "name": "AI risk category code", "description": "Coded AI-specific risk category assigned to the subject.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-004" ] }, { "id": "de-trust-characteristic-code", "name": "Trustworthiness characteristic code", "description": "Coded trustworthiness characteristic implicated by the assigned risk.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "de-taxonomy-scheme-version", "name": "Taxonomy scheme version", "description": "Version of the taxonomy scheme supplying the code list.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-004" ] }, { "id": "de-ruled-out-entry", "name": "Ruled-out taxonomy entry", "description": "A taxonomy entry considered and excluded, with basis.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] } ], "artifacts": [], "inline_only_rationale": "Tagging is controlled-vocabulary code assignment intended for filtering, aggregation and coverage checks; expressing it as an artefact would obstruct the machine reasoning it exists to enable." }, { "id": "fd-stakeholder-impact-analysis", "name": "Affected stakeholder and impact analysis", "description": "Identification of individuals, groups, communities and environmental receptors that could be affected, with characterised severity, breadth and reversibility, and the record of stakeholder consultation.", "source_refs": [ "SRC-008", "SRC-003", "SRC-002" ], "questions": [ { "id": "q-affected-receptors", "text": "Which individuals, groups, communities and environmental receptors could be affected, including people who never interact with the system?", "kind": "relationship", "answer_data": [ "Affected group descriptors", "Vulnerable or protected group flags", "Non-user and environmental receptors" ] }, { "id": "q-impact-characterisation", "text": "How are severity, likelihood, reversibility and breadth of impact characterised for each affected group?", "kind": "measurement", "answer_data": [ "Severity scale value", "Reversibility classification", "Breadth or number of affected persons estimate" ] }, { "id": "q-stakeholder-consultation", "text": "Which stakeholders were consulted and how was their input incorporated or rejected?", "kind": "process", "answer_data": [ "Consultation method and dates", "Input summary", "Disposition of each input" ] }, { "id": "q-personal-data-linkage", "text": "What personal data or special-category processing does the system entail and which separate assessment covers it?", "kind": "privacy", "answer_data": [ "Personal data categories", "Special-category processing flag", "Reference to the data protection impact assessment" ] } ], "data_elements": [ { "id": "de-affected-group", "name": "Affected group descriptor", "description": "A group of persons or receptors identified as potentially affected.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "de-impact-severity", "name": "Impact severity value", "description": "Characterised severity of impact on a given affected group.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "de-dpia-reference", "name": "Data protection assessment reference", "description": "Reference to the separate personal-data impact assessment where one exists.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [ { "id": "art-impact-assessment-record", "name": "AI system impact assessment record", "description": "Documented analysis of intended and unintended impacts on individuals, groups and society across the lifecycle, including consultation and, where required, the fundamental rights impact assessment.", "media_or_form": [ "narrative document", "structured record" ], "serial": true, "identity_strategy": "Master-system impact assessment identifier; otherwise assessment identifier plus impact-assessment sequence key, with content digest.", "source_refs": [ "SRC-008", "SRC-003" ] } ], "inline_only_rationale": null }, { "id": "fd-risk-register-binding", "name": "Risk and opportunity register binding", "description": "The citation of externally owned risk and opportunity register items as evidence, with the assessment-scoped parameters that may legitimately be carried on the binding.", "source_refs": [ "SRC-007", "SRC-001", "SRC-006" ], "questions": [ { "id": "q-cited-register-items", "text": "Which risk and opportunity register items does this assessment cite as evidence?", "kind": "relationship", "answer_data": [ "Register item identifiers", "Citation purpose per item", "Register instance or namespace reference" ] }, { "id": "q-register-item-revision", "text": "Which revision of each cited register item is bound so the citation stays reproducible?", "kind": "identity", "answer_data": [ "Item revision or version key", "Content digest where available", "Resolution rule when the item has moved on" ] }, { "id": "q-binding-local-parameters", "text": "Which assessment-scoped parameters may be recorded on the binding without duplicating register state?", "kind": "constraint", "answer_data": [ "Permitted local parameter list", "Explicitly forbidden fields such as register status or treatment plan", "Validation rule enforcing the restriction" ] }, { "id": "q-register-read-time", "text": "When was each register item read and which register version was current at that moment?", "kind": "provenance", "answer_data": [ "Register read timestamp", "Register version or snapshot key", "Reader identity or service reference" ] } ], "data_elements": [ { "id": "de-register-item-ref", "name": "Register item reference", "description": "Reference to a risk or opportunity item in the referenced register model.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-007" ] }, { "id": "de-register-item-revision", "name": "Register item revision key", "description": "Revision identifier of the cited register item at citation time.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "de-register-read-at", "name": "Register read time", "description": "Observation time at which the register item was read for this assessment.", "value_kind": "timestamp", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-007" ] } ], "artifacts": [], "inline_only_rationale": "The register items themselves are owned by WM-KNW-015; this finding may hold only the reference, revision key, read time and assessment-scoped parameters. Emitting an artefact would materialise a second copy of register content and violate the reference-only ownership contract." } ] }, { "id": "ly-threat-and-data", "name": "Threat and Data Analysis", "description": "Adversarial attack surface and data-provenance findings specific to the assessed subject.", "source_refs": [ "SRC-005", "SRC-003", "SRC-009" ], "findings": [ { "id": "fd-adversarial-threat-surface", "name": "Adversarial threat surface", "description": "Credible adversarial attack classes against the system's training and inference stages, the trust boundaries and untrusted input channels, and the attacker assumptions adopted.", "source_refs": [ "SRC-005", "SRC-002", "SRC-011" ], "questions": [ { "id": "q-attack-classes-credible", "text": "Which adversarial attack classes are credible against this system's learning and inference stages?", "kind": "security", "answer_data": [ "Attack class codes such as evasion, poisoning, privacy extraction, abuse and prompt injection", "Lifecycle stage targeted", "Credibility rating with reasoning" ] }, { "id": "q-trust-boundaries-surfaces", "text": "Which trust boundaries, untrusted input channels and tool or agent surfaces exist in the deployment?", "kind": "composition", "answer_data": [ "Trust boundary inventory", "Untrusted content ingestion points", "Tool, plugin and autonomous action surfaces" ] }, { "id": "q-attacker-assumptions", "text": "What attacker capability, knowledge and access assumptions were adopted for the analysis?", "kind": "classification", "answer_data": [ "Attacker capability level", "Knowledge assumption such as white-box or black-box", "Access and positioning assumptions" ] }, { "id": "q-security-test-coverage", "text": "Which security tests or red-team exercises probed each identified attack class?", "kind": "validation", "answer_data": [ "Test or exercise references", "Attack classes covered and uncovered", "Date and subject version tested" ] } ], "data_elements": [ { "id": "de-attack-class-code", "name": "Attack class code", "description": "Coded adversarial attack class considered credible for the subject.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005" ] }, { "id": "de-trust-boundary-entry", "name": "Trust boundary entry", "description": "A declared trust boundary or untrusted input channel.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005" ] }, { "id": "de-attacker-assumption", "name": "Attacker assumption", "description": "Assumed attacker capability, knowledge or access level.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005" ] } ], "artifacts": [ { "id": "art-threat-model-record", "name": "Subject threat model record", "description": "Structured threat model for the assessed subject covering attack classes, trust boundaries, attacker assumptions and coverage of security testing.", "media_or_form": [ "structured record", "diagrammatic model" ], "serial": true, "identity_strategy": "Master-system threat model identifier where the security function maintains one; otherwise assessment identifier plus threat model sequence key and content digest.", "source_refs": [ "SRC-005" ] } ], "inline_only_rationale": null }, { "id": "fd-data-provenance-risk", "name": "Data and provenance risk finding", "description": "Assessment findings on the origin, licensing, quality, representativeness and restrictions of training, validation and test data, referencing dataset documentation held elsewhere.", "source_refs": [ "SRC-003", "SRC-009", "SRC-004" ], "questions": [ { "id": "q-data-origin-basis", "text": "What is the origin, licensing status and collection basis of the training, validation and test data?", "kind": "provenance", "answer_data": [ "Data source categories", "Licence or rights basis per source", "Reference to the authoritative dataset documentation" ] }, { "id": "q-data-quality-properties", "text": "Which data quality, representativeness and bias properties were examined against the intended purpose?", "kind": "quality", "answer_data": [ "Quality dimensions examined", "Representativeness findings for target populations", "Identified bias sources" ] }, { "id": "q-data-use-restrictions", "text": "Which data-related restrictions bind the system's permitted use?", "kind": "constraint", "answer_data": [ "Copyright and text-and-data-mining reservations", "Consent or contractual limits", "Export or localisation restrictions" ] }, { "id": "q-data-doc-retention-owner", "text": "Where is the authoritative dataset record held and who retains it?", "kind": "ownership", "answer_data": [ "Owning system or team", "Dataset record reference", "Retention responsibility statement" ] } ], "data_elements": [ { "id": "de-data-source-category", "name": "Data source category", "description": "Category of data source used for training, validation or testing.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-data-rights-basis", "name": "Data rights basis", "description": "Licence, consent or other rights basis asserted for a data source.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "de-dataset-record-ref", "name": "Dataset documentation reference", "description": "Reference to the externally owned dataset documentation.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [ { "id": "art-data-governance-assessment-note", "name": "Data governance assessment note", "description": "Assessment-side note recording findings and open questions about data provenance, quality, representativeness and use restrictions, pointing to the dataset documentation rather than restating it.", "media_or_form": [ "narrative document", "structured record" ], "serial": false, "identity_strategy": "Assessment identifier plus revision designator and a fixed note key, with content digest.", "source_refs": [ "SRC-003", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bd-safeguards-and-evidence", "name": "Safeguards and Evidence", "description": "Declared safeguards, human oversight, capability-threshold tiering, effectiveness judgements, and the evidence base with its metrics and validity limits.", "rationale": "An assessment is only defensible if the safeguards it credits are enumerated, if oversight is specified, and if the evidence cited is identified, current and honestly qualified. Capability-threshold tiering is the practice used by frontier developers and required for advanced models under the general-purpose AI regime.", "source_refs": [ "SRC-006", "SRC-003", "SRC-011", "SRC-012" ], "layers": [ { "id": "ly-control-declaration", "name": "Safeguard Declaration", "description": "The safeguards selected, the human oversight arrangement and the capability-threshold safeguard tier.", "source_refs": [ "SRC-006", "SRC-003", "SRC-011" ], "findings": [ { "id": "fd-control-applicability", "name": "Safeguard selection and applicability", "description": "The safeguards and controls selected to address each applicable requirement and risk, how they are layered across lifecycle stages, who owns them, and which are declared but not yet implemented.", "source_refs": [ "SRC-006", "SRC-001", "SRC-003" ], "questions": [ { "id": "q-safeguards-selected", "text": "Which safeguards are selected to address each applicable requirement and identified risk?", "kind": "requirement", "answer_data": [ "Safeguard identifiers", "Requirement and risk each safeguard addresses", "Source control catalogue and version" ] }, { "id": "q-safeguard-layering", "text": "How are safeguards layered across design, training, deployment and operational stages?", "kind": "composition", "answer_data": [ "Lifecycle stage per safeguard", "Defence-in-depth grouping", "Single points of failure identified" ] }, { "id": "q-safeguard-owner", "text": "Which organisational unit owns each declared safeguard?", "kind": "ownership", "answer_data": [ "Owning unit reference", "Accountable role", "Third-party operated safeguards flagged" ] }, { "id": "q-safeguard-implementation-state", "text": "Which safeguards are declared but not yet implemented and by when are they due?", "kind": "state", "answer_data": [ "Implementation status code", "Target implementation date", "Interim compensating measure" ] } ], "data_elements": [ { "id": "de-safeguard-ref", "name": "Safeguard reference", "description": "Identifier of a selected safeguard or control from a named catalogue.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "de-safeguard-stage", "name": "Safeguard lifecycle stage", "description": "Lifecycle stage at which the safeguard operates.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "de-safeguard-status", "name": "Safeguard implementation status", "description": "Declared implementation status of the safeguard at assessment cut-off.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-006" ] } ], "artifacts": [ { "id": "art-control-applicability-register", "name": "Safeguard applicability register", "description": "Enumerated register of selected safeguards mapped to requirements and risks, with owner, lifecycle stage and implementation status at assessment cut-off.", "media_or_form": [ "tabular matrix", "structured record" ], "serial": false, "identity_strategy": "Assessment identifier plus revision designator; digest recorded so that credited safeguards cannot change without a new revision.", "source_refs": [ "SRC-006", "SRC-001" ] } ], "inline_only_rationale": null }, { "id": "fd-human-oversight-design", "name": "Human oversight arrangement", "description": "The oversight measures built into the system and those the deployer must add, the overseer's authority to intervene, and the competence and conditions effective oversight requires.", "source_refs": [ "SRC-003", "SRC-002", "SRC-001" ], "questions": [ { "id": "q-oversight-measures-split", "text": "What oversight measures are built into the system and which measures must the deployer add?", "kind": "process", "answer_data": [ "Built-in oversight measures", "Deployer-side measures to be implemented", "Interface and instruction references" ] }, { "id": "q-overseer-authority", "text": "Which decisions can a human overseer override, halt or escalate, and under what authority?", "kind": "authority", "answer_data": [ "Override and stop capabilities", "Escalation path", "Authority basis and limits" ] }, { "id": "q-oversight-competence", "text": "What competence, training, tooling and time budget does effective oversight require?", "kind": "requirement", "answer_data": [ "Required competence profile", "Training and tooling provided", "Realistic time per decision" ] }, { "id": "q-automation-bias-counter", "text": "How is automation bias detected and counteracted in the oversight arrangement?", "kind": "quality", "answer_data": [ "Automation bias countermeasures", "Monitoring indicators for over-reliance", "Evidence that overseers do intervene" ] } ], "data_elements": [ { "id": "de-oversight-measure", "name": "Oversight measure", "description": "A specific human oversight measure and the party implementing it.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003" ] }, { "id": "de-override-capability", "name": "Override capability descriptor", "description": "Description of the overseer's ability to intervene, override or stop the system.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-overseer-competence", "name": "Overseer competence requirement", "description": "Competence, training or tooling required for effective oversight.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [ { "id": "art-human-oversight-specification", "name": "Human oversight specification", "description": "Specification of built-in and deployer-side oversight measures, override authority, competence requirements and automation-bias countermeasures for the assessed subject.", "media_or_form": [ "narrative document", "structured record" ], "serial": false, "identity_strategy": "Master-system specification identifier where one exists; otherwise assessment identifier plus a fixed oversight key and content digest.", "source_refs": [ "SRC-003" ] } ], "inline_only_rationale": null }, { "id": "fd-capability-threshold-tiering", "name": "Capability threshold and safeguard tier", "description": "Whether the model approaches or crosses declared capability thresholds, which safeguard tier is consequently required, which is in force, and what elicitation effort backs a not-crossed claim.", "source_refs": [ "SRC-011", "SRC-009", "SRC-004" ], "questions": [ { "id": "q-threshold-proximity", "text": "Which declared capability thresholds does the model approach or cross?", "kind": "measurement", "answer_data": [ "Threshold identifiers and definitions", "Measured proximity or crossing determination", "Capability domains assessed such as autonomy or uplift" ] }, { "id": "q-safeguard-tier-state", "text": "Which safeguard tier is required by the determination and which tier is currently in force?", "kind": "state", "answer_data": [ "Required tier code", "In-force tier code", "Gap and interim measures where they differ" ] }, { "id": "q-threshold-reassessment-event", "text": "What triggers a capability reassessment ahead of the scheduled interval?", "kind": "event", "answer_data": [ "Trigger event types such as effective compute increase or new elicitation result", "Notification path", "Maximum permitted delay" ] }, { "id": "q-elicitation-sufficiency", "text": "What elicitation effort backs a claim that a threshold is not crossed?", "kind": "evidence", "answer_data": [ "Elicitation methods and budget", "Known elicitation gaps", "Conservatism margin applied" ] } ], "data_elements": [ { "id": "de-capability-threshold-ref", "name": "Capability threshold reference", "description": "Reference to a declared capability threshold in the governing safety framework.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "de-required-safeguard-tier", "name": "Required safeguard tier", "description": "Safeguard tier required by the capability determination.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "de-elicitation-gap-note", "name": "Elicitation gap note", "description": "Known limitation in capability elicitation affecting the determination.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011" ] } ], "artifacts": [ { "id": "art-safeguards-and-capability-report", "name": "Capability and safeguards report", "description": "Periodic report stating capability determinations against thresholds, the safeguard tier in force, elicitation limitations and, where applicable, the model report supplied to authorities or external reviewers.", "media_or_form": [ "narrative document", "structured record", "redacted release" ], "serial": true, "identity_strategy": "Master-system report identifier; otherwise subject identifier plus report sequence key and content digest, with the redacted variant digest recorded separately.", "source_refs": [ "SRC-011", "SRC-009" ] } ], "inline_only_rationale": null } ] }, { "id": "ly-control-assessment", "name": "Effectiveness and Residual Risk", "description": "Point-in-time judgement of safeguard effectiveness and the resulting residual risk position.", "source_refs": [ "SRC-001", "SRC-007", "SRC-006" ], "findings": [ { "id": "fd-effectiveness-and-residual-risk", "name": "Safeguard effectiveness judgement and residual risk position", "description": "The assessor's point-in-time judgement of whether each credited safeguard is effective, the residual risk that remains per category, and the deficiencies accepted as open.", "source_refs": [ "SRC-001", "SRC-007", "SRC-006" ], "questions": [ { "id": "q-effectiveness-basis", "text": "On what basis is each credited safeguard judged effective, partially effective or ineffective?", "kind": "validation", "answer_data": [ "Effectiveness rating per safeguard", "Evidence reference supporting the rating", "Test or inspection method used" ] }, { "id": "q-residual-risk-level", "text": "What residual risk remains per risk category after the assessed safeguards?", "kind": "measurement", "answer_data": [ "Residual risk level per category", "Scale definition and version", "Comparison against the pre-safeguard position" ] }, { "id": "q-judgement-as-of-time", "text": "As of which point in time does the effectiveness judgement hold?", "kind": "temporal", "answer_data": [ "Judgement as-of timestamp", "Observation or recording timestamp", "Validity window" ] }, { "id": "q-accepted-open-deficiency", "text": "Which deficiencies are left open, by whose acceptance, and under what compensating measure?", "kind": "exception", "answer_data": [ "Open deficiency descriptions", "Accepting role and authority", "Compensating measure and expiry" ] } ], "data_elements": [ { "id": "de-effectiveness-rating", "name": "Safeguard effectiveness rating", "description": "Rating of a credited safeguard's effectiveness at the judgement time.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "de-residual-risk-level", "name": "Residual risk level", "description": "Residual risk level recorded for a risk category after safeguards.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-007" ] }, { "id": "de-judgement-as-of", "name": "Judgement as-of time", "description": "Event time to which the effectiveness and residual risk judgement applies.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-007" ] }, { "id": "de-open-deficiency", "name": "Open deficiency entry", "description": "A deficiency left open at assessment close with its acceptance and compensating measure.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [ { "id": "art-residual-risk-statement", "name": "Residual risk and deficiency statement", "description": "Statement of safeguard effectiveness judgements, residual risk per category and open deficiencies with compensating measures, as at the assessment cut-off.", "media_or_form": [ "structured record", "narrative document" ], "serial": false, "identity_strategy": "Assessment identifier plus revision designator; content digest recorded so the accepted position is fixed at sign-off.", "source_refs": [ "SRC-007", "SRC-001" ] } ], "inline_only_rationale": null } ] }, { "id": "ly-evaluation-evidence", "name": "Evaluation Evidence", "description": "Citations to evaluation results, the metrics and thresholds they are read against, and the validity limits of those measurements.", "source_refs": [ "SRC-012", "SRC-003", "SRC-004" ], "findings": [ { "id": "fd-evaluation-evidence-reference", "name": "Evaluation evidence citation", "description": "The set of evaluation runs, benchmarks, audits and red-team exercises cited as evidence, each identified, integrity-checked, attributed and judged for sufficiency and currency.", "source_refs": [ "SRC-012", "SRC-011", "SRC-001" ], "questions": [ { "id": "q-cited-evaluations", "text": "Which evaluation runs, benchmarks, audits and red-team exercises are cited as evidence?", "kind": "evidence", "answer_data": [ "Evidence item references", "Evidence type per item", "Claim each item supports" ] }, { "id": "q-evidence-integrity", "text": "How is each cited evidence item identified and integrity-checked?", "kind": "identity", "answer_data": [ "Evidence identifier and scheme", "Content digest or signature", "Storage location reference" ] }, { "id": "q-evidence-execution-attribution", "text": "Who executed each evaluation, against which subject version, and under which harness configuration?", "kind": "provenance", "answer_data": [ "Executing party reference", "Subject version evaluated", "Harness and configuration reference" ] }, { "id": "q-evidence-sufficiency", "text": "Is the cited evidence sufficient and current for the claim it is used to support?", "kind": "quality", "answer_data": [ "Sufficiency judgement", "Currency judgement against the subject version", "Gaps requiring further evidence" ] } ], "data_elements": [ { "id": "de-evidence-item-ref", "name": "Evidence item reference", "description": "Reference to an externally owned evaluation, audit or exercise record.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-012" ] }, { "id": "de-evidence-digest", "name": "Evidence content digest", "description": "Digest or signature fixing the cited evidence content.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "de-evidence-subject-version", "name": "Evaluated subject version", "description": "Subject version against which the cited evidence was produced.", "value_kind": "text", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-011" ] }, { "id": "de-evidence-sufficiency-judgement", "name": "Evidence sufficiency judgement", "description": "Assessor judgement on whether the evidence supports the claim.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001" ] } ], "artifacts": [ { "id": "art-evidence-manifest", "name": "Evaluation evidence manifest", "description": "Manifest listing every cited evidence item with identifier, digest, executing party, evaluated subject version and sufficiency judgement; it cites results and never contains harness or run semantics.", "media_or_form": [ "manifest", "structured record" ], "serial": true, "identity_strategy": "Assessment identifier plus revision designator and manifest sequence key; each entry keyed by the evidence system's own identifier where one exists.", "source_refs": [ "SRC-012", "SRC-001" ] } ], "inline_only_rationale": null }, { "id": "fd-metric-and-threshold", "name": "Metrics and acceptance thresholds", "description": "The metrics that express accuracy, robustness, safety and fairness for this system, the acceptance thresholds set for them, the conditions under which those thresholds hold, and current measured values.", "source_refs": [ "SRC-003", "SRC-001", "SRC-002" ], "questions": [ { "id": "q-metric-definitions", "text": "Which metrics and units express accuracy, robustness, safety and fairness for this system?", "kind": "measurement", "answer_data": [ "Metric identifiers and definitions", "Units and scales", "Metric version or specification reference" ] }, { "id": "q-threshold-and-setter", "text": "What acceptance threshold applies to each metric and who set it?", "kind": "requirement", "answer_data": [ "Threshold value per metric", "Setting authority and date", "Basis for the chosen level" ] }, { "id": "q-threshold-conditions", "text": "Under which operating conditions and populations do the declared thresholds hold?", "kind": "constraint", "answer_data": [ "Operating condition envelope", "Population or subgroup scope", "Conditions where the threshold is not asserted" ] }, { "id": "q-current-metric-state", "text": "What is the current measured value against each threshold and is it passing?", "kind": "state", "answer_data": [ "Measured value", "Pass or fail status", "Measurement timestamp and evidence reference" ] } ], "data_elements": [ { "id": "de-metric-ref", "name": "Metric reference", "description": "Identifier and definition reference of a declared metric.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003" ] }, { "id": "de-threshold-value", "name": "Acceptance threshold value", "description": "Threshold value the metric must meet.", "value_kind": "quantity", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-measured-value", "name": "Measured metric value", "description": "Most recent measured value for the metric within this assessment.", "value_kind": "quantity", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "de-threshold-condition", "name": "Threshold applicability condition", "description": "Operating condition or population under which the threshold is asserted.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] } ], "artifacts": [], "inline_only_rationale": "Metrics, thresholds and measured values are numeric fields that must be comparable across revisions and queryable for pass or fail state; the measurement results themselves live in the externally owned evaluation records this finding points at." }, { "id": "fd-measurement-validity", "name": "Measurement validity and limitations", "description": "Honest qualification of the evidence base: construct validity of each metric relative to the harm it stands for, risks acknowledged as unmeasurable, contamination and distribution-shift caveats, and staleness intervals.", "source_refs": [ "SRC-004", "SRC-011", "SRC-001" ], "questions": [ { "id": "q-construct-validity", "text": "What is the construct validity of each metric relative to the harm it is taken to represent?", "kind": "quality", "answer_data": [ "Construct validity assessment per metric", "Known proxy weaknesses", "Alternative measures considered" ] }, { "id": "q-unmeasurable-risks", "text": "Which identified risks are acknowledged as not measurable with the available methods?", "kind": "exception", "answer_data": [ "Unmeasurable risk list", "Reason measurement is unavailable", "Qualitative treatment applied instead" ] }, { "id": "q-result-caveats", "text": "Which contamination, elicitation-gap or distribution-shift caveats apply to the cited results?", "kind": "constraint", "answer_data": [ "Benchmark contamination indicators", "Elicitation gap statements", "Distribution shift between test and deployment" ] }, { "id": "q-evidence-staleness", "text": "How quickly do the cited results go stale and what revalidation interval applies?", "kind": "temporal", "answer_data": [ "Staleness rationale", "Revalidation interval", "Conditions that force early revalidation" ] } ], "data_elements": [ { "id": "de-validity-caveat", "name": "Validity caveat", "description": "A recorded limitation affecting interpretation of cited measurements.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "de-unmeasurable-risk-ref", "name": "Unmeasurable risk reference", "description": "Reference to a risk that current methods cannot measure.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "de-revalidation-interval", "name": "Revalidation interval", "description": "Interval after which cited evidence must be refreshed.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] } ], "artifacts": [ { "id": "art-measurement-limitations-note", "name": "Measurement limitations note", "description": "Written qualification of what the evidence base can and cannot establish, covering construct validity, unmeasurable risks, contamination and staleness.", "media_or_form": [ "narrative document" ], "serial": false, "identity_strategy": "Assessment identifier plus revision designator and a fixed limitations key, with content digest.", "source_refs": [ "SRC-004", "SRC-011" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bd-decision-and-accountability", "name": "Decision and Accountability", "description": "Operational signal linkage, the assessment conclusion and conditions, accountable sign-off and independent review citations.", "rationale": "An assessment that does not terminate in an attributable decision with conditions and a named accountable owner cannot be relied upon. Post-market signals and incidents are the feedback that makes the decision revisable.", "source_refs": [ "SRC-003", "SRC-010", "SRC-006" ], "layers": [ { "id": "ly-operational-signals", "name": "Operational Signal Linkage", "description": "References to post-market monitoring and incident or hazard records that feed the assessment.", "source_refs": [ "SRC-003", "SRC-010" ], "findings": [ { "id": "fd-signal-and-incident-binding", "name": "Post-market signal and incident binding", "description": "References to the post-market monitoring arrangement and to incident and hazard records considered by this assessment, with the classes of signal that must feed back into it.", "source_refs": [ "SRC-003", "SRC-010", "SRC-001" ], "questions": [ { "id": "q-monitoring-and-incident-refs", "text": "Which post-market monitoring arrangement and which incident or hazard records does this assessment reference?", "kind": "relationship", "answer_data": [ "Monitoring plan reference", "Incident and hazard record identifiers", "Relevance of each record to this assessment" ] }, { "id": "q-signal-classes-feedback", "text": "Which incident and hazard classes must be fed back into this assessment?", "kind": "event", "answer_data": [ "Signal class codes such as incident, serious incident, hazard and serious hazard", "Threshold for feedback", "Routing rule to the assessment owner" ] }, { "id": "q-signal-timeline", "text": "What timelines apply from signal detection to assessment update?", "kind": "temporal", "answer_data": [ "Detection to notification interval", "Notification to assessment update interval", "Regulatory reporting deadlines referenced, not executed" ] }, { "id": "q-incident-ownership-split", "text": "Which system owns incident case management and what does this assessment retain?", "kind": "ownership", "answer_data": [ "Owning system reference", "Fields retained locally such as reference, class and consideration outcome", "Fields explicitly not retained such as case state and notification log" ] } ], "data_elements": [ { "id": "de-monitoring-plan-ref", "name": "Post-market monitoring reference", "description": "Reference to the externally owned post-market monitoring plan or system.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-incident-record-ref", "name": "Incident or hazard record reference", "description": "Reference to an incident or hazard record considered by this assessment.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010" ] }, { "id": "de-signal-class-code", "name": "Signal class code", "description": "Coded class of the referenced signal using interoperable incident and hazard definitions.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010" ] } ], "artifacts": [], "inline_only_rationale": "Incident triage, notification workflow and regulator correspondence are owned by the incident register and the applicable reporting regime. Only the reference, signal class, consideration outcome and feedback routing may be held here, which is reference data rather than a document." } ] }, { "id": "ly-decision-and-assurance", "name": "Decision, Conditions and Assurance", "description": "The conclusion and residual-risk acceptance, attached conditions and triggers, accountable sign-off, and citations to independent review.", "source_refs": [ "SRC-006", "SRC-003", "SRC-009" ], "findings": [ { "id": "fd-conclusion-and-acceptance", "name": "Assessment conclusion and residual risk acceptance", "description": "The terminating judgement of the assessment, who holds authority to accept the stated residual risk, which deployment scopes the conclusion covers and how long it is valid.", "source_refs": [ "SRC-006", "SRC-003", "SRC-011" ], "questions": [ { "id": "q-conclusion-outcome", "text": "What is the assessment conclusion: approve, approve with conditions, defer or reject?", "kind": "decision", "answer_data": [ "Conclusion code", "Reasoning summary", "Dissenting positions recorded" ] }, { "id": "q-acceptance-authority", "text": "Who holds authority to accept residual risk at the stated level?", "kind": "authority", "answer_data": [ "Accepting role and authority basis", "Escalation threshold above which a higher body must accept", "Delegation instrument reference" ] }, { "id": "q-conclusion-coverage", "text": "Which deployment scopes, markets and use cases does the conclusion cover?", "kind": "constraint", "answer_data": [ "Covered deployment scopes", "Covered markets", "Explicitly uncovered uses" ] }, { "id": "q-conclusion-validity-window", "text": "For how long is the conclusion valid absent a triggering change?", "kind": "temporal", "answer_data": [ "Validity start and end times", "Default review interval", "Automatic lapse behaviour" ] } ], "data_elements": [ { "id": "de-conclusion-code", "name": "Assessment conclusion code", "description": "Coded terminating judgement of the assessment.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "de-acceptance-authority-ref", "name": "Risk acceptance authority reference", "description": "Reference to the role or body that accepted the residual risk.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "de-conclusion-valid-until", "name": "Conclusion validity end", "description": "Time at which the conclusion lapses absent renewal.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [ { "id": "art-assessment-decision-record", "name": "Assessment decision record", "description": "Record of the conclusion, reasoning, residual-risk acceptance, coverage and validity window, fixed at sign-off.", "media_or_form": [ "structured record", "signed attestation" ], "serial": false, "identity_strategy": "Master-system decision identifier; otherwise assessment identifier plus revision designator and a fixed decision key, with content digest and signature reference.", "source_refs": [ "SRC-006", "SRC-003" ] } ], "inline_only_rationale": null }, { "id": "fd-conditions-and-triggers", "name": "Conditions, restrictions and reassessment triggers", "description": "The conditions and restrictions attached to an approval, the events that trigger reassessment, what happens to approval status while reassessment is pending, and who monitors for triggers.", "source_refs": [ "SRC-003", "SRC-008", "SRC-011" ], "questions": [ { "id": "q-attached-conditions", "text": "Which conditions, restrictions and prohibited uses attach to the approval?", "kind": "constraint", "answer_data": [ "Condition statements", "Prohibited use list", "Verification method per condition" ] }, { "id": "q-reassessment-trigger-set", "text": "Which changes to the model, data, deployment context or law trigger reassessment?", "kind": "event", "answer_data": [ "Trigger event types", "Materiality threshold per trigger", "Reference to the subject binding invalidation rules" ] }, { "id": "q-pending-reassessment-status", "text": "What happens to approval status when a trigger fires but reassessment is not yet complete?", "kind": "state", "answer_data": [ "Interim status code", "Permitted operation during the interim", "Maximum interim duration" ] }, { "id": "q-trigger-monitoring-duty", "text": "Who watches for trigger conditions and how are they notified?", "kind": "process", "answer_data": [ "Monitoring role reference", "Notification channel and route", "Escalation on missed notification" ] } ], "data_elements": [ { "id": "de-approval-condition", "name": "Approval condition", "description": "A condition or restriction attached to the assessment conclusion.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-reassessment-trigger", "name": "Reassessment trigger", "description": "An event type that requires the assessment to be reopened.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-008" ] }, { "id": "de-interim-status-code", "name": "Interim status code", "description": "Status applied while a triggered reassessment is pending.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011" ] } ], "artifacts": [], "inline_only_rationale": "Conditions and triggers are machine-evaluable rules that must be watched continuously by other systems; embedding them in a document would prevent automated trigger detection and status enforcement." }, { "id": "fd-accountable-signoff", "name": "Accountable ownership and sign-off", "description": "The named accountable person or body owning the assessment outcome, the delegated authority permitting sign-off at this risk level, the form of the sign-off and what happens when the owner changes.", "source_refs": [ "SRC-006", "SRC-001", "SRC-003" ], "questions": [ { "id": "q-accountable-owner", "text": "Which named person or body owns this assessment and its outcome?", "kind": "ownership", "answer_data": [ "Accountable party reference", "Owning function", "Deputy or successor arrangement" ] }, { "id": "q-signoff-delegation", "text": "Which delegated authority permits sign-off at this risk level?", "kind": "authority", "answer_data": [ "Delegation instrument reference", "Authority limit", "Cases requiring escalation beyond the delegation" ] }, { "id": "q-signoff-form-identity", "text": "What form does the sign-off take and how is signer identity established?", "kind": "evidence", "answer_data": [ "Sign-off form such as signature, attestation or approval event", "Identity assurance method", "Timestamp of signature" ] }, { "id": "q-owner-change-handling", "text": "What happens to accountability when the named owner leaves the role?", "kind": "lifecycle", "answer_data": [ "Reassignment rule", "Whether reassignment creates a new revision", "Historical owner preservation rule" ] } ], "data_elements": [ { "id": "de-accountable-party-ref", "name": "Accountable party reference", "description": "Reference to the person or body accountable for the assessment.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "de-signoff-at", "name": "Sign-off event time", "description": "Event time at which the sign-off occurred.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-delegation-ref", "name": "Delegation instrument reference", "description": "Reference to the instrument granting sign-off authority.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] } ], "artifacts": [ { "id": "art-signoff-attestation", "name": "Assessment sign-off attestation", "description": "Attestation binding the accountable party, the delegated authority and the signed assessment revision.", "media_or_form": [ "signed attestation", "structured record" ], "serial": false, "identity_strategy": "Assessment identifier plus revision designator and signer reference; digest of the signed revision recorded in the attestation.", "source_refs": [ "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "fd-independent-review-binding", "name": "Independent review and attestation citation", "description": "Citations to internal audit, external review, notified body or certification records related to this assessment, with independence characterisation and explicit limits on what may be claimed from them.", "source_refs": [ "SRC-003", "SRC-009", "SRC-011" ], "questions": [ { "id": "q-review-records-cited", "text": "Which internal audit, external review or certification records relate to this assessment?", "kind": "relationship", "answer_data": [ "Review or certificate identifiers", "Issuing body reference", "Issue and expiry dates" ] }, { "id": "q-reviewer-independence", "text": "How independent was each reviewer from the development and deployment teams?", "kind": "quality", "answer_data": [ "Independence characterisation", "Declared conflicts of interest", "Access level granted to the reviewer" ] }, { "id": "q-attestation-scope", "text": "What is the exact scope of each cited external attestation?", "kind": "evidence", "answer_data": [ "Scope statement of the attestation", "Subject version and boundary covered", "Standard or scheme and version" ] }, { "id": "q-claim-limits-from-review", "text": "What may and may not be claimed on the basis of each cited review?", "kind": "validation", "answer_data": [ "Permitted claim wording", "Prohibited claims such as unevidenced conformance", "Conditions or qualifications carried by the attestation" ] } ], "data_elements": [ { "id": "de-review-record-ref", "name": "Review or certificate reference", "description": "Reference to an externally owned review, audit or certification record.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-reviewer-independence", "name": "Reviewer independence characterisation", "description": "Recorded degree and basis of reviewer independence.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "de-claim-limit-note", "name": "Claim limitation note", "description": "Explicit limit on claims derivable from a cited review.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "Conformity assessment, certification and audit records are issued and held by their issuing bodies. This model may hold only the citation, scope, independence characterisation and claim limits, so a locally produced artefact would risk asserting conformance the model has no authority to certify." } ] } ] }, { "id": "bd-record-lifecycle-and-disclosure", "name": "Record Lifecycle, Retention and Disclosure", "description": "The assessment record's own state machine, supersession provenance, retention and disposition, disclosure tiering and alignment crosswalks.", "rationale": "Assessment records are evidence with long statutory retention and contested disclosure interests. Their own lifecycle, retention rule and redaction path must be modelled explicitly, and alignment claims to external frameworks must be traceable and qualified.", "source_refs": [ "SRC-003", "SRC-006", "SRC-009" ], "layers": [ { "id": "ly-record-lifecycle", "name": "Record Lifecycle and Retention", "description": "States, transitions, supersession provenance, retention period and disposition of the assessment record.", "source_refs": [ "SRC-003", "SRC-006" ], "findings": [ { "id": "fd-state-and-supersession", "name": "Record state and supersession provenance", "description": "The lifecycle state of the assessment record, which transitions are permitted, what changed relative to the superseded revision, and the separate event and recording times of each transition.", "source_refs": [ "SRC-006", "SRC-008", "SRC-003" ], "questions": [ { "id": "q-record-current-state", "text": "Which lifecycle state is this assessment record currently in?", "kind": "state", "answer_data": [ "State code such as draft, in review, approved, conditionally approved, superseded or withdrawn", "State entered at time", "Actor who caused the transition" ] }, { "id": "q-permitted-transitions", "text": "Which transitions are permitted and which changes require a new revision rather than an in-place edit?", "kind": "lifecycle", "answer_data": [ "Permitted transition set", "Immutability rule after sign-off", "Change classes forcing a new revision" ] }, { "id": "q-supersession-diff", "text": "What changed relative to the superseded revision and why was the assessment reopened?", "kind": "provenance", "answer_data": [ "Superseded revision reference", "Change summary by section", "Triggering reason reference" ] }, { "id": "q-transition-time-pair", "text": "When did each transition occur in event time and when was it recorded in the system?", "kind": "temporal", "answer_data": [ "Transition event timestamp", "Recording or ingestion timestamp", "Clock or source of each timestamp" ] } ], "data_elements": [ { "id": "de-record-state-code", "name": "Record state code", "description": "Current lifecycle state of the assessment record.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-006" ] }, { "id": "de-superseded-revision-ref", "name": "Superseded revision reference", "description": "Reference to the revision this record supersedes.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008" ] }, { "id": "de-transition-event-at", "name": "Transition event time", "description": "Event time of a lifecycle state transition.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-transition-recorded-at", "name": "Transition recording time", "description": "Time at which the transition was recorded, distinct from its event time.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [], "inline_only_rationale": "State, permitted transitions and supersession pointers are control fields that governance tooling must read and enforce directly; a document form would obscure the current authoritative revision." }, { "id": "fd-retention-and-disposition", "name": "Retention and disposition of the assessment record", "description": "How long the assessment and its supporting citations must be kept, under which authority, what remains discoverable after disposition, and how personal data inside the record is minimised.", "source_refs": [ "SRC-003", "SRC-006", "SRC-009" ], "questions": [ { "id": "q-retention-period-basis", "text": "How long must this assessment and its supporting citations be retained and under which rule?", "kind": "retention", "answer_data": [ "Retention period value", "Retention rule or legal basis reference", "Retention clock start event such as placing on the market or withdrawal" ] }, { "id": "q-disposition-authority", "text": "Which policy or authority sets the retention period and authorises disposition?", "kind": "authority", "answer_data": [ "Policy owner reference", "Disposition approver", "Legal hold override rule" ] }, { "id": "q-post-disposition-discoverability", "text": "What must remain discoverable after disposition, such as a tombstone or index entry?", "kind": "access", "answer_data": [ "Tombstone fields retained", "Index entry content", "Retention period for the tombstone itself" ] }, { "id": "q-personal-data-minimisation", "text": "How is personal data inside the assessment minimised or redacted before long-term retention?", "kind": "privacy", "answer_data": [ "Personal data fields present", "Minimisation or pseudonymisation rule", "Timing of redaction relative to retention" ] } ], "data_elements": [ { "id": "de-retention-period", "name": "Retention period", "description": "Required retention duration for the assessment record.", "value_kind": "duration", "cardinality": "1", "required": true, "source_refs": [ "SRC-003" ] }, { "id": "de-retention-clock-start", "name": "Retention clock start event", "description": "Event from which the retention period is counted.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-003" ] }, { "id": "de-legal-hold-flag", "name": "Legal hold indicator", "description": "Whether a legal hold suspends disposition.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-tombstone-fields", "name": "Tombstone field set", "description": "Fields preserved after disposition to keep the record discoverable.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [], "inline_only_rationale": "Retention is a set of policy-driven scalar fields evaluated by records-management tooling; the schedule itself is owned by the adopting Dimension's retention policy, so a local document would fork the authoritative rule." } ] }, { "id": "ly-disclosure-and-alignment", "name": "Disclosure and Alignment", "description": "Audience-tiered disclosure with redaction, and traceable crosswalks to aligned external frameworks.", "source_refs": [ "SRC-009", "SRC-003", "SRC-011" ], "findings": [ { "id": "fd-disclosure-tiering", "name": "Disclosure tiering and redaction", "description": "Which audiences may see which parts of the assessment, what is withheld as trade secret or security-sensitive, how a redacted external version is derived, and which disclosures are mandatory regardless of preference.", "source_refs": [ "SRC-009", "SRC-011", "SRC-003" ], "questions": [ { "id": "q-audience-tiers", "text": "Which audiences may see which parts of this assessment?", "kind": "access", "answer_data": [ "Audience tier definitions such as internal, regulator, external reviewer and public", "Section visibility per tier", "Approval required per tier" ] }, { "id": "q-withheld-content", "text": "Which content is withheld as trade secret, security-sensitive or dual-use hazardous?", "kind": "security", "answer_data": [ "Withholding category per section", "Justification for withholding", "Reviewer of the withholding decision" ] }, { "id": "q-redaction-derivation", "text": "How is a redacted external version derived and kept consistent with the internal record?", "kind": "process", "answer_data": [ "Redaction procedure", "Linkage between internal revision and redacted release", "Consistency verification method" ] }, { "id": "q-mandatory-disclosure", "text": "Which disclosures are legally mandatory regardless of confidentiality preference?", "kind": "requirement", "answer_data": [ "Mandatory disclosure items", "Recipient and legal basis", "Deadline reference" ] } ], "data_elements": [ { "id": "de-audience-tier", "name": "Audience tier", "description": "Defined audience tier for disclosure of assessment content.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-009" ] }, { "id": "de-withholding-category", "name": "Withholding category", "description": "Basis on which a section is withheld from a tier.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "de-redacted-release-ref", "name": "Redacted release reference", "description": "Reference to a published redacted variant of this assessment revision.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009" ] } ], "artifacts": [ { "id": "art-disclosure-package", "name": "Audience-tiered disclosure package", "description": "Derived, audience-scoped release of the assessment, including the redacted external variant and any mandated documentation form supplied to authorities or downstream operators.", "media_or_form": [ "redacted release", "structured record", "narrative document" ], "serial": true, "identity_strategy": "Assessment identifier plus revision designator, audience tier code and release sequence key; digest of both source revision and released variant recorded.", "source_refs": [ "SRC-009", "SRC-011" ] } ], "inline_only_rationale": null }, { "id": "fd-standards-crosswalk", "name": "Framework alignment crosswalk", "description": "Traceable mapping from this assessment's elements onto each aligned external framework, with mapping strength, conflicts between frameworks and the framework version used.", "source_refs": [ "SRC-001", "SRC-006", "SRC-003" ], "questions": [ { "id": "q-crosswalk-mapping", "text": "How do this assessment's elements map onto each aligned framework's structure?", "kind": "interoperability", "answer_data": [ "Element to framework element mappings", "Framework identifier per mapping", "Direction and cardinality of the mapping" ] }, { "id": "q-mapping-strength-evidence", "text": "Which mappings are exact, partial or absent, and what evidence supports each claim?", "kind": "validation", "answer_data": [ "Mapping strength code", "Supporting evidence or reasoning", "Unmapped elements on both sides" ] }, { "id": "q-framework-conflicts", "text": "Where do the aligned frameworks conflict or use the same term with different meanings?", "kind": "exception", "answer_data": [ "Conflict description", "Terms with divergent definitions", "Resolution or deferral decision" ] }, { "id": "q-framework-version-check", "text": "Which framework version was used for each mapping and when was it last verified?", "kind": "provenance", "answer_data": [ "Framework version or edition", "Last verification timestamp", "Verifier reference" ] } ], "data_elements": [ { "id": "de-crosswalk-entry", "name": "Crosswalk entry", "description": "A mapping from a local element to an external framework element.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "de-mapping-strength", "name": "Mapping strength code", "description": "Whether a mapping is exact, partial or absent.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-framework-version", "name": "Aligned framework version", "description": "Version of the external framework used for the mapping.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] } ], "artifacts": [ { "id": "art-crosswalk-matrix", "name": "Alignment crosswalk matrix", "description": "Matrix mapping assessment elements to aligned external frameworks with mapping strength, evidence, conflicts and framework versions; it records alignment, never conformance.", "media_or_form": [ "tabular matrix", "structured record" ], "serial": false, "identity_strategy": "Assessment identifier plus revision designator and a fixed crosswalk key; each row keyed by the external framework identifier and version.", "source_refs": [ "SRC-001", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "fn-open-assessment", "name": "Open assessment", "description": "Create a new assessment record in draft state under a stated mandate, with identity, revision and temporal anchors set.", "inputs": [ "Subject system reference", "Mandate basis and commissioning body", "Assessment type code" ], "outputs": [ "Assessment identifier and revision designator", "Draft assessment record", "Creation timestamp" ], "preconditions": [ "A resolvable subject system reference exists", "The commissioning authority is identified" ], "effects": [ "A draft record exists and is addressable", "Subsequent findings can attach to a stable identifier" ], "source_refs": [ "SRC-006", "SRC-008" ] }, { "id": "fn-bind-subject-and-profile", "name": "Bind subject and record classification profile", "description": "Fix the assessed system version, component boundary, intended purpose and coded classification profile.", "inputs": [ "Subject identifier and version designation", "Component inventory references", "Intended purpose and deployment context" ], "outputs": [ "Subject binding with observation timestamp", "Classification profile values", "Binding invalidation rule set" ], "preconditions": [ "Assessment record is in draft state", "Subject version is immutably identifiable" ], "effects": [ "The assessment scope becomes reproducible", "Changes to the subject can be detected against the binding" ], "source_refs": [ "SRC-003", "SRC-013" ] }, { "id": "fn-determine-role-and-tier", "name": "Determine operator role and risk tier", "description": "Record the operator role per market, the applicable regime set and the risk tier determination with its justification.", "inputs": [ "Classification profile", "Market and jurisdiction list", "Regime references with versions" ], "outputs": [ "Operator role codes", "Risk tier codes per regime", "Tier determination record" ], "preconditions": [ "Subject binding and classification profile are recorded", "Regime versions in force at the cut-off are known" ], "effects": [ "The obligation surface becomes computable", "Any not-high-risk claim is documented before market placement" ], "source_refs": [ "SRC-003", "SRC-009" ] }, { "id": "fn-compile-applicability", "name": "Compile requirement and safeguard applicability", "description": "Derive the applicable requirement set from role and tier, record exclusions with justification, and map selected safeguards to each requirement and risk.", "inputs": [ "Operator role and tier determinations", "Requirement catalogue references", "Safeguard catalogue references" ], "outputs": [ "Requirement applicability statement", "Safeguard applicability register", "Responsibility assignments" ], "preconditions": [ "Role and tier are determined", "Catalogue versions are pinned" ], "effects": [ "Exclusions carry recorded justification", "Every applicable requirement has a named responsible party" ], "source_refs": [ "SRC-006", "SRC-001" ] }, { "id": "fn-attach-risk-reference", "name": "Attach risk and impact references", "description": "Bind externally owned risk and opportunity register items as evidence, carrying only reference, revision, read time and assessment-scoped parameters.", "inputs": [ "Register item identifiers", "Register snapshot or version key", "Assessment-scoped tags such as risk category codes" ], "outputs": [ "Risk register bindings", "Read timestamps", "Unmapped tag list for register follow-up" ], "preconditions": [ "The referenced register is resolvable", "Local parameter allow-list is enforced" ], "effects": [ "Risk evidence is citable and reproducible", "No register state, scoring or treatment content is copied locally" ], "source_refs": [ "SRC-007", "SRC-001" ] }, { "id": "fn-register-evidence-reference", "name": "Register evaluation evidence reference", "description": "Add a citation to an externally produced evaluation, audit or exercise, with identifier, digest, executing party, evaluated subject version and sufficiency judgement.", "inputs": [ "Evidence item reference", "Content digest or signature", "Evaluated subject version" ], "outputs": [ "Evidence manifest entry", "Sufficiency and currency judgement", "Gap note where evidence is insufficient" ], "preconditions": [ "Evidence item is retrievable and integrity-verifiable", "Evaluated subject version is comparable to the bound subject" ], "effects": [ "Claims become traceable to identified evidence", "Stale or mismatched evidence is flagged rather than silently credited" ], "source_refs": [ "SRC-012", "SRC-011" ] }, { "id": "fn-record-residual-position", "name": "Record effectiveness and residual risk position", "description": "Capture per-safeguard effectiveness ratings, residual risk levels per category, the as-of time and any accepted open deficiencies.", "inputs": [ "Safeguard applicability register", "Evidence manifest", "Residual risk scale definition" ], "outputs": [ "Effectiveness ratings", "Residual risk levels", "Residual risk and deficiency statement" ], "preconditions": [ "Safeguards are enumerated", "Evidence citations exist for rated safeguards" ], "effects": [ "A dated, evidenced risk position exists for the decision", "Open deficiencies are visible with compensating measures" ], "source_refs": [ "SRC-001", "SRC-007" ] }, { "id": "fn-issue-decision", "name": "Issue assessment decision", "description": "Terminate the assessment with a conclusion, residual-risk acceptance by an authorised role, coverage scope, validity window, attached conditions and reassessment triggers.", "inputs": [ "Residual risk statement", "Acceptance authority reference", "Proposed conditions and triggers" ], "outputs": [ "Assessment decision record", "Sign-off attestation", "Condition and trigger set" ], "preconditions": [ "Residual risk position is recorded", "The accepting role is within its delegated authority limit" ], "effects": [ "The record becomes immutable at the signed revision", "Conditions and triggers become watchable by other systems" ], "source_refs": [ "SRC-006", "SRC-003" ] }, { "id": "fn-supersede-assessment", "name": "Supersede or reopen assessment", "description": "Create a new revision in response to a fired trigger or scheduled review, linking the superseded revision and recording the change reason and both event and recording times.", "inputs": [ "Triggering reason reference", "Prior revision reference", "Change scope" ], "outputs": [ "New revision in draft state", "Supersession link and change summary", "Interim status on the prior conclusion" ], "preconditions": [ "A prior signed revision exists", "A trigger or scheduled review is recorded" ], "effects": [ "Revision history remains auditable", "Only one revision is authoritative at a time" ], "source_refs": [ "SRC-008", "SRC-006" ] }, { "id": "fn-emit-disclosure-view", "name": "Emit audience-tiered disclosure view", "description": "Derive an audience-scoped release from a signed revision, applying withholding rules and recording digests of both the source revision and the released variant.", "inputs": [ "Signed assessment revision", "Audience tier code", "Withholding decisions" ], "outputs": [ "Disclosure package for the tier", "Source and release digests", "Mandatory disclosure checklist result" ], "preconditions": [ "The source revision is signed", "Withholding decisions are reviewed and approved" ], "effects": [ "External releases stay traceable to an internal revision", "Mandatory disclosures are not suppressed by confidentiality preference" ], "source_refs": [ "SRC-009", "SRC-011" ] } ], "composition": [ { "target": "WM-KNW-015", "relation": "REFERENCE", "purpose": "Cite risk and opportunity register items as the evidence base for this assessment. This model carries the item reference, revision key, read time and assessment-scoped parameters such as AI risk category tags. It does not carry register item state, scoring methodology, treatment plans, register ownership or register review cadence.", "required": true, "source_refs": [ "SRC-007", "SRC-001" ] }, { "target": "WM-ACT-037", "relation": "CHILD", "purpose": "This model is registered as a child of WM-ACT-037 and specialises only the AI-specific assessment surface. Generic assessment-activity scheduling, actor mechanics and workflow state are expected to remain in the parent; the parent's exact surface is unverified and is recorded as an open boundary.", "required": true, "source_refs": [ "SRC-006" ] }, { "target": "Regulation (EU) 2024/1689 (Artificial Intelligence Act)", "relation": "ALIGN", "purpose": "Align operator role, risk tier, requirement applicability, human oversight, technical documentation, post-market monitoring and serious incident vocabulary. Alignment is recorded in the crosswalk with mapping strength; no conformance is asserted without cited attestation evidence.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "ISO/IEC 42001:2023 AI management system", "relation": "ALIGN", "purpose": "Align the applicability statement, control selection and record retention concepts with the management system standard's Annex A controls and Statement of Applicability. Organisation-level management system clauses remain outside this model.", "required": false, "source_refs": [ "SRC-006" ] }, { "target": "NIST AI Risk Management Framework 1.0 and Generative AI Profile (NIST AI 600-1)", "relation": "ALIGN", "purpose": "Align the MAP, MEASURE and MANAGE analysis layers, the trustworthiness characteristic vocabulary and the generative-AI risk category codes used for taxonomy tagging.", "required": false, "source_refs": [ "SRC-001", "SRC-002", "SRC-004" ] }, { "target": "ISO/IEC 23894:2023 AI risk management guidance", "relation": "ALIGN", "purpose": "Align risk terminology and reinforce the separation between the risk management process owned by the register and the assessment that consumes its output as evidence.", "required": false, "source_refs": [ "SRC-007" ] }, { "target": "ISO/IEC 42005:2025 AI system impact assessment", "relation": "ALIGN", "purpose": "Align the impact analysis finding, its lifecycle placement and its update conditions with the impact assessment guidance.", "required": false, "source_refs": [ "SRC-008" ] }, { "target": "OECD Framework for the Classification of AI Systems", "relation": "ALIGN", "purpose": "Supply the coded classification profile dimensions used to characterise the assessed system independently of any single regulatory tier scheme.", "required": false, "source_refs": [ "SRC-013" ] }, { "target": "AI system technical record (sibling model not yet registered)", "relation": "REFERENCE", "purpose": "Reference the provider-maintained technical documentation describing the system's design, training and performance. This model records the reference and an adequacy judgement only. The sibling model is not present in the registry and is recorded as a structural gap.", "required": false, "source_refs": [ "SRC-003" ] }, { "target": "AI evaluation run record and evaluation harness", "relation": "REFERENCE", "purpose": "Reference evaluation runs cited as evidence. Task, solver, scorer, sandbox and log semantics remain owned by the harness; this model holds the run reference, digest, subject version and sufficiency judgement.", "required": false, "source_refs": [ "SRC-012" ] }, { "target": "AI incident and hazard record", "relation": "REFERENCE", "purpose": "Reference incident and hazard records considered by the assessment using interoperable incident definitions. Case management, triage, notification workflow and authority correspondence remain owned by the incident register and the applicable reporting regime.", "required": false, "source_refs": [ "SRC-010", "SRC-003" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "The adopting Dimension must name a single accountable owner for the assessment model instance, typically the AI system owner together with the accountable deployer, and record the delegation instrument that permits residual-risk acceptance.", "The Dimension must pin the versions of every external catalogue it uses: requirement catalogues, safeguard catalogues, risk taxonomies, classification schemes and metric definitions. Unpinned catalogue references are invalid.", "The Dimension must declare its records-retention policy and its legal-hold procedure before any assessment record reaches an approved state, because disposition execution is owned by that policy and not by this model.", "The Dimension must register the resolvable endpoints for the referenced risk register, evaluation evidence store and incident register, and must reject bindings whose targets cannot be resolved.", "The Dimension must publish its audience-tier definitions and withholding review procedure before any disclosure package is emitted." ], "namespace_guidance": "Use a stable Dimension-scoped namespace such as {dimension}/ai-governance-assessment/{assessment-identifier}/{revision}. Keep external vocabularies in their own namespaces and never rewrite external codes into local ones; carry the scheme identifier and version alongside every code. Local extension codes must be prefixed to prevent collision with governed vocabularies.", "registry_links": [ "Registry entry vr.wm-ai-008 under navigation path NAV.INF.AI.GOV with domain tag INF.AI.GOV", "Known-relation ledger entry: REFERENCE from WM-AI-008 to WM-KNW-015 for risk evidence", "Parent registry link to WM-ACT-037, whose surface is unverified and flagged for boundary review" ] }, "canon_and_patch": { "canonicalization_rules": [ "Canonical form is a directed acyclic structure of bundle, layer, finding and question nodes keyed by stable lower-kebab-case local identifiers; serialisation order is not semantic.", "All timestamps are canonicalised to RFC 3339 with explicit seconds and an explicit numeric offset or Z; local-time strings without offset are rejected at ingest.", "All coded values are canonicalised as a pair of scheme identifier, scheme version and code; a bare code without scheme and version is not canonical.", "External references are canonicalised as target model or system identifier, target record identifier, target revision key and read timestamp; a reference lacking a revision key is marked non-reproducible.", "Free text is stored as-is; only whitespace normalisation and Unicode normalisation are applied, so that quoted regulatory language is preserved verbatim." ], "patch_rules": [ "Before sign-off, patches may modify any finding in place, incrementing a draft counter without creating a new revision.", "After sign-off, the signed revision is immutable. Any substantive change creates a new revision linked by a supersession pointer with a recorded change reason.", "Patches to references may update the read timestamp and revision key of a target without a new assessment revision, provided the target's content did not change the finding's conclusion; if it did, a new revision is required.", "Corrections of clerical error in a signed revision are recorded as an erratum entry attached to the revision, never as a silent edit.", "A patch must not add fields to a reference binding that appear on the target model's forbidden-field list." ], "compatibility_rules": [ "Adding a new optional finding, question or data element is a minor, backward-compatible change.", "Removing or renaming a local identifier, changing a data element from optional to required, or narrowing a code list is a breaking change requiring a major version and a migration note.", "Changing the version of an aligned external framework does not change this model's version, but requires re-verification of every affected crosswalk entry and a new verification timestamp.", "Consumers must tolerate unknown code values from a newer scheme version by preserving them verbatim rather than dropping them.", "Any change that moves a concept across the boundary to or from a referenced model requires an update to the composition link and to boundary notes in the same change set." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier: the identifier issued by the system of record for the assessment, for example the AI management system, GRC platform or quality management system assessment number, used verbatim as the primary key whenever one exists.", "Governed global identifier or IRI: an identifier from a governed scheme, such as a registration identifier in an official database for high-risk AI systems, an accredited certificate number, or a persistent DOI or organisation-governed IRI.", "UUID or ULID minted by the adopting Dimension, used only when neither a master-system identifier nor a governed global identifier is available, and recorded together with the reason no higher-priority identifier applied.", "A date, a title, a file name, a storage path or an author name is never an identifier and must not be used as a key or as a disambiguator on its own." ], "timestamp_rule": "All time values are recorded in RFC 3339 format with explicit seconds and an explicit numeric UTC offset or the literal Z; timestamps without an offset are rejected. Event time and observation or ingestion time are recorded as separate fields whenever they can differ: for example, the time a lifecycle transition or sign-off actually occurred is stored separately from the time it was recorded in the store, and the time a referenced register item or evaluation result was produced is stored separately from the time this assessment read it. Durations use RFC 3339 or ISO 8601 duration form and never substitute for a timestamp.", "serial_naming_rule": "Artifacts marked serial are named as {artifact-key}/{assessment-identifier}/{revision-designator}/{sequence}, where sequence is a zero-padded monotonically increasing integer scoped to the artifact key and assessment identifier. Sequence numbers are never reused after disposition, and no date component is embedded in the name; the production time is carried as a separate RFC 3339 field.", "integrity_rule": "Every artifact carries a content digest computed over its canonical byte representation, recorded together with the digest algorithm and the time of computation. Signed artifacts additionally carry a signature reference and signer identity. A cited external artifact is stored with the digest observed at citation time, and any later digest mismatch invalidates the citation and raises a reassessment trigger rather than silently updating the reference." }, "policies": [ "No conformance claim may be asserted against any external framework without a cited attestation whose scope, version and issuer are recorded; crosswalks record alignment only.", "No finding may reproduce a referenced model's owned content. Reference bindings are limited to target identifier, revision key, read time and an explicit allow-list of assessment-scoped parameters.", "An assessment may not reach an approved state while any credited safeguard has no evidence citation or while any required requirement has no responsible party.", "Evidence whose evaluated subject version differs from the bound subject version must be either re-run or explicitly justified as transferable, with the justification recorded.", "Withholding content from a mandated disclosure recipient requires a recorded justification and a named approver; confidentiality preference never overrides a mandatory disclosure.", "Every assessment that cites a risk register item must record the register revision key, so that later register changes are detectable rather than silently inherited.", "Unmeasurable or poorly measured risks must be stated as such rather than omitted; absence of a metric is never recorded as absence of risk." ], "crud": { "read": [ "Read access is granted at the smallest scope that satisfies the request: a single finding or artifact rather than the whole bundle.", "Reads of a signed revision return the immutable revision content plus any attached errata; reads of a draft return the current draft counter.", "Reads that resolve external references return the stored reference, revision key and read time; they do not silently dereference the target and inline its content.", "Every read of a restricted finding or artifact is logged with reader identity, scope requested and time, for the retention period set by the Dimension." ], "create": [ "Creation requires a resolvable subject reference, a mandate basis and an assessment type; records failing these preconditions are rejected rather than created in an incomplete state.", "The creating service assigns identity following the identity priority order and records which priority level was used and why.", "Creating a reference binding requires the target to be resolvable at creation time and the target's revision key to be captured.", "Creating an artifact requires a content digest and, for serial artifacts, the next unused sequence number." ], "update": [ "Before sign-off, updates modify the draft in place and increment the draft counter; the actor and time of each update are recorded.", "After sign-off, updates are prohibited on the signed revision; a supersession creates a new revision instead.", "Updating a reference binding's read time and revision key is permitted without a new revision only when the finding's conclusion is unchanged; otherwise a new revision is required.", "Updates that would add a field forbidden by a referenced model's ownership contract are rejected by validation." ], "delete": [ "Signed assessment revisions are not hard-deleted while within their retention period. The default disposition rule keeps the assessment record, its decision, its sign-off and its evidence manifest for the longest applicable retention period, whose clock starts at the later of final decision and withdrawal of the assessed system from service.", "On disposition, the record is replaced by a tombstone preserving the assessment identifier, revision designator, subject identifier, conclusion code, retention rule reference, disposition time and disposing authority, so that citations from other records do not dangle.", "Draft revisions that never reached sign-off may be deleted after a Dimension-defined grace period, leaving a tombstone with the identifier and deletion reason only.", "This model does not own deletion execution. The adopting Dimension's records-retention and legal-hold policy owns the disposition schedule, approval and execution, and any statutory retention period referenced from Regulation (EU) 2024/1689 or the AI management system's documented information controls takes precedence over local defaults.", "Deletion of a referenced target is never propagated from here. Register items, evaluation results and incident records are deleted only under their own owning model's policy; this model reacts by marking the affected binding as unresolvable and raising a reassessment trigger.", "A legal hold suspends all disposition, including tombstoning, until the hold is released by the authority that placed it." ] }, "roles": [ { "name": "Assessment owner", "responsibilities": [ "Hold accountability for the assessment scope, method and outcome", "Ensure every credited safeguard has evidence and a responsible party", "Initiate supersession when a reassessment trigger fires" ] }, { "name": "Assessor", "responsibilities": [ "Perform the analysis and record findings, ratings and residual risk with as-of times", "Cite evidence with identifiers, digests and sufficiency judgements", "State measurement limitations and unmeasurable risks explicitly" ] }, { "name": "Risk acceptance authority", "responsibilities": [ "Accept or refuse the stated residual risk within a recorded delegation limit", "Approve attached conditions and restrictions", "Escalate acceptance beyond the delegation limit to a higher body" ] }, { "name": "Records and retention custodian", "responsibilities": [ "Apply the retention schedule, legal holds and disposition approvals", "Maintain tombstones and prevent dangling citations", "Log access to restricted findings and artifacts" ] }, { "name": "Disclosure reviewer", "responsibilities": [ "Review withholding decisions and their justifications", "Verify that mandatory disclosures are not suppressed", "Confirm each released variant is traceable to a signed revision by digest" ] }, { "name": "Boundary steward", "responsibilities": [ "Verify that no finding reproduces a referenced model's owned content", "Maintain composition links, forbidden-field allow-lists and boundary notes", "Re-verify crosswalk entries when an aligned framework version changes" ] } ], "access": { "default_rule": "Deny by default. Access is granted per scope to a named role for a stated purpose and a bounded period; the narrowest scope that satisfies the purpose is used, and the assessment's most restrictive content classification governs the whole scope unless a finer-grained grant exists.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Regulators and market surveillance authorities receive the scope required by the applicable regime regardless of internal confidentiality classification; the disclosure is logged and the legal basis recorded.", "External reviewers under a confidentiality arrangement may receive unredacted safeguard and capability content that is withheld from public tiers, with the arrangement reference recorded.", "Security-sensitive or dual-use hazardous content may be withheld from otherwise-entitled internal readers on a recorded need-to-know basis approved by the disclosure reviewer.", "Data subjects exercising rights over personal data inside the assessment receive the personal-data extract, not the full assessment, and the request is routed to the owning privacy process.", "During an active legal hold, disposition and redaction actions are blocked even for roles that normally hold that authority." ], "audit_requirements": [ "Log every access grant and use with actor identity, scope, purpose, legal or policy basis, and RFC 3339 timestamps for both the access event and its recording.", "Log every disclosure package emission with source revision digest, released variant digest, audience tier and approver.", "Log every withholding decision and its justification, and every override of a default access rule.", "Retain access logs for the retention period set by the adopting Dimension. This model records the logging requirement only; the audit-trail store and its integrity, query and retention semantics are owned by the Dimension's audit platform, not by this model." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL", "Owner", "Model version" ], "read_order": [ "Read AGENTS.md first to obtain Name, Type and the four URLs before touching any record.", "Read the Specification URL to load scope, boundaries, out-of-scope list and the composition and ownership contract.", "Read the Storage type URL to learn how the format-neutral semantics are projected into the concrete store, whether that is a document store, a repository, a database or an interface server.", "Read the Interface URL to learn the available read and write operations and their access scopes.", "Read the Processes URL to learn the assessment lifecycle, sign-off, supersession, retention and disclosure procedures before performing any create, update or disposition action.", "Resolve every composition link and confirm no local write would place target-owned content into this model." ] } }, "coverage": { "claim": "Covers one AI safety and governance assessment record as a single aggregate: subject binding, intended purpose and classification profile, operator role and regime applicability, risk tier, requirement and safeguard applicability, AI risk taxonomy and stakeholder impact, adversarial and data-provenance findings, human oversight, capability-threshold tiering, evidence citation with validity limits, residual-risk position, decision with conditions and triggers, accountable sign-off, record lifecycle, retention, disclosure tiering and framework crosswalks. Completeness is asserted only against the thirteen cited sources and only for the assessment record itself; register internals, AI system technical documentation, evaluation execution, incident case management, conformity assessment procedures and organisation-level management-system clauses are referenced rather than modelled. Environmental measurement, agentic composition, supply-chain attestation, contestation and redress, and sector overlays remain declared gaps. No universal completeness is claimed, and no second-provider corroboration exists.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Subject binding and assessment identity findings define identifiers, revision designators and the priority order for identifier selection; artifact rules forbid dates or titles as keys." }, { "dimension": "lifecycle", "status": "covered", "notes": "Record state and supersession finding defines states, permitted transitions and immutability after sign-off; conditions and triggers finding defines reopening events and interim status." }, { "dimension": "relationships", "status": "covered", "notes": "Register binding, evidence citation, signal and incident binding, and independent review binding are all modelled as reference-only links with revision keys and forbidden-field limits." }, { "dimension": "temporal", "status": "covered", "notes": "Evidence cut-off, judgement as-of time, transition event time and recording time, validity windows and revalidation intervals are separate fields under an RFC 3339 rule." }, { "dimension": "provenance", "status": "covered", "notes": "Binding origin, register read time, evidence execution attribution, supersession change reason and framework version verification are each modelled explicitly." }, { "dimension": "ownership", "status": "covered", "notes": "Accountable sign-off, safeguard owners, requirement responsible parties, incident ownership split and boundary steward role are defined." }, { "dimension": "validation", "status": "covered", "notes": "Effectiveness judgement, security test coverage, evidence sufficiency, mapping strength evidence and claim-limit rules govern what may be asserted." }, { "dimension": "access", "status": "covered", "notes": "Deny-by-default rule across bundle, layer, finding and artifact scopes, with regulator, external reviewer, need-to-know, data-subject and legal-hold exceptions." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Retention finding plus CRUD delete rules define retention clock start, tombstones, legal hold and explicit deferral of disposition execution to the adopting Dimension's records policy and statutory periods." }, { "dimension": "interoperability", "status": "covered", "notes": "Crosswalk finding, cross-regime tier mapping, requirement deduplication with traceability and coded scheme-plus-version canonicalisation." }, { "dimension": "classification and risk tiering", "status": "covered", "notes": "Classification profile, risk tier determination with derogation documentation and AI risk taxonomy assignment are separate, independently evidenced findings." }, { "dimension": "measurement and evidence quality", "status": "covered", "notes": "Metrics and thresholds, evidence manifest and measurement validity findings separate declared criteria, cited results and honest qualification." }, { "dimension": "security", "status": "covered", "notes": "Adversarial threat surface finding uses an attack-class taxonomy with attacker assumptions and test coverage; disclosure tiering handles dual-use hazardous content." }, { "dimension": "privacy", "status": "covered", "notes": "Personal data linkage in impact analysis and personal-data minimisation in retention; execution of data-protection assessment is referenced, not owned." }, { "dimension": "human oversight", "status": "covered", "notes": "Oversight arrangement, override authority, competence requirements and automation-bias countermeasures are modelled as a distinct finding." }, { "dimension": "decision and authority", "status": "covered", "notes": "Conclusion, acceptance authority with delegation limits, coverage scope, validity window and sign-off attestation." }, { "dimension": "process and events", "status": "covered", "notes": "Ten functions define the operating surface; reassessment triggers and signal feedback define the event surface." }, { "dimension": "spatial", "status": "covered", "notes": "Deployment jurisdictions, sectors and settings feed territorial regime applicability and per-market role determination." }, { "dimension": "sustainability and environmental impact", "status": "gap", "notes": "Environmental impact appears in the impact analysis receptors and in the generative-AI risk taxonomy, but no dedicated measurement finding for compute, energy or emissions is proposed; the cited sources support the risk category without prescribing an assessment structure." }, { "dimension": "cost and resource planning", "status": "not-applicable", "notes": "Assessment budgeting and staffing are management-system concerns expected in the parent or in the AI management system, not in a single assessment record." } ], "known_omissions": [ "No dedicated finding for compute, energy or emissions measurement, despite environmental impact being a named generative-AI risk category.", "No structure for agentic or multi-agent system composition, tool authority scoping or delegation chains; current sources treat these only as attack surfaces and autonomy attributes rather than as a governed structure.", "No structure for model or system supply-chain attestation such as bill-of-materials or provenance signatures; value chain risk is named by the cited sources but no normative structure is established for an assessment record.", "No sector-specific overlays, for example medical device, financial services or automotive assessment content, which would sit in sibling models.", "No treatment of contestation and redress mechanisms for affected persons beyond the impact analysis and oversight findings.", "The AI system technical record sibling model is not registered; the reference is declared as a structural gap rather than a canonical link.", "The parent model WM-ACT-037 surface is unverified, so the split between generic assessment-activity mechanics and AI-specific content is asserted rather than confirmed." ], "conflicts": [ "Tier vocabularies conflict across regimes: the EU risk categories, the OECD classification dimensions and developer capability tiers are not mutually derivable, so cross-regime mapping is recorded with mapping strength rather than as equivalence.", "The term risk is used differently by the risk management guidance, which treats risk as the effect of uncertainty on objectives, and by the generative-AI profile, which enumerates risk categories as harm types; the model carries both under distinct fields.", "Transparency obligations and trade-secret or dual-use withholding pull in opposite directions; the model resolves this by mandatory-disclosure precedence and recorded withholding justification rather than by asserting a general rule.", "Impact assessment guidance and the fundamental rights impact assessment obligation overlap substantially but are not identical in scope or in who must perform them; the model holds one impact finding with a regime-specific applicability flag rather than merging the two obligations.", "Voluntary framework language and binding regulation use similar terminology with different legal effect; the model forbids conformance claims from crosswalks to prevent voluntary alignment being read as regulatory conformity." ], "regional_assumptions": [ "Regulatory role and tier vocabulary is drawn primarily from the European Union regime; other jurisdictions require additional coded regime entries and may not use a comparable tiering concept.", "Retention periods are assumed to be set by the adopting Dimension and by applicable law; the model prescribes only the clock-start event and the tombstone rule, not a numeric period.", "Serious incident reporting deadlines and recipients are jurisdiction-specific and are referenced rather than encoded.", "Personal data handling assumes a jurisdiction with a data protection impact assessment instrument; where none exists, the linkage field is left empty rather than the concept being redefined.", "Capability-threshold and safeguard-tier practice is drawn from voluntary developer frameworks and the European general-purpose AI regime, and is not a global requirement." ], "adversarial_checks": [ "Checked every finding against the WM-KNW-015 relation rationale: the register binding finding carries only reference, revision, read time and an allow-listed parameter set, and no finding models risk item state, scoring methodology, treatment plans or register review cadence.", "Checked that referencing an evaluation harness, a guardrail engine, an incident register or an audit platform grants no ownership: evaluation execution, enforcement, incident case management and audit-trail storage are each listed in out-of-scope and in boundary notes, and the access layer explicitly defers audit-trail semantics to the Dimension's audit platform.", "Searched for a counterexample where an assessment must own an operational audit trail; concluded it does not, because the assessment needs only a dated judgement plus an evidence citation, so effectiveness judgement is bounded by an as-of time rather than a continuous control log.", "Tested whether the model duplicates AI system technical documentation; it does not, because the subject binding holds identifiers and boundary references and the adequacy of Annex IV documentation is judged rather than restated.", "Tested whether crosswalk entries could be read as conformance claims; blocked by an explicit policy requiring a cited attestation with issuer, scope and version before any conformance assertion.", "Tested identity rules against a date-based naming temptation: serial artifact naming uses a sequence scoped to assessment identifier and revision with no embedded date, and the production time is a separate RFC 3339 field.", "Checked that no bundle silently reintroduces organisation-level management system content; leadership, competence, internal audit programme and management review are listed as out-of-scope and left to the AI management system." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "claude" ], "waivedProviders": [ "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-08-29T09:06:27Z", "scope": "Queued subject-model research from WM-XCT-013 onward", "active_providers": [ "claude" ], "waived_providers": [ { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-08-29T09:06:27Z", "reason": "The repository owner explicitly instructed the research queue to continue without Grok after repeated structured-output failures." } ], "review_rule": "Claude-only results require a separate no-tools adversarial audit and remain reviewable drafts with a visible single-provider hold." }, "boundaryDecision": { "entry_kind": "aggregate", "status": "accepted", "rationale": "The assessment record, not the assessed AI system, is the consistency boundary: it owns its identifier, revision designation, lifecycle states, supersession provenance, sign-off, retention and disclosure tiering, while every external record it touches is held only as reference, revision key, read time and an allow-listed parameter set. That is an aggregate root, and the inline-only rationales on the reference bindings enforce it rather than merely asserting it. Split is rejected because the record terminates in one signed conclusion whose acceptance authority depends on tier, applicability, safeguard and residual-risk content being co-signed; the frozen registry also carries empty contains_ids and a REFERENCE composition role. Merge into WM-ACT-037 cannot be evaluated because the parent surface is unverified. The frozen registry value standalone-mm is a registry packaging label on a different axis from the ownership-plane aggregate determination; this audit does not reconcile the two, so registry review_state boundary-review-required stays set and the divergence is published as a visible hold." }, "decisions": [ { "concept": "Aggregate root granularity: assessment record versus assessment revision", "disposition": "accepted with condition", "rationale": "The root is correctly the record rather than the assessed system, but q-assessment-revision-rule implies a root spanning revisions with one authoritative pointer, while fn-supersede-assessment and the artifact naming scope imply the identifier-plus-revision pair is the key. Synthesis must state that the stable assessment identifier is the root, revisions are immutable versions beneath it, and exactly one revision is authoritative at any time." }, { "concept": "Entry kind aggregate versus the frozen registry value standalone-mm", "disposition": "accepted as aggregate, registry field flagged for reconciliation", "rationale": "Ownership of identity, revision, lifecycle, supersession, sign-off, retention and disclosure within one consistency boundary supports the aggregate reading. The registry label sits on a different axis and is not resolved here; the divergence is carried forward as a publication hold rather than silently overwritten in either direction." }, { "concept": "Split into separate obligation, risk-and-impact and decision models", "disposition": "rejected", "rationale": "The record terminates in a single signed conclusion whose acceptance authority depends on tier determination, requirement applicability, safeguard effectiveness and residual risk being co-signed as one judgement. Splitting would require joint signature across records and would fracture the acceptance chain, and the registry's empty contains_ids assumes one record." }, { "concept": "WM-KNW-015 binding parameter 'assessment-local severity view'", "disposition": "accepted with constraint", "rationale": "A locally defined severity view is functionally a re-score and sits in tension with the same boundary note that forbids carrying register scoring methodology. Permit it only as a reference to an externally owned scale scheme plus version, mark it non-authoritative for the register, and forbid any write-back to the cited item." }, { "concept": "Residual-risk position versus the register's residual score of record", "disposition": "accepted with non-authoritative labelling", "rationale": "The assessment legitimately owns a dated assessor judgement, but q-residual-risk-level per category can be read as the authoritative residual score that WM-KNW-015 owns. Require an explicit statement that the assessment position is point-in-time, is bounded by its as-of time, and does not update register state." }, { "concept": "fd-capability-threshold-tiering anchored on tier-3 vendor policy SRC-011", "disposition": "accepted with conditional-applicability flag", "rationale": "Capability thresholds and safeguard tiers are voluntary frontier-developer practice plus general-purpose AI regime content and do not apply to most deployer assessments. The four questions are already vocabulary-neutral, so retain the finding but attach a regime-applicability flag in the same manner used for the fundamental-rights impact assessment overlap." }, { "concept": "Source pinning for SRC-012 Inspect and SRC-011 Responsible Scaling Policy", "disposition": "deferred to live verification hold", "rationale": "SRC-012 carries only an access date with no version or commit pin, and SRC-011 is a frequently revised vendor policy appearing in nine findings. Publication requires a version pin or archived snapshot for the former and a re-check of the policy version in force for the latter." }, { "concept": "Paywalled ISO catalogue URLs as source support (SRC-006, SRC-007, SRC-008)", "disposition": "accepted", "rationale": "The cited pages are catalogue entries rather than normative text, so the underlying clauses are not verifiable from the citation itself. The check nonetheless passes: every one of the twenty-eight findings carries at least one openly verifiable tier-1 source alongside its ISO references, so no finding rests solely on unverifiable content." }, { "concept": "Artifact seriality scope and two competing signed attestations", "disposition": "accepted with condition", "rationale": "Seriality is defined only in an adversarial-check note as scoped to identifier plus revision and is not stated per artifact. Under that scope art-evidence-manifest being serial while art-assessment-decision-record is not, and art-signoff-attestation being non-serial despite plausible multiple signers, are unexplained. Require an explicit seriality scope on each artifact and a non-overlap rule separating decision content from signer attestation." }, { "concept": "Operating-surface gap: no function enters the trigger-fired, reassessment-pending state", "disposition": "deferred", "rationale": "q-pending-reassessment-status defines an interim approval state that none of the ten functions can set; fn-supersede-assessment only reacts to an already-fired trigger. Capability-tier determination, impact-analysis production and threat-model production are likewise unserved by any function. Single-provider mode forbids adding functions, so this is recorded as a declared omission for a later pass." }, { "concept": "Retention questions omit clock start and legal hold asserted in the coverage checklist", "disposition": "deferred with checklist narrowing", "rationale": "The retention-and-deletion note claims retention clock start, tombstones and legal hold, but only tombstones map to a visible question in fd-retention-and-disposition. Either surface clock-start and legal-hold questions at synthesis or narrow the checklist note so the coverage claim does not exceed the elicited question surface." }, { "concept": "Checklist dimensions asserting policy surfaces absent from the serialized structure", "disposition": "deferred to verification, not treated as a conflict", "rationale": "The evidence pack's structure carries only bundles, layers, findings, questions and artifacts, so the asserted access policy, CRUD delete rules, artifact naming policy and boundary steward role cannot appear in it; their absence is most likely a pack-shape artifact. Verify presence in the published record, and downgrade access, security and privacy from covered to partial if absent, since only two of one hundred twelve questions carry each of those kinds." }, { "concept": "Unregistered neighbour references enumerated asymmetrically", "disposition": "accepted with condition", "rationale": "The frozen relationship contract holds exactly one REFERENCE edge to WM-KNW-015, yet known omissions declare only the AI system technical record as an unregistered sibling. The evaluation run record, incident and hazard record, certification record, management system and data-protection assessment are equally unregistered and must be listed uniformly as unregistered external references rather than implied canonical links." } ], "publicationHolds": [ "Publish as a reviewable draft carrying a visible single-provider notice: Grok was waived by the repository owner at 2026-08-29T09:06:27Z after repeated structured-output failures, so no independent second-provider review of WM-AI-008 exists and this no-tools adversarial audit is not a substitute for one.", "Re-verify all thirteen source URLs, titles and version pins live before publication, with explicit attention to SRC-012 (access date only, no version or commit pin), SRC-011 (vendor policy version 3.4 may have been superseded) and SRC-003 (check for corrigenda, amendments and subsequent delegated or implementing acts after OJ L 2024/1689).", "State plainly that SRC-006, SRC-007 and SRC-008 are cited from paywalled ISO catalogue pages whose normative clause text was not verified, and that no finding rests on those citations alone.", "Keep the registry entry-kind divergence visible: the frozen record says standalone-mm and the research result says aggregate; registry review_state must remain boundary-review-required until the two are reconciled.", "Publish the WM-ACT-037 parent split as asserted and unverified; the division between generic assessment-activity mechanics and AI-specific content across identity, scope and method, sign-off, record state and retention is not confirmed against the parent's surface.", "Label every neighbour binding other than WM-KNW-015 as an unregistered external reference; the frozen relationship contract carries exactly one REFERENCE edge and contains_ids is empty.", "Confirm that the access policy, CRUD delete rules, retention-clock rule and artifact-naming policy asserted in the coverage checklist and adversarial checks are actually present in the published record, or narrow those checklist notes before release.", "Independent second-provider review was explicitly waived by the repository owner; this Claude-only result remains a reviewable draft." ], "deferredResearch": [ "Verify the WM-ACT-037 parent surface and re-run the duplication check against assessment identity, scope and method, accountable sign-off, record state and supersession, and retention findings.", "Register or author the AI system technical record sibling for EU AI Act Annex IV documentation and the AI evaluation run record, then convert the reference-only bindings into typed edges in the relationship contract.", "Design the compute, energy and emissions measurement structure that the sustainability checklist dimension currently records as an open gap.", "Model agentic and multi-agent composition, tool authority scoping and delegation chains, which the cited sources presently treat only as attack surfaces and autonomy attributes.", "Establish supply-chain attestation structure such as an AI bill of materials and provenance signatures to carry the value-chain risk the sources name but do not structure.", "Add contestation and redress mechanisms for affected persons beyond what the impact analysis and human oversight findings currently hold.", "Close the operating-surface gaps: an operation that records a fired reassessment trigger and sets interim status, a withdraw or void operation distinct from supersession, a capability-tier determination operation, and operations producing the impact assessment and threat model artifacts.", "Obtain independent second-provider corroboration of the aggregate boundary, source set and question surface if the owner-authorized Grok waiver is ever lifted." ] }, "statistics": { "sources": 13, "bundles": 6, "layers": 13, "findings": 28, "questions": 112, "artifacts": 16, "functions": 10 } }