AI Control Checklist
The AI control checklist sets out which security and governance controls apply at each consequence tier, so that scrutiny is proportional to what happens when a system is wrong. Registration in the model register and recorded data classification of inputs apply at every tier.
Applying every control to every system guarantees that the controls are ignored on the systems that matter. Proportionality is what makes a control set survive contact with delivery pressure.
The template
Apply proportionally to consequence tier.
| Control | Tier 1 | Tier 2 | Tier 3 | Tier 4 |
|---|---|---|---|---|
| Registered in model register | Yes | Yes | Yes | Yes |
| Data classification of inputs recorded | Yes | Yes | Yes | Yes |
| Data path diagram | No | Yes | Yes | Yes |
| No standing credentials held by model | Yes | Yes | Yes | Yes |
| Authorisation enforced outside the model | Yes | Yes | Yes | Yes |
| Untrusted content marked and de-privileged | Yes | Yes | Yes | Yes |
| Consumption limits and spend alerts | Yes | Yes | Yes | Yes |
| Prompt and completion logging with access control | No | Yes | Yes | Yes |
| Confirmation required for irreversible actions | No | Yes | Yes | Yes |
| Structured red team exercise before go live | No | No | Yes | Yes |
| Independent review of output quality on live-like data | No | No | Yes | Yes |
| Tested rollback to prior process | No | No | Yes | Yes |
| Named stopper with withdrawal authority | No | No | Yes | Yes |
| Re-test triggered by vendor model change | No | No | Yes | Yes |
How to use it
- Read the tier from the model register rather than assigning it separately, so one classification drives everything.
- Apply the controls marked for that tier as mandatory, and record the exceptions rather than allowing silent omission.
- Escalate the control set when a system is promoted to a higher tier, which happens whenever its use widens.
Common questions
What security controls does an AI system need?
Controls should be applied proportionally to consequence tier rather than uniformly. Registration in the model register and recorded data classification of inputs apply at every tier. Higher tiers add progressively stricter requirements. Applying every control to every system guarantees the controls are ignored on the systems where they matter most.