AI Control Checklist

Last updated: 2026-08-14

The AI control checklist sets out which security and governance controls apply at each consequence tier, so that scrutiny is proportional to what happens when a system is wrong. Registration in the model register and recorded data classification of inputs apply at every tier.

Applying every control to every system guarantees that the controls are ignored on the systems that matter. Proportionality is what makes a control set survive contact with delivery pressure.

The template

Apply proportionally to consequence tier.

ControlTier 1Tier 2Tier 3Tier 4
Registered in model registerYesYesYesYes
Data classification of inputs recordedYesYesYesYes
Data path diagramNoYesYesYes
No standing credentials held by modelYesYesYesYes
Authorisation enforced outside the modelYesYesYesYes
Untrusted content marked and de-privilegedYesYesYesYes
Consumption limits and spend alertsYesYesYesYes
Prompt and completion logging with access controlNoYesYesYes
Confirmation required for irreversible actionsNoYesYesYes
Structured red team exercise before go liveNoNoYesYes
Independent review of output quality on live-like dataNoNoYesYes
Tested rollback to prior processNoNoYesYes
Named stopper with withdrawal authorityNoNoYesYes
Re-test triggered by vendor model changeNoNoYesYes

How to use it

  • Read the tier from the model register rather than assigning it separately, so one classification drives everything.
  • Apply the controls marked for that tier as mandatory, and record the exceptions rather than allowing silent omission.
  • Escalate the control set when a system is promoted to a higher tier, which happens whenever its use widens.

This template comes from the AI Security and Assurance: A Practical Playbook, which sets out the reasoning behind it, the rules of thumb that govern its use, and the signals that tell you the approach is failing. The full playbook is also available as Markdown. See all AI governance templates.