All 25 terms

Tier 1: Foundation controls

AI risk appetite and tolerance

Board-approved boundaries that define which AI risks are acceptable, which are constrained, and which are not permitted, with measurable thresholds for decision-making.

Board-defensible evidence

Why this matters

In enforcement or litigation, the gap between stated appetite and actual approvals becomes discoverable evidence of oversight failure.

How ready is your board on foundation controls?

Twelve questions, scored across all four tiers, with your gaps named — or take the whole framework into your next meeting.

Take the readiness check