Tier 2: Evidence-grade controls
Technical and organizational measures (TOMs) for AI
Practical controls, both technical and procedural, that reduce AI risks and demonstrate responsible operation across people, process, and technology.
Board-defensible evidence
- Control catalog mapping TOMs to specific risks (privacy, security, discrimination, safety, integrity), including which TOMs are mandatory by risk tier and who owns implementation.
- Implementation evidence such as configuration baselines, security control settings, access controls, monitoring configurations, and documented procedures for approvals and reviews.
- Control testing results showing whether TOMs operate effectively, including sampling approach, testing dates, identified gaps, and remediation confirmation.
- Organizational readiness records such as training completion, role-based access approval, and documented operational procedures for incident response and change control.
- Exception process evidence showing compensating controls, approval authority, expiry dates, and periodic reassessment of exceptions that weaken baseline TOMs.
Why this matters
Regulators do not grade intentions, they evaluate whether controls were implemented, tested, and enforced.
How ready is your board on evidence-grade controls?
Twelve questions, scored across all four tiers, with your gaps named — or take the whole framework into your next meeting.