AIIS · VERSION 1.0
AI-IRF Control Catalogue
The authoritative searchable HTML representation of the public 19-domain, 79-control AIIS register.
Canonical control catalogue
The catalogue below is generated from aiis-control-records-v1.0.json. It contains 79 unique controls across 19 domains. Test vectors and automated conformance objects are future work.
MCP & A2A Protocol Security 7 controls
MCP-1PUBLIC SCHEMA
MCP endpoints SHALL require mutual TLS (mTLS) or workload identity federation. No unauthenticated endpoints permitted.
- Minimum tier
- T1+
- Requirement
- preventive
- Evidence
- configuration_attestation
- Regulatory references
- DORA Art. 9, NIS2 Art. 21(2)(a)
MCP-2PUBLIC SCHEMA
All MCP message traffic SHALL be inspected at semantic level for injection patterns, malicious skill payloads, or protocol tampering.
- Minimum tier
- T2+
- Requirement
- detective
- Evidence
- log_record
- Regulatory references
- EU AI Act Art. 15
MCP-3PUBLIC SCHEMA
Unregistered MCP servers SHALL be automatically quarantined upon detection; notifications sent to orchestrator and platform owner within 5 minutes.
- Minimum tier
- T2+
- Requirement
- corrective
- Evidence
- log_record
- Regulatory references
- NIS2 Art. 21(2)(a)
MCP-4PUBLIC SCHEMA
MCP server manifests SHALL be registered with the agent orchestrator before endpoints go live; unregistered servers blocked at network layer.
- Minimum tier
- T2+
- Requirement
- preventive
- Evidence
- configuration_attestation
- Regulatory references
- NIS2 Art. 21(2)(a)
A2A-1PUBLIC SCHEMA
Inter-agent authorization SHALL enforce least-privilege action scopes. Policy-as-code enforcement mandatory.
- Minimum tier
- T1+
- Requirement
- preventive
- Evidence
- policy_document
- Regulatory references
- DORA Art. 9
A2A-2PUBLIC SCHEMA
All inter-agent messages SHALL be cryptographically signed (ECDSA) and integrity-verified before processing. Unsigned or tampered messages SHALL be rejected and logged with SIEM alert.
- Minimum tier
- T2+
- Requirement
- preventive
- Evidence
- signed_artifact
- Regulatory references
- DORA Art. 9
A2A-3PUBLIC SCHEMA
A2A communication SHALL enforce per-agent-pair rate limits and anomaly detection to prevent agent loop amplification attacks. Circuit-breaker SHALL trigger on >3 anomalies per hour, freezing the amplifying agent and alerting SOC.
- Minimum tier
- T2+
- Requirement
- preventive
- Evidence
- configuration_attestation
- Regulatory references
- NIS2 Art. 21(2)(a)
Shadow AI & Continuous Visibility 5 controls
SAI-1PUBLIC SCHEMA
Organizations SHALL deploy instance-aware discovery across network edges, SaaS connectors, endpoints, and browser extensions.
- Minimum tier
- T1+
- Requirement
- detective
- Evidence
- log_record
- Regulatory references
- DORA Art. 8
SAI-2PUBLIC SCHEMA
DLP controls SHALL inspect all AI data egress points for sensitive data exposure.
- Minimum tier
- T1+
- Requirement
- preventive
- Evidence
- log_record
- Regulatory references
- GDPR Art. 32
SAI-3PUBLIC SCHEMA
Shadow AI instances SHALL be automatically classified into risk tiers (sanctioned/shadow/rogue) within 1 hour of discovery and logged to CMDB.
- Minimum tier
- T1+
- Requirement
- detective
- Evidence
- log_record
- Regulatory references
- RBI AI Governance Pillar 5
SAI-4PUBLIC SCHEMA
Rogue AI instances SHALL trigger automated quarantine and incident declaration within 15 minutes of classification; AI Security Lead paged automatically.
- Minimum tier
- T1+
- Requirement
- corrective
- Evidence
- log_record
- Regulatory references
- NIS2 Art. 21(2)(b)
SAI-5PUBLIC SCHEMA
Unauthorised AI deployments classified as rogue SHALL trigger automated SOC alert with risk classification within 5 minutes of rogue designation.
- Minimum tier
- T1+
- Requirement
- detective
- Evidence
- log_record
- Regulatory references
- NIS2 Art. 21(2)(b)
Adaptive Machine-Speed Response 5 controls
MSR-1PUBLIC SCHEMA
Response frameworks SHALL integrate LLM-as-Judge (LLM-J) metrics for real-time behavioral validation.
- Minimum tier
- T2+
- Requirement
- detective
- Evidence
- log_record
- Regulatory references
- DORA Art. 10
MSR-2PUBLIC SCHEMA
Playbooks SHALL support conditional branching based on live telemetry deltas.
- Minimum tier
- T2+
- Requirement
- corrective
- Evidence
- configuration_attestation
- Regulatory references
- DORA Art. 11
MSR-3PUBLIC SCHEMA
Behavioral baselines SHALL trigger automated containment for high-confidence attacks (>95%) without human delay.
- Minimum tier
- T2+
- Requirement
- corrective
- Evidence
- log_record
- Regulatory references
- NIS2 Art. 21(2)(b)
MSR-4PUBLIC SCHEMA
HITL SHALL be required for actions with blast radius >10 users, financial impact >$10K, or safety-critical involvement.
- Minimum tier
- T1+
- Requirement
- governance
- Evidence
- audit_trail
- Regulatory references
- EU AI Act Art. 14
MSR-5PUBLIC SCHEMA
MTTC (mean time to containment) for agentic threat events SHALL be 2 seconds or less.
- Minimum tier
- T2+
- Requirement
- detective
- Evidence
- log_record
- Regulatory references
- DORA Art. 10
Model Extraction & Distillation Defenses 4 controls
MEX-1PUBLIC SCHEMA
Behavioral distillation detection SHALL analyze query patterns for systematic extraction.
- Minimum tier
- T2+
- Requirement
- detective
- Evidence
- log_record
- Regulatory references
- DORA Art. 9
MEX-2PUBLIC SCHEMA
Dynamic rate limiting SHALL use per-user/session quotas with semantic clustering.
- Minimum tier
- T2+
- Requirement
- preventive
- Evidence
- configuration_attestation
- Regulatory references
- EU AI Act Art. 15
MEX-3PUBLIC SCHEMA
Cryptographic output perturbation SHALL be applied for high-confidence suspected extraction (>85% similarity).
- Minimum tier
- T3
- Requirement
- preventive
- Evidence
- configuration_attestation
- Regulatory references
- EU AI Act Art. 15
MEX-4PUBLIC SCHEMA
API key revocation workflow SHALL execute within 5 minutes of confirmed extraction detection.
- Minimum tier
- T2+
- Requirement
- corrective
- Evidence
- log_record
- Regulatory references
- DORA Art. 9
AI-BOM & Supply Chain Integrity 5 controls
BOM-1PUBLIC SCHEMA
Every production AI system SHALL have a cryptographically signed manifest before deployment.
- Minimum tier
- T2+
- Requirement
- preventive
- Evidence
- signed_artifact
- Regulatory references
- DORA Art. 28
BOM-2PUBLIC SCHEMA
Training data and model weights SHALL be cryptographically hashed before ingestion.
- Minimum tier
- T2+
- Requirement
- preventive
- Evidence
- log_record
- Regulatory references
- EU AI Act Art. 10
BOM-3PUBLIC SCHEMA
External data sources SHALL undergo source authenticity checks including vendor attestation.
- Minimum tier
- T2+
- Requirement
- preventive
- Evidence
- policy_document
- Regulatory references
- DORA Art. 28
BOM-4PUBLIC SCHEMA
Incident playbooks SHALL include supply chain rollback and vendor notification SLA (<=24h).
- Minimum tier
- T2+
- Requirement
- governance
- Evidence
- policy_document
- Regulatory references
- DORA Art. 28
BOM-5PUBLIC SCHEMA
Runtime BOM validation SHALL occur on every model load; mismatch between loaded model and registered BOM blocks inference.
- Minimum tier
- T2+
- Requirement
- preventive
- Evidence
- log_record
- Regulatory references
- GDPR Art. 25
Agentic Permission Architecture 5 controls
APA-1PUBLIC SCHEMA
Pre-execution validation gates SHALL enforce policy checks before any consequential action.
- Minimum tier
- T1+
- Requirement
- preventive
- Evidence
- configuration_attestation
- Regulatory references
- EU AI Act Art. 9
APA-2PUBLIC SCHEMA
Agents SHALL operate under least-privilege, task-scoped permissions with auto-expiration (<=15 min).
- Minimum tier
- T1+
- Requirement
- preventive
- Evidence
- configuration_attestation
- Regulatory references
- GDPR Art. 25
APA-3PUBLIC SCHEMA
HITL SHALL be required for: data export >1K records, payment initiation, production delete, PII access, safety override.
- Minimum tier
- T1+
- Requirement
- governance
- Evidence
- audit_trail
- Regulatory references
- GDPR Art. 22
APA-4PUBLIC SCHEMA
All permission grants, denials, and overrides SHALL be logged with immutable timestamps and cryptographic signing.
- Minimum tier
- T1+
- Requirement
- governance
- Evidence
- audit_trail
- Regulatory references
- MAS FEAT Accountability
APA-5PUBLIC SCHEMA
Tool use SHALL require a pre-execution approval gate, separate from the general APA-1 action validation gate, specific to tool invocation.
- Minimum tier
- T1+
- Requirement
- preventive
- Evidence
- configuration_attestation
- Regulatory references
- DORA Art. 9
Regulatory & Compliance Operations 4 controls
REG-1PUBLIC SCHEMA
Incident playbooks SHALL include a regulatory notification decision tree.
- Minimum tier
- T1+
- Requirement
- governance
- Evidence
- policy_document
- Regulatory references
- DORA Art. 6
REG-2PUBLIC SCHEMA
Legal and Compliance SHALL be embedded as Consulted/Accountable roles in initial triage within 1 hour.
- Minimum tier
- T1+
- Requirement
- governance
- Evidence
- audit_trail
- Regulatory references
- DORA Art. 6
REG-3PUBLIC SCHEMA
Organizations SHALL maintain incident-to-regulation mapping tables reviewed quarterly.
- Minimum tier
- T2+
- Requirement
- governance
- Evidence
- policy_document
- Regulatory references
- DORA Art. 6
REG-4PUBLIC SCHEMA
Audit-ready documentation SHALL be preserved with cryptographic integrity for minimum 3 years.
- Minimum tier
- T2+
- Requirement
- governance
- Evidence
- audit_trail
- Regulatory references
- DORA Art. 6
Physical AI & Safety Integration 4 controls
PHY-1PUBLIC SCHEMA
Separate incident playbooks SHALL exist for physical-harm scenarios.
- Minimum tier
- T3
- Requirement
- governance
- Evidence
- policy_document
- Regulatory references
- NIS2 Art. 21(2)(c)
PHY-2PUBLIC SCHEMA
Safety and cybersecurity teams SHALL operate in integrated incident command structures.
- Minimum tier
- T3
- Requirement
- governance
- Evidence
- policy_document
- Regulatory references
- NIS2 Art. 21(2)(c)
PHY-3PUBLIC SCHEMA
Systems SHALL mandate fail-safe fallback modes upon cyber anomaly detection.
- Minimum tier
- T3
- Requirement
- preventive
- Evidence
- test_report
- Regulatory references
- IEC 62443 FR 7
PHY-4PUBLIC SCHEMA
Hardware-rooted trust SHALL default to human oversight if cryptographic attestation fails.
- Minimum tier
- T3
- Requirement
- preventive
- Evidence
- configuration_attestation
- Regulatory references
- IEC 62443 FR 1
Model Lifecycle Security 5 controls
MLC-1PUBLIC SCHEMA
Every production model SHALL have a unique immutable identifier and cryptographic signature.
- Minimum tier
- T2+
- Requirement
- governance
- Evidence
- configuration_attestation
- Regulatory references
- DORA Art. 8
MLC-2PUBLIC SCHEMA
Automated rollback capability SHALL execute within 15 minutes of compromise detection.
- Minimum tier
- T3
- Requirement
- corrective
- Evidence
- log_record
- Regulatory references
- DORA Art. 11
MLC-3PUBLIC SCHEMA
Recovery playbooks SHALL include rollback validation gates confirming integrity, performance, and adversarial robustness.
- Minimum tier
- T2+
- Requirement
- governance
- Evidence
- policy_document
- Regulatory references
- FDA SaMD TPLC
MLC-4PUBLIC SCHEMA
Model version changes SHALL be logged in immutable audit trail with dual approval.
- Minimum tier
- T2+
- Requirement
- governance
- Evidence
- audit_trail
- Regulatory references
- DORA Art. 9
MLC-5PUBLIC SCHEMA
Drift detection thresholds SHALL trigger a dual-approval retraining workflow; retraining without dual approval is blocked.
- Minimum tier
- T2+
- Requirement
- governance
- Evidence
- audit_trail
- Regulatory references
- RBI AI Governance Pillar 5
Zero Trust Architecture for AI (ZTAI) 4 controls
ZTA-1PUBLIC SCHEMA
AI infrastructure SHALL adopt explicit zero-trust design with documented architecture reviewed at least annually.
- Minimum tier
- T2+
- Requirement
- preventive
- Evidence
- configuration_attestation
- Regulatory references
- DORA Art. 9
ZTA-2PUBLIC SCHEMA
Continuous verification SHALL require re-authentication every 15 minutes or per high-risk action; no persistent sessions permitted.
- Minimum tier
- T2+
- Requirement
- preventive
- Evidence
- configuration_attestation
- Regulatory references
- HIPAA Security Rule
ZTA-3PUBLIC SCHEMA
Micro-segmentation SHALL isolate inference, vector storage, and orchestration layers with explicit allow-lists enforced in policy-as-code.
- Minimum tier
- T2+
- Requirement
- preventive
- Evidence
- configuration_attestation
- Regulatory references
- NIS2 Art. 21(2)(a)
ZTA-4PUBLIC SCHEMA
Runtime least-privilege enforcement SHALL include per-request authorization for tool execution with full audit trail.
- Minimum tier
- T2+
- Requirement
- preventive
- Evidence
- configuration_attestation
- Regulatory references
- NIS2 Art. 21(2)(a)
Detection Reliability 3 controls
REL-1PUBLIC SCHEMA
Auto-containment SHALL require >=3 ensemble signals, agreement >=0.7
- Minimum tier
- T2+
- Requirement
- governance
- Evidence
- log_record
- Regulatory references
- EU AI Act Art. 15 (accuracy, robustness, cybersecurity), DORA Art. 10 (detection capability)
REL-2PUBLIC SCHEMA
Confidence scores SHALL decay 10% per consecutive similar alert
- Minimum tier
- T2+
- Requirement
- governance
- Evidence
- log_record
- Regulatory references
- DORA Art. 10 (detection quality)
REL-3PUBLIC SCHEMA
Circuit-breaker SHALL disable automation after 3 FP within 1h
- Minimum tier
- T2+
- Requirement
- governance
- Evidence
- log_record
- Regulatory references
- DORA Art. 10 (detection reliability)
Agentic Threat Detection 3 controls
APT-1PUBLIC SCHEMA
Prompt injection detection >=90% across all channels
- Minimum tier
- T2+
- Requirement
- detective
- Evidence
- log_record
- Regulatory references
- NIS2 Art. 21(2)(b) (incident handling), NCSC AI Security Principle 2
APT-2PUBLIC SCHEMA
Tool abuse prevention via pre-execution gate on every tool call
- Minimum tier
- T1+
- Requirement
- detective
- Evidence
- log_record
- Regulatory references
- NIS2 Art. 21(2)(b)
APT-3PUBLIC SCHEMA
Memory poisoning detection with automated quarantine <=60s
- Minimum tier
- T2+
- Requirement
- detective
- Evidence
- log_record
- Regulatory references
- NIS2 Art. 21(2)(b)
Severity Classification 2 controls
SEV-CLSPUBLIC SCHEMA
Deterministic severity scoring algorithm implemented and versioned
- Minimum tier
- T1+
- Requirement
- governance
- Evidence
- configuration_attestation
- Regulatory references
- DORA Art. 10 (incident classification), NIS2 Art. 23 (significant incident determination)
SEV-RPTPUBLIC SCHEMA
Reportability thresholds evaluated deterministically
- Minimum tier
- T1+
- Requirement
- governance
- Evidence
- configuration_attestation
- Regulatory references
- DORA Art. 19 (major incident reporting), GDPR Art. 33 (breach notification), NIS2 Art. 23 (incident reporting)
Content Safety 7 controls
CSS-1PUBLIC SCHEMA
Harmful content detection pipeline SHALL achieve >99.9% block rate for CSAM (zero-tolerance); alert and log all blocked outputs.
- Minimum tier
- T1+
- Requirement
- preventive
- Evidence
- test_report
- Regulatory references
- EU AI Act Art. 5
CSS-2PUBLIC SCHEMA
Maintain a sufficiently detailed summary of content used to train the GPAI model, published per EU AI Act Art. 53(1)(c) template requirements. Implement output filtering to detect verbatim or near-ver
- Minimum tier
- T2+
- Requirement
- governance
- Evidence
- policy_document
- Regulatory references
- EU AI Act Art. 53(1)(c)
CSS-3PUBLIC SCHEMA
AI-generated synthetic media SHALL carry machine-readable provenance marker (C2PA recommended) and human-facing disclosure label.
- Minimum tier
- T1+
- Requirement
- preventive
- Evidence
- configuration_attestation
- Regulatory references
- EU AI Act Art. 50
CSS-4PUBLIC SCHEMA
Design review SHALL confirm the AI system does not employ subliminal techniques (content presented below the threshold of conscious perception) or techniques designed to exploit known vulnerabilities of specific groups to materially distort behaviour.
- Minimum tier
- T2+
- Requirement
- preventive
- Evidence
- test_report
- Regulatory references
- EU AI Act Art. 5(1)(b)
CSS-5PUBLIC SCHEMA
Monthly statistical analysis of AI outputs across protected demographic groups
- Minimum tier
- T1+
- Requirement
- detective
- Evidence
- test_report
- Regulatory references
- EU AI Act Art. 10(2)(f)
CSS-6PUBLIC SCHEMA
Conduct a quarterly Demographic Impact Assessment (DIA) for all high-risk AI systems. The DIA
- Minimum tier
- T2+
- Requirement
- detective
- Evidence
- test_report
- Regulatory references
- EU AI Act Art. 9(7)
CSS-7PUBLIC SCHEMA
Tier 1 + documented vulnerable population impact assessment, conducted alongside CSS-6's DIA, specifically evaluating outcomes for identified vulnerable groups rather than aggregate demographic catego
- Minimum tier
- T1+
- Requirement
- preventive
- Evidence
- test_report
- Regulatory references
- EU AI Act Art. 5(1)(b)
Federated Learning Security 4 controls
FL-1PUBLIC SCHEMA
Federated clients authenticated via mutual TLS with client-specific certificates; unregistered/revoked clients rejected.
- Minimum tier
- T2+
- Requirement
- preventive
- Evidence
- configuration_attestation
- Regulatory references
- GDPR Art. 25
FL-2PUBLIC SCHEMA
Byzantine-robust aggregation (FedAvg with clipping; Krum/Bulyan for high-threat); gradients >3 sigma from epoch mean flagged; clients with anomaly rate >5% rejected.
- Minimum tier
- T2+
- Requirement
- detective
- Evidence
- log_record
- Regulatory references
- DORA Art. 28, GDPR Art. 32
FL-3PUBLIC SCHEMA
Differential privacy (DP-SGD) applied; epsilon <=1 for high-sensitivity data, epsilon <=8 maximum ceiling for lower-sensitivity data; epsilon=10 not recommended for production.
- Minimum tier
- T2+
- Requirement
- preventive
- Evidence
- configuration_attestation
- Regulatory references
- India DPDP Sec. 4
FL-4PUBLIC SCHEMA
Global model signed with ECDSA (or CRYSTALS-Dilithium per PQC-1) after each aggregation round; signed checkpoint stored in AI-BOM registry.
- Minimum tier
- T2+
- Requirement
- preventive
- Evidence
- signed_artifact
- Regulatory references
- GDPR Art. 32
Model Merge Defense 3 controls
MMD-1PUBLIC SCHEMA
Pre-merge source model vetting: AI-BOM provenance, absence of known malicious fine-tuning datasets, training data manifest completeness verified; incomplete provenance rejected.
- Minimum tier
- T2+
- Requirement
- preventive
- Evidence
- signed_artifact
- Regulatory references
- DORA Art. 28
MMD-2PUBLIC SCHEMA
Post-merge backdoor scan (Neural Cleanse or ABS); semantic consistency testing across 500+ prompt templates; embedding space anomaly analysis.
- Minimum tier
- T2+
- Requirement
- detective
- Evidence
- test_report
- Regulatory references
- EU AI Act Art. 15
MMD-3PUBLIC SCHEMA
Model merge operations performed in isolated compute environment with no internet access; all artifacts hash-verified entering and leaving.
- Minimum tier
- T2+
- Requirement
- preventive
- Evidence
- configuration_attestation
- Regulatory references
- EU AI Act Art. 15
Quantization Security 3 controls
QBS-1PUBLIC SCHEMA
Pre-quantization behavioural baseline established on 1,000+ representative inputs; stored as signed artefact in AI-BOM.
- Minimum tier
- T2+
- Requirement
- preventive
- Evidence
- signed_artifact
- Regulatory references
- DORA Art. 28
QBS-2PUBLIC SCHEMA
Post-quantization differential analysis against baseline; divergence >5% flagged; divergence >10% rejects model.
- Minimum tier
- T2+
- Requirement
- detective
- Evidence
- test_report
- Regulatory references
- DORA Art. 28
QBS-3PUBLIC SCHEMA
Only trusted, audited quantization toolchains used (ONNX Runtime, TensorRT, PyTorch quantization); toolchain integrity hash-verified; third-party pre-quantized models screened via QBS-1/QBS-2.
- Minimum tier
- T2+
- Requirement
- preventive
- Evidence
- signed_artifact
- Regulatory references
- DORA Art. 28
Hallucination Detection 5 controls
HAL-1PUBLIC SCHEMA
RAG factual grounding verification: all factual claims grounded in retrieved source documents; citation extraction and source verification; ungrounded claims flagged for human review.
- Minimum tier
- T1+
- Requirement
- detective
- Evidence
- log_record
- Regulatory references
- EU AI Act Art. 13
HAL-2PUBLIC SCHEMA
Model confidence scoring implemented; outputs below 0.7 confidence for consequential decisions require human review before action; uncertainty surfaced to end users.
- Minimum tier
- T2+
- Requirement
- governance
- Evidence
- configuration_attestation
- Regulatory references
- EU AI Act Art. 15
HAL-3PUBLIC SCHEMA
For high-stakes outputs (medical, legal, financial, safety-critical): parallel inference with second model or rule-based verifier; inconsistencies >10% divergence flagged for human review.
- Minimum tier
- T2+
- Requirement
- detective
- Evidence
- log_record
- Regulatory references
- EU AI Act Art. 15
HAL-4PUBLIC SCHEMA
Hallucination rate tracked via human correction feedback loop; alert at >3% of evaluated outputs; escalate to AI-IRF corrective action at >5% (trust_erosion_rate threshold).
- Minimum tier
- T1+
- Requirement
- detective
- Evidence
- log_record
- Regulatory references
- RBI AI Governance Pillar 3
HAL-5PUBLIC SCHEMA
For regulated domains (medical diagnosis, legal analysis, financial advice): external fact-checking API or knowledge graph verification integrated for domain-specific claims.
- Minimum tier
- T2+
- Requirement
- preventive
- Evidence
- configuration_attestation
- Regulatory references
- FDA SaMD GMLP
Post-Quantum Cryptography 1 controls
PQC-1PUBLIC SCHEMA
PQC readiness assessment SHALL be completed covering BOM-4, MCP-1, A2A-2, and REG-4 cryptographic use cases. Migration to CRYSTALS-Dilithium (BOM-4, A2A-2) at Tier 3 from Q1 2027; hybrid Kyber-1024 (MCP-1) from Q3 2027; hybrid ECDSA+Dilithium (REG-4, all tiers) from Q3 2027.
- Minimum tier
- T3+
- Requirement
- preventive
- Evidence
- configuration_attestation
- Regulatory references
- NIS2 Art. 21(2)(a), DORA Art. 9
Machine-readable source
Download the canonical JSON control register →
Scope boundary
This catalogue communicates normative control records. It does not include test vectors, certification decisions or permission to use certification marks.