All 25 terms

Tier 1: Foundation controls

AI system risk classification

A formal method for categorizing AI systems by risk level, so controls, approvals, and obligations match the impact of the use case.

Board-defensible evidence

Why this matters

In enforcement or litigation, an inconsistent or undocumented classification process becomes evidence that the organization did not exercise credible oversight over AI risk.

How ready is your board on foundation controls?

Twelve questions, scored across all four tiers, with your gaps named — or take the whole framework into your next meeting.

Take the readiness check