Table 2: AI Governance & Oversight
ViewTable 2: Model Risk Management
ViewTable 2: Investment Advice & Suitability
ViewTable 2: Market Risks
ViewTable 2: System Reliability & Business Continuity Planning
ViewTable 2: Cybersecurity & Data Privacy/Protection
ViewRisks
AIR-SEC-010Prompt Injection
AIR-RC-001Information Leaked To Hosted Model
AIR-SEC-026MCP Server Supply Chain Compromise
AIR-SEC-027Agent State Persistence Poisoning
AIR-SEC-029Agent-Mediated Credential Discovery and Harvesting
AIR-SEC-002Information Leaked to Vector Store
AIR-SEC-008Tampering With the Foundational Model
AIR-SEC-009Data Poisoning
Mitigations
AIR-PREV-012Role-Based Access Control for AI Data
AIR-PREV-014Encryption of AI Data at Rest
AIR-DET-016Preserving Source Data Access Controls in AI Systems
AIR-PREV-017AI Firewall Implementation and Management
AIR-DET-001AI Data Leakage Prevention and Detection
AIR-PREV-022Multi-Agent Isolation and Segmentation
AIR-PREV-023Agentic System Credential Protection Framework
AIR-PREV-003User/App/Model Firewalling/Filtering
Table 2: Outsourcing & Third-Party Dependencies
ViewTable 2: Disclosure & Transparency
ViewTable 2: Recordkeeping & Audit Trail
ViewTable 3.1: Oversight from Board or Governing Body
ViewTable 3.2: Senior Management Responsibilities
ViewTable 3.3: AI Risk Management Systems, Policies and Procedures
ViewTable 3.4: Data Governance
ViewRisks
Table 3.5: Risk Management of Advanced AI Systems
ViewRisks
AIR-SEC-010Prompt Injection
AIR-OP-014Inadequate System Alignment
AIR-OP-018Model Overreach / Expanded Use
AIR-SEC-024Agent Action Authorization Bypass
AIR-SEC-025Tool Chain Manipulation and Injection
AIR-SEC-026MCP Server Supply Chain Compromise
AIR-SEC-027Agent State Persistence Poisoning
AIR-OP-028Multi-Agent Trust Boundary Violations
AIR-SEC-029Agent-Mediated Credential Discovery and Harvesting
AIR-OP-006Non-Deterministic Behaviour
Table 3.6: AI Model Validation, Testing and Monitoring
ViewRisks
Table 3.7: Controls and Human Oversight of AI Systems
ViewRisks
Table 4.1: Assessment of Risk-Proportionate Controls
ViewTable 4.2: Transparency Measures
ViewTable 4.3: Fairness Due Diligence Assessment
ViewTable 4.4: Supply Chain Risk Assessment
ViewRisks
Table 4.5: Concentration Risk
ViewTable 4.6: Contingency Planning
ViewTable 4.7: Legal Framework and Accountability
ViewTable 4.9: Use of Complex AI Products
ViewTable 5.1: Disclosure of AI Use in Products and Services to End-Users
ViewTable 5.2: AI Governance and Strategy Disclosures
ViewTable 5.4: Identifying Misleading Claims
ViewTable 6.1: Documentation of AI Lifecycle Oversight
ViewTable 6.3: Documentation of AI-Generated Outcomes
ViewTable 6.4: Documentation of Explainability of AI Outputs
ViewTable 6.5: Records on Incidents Relating to AI Products or Services
ViewRisks
Table 6.6: Reporting
ViewTable 7: AI Adoption Indicators
ViewMitigations
Table 7: Nature and Use Cases of AI Systems
ViewMitigations