Tier 3: Safety and resilience controls
Robustness, resilience, and adversarial testing
Testing and controls designed to confirm an AI system remains reliable under stress, unusual inputs, attacks, and changing real-world conditions.
Board-defensible evidence
- Adversarial test plan defining threat scenarios, misuse cases, stress conditions, and acceptance criteria, including who approved the plan and who executed testing.
- Red-team or penetration testing outputs showing findings, severity, reproducibility steps, and documented remediation with retest results and closure dates.
- Resilience controls evidence showing input validation, rate limiting, monitoring for anomalous prompts or inputs, and fail-safe behaviors when the system encounters unknowns.
- Business continuity and recovery artifacts showing how the AI system is maintained during outages, model failures, or dependency failures, including tested recovery procedures.
- Continuous improvement records showing that new threats, incidents, or near misses update the testing program, not just the documentation.
Why this matters
Robustness is a defensibility issue because predictable failure modes that were never tested look like negligence after the fact.
How ready is your board on safety and resilience controls?
Twelve questions, scored across all four tiers, with your gaps named — or take the whole framework into your next meeting.