30 × 30 × 3
30 capabilities A1–F5, 30 anti-patterns AP-A1–AP-F5, 180 primary questions. Source: AI Governance Categories and Anti-Patterns v1.1.
Every applicable capability and anti-pattern receives an explicit result. Each object is asked the same three questions: is the requirement defined, is it implemented in the actual system, and does current evidence show that it works? Claims become findings only after independent verification. Tactics appear only from locked findings mapped to these object IDs. Missing evidence stays UNKNOWN. Named humans retain formal authority.
30 capabilities A1–F5, 30 anti-patterns AP-A1–AP-F5, 180 primary questions. Source: AI Governance Categories and Anti-Patterns v1.1.
Every capability and anti-pattern has at least one mapped tactic. Retrieval is exact object-id matching from locked findings — not keywords.
Q1 definition and intent. Q2 implementation and operation. Q3 evidence and effectiveness. Design cannot be treated as operational proof.
The user is the only Intake authority. The Engine never issues legal conclusions, residual-risk acceptance or formal approval.
The Engine begins with the evidence itself. Files are parsed locally, screened, registered with stable provenance, and converted into redacted bounded packets before any governance inference is permitted.
Normalizes code, text, JSON, CSV, HTML, PDF, DOCX, XLSX and supported images into source units through versioned acquisition lanes.
Detects sensitive values and prepares only approved redacted evidence packets for external reasoning calls.
Registers source units, hashes, locators, exclusions and extraction lineage before assessment begins.
Assessment asks the 30 capability / 30 anti-pattern instrument. Tactics retrieve from locked findings mapped to those object IDs. Methodology stays separate from the assessed solution.
Before the main assessment, the Engine constructs a field-level understanding of intended use, shows it to the user, preserves conflicts, and creates an immutable confirmed intake boundary. Analysis does not start until that user action.
Extracts purpose, lifecycle, users, data, autonomy and other case facts with explicit provenance and uncertainty. Unknown is a valid resolution.
Uses bounded AI reasoning to challenge the deterministic intake draft without overwriting deterministic or user-entered values.
The user reviews detected facts, may Accept-as-Unknown, and is the only actor who can freeze Intake and start analysis.
Only the redacted packets bound after confirm, and the configured provider route, may cross the external reasoning boundary.
The confirmed dossier is turned into a candidate solution model, externally observed facts are independently checked, and source units are routed into bounded governance-domain packets.
Builds a structured view of purpose, actors, data, architecture, autonomy, lifecycle and material dependencies.
Observed candidate facts are challenged by an independent reasoning route before entering the shared model.
Deterministic signals route source units to A–F; only ambiguous units receive semantic routing assistance.
Image pixels never enter provider packets. Visual evidence may produce derived text linked to an immutable parent source unit.
Six domain assessments run over bounded evidence and the governed instrument. The universe is 30 capabilities, 30 paired anti-patterns and 180 primary questions. Every applicable object receives an explicit result, including “no evidence found.”
Intended purpose, value rationale, roles, system boundary and regulatory/governance classification.
Data provenance, lawful handling, privacy, confidentiality and intellectual-property controls.
Model and provider selection, agent/tool boundaries, provenance and third-party risk.
Technical architecture, security, resilience, safety, testing and evaluation sufficiency.
Affected-person impact, fairness, transparency, meaningful human oversight and recourse.
Decision authority, evidence quality, risk decisions, monitoring, reassessment and lifecycle governance.
Work items are batched and paired only with the domain knowledge those objects need. Each item’s question wording is exact — not rewritten, merged or invented.
Records whether every applicable governance object was assessed, had no evidence, or failed due to a domain-stage problem.
Intended purpose, value rationale, roles, system boundary and regulatory/governance classification.
The intended purpose, users, affected persons, operating context, expected outputs, permitted uses, prohibited uses and foreseeable misuse are precise enough to govern design and evaluation.
A1-Q1A1-Q2A1-Q3The purpose is vague, technically framed, inconsistent or expands without requalification.
AP-A1-Q1AP-A1-Q2AP-A1-Q3The organization demonstrates that AI is a proportionate mechanism for a defined problem and that expected value is measurable against cost, alternatives and risk.
A2-Q1A2-Q2A2-Q3AI is adopted for novelty, availability or signalling without evidence that it is the best proportionate mechanism.
AP-A2-Q1AP-A2-Q2AP-A2-Q3Organizational, contractual and regulatory roles across the complete AI value chain are identified and matched to real control and accountability.
A3-Q1A3-Q2A3-Q3Parties assume that governance, compliance or operational control belongs to someone else.
AP-A3-Q1AP-A3-Q2AP-A3-Q3The complete system and actual use are classified through a reviewable applicability analysis covering role, risk, jurisdiction, data, impact and sector obligations.
A4-Q1A4-Q2A4-Q3Classification is copied, model-centric, overconfident or treated as a one-time formality.
AP-A4-Q1AP-A4-Q2AP-A4-Q3The current stage, permitted activities, target stage, acceptance criteria and authorization boundary are explicit from qualification through retirement.
A5-Q1A5-Q2A5-Q3An experiment accumulates real users, data, integrations or dependency without formal transition and reassessment.
AP-A5-Q1AP-A5-Q2AP-A5-Q3Data provenance, lawful handling, privacy, confidentiality and intellectual-property controls.
Training, tuning, retrieval, prompt, evaluation, operational and output data are separately identifiable from origin through transformation, storage, transfer and deletion.
B1-Q1B1-Q2B1-Q3Data origin, ownership, transformation, transmission, retention or reuse cannot be reliably established.
AP-B1-Q1AP-B1-Q2AP-B1-Q3Only data demonstrably necessary and proportionate for the declared purpose and lifecycle stage are processed and retained.
B2-Q1B2-Q2B2-Q3Data is collected, transmitted or retained because it may be useful rather than because it is necessary.
AP-B2-Q1AP-B2-Q2AP-B2-Q3Personal-data processing, lawful basis, transparency, rights, privacy risks and impact-assessment duties are operationalized in the system and its lifecycle.
B3-Q1B3-Q2B3-Q3Privacy exists in policy text but is not reflected in actual data flows, controls or operations.
AP-B3-Q1AP-B3-Q2AP-B3-Q3Confidential, restricted, customer-controlled and security-sensitive information remains within approved identity, tenant, provider, logging and contractual boundaries.
B4-Q1B4-Q2B4-Q3Sensitive information enters or leaves models, prompts, logs, caches, retrieval stores or tools without adequate protection.
AP-B4-Q1AP-B4-Q2AP-B4-Q3The organization has a defensible and traceable basis to use, transform, train on, retrieve, generate and distribute relevant data, models, code and outputs.
B5-Q1B5-Q2B5-Q3Accessible content is assumed to be available for AI use, transformation or redistribution without rights analysis.
AP-B5-Q1AP-B5-Q2AP-B5-Q3Model and provider selection, agent/tool boundaries, provenance and third-party risk.
Models, agents, prompts, tools, APIs, datasets, providers, infrastructure, versions and owners are registered and linked to the assessed system.
C1-Q1C1-Q2C1-Q3Unregistered or uncontrolled models, tools, providers, prompts or agent capabilities are used.
AP-C1-Q1AP-C1-Q2AP-C1-Q3Model and provider selections are evidence-based for task quality, language, latency, security, privacy, resilience, cost, contract and risk.
C2-Q1C2-Q2C2-Q3Models or providers are selected by familiarity, availability, prestige or generic benchmarks rather than contextual evidence.
AP-C2-Q1AP-C2-Q2AP-C2-Q3Agent authority is explicit, least-privilege, stage-appropriate, budgeted, observable and bounded by deterministic authorization for consequential actions.
C3-Q1C3-Q2C3-Q3An agent receives broad access and can choose independently how to exercise it without enforceable limits.
AP-C3-Q1AP-C3-Q2AP-C3-Q3Third-party AI services are evaluated, contractually governed, monitored and replaceable in the context of the actual system.
C4-Q1C4-Q2C4-Q3Vendor claims, certifications or marketing are treated as proof that the integrated system is governed.
AP-C4-Q1AP-C4-Q2AP-C4-Q3AI models, datasets, libraries, tools, services and update channels have verifiable provenance, controlled baselines and risk-based change gates.
C5-Q1C5-Q2C5-Q3Components or dependencies change without the organization understanding or authorizing their effect on behavior and risk.
AP-C5-Q1AP-C5-Q2AP-C5-Q3Technical architecture, security, resilience, safety, testing and evaluation sufficiency.
The system uses defense in depth, explicit trust boundaries and enforced identity, network, environment, tenant, secrets and data-flow controls.
D1-Q1D1-Q2D1-Q3The system relies on prompts, conventions or developer intent instead of enforceable architectural controls.
AP-D1-Q1AP-D1-Q2AP-D1-Q3End-to-end performance is evaluated on representative tasks, users, contexts and failure modes against consequence-based acceptance thresholds.
D2-Q1D2-Q2D2-Q3Successful examples or generic model benchmarks are treated as proof of end-to-end reliability.
AP-D2-Q1AP-D2-Q2AP-D2-Q3The system identifies and controls attack paths that exploit AI models, prompts, training or retrieval data, generated outputs, tools and feedback loops, and verifies resilience through representative adversarial testing and monitoring.
D3-Q1D3-Q2D3-Q3Security-critical restrictions depend mainly on instructions, refusals, model behavior or unverified filters instead of enforceable external controls and adversarial evidence.
AP-D3-Q1AP-D3-Q2AP-D3-Q3Material outputs and actions can be reconstructed from evidence, data, component versions, prompts, tools, validations and human decisions with sufficient operational telemetry.
D4-Q1D4-Q2D4-Q3The organization cannot determine how a material result or action was produced.
AP-D4-Q1AP-D4-Q2AP-D4-Q3Foreseeable unsafe states are constrained through fail-safe behavior, interruption, fallback, rollback, human takeover, incident response and recovery testing.
D5-Q1D5-Q2D5-Q3When confidence, controls, components or evidence fail, the system continues without safe limitation.
AP-D5-Q1AP-D5-Q2AP-D5-Q3Affected-person impact, fairness, transparency, meaningful human oversight and recourse.
The organization evaluates direct, indirect and cumulative benefits and harms for users, non-users, affected groups and rights across the actual context.
E1-Q1E1-Q2E1-Q3The system is evaluated only from the buyer's or operator's perspective while affected non-users and rights are ignored.
AP-E1-Q1AP-E1-Q2AP-E1-Q3Contextual fairness objectives, relevant groups, data and decision pathways are defined, measured and governed for unacceptable disparity.
E2-Q1E2-Q2E2-Q3Overall performance or removal of explicit protected attributes is treated as proof of fairness.
AP-E2-Q1AP-E2-Q2AP-E2-Q3Users and affected persons receive timely, accurate and actionable information about AI use, purpose, limitations, data use, human involvement and relevant consequences.
E3-Q1E3-Q2E3-Q3Generic disclosures exist but do not accurately explain the system or enable informed action.
AP-E3-Q1AP-E3-Q2AP-E3-Q3Competent humans have sufficient information, authority, time and technical ability to review, intervene, override and escalate at material decision points.
E4-Q1E4-Q2E4-Q3A human is nominally present but lacks information, capacity, authority or incentive for independent judgment.
AP-E4-Q1AP-E4-Q2AP-E4-Q3Material outcomes can be questioned and corrected through accessible human recourse, while users, reviewers and decision-makers have role-appropriate competence.
E5-Q1E5-Q2E5-Q3Outcomes are functionally final or relevant people lack the means and understanding to question them.
AP-E5-Q1AP-E5-Q2AP-E5-Q3Decision authority, evidence quality, risk decisions, monitoring, reassessment and lifecycle governance.
One accountable system owner and clearly assigned business, technical, data, model, security, privacy, operations and decision roles exercise authority throughout the lifecycle.
F1-Q1F1-Q2F1-Q3Governance bodies exist but no identifiable person is operationally accountable for the system.
AP-F1-Q1AP-F1-Q2AP-F1-Q3Material claims, requirements, controls and readiness conclusions are linked to current, scoped, attributable and sufficient evidence that matches implementation and operation.
F2-Q1F2-Q2F2-Q3Documents and checkboxes create apparent assurance without demonstrating implementation or effectiveness.
AP-F2-Q1AP-F2-Q2AP-F2-Q3System-specific risks are linked to controls, evidence, owners, treatment criteria, residual uncertainty and authorized acceptance.
F3-Q1F3-Q2F3-Q3Risks are listed but not operationally treated, tested, reassessed or accepted by the correct authority.
AP-F3-Q1AP-F3-Q2AP-F3-Q3The correct human authority makes timely, proportional and recorded lifecycle decisions, clearly separated from automated recommendations.
F4-Q1F4-Q2F4-Q3Progress depends on periodic forums, silent assent or unclear authority, or automated recommendations are mistaken for approval.
AP-F4-Q1AP-F4-Q2AP-F4-Q3Quality, risk, security, impact and compliance are monitored; incidents and material changes trigger response, reassessment, reauthorization or controlled retirement.
F5-Q1F5-Q2F5-Q3Governance effectively stops after initial approval while operation, change and retirement remain uncontrolled.
AP-F5-Q1AP-F5-Q2AP-F5-Q3Domain claims remain provisional. They must pass citation integrity, independent semantic verification and — when disputed — bounded re-analysis before they can become deterministic findings. Playbook retrieval consumes only this locked set.
Rejects structurally invalid claims before an independent model is asked to judge their semantics.
An independent reasoning route evaluates whether the cited evidence supports, conflicts with, or cannot verify each claim.
Weak, contradictory or integrity-sensitive claims receive a focused second pass rather than an unrestricted rerun.
Only decision-eligible adjudicated claims become locked findings. Gaps and unknowns are not locked findings and cannot retrieve tactics.
Once findings are locked, generative reasoning no longer owns the decision. Applicability, controls, anti-pattern state, hard gates, readiness dimensions and tactic eligibility are calculated from governed rules and locked evidence.
Evaluates applicable requirements and controls for the confirmed lifecycle transition and evidence state across seven stages from qualification to retirement.
Creates BLOCK / REVIEW conditions for documentation, source coverage, required human authority and incomplete cognitive assessment.
Separates evidence coverage, verified-evidence coverage, control assurance, assurance deficit and potential risk determination.
119 approved tactics become candidate actions only when a locked finding carries a mapped capability or anti-pattern ID from the instrument.
Only after deterministic readiness exists does the Engine create decision-ready narrative. Synthesis receives locked findings, deterministic results and already-selected actions. It cannot invent tactics or rewrite scores.
Explains the deterministic result, evidence-backed drivers, limitations and candidate actions without recalculating readiness.
A separate reasoning route checks generated narrative and actions against locked findings and the deterministic package.
A grounding error can reopen only the affected claim, re-adjudicate it, and recompute the deterministic package from the revised finding set.
Unsupported prose can be corrected once and rechecked; unresolved items are quarantined from the published narrative.
The final stage decides whether generated narrative is publishable, then returns one canonical package containing deterministic results, cognitive evidence, unresolved claims, traceability and named human decision requirements.
Combines coverage, finding-lock integrity, unresolved claims, fact-check integrity, action grounding and re-analysis outcomes.
One hashed JSON package drives the Assessment Workspace and the Assurance Summary. HTML/PDF do not calculate a second result.
Records packet hashes, stage events, reasoning executions, budgets, unresolved claims and recomputation history without storing credentials.
Legal, privacy, security, governance, residual-risk and lifecycle approval remain attributable human acts.
Detailed intake, evidence, controls, anti-patterns, findings, diagnostics and remediation context.
Decision-ready view of recommendation, dimensions, transition boundary, gates and required human decisions.
Decision-eligible claims with exact evidence. The only input that can retrieve Playbook tactics.
Approved tactics activated only by locked findings mapped to A1–F5 / AP-A1–AP-F5.
Claims, verifications, adjudications, unresolved items, publication integrity and execution trace.