Tier 3: Safety and resilience controls
AI in safety-critical systems
AI used in environments where failures can cause injury, loss of life, major infrastructure disruption, regulatory shutdown, or contract termination.
Board-defensible evidence
- Safety case or hazard analysis documenting plausible failure modes, severity ratings, and mitigations, including who approved the safety assumptions and when they were last reviewed.
- Operational constraints documentation defining where AI is allowed to act autonomously, where it must defer to humans, and what conditions force a safe state.
- Verification and validation evidence showing testing under representative operating conditions, edge-case testing, and documented results reviewed by safety, engineering, and risk leadership.
- Fail-safe and rollback procedures showing how the system is halted or reverted, who can trigger it, how quickly it must happen, and how it is tested periodically.
- Incident reporting and post-event review artifacts showing how near misses and failures are logged, investigated, escalated, and used to update controls and operating limits.
Why this matters
In safety-critical contexts, governance must prove that controls were designed for harm prevention, not just performance optimization.
How ready is your board on safety and resilience controls?
Twelve questions, scored across all four tiers, with your gaps named — or take the whole framework into your next meeting.