AIIS · VERSION 1.0

AI-IRF Control Catalogue

The authoritative searchable HTML representation of the public 19-domain, 79-control AIIS register.

Canonical control catalogue

The catalogue below is generated from aiis-control-records-v1.0.json. It contains 79 unique controls across 19 domains. Test vectors and automated conformance objects are future work.

MCP & A2A Protocol Security 7 controls

MCP-1PUBLIC SCHEMA

MCP endpoints SHALL require mutual TLS (mTLS) or workload identity federation. No unauthenticated endpoints permitted.

Minimum tier
T1+
Requirement
preventive
Evidence
configuration_attestation
Regulatory references
DORA Art. 9, NIS2 Art. 21(2)(a)
MCP-2PUBLIC SCHEMA

All MCP message traffic SHALL be inspected at semantic level for injection patterns, malicious skill payloads, or protocol tampering.

Minimum tier
T2+
Requirement
detective
Evidence
log_record
Regulatory references
EU AI Act Art. 15
MCP-3PUBLIC SCHEMA

Unregistered MCP servers SHALL be automatically quarantined upon detection; notifications sent to orchestrator and platform owner within 5 minutes.

Minimum tier
T2+
Requirement
corrective
Evidence
log_record
Regulatory references
NIS2 Art. 21(2)(a)
MCP-4PUBLIC SCHEMA

MCP server manifests SHALL be registered with the agent orchestrator before endpoints go live; unregistered servers blocked at network layer.

Minimum tier
T2+
Requirement
preventive
Evidence
configuration_attestation
Regulatory references
NIS2 Art. 21(2)(a)
A2A-1PUBLIC SCHEMA

Inter-agent authorization SHALL enforce least-privilege action scopes. Policy-as-code enforcement mandatory.

Minimum tier
T1+
Requirement
preventive
Evidence
policy_document
Regulatory references
DORA Art. 9
A2A-2PUBLIC SCHEMA

All inter-agent messages SHALL be cryptographically signed (ECDSA) and integrity-verified before processing. Unsigned or tampered messages SHALL be rejected and logged with SIEM alert.

Minimum tier
T2+
Requirement
preventive
Evidence
signed_artifact
Regulatory references
DORA Art. 9
A2A-3PUBLIC SCHEMA

A2A communication SHALL enforce per-agent-pair rate limits and anomaly detection to prevent agent loop amplification attacks. Circuit-breaker SHALL trigger on >3 anomalies per hour, freezing the amplifying agent and alerting SOC.

Minimum tier
T2+
Requirement
preventive
Evidence
configuration_attestation
Regulatory references
NIS2 Art. 21(2)(a)

Shadow AI & Continuous Visibility 5 controls

SAI-1PUBLIC SCHEMA

Organizations SHALL deploy instance-aware discovery across network edges, SaaS connectors, endpoints, and browser extensions.

Minimum tier
T1+
Requirement
detective
Evidence
log_record
Regulatory references
DORA Art. 8
SAI-2PUBLIC SCHEMA

DLP controls SHALL inspect all AI data egress points for sensitive data exposure.

Minimum tier
T1+
Requirement
preventive
Evidence
log_record
Regulatory references
GDPR Art. 32
SAI-3PUBLIC SCHEMA

Shadow AI instances SHALL be automatically classified into risk tiers (sanctioned/shadow/rogue) within 1 hour of discovery and logged to CMDB.

Minimum tier
T1+
Requirement
detective
Evidence
log_record
Regulatory references
RBI AI Governance Pillar 5
SAI-4PUBLIC SCHEMA

Rogue AI instances SHALL trigger automated quarantine and incident declaration within 15 minutes of classification; AI Security Lead paged automatically.

Minimum tier
T1+
Requirement
corrective
Evidence
log_record
Regulatory references
NIS2 Art. 21(2)(b)
SAI-5PUBLIC SCHEMA

Unauthorised AI deployments classified as rogue SHALL trigger automated SOC alert with risk classification within 5 minutes of rogue designation.

Minimum tier
T1+
Requirement
detective
Evidence
log_record
Regulatory references
NIS2 Art. 21(2)(b)

Adaptive Machine-Speed Response 5 controls

MSR-1PUBLIC SCHEMA

Response frameworks SHALL integrate LLM-as-Judge (LLM-J) metrics for real-time behavioral validation.

Minimum tier
T2+
Requirement
detective
Evidence
log_record
Regulatory references
DORA Art. 10
MSR-2PUBLIC SCHEMA

Playbooks SHALL support conditional branching based on live telemetry deltas.

Minimum tier
T2+
Requirement
corrective
Evidence
configuration_attestation
Regulatory references
DORA Art. 11
MSR-3PUBLIC SCHEMA

Behavioral baselines SHALL trigger automated containment for high-confidence attacks (>95%) without human delay.

Minimum tier
T2+
Requirement
corrective
Evidence
log_record
Regulatory references
NIS2 Art. 21(2)(b)
MSR-4PUBLIC SCHEMA

HITL SHALL be required for actions with blast radius >10 users, financial impact >$10K, or safety-critical involvement.

Minimum tier
T1+
Requirement
governance
Evidence
audit_trail
Regulatory references
EU AI Act Art. 14
MSR-5PUBLIC SCHEMA

MTTC (mean time to containment) for agentic threat events SHALL be 2 seconds or less.

Minimum tier
T2+
Requirement
detective
Evidence
log_record
Regulatory references
DORA Art. 10

Model Extraction & Distillation Defenses 4 controls

MEX-1PUBLIC SCHEMA

Behavioral distillation detection SHALL analyze query patterns for systematic extraction.

Minimum tier
T2+
Requirement
detective
Evidence
log_record
Regulatory references
DORA Art. 9
MEX-2PUBLIC SCHEMA

Dynamic rate limiting SHALL use per-user/session quotas with semantic clustering.

Minimum tier
T2+
Requirement
preventive
Evidence
configuration_attestation
Regulatory references
EU AI Act Art. 15
MEX-3PUBLIC SCHEMA

Cryptographic output perturbation SHALL be applied for high-confidence suspected extraction (>85% similarity).

Minimum tier
T3
Requirement
preventive
Evidence
configuration_attestation
Regulatory references
EU AI Act Art. 15
MEX-4PUBLIC SCHEMA

API key revocation workflow SHALL execute within 5 minutes of confirmed extraction detection.

Minimum tier
T2+
Requirement
corrective
Evidence
log_record
Regulatory references
DORA Art. 9

AI-BOM & Supply Chain Integrity 5 controls

BOM-1PUBLIC SCHEMA

Every production AI system SHALL have a cryptographically signed manifest before deployment.

Minimum tier
T2+
Requirement
preventive
Evidence
signed_artifact
Regulatory references
DORA Art. 28
BOM-2PUBLIC SCHEMA

Training data and model weights SHALL be cryptographically hashed before ingestion.

Minimum tier
T2+
Requirement
preventive
Evidence
log_record
Regulatory references
EU AI Act Art. 10
BOM-3PUBLIC SCHEMA

External data sources SHALL undergo source authenticity checks including vendor attestation.

Minimum tier
T2+
Requirement
preventive
Evidence
policy_document
Regulatory references
DORA Art. 28
BOM-4PUBLIC SCHEMA

Incident playbooks SHALL include supply chain rollback and vendor notification SLA (<=24h).

Minimum tier
T2+
Requirement
governance
Evidence
policy_document
Regulatory references
DORA Art. 28
BOM-5PUBLIC SCHEMA

Runtime BOM validation SHALL occur on every model load; mismatch between loaded model and registered BOM blocks inference.

Minimum tier
T2+
Requirement
preventive
Evidence
log_record
Regulatory references
GDPR Art. 25

Agentic Permission Architecture 5 controls

APA-1PUBLIC SCHEMA

Pre-execution validation gates SHALL enforce policy checks before any consequential action.

Minimum tier
T1+
Requirement
preventive
Evidence
configuration_attestation
Regulatory references
EU AI Act Art. 9
APA-2PUBLIC SCHEMA

Agents SHALL operate under least-privilege, task-scoped permissions with auto-expiration (<=15 min).

Minimum tier
T1+
Requirement
preventive
Evidence
configuration_attestation
Regulatory references
GDPR Art. 25
APA-3PUBLIC SCHEMA

HITL SHALL be required for: data export >1K records, payment initiation, production delete, PII access, safety override.

Minimum tier
T1+
Requirement
governance
Evidence
audit_trail
Regulatory references
GDPR Art. 22
APA-4PUBLIC SCHEMA

All permission grants, denials, and overrides SHALL be logged with immutable timestamps and cryptographic signing.

Minimum tier
T1+
Requirement
governance
Evidence
audit_trail
Regulatory references
MAS FEAT Accountability
APA-5PUBLIC SCHEMA

Tool use SHALL require a pre-execution approval gate, separate from the general APA-1 action validation gate, specific to tool invocation.

Minimum tier
T1+
Requirement
preventive
Evidence
configuration_attestation
Regulatory references
DORA Art. 9

Regulatory & Compliance Operations 4 controls

REG-1PUBLIC SCHEMA

Incident playbooks SHALL include a regulatory notification decision tree.

Minimum tier
T1+
Requirement
governance
Evidence
policy_document
Regulatory references
DORA Art. 6
REG-2PUBLIC SCHEMA

Legal and Compliance SHALL be embedded as Consulted/Accountable roles in initial triage within 1 hour.

Minimum tier
T1+
Requirement
governance
Evidence
audit_trail
Regulatory references
DORA Art. 6
REG-3PUBLIC SCHEMA

Organizations SHALL maintain incident-to-regulation mapping tables reviewed quarterly.

Minimum tier
T2+
Requirement
governance
Evidence
policy_document
Regulatory references
DORA Art. 6
REG-4PUBLIC SCHEMA

Audit-ready documentation SHALL be preserved with cryptographic integrity for minimum 3 years.

Minimum tier
T2+
Requirement
governance
Evidence
audit_trail
Regulatory references
DORA Art. 6

Physical AI & Safety Integration 4 controls

PHY-1PUBLIC SCHEMA

Separate incident playbooks SHALL exist for physical-harm scenarios.

Minimum tier
T3
Requirement
governance
Evidence
policy_document
Regulatory references
NIS2 Art. 21(2)(c)
PHY-2PUBLIC SCHEMA

Safety and cybersecurity teams SHALL operate in integrated incident command structures.

Minimum tier
T3
Requirement
governance
Evidence
policy_document
Regulatory references
NIS2 Art. 21(2)(c)
PHY-3PUBLIC SCHEMA

Systems SHALL mandate fail-safe fallback modes upon cyber anomaly detection.

Minimum tier
T3
Requirement
preventive
Evidence
test_report
Regulatory references
IEC 62443 FR 7
PHY-4PUBLIC SCHEMA

Hardware-rooted trust SHALL default to human oversight if cryptographic attestation fails.

Minimum tier
T3
Requirement
preventive
Evidence
configuration_attestation
Regulatory references
IEC 62443 FR 1

Model Lifecycle Security 5 controls

MLC-1PUBLIC SCHEMA

Every production model SHALL have a unique immutable identifier and cryptographic signature.

Minimum tier
T2+
Requirement
governance
Evidence
configuration_attestation
Regulatory references
DORA Art. 8
MLC-2PUBLIC SCHEMA

Automated rollback capability SHALL execute within 15 minutes of compromise detection.

Minimum tier
T3
Requirement
corrective
Evidence
log_record
Regulatory references
DORA Art. 11
MLC-3PUBLIC SCHEMA

Recovery playbooks SHALL include rollback validation gates confirming integrity, performance, and adversarial robustness.

Minimum tier
T2+
Requirement
governance
Evidence
policy_document
Regulatory references
FDA SaMD TPLC
MLC-4PUBLIC SCHEMA

Model version changes SHALL be logged in immutable audit trail with dual approval.

Minimum tier
T2+
Requirement
governance
Evidence
audit_trail
Regulatory references
DORA Art. 9
MLC-5PUBLIC SCHEMA

Drift detection thresholds SHALL trigger a dual-approval retraining workflow; retraining without dual approval is blocked.

Minimum tier
T2+
Requirement
governance
Evidence
audit_trail
Regulatory references
RBI AI Governance Pillar 5

Zero Trust Architecture for AI (ZTAI) 4 controls

ZTA-1PUBLIC SCHEMA

AI infrastructure SHALL adopt explicit zero-trust design with documented architecture reviewed at least annually.

Minimum tier
T2+
Requirement
preventive
Evidence
configuration_attestation
Regulatory references
DORA Art. 9
ZTA-2PUBLIC SCHEMA

Continuous verification SHALL require re-authentication every 15 minutes or per high-risk action; no persistent sessions permitted.

Minimum tier
T2+
Requirement
preventive
Evidence
configuration_attestation
Regulatory references
HIPAA Security Rule
ZTA-3PUBLIC SCHEMA

Micro-segmentation SHALL isolate inference, vector storage, and orchestration layers with explicit allow-lists enforced in policy-as-code.

Minimum tier
T2+
Requirement
preventive
Evidence
configuration_attestation
Regulatory references
NIS2 Art. 21(2)(a)
ZTA-4PUBLIC SCHEMA

Runtime least-privilege enforcement SHALL include per-request authorization for tool execution with full audit trail.

Minimum tier
T2+
Requirement
preventive
Evidence
configuration_attestation
Regulatory references
NIS2 Art. 21(2)(a)

Detection Reliability 3 controls

REL-1PUBLIC SCHEMA

Auto-containment SHALL require >=3 ensemble signals, agreement >=0.7

Minimum tier
T2+
Requirement
governance
Evidence
log_record
Regulatory references
EU AI Act Art. 15 (accuracy, robustness, cybersecurity), DORA Art. 10 (detection capability)
REL-2PUBLIC SCHEMA

Confidence scores SHALL decay 10% per consecutive similar alert

Minimum tier
T2+
Requirement
governance
Evidence
log_record
Regulatory references
DORA Art. 10 (detection quality)
REL-3PUBLIC SCHEMA

Circuit-breaker SHALL disable automation after 3 FP within 1h

Minimum tier
T2+
Requirement
governance
Evidence
log_record
Regulatory references
DORA Art. 10 (detection reliability)

Agentic Threat Detection 3 controls

APT-1PUBLIC SCHEMA

Prompt injection detection >=90% across all channels

Minimum tier
T2+
Requirement
detective
Evidence
log_record
Regulatory references
NIS2 Art. 21(2)(b) (incident handling), NCSC AI Security Principle 2
APT-2PUBLIC SCHEMA

Tool abuse prevention via pre-execution gate on every tool call

Minimum tier
T1+
Requirement
detective
Evidence
log_record
Regulatory references
NIS2 Art. 21(2)(b)
APT-3PUBLIC SCHEMA

Memory poisoning detection with automated quarantine <=60s

Minimum tier
T2+
Requirement
detective
Evidence
log_record
Regulatory references
NIS2 Art. 21(2)(b)

Severity Classification 2 controls

SEV-CLSPUBLIC SCHEMA

Deterministic severity scoring algorithm implemented and versioned

Minimum tier
T1+
Requirement
governance
Evidence
configuration_attestation
Regulatory references
DORA Art. 10 (incident classification), NIS2 Art. 23 (significant incident determination)
SEV-RPTPUBLIC SCHEMA

Reportability thresholds evaluated deterministically

Minimum tier
T1+
Requirement
governance
Evidence
configuration_attestation
Regulatory references
DORA Art. 19 (major incident reporting), GDPR Art. 33 (breach notification), NIS2 Art. 23 (incident reporting)

Content Safety 7 controls

CSS-1PUBLIC SCHEMA

Harmful content detection pipeline SHALL achieve >99.9% block rate for CSAM (zero-tolerance); alert and log all blocked outputs.

Minimum tier
T1+
Requirement
preventive
Evidence
test_report
Regulatory references
EU AI Act Art. 5
CSS-2PUBLIC SCHEMA

Maintain a sufficiently detailed summary of content used to train the GPAI model, published per EU AI Act Art. 53(1)(c) template requirements. Implement output filtering to detect verbatim or near-ver

Minimum tier
T2+
Requirement
governance
Evidence
policy_document
Regulatory references
EU AI Act Art. 53(1)(c)
CSS-3PUBLIC SCHEMA

AI-generated synthetic media SHALL carry machine-readable provenance marker (C2PA recommended) and human-facing disclosure label.

Minimum tier
T1+
Requirement
preventive
Evidence
configuration_attestation
Regulatory references
EU AI Act Art. 50
CSS-4PUBLIC SCHEMA

Design review SHALL confirm the AI system does not employ subliminal techniques (content presented below the threshold of conscious perception) or techniques designed to exploit known vulnerabilities of specific groups to materially distort behaviour.

Minimum tier
T2+
Requirement
preventive
Evidence
test_report
Regulatory references
EU AI Act Art. 5(1)(b)
CSS-5PUBLIC SCHEMA

Monthly statistical analysis of AI outputs across protected demographic groups

Minimum tier
T1+
Requirement
detective
Evidence
test_report
Regulatory references
EU AI Act Art. 10(2)(f)
CSS-6PUBLIC SCHEMA

Conduct a quarterly Demographic Impact Assessment (DIA) for all high-risk AI systems. The DIA

Minimum tier
T2+
Requirement
detective
Evidence
test_report
Regulatory references
EU AI Act Art. 9(7)
CSS-7PUBLIC SCHEMA

Tier 1 + documented vulnerable population impact assessment, conducted alongside CSS-6's DIA, specifically evaluating outcomes for identified vulnerable groups rather than aggregate demographic catego

Minimum tier
T1+
Requirement
preventive
Evidence
test_report
Regulatory references
EU AI Act Art. 5(1)(b)

Federated Learning Security 4 controls

FL-1PUBLIC SCHEMA

Federated clients authenticated via mutual TLS with client-specific certificates; unregistered/revoked clients rejected.

Minimum tier
T2+
Requirement
preventive
Evidence
configuration_attestation
Regulatory references
GDPR Art. 25
FL-2PUBLIC SCHEMA

Byzantine-robust aggregation (FedAvg with clipping; Krum/Bulyan for high-threat); gradients >3 sigma from epoch mean flagged; clients with anomaly rate >5% rejected.

Minimum tier
T2+
Requirement
detective
Evidence
log_record
Regulatory references
DORA Art. 28, GDPR Art. 32
FL-3PUBLIC SCHEMA

Differential privacy (DP-SGD) applied; epsilon <=1 for high-sensitivity data, epsilon <=8 maximum ceiling for lower-sensitivity data; epsilon=10 not recommended for production.

Minimum tier
T2+
Requirement
preventive
Evidence
configuration_attestation
Regulatory references
India DPDP Sec. 4
FL-4PUBLIC SCHEMA

Global model signed with ECDSA (or CRYSTALS-Dilithium per PQC-1) after each aggregation round; signed checkpoint stored in AI-BOM registry.

Minimum tier
T2+
Requirement
preventive
Evidence
signed_artifact
Regulatory references
GDPR Art. 32

Model Merge Defense 3 controls

MMD-1PUBLIC SCHEMA

Pre-merge source model vetting: AI-BOM provenance, absence of known malicious fine-tuning datasets, training data manifest completeness verified; incomplete provenance rejected.

Minimum tier
T2+
Requirement
preventive
Evidence
signed_artifact
Regulatory references
DORA Art. 28
MMD-2PUBLIC SCHEMA

Post-merge backdoor scan (Neural Cleanse or ABS); semantic consistency testing across 500+ prompt templates; embedding space anomaly analysis.

Minimum tier
T2+
Requirement
detective
Evidence
test_report
Regulatory references
EU AI Act Art. 15
MMD-3PUBLIC SCHEMA

Model merge operations performed in isolated compute environment with no internet access; all artifacts hash-verified entering and leaving.

Minimum tier
T2+
Requirement
preventive
Evidence
configuration_attestation
Regulatory references
EU AI Act Art. 15

Quantization Security 3 controls

QBS-1PUBLIC SCHEMA

Pre-quantization behavioural baseline established on 1,000+ representative inputs; stored as signed artefact in AI-BOM.

Minimum tier
T2+
Requirement
preventive
Evidence
signed_artifact
Regulatory references
DORA Art. 28
QBS-2PUBLIC SCHEMA

Post-quantization differential analysis against baseline; divergence >5% flagged; divergence >10% rejects model.

Minimum tier
T2+
Requirement
detective
Evidence
test_report
Regulatory references
DORA Art. 28
QBS-3PUBLIC SCHEMA

Only trusted, audited quantization toolchains used (ONNX Runtime, TensorRT, PyTorch quantization); toolchain integrity hash-verified; third-party pre-quantized models screened via QBS-1/QBS-2.

Minimum tier
T2+
Requirement
preventive
Evidence
signed_artifact
Regulatory references
DORA Art. 28

Hallucination Detection 5 controls

HAL-1PUBLIC SCHEMA

RAG factual grounding verification: all factual claims grounded in retrieved source documents; citation extraction and source verification; ungrounded claims flagged for human review.

Minimum tier
T1+
Requirement
detective
Evidence
log_record
Regulatory references
EU AI Act Art. 13
HAL-2PUBLIC SCHEMA

Model confidence scoring implemented; outputs below 0.7 confidence for consequential decisions require human review before action; uncertainty surfaced to end users.

Minimum tier
T2+
Requirement
governance
Evidence
configuration_attestation
Regulatory references
EU AI Act Art. 15
HAL-3PUBLIC SCHEMA

For high-stakes outputs (medical, legal, financial, safety-critical): parallel inference with second model or rule-based verifier; inconsistencies >10% divergence flagged for human review.

Minimum tier
T2+
Requirement
detective
Evidence
log_record
Regulatory references
EU AI Act Art. 15
HAL-4PUBLIC SCHEMA

Hallucination rate tracked via human correction feedback loop; alert at >3% of evaluated outputs; escalate to AI-IRF corrective action at >5% (trust_erosion_rate threshold).

Minimum tier
T1+
Requirement
detective
Evidence
log_record
Regulatory references
RBI AI Governance Pillar 3
HAL-5PUBLIC SCHEMA

For regulated domains (medical diagnosis, legal analysis, financial advice): external fact-checking API or knowledge graph verification integrated for domain-specific claims.

Minimum tier
T2+
Requirement
preventive
Evidence
configuration_attestation
Regulatory references
FDA SaMD GMLP

Post-Quantum Cryptography 1 controls

PQC-1PUBLIC SCHEMA

PQC readiness assessment SHALL be completed covering BOM-4, MCP-1, A2A-2, and REG-4 cryptographic use cases. Migration to CRYSTALS-Dilithium (BOM-4, A2A-2) at Tier 3 from Q1 2027; hybrid Kyber-1024 (MCP-1) from Q3 2027; hybrid ECDSA+Dilithium (REG-4, all tiers) from Q3 2027.

Minimum tier
T3+
Requirement
preventive
Evidence
configuration_attestation
Regulatory references
NIS2 Art. 21(2)(a), DORA Art. 9

Machine-readable source

Download the canonical JSON control register →

Scope boundary

This catalogue communicates normative control records. It does not include test vectors, certification decisions or permission to use certification marks.