Tier 2: Evidence-grade controls
Bias, fairness, and non-discrimination controls
Documented measures to detect, prevent, and remediate discriminatory outcomes in AI systems, especially where decisions affect people, access, or eligibility.
Board-defensible evidence
- Defined fairness objectives tied to the use case, including which protected classes and stakeholder groups are in scope, and why the chosen fairness approach is appropriate for the business context.
- Testing artifacts showing pre-deployment bias evaluation, what datasets were used, what metrics were computed, and how results were reviewed and approved by risk and compliance.
- Ongoing monitoring records showing fairness metrics over time, alert thresholds, and evidence of investigation when drift or disparate impact signals appear.
- Remediation logs showing what changes were made (data rebalancing, threshold adjustments, model changes, policy changes), who authorized them, and what post-fix validation confirmed improvement.
- External or second-line review evidence (legal, compliance, internal audit, or independent reviewer) confirming testing and monitoring are consistent with policy and that exceptions are justified and time-bound.
Why this matters
Discrimination claims convert quickly into regulatory scrutiny and litigation, and the defense depends on what you tested, what you monitored, and what you fixed.
How ready is your board on evidence-grade controls?
Twelve questions, scored across all four tiers, with your gaps named — or take the whole framework into your next meeting.