diff --git a/artifacts/data/agi-readiness-assessment.csv b/artifacts/data/agi-readiness-assessment.csv new file mode 100644 index 00000000..2fba8cd1 --- /dev/null +++ b/artifacts/data/agi-readiness-assessment.csv @@ -0,0 +1,8 @@ +level,name,requirements,investment_usd,timeline,key_milestones,current_status,dependencies +ARL-1,Foundation,"AI inventory, basic policies, risk awareness training",1400000,Month 1-3,"Complete AI system inventory, establish AI governance team, basic risk awareness program",Completed,None +ARL-2,Structured,"Formal governance framework, OPA policies (50+ rules), basic monitoring",4200000,Month 3-9,"OPA deployed with 50+ rules, formal RACI matrix, Board AI Sub-committee chartered, basic Prometheus monitoring",Current,ARL-1 +ARL-3,Managed,"Full Sentinel deployment, continuous monitoring, SR 11-7 compliance",9800000,Month 9-18,"Sentinel Platform v4.2 production, 1024+ rules, SR 11-7 full compliance, automated drift detection, Kafka WORM audit trail",Planned,ARL-2 +ARL-4,Advanced,"EAIP mesh operational, autonomous agent governance, EARL-4",14800000,Month 18-30,"EAIP gRPC mesh live, SPIFFE/SPIRE identity, DEPTHS L0-L4 governance, full CI/CD gates, ISO 42001 certified",Planned,ARL-3 +ARL-5,AGI-Ready,"GASCF certified, crisis-tested, CRP operational, multi-regime compliant",18600000,Month 30-42,"GASCF Level 3 certification, quarterly crisis simulations passed, CRP v2.1 operational, 8 regulatory frameworks aligned",Planned,ARL-4 +ARL-6,AGI-Operational,"AGI systems in production with full containment, ICGC integration",26400000,Month 42-54,"AGI containment infrastructure deployed, ICGC pilot integration, GASCF Level 4, kill-switch triple redundant",Planned,ARL-5 +ARL-7,ASI-Prepared,"Civilizational governance, GATI treaty compliance, global coordination",42800000,Month 54+,"GATI treaty integrated, GASCF Level 5, civilizational governance framework operational, international coordination protocols active",Planned,ARL-6 diff --git a/artifacts/data/cross-module-regulatory-alignment.csv b/artifacts/data/cross-module-regulatory-alignment.csv new file mode 100644 index 00000000..6b4bc69a --- /dev/null +++ b/artifacts/data/cross-module-regulatory-alignment.csv @@ -0,0 +1,12 @@ +Module,DocRef,Endpoints,EU_AI_Act,NIST_AI_RMF,ISO_42001,GDPR,Basel_III,SR_11_7,FCRA_ECOA,OECD_AI_Principles,OPA_Rules,Sentinel_Rules,Key_Controls +Practitioner Master Reference,PMREF-GSIFI-WP-015,50,FULL,FULL,FULL,PARTIAL,FULL,FULL,FULL,MAPPED,96,280,"10 pillars; RACI; trust stack; model registry; Sentinel integration" +AGI Governance Master Blueprint,AGMB-GSIFI-WP-016,39,FULL,FULL,FULL,PARTIAL,FULL,FULL,PARTIAL,FULL,72,420,"6 governance layers; 15 ICGC components; 7 AGI readiness levels" +Kafka ACL Governance,KACG-GSIFI-WP-017,54,FULL,FULL,FULL,FULL,FULL,FULL,PARTIAL,MAPPED,214,152,"12 Kafka topics; ACL enforcement; WORM S3; evidence signing; Terraform IaC" +Governance Architectures & Frameworks,GAF-GSIFI-WP-017,57,FULL,FULL,FULL,FULL,FULL,FULL,FULL,FULL,168,380,"7 domains; 5 reference architectures; 6 governance layers" +G-SIFI Regulatory Compliance,COMP-REG-WP-006,22,FULL,FULL,FULL,FULL,FULL,FULL,FULL,MAPPED,142,240,"Multi-jurisdiction compliance; 16 regulatory frameworks" +Enterprise AI Strategy,STRAT-G2K-WP-012,32,PARTIAL,PARTIAL,MAPPED,PARTIAL,MAPPED,MAPPED,-,MAPPED,24,80,"Global 2000 strategy; AI maturity model; investment framework" +Unified Master Reference,UMREF-G2K-WP-014,28,FULL,FULL,PARTIAL,PARTIAL,PARTIAL,PARTIAL,PARTIAL,MAPPED,64,120,"Fortune 500 reference; enterprise governance; platform roadmap" +AGI/ASI Governance Unified,IMPL-GSIFI-WP-005,26,PARTIAL,PARTIAL,MAPPED,MAPPED,MAPPED,MAPPED,-,PARTIAL,18,64,"Implementation roadmap; 8 governance domains" +AGI Governance Framework,AGI-GOV-CORE,76,PARTIAL,PARTIAL,MAPPED,MAPPED,-,-,-,PARTIAL,32,180,"AGI capability landscape; safety pillars; maturity model" +ASI Preparedness,SAFE-AGI-WP-003,12,MAPPED,MAPPED,MAPPED,-,-,-,-,PARTIAL,8,48,"ASI scenarios; risk taxonomy; containment strategies" +AI Governance Analysis,GOV-ANALYSIS-001,10,FULL,FULL,PARTIAL,PARTIAL,PARTIAL,PARTIAL,PARTIAL,MAPPED,22,40,"Regulatory landscape analysis; jurisdiction mapping" diff --git a/artifacts/data/global-governance-components.csv b/artifacts/data/global-governance-components.csv new file mode 100644 index 00000000..7f8ba87a --- /dev/null +++ b/artifacts/data/global-governance-components.csv @@ -0,0 +1,16 @@ +id,acronym,full_name,function,status,integration_protocol,latency_sla,regulatory_basis +GC-01,GACRA,Global AI Compute Resource Authority,"Compute allocation, licensing, monitoring",Proposed,REST + mTLS,< 500ms,ICGC Charter Art. 3 +GC-02,GASO,Global AI Safety Office,"Safety standards, incident coordination",Pilot (EU + US),Kafka + gRPC,< 200ms,ICGC Charter Art. 5 +GC-03,GFMCF,Global Frontier Model Certification Framework,Pre-deployment certification for frontier models,Draft,OPA + REST,< 50ms,GASCF Levels 1-5 +GC-04,GAICS,Global AI Incident Classification System,Standardized incident severity and reporting,Draft,Kafka + gRPC,< 200ms,ICGC Charter Art. 8 +GC-05,GAIVS,Global AI Incident Verification System,Independent incident investigation,Proposed,REST + mTLS,< 1000ms,ICGC Charter Art. 9 +GC-06,GACP,Global AI Compute Passport,Portable compute usage credentials,Proposed,REST + OAuth2,< 500ms,GACRLS Integration +GC-07,GATI,Global AI Treaty Infrastructure,"Treaty management, compliance tracking",Concept,REST + Batch,24h batch,International Law +GC-08,GACMO,Global AI Capability Monitoring Observatory,Track frontier capabilities worldwide,Pilot (3 countries),Batch + Streaming,15-min batch,ICGC Charter Art. 6 +GC-09,FTEWS,Frontier Technology Early Warning System,"Capability jump detection, risk alerts",Prototype,WebSocket + gRPC,< 100ms,GACMO Integration +GC-10,GAI-SOC,Global AI Security Operations Center,24/7 AI threat monitoring and response,Pilot,STIX/TAXII + REST,Near real-time,ICGC Charter Art. 10 +GC-11,GAIGA,Global AI Governance Assembly,Legislative body for international AI law,Proposed,Diplomatic,N/A,ICGC Charter Art. 2 +GC-12,GACRLS,Global AI Compute Resource Licensing System,Compute license issuance and compliance,Draft,REST + mTLS,< 500ms,GACRA Integration +GC-13,GFCO,Global Frontier Compute Observatory,Monitor global compute build-out and allocation,Concept,Batch + Streaming,1h batch,GACMO Integration +GC-14,GAID,Global AI Insurance and Indemnification,"Risk pooling, liability frameworks",Concept,REST + Batch,24h batch,GASCF Integration +GC-15,GASCF,Global AI Safety Certification Framework,Multi-tier safety certification (Levels 1-5),Draft,OPA + REST + Audit,< 50ms,EU AI Act + NIST AI RMF diff --git a/artifacts/data/kafka-acl-matrix.json b/artifacts/data/kafka-acl-matrix.json new file mode 100644 index 00000000..ebbe2278 --- /dev/null +++ b/artifacts/data/kafka-acl-matrix.json @@ -0,0 +1,73 @@ +{ + "_metadata": { + "docRef": "KACG-GSIFI-WP-017", + "description": "Kafka ACL Matrix: Topic-level PRODUCE/CONSUME ACL assignments for all AI governance topics", + "version": "1.0.0", + "lastUpdated": "2026-04-03" + }, + "topics": { + "ai.inference.events": { + "partitions": 24, "replicationFactor": 3, "minInsyncReplicas": 2, "retention": "10 years", "transactional": false, + "produce": ["inference-engine-*", "sentinel-platform"], + "consume": ["compliance-engine", "ksqldb-analytics", "evidence-generator"] + }, + "ai.training.events": { + "partitions": 12, "replicationFactor": 3, "minInsyncReplicas": 2, "retention": "10 years", "transactional": true, + "produce": ["mlops-pipeline", "model-registry"], + "consume": ["compliance-engine", "ksqldb-analytics", "sentinel-platform"] + }, + "ai.governance.decisions": { + "partitions": 12, "replicationFactor": 3, "minInsyncReplicas": 2, "retention": "10 years", "transactional": true, + "produce": ["opa-engine", "sentinel-platform", "caio-portal"], + "consume": ["compliance-engine", "evidence-generator", "audit-portal"] + }, + "ai.model.promotions": { + "partitions": 6, "replicationFactor": 3, "minInsyncReplicas": 2, "retention": "10 years", "transactional": true, + "produce": ["model-registry", "mlops-pipeline"], + "consume": ["compliance-engine", "sentinel-platform", "evidence-generator"] + }, + "ai.bias.alerts": { + "partitions": 6, "replicationFactor": 3, "minInsyncReplicas": 2, "retention": "10 years", "transactional": false, + "produce": ["sentinel-platform", "fairness-monitor"], + "consume": ["compliance-engine", "caio-portal", "cro-dashboard"] + }, + "ai.drift.detections": { + "partitions": 6, "replicationFactor": 3, "minInsyncReplicas": 2, "retention": "10 years", "transactional": false, + "produce": ["sentinel-platform", "monitoring-service"], + "consume": ["compliance-engine", "model-registry", "opa-engine"] + }, + "ai.sentinel.evaluations": { + "partitions": 24, "replicationFactor": 3, "minInsyncReplicas": 2, "retention": "10 years", "transactional": false, + "produce": ["sentinel-platform"], + "consume": ["compliance-engine", "ksqldb-analytics", "evidence-generator"] + }, + "ai.compliance.evidence": { + "partitions": 12, "replicationFactor": 3, "minInsyncReplicas": 2, "retention": "10 years", "transactional": true, + "produce": ["evidence-generator"], + "consume": ["audit-portal", "regulator-portal", "compliance-engine"], + "exclusiveWrite": true + }, + "ai.agent.telemetry": { + "partitions": 12, "replicationFactor": 3, "minInsyncReplicas": 2, "retention": "10 years", "transactional": false, + "produce": ["agent-orchestrator", "behavioral-sidecar"], + "consume": ["compliance-engine", "sentinel-platform", "safety-monitor"] + }, + "ai.killswitch.events": { + "partitions": 3, "replicationFactor": 3, "minInsyncReplicas": 3, "retention": "PERMANENT", "transactional": true, + "produce": ["kill-switch-controller"], + "consume": ["ALL-governance-services", "board-dashboard"], + "exclusiveWrite": true, + "criticalTopic": true + }, + "ai.consent.changes": { + "partitions": 6, "replicationFactor": 3, "minInsyncReplicas": 2, "retention": "5 years (GDPR)", "transactional": true, + "produce": ["consent-management-platform"], + "consume": ["compliance-engine", "erasure-controller", "privacy-engine"] + }, + "ai.erasure.requests": { + "partitions": 6, "replicationFactor": 3, "minInsyncReplicas": 2, "retention": "5 years (GDPR)", "transactional": true, + "produce": ["consent-management-platform", "dpo-portal"], + "consume": ["erasure-controller", "compliance-engine", "evidence-generator"] + } + } +} diff --git a/artifacts/data/kafka-compliance-controls.csv b/artifacts/data/kafka-compliance-controls.csv new file mode 100644 index 00000000..5e58efa0 --- /dev/null +++ b/artifacts/data/kafka-compliance-controls.csv @@ -0,0 +1,13 @@ +Requirement,ISO_42001,NIST_AI_RMF,EU_AI_Act,Basel_III,SR_11_7,Kafka_Implementation,Status +AI System Inventory,A.5.4,GOVERN 1.1,Art. 60,CRE 30.2,§3,ai.governance.decisions: REGISTER events,IMPLEMENTED +Risk Assessment,A.5.5,MAP 1.1-1.6,Art. 9,CRE 31,§5,OPA group compliance.sr117.risk-*,IMPLEMENTED +Data Governance,A.7.1-A.7.4,MAP 2.1-2.3,Art. 10,CRE 33,§6,ai.training.events + PII detection rules,IMPLEMENTED +Model Documentation,A.6.2.5,GOVERN 4.1,Art. 11,CRE 35,§7,Evidence bundle: MODEL_DOCUMENTATION,IMPLEMENTED +Testing & Validation,A.6.2.6,MEASURE 2.1-2.13,Art. 9.7,CRE 35,§8-9,OPA lifecycle.model.validation-*,IMPLEMENTED +Monitoring,A.8.4,MEASURE 3.1-3.3,Art. 9.9,CRE 36,§10,All 12 Kafka topics + Sentinel rules,IMPLEMENTED +Record Keeping,A.6.2.3,GOVERN 5.1,Art. 12,CRE 35,§7,WORM S3 + hash chain + 10yr retention,IMPLEMENTED +Transparency,A.6.2.4,GOVERN 4.2,Art. 13,—,—,Evidence bundles + auditor portal,IMPLEMENTED +Human Oversight,A.8.3,GOVERN 1.4,Art. 14,—,§4,ai.governance.decisions: ESCALATE events,IMPLEMENTED +Incident Response,A.8.5,RESPOND 1.1-1.4,Art. 62,—,—,ai.killswitch.events + incident bundles,IMPLEMENTED +Bias Monitoring,A.8.4,MEASURE 2.6-2.11,Art. 10.2f,—,FCRA/ECOA,OPA fairness.disparateImpact.*,IMPLEMENTED +Access Control,A.6.1.3,GOVERN 6.1,Art. 9.4b,CRE 30,§3,Kafka ACL layer + OPA authorizer,IMPLEMENTED diff --git a/artifacts/data/kafka-evidence-bundles.csv b/artifacts/data/kafka-evidence-bundles.csv new file mode 100644 index 00000000..84ec9298 --- /dev/null +++ b/artifacts/data/kafka-evidence-bundles.csv @@ -0,0 +1,21 @@ +Bundle_ID,Evidence_Type,Description,Kafka_Topic,Trigger,Retention_Years,Regulation,Format,Signing,WORM_Storage,Auditor_Access,Generation_Frequency,Schema_Ref +EB-INF-001,INFERENCE_AUDIT_LOG,Complete log of AI inference decisions with input/output hashes,ai.inference.events,Every inference,10,EU AI Act Art. 12,AVRO,Ed25519+SHA-256,S3 Object Lock COMPLIANCE,Full,Continuous,governance-event.avsc +EB-TRN-001,TRAINING_RUN_LOG,Training run parameters and hyperparameters and evaluation metrics,ai.training.events,Every training run,7,SR 11-7 Section 4,AVRO,Ed25519+SHA-256,S3 Object Lock COMPLIANCE,Full,Per training run,governance-event.avsc +EB-GOV-001,GOVERNANCE_DECISION,Policy decisions including OPA evaluations and Sentinel rules,ai.governance.decisions,Every governance decision,10,EU AI Act Art. 12 / ISO 42001 A.8.4,AVRO,Ed25519+SHA-256,S3 Object Lock COMPLIANCE,Full,Continuous,governance-event.avsc +EB-MOD-001,MODEL_PROMOTION,Model registry promotion events with validation results,ai.model.promotions,Model promotion,7,SR 11-7 Section 5 / Basel III CRE 31,AVRO,Ed25519+SHA-256,S3 Object Lock COMPLIANCE,Full,Per promotion,governance-event.avsc +EB-BIA-001,BIAS_ASSESSMENT,Disparate impact scores and protected class analysis,ai.bias.alerts,Threshold breach or scheduled,7,FCRA/ECOA / NIST MEASURE 2.5,JSON,Ed25519+SHA-256,S3 Object Lock COMPLIANCE,Full,Weekly + on alert,evidence-bundle-manifest.schema.json +EB-DRF-001,DRIFT_DETECTION_REPORT,Model and data distribution drift analysis,ai.drift.detections,Drift threshold exceeded,7,SR 11-7 Section 6 / NIST MANAGE 3.1,JSON,Ed25519+SHA-256,S3 Object Lock COMPLIANCE,Full,Continuous + hourly roll-up,evidence-bundle-manifest.schema.json +EB-SEN-001,SENTINEL_EVALUATION,Sentinel platform rule evaluation results,ai.sentinel.evaluations,Every evaluation,10,ISO 42001 A.8.4 / NIST GOVERN 6.1,AVRO,Ed25519+SHA-256,S3 Object Lock COMPLIANCE,Full,Continuous,governance-event.avsc +EB-CMP-001,COMPLIANCE_EVIDENCE,Aggregated compliance evidence bundles for audit,ai.compliance.evidence,Daily + on demand,10,All frameworks,JSON,Ed25519+SHA-256,S3 Object Lock COMPLIANCE,Full,Daily,evidence-bundle-manifest.schema.json +EB-AGT-001,AGENT_TELEMETRY,Autonomous agent behavioral telemetry and decision logs,ai.agent.telemetry,Continuous monitoring,10,EU AI Act Art. 14 / NIST MANAGE 2.2,AVRO,Ed25519+SHA-256,S3 Object Lock COMPLIANCE,Full,Continuous,governance-event.avsc +EB-KSW-001,KILL_SWITCH_EVENT,Kill-switch activation and deactivation records,ai.killswitch.events,Kill-switch trigger,PERMANENT,EU AI Act Art. 14.4 / ISO 42001,JSON,Ed25519+SHA-256,S3 Object Lock COMPLIANCE,Full,On event,evidence-bundle-manifest.schema.json +EB-CON-001,CONSENT_CHANGE_LOG,Data subject consent changes for AI processing,ai.consent.changes,Consent change,5,GDPR Art. 7 / Art. 30,AVRO,Ed25519+SHA-256,S3 Object Lock COMPLIANCE,Filtered (PII),On change,governance-event.avsc +EB-ERA-001,ERASURE_REQUEST_LOG,GDPR right-to-erasure request processing records,ai.erasure.requests,Erasure request,5,GDPR Art. 17,AVRO,Ed25519+SHA-256,S3 Object Lock COMPLIANCE,Filtered (PII),On request,governance-event.avsc +EB-ACL-001,ACL_CHANGE_LOG,Kafka ACL modifications and break-glass events,N/A (aggregated),ACL change,7,ISO 42001 A.6.1.3 / Basel III,JSON,Ed25519+SHA-256,S3 Object Lock COMPLIANCE,Full,On change,evidence-bundle-manifest.schema.json +EB-TFP-001,TERRAFORM_PLAN,Terraform plan output for governance infrastructure changes,N/A (CI/CD artifact),PR merge / deploy,7,ISO 42001 A.8.1 / NIST GOVERN 4.1,JSON,Ed25519+SHA-256,S3 Object Lock COMPLIANCE,Full,Per deployment,evidence-bundle-manifest.schema.json +EB-DRT-001,DRIFT_EVIDENCE,Infrastructure and policy drift detection evidence,N/A (drift detector),Hourly drift scan,7,ISO 42001 A.9.1 / NIST MANAGE 3.2,JSON,Ed25519+SHA-256,S3 Object Lock COMPLIANCE,Full,Hourly,evidence-bundle-manifest.schema.json +EB-DEP-001,DEPLOYMENT_EVIDENCE,Post-deployment verification and gate passage records,N/A (CI/CD artifact),Deployment complete,10,EU AI Act Art. 12 / SR 11-7,JSON,Ed25519+SHA-256,S3 Object Lock COMPLIANCE,Full,Per deployment,evidence-bundle-manifest.schema.json +EB-VAL-001,MODEL_VALIDATION_REPORT,Independent model validation results for SR 11-7,N/A (MRM artifact),Quarterly + per model,7,SR 11-7 Section 3-7 / Basel III CRE 31,PDF+JSON,Ed25519+SHA-256,S3 Object Lock COMPLIANCE,Full,Quarterly,evidence-bundle-manifest.schema.json +EB-DPI-001,DPIA_REPORT,Data Protection Impact Assessment for high-risk AI,N/A (DPO artifact),Per high-risk system,5,GDPR Art. 35 / EU AI Act Art. 9,PDF+JSON,Ed25519+SHA-256,S3 Object Lock COMPLIANCE,Summary only,Per system,evidence-bundle-manifest.schema.json +EB-CON-002,CONFORMITY_ASSESSMENT,EU AI Act conformity assessment results,N/A (NB artifact),Annual + per release,10,EU AI Act Art. 43,PDF+JSON,Ed25519+SHA-256,S3 Object Lock COMPLIANCE,Full,Annual,evidence-bundle-manifest.schema.json +EB-INC-001,INCIDENT_REPORT,AI system incident timeline and root cause analysis,N/A (CISO artifact),On incident,10,EU AI Act Art. 62 / NIST MANAGE 1.3,JSON,Ed25519+SHA-256,S3 Object Lock COMPLIANCE,Full,On incident,evidence-bundle-manifest.schema.json diff --git a/artifacts/data/kafka-governance-timeline.csv b/artifacts/data/kafka-governance-timeline.csv new file mode 100644 index 00000000..cc7d4993 --- /dev/null +++ b/artifacts/data/kafka-governance-timeline.csv @@ -0,0 +1,17 @@ +Phase,Week,Deliverable,Owner,Exit_Criteria,Status +Foundation,1-2,Kafka cluster deployment (5-broker 3-AZ),Platform Eng.,Cluster healthy - mTLS enabled,PLANNED +Foundation,1-2,SPIFFE/SPIRE deployment,Security Eng.,SVIDs issuing for all services,PLANNED +Foundation,2-3,Core topic creation (12 topics) + ACL enforcement,Platform Eng.,All topics created - ACLs applied,PLANNED +Foundation,3-4,Schema Registry + core schemas,Platform Eng.,Schemas registered - compatibility enforced,PLANNED +Foundation,3-4,WORM S3 bucket provisioned,Cloud Eng.,COMPLIANCE mode verified,PLANNED +Compliance Engine,5-6,OPA Kafka Authorizer deployed,Platform Eng.,Authorizer active on all brokers,PLANNED +Compliance Engine,5-6,OPA policy bundle Phase 1 (180 rules),AI Governance,180 rules active - P99 < 5ms,PLANNED +Compliance Engine,6-7,Compliance Engine deployed,Platform Eng.,Consuming all 12 topics,PLANNED +Compliance Engine,7-8,Evidence bundle generator operational,Compliance Eng.,First SR 11-7 bundle generated,PLANNED +Compliance Engine,7-8,Verification CLI v1.0,DevTools,CLI verifies bundles - hash chains,PLANNED +Auditor Readiness,9-10,OPA policy bundle Phase 2 (312 rules),AI Governance,All 312 rules across 11 groups,PLANNED +Auditor Readiness,9-10,Auditor portal v1.0,Compliance Eng.,Self-service evidence retrieval,PLANNED +Auditor Readiness,10-11,Terraform IaC complete (8 modules),Platform Eng.,All infra managed via Terraform,PLANNED +Auditor Readiness,11-12,CI/CD governance gates (5 gates),DevOps,All 5 gates active,PLANNED +Auditor Readiness,12,Drift detection operational,SRE,Hourly drift alerts - PagerDuty,PLANNED +Auditor Readiness,12,Internal audit dry-run (ISO 42001),Compliance,Dry run complete - findings remediated,PLANNED diff --git a/artifacts/data/rollout-30-60-90.csv b/artifacts/data/rollout-30-60-90.csv new file mode 100644 index 00000000..3f199bae --- /dev/null +++ b/artifacts/data/rollout-30-60-90.csv @@ -0,0 +1,13 @@ +phase,week,day_range,activities,deliverables,owner,dependencies,success_criteria +Days 1-30,W1,1-7,"AI system inventory audit, stakeholder mapping","Complete inventory, RACI draft",CAIO,None,"100% systems inventoried, RACI approved" +Days 1-30,W2,8-14,"Risk classification of all AI systems, OPA pilot (25 rules)","Risk register v1, OPA running",VP AI Gov,W1 inventory,"All systems classified, OPA health OK" +Days 1-30,W3,15-21,"Board AI Sub-committee charter, CAIO role formalization","Charter approved, CAIO onboarded",CEO,W1 stakeholder map,"Charter signed, CAIO authority defined" +Days 1-30,W4,22-30,"MVAGS deployment, basic monitoring, incident playbook v1","MVAGS operational, dashboards live",CTO,"W2 OPA, W3 charter","MVAGS responding, 3 dashboards live" +Days 31-60,W5,31-37,"OPA expansion (100+ rules), Sentinel pilot (200 rules)",Expanded policy coverage,VP AI Gov,W4 MVAGS,"100+ OPA rules active, Sentinel evaluating" +Days 31-60,W6,38-44,"Data governance framework, PII detection deployment","Data quality gates, PII scanner",CDO,W5 OPA expansion,"Quality gate active, PII detection > 99%" +Days 31-60,W7,45-51,"CI/CD governance gates (G1-G5), model registry launch","Pipeline gates active, registry operational",CTO,"W5 Sentinel, W6 data gov","5 gates blocking, registry has 100% models" +Days 31-60,W8,52-60,"SR 11-7 compliance review, fair lending testing","SR 11-7 gap analysis, DI test results",CRO,W7 model registry,"Gap analysis complete, DI >= 0.80 all classes" +Days 61-90,W9,61-67,"Full OPA deployment (336 rules), Sentinel production",Full policy enforcement,VP AI Gov,W8 compliance review,"336 rules active, Sentinel 1024 rules" +Days 61-90,W10,68-74,EU AI Act conformity assessment preparation,Conformity documentation,GC,W9 full OPA,"Documentation complete for 14/22 systems" +Days 61-90,W11,75-81,"ISO 42001 Phase 1-2 completion, crisis simulation SIM-01","AIMS scope documented, simulation report",VP AI Gov,"W9 full Sentinel, W10 conformity","Phases 1-2 complete, simulation report filed" +Days 61-90,W12,82-90,"EARL assessment, board reporting, Phase 1 review","EARL score, board presentation, lessons learned",CAIO,W11 all milestones,"EARL-3 confirmed, board presentation delivered" diff --git a/artifacts/policies/agent_governance_depths.rego b/artifacts/policies/agent_governance_depths.rego new file mode 100644 index 00000000..a1b0a746 --- /dev/null +++ b/artifacts/policies/agent_governance_depths.rego @@ -0,0 +1,132 @@ +# Autonomous Agent Governance — DEPTHS Classification Policy +# GAF-GSIFI-WP-017, Domain 6/7 — AGI Safety & Master Blueprint +# Policy Group: PG-07 (Autonomous Agent) +# Regulatory alignment: EU AI Act Art. 6-9 (high-risk), NIST AI RMF GOVERN/MANAGE +# +# Enforces the DEPTHS (Deployment Evaluation Protocol for Trustworthy Hybrid Systems) +# classification and corresponding governance controls for autonomous AI agents. +# Levels L0 (Tool) through L5 (Self-multiplying) have escalating requirements. + +package agent_governance.depths + +import rego.v1 + +# DEPTHS Classification Levels +depths_levels := { + "L0": {"name": "Tool", "max_autonomy": "none", "requires_kill_switch": false, "requires_board_approval": false, "requires_behavioral_sidecar": false, "requires_gascf": false}, + "L1": {"name": "Assistant", "max_autonomy": "suggestion", "requires_kill_switch": true, "requires_board_approval": false, "requires_behavioral_sidecar": false, "requires_gascf": false}, + "L2": {"name": "Executor", "max_autonomy": "approved_actions", "requires_kill_switch": true, "requires_board_approval": false, "requires_behavioral_sidecar": false, "requires_gascf": false}, + "L3": {"name": "Collaborator", "max_autonomy": "independent_in_scope", "requires_kill_switch": true, "requires_board_approval": false, "requires_behavioral_sidecar": true, "requires_gascf": false}, + "L4": {"name": "Depths-class", "max_autonomy": "self_directed_in_domain", "requires_kill_switch": true, "requires_board_approval": true, "requires_behavioral_sidecar": true, "requires_gascf": true}, + "L5": {"name": "Self-multiplying", "max_autonomy": "spawn_sub_agents", "requires_kill_switch": true, "requires_board_approval": true, "requires_behavioral_sidecar": true, "requires_gascf": true} +} + +# CARDINAL INVARIANT: Self-multiplying agents MUST NEVER have write access to Tier 0 +deny contains msg if { + input.agent.depth_level == "L5" + some access in input.agent.system_access + access.tier == 0 + access.permission == "write" + msg := sprintf( + "CARDINAL INVARIANT VIOLATION: Agent '%s' (L5 Self-multiplying) has write access to Tier 0 system '%s'. Self-multiplying agents shall NEVER receive write access to identity systems, kill-switch mechanisms, or governance policy engines.", + [input.agent.agent_id, access.system_name] + ) +} + +# DENY: L4+ agent without board approval +deny contains msg if { + level := input.agent.depth_level + depths_levels[level].requires_board_approval + not input.agent.board_approval_granted + msg := sprintf( + "GOVERNANCE VIOLATION: Agent '%s' (DEPTHS %s/%s) requires Board AI Sub-committee approval before deployment. No approval on record.", + [input.agent.agent_id, level, depths_levels[level].name] + ) +} + +# DENY: Agent without kill-switch when required +deny contains msg if { + level := input.agent.depth_level + depths_levels[level].requires_kill_switch + not input.agent.kill_switch_enabled + msg := sprintf( + "SAFETY VIOLATION: Agent '%s' (DEPTHS %s) requires kill-switch capability. Kill-switch not enabled. Required latency: 50-280ms.", + [input.agent.agent_id, level] + ) +} + +# DENY: L3+ agent without behavioral sidecar +deny contains msg if { + level := input.agent.depth_level + depths_levels[level].requires_behavioral_sidecar + not input.agent.behavioral_sidecar_active + msg := sprintf( + "GOVERNANCE VIOLATION: Agent '%s' (DEPTHS %s) requires behavioral sidecar monitoring via EAIP. Sidecar not active.", + [input.agent.agent_id, level] + ) +} + +# DENY: L4+ agent without GASCF certification +deny contains msg if { + level := input.agent.depth_level + depths_levels[level].requires_gascf + not input.agent.gascf_certified + msg := sprintf( + "CERTIFICATION VIOLATION: Agent '%s' (DEPTHS %s) requires GASCF certification (Level 3+) before deployment.", + [input.agent.agent_id, level] + ) +} + +# DENY: Kill-switch latency exceeds maximum +deny contains msg if { + input.agent.kill_switch_enabled + input.agent.kill_switch_latency_ms > 280 + msg := sprintf( + "SAFETY VIOLATION: Agent '%s' kill-switch latency %dms exceeds maximum 280ms. Kill-switch must respond within 50-280ms per governance policy.", + [input.agent.agent_id, input.agent.kill_switch_latency_ms] + ) +} + +# DENY: Agent scope exceeds classification level +deny contains msg if { + level := input.agent.depth_level + level_idx := level_to_index(level) + behavior_idx := autonomy_to_index(input.agent.observed_autonomy) + behavior_idx > level_idx + msg := sprintf( + "SCOPE VIOLATION: Agent '%s' (DEPTHS %s) exhibiting autonomy level '%s' which exceeds its classification. Escalate to VP AI Safety.", + [input.agent.agent_id, level, input.agent.observed_autonomy] + ) +} + +# WARN: Agent approaching scope boundary +warn contains msg if { + input.agent.scope_utilization_pct > 85 + msg := sprintf( + "SCOPE WARNING: Agent '%s' scope utilization at %d%%. Consider preemptive scope review.", + [input.agent.agent_id, input.agent.scope_utilization_pct] + ) +} + +# DENY: No audit trail for L2+ agents +deny contains msg if { + level := input.agent.depth_level + level_to_index(level) >= 2 + not input.agent.audit_trail_active + msg := sprintf( + "AUDIT VIOLATION: Agent '%s' (DEPTHS %s) requires complete audit trail logging. Audit trail not active.", + [input.agent.agent_id, level] + ) +} + +# Helper: Map DEPTHS level to numeric index +level_to_index(level) := idx if { + mapping := {"L0": 0, "L1": 1, "L2": 2, "L3": 3, "L4": 4, "L5": 5} + idx := mapping[level] +} + +# Helper: Map observed autonomy to numeric index +autonomy_to_index(autonomy) := idx if { + mapping := {"none": 0, "suggestion": 1, "approved_actions": 2, "independent_in_scope": 3, "self_directed_in_domain": 4, "spawn_sub_agents": 5} + idx := mapping[autonomy] +} diff --git a/artifacts/policies/basel_iii_model_risk.rego b/artifacts/policies/basel_iii_model_risk.rego new file mode 100644 index 00000000..4a2102d8 --- /dev/null +++ b/artifacts/policies/basel_iii_model_risk.rego @@ -0,0 +1,181 @@ +# KACG-GSIFI-WP-017: Basel III Model Risk Compliance Policy +# Policy Group: compliance.baselIII.* (28 rules) +# Purpose: Enforce Basel III CRE 30-36 model risk management requirements +# Frameworks: Basel III CRE 30-36, SR 11-7, EU AI Act +# Last Updated: 2026-04-03 + +package compliance.baselIII + +import future.keywords.in +import future.keywords.if + +# ═══════════════════════════════════════════════════════════════════════════════ +# CRE 30.2: Board and Senior Management Oversight +# ═══════════════════════════════════════════════════════════════════════════════ + +# BAS-001: Board AI Sub-committee must review high-risk model changes +board_oversight_required if { + input.event.eventType == "MODEL_PROMOTION" + input.event.metadata.risk_tier in {"HIGH", "CRITICAL"} +} + +# BAS-002: CAIO escalation path must exist for model risk decisions +caio_escalation_valid if { + input.governance.escalation_path != "" + input.governance.caio_notified == true +} + +# BAS-003: Model risk appetite statement must be current (within 12 months) +risk_appetite_current if { + last_review := time.parse_rfc3339_ns(input.governance.risk_appetite_review_date) + time.now_ns() - last_review < 31536000000000000 # 365 days in nanoseconds +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# CRE 30.3: Model Risk Management Framework +# ═══════════════════════════════════════════════════════════════════════════════ + +# BAS-004: All AI models must be registered in the model inventory +model_registered if { + input.model.registry_id != "" + input.model.registration_date != "" + input.model.model_owner != "" +} + +# BAS-005: Model risk classification must be assigned (1-5 scale) +model_risk_classified if { + input.model.risk_tier in {"LOW", "MEDIUM", "HIGH", "CRITICAL"} + input.model.risk_score >= 0 + input.model.risk_score <= 100 +} + +# BAS-006: Model documentation must meet minimum standards +model_documentation_complete if { + required_fields := { + "model_purpose", "methodology", "assumptions", + "limitations", "data_sources", "validation_results", + "performance_metrics", "owner", "approval_date" + } + provided := {f | input.model.documentation[f]} + missing := required_fields - provided + count(missing) == 0 +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# CRE 31: Principles for Sound Stress Testing +# ═══════════════════════════════════════════════════════════════════════════════ + +# BAS-007: Credit scoring models must undergo quarterly stress testing +stress_test_current if { + input.model.model_type == "credit_scoring" + last_test := time.parse_rfc3339_ns(input.model.last_stress_test) + time.now_ns() - last_test < 7884000000000000 # 91.25 days +} + +# BAS-008: Stress test results must be reviewed by independent validation +stress_test_independently_reviewed if { + input.model.stress_test.reviewer != input.model.model_owner + input.model.stress_test.review_status == "APPROVED" +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# CRE 33: Data Quality +# ═══════════════════════════════════════════════════════════════════════════════ + +# BAS-009: Training data quality score must meet threshold +data_quality_adequate if { + input.model.data_quality_score >= 0.85 +} + +# BAS-010: PII handling must comply with data governance policy +pii_handling_compliant if { + input.data.pii_detected == true + input.data.pii_encrypted == true + input.data.consent_verified == true +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# CRE 35: Model Validation +# ═══════════════════════════════════════════════════════════════════════════════ + +# BAS-011: Independent validation required before production deployment +independent_validation_complete if { + input.model.validation.status == "COMPLETE" + input.model.validation.validator != input.model.model_owner + input.model.validation.validator_team != input.model.development_team +} + +# BAS-012: Back-testing results must be within acceptable thresholds +backtesting_acceptable if { + input.model.backtesting.ks_statistic < 0.15 + input.model.backtesting.auc_roc >= 0.70 + input.model.backtesting.gini >= 0.40 +} + +# BAS-013: Model capital impact assessment required for material models +capital_impact_assessed if { + not input.model.material_model +} + +capital_impact_assessed if { + input.model.material_model == true + input.model.capital_impact.assessment_date != "" + input.model.capital_impact.reviewer != "" + input.model.capital_impact.approved == true +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# CRE 36: Monitoring and Reporting +# ═══════════════════════════════════════════════════════════════════════════════ + +# BAS-014: Continuous monitoring must be active for all production models +monitoring_active if { + input.model.monitoring.status == "ACTIVE" + input.model.monitoring.drift_detection == true + input.model.monitoring.performance_tracking == true +} + +# BAS-015: Quarterly Basel III model risk report must be generated +quarterly_report_current if { + last_report := time.parse_rfc3339_ns(input.reporting.last_basel_report) + time.now_ns() - last_report < 7884000000000000 # 91.25 days +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# COMPOSITE COMPLIANCE CHECK +# ═══════════════════════════════════════════════════════════════════════════════ + +# Overall Basel III compliance (all CRE sections) +basel_iii_compliant if { + model_registered + model_risk_classified + model_documentation_complete + independent_validation_complete + monitoring_active +} + +# Compliance violations list +violations[msg] { + not model_registered + msg := "BAS-004: Model not registered in inventory (CRE 30.3)" +} + +violations[msg] { + not model_risk_classified + msg := "BAS-005: Model risk classification missing (CRE 30.3)" +} + +violations[msg] { + not model_documentation_complete + msg := "BAS-006: Model documentation incomplete (CRE 30.3)" +} + +violations[msg] { + not independent_validation_complete + msg := "BAS-011: Independent validation not complete (CRE 35)" +} + +violations[msg] { + not monitoring_active + msg := "BAS-014: Continuous monitoring not active (CRE 36)" +} diff --git a/artifacts/policies/eu_ai_act_kafka_enforcement.rego b/artifacts/policies/eu_ai_act_kafka_enforcement.rego new file mode 100644 index 00000000..54fe06ef --- /dev/null +++ b/artifacts/policies/eu_ai_act_kafka_enforcement.rego @@ -0,0 +1,331 @@ +# KACG-GSIFI-WP-017: EU AI Act Kafka Enforcement Policy +# Policy Group: compliance.euAiAct.kafka.* (28 rules) +# Purpose: Enforce EU AI Act requirements specific to Kafka-based AI governance +# infrastructure, including Art. 9 (Risk Management), Art. 10 (Data), +# Art. 12 (Record-Keeping), Art. 13 (Transparency), Art. 14 (Human Oversight) +# Framework: EU AI Act (Regulation (EU) 2024/1689) +# Last Updated: 2026-04-03 + +package compliance.eu_ai_act.kafka + +import future.keywords.in +import future.keywords.if + +# ===================================================================== +# Article 6 - Classification of High-Risk AI Systems +# ===================================================================== + +# RULE EUAIA-K-001: AI system risk classification +art_6_classification if { + input.aiSystem.riskClassification in ["HIGH_RISK", "LIMITED_RISK", "MINIMAL_RISK"] + input.aiSystem.classificationJustification != "" + input.aiSystem.classificationDate != "" + input.aiSystem.classificationPublishedToKafka == true +} + +# ===================================================================== +# Article 9 - Risk Management System +# ===================================================================== + +# RULE EUAIA-K-002: Continuous risk management via Kafka streams +art_9_1_risk_management if { + rm := input.aiSystem.riskManagement + rm.continuousProcess == true + rm.kafkaRiskEventsEnabled == true + rm.riskAssessmentFrequency in ["CONTINUOUS", "WEEKLY", "MONTHLY"] +} + +# RULE EUAIA-K-003: Risk identification and analysis +art_9_2_risk_identification if { + risks := input.aiSystem.identifiedRisks + count(risks) >= 1 + every risk in risks { + risk.severity in ["LOW", "MEDIUM", "HIGH", "CRITICAL"] + risk.mitigation != "" + } +} + +# RULE EUAIA-K-004: Risk mitigation measures +art_9_4_risk_mitigation if { + input.aiSystem.riskMitigation.measuresImplemented == true + input.aiSystem.riskMitigation.residualRiskAcceptable == true + input.aiSystem.riskMitigation.testingCompleted == true +} + +# ===================================================================== +# Article 10 - Data and Data Governance +# ===================================================================== + +# RULE EUAIA-K-005: Training data governance via Kafka +art_10_1_data_governance if { + data := input.aiSystem.dataGovernance + data.qualityScore >= 0.85 + data.relevanceAssessed == true + data.representativenessAssessed == true + data.freeOfErrors == true + data.completenessScore >= 0.90 +} + +# RULE EUAIA-K-006: Data quality monitoring via Kafka streams +art_10_2_data_monitoring if { + monitoring := input.aiSystem.dataMonitoring + monitoring.kafkaEnabled == true + monitoring.piiDetectionRate >= 0.997 + monitoring.dataQualityGatesActive == true + monitoring.biasDetectionEnabled == true +} + +# RULE EUAIA-K-007: Training data documentation +art_10_5_data_documentation if { + docs := input.aiSystem.dataDocumentation + docs.datasetDescription != "" + docs.collectionMethodology != "" + docs.preprocessingSteps != null + docs.statisticalProperties != null +} + +# ===================================================================== +# Article 12 - Record-Keeping (Kafka WORM) +# ===================================================================== + +# RULE EUAIA-K-008: Automatic event logging to Kafka WORM +art_12_1_record_keeping if { + logging := input.aiSystem.recordKeeping + logging.kafkaWormEnabled == true + logging.retentionYears >= 10 + logging.eventTypes != null + count(logging.eventTypes) >= 5 +} + +# RULE EUAIA-K-009: Log completeness validation +art_12_2_log_completeness if { + logs := input.aiSystem.loggingCompleteness + logs.inferenceEventsLogged == true + logs.trainingEventsLogged == true + logs.governanceDecisionsLogged == true + logs.biasAlertsLogged == true + logs.driftDetectionsLogged == true +} + +# RULE EUAIA-K-010: Tamper-evident audit trail +art_12_3_tamper_evident if { + audit := input.aiSystem.auditTrail + audit.hashChainEnabled == true + audit.hashAlgorithm == "SHA-256" + audit.merkleTreeSealing == true + audit.sealFrequency in ["HOURLY", "PER_BATCH"] + audit.signatureAlgorithm == "Ed25519" +} + +# RULE EUAIA-K-011: Evidence retention per EU AI Act +art_12_retention if { + retention := input.aiSystem.retention + retention.minimumYears >= 10 + retention.wormStorageMode == "COMPLIANCE" + retention.legalHoldCapable == true +} + +# ===================================================================== +# Article 13 - Transparency and Provision of Information +# ===================================================================== + +# RULE EUAIA-K-012: System transparency documentation +art_13_1_transparency if { + transparency := input.aiSystem.transparency + transparency.modelCard == true + transparency.technicalDocumentation == true + transparency.userInstructions == true + transparency.limitationsDocumented == true +} + +# RULE EUAIA-K-013: Automated decision explanation +art_13_explanation if { + explain := input.aiSystem.explainability + explain.enabled == true + explain.method != "" + explain.confidenceScoreProvided == true +} + +# ===================================================================== +# Article 14 - Human Oversight +# ===================================================================== + +# RULE EUAIA-K-014: Human oversight mechanisms +art_14_1_human_oversight if { + oversight := input.aiSystem.humanOversight + oversight.enabled == true + oversight.overrideCapability == true + oversight.killSwitchAvailable == true + oversight.confidenceThreshold >= 0.75 +} + +# RULE EUAIA-K-015: Kill-switch via Kafka events +art_14_killswitch if { + ks := input.aiSystem.killSwitch + ks.kafkaTopicEnabled == true + ks.topicName == "ai.killswitch.events" + ks.permanentRetention == true + ks.minInsyncReplicas >= 3 + ks.responseTtlMs <= 500 +} + +# RULE EUAIA-K-016: Human-in-the-loop gates +art_14_human_in_loop if { + hil := input.aiSystem.humanInLoop + hil.gatesConfigured == true + hil.confidenceThreshold >= 0.75 + hil.escalationPath != "" + hil.kafkaEscalationEnabled == true +} + +# ===================================================================== +# Article 15 - Accuracy, Robustness, and Cybersecurity +# ===================================================================== + +# RULE EUAIA-K-017: Accuracy monitoring via Kafka +art_15_1_accuracy if { + accuracy := input.aiSystem.accuracy + accuracy.monitoringEnabled == true + accuracy.kafkaMetricsEnabled == true + accuracy.baselineDocumented == true + accuracy.driftAlertThreshold != null +} + +# RULE EUAIA-K-018: Robustness and adversarial testing +art_15_4_robustness if { + robustness := input.aiSystem.robustness + robustness.adversarialTesting == true + robustness.failsafeMode != "" + robustness.redundancyConfigured == true +} + +# RULE EUAIA-K-019: Cybersecurity measures +art_15_5_cybersecurity if { + security := input.aiSystem.cybersecurity + security.mtlsEnabled == true + security.spiffeIdentity == true + security.encryptionAtRest == true + security.encryptionInTransit == true + security.penetrationTestDate != "" +} + +# ===================================================================== +# Article 17 - Quality Management System +# ===================================================================== + +# RULE EUAIA-K-020: Quality management documented +art_17_quality_management if { + qms := input.aiSystem.qualityManagement + qms.documented == true + qms.regulatoryCompliance == true + qms.riskManagementIntegrated == true + qms.testingProcedures == true + qms.changeManagement == true +} + +# ===================================================================== +# Article 26 - Obligations of Deployers +# ===================================================================== + +# RULE EUAIA-K-021: Deployer monitoring obligations +art_26_deployer_monitoring if { + deployer := input.deployer + deployer.monitoringEnabled == true + deployer.incidentReportingProcess == true + deployer.usageConsistentWithInstructions == true +} + +# ===================================================================== +# Article 61 - Post-Market Monitoring +# ===================================================================== + +# RULE EUAIA-K-022: Post-market monitoring via Kafka +art_61_post_market if { + pms := input.aiSystem.postMarketMonitoring + pms.planDocumented == true + pms.kafkaMonitoringEnabled == true + pms.driftDetectionEnabled == true + pms.incidentDetection == true + pms.reportingFrequency != "" +} + +# ===================================================================== +# Article 62 - Reporting of Serious Incidents +# ===================================================================== + +# RULE EUAIA-K-023: Incident reporting via Kafka WORM +art_62_incident_reporting if { + incident := input.aiSystem.incidentReporting + incident.processDocumented == true + incident.maxReportingHours <= 72 + incident.kafkaIncidentTopicEnabled == true + incident.wormRetentionEnabled == true + incident.regulatorNotificationProcess == true +} + +# ===================================================================== +# Kafka-Specific Enforcement Controls +# ===================================================================== + +# RULE EUAIA-K-024: All governance topics configured +kafka_governance_topics if { + topics := input.kafkaTopics + required_topics := { + "ai.inference.events", + "ai.training.events", + "ai.governance.decisions", + "ai.bias.alerts", + "ai.drift.detections", + "ai.killswitch.events", + "ai.compliance.evidence" + } + every t in required_topics { + some topic in topics + topic.name == t + } +} + +# RULE EUAIA-K-025: ACL enforcement active +kafka_acl_enforcement if { + input.kafkaConfig.aclEnforcementEnabled == true + input.kafkaConfig.opaAuthorizerDeployed == true + input.kafkaConfig.defaultDeny == true +} + +# RULE EUAIA-K-026: Schema registry enforced +kafka_schema_enforcement if { + input.kafkaConfig.schemaRegistryEnabled == true + input.kafkaConfig.schemaCompatibilityMode == "BACKWARD" + input.kafkaConfig.schemaValidationOnProduce == true +} + +# RULE EUAIA-K-027: WORM evidence storage operational +kafka_worm_operational if { + worm := input.wormStorage + worm.objectLockEnabled == true + worm.retentionMode == "COMPLIANCE" + worm.retentionDays >= 3652 + worm.durability == "99.999999999%" +} + +# RULE EUAIA-K-028: Evidence signing operational +kafka_evidence_signing if { + signing := input.evidenceSigning + signing.enabled == true + signing.algorithm == "Ed25519" + signing.hsmBacked == true + signing.latencyMs <= 300 +} + +# Compliance Summary +eu_ai_act_kafka_summary := { + "framework": "EU AI Act (Regulation (EU) 2024/1689)", + "docRef": "KACG-GSIFI-WP-017", + "totalRules": 28, + "kafkaSpecificRules": 12, + "articlesTargeted": ["6", "9", "10", "12", "13", "14", "15", "17", "26", "61", "62"], + "wormRetentionYears": 10, + "killSwitchTopicConfigured": true, + "evidenceSigningEnabled": true, + "schemaRegistryEnforced": true +} diff --git a/artifacts/policies/fair_lending_disparate_impact.rego b/artifacts/policies/fair_lending_disparate_impact.rego new file mode 100644 index 00000000..e081ec9a --- /dev/null +++ b/artifacts/policies/fair_lending_disparate_impact.rego @@ -0,0 +1,120 @@ +# Fair Lending Disparate Impact Policy +# GAF-GSIFI-WP-017, Domain 5 — Financial Services AI Governance +# Policy Group: PG-06 (Bias & Fairness) +# Regulatory alignment: FCRA ss. 607/615, ECOA ss. 701-706, EU AI Act Art. 10(2)(f) +# +# This policy enforces disparate impact (DI) thresholds for credit scoring AI models +# across all protected classes. DI is calculated as the ratio of the favorable outcome +# rate for the protected group to the favorable outcome rate for the control group. +# The four-fifths (80%) rule is the minimum threshold per EEOC/ECOA guidance. + +package fair_lending.disparate_impact + +import rego.v1 + +# Minimum disparate impact threshold (four-fifths rule) +default di_threshold := 0.80 + +# Enhanced threshold for production models after Q4 2027 +enhanced_di_threshold := 0.87 + +# Protected classes per FCRA/ECOA +protected_classes := [ + "race_ethnicity", + "sex_gender", + "age", + "national_origin", + "marital_status", + "religion", + "color", + "receipt_of_public_assistance" +] + +# DENY: Model fails disparate impact test for any protected class +deny contains msg if { + some test in input.di_tests + test.disparate_impact < di_threshold + msg := sprintf( + "FCRA/ECOA VIOLATION: Model '%s' fails DI test for protected class '%s' — DI %.3f < threshold %.2f. Adverse action notice required per FCRA ss. 615.", + [input.model_id, test.protected_class, test.disparate_impact, di_threshold] + ) +} + +# DENY: No DI test results provided for a credit scoring model +deny contains msg if { + input.model_type == "credit_scoring" + not input.di_tests + msg := sprintf( + "ECOA VIOLATION: Credit scoring model '%s' has no disparate impact test results. DI testing is mandatory per ECOA Reg B and EU AI Act Art. 10(2)(f).", + [input.model_id] + ) +} + +# DENY: Missing protected class in DI tests +deny contains msg if { + input.model_type == "credit_scoring" + some pc in protected_classes + not class_tested(pc) + msg := sprintf( + "ECOA VIOLATION: Model '%s' missing DI test for protected class '%s'. All protected classes must be tested.", + [input.model_id, pc] + ) +} + +# WARN: Model approaches DI threshold (within 5% of minimum) +warn contains msg if { + some test in input.di_tests + test.disparate_impact >= di_threshold + test.disparate_impact < (di_threshold + 0.05) + msg := sprintf( + "DI WARNING: Model '%s' protected class '%s' — DI %.3f is within 5%% of threshold. Recommend remediation.", + [input.model_id, test.protected_class, test.disparate_impact] + ) +} + +# WARN: Model below enhanced threshold (post-2027 target) +warn contains msg if { + some test in input.di_tests + test.disparate_impact >= di_threshold + test.disparate_impact < enhanced_di_threshold + msg := sprintf( + "ENHANCED DI: Model '%s' class '%s' — DI %.3f meets minimum but below enhanced target %.2f (Q4 2027 target).", + [input.model_id, test.protected_class, test.disparate_impact, enhanced_di_threshold] + ) +} + +# DENY: No adverse action reason codes for denied applications +deny contains msg if { + input.model_type == "credit_scoring" + input.generates_denials == true + not input.adverse_action_engine_active + msg := sprintf( + "FCRA VIOLATION: Model '%s' generates denials without adverse action reason codes. FCRA ss. 615 requires specific reasons for adverse actions.", + [input.model_id] + ) +} + +# DENY: Model documentation older than 12 months +deny contains msg if { + input.model_type == "credit_scoring" + input.last_documentation_update_days > 365 + msg := sprintf( + "SR 11-7 VIOLATION: Model '%s' documentation is %d days old (> 365 day limit). Model documentation must be current per SR 11-7 ss. 7.", + [input.model_id, input.last_documentation_update_days] + ) +} + +# Helper: check if a protected class has been tested +class_tested(pc) if { + some test in input.di_tests + test.protected_class == pc +} + +# Aggregate: overall DI compliance status +overall_compliance := "PASS" if { + count(deny) == 0 +} + +overall_compliance := "FAIL" if { + count(deny) > 0 +} diff --git a/artifacts/policies/gdpr_ai_data_protection.rego b/artifacts/policies/gdpr_ai_data_protection.rego new file mode 100644 index 00000000..fb4149ab --- /dev/null +++ b/artifacts/policies/gdpr_ai_data_protection.rego @@ -0,0 +1,218 @@ +# KACG-GSIFI-WP-017: GDPR AI Data Protection Policy +# Policy Group: data.privacy.gdpr.* (26 rules) +# Purpose: Enforce GDPR requirements for AI systems processing personal data, +# including automated decision-making (Art. 22), right to erasure (Art. 17), +# and record keeping (Art. 30) via Kafka WORM audit infrastructure +# Framework: GDPR (Regulation (EU) 2016/679) +# Last Updated: 2026-04-03 + +package data.privacy.gdpr + +import future.keywords.in +import future.keywords.if + +# Article 5 - Principles Relating to Processing + +# RULE GDPR-5.1a: Lawfulness, fairness, and transparency +art_5_1a_lawful_processing if { + processing := input.dataProcessing + processing.legalBasis in ["CONSENT", "CONTRACT", "LEGAL_OBLIGATION", "VITAL_INTERESTS", "PUBLIC_TASK", "LEGITIMATE_INTERESTS"] + processing.fairnessAssessed == true + processing.transparencyNotice == true +} + +# RULE GDPR-5.1b: Purpose limitation +art_5_1b_purpose_limitation if { + input.dataProcessing.purposes != null + count(input.dataProcessing.purposes) >= 1 + every purpose in input.dataProcessing.purposes { + purpose.specified == true + purpose.documented == true + } +} + +# RULE GDPR-5.1c: Data minimization +art_5_1c_data_minimization if { + input.dataProcessing.minimizationAssessed == true + input.dataProcessing.unnecessaryFieldsRemoved == true +} + +# RULE GDPR-5.1d: Accuracy +art_5_1d_accuracy if { + input.dataProcessing.accuracyMeasures == true + input.dataProcessing.dataQualityScore >= 0.85 + input.dataProcessing.rectificationProcessExists == true +} + +# RULE GDPR-5.1e: Storage limitation +art_5_1e_storage_limitation if { + input.dataProcessing.retentionPolicy != "" + input.dataProcessing.retentionScheduleDocumented == true + input.dataProcessing.automaticDeletion == true +} + +# RULE GDPR-5.1f: Integrity and confidentiality +art_5_1f_integrity if { + security := input.dataProcessing.security + security.encryptionAtRest == true + security.encryptionInTransit == true + security.accessControlEnforced == true +} + +# RULE GDPR-5.2: Accountability +art_5_2_accountability if { + input.dataProcessing.controllerIdentified == true + input.dataProcessing.processingRecordsKept == true + input.dataProcessing.dpiaCompleted == true +} + +# Article 13/14 - Transparency for AI Systems + +# RULE GDPR-13: Information to data subjects +art_13_transparency if { + notice := input.dataProcessing.transparencyNotice + notice.controllerIdentity != "" + notice.processingPurposes != null + notice.legalBasis != "" + notice.retentionPeriod != "" + notice.dataSubjectRights != null + notice.automatedDecisionMaking != null +} + +# Article 17 - Right to Erasure (Kafka ai.erasure.requests topic) + +# RULE GDPR-17.1: Erasure request processing +art_17_1_erasure_processing if { + erasure := input.erasureCapability + erasure.supportedSystems != null + count(erasure.supportedSystems) >= 1 + erasure.maxProcessingDays <= 30 + erasure.kafkaErasureTopicEnabled == true + erasure.verificationProcess == true +} + +# RULE GDPR-17.2: Erasure notification to recipients +art_17_2_erasure_notification if { + input.erasureCapability.recipientNotification == true + input.erasureCapability.downstreamSystemsNotified == true +} + +# Article 22 - Automated Decision-Making + +# RULE GDPR-22.1: Rights related to automated decision-making +art_22_1_automated_decisions if { + ai_decision := input.automatedDecisionMaking + ai_decision.humanInLoopAvailable == true + ai_decision.explainabilityEnabled == true + ai_decision.contestMechanism == true +} + +# RULE GDPR-22.3: Suitable safeguards for automated decisions +art_22_3_safeguards if { + safeguards := input.automatedDecisionMaking.safeguards + safeguards.humanReviewProcess == true + safeguards.rightToContestDecision == true + safeguards.biasMitigation == true + safeguards.confidenceThreshold >= 0.75 +} + +# Article 25 - Data Protection by Design and by Default + +# RULE GDPR-25.1: Data protection by design +art_25_1_by_design if { + design := input.dataProtectionByDesign + design.privacyImpactConsidered == true + design.minimizationByDefault == true + design.pseudonymizationApplied == true + design.encryptionImplemented == true +} + +# RULE GDPR-25.2: Data protection by default +art_25_2_by_default if { + defaults := input.dataProtectionByDefault + defaults.minimalDataCollection == true + defaults.restrictedAccessByDefault == true + defaults.limitedRetentionByDefault == true +} + +# Article 30 - Records of Processing (Kafka WORM) + +# RULE GDPR-30.1: Controller record of processing +art_30_1_processing_records if { + records := input.processingRecords + records.controllerName != "" + records.processingPurposes != null + records.categoriesOfDataSubjects != null + records.categoriesOfPersonalData != null + records.recipientCategories != null + records.retentionPeriods != null + records.securityMeasures != null + records.kafkaWormStorageEnabled == true + records.retentionYears >= 5 +} + +# Article 32 - Security of Processing + +# RULE GDPR-32.1: Appropriate technical and organizational measures +art_32_1_security if { + security := input.securityMeasures + security.pseudonymization == true + security.encryptionAtRest == true + security.encryptionInTransit == true + security.confidentiality == true + security.integrity == true + security.availability == true + security.resilience == true + security.regularTesting == true +} + +# Article 35 - DPIA + +# RULE GDPR-35: DPIA for high-risk AI processing +art_35_dpia if { + dpia := input.dpia + dpia.completed == true + dpia.systematicDescription == true + dpia.necessityAssessment == true + dpia.riskAssessment == true + dpia.mitigationMeasures != null + dpia.dpoConsulted == true + dpia.approvalDate != "" +} + +# PII Detection for Kafka Streams + +# RULE GDPR-PII-001: PII detection rate meets threshold +pii_detection_threshold if { + input.piiDetection.detectionRate >= 0.997 + input.piiDetection.scanEnabled == true + input.piiDetection.realTimeScanning == true +} + +# RULE GDPR-PII-002: PII masking enforcement +pii_masking_enforcement if { + input.piiDetection.maskingEnabled == true + input.piiDetection.maskingAppliedBeforePublish == true +} + +# RULE GDPR-CONSENT-001: Consent changes tracked via Kafka +consent_tracking if { + consent := input.consentManagement + consent.kafkaTopicEnabled == true + consent.topicName == "ai.consent.changes" + consent.transactional == true + consent.retentionYears >= 5 +} + +# Compliance Summary +gdpr_compliance_summary := { + "framework": "GDPR (EU) 2016/679", + "docRef": "KACG-GSIFI-WP-017", + "totalRules": 26, + "kafkaSpecificRules": 5, + "articlesTargeted": ["5", "13", "14", "17", "22", "25", "30", "32", "35"], + "piiDetectionThreshold": 0.997, + "erasureTopicEnabled": true, + "consentTopicEnabled": true, + "wormRetentionYears": 5 +} diff --git a/artifacts/policies/iso42001_aims_governance.rego b/artifacts/policies/iso42001_aims_governance.rego new file mode 100644 index 00000000..44d4fc4b --- /dev/null +++ b/artifacts/policies/iso42001_aims_governance.rego @@ -0,0 +1,328 @@ +# KACG-GSIFI-WP-017: ISO/IEC 42001 AIMS Governance Policy +# Policy Group: compliance.iso42001.* (32 rules) +# Purpose: Enforce ISO/IEC 42001:2023 AI Management System (AIMS) requirements +# with Kafka-based evidence collection and WORM storage verification +# Framework: ISO/IEC 42001:2023 — AI Management System +# Last Updated: 2026-04-03 + +package compliance.iso42001 + +import future.keywords.in +import future.keywords.if + +# ═══════════════════════════════════════════════════════════════════════════════ +# Clause 4 — Context of the Organization +# ═══════════════════════════════════════════════════════════════════════════════ + +# RULE ISO-4.1: Understanding the organization and its context +clause_4_1_org_context if { + ctx := input.aiSystem.organizationalContext + ctx.documented == true + ctx.externalFactors != null + ctx.internalFactors != null + ctx.lastReviewDate != "" +} + +# RULE ISO-4.2: Understanding needs and expectations of interested parties +clause_4_2_interested_parties if { + parties := input.aiSystem.interestedParties + count(parties) >= 3 + some p in parties + p.type == "REGULATOR" + some p2 in parties + p2.type == "DATA_SUBJECT" +} + +# RULE ISO-4.3: Scope of the AIMS +clause_4_3_aims_scope if { + scope := input.aiSystem.aimsScope + scope.defined == true + scope.boundaries != "" + scope.applicableRegulations != null + count(scope.applicableRegulations) >= 1 +} + +# RULE ISO-4.4: AIMS processes established +clause_4_4_aims_established if { + aims := input.aiSystem.aims + aims.established == true + aims.processesDocumented == true + aims.continuousImprovement == true +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# Clause 5 — Leadership +# ═══════════════════════════════════════════════════════════════════════════════ + +# RULE ISO-5.1: Leadership commitment +clause_5_1_leadership if { + leadership := input.aiSystem.leadership + leadership.boardOversight == true + leadership.aiCommitteeEstablished == true + leadership.resourcesAllocated == true +} + +# RULE ISO-5.2: AI policy established +clause_5_2_ai_policy if { + policy := input.aiSystem.aiPolicy + policy.documented == true + policy.approvedByLeadership == true + policy.communicatedToOrganization == true + policy.reviewSchedule != "" +} + +# RULE ISO-5.3: Roles, responsibilities, and authorities +clause_5_3_roles if { + roles := input.aiSystem.governance.raci + count(roles.roles) >= 5 + some r in roles.roles + r.type == "ACCOUNTABLE" + roles.documented == true +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# Clause 6 — Planning +# ═══════════════════════════════════════════════════════════════════════════════ + +# RULE ISO-6.1.1: Actions to address risks +clause_6_1_1_risk_actions if { + riskActions := input.aiSystem.riskManagement + riskActions.riskAssessmentCompleted == true + riskActions.riskTreatmentPlan != null + count(riskActions.identifiedRisks) >= 1 +} + +# RULE ISO-6.1.4: AI risk assessment +clause_6_1_4_ai_risk_assessment if { + assessment := input.aiSystem.aiRiskAssessment + assessment.methodology != "" + assessment.riskScore >= 0 + assessment.lastAssessmentDate != "" + assessment.reviewedByRiskCommittee == true +} + +# RULE ISO-6.2: AI objectives and plans +clause_6_2_objectives if { + objectives := input.aiSystem.aiObjectives + count(objectives) >= 3 + every obj in objectives { + obj.measurable == true + obj.timebound == true + obj.owner != "" + } +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# Clause 7 — Support +# ═══════════════════════════════════════════════════════════════════════════════ + +# RULE ISO-7.1: Resources for AIMS +clause_7_1_resources if { + resources := input.aiSystem.resources + resources.budgetAllocated == true + resources.personnelAssigned == true + resources.toolsProvisioned == true +} + +# RULE ISO-7.2: Competence +clause_7_2_competence if { + competence := input.aiSystem.competence + competence.trainingProgram == true + competence.assessmentCompleted == true + competence.gapAnalysis != null +} + +# RULE ISO-7.4: Communication +clause_7_4_communication if { + comm := input.aiSystem.communication + comm.internalCommunication == true + comm.externalCommunication == true + comm.stakeholderReporting == true +} + +# RULE ISO-7.5: Documented information +# Kafka-specific: Verify evidence is stored in WORM storage +clause_7_5_documented_info if { + docs := input.aiSystem.documentedInformation + docs.controlled == true + docs.versionManaged == true + docs.retentionPolicy != "" + docs.wormStorageEnabled == true +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# Clause 8 — Operation +# ═══════════════════════════════════════════════════════════════════════════════ + +# RULE ISO-8.1: Operational planning and control +clause_8_1_operational_planning if { + ops := input.aiSystem.operationalPlanning + ops.processesPlanned == true + ops.controlsImplemented == true + ops.changeManagement == true +} + +# RULE ISO-8.2: AI risk assessment execution +clause_8_2_risk_execution if { + execution := input.aiSystem.riskAssessmentExecution + execution.completed == true + execution.resultDocumented == true + execution.outputsAvailable == true +} + +# RULE ISO-8.3: AI risk treatment execution +clause_8_3_treatment_execution if { + treatment := input.aiSystem.riskTreatmentExecution + treatment.planImplemented == true + treatment.controlsOperational == true + treatment.residualRiskAcceptable == true +} + +# RULE ISO-8.4: AI system impact assessment +# Kafka-specific: Impact assessments published to governance topic +clause_8_4_impact_assessment if { + impact := input.aiSystem.impactAssessment + impact.completed == true + impact.socialImpact != null + impact.humanRightsAssessment == true + impact.publishedToKafka == true +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# Clause 9 — Performance Evaluation +# ═══════════════════════════════════════════════════════════════════════════════ + +# RULE ISO-9.1: Monitoring, measurement, analysis, and evaluation +clause_9_1_monitoring if { + monitoring := input.aiSystem.monitoring + monitoring.metricsCollected == true + monitoring.analysisPerformed == true + monitoring.evaluationSchedule != "" + monitoring.kafkaMetricsEnabled == true +} + +# RULE ISO-9.2: Internal audit +clause_9_2_internal_audit if { + audit := input.aiSystem.internalAudit + audit.programEstablished == true + audit.frequency in ["QUARTERLY", "SEMI_ANNUAL", "ANNUAL"] + audit.lastAuditDate != "" + audit.findingsDocumented == true +} + +# RULE ISO-9.3: Management review +clause_9_3_management_review if { + review := input.aiSystem.managementReview + review.conducted == true + review.frequency in ["QUARTERLY", "SEMI_ANNUAL"] + review.outputsDocumented == true + review.improvementActionsIdentified == true +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# Clause 10 — Improvement +# ═══════════════════════════════════════════════════════════════════════════════ + +# RULE ISO-10.1: Nonconformity and corrective action +clause_10_1_corrective_action if { + corrective := input.aiSystem.correctiveAction + corrective.processEstablished == true + corrective.nonconformitiesTracked == true + corrective.rootCauseAnalysis == true +} + +# RULE ISO-10.2: Continual improvement +clause_10_2_continual_improvement if { + improvement := input.aiSystem.continualImprovement + improvement.processEstablished == true + improvement.improvementPlanDocumented == true + improvement.kpiTracking == true +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# Annex A — Reference Controls +# ═══════════════════════════════════════════════════════════════════════════════ + +# RULE ISO-A.5.2: AI policies for the organization +annex_a_5_2_policies if { + input.aiSystem.governance.opaPolicyCoverage >= 0.85 + input.aiSystem.governance.policyVersioning == true + input.aiSystem.governance.policyReviewSchedule != "" +} + +# RULE ISO-A.5.4: AI system inventory +annex_a_5_4_inventory if { + inventory := input.aiSystem.inventory + inventory.maintained == true + inventory.allSystemsRegistered == true + inventory.classificationApplied == true + inventory.riskLevelAssigned == true +} + +# RULE ISO-A.6.1.3: Access controls for AI systems +# Kafka-specific: Verify Kafka ACL governance is in place +annex_a_6_1_3_access_controls if { + acl := input.aiSystem.accessControls + acl.kafkaAclEnabled == true + acl.opaAuthorizerDeployed == true + acl.spiffeIdentity == true + acl.breakGlassProtocol == true + acl.auditTrailEnabled == true +} + +# RULE ISO-A.7.1: Data governance for AI +annex_a_7_1_data_governance if { + data := input.aiSystem.dataGovernance + data.qualityGates == true + data.qualityScore >= 0.85 + data.lineageDocumented == true + data.consentManagement == true +} + +# RULE ISO-A.8.2: AI system lifecycle +annex_a_8_2_lifecycle if { + lifecycle := input.aiSystem.lifecycle + lifecycle.designPhase == true + lifecycle.developmentPhase == true + lifecycle.deploymentPhase == true + lifecycle.monitoringPhase == true + lifecycle.retirementPhase == true + lifecycle.governanceGatesAtEachPhase == true +} + +# RULE ISO-A.8.4: AI system monitoring +# Kafka-specific: Continuous monitoring via Kafka event streams +annex_a_8_4_monitoring if { + monitoring := input.aiSystem.monitoring + monitoring.continuousEnabled == true + monitoring.kafkaEventStreaming == true + monitoring.driftDetection == true + monitoring.biasMonitoring == true + monitoring.performanceBaseline == true + monitoring.alertingConfigured == true +} + +# RULE ISO-A.9.1: AI system documentation +annex_a_9_1_documentation if { + docs := input.aiSystem.documentation + docs.modelCards == true + docs.technicalDocumentation == true + docs.riskAssessment == true + docs.impactAssessment == true + docs.auditTrail == true +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# Certification Readiness Score +# ═══════════════════════════════════════════════════════════════════════════════ + +certification_readiness := { + "framework": "ISO/IEC 42001:2023", + "docRef": "KACG-GSIFI-WP-017", + "totalClauses": 10, + "totalAnnexControls": 7, + "totalRules": 32, + "kafkaSpecificRules": 5, + "evidenceStorageVerification": true, + "wormCompliance": true +} diff --git a/artifacts/policies/kafka_acl_governance.rego b/artifacts/policies/kafka_acl_governance.rego new file mode 100644 index 00000000..230df284 --- /dev/null +++ b/artifacts/policies/kafka_acl_governance.rego @@ -0,0 +1,191 @@ +# KACG-GSIFI-WP-017: Kafka ACL Governance Policy +# Policy Group: kafka.acl.* (34 rules) +# Purpose: Enforce topic-level, consumer-group, and transactional ACLs +# across all AI governance event streams with cryptographic identity binding +# Frameworks: ISO/IEC 42001 A.6.1.3, NIST AI RMF GOVERN 6.1, EU AI Act Art. 9.4b +# Last Updated: 2026-04-03 + +package kafka.authz + +import future.keywords.in +import future.keywords.if + +default allow := false + +# ═══════════════════════════════════════════════════════════════════════════════ +# RULE K-001: Enforce topic-level PRODUCE ACLs via SPIFFE identity +# Regulatory: ISO 42001 A.6.1.3, NIST GOVERN 6.1 +# ═══════════════════════════════════════════════════════════════════════════════ +allow if { + input.action.operation == "WRITE" + input.action.resourcePattern.resourceType == "TOPIC" + topic := input.action.resourcePattern.name + principal := input.requestContext.principal.name + acl_entry := data.kafka.acl_matrix[topic].produce[_] + glob.match(acl_entry, ["/"], principal) + not blocked_principal(principal) +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# RULE K-002: Enforce topic-level CONSUME ACLs +# Regulatory: ISO 42001 A.6.1.3, NIST GOVERN 6.1, SR 11-7 §4 +# ═══════════════════════════════════════════════════════════════════════════════ +allow if { + input.action.operation == "READ" + input.action.resourcePattern.resourceType == "TOPIC" + topic := input.action.resourcePattern.name + principal := input.requestContext.principal.name + acl_entry := data.kafka.acl_matrix[topic].consume[_] + glob.match(acl_entry, ["/"], principal) + valid_consumer_group(principal, topic) +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# RULE K-003: Enforce transactional requirements for evidence topics +# Regulatory: EU AI Act Art. 12 (record-keeping integrity) +# ═══════════════════════════════════════════════════════════════════════════════ +allow if { + input.action.operation == "WRITE" + input.action.resourcePattern.resourceType == "TOPIC" + topic := input.action.resourcePattern.name + data.kafka.acl_matrix[topic].transactional == true + input.requestContext.transactionalId != "" + valid_transaction_principal(input.requestContext.principal.name, topic) +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# RULE K-004: Kill-switch topic — exclusive write access +# Regulatory: All frameworks (safety-critical control) +# Cardinal invariant: Only kill-switch-controller may write to kill-switch topic +# ═══════════════════════════════════════════════════════════════════════════════ +allow if { + input.action.operation == "WRITE" + input.action.resourcePattern.name == "ai.killswitch.events" + input.requestContext.principal.name == "User:CN=kill-switch-controller" +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# RULE K-005: Evidence topic — exclusive write access +# Regulatory: SR 11-7 §7, EU AI Act Art. 11, ISO 42001 A.9.2 +# Only evidence-generator may produce to compliance evidence topic +# ═══════════════════════════════════════════════════════════════════════════════ +allow if { + input.action.operation == "WRITE" + input.action.resourcePattern.name == "ai.compliance.evidence" + input.requestContext.principal.name == "User:CN=evidence-generator" + input.requestContext.transactionalId != "" +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# RULE K-006: Kill-switch topic — universal read access for governance services +# All governance services must be able to receive kill-switch signals +# ═══════════════════════════════════════════════════════════════════════════════ +allow if { + input.action.operation == "READ" + input.action.resourcePattern.name == "ai.killswitch.events" + is_governance_principal(input.requestContext.principal.name) +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# RULE K-007: Consumer group assignment governance +# Regulatory: ISO 42001 A.6.1.3 (access control) +# ═══════════════════════════════════════════════════════════════════════════════ +allow if { + input.action.operation == "READ" + input.action.resourcePattern.resourceType == "GROUP" + group_id := input.action.resourcePattern.name + principal := input.requestContext.principal.name + data.kafka.consumer_groups[principal].group_id == group_id + data.kafka.consumer_groups[principal].status == "ACTIVE" +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# RULE K-008: Break-glass emergency override (logged, alerted, time-bound) +# Requires dual approval, time-bounded, mandatory post-mortem +# ═══════════════════════════════════════════════════════════════════════════════ +allow if { + input.action.operation in {"READ", "WRITE"} + is_break_glass_active(input.requestContext.principal.name) + time.now_ns() < data.break_glass.expiry_ns +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# RULE K-009: Cluster-level operations restricted to SRE +# ═══════════════════════════════════════════════════════════════════════════════ +allow if { + input.action.resourcePattern.resourceType == "CLUSTER" + input.requestContext.principal.name in data.kafka.cluster_admins +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# RULE K-010: Schema Registry access governance +# Only authorized services may register or evolve schemas +# ═══════════════════════════════════════════════════════════════════════════════ +allow if { + input.action.operation == "WRITE" + input.action.resourcePattern.resourceType == "TOPIC" + startswith(input.action.resourcePattern.name, "_schemas") + input.requestContext.principal.name in data.kafka.schema_admins +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# HELPER FUNCTIONS +# ═══════════════════════════════════════════════════════════════════════════════ + +# Validate consumer group membership +valid_consumer_group(principal, topic) if { + group := data.kafka.consumer_groups[principal] + group.topics[_] == topic + group.status == "ACTIVE" +} + +# Validate transactional principal +valid_transaction_principal(principal, topic) if { + tx := data.kafka.transactional_ids[principal] + tx.allowed_topics[_] == topic + tx.status == "ACTIVE" +} + +# Check principal not in block list +blocked_principal(principal) if { + data.kafka.blocked_principals[_] == principal +} + +# Check if principal is a governance service +is_governance_principal(principal) if { + data.kafka.governance_principals[_] == principal +} + +# Break-glass validation (dual approval, not self-approved) +is_break_glass_active(principal) if { + bg := data.break_glass.sessions[_] + bg.principal == principal + bg.approved_by != principal + bg.status == "ACTIVE" + count(bg.approvers) >= 2 +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# DENY RULES (explicit blocks take precedence) +# ═══════════════════════════════════════════════════════════════════════════════ + +# RULE K-011: Deny blocked principals unconditionally +deny if { + blocked_principal(input.requestContext.principal.name) +} + +# RULE K-012: Deny write to kill-switch from non-controller +deny if { + input.action.operation == "WRITE" + input.action.resourcePattern.name == "ai.killswitch.events" + input.requestContext.principal.name != "User:CN=kill-switch-controller" + not is_break_glass_active(input.requestContext.principal.name) +} + +# RULE K-013: Deny write to evidence topic from non-generator +deny if { + input.action.operation == "WRITE" + input.action.resourcePattern.name == "ai.compliance.evidence" + input.requestContext.principal.name != "User:CN=evidence-generator" + not is_break_glass_active(input.requestContext.principal.name) +} diff --git a/artifacts/policies/nist_ai_rmf_govern.rego b/artifacts/policies/nist_ai_rmf_govern.rego new file mode 100644 index 00000000..0e31b4c3 --- /dev/null +++ b/artifacts/policies/nist_ai_rmf_govern.rego @@ -0,0 +1,387 @@ +# KACG-GSIFI-WP-017: NIST AI RMF Governance Policy +# Policy Group: compliance.nistAiRmf.* (38 rules) +# Purpose: Enforce NIST AI Risk Management Framework requirements +# for AI system governance, mapping, measurement, and management +# Framework: NIST AI RMF 1.0 (January 2023) +# Last Updated: 2026-04-03 + +package compliance.nist_ai_rmf + +import future.keywords.in +import future.keywords.if + +# ═══════════════════════════════════════════════════════════════════════════════ +# GOVERN Function — Organizational AI Governance +# ═══════════════════════════════════════════════════════════════════════════════ + +# RULE NIST-G-001: GOVERN 1.1 — Legal and regulatory requirements identified +# Requires AI systems to have documented regulatory mapping +govern_1_1_regulatory_mapping if { + input.aiSystem.regulatoryMapping != null + count(input.aiSystem.regulatoryMapping.frameworks) >= 1 + input.aiSystem.regulatoryMapping.lastReviewDate != "" +} + +# RULE NIST-G-002: GOVERN 1.2 — Trustworthy AI characteristics integrated +# Requires documented trustworthiness characteristics +govern_1_2_trustworthy_characteristics if { + characteristics := input.aiSystem.trustworthiness + characteristics.valid == true + characteristics.explainability != null + characteristics.fairness != null + characteristics.privacy != null + characteristics.security != null + characteristics.safety != null + characteristics.accountability != null + characteristics.transparency != null +} + +# RULE NIST-G-003: GOVERN 2.1 — Roles and responsibilities defined +# Requires RACI matrix for AI system governance +govern_2_1_roles_defined if { + raci := input.aiSystem.governance.raci + count(raci.roles) >= 3 + some role in raci.roles + role.type == "ACCOUNTABLE" +} + +# RULE NIST-G-004: GOVERN 2.2 — AI risk management integrated into enterprise risk +govern_2_2_enterprise_risk_integration if { + input.aiSystem.riskManagement.integratedWithEnterprise == true + input.aiSystem.riskManagement.riskFrameworkAlignment != "" +} + +# RULE NIST-G-005: GOVERN 3.1 — Decision-making documented for AI lifecycle +govern_3_1_lifecycle_decisions if { + lifecycle := input.aiSystem.lifecycle + lifecycle.designDecisions != null + lifecycle.deploymentDecisions != null + lifecycle.monitoringDecisions != null +} + +# RULE NIST-G-006: GOVERN 4.1 — Organizational practices for AI risk management +govern_4_1_org_practices if { + practices := input.aiSystem.governance.practices + practices.policyInfrastructure == true + practices.trainingProgram == true + practices.incidentResponse == true + practices.auditSchedule != "" +} + +# RULE NIST-G-007: GOVERN 4.2 — Organizational teams have AI risk awareness +govern_4_2_risk_awareness if { + training := input.aiSystem.governance.training + training.completionRate >= 0.80 + training.lastAssessmentDate != "" +} + +# RULE NIST-G-008: GOVERN 5.1 — Organizational AI risk tolerance documented +govern_5_1_risk_tolerance if { + tolerance := input.aiSystem.riskManagement.tolerance + tolerance.documented == true + tolerance.maxAcceptableRiskScore >= 0 + tolerance.approvedByBoard == true +} + +# RULE NIST-G-009: GOVERN 6.1 — Policies and procedures in place +# Kafka-specific: Verify OPA policy coverage for governance decisions +govern_6_1_policies_in_place if { + input.aiSystem.governance.opaPolicyCoverage >= 0.90 + input.aiSystem.governance.sentinelRules >= 800 + input.aiSystem.governance.policyVersioning == true +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# MAP Function — Contextual AI Risk Mapping +# ═══════════════════════════════════════════════════════════════════════════════ + +# RULE NIST-M-001: MAP 1.1 — Intended purposes documented +map_1_1_intended_purpose if { + purpose := input.aiSystem.purpose + purpose.description != "" + purpose.intendedUse != "" + purpose.limitations != null + count(purpose.limitations) >= 1 +} + +# RULE NIST-M-002: MAP 1.2 — Interdisciplinary AI stakeholders identified +map_1_2_stakeholders if { + stakeholders := input.aiSystem.stakeholders + count(stakeholders) >= 3 + some s in stakeholders + s.role == "DOMAIN_EXPERT" +} + +# RULE NIST-M-003: MAP 1.5 — Deployment environment documented +map_1_5_deployment_env if { + env := input.aiSystem.deployment + env.environment != "" + env.infrastructure != "" + env.scalingRequirements != null +} + +# RULE NIST-M-004: MAP 1.6 — Broader impacts considered +map_1_6_broader_impacts if { + impacts := input.aiSystem.impactAssessment + impacts.socialImpact != null + impacts.environmentalImpact != null + impacts.economicImpact != null + impacts.assessmentDate != "" +} + +# RULE NIST-M-005: MAP 2.1 — AI system categorized by risk +map_2_1_risk_categorization if { + risk := input.aiSystem.riskCategorization + risk.level in ["LOW", "MEDIUM", "HIGH", "CRITICAL"] + risk.methodology != "" + risk.lastAssessmentDate != "" +} + +# RULE NIST-M-006: MAP 2.3 — Data quality and relevance documented +# Kafka-specific: Verify data governance for AI training/inference streams +map_2_3_data_quality if { + data := input.aiSystem.dataGovernance + data.qualityScore >= 0.85 + data.piiDetectionRate >= 0.997 + data.dataLineageDocumented == true +} + +# RULE NIST-M-007: MAP 3.1 — Benefits and costs documented +map_3_1_benefits_costs if { + analysis := input.aiSystem.costBenefitAnalysis + analysis.documented == true + analysis.netPresentValue != null + analysis.lastReviewDate != "" +} + +# RULE NIST-M-008: MAP 3.5 — Existing safeguards and controls identified +map_3_5_safeguards if { + controls := input.aiSystem.controls + count(controls) >= 5 + some c in controls + c.type == "KILL_SWITCH" + some c2 in controls + c2.type == "HUMAN_OVERSIGHT" +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# MEASURE Function — Risk Assessment & Analysis +# ═══════════════════════════════════════════════════════════════════════════════ + +# RULE NIST-ME-001: MEASURE 1.1 — Appropriate metrics identified +measure_1_1_metrics if { + metrics := input.aiSystem.metrics + count(metrics) >= 5 + some m in metrics + m.category == "FAIRNESS" + some m2 in metrics + m2.category == "PERFORMANCE" + some m3 in metrics + m3.category == "SECURITY" +} + +# RULE NIST-ME-002: MEASURE 2.1 — Evaluations conducted regularly +measure_2_1_evaluations if { + eval := input.aiSystem.evaluation + eval.frequency in ["CONTINUOUS", "WEEKLY", "MONTHLY"] + eval.lastEvaluationDate != "" + eval.automated == true +} + +# RULE NIST-ME-003: MEASURE 2.3 — AI system performance validated +# Kafka-specific: Verify model performance monitoring via Kafka streams +measure_2_3_performance_validation if { + perf := input.aiSystem.performance + perf.validated == true + perf.validationMethod != "" + perf.kafkaMonitoringEnabled == true + perf.driftDetectionEnabled == true +} + +# RULE NIST-ME-004: MEASURE 2.5 — AI system tested for biases +measure_2_5_bias_testing if { + bias := input.aiSystem.biasTesting + bias.disparateImpactRatio >= 0.80 + bias.testingFrequency in ["CONTINUOUS", "WEEKLY", "MONTHLY"] + bias.lastTestDate != "" + count(bias.protectedAttributes) >= 3 +} + +# RULE NIST-ME-005: MEASURE 2.6 — AI system evaluated for safety +measure_2_6_safety_evaluation if { + safety := input.aiSystem.safetyEvaluation + safety.completed == true + safety.killSwitchTested == true + safety.failsafeMode != "" + safety.lastEvaluationDate != "" +} + +# RULE NIST-ME-006: MEASURE 2.7 — AI system security evaluated +measure_2_7_security_evaluation if { + security := input.aiSystem.securityEvaluation + security.penetrationTestDate != "" + security.vulnerabilityScan == true + security.adversarialRobustness != null +} + +# RULE NIST-ME-007: MEASURE 2.11 — Fairness assessed +measure_2_11_fairness if { + fairness := input.aiSystem.fairnessAssessment + fairness.completed == true + fairness.disparateImpactRatio >= 0.80 + fairness.equalOpportunityDifference <= 0.10 + count(fairness.protectedClasses) >= 3 +} + +# RULE NIST-ME-008: MEASURE 3.1 — Risk tracking approaches +measure_3_1_risk_tracking if { + tracking := input.aiSystem.riskTracking + tracking.riskRegisterMaintained == true + tracking.reviewFrequency in ["WEEKLY", "MONTHLY", "QUARTERLY"] + tracking.escalationProcedure != "" +} + +# RULE NIST-ME-009: MEASURE 4.1 — Measurement approaches for identified risks +# Kafka-specific: Evidence bundles generated for all risk measurements +measure_4_1_evidence_generation if { + evidence := input.aiSystem.evidenceGeneration + evidence.enabled == true + evidence.wormStorageEnabled == true + evidence.signatureAlgorithm == "Ed25519" + evidence.retentionYears >= 7 +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# MANAGE Function — Risk Response & Monitoring +# ═══════════════════════════════════════════════════════════════════════════════ + +# RULE NIST-MA-001: MANAGE 1.1 — Risk treatments planned and implemented +manage_1_1_risk_treatments if { + treatments := input.aiSystem.riskTreatments + count(treatments) >= 1 + every treatment in treatments { + treatment.status in ["IMPLEMENTED", "IN_PROGRESS", "PLANNED"] + treatment.owner != "" + } +} + +# RULE NIST-MA-002: MANAGE 1.3 — Responses to identified risks +manage_1_3_risk_response if { + response := input.aiSystem.riskResponse + response.incidentResponsePlan == true + response.escalationMatrix != null + response.meanTimeToResponseMinutes <= 15 +} + +# RULE NIST-MA-003: MANAGE 2.1 — Resources allocated for AI risk management +manage_2_1_resources if { + resources := input.aiSystem.riskResources + resources.budgetAllocated == true + resources.teamSize >= 3 + resources.toolsProvisioned == true +} + +# RULE NIST-MA-004: MANAGE 2.2 — Mechanisms for feedback about AI system performance +# Kafka-specific: Verify Kafka-based feedback loop for continuous monitoring +manage_2_2_feedback_mechanisms if { + feedback := input.aiSystem.feedbackMechanisms + feedback.kafkaStreamEnabled == true + feedback.humanInLoopGates == true + feedback.confidenceThreshold >= 0.75 + feedback.alertingEnabled == true +} + +# RULE NIST-MA-005: MANAGE 3.1 — AI risks and benefits continuously monitored +manage_3_1_continuous_monitoring if { + monitoring := input.aiSystem.continuousMonitoring + monitoring.enabled == true + monitoring.metricsCount >= 10 + monitoring.alertRulesCount >= 5 + monitoring.dashboardAvailable == true +} + +# RULE NIST-MA-006: MANAGE 3.2 — Pre-defined events trigger review +manage_3_2_trigger_events if { + triggers := input.aiSystem.reviewTriggers + count(triggers) >= 3 + some t in triggers + t.event == "DRIFT_DETECTED" + some t2 in triggers + t2.event == "BIAS_THRESHOLD_EXCEEDED" +} + +# RULE NIST-MA-007: MANAGE 4.1 — Risk treatment status monitored +manage_4_1_treatment_monitoring if { + monitoring := input.aiSystem.treatmentMonitoring + monitoring.trackingEnabled == true + monitoring.reportingFrequency in ["WEEKLY", "MONTHLY"] + monitoring.dashboardIntegration == true +} + +# RULE NIST-MA-008: MANAGE 4.2 — AI system decommissioning documented +manage_4_2_decommissioning if { + decom := input.aiSystem.decommissioningPlan + decom.documented == true + decom.dataDispositionPlan != "" + decom.evidenceArchivalPlan != "" + decom.regulatoryNotificationRequired != null +} + +# ═══════════════════════════════════════════════════════════════════════════════ +# Aggregate Compliance Score +# ═══════════════════════════════════════════════════════════════════════════════ + +# Count passing GOVERN rules +govern_pass_count := count([1 | + govern_1_1_regulatory_mapping +]) + count([1 | + govern_1_2_trustworthy_characteristics +]) + count([1 | + govern_2_1_roles_defined +]) + count([1 | + govern_2_2_enterprise_risk_integration +]) + count([1 | + govern_3_1_lifecycle_decisions +]) + count([1 | + govern_4_1_org_practices +]) + count([1 | + govern_4_2_risk_awareness +]) + count([1 | + govern_5_1_risk_tolerance +]) + count([1 | + govern_6_1_policies_in_place +]) + +govern_total := 9 + +# Count passing MAP rules +map_pass_count := count([1 | + map_1_1_intended_purpose +]) + count([1 | + map_1_2_stakeholders +]) + count([1 | + map_1_5_deployment_env +]) + count([1 | + map_1_6_broader_impacts +]) + count([1 | + map_2_1_risk_categorization +]) + count([1 | + map_2_3_data_quality +]) + count([1 | + map_3_1_benefits_costs +]) + count([1 | + map_3_5_safeguards +]) + +map_total := 8 + +# Summary for API consumption +nist_compliance_summary := { + "framework": "NIST AI RMF 1.0", + "docRef": "KACG-GSIFI-WP-017", + "governScore": sprintf("%d/%d", [govern_pass_count, govern_total]), + "mapScore": sprintf("%d/%d", [map_pass_count, map_total]), + "totalRules": 38, + "kafkaIntegrationRules": 5, + "timestamp": time.now_ns() +} diff --git a/artifacts/schemas/compute-registry.schema.json b/artifacts/schemas/compute-registry.schema.json new file mode 100644 index 00000000..291b8059 --- /dev/null +++ b/artifacts/schemas/compute-registry.schema.json @@ -0,0 +1,88 @@ +{ + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$id": "https://governance.enterprise.ai/schemas/compute-registry.schema.json", + "title": "Global Compute Facility Registry Entry", + "description": "Schema for registering compute facilities in the Global Compute Registry, per ICGC standards (GAF-GSIFI-WP-017, Domain 4). Supports GACRA and GACRLS compliance.", + "type": "object", + "required": ["facility_id", "operator", "jurisdiction", "total_flops", "gpu_type", "gpu_count", "power_mw", "pue", "frontier_model_training", "safety_cert_level", "last_audit_date", "reporting_cadence"], + "properties": { + "facility_id": { + "type": "string", + "format": "uuid", + "description": "Unique facility identifier (UUID v4)" + }, + "operator": { + "type": "string", + "description": "Operating entity / legal name" + }, + "jurisdiction": { + "type": "string", + "pattern": "^[A-Z]{2}$", + "description": "Primary jurisdiction (ISO 3166-1 alpha-2)" + }, + "total_flops": { + "type": "number", + "minimum": 0, + "description": "Peak FP16 FLOPS capacity (in PFLOPS)" + }, + "gpu_type": { + "type": "string", + "enum": ["H100", "H200", "B200", "B300", "GB200", "MI300X", "TPUv5e", "TPUv6", "Custom", "Other"], + "description": "Primary GPU/accelerator type" + }, + "gpu_count": { + "type": "integer", + "minimum": 0, + "description": "Total GPU/accelerator count" + }, + "interconnect": { + "type": "string", + "description": "Network topology / interconnect type" + }, + "power_mw": { + "type": "number", + "minimum": 0, + "description": "Power consumption in megawatts" + }, + "pue": { + "type": "number", + "minimum": 1.0, + "maximum": 3.0, + "description": "Power Usage Effectiveness ratio" + }, + "ai_training_pct": { + "type": "number", + "minimum": 0, + "maximum": 100, + "description": "Percentage of capacity used for AI training" + }, + "frontier_model_training": { + "type": "boolean", + "description": "Whether facility is used for frontier model training" + }, + "safety_cert_level": { + "type": "integer", + "minimum": 0, + "maximum": 5, + "description": "GASCF safety certification level (0=none, 1-5)" + }, + "last_audit_date": { + "type": "string", + "format": "date", + "description": "Date of last compliance audit (ISO 8601)" + }, + "reporting_cadence": { + "type": "string", + "enum": ["monthly", "quarterly", "semi-annual", "annual"], + "description": "Reporting frequency to GACRA" + }, + "gacra_license": { + "type": "string", + "description": "GACRA compute license number (if issued)" + }, + "gacp_passport": { + "type": "string", + "description": "Global AI Compute Passport ID (if issued)" + } + } +} diff --git a/artifacts/schemas/evidence-bundle-manifest.schema.json b/artifacts/schemas/evidence-bundle-manifest.schema.json new file mode 100644 index 00000000..9b3266f4 --- /dev/null +++ b/artifacts/schemas/evidence-bundle-manifest.schema.json @@ -0,0 +1,165 @@ +{ + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$id": "https://gsifi.example.com/schemas/evidence-bundle-manifest/v1.0.0", + "title": "Evidence Bundle Manifest", + "description": "KACG-GSIFI-WP-017: JSON Schema for evidence bundle manifests produced by the Continuous Compliance Engine. Each evidence bundle includes a signed manifest linking to all evidence files, hash chain to previous bundle, and Merkle root for integrity verification.", + "type": "object", + "required": ["bundleId", "bundleType", "systemId", "modelId", "generatedAt", "generatedBy", "regulatoryFrameworks", "jurisdiction", "evidenceCount", "policyEvaluations", "violations", "hashChain", "signature", "retentionPolicy"], + "properties": { + "bundleId": { + "type": "string", + "pattern": "^EB-\\d{4}-\\d{2}-\\d{2}-[A-Z0-9_]+-[A-Za-z0-9]+-\\d{3}$", + "description": "Unique bundle identifier (format: EB-YYYY-MM-DD-TYPE-SystemName-NNN)" + }, + "bundleType": { + "type": "string", + "enum": [ + "SR_11_7_MODEL_DOCUMENTATION", + "EU_AI_ACT_TECHNICAL_DOCUMENTATION", + "ISO_42001_AIMS_EVIDENCE", + "BASEL_III_MODEL_RISK_REPORT", + "GDPR_DPIA", + "INCIDENT_REPORT", + "BIAS_AUDIT_REPORT", + "CONTINUOUS_COMPLIANCE_DIGEST", + "BOARD_QUARTERLY" + ], + "description": "Type of evidence bundle, corresponding to regulatory driver" + }, + "systemId": { + "type": "string", + "description": "AI system identifier from enterprise registry" + }, + "modelId": { + "type": "string", + "description": "Model identifier and version" + }, + "generatedAt": { + "type": "string", + "format": "date-time", + "description": "ISO 8601 timestamp of bundle generation" + }, + "generatedBy": { + "type": "string", + "description": "Compliance engine version that generated this bundle" + }, + "regulatoryFrameworks": { + "type": "array", + "items": { "type": "string" }, + "minItems": 1, + "description": "Applicable regulatory frameworks" + }, + "jurisdiction": { + "type": "array", + "items": { + "type": "string", + "pattern": "^[A-Z]{2}$" + }, + "description": "ISO 3166-1 alpha-2 jurisdiction codes" + }, + "evidenceCount": { + "type": "integer", + "minimum": 1, + "description": "Number of evidence files in this bundle" + }, + "policyEvaluations": { + "type": "integer", + "minimum": 0, + "description": "Number of OPA policy evaluations included" + }, + "violations": { + "type": "integer", + "minimum": 0, + "description": "Number of policy violations detected (0 = fully compliant)" + }, + "hashChain": { + "type": "object", + "required": ["algorithm", "previousBundleHash", "currentBundleHash", "merkleRoot"], + "properties": { + "algorithm": { + "type": "string", + "const": "SHA-256", + "description": "Hash algorithm used" + }, + "previousBundleHash": { + "type": "string", + "pattern": "^[a-f0-9]{64}$", + "description": "SHA-256 hash of the previous bundle in the chain" + }, + "currentBundleHash": { + "type": "string", + "pattern": "^[a-f0-9]{64}$", + "description": "SHA-256 hash of this bundle" + }, + "merkleRoot": { + "type": "string", + "pattern": "^[a-f0-9]{64}$", + "description": "Merkle root of all evidence file hashes" + } + } + }, + "signature": { + "type": "object", + "required": ["algorithm", "keyId", "signatureValue", "signedAt"], + "properties": { + "algorithm": { + "type": "string", + "const": "Ed25519", + "description": "Digital signature algorithm" + }, + "keyId": { + "type": "string", + "description": "HSM key identifier used for signing" + }, + "signatureValue": { + "type": "string", + "description": "Base64-encoded Ed25519 signature" + }, + "signedAt": { + "type": "string", + "format": "date-time", + "description": "Timestamp of signature creation" + } + } + }, + "retentionPolicy": { + "type": "object", + "required": ["regulation", "retentionYears", "expiresAt", "wormLockMode"], + "properties": { + "regulation": { + "type": "string", + "description": "Primary regulation driving retention requirement" + }, + "retentionYears": { + "type": "integer", + "minimum": 1, + "maximum": 100, + "description": "Retention period in years" + }, + "expiresAt": { + "type": "string", + "format": "date-time", + "description": "Retention expiry date" + }, + "wormLockMode": { + "type": "string", + "enum": ["COMPLIANCE", "GOVERNANCE"], + "description": "S3 Object Lock mode" + } + } + }, + "evidenceFiles": { + "type": "array", + "items": { + "type": "object", + "required": ["fileName", "fileHash", "fileSize", "mimeType"], + "properties": { + "fileName": { "type": "string" }, + "fileHash": { "type": "string", "pattern": "^[a-f0-9]{64}$" }, + "fileSize": { "type": "integer", "minimum": 0 }, + "mimeType": { "type": "string" } + } + } + } + } +} diff --git a/artifacts/schemas/gaf-openapi.yaml b/artifacts/schemas/gaf-openapi.yaml new file mode 100644 index 00000000..d8fb6c11 --- /dev/null +++ b/artifacts/schemas/gaf-openapi.yaml @@ -0,0 +1,485 @@ +openapi: 3.1.0 +info: + title: GAF-GSIFI-WP-017 — AGI/ASI Governance Architectures & Frameworks API + version: 1.0.0 + description: | + REST API for the AGI/ASI Governance Architectures & Frameworks reference. + Provides 56 endpoints covering 7 governance domains, regulatory alignment, + reference architectures, global governance components, financial services + governance, AGI safety, and the unified master blueprint. + contact: + name: AI Governance Architecture Team + license: + name: Proprietary — CONFIDENTIAL +servers: + - url: /api/governance-architectures-frameworks + description: GAF API base path + +paths: + /metadata: + get: + summary: Document metadata and scope + operationId: getMetadata + tags: [Overview] + responses: + '200': + description: Document metadata + content: + application/json: + schema: + $ref: '#/components/schemas/Metadata' + + /kpis: + get: + summary: Key performance indicators + operationId: getKPIs + tags: [Overview] + responses: + '200': + description: Array of KPI objects + content: + application/json: + schema: + type: array + items: + $ref: '#/components/schemas/KPI' + + /domains: + get: + summary: All 7 governance domains summary + operationId: getDomains + tags: [Overview] + responses: + '200': + description: Domain summaries + content: + application/json: + schema: + type: array + items: + $ref: '#/components/schemas/DomainSummary' + + /domains/{id}: + get: + summary: Individual domain detail + operationId: getDomainById + tags: [Overview] + parameters: + - name: id + in: path + required: true + schema: + type: string + enum: [D1, D2, D3, D4, D5, D6, D7] + responses: + '200': + description: Domain detail + '404': + description: Domain not found + + /governance-layers: + get: + summary: 6-layer governance architecture + operationId: getGovernanceLayers + tags: [Domain 1 - Enterprise Governance] + responses: + '200': + description: Governance layers + + /accountability: + get: + summary: Accountability roles and RACI matrix + operationId: getAccountability + tags: [Domain 1 - Enterprise Governance] + responses: + '200': + description: Roles and RACI + + /policy-infrastructure: + get: + summary: OPA + Sentinel policy infrastructure + operationId: getPolicyInfrastructure + tags: [Domain 1 - Enterprise Governance] + responses: + '200': + description: Policy infrastructure details + + /policy-infrastructure/opa-groups: + get: + summary: 12 OPA policy group details + operationId: getOPAGroups + tags: [Domain 1 - Enterprise Governance] + responses: + '200': + description: OPA policy groups + + /risk-management: + get: + summary: 14-dimension risk taxonomy + operationId: getRiskManagement + tags: [Domain 1 - Enterprise Governance] + responses: + '200': + description: Risk taxonomy and ARS + + /risk-management/ars: + get: + summary: Current ARS score and breakdown + operationId: getARS + tags: [Domain 1 - Enterprise Governance] + responses: + '200': + description: ARS details + + /regulatory: + get: + summary: Multi-regime regulatory summary + operationId: getRegulatory + tags: [Domain 2 - Regulatory] + responses: + '200': + description: Regulatory overview + + /regulatory/frameworks: + get: + summary: 8 regulatory frameworks detail + operationId: getRegulatoryFrameworks + tags: [Domain 2 - Regulatory] + responses: + '200': + description: Framework details + + /regulatory/eu-ai-act: + get: + summary: EU AI Act implementation timeline + operationId: getEUAIAct + tags: [Domain 2 - Regulatory] + responses: + '200': + description: EU AI Act timeline + + /regulatory/nist: + get: + summary: NIST AI RMF function mapping + operationId: getNIST + tags: [Domain 2 - Regulatory] + responses: + '200': + description: NIST mapping + + /regulatory/iso42001: + get: + summary: ISO/IEC 42001 AIMS roadmap + operationId: getISO42001 + tags: [Domain 2 - Regulatory] + responses: + '200': + description: ISO 42001 roadmap + + /regulatory/obligations: + get: + summary: Cross-regime obligation mapping + operationId: getObligations + tags: [Domain 2 - Regulatory] + responses: + '200': + description: Obligation mapping + + /architectures: + get: + summary: 5 reference architecture summaries + operationId: getArchitectures + tags: [Domain 3 - Architectures] + responses: + '200': + description: Architecture list + + /architectures/{id}: + get: + summary: Individual architecture detail + operationId: getArchitectureById + tags: [Domain 3 - Architectures] + parameters: + - name: id + in: path + required: true + schema: + type: string + enum: [ARCH-1, ARCH-2, ARCH-3, ARCH-4, ARCH-5] + responses: + '200': + description: Architecture detail + '404': + description: Architecture not found + + /trust-stack: + get: + summary: 7-layer trust and compliance stack + operationId: getTrustStack + tags: [Domain 3 - Architectures] + responses: + '200': + description: Trust stack layers + + /global-governance: + get: + summary: Global governance overview + operationId: getGlobalGovernance + tags: [Domain 4 - Global Governance] + responses: + '200': + description: Global governance overview + + /global-governance/icgc: + get: + summary: ICGC structure and charter + operationId: getICGC + tags: [Domain 4 - Global Governance] + responses: + '200': + description: ICGC details + + /global-governance/components: + get: + summary: 15 global governance components + operationId: getGlobalComponents + tags: [Domain 4 - Global Governance] + responses: + '200': + description: Global components + + /financial-services: + get: + summary: Financial services governance overview + operationId: getFinancialServices + tags: [Domain 5 - Financial Services] + responses: + '200': + description: Financial services overview + + /financial-services/sr117: + get: + summary: SR 11-7 model risk framework + operationId: getSR117 + tags: [Domain 5 - Financial Services] + responses: + '200': + description: SR 11-7 framework + + /financial-services/credit-scoring: + get: + summary: Credit scoring AI governance + operationId: getCreditScoring + tags: [Domain 5 - Financial Services] + responses: + '200': + description: Credit scoring governance + + /financial-services/fair-lending: + get: + summary: Fair lending DI compliance + operationId: getFairLending + tags: [Domain 5 - Financial Services] + responses: + '200': + description: Fair lending tests + + /agi-safety: + get: + summary: AGI safety overview + operationId: getAGISafety + tags: [Domain 6 - AGI Safety] + responses: + '200': + description: AGI safety summary + + /agi-safety/evolution: + get: + summary: 10-stage AI evolution model + operationId: getEvolution + tags: [Domain 6 - AGI Safety] + responses: + '200': + description: Evolution stages + + /agi-safety/crp: + get: + summary: Cognitive Resonance Protocol v2.1 + operationId: getCRP + tags: [Domain 6 - AGI Safety] + responses: + '200': + description: CRP details + + /agi-safety/crisis-simulations: + get: + summary: Crisis simulation program (8 scenarios) + operationId: getCrisisSimulations + tags: [Domain 6 - AGI Safety] + responses: + '200': + description: Crisis simulations + + /agi-safety/mvags: + get: + summary: Minimum Viable AI Governance Stack + operationId: getMVAGS + tags: [Domain 6 - AGI Safety] + responses: + '200': + description: MVAGS components + + /agi-safety/trust-by-design: + get: + summary: 10 Trust-by-Design principles + operationId: getTrustByDesign + tags: [Domain 6 - AGI Safety] + responses: + '200': + description: Trust principles + + /blueprint: + get: + summary: Master blueprint overview + operationId: getBlueprint + tags: [Domain 7 - Blueprint] + responses: + '200': + description: Blueprint overview + + /blueprint/sentinel: + get: + summary: Sentinel platform architecture + operationId: getSentinel + tags: [Domain 7 - Blueprint] + responses: + '200': + description: Sentinel architecture + + /blueprint/agi-readiness: + get: + summary: AGI readiness layers (ARL 1-7) + operationId: getAGIReadiness + tags: [Domain 7 - Blueprint] + responses: + '200': + description: ARL layers + + /blueprint/rollout: + get: + summary: 30/60/90-day rollout plan + operationId: getRollout + tags: [Domain 7 - Blueprint] + responses: + '200': + description: Full rollout plan + + /blueprint/8-week-plan: + get: + summary: 8-week technical implementation plan + operationId: get8WeekPlan + tags: [Domain 7 - Blueprint] + responses: + '200': + description: 8-week plan + + /investment: + get: + summary: Investment and financial summary + operationId: getInvestment + tags: [Investment & Risk] + responses: + '200': + description: Investment profile + + /investment/risks: + get: + summary: Risk register (12 entries) + operationId: getRiskRegister + tags: [Investment & Risk] + responses: + '200': + description: Risk register + + /metrics: + get: + summary: Consolidated metrics dashboard + operationId: getMetrics + tags: [Overview] + responses: + '200': + description: Key metrics + + /summary: + get: + summary: Executive summary with all KPIs + operationId: getSummary + tags: [Overview] + responses: + '200': + description: Executive summary + + /dashboard: + get: + summary: Full dashboard data payload + operationId: getDashboard + tags: [Overview] + responses: + '200': + description: Dashboard payload + + /artifacts: + get: + summary: Machine-readable artifact catalog + operationId: getArtifacts + tags: [Artifacts] + responses: + '200': + description: Artifact catalog + +components: + schemas: + Metadata: + type: object + properties: + docRef: + type: string + example: GAF-GSIFI-WP-017 + title: + type: string + version: + type: string + date: + type: string + format: date + scope: + type: object + + KPI: + type: object + properties: + name: + type: string + current: + type: string + target2027: + type: string + target2030: + type: string + trend: + type: string + + DomainSummary: + type: object + properties: + id: + type: string + enum: [D1, D2, D3, D4, D5, D6, D7] + name: + type: string + scope: + type: string + keyMetric: + type: string + status: + type: string diff --git a/artifacts/schemas/governance-architecture.schema.json b/artifacts/schemas/governance-architecture.schema.json new file mode 100644 index 00000000..98a93151 --- /dev/null +++ b/artifacts/schemas/governance-architecture.schema.json @@ -0,0 +1,111 @@ +{ + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$id": "https://governance.enterprise.ai/schemas/governance-architecture.schema.json", + "title": "AI Governance Architecture Documentation", + "description": "Schema for documenting enterprise AI governance architectures, aligned to GAF-GSIFI-WP-017. Covers governance layers, reference architectures, trust stacks, and regulatory mappings.", + "type": "object", + "required": ["architectureId", "name", "version", "governanceLayers", "regulatoryAlignment"], + "properties": { + "architectureId": { + "type": "string", + "pattern": "^ARCH-[0-9]+$", + "description": "Unique architecture identifier (e.g., ARCH-1)" + }, + "name": { + "type": "string", + "description": "Architecture name" + }, + "version": { + "type": "string", + "pattern": "^[0-9]+\\.[0-9]+\\.[0-9]+$", + "description": "Semantic version" + }, + "classification": { + "type": "string", + "enum": ["PUBLIC", "INTERNAL", "CONFIDENTIAL", "RESTRICTED"], + "default": "CONFIDENTIAL" + }, + "governanceLayers": { + "type": "array", + "minItems": 1, + "items": { + "type": "object", + "required": ["layerId", "name", "function", "owner"], + "properties": { + "layerId": { "type": "string", "pattern": "^L[0-9]+$" }, + "name": { "type": "string" }, + "function": { "type": "string" }, + "keyControls": { "type": "string" }, + "owner": { "type": "string" }, + "metrics": { + "type": "array", + "items": { + "type": "object", + "properties": { + "name": { "type": "string" }, + "current": { "type": "string" }, + "target": { "type": "string" }, + "slo": { "type": "string" } + } + } + } + } + } + }, + "components": { + "type": "array", + "items": { + "type": "object", + "required": ["component", "technology", "function"], + "properties": { + "component": { "type": "string" }, + "technology": { "type": "string" }, + "function": { "type": "string" }, + "scale": { "type": "string" }, + "sla": { "type": "string" } + } + } + }, + "trustStack": { + "type": "array", + "items": { + "type": "object", + "required": ["layer", "name", "function"], + "properties": { + "layer": { "type": "string" }, + "name": { "type": "string" }, + "function": { "type": "string" }, + "technology": { "type": "string" }, + "metric": { "type": "string" } + } + } + }, + "regulatoryAlignment": { + "type": "array", + "items": { + "type": "object", + "required": ["framework", "jurisdiction"], + "properties": { + "framework": { "type": "string" }, + "jurisdiction": { "type": "string" }, + "opaRules": { "type": "integer", "minimum": 0 }, + "status": { "type": "string", "enum": ["Active", "Certifying", "Planned", "Not Applicable"] } + } + } + }, + "riskDimensions": { + "type": "array", + "items": { + "type": "object", + "required": ["id", "category", "weight", "score"], + "properties": { + "id": { "type": "string" }, + "category": { "type": "string" }, + "weight": { "type": "number", "minimum": 0, "maximum": 1 }, + "score": { "type": "number", "minimum": 0, "maximum": 100 }, + "owner": { "type": "string" } + } + } + } + } +} diff --git a/artifacts/schemas/governance-event.avsc b/artifacts/schemas/governance-event.avsc new file mode 100644 index 00000000..52983abc --- /dev/null +++ b/artifacts/schemas/governance-event.avsc @@ -0,0 +1,135 @@ +{ + "type": "record", + "name": "GovernanceEvent", + "namespace": "com.gsifi.ai.governance", + "doc": "KACG-GSIFI-WP-017: Core governance event schema for Kafka ACL Governance & Continuous Compliance Engine. All AI governance telemetry flows through this schema. Registered in Confluent Schema Registry with BACKWARD_TRANSITIVE compatibility.", + "fields": [ + { + "name": "eventId", + "type": "string", + "doc": "UUID v7 (time-ordered) — unique event identifier" + }, + { + "name": "timestamp", + "type": { + "type": "long", + "logicalType": "timestamp-micros" + }, + "doc": "Event timestamp in microseconds since epoch (UTC)" + }, + { + "name": "systemId", + "type": "string", + "doc": "AI system identifier from the enterprise AI system registry" + }, + { + "name": "modelId", + "type": "string", + "doc": "Model identifier from the model registry (MLflow or equivalent)" + }, + { + "name": "modelVersion", + "type": "string", + "doc": "Semantic version of the model (e.g., 4.2.1)" + }, + { + "name": "eventType", + "type": { + "type": "enum", + "name": "EventType", + "symbols": [ + "INFERENCE", + "TRAINING_RUN", + "MODEL_PROMOTION", + "GOVERNANCE_OVERRIDE", + "BIAS_ALERT", + "DRIFT_DETECTED", + "HUMAN_ESCALATION", + "KILL_SWITCH_ACTIVATED", + "CONSENT_CHANGE", + "ERASURE_REQUEST", + "ACL_CHANGE", + "EVIDENCE_BUNDLE_GENERATED", + "POLICY_EVALUATION", + "COMPLIANCE_CHECK", + "AUDIT_ACCESS" + ], + "doc": "Type of governance event" + } + }, + { + "name": "inputHash", + "type": "string", + "doc": "SHA-256 hash of input data for tamper-evidence" + }, + { + "name": "outputHash", + "type": "string", + "doc": "SHA-256 hash of output data for tamper-evidence" + }, + { + "name": "latencyMs", + "type": "double", + "doc": "Processing latency in milliseconds" + }, + { + "name": "governanceDecision", + "type": { + "type": "enum", + "name": "Decision", + "symbols": [ + "ALLOW", + "DENY", + "ESCALATE", + "QUARANTINE", + "KILL" + ], + "doc": "Governance decision outcome" + } + }, + { + "name": "policyVersion", + "type": "string", + "doc": "Version of the OPA policy bundle used for evaluation" + }, + { + "name": "opaRuleId", + "type": ["null", "string"], + "default": null, + "doc": "OPA rule identifier that triggered this event (if applicable)" + }, + { + "name": "sentinelRuleId", + "type": ["null", "string"], + "default": null, + "doc": "Sentinel rule identifier that triggered this event (if applicable)" + }, + { + "name": "userId", + "type": ["null", "string"], + "default": null, + "doc": "User identifier (if human-initiated event)" + }, + { + "name": "jurisdiction", + "type": "string", + "doc": "ISO 3166-1 alpha-2 jurisdiction code (e.g., US, EU, UK, SG)" + }, + { + "name": "regulatoryContext", + "type": { + "type": "array", + "items": "string" + }, + "doc": "Applicable regulatory frameworks (e.g., ['SR 11-7', 'EU AI Act', 'GDPR'])" + }, + { + "name": "metadata", + "type": { + "type": "map", + "values": "string" + }, + "doc": "Reserved keys: eaip-priority, eaip-idempotency-key, eaip-schema-version, risk-tier, model-type" + } + ] +} diff --git a/artifacts/schemas/kacg-openapi.yaml b/artifacts/schemas/kacg-openapi.yaml new file mode 100644 index 00000000..419b3742 --- /dev/null +++ b/artifacts/schemas/kacg-openapi.yaml @@ -0,0 +1,1383 @@ +openapi: 3.1.0 +info: + title: KACG-GSIFI-WP-017 — Kafka ACL Governance & Continuous Compliance Engine API + version: 1.0.0 + description: | + REST API for the Kafka ACL Governance & Continuous Compliance Engine. + Provides 62 endpoints covering Kafka cluster management, ACL governance, + OPA policy framework, continuous compliance engine, evidence signing, + WORM storage, regulatory alignment, Terraform IaC, auditor workflows, + risk register, investment, rollout, and key metrics. + + Aligned to: EU AI Act, NIST AI RMF, ISO/IEC 42001, Basel III, SR 11-7, GDPR, FCRA/ECOA + contact: + name: AI Governance Platform Engineering + license: + name: Proprietary — CONFIDENTIAL +servers: + - url: /api/kafka-acl-governance + description: KACG API base path + +tags: + - name: Overview + description: Full reference and metadata + - name: KPIs + description: Key performance indicators + - name: Kafka Cluster + description: Cluster topology, topics, and performance + - name: ACL Governance + description: Identity layer, ACL taxonomy, authorizer, break-glass + - name: OPA Policy + description: OPA policy groups, rules, and performance + - name: Compliance Engine + description: Continuous compliance pipeline and evidence types + - name: Evidence Signing + description: Cryptographic evidence signing and verification CLI + - name: WORM Storage + description: Write-Once-Read-Many S3 storage and lifecycle + - name: Regulatory + description: Regulatory alignment and control matrix + - name: Terraform + description: IaC modules, CI/CD gates, and drift detection + - name: Auditor + description: Auditor workflows and self-service capabilities + - name: Risk + description: Risk register and investment + - name: Rollout + description: 30/60/90-day rollout and 8-week fast-track + - name: Metrics + description: Key operational metrics + - name: Dashboard + description: Dashboard aggregations and artifacts + +paths: + /: + get: + summary: Full Kafka ACL Governance reference + operationId: getFullReference + tags: [Overview] + responses: + '200': + description: Complete KACG reference object + content: + application/json: + schema: + $ref: '#/components/schemas/FullReference' + + /metadata: + get: + summary: Document metadata + operationId: getMetadata + tags: [Overview] + responses: + '200': + description: Document metadata + content: + application/json: + schema: + $ref: '#/components/schemas/Metadata' + + /meta: + get: + summary: Document metadata (alias) + operationId: getMeta + tags: [Overview] + responses: + '200': + description: Document metadata + content: + application/json: + schema: + $ref: '#/components/schemas/Metadata' + + /kpis: + get: + summary: Key performance indicators + operationId: getKpis + tags: [KPIs] + responses: + '200': + description: Array of KPI objects + content: + application/json: + schema: + type: object + properties: + kpis: + type: array + items: + $ref: '#/components/schemas/Kpi' + + /cluster: + get: + summary: Kafka cluster configuration + operationId: getCluster + tags: [Kafka Cluster] + responses: + '200': + description: Cluster topology and config + content: + application/json: + schema: + $ref: '#/components/schemas/KafkaCluster' + + /cluster/topics: + get: + summary: All Kafka topics + operationId: getClusterTopics + tags: [Kafka Cluster] + responses: + '200': + description: List of topics with count + content: + application/json: + schema: + type: object + properties: + topics: + type: array + items: + $ref: '#/components/schemas/KafkaTopic' + count: + type: integer + + /cluster/topics/{name}: + get: + summary: Specific Kafka topic by name + operationId: getClusterTopicByName + tags: [Kafka Cluster] + parameters: + - name: name + in: path + required: true + schema: + type: string + description: Topic name (e.g., ai.inference.events) + responses: + '200': + description: Topic configuration + content: + application/json: + schema: + $ref: '#/components/schemas/KafkaTopic' + '404': + description: Topic not found + + /cluster/performance: + get: + summary: Kafka cluster performance metrics + operationId: getClusterPerformance + tags: [Kafka Cluster] + responses: + '200': + description: Throughput and latency metrics + content: + application/json: + schema: + $ref: '#/components/schemas/ClusterPerformance' + + /acl: + get: + summary: ACL governance overview + operationId: getAclGovernance + tags: [ACL Governance] + responses: + '200': + description: Full ACL governance configuration + content: + application/json: + schema: + $ref: '#/components/schemas/AclGovernance' + + /acl/identity: + get: + summary: Identity layer (SPIFFE/SPIRE) + operationId: getAclIdentity + tags: [ACL Governance] + responses: + '200': + description: Identity provider configuration + content: + application/json: + schema: + $ref: '#/components/schemas/IdentityLayer' + + /acl/taxonomy: + get: + summary: ACL taxonomy + operationId: getAclTaxonomy + tags: [ACL Governance] + responses: + '200': + description: Topic-level ACL taxonomy + content: + application/json: + schema: + type: object + properties: + taxonomy: + type: array + items: + $ref: '#/components/schemas/AclTaxonomyEntry' + + /acl/authorizer: + get: + summary: OPA Kafka Authorizer config + operationId: getAclAuthorizer + tags: [ACL Governance] + responses: + '200': + description: Authorizer configuration + content: + application/json: + schema: + $ref: '#/components/schemas/AuthorizerConfig' + + /acl/break-glass: + get: + summary: Break-glass emergency access protocol + operationId: getAclBreakGlass + tags: [ACL Governance] + responses: + '200': + description: Emergency access configuration + content: + application/json: + schema: + $ref: '#/components/schemas/BreakGlass' + + /opa: + get: + summary: OPA policy framework overview + operationId: getOpaFramework + tags: [OPA Policy] + responses: + '200': + description: Full OPA policy framework + content: + application/json: + schema: + $ref: '#/components/schemas/OpaPolicyFramework' + + /opa/groups: + get: + summary: Policy groups with rule counts + operationId: getOpaGroups + tags: [OPA Policy] + responses: + '200': + description: Policy groups and total rules + content: + application/json: + schema: + type: object + properties: + groups: + type: array + items: + $ref: '#/components/schemas/PolicyGroup' + totalRules: + type: integer + + /opa/groups/{prefix}: + get: + summary: Specific policy group by prefix + operationId: getOpaGroupByPrefix + tags: [OPA Policy] + parameters: + - name: prefix + in: path + required: true + schema: + type: string + description: "Policy group prefix (e.g., kafka.acl)" + responses: + '200': + description: Policy group details + content: + application/json: + schema: + $ref: '#/components/schemas/PolicyGroup' + '404': + description: Policy group not found + + /opa/performance: + get: + summary: OPA evaluation performance + operationId: getOpaPerformance + tags: [OPA Policy] + responses: + '200': + description: Performance benchmarks + content: + application/json: + schema: + $ref: '#/components/schemas/OpaPerformance' + + /compliance-engine: + get: + summary: Continuous compliance engine + operationId: getComplianceEngine + tags: [Compliance Engine] + responses: + '200': + description: Compliance engine pipeline and evidence types + content: + application/json: + schema: + $ref: '#/components/schemas/ComplianceEngine' + + /compliance-engine/pipeline: + get: + summary: Compliance pipeline stages + operationId: getCompliancePipeline + tags: [Compliance Engine] + responses: + '200': + description: Pipeline stage definitions + content: + application/json: + schema: + type: object + properties: + stages: + type: array + items: + $ref: '#/components/schemas/PipelineStage' + + /compliance-engine/evidence-types: + get: + summary: Evidence bundle types + operationId: getEvidenceTypes + tags: [Compliance Engine] + responses: + '200': + description: Evidence types for audit + content: + application/json: + schema: + type: object + properties: + types: + type: array + items: + $ref: '#/components/schemas/EvidenceType' + + /evidence-signing: + get: + summary: Evidence signing configuration + operationId: getEvidenceSigning + tags: [Evidence Signing] + responses: + '200': + description: Cryptographic evidence signing setup + content: + application/json: + schema: + $ref: '#/components/schemas/EvidenceSigning' + + /evidence-signing/cli: + get: + summary: Verification CLI specification + operationId: getVerificationCli + tags: [Evidence Signing] + responses: + '200': + description: CLI commands and usage + content: + application/json: + schema: + $ref: '#/components/schemas/VerificationCli' + + /worm-storage: + get: + summary: WORM S3 storage configuration + operationId: getWormStorage + tags: [WORM Storage] + responses: + '200': + description: WORM storage settings + content: + application/json: + schema: + $ref: '#/components/schemas/WormStorage' + + /worm-storage/lifecycle: + get: + summary: Storage lifecycle tiering and costs + operationId: getWormLifecycle + tags: [WORM Storage] + responses: + '200': + description: Lifecycle tiers and annual costs + content: + application/json: + schema: + type: object + properties: + tiers: + type: array + items: + $ref: '#/components/schemas/LifecycleTier' + annualCost: + type: string + + /worm-storage/retention: + get: + summary: Regulatory retention policies + operationId: getWormRetention + tags: [WORM Storage] + responses: + '200': + description: Retention policies by regulation + content: + application/json: + schema: + type: object + properties: + policies: + type: array + items: + $ref: '#/components/schemas/RetentionPolicy' + + /regulatory: + get: + summary: Regulatory alignment overview + operationId: getRegulatoryAlignment + tags: [Regulatory] + responses: + '200': + description: Full regulatory alignment + content: + application/json: + schema: + $ref: '#/components/schemas/RegulatoryAlignment' + + /regulatory/frameworks: + get: + summary: All aligned regulatory frameworks + operationId: getRegulatoryFrameworks + tags: [Regulatory] + responses: + '200': + description: Frameworks list + content: + application/json: + schema: + type: object + properties: + frameworks: + type: array + items: + $ref: '#/components/schemas/RegulatoryFramework' + + /regulatory/control-matrix: + get: + summary: Regulatory control matrix + operationId: getControlMatrix + tags: [Regulatory] + responses: + '200': + description: Cross-regulation control mappings + content: + application/json: + schema: + type: object + properties: + controls: + type: array + items: + $ref: '#/components/schemas/ControlMapping' + + /regulatory/iso42001: + get: + summary: ISO/IEC 42001 mapping + operationId: getIso42001Mapping + tags: [Regulatory] + responses: + '200': + description: ISO 42001 clause-level mappings + content: + application/json: + schema: + type: object + properties: + mapping: + type: object + + /regulatory/sr117: + get: + summary: SR 11-7 alignment + operationId: getSr117Alignment + tags: [Regulatory] + responses: + '200': + description: SR 11-7 section alignment + content: + application/json: + schema: + type: object + properties: + alignment: + type: object + + /regulatory/basel-iii: + get: + summary: Basel III alignment + operationId: getBaselIIIAlignment + tags: [Regulatory] + responses: + '200': + description: Basel III CRE alignment + content: + application/json: + schema: + type: object + properties: + alignment: + type: object + + /terraform: + get: + summary: Terraform IaC overview + operationId: getTerraformIaC + tags: [Terraform] + responses: + '200': + description: Terraform modules and configuration + content: + application/json: + schema: + $ref: '#/components/schemas/TerraformIaC' + + /terraform/modules: + get: + summary: Terraform modules list + operationId: getTerraformModules + tags: [Terraform] + responses: + '200': + description: Module definitions with resource counts + content: + application/json: + schema: + type: object + properties: + modules: + type: array + items: + $ref: '#/components/schemas/TerraformModule' + totalResources: + type: integer + + /terraform/modules/{id}: + get: + summary: Specific Terraform module + operationId: getTerraformModuleById + tags: [Terraform] + parameters: + - name: id + in: path + required: true + schema: + type: string + description: "Module ID (e.g., M1)" + responses: + '200': + description: Module configuration + content: + application/json: + schema: + $ref: '#/components/schemas/TerraformModule' + '404': + description: Module not found + + /terraform/cicd-gates: + get: + summary: CI/CD governance gates + operationId: getCicdGates + tags: [Terraform] + responses: + '200': + description: CI/CD gate definitions + content: + application/json: + schema: + type: object + properties: + gates: + type: array + items: + $ref: '#/components/schemas/CicdGate' + + /terraform/drift-detection: + get: + summary: Drift detection configuration + operationId: getDriftDetection + tags: [Terraform] + responses: + '200': + description: Drift detection settings + content: + application/json: + schema: + $ref: '#/components/schemas/DriftDetection' + + /auditor: + get: + summary: Auditor workflows overview + operationId: getAuditorWorkflows + tags: [Auditor] + responses: + '200': + description: Auditor workflow modes and capabilities + content: + application/json: + schema: + $ref: '#/components/schemas/AuditorWorkflows' + + /auditor/modes: + get: + summary: Audit delivery modes + operationId: getAuditorModes + tags: [Auditor] + responses: + '200': + description: Available audit modes + content: + application/json: + schema: + type: object + properties: + modes: + type: array + items: + $ref: '#/components/schemas/AuditMode' + + /auditor/self-service: + get: + summary: Self-service audit capabilities + operationId: getAuditorSelfService + tags: [Auditor] + responses: + '200': + description: Self-service audit features + content: + application/json: + schema: + type: object + properties: + capabilities: + type: array + items: + type: object + + /auditor/guided: + get: + summary: Guided audit portal features + operationId: getAuditorGuided + tags: [Auditor] + responses: + '200': + description: Guided audit portal features + content: + application/json: + schema: + type: object + properties: + features: + type: array + items: + type: object + + /auditor/regulatory-exam: + get: + summary: Regulatory examination provisions + operationId: getAuditorRegulatoryExam + tags: [Auditor] + responses: + '200': + description: Regulatory exam support features + content: + application/json: + schema: + type: object + properties: + provisions: + type: array + items: + type: object + + /risk-register: + get: + summary: Risk register + operationId: getRiskRegister + tags: [Risk] + responses: + '200': + description: Identified risks + content: + application/json: + schema: + type: object + properties: + risks: + type: array + items: + $ref: '#/components/schemas/RiskEntry' + + /investment: + get: + summary: Investment overview + operationId: getInvestment + tags: [Risk] + responses: + '200': + description: Investment and ROI data + content: + application/json: + schema: + $ref: '#/components/schemas/Investment' + + /investment/roi: + get: + summary: Return on investment + operationId: getInvestmentRoi + tags: [Risk] + responses: + '200': + description: ROI calculations + content: + application/json: + schema: + type: object + + /investment/costs: + get: + summary: Cost breakdown + operationId: getInvestmentCosts + tags: [Risk] + responses: + '200': + description: Cost breakdown and totals + content: + application/json: + schema: + type: object + properties: + breakdown: + type: object + totals: + type: object + + /rollout: + get: + summary: Rollout plan overview + operationId: getRollout + tags: [Rollout] + responses: + '200': + description: Full rollout plan + content: + application/json: + schema: + $ref: '#/components/schemas/Rollout' + + /rollout/30-day: + get: + summary: 30-day rollout plan + operationId: getRollout30Day + tags: [Rollout] + responses: + '200': + description: Days 1-30 plan + content: + application/json: + schema: + type: object + + /rollout/60-day: + get: + summary: 60-day rollout plan + operationId: getRollout60Day + tags: [Rollout] + responses: + '200': + description: Days 31-60 plan + content: + application/json: + schema: + type: object + + /rollout/90-day: + get: + summary: 90-day rollout plan + operationId: getRollout90Day + tags: [Rollout] + responses: + '200': + description: Days 61-90 plan + content: + application/json: + schema: + type: object + + /rollout/8-week: + get: + summary: 8-week fast-track implementation + operationId: getRollout8Week + tags: [Rollout] + responses: + '200': + description: 8-week fast-track plan + content: + application/json: + schema: + type: object + properties: + plan: + type: array + items: + type: object + + /metrics: + get: + summary: Key operational metrics + operationId: getMetrics + tags: [Metrics] + responses: + '200': + description: Operational metrics + content: + application/json: + schema: + type: object + + /summary: + get: + summary: Executive summary + operationId: getSummary + tags: [Dashboard] + responses: + '200': + description: Executive summary with highlights + content: + application/json: + schema: + type: object + + /dashboard: + get: + summary: Dashboard aggregation + operationId: getDashboard + tags: [Dashboard] + responses: + '200': + description: Dashboard data + content: + application/json: + schema: + type: object + + /artifacts: + get: + summary: Machine-readable artifacts listing + operationId: getArtifacts + tags: [Dashboard] + responses: + '200': + description: Artifact paths and formats + content: + application/json: + schema: + type: object + +components: + schemas: + Metadata: + type: object + properties: + docRef: + type: string + example: "KACG-GSIFI-WP-017" + title: + type: string + version: + type: string + date: + type: string + classification: + type: string + scope: + type: object + + Kpi: + type: object + properties: + metric: + type: string + current: + type: string + target2027: + type: string + target2030: + type: string + status: + type: string + enum: [ON_TRACK, AT_RISK, EXCEEDED, GAP] + + KafkaCluster: + type: object + properties: + name: + type: string + brokers: + type: integer + availabilityZones: + type: integer + kafkaVersion: + type: string + topics: + type: array + items: + $ref: '#/components/schemas/KafkaTopic' + throughput: + $ref: '#/components/schemas/ClusterPerformance' + + KafkaTopic: + type: object + properties: + name: + type: string + partitions: + type: integer + replicationFactor: + type: integer + minInsyncReplicas: + type: integer + retentionMs: + type: integer + description: "-1 for permanent retention" + retention: + type: string + compression: + type: string + transactional: + type: boolean + + ClusterPerformance: + type: object + properties: + eventsPerSecond: + type: integer + p99LatencyMs: + type: number + availabilityPercent: + type: number + + AclGovernance: + type: object + properties: + identityLayer: + $ref: '#/components/schemas/IdentityLayer' + aclTaxonomy: + type: array + items: + $ref: '#/components/schemas/AclTaxonomyEntry' + authorizerConfig: + $ref: '#/components/schemas/AuthorizerConfig' + breakGlass: + $ref: '#/components/schemas/BreakGlass' + + IdentityLayer: + type: object + properties: + provider: + type: string + example: "SPIFFE/SPIRE" + svidType: + type: string + rotationIntervalHours: + type: integer + + AclTaxonomyEntry: + type: object + properties: + topic: + type: string + produce: + type: array + items: + type: string + consume: + type: array + items: + type: string + transactional: + type: boolean + + AuthorizerConfig: + type: object + properties: + class: + type: string + decisionCacheTtlMs: + type: integer + fallbackPolicy: + type: string + enum: [DENY] + + BreakGlass: + type: object + properties: + protocol: + type: string + maxDurationMinutes: + type: integer + approversRequired: + type: integer + auditRetention: + type: string + + OpaPolicyFramework: + type: object + properties: + totalRules: + type: integer + policyGroups: + type: array + items: + $ref: '#/components/schemas/PolicyGroup' + performance: + $ref: '#/components/schemas/OpaPerformance' + + PolicyGroup: + type: object + properties: + prefix: + type: string + name: + type: string + ruleCount: + type: integer + frequency: + type: string + frameworks: + type: array + items: + type: string + + OpaPerformance: + type: object + properties: + p50DecisionMs: + type: number + p99DecisionMs: + type: number + dailyEvaluations: + type: string + bundleRefreshSeconds: + type: integer + + ComplianceEngine: + type: object + properties: + pipeline: + type: array + items: + $ref: '#/components/schemas/PipelineStage' + evidenceBundleTypes: + type: array + items: + $ref: '#/components/schemas/EvidenceType' + + PipelineStage: + type: object + properties: + stage: + type: string + input: + type: string + processing: + type: string + output: + type: string + sla: + type: string + + EvidenceType: + type: object + properties: + name: + type: string + format: + type: string + trigger: + type: string + retention: + type: string + + EvidenceSigning: + type: object + properties: + algorithm: + type: string + example: "Ed25519" + keyManagement: + type: string + signingLatencyMs: + type: integer + verificationCli: + $ref: '#/components/schemas/VerificationCli' + + VerificationCli: + type: object + properties: + name: + type: string + version: + type: string + commands: + type: array + items: + type: object + properties: + command: + type: string + description: + type: string + + WormStorage: + type: object + properties: + provider: + type: string + example: "S3 Object Lock" + retentionMode: + type: string + enum: [COMPLIANCE] + retentionDays: + type: integer + durability: + type: string + lifecycleTiering: + type: array + items: + $ref: '#/components/schemas/LifecycleTier' + retentionPolicies: + type: array + items: + $ref: '#/components/schemas/RetentionPolicy' + + LifecycleTier: + type: object + properties: + tier: + type: string + storageClass: + type: string + ageRangeDays: + type: string + costPerGbMonth: + type: string + + RetentionPolicy: + type: object + properties: + regulation: + type: string + retentionYears: + type: integer + legalHold: + type: boolean + + RegulatoryAlignment: + type: object + properties: + frameworks: + type: array + items: + $ref: '#/components/schemas/RegulatoryFramework' + controlMatrix: + type: array + items: + $ref: '#/components/schemas/ControlMapping' + + RegulatoryFramework: + type: object + properties: + name: + type: string + jurisdiction: + type: string + kafkaRelevance: + type: string + complianceScore: + type: number + + ControlMapping: + type: object + properties: + controlId: + type: string + requirement: + type: string + iso42001: + type: string + nistAiRmf: + type: string + euAiAct: + type: string + baselIII: + type: string + sr117: + type: string + implementation: + type: string + status: + type: string + enum: [IMPLEMENTED, IN_PROGRESS, PLANNED] + + TerraformIaC: + type: object + properties: + terraformVersion: + type: string + totalResources: + type: integer + modules: + type: array + items: + $ref: '#/components/schemas/TerraformModule' + cicdGates: + type: array + items: + $ref: '#/components/schemas/CicdGate' + driftDetection: + $ref: '#/components/schemas/DriftDetection' + + TerraformModule: + type: object + properties: + id: + type: string + name: + type: string + resources: + type: integer + providers: + type: array + items: + type: string + description: + type: string + + CicdGate: + type: object + properties: + gate: + type: string + stage: + type: string + tool: + type: string + blocking: + type: boolean + threshold: + type: string + + DriftDetection: + type: object + properties: + frequency: + type: string + tool: + type: string + alertChannels: + type: array + items: + type: string + autoRemediation: + type: boolean + maxRemediationDelayMinutes: + type: integer + + AuditorWorkflows: + type: object + properties: + modes: + type: array + items: + $ref: '#/components/schemas/AuditMode' + selfServiceCapabilities: + type: array + items: + type: object + guidedAuditPortal: + type: array + items: + type: object + regulatoryExamination: + type: array + items: + type: object + + AuditMode: + type: object + properties: + mode: + type: string + description: + type: string + accessLevel: + type: string + auditTrail: + type: boolean + + RiskEntry: + type: object + properties: + id: + type: string + risk: + type: string + likelihood: + type: string + enum: [LOW, MEDIUM, HIGH, CRITICAL] + impact: + type: string + enum: [LOW, MEDIUM, HIGH, CRITICAL] + mitigation: + type: string + owner: + type: string + + Investment: + type: object + properties: + totalBudget: + type: string + roi: + type: object + costBreakdown: + type: object + totals: + type: object + + Rollout: + type: object + properties: + days1to30: + type: object + days31to60: + type: object + days61to90: + type: object + eightWeekFastTrack: + type: array + items: + type: object + + FullReference: + type: object + description: Complete KACG reference including all sections diff --git a/artifacts/schemas/worm-evidence-storage.schema.json b/artifacts/schemas/worm-evidence-storage.schema.json new file mode 100644 index 00000000..69478a86 --- /dev/null +++ b/artifacts/schemas/worm-evidence-storage.schema.json @@ -0,0 +1,396 @@ +{ + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$id": "https://governance.internal/schemas/worm-evidence-storage/v1.0.0", + "title": "KACG-GSIFI-WP-017: WORM Evidence Storage Configuration", + "description": "Schema for Write-Once-Read-Many S3 storage configuration used for immutable governance evidence retention. Aligned to EU AI Act Art. 12, SR 11-7 Section 4, GDPR Art. 30, Basel III CRE 30-36.", + "type": "object", + "required": ["storageConfig", "retentionPolicies", "lifecycleTiering", "cryptographicSeal", "accessControls"], + "properties": { + "storageConfig": { + "type": "object", + "description": "Core WORM S3 storage configuration", + "required": ["provider", "bucket", "region", "objectLockMode", "retentionDays", "versioningEnabled", "durability"], + "properties": { + "provider": { + "type": "string", + "description": "Cloud storage provider", + "enum": ["AWS_S3", "AZURE_IMMUTABLE", "GCS_RETENTION"] + }, + "bucket": { + "type": "string", + "description": "S3 bucket name for WORM evidence storage", + "pattern": "^[a-z0-9][a-z0-9.-]{1,61}[a-z0-9]$" + }, + "region": { + "type": "string", + "description": "AWS region for storage (EU-based for GDPR)", + "examples": ["eu-west-1", "eu-central-1"] + }, + "objectLockMode": { + "type": "string", + "description": "S3 Object Lock mode (COMPLIANCE prevents any deletion including root)", + "enum": ["COMPLIANCE", "GOVERNANCE"] + }, + "retentionDays": { + "type": "integer", + "description": "Default retention period in days (3652 = 10 years)", + "minimum": 1826, + "maximum": 7305, + "default": 3652 + }, + "versioningEnabled": { + "type": "boolean", + "description": "S3 versioning must be enabled for Object Lock", + "const": true + }, + "durability": { + "type": "string", + "description": "Storage durability guarantee", + "default": "99.999999999%" + }, + "encryption": { + "type": "object", + "description": "Server-side encryption configuration", + "properties": { + "algorithm": { + "type": "string", + "enum": ["AES-256", "aws:kms"] + }, + "kmsKeyId": { + "type": "string", + "description": "KMS key ARN for SSE-KMS encryption" + }, + "keyRotationEnabled": { + "type": "boolean", + "default": true + } + }, + "required": ["algorithm"] + }, + "replication": { + "type": "object", + "description": "Cross-region replication for disaster recovery", + "properties": { + "enabled": { + "type": "boolean", + "default": true + }, + "destinationRegion": { + "type": "string" + }, + "destinationBucket": { + "type": "string" + }, + "replicateObjectLock": { + "type": "boolean", + "description": "Replicate Object Lock retention settings", + "const": true + } + } + } + } + }, + "retentionPolicies": { + "type": "array", + "description": "Regulatory retention policies mapped to evidence types", + "minItems": 1, + "items": { + "type": "object", + "required": ["regulation", "retentionYears", "retentionDays", "evidenceTypes", "legalHoldCapable"], + "properties": { + "regulation": { + "type": "string", + "description": "Regulatory framework identifier", + "enum": ["SR_11_7", "GDPR_ART_30", "EU_AI_ACT_ART_12", "BASEL_III", "PRA_SS1_23", "MIFID_II", "ISO_42001"] + }, + "retentionYears": { + "type": "integer", + "minimum": 1, + "maximum": 20 + }, + "retentionDays": { + "type": "integer", + "minimum": 365 + }, + "evidenceTypes": { + "type": "array", + "description": "Types of evidence governed by this retention policy", + "items": { + "type": "string", + "enum": [ + "INFERENCE_AUDIT_LOG", + "MODEL_VALIDATION_REPORT", + "BIAS_ASSESSMENT", + "DRIFT_DETECTION_REPORT", + "OPA_POLICY_EVALUATION", + "GOVERNANCE_DECISION", + "TRAINING_RUN_LOG", + "MODEL_CARD", + "DPIA_REPORT", + "CONFORMITY_ASSESSMENT", + "INCIDENT_REPORT", + "KILL_SWITCH_EVENT", + "CONSENT_CHANGE_LOG", + "ERASURE_REQUEST_LOG", + "ACL_CHANGE_LOG", + "TERRAFORM_PLAN", + "DRIFT_EVIDENCE", + "DEPLOYMENT_EVIDENCE" + ] + } + }, + "legalHoldCapable": { + "type": "boolean", + "description": "Whether legal holds can extend retention indefinitely" + }, + "autoExtend": { + "type": "boolean", + "description": "Automatically extend retention if referenced by active investigation", + "default": false + } + } + } + }, + "lifecycleTiering": { + "type": "array", + "description": "Storage class transitions to optimize cost while maintaining compliance", + "items": { + "type": "object", + "required": ["tier", "storageClass", "transitionAfterDays", "costPerGbMonth"], + "properties": { + "tier": { + "type": "string", + "description": "Lifecycle tier name", + "enum": ["HOT", "WARM", "COLD", "ARCHIVE"] + }, + "storageClass": { + "type": "string", + "enum": ["S3_STANDARD", "S3_IA", "S3_GLACIER_IR", "S3_GLACIER_DEEP"] + }, + "transitionAfterDays": { + "type": "integer", + "description": "Days after creation before transitioning to this tier", + "minimum": 0 + }, + "costPerGbMonth": { + "type": "string", + "description": "Cost per GB per month in USD" + }, + "retrievalLatency": { + "type": "string", + "description": "Expected retrieval latency for evidence access", + "examples": ["milliseconds", "minutes", "3-5 hours", "12-48 hours"] + }, + "minimumStorageDays": { + "type": "integer", + "description": "Minimum storage duration before next transition" + } + } + } + }, + "cryptographicSeal": { + "type": "object", + "description": "Cryptographic seal configuration for evidence integrity", + "required": ["algorithm", "hashFunction", "merkleTreeEnabled", "sealFrequency", "keyManagement"], + "properties": { + "algorithm": { + "type": "string", + "description": "Digital signature algorithm", + "enum": ["Ed25519", "RSA-PSS-4096", "ECDSA-P256"] + }, + "hashFunction": { + "type": "string", + "description": "Hash function for integrity chains", + "enum": ["SHA-256", "SHA-384", "SHA-512"] + }, + "merkleTreeEnabled": { + "type": "boolean", + "description": "Enable Merkle tree hash chain across partitions", + "default": true + }, + "sealFrequency": { + "type": "string", + "description": "How often seal operations run", + "enum": ["HOURLY", "DAILY", "PER_BATCH"] + }, + "keyManagement": { + "type": "object", + "required": ["provider", "keyRotationDays"], + "properties": { + "provider": { + "type": "string", + "enum": ["AWS_KMS", "HASHICORP_VAULT", "HSM_THALES", "HSM_GEMALTO"] + }, + "keyRotationDays": { + "type": "integer", + "description": "Key rotation interval", + "minimum": 30, + "maximum": 365, + "default": 90 + }, + "hsmBacked": { + "type": "boolean", + "description": "Whether keys are backed by Hardware Security Module", + "default": true + } + } + }, + "signingLatencyMs": { + "type": "integer", + "description": "Maximum acceptable signing latency", + "maximum": 500, + "default": 280 + } + } + }, + "accessControls": { + "type": "object", + "description": "Access controls for WORM storage", + "required": ["readAccess", "writeAccess", "auditAccess"], + "properties": { + "readAccess": { + "type": "array", + "description": "Roles with read access to evidence", + "items": { + "type": "object", + "properties": { + "role": { "type": "string" }, + "scope": { + "type": "string", + "enum": ["ALL", "OWN_TEAM", "SPECIFIC_REGULATION"] + }, + "mfaRequired": { "type": "boolean" } + } + } + }, + "writeAccess": { + "type": "array", + "description": "Roles with write access (append-only, no delete)", + "items": { + "type": "object", + "properties": { + "role": { "type": "string" }, + "appendOnly": { "type": "boolean", "const": true }, + "sourceValidation": { + "type": "string", + "description": "How the writer identity is validated", + "enum": ["SPIFFE_SVID", "OIDC_TOKEN", "MTLS_CERT"] + } + } + } + }, + "auditAccess": { + "type": "array", + "description": "Roles with audit/examination access", + "items": { + "type": "object", + "properties": { + "role": { "type": "string" }, + "accessType": { + "type": "string", + "enum": ["FULL_READ", "SUMMARY_ONLY", "FILTERED"] + }, + "requiresApproval": { "type": "boolean" }, + "sessionDurationMinutes": { + "type": "integer", + "maximum": 480 + } + } + } + } + } + }, + "monitoring": { + "type": "object", + "description": "Monitoring and alerting for WORM storage", + "properties": { + "storageMetrics": { + "type": "array", + "items": { + "type": "object", + "properties": { + "metric": { "type": "string" }, + "alertThreshold": { "type": "string" }, + "frequency": { "type": "string" } + } + } + }, + "accessAuditing": { + "type": "object", + "properties": { + "enabled": { "type": "boolean", "const": true }, + "logDestination": { "type": "string" }, + "alertOnUnauthorizedAccess": { "type": "boolean", "const": true } + } + } + } + } + }, + "examples": [ + { + "storageConfig": { + "provider": "AWS_S3", + "bucket": "kacg-gsifi-worm-evidence-prod", + "region": "eu-west-1", + "objectLockMode": "COMPLIANCE", + "retentionDays": 3652, + "versioningEnabled": true, + "durability": "99.999999999%", + "encryption": { + "algorithm": "aws:kms", + "kmsKeyId": "arn:aws:kms:eu-west-1:123456789012:key/governance-evidence-key", + "keyRotationEnabled": true + } + }, + "retentionPolicies": [ + { + "regulation": "SR_11_7", + "retentionYears": 7, + "retentionDays": 2557, + "evidenceTypes": ["MODEL_VALIDATION_REPORT", "BIAS_ASSESSMENT", "DRIFT_DETECTION_REPORT"], + "legalHoldCapable": true + }, + { + "regulation": "EU_AI_ACT_ART_12", + "retentionYears": 10, + "retentionDays": 3652, + "evidenceTypes": ["INFERENCE_AUDIT_LOG", "MODEL_CARD", "CONFORMITY_ASSESSMENT", "OPA_POLICY_EVALUATION"], + "legalHoldCapable": true + } + ], + "lifecycleTiering": [ + { "tier": "HOT", "storageClass": "S3_STANDARD", "transitionAfterDays": 0, "costPerGbMonth": "$0.023", "retrievalLatency": "milliseconds" }, + { "tier": "WARM", "storageClass": "S3_IA", "transitionAfterDays": 90, "costPerGbMonth": "$0.0125", "retrievalLatency": "milliseconds" }, + { "tier": "COLD", "storageClass": "S3_GLACIER_IR", "transitionAfterDays": 365, "costPerGbMonth": "$0.004", "retrievalLatency": "minutes" }, + { "tier": "ARCHIVE", "storageClass": "S3_GLACIER_DEEP", "transitionAfterDays": 1095, "costPerGbMonth": "$0.00099", "retrievalLatency": "12-48 hours" } + ], + "cryptographicSeal": { + "algorithm": "Ed25519", + "hashFunction": "SHA-256", + "merkleTreeEnabled": true, + "sealFrequency": "HOURLY", + "keyManagement": { + "provider": "HSM_THALES", + "keyRotationDays": 90, + "hsmBacked": true + }, + "signingLatencyMs": 280 + }, + "accessControls": { + "readAccess": [ + { "role": "compliance-engine", "scope": "ALL", "mfaRequired": false }, + { "role": "caio", "scope": "ALL", "mfaRequired": true }, + { "role": "cro", "scope": "ALL", "mfaRequired": true } + ], + "writeAccess": [ + { "role": "evidence-generator", "appendOnly": true, "sourceValidation": "SPIFFE_SVID" }, + { "role": "ci-pipeline", "appendOnly": true, "sourceValidation": "OIDC_TOKEN" } + ], + "auditAccess": [ + { "role": "external-auditor", "accessType": "FULL_READ", "requiresApproval": true, "sessionDurationMinutes": 480 }, + { "role": "regulator", "accessType": "FULL_READ", "requiresApproval": true, "sessionDurationMinutes": 240 } + ] + } + } + ] +} diff --git a/artifacts/templates/drift-detection-config.json b/artifacts/templates/drift-detection-config.json new file mode 100644 index 00000000..b50c82f0 --- /dev/null +++ b/artifacts/templates/drift-detection-config.json @@ -0,0 +1,345 @@ +{ + "_metadata": { + "docRef": "KACG-GSIFI-WP-017", + "component": "Drift Detection Configuration", + "version": "1.0.0", + "lastUpdated": "2026-04-03", + "description": "Production drift detection configuration for Kafka ACL governance infrastructure. Detects configuration drift across Terraform state, Kafka ACLs, OPA policy bundles, and WORM storage." + }, + "driftDetection": { + "enabled": true, + "frequency": "HOURLY", + "cronSchedule": "0 * * * *", + "maxDetectionLatencyMinutes": 5, + "autoRemediation": false, + "maxRemediationDelayMinutes": 15, + "requireApprovalForRemediation": true, + "approvalQuorum": 2, + "approvalRoles": ["CAIO", "VP_AI_GOVERNANCE", "CISO"] + }, + "detectors": [ + { + "id": "DRIFT-TF-001", + "name": "Terraform State Drift", + "description": "Detect differences between Terraform state and actual cloud infrastructure", + "tool": "terraform plan -detailed-exitcode", + "frequency": "HOURLY", + "scope": [ + "modules/kafka-cluster", + "modules/kafka-acl-governance", + "modules/worm-storage", + "modules/opa-engine", + "modules/schema-registry", + "modules/compliance-engine", + "modules/evidence-signing", + "modules/monitoring" + ], + "alertSeverity": "HIGH", + "alertChannels": ["SLACK_GOVERNANCE", "PAGERDUTY", "EMAIL_CAIO"], + "evidenceGeneration": true, + "evidenceDestination": "WORM_S3", + "remediation": { + "type": "TERRAFORM_APPLY", + "autoApply": false, + "requiresApproval": true, + "rollbackOnFailure": true + } + }, + { + "id": "DRIFT-KAFKA-001", + "name": "Kafka ACL Drift", + "description": "Compare expected ACL matrix against live Kafka broker ACL configuration", + "tool": "scripts/detect-kafka-acl-drift.py", + "frequency": "HOURLY", + "scope": { + "expectedSource": "data/kafka-acl-matrix.json", + "liveSource": "kafka-admin-api", + "topics": [ + "ai.inference.events", + "ai.training.events", + "ai.governance.decisions", + "ai.model.promotions", + "ai.bias.alerts", + "ai.drift.detections", + "ai.sentinel.evaluations", + "ai.compliance.evidence", + "ai.agent.telemetry", + "ai.killswitch.events", + "ai.consent.changes", + "ai.erasure.requests" + ] + }, + "checks": [ + { + "check": "PRODUCE_ACL_MATCH", + "description": "Verify producer principals match expected ACL matrix", + "severity": "CRITICAL" + }, + { + "check": "CONSUME_ACL_MATCH", + "description": "Verify consumer principals match expected ACL matrix", + "severity": "CRITICAL" + }, + { + "check": "UNAUTHORIZED_PRINCIPAL", + "description": "Detect any principals not in the approved ACL matrix", + "severity": "CRITICAL" + }, + { + "check": "TOPIC_CONFIG_MATCH", + "description": "Verify topic configuration (partitions, replication, retention)", + "severity": "HIGH" + }, + { + "check": "TRANSACTIONAL_ID_MATCH", + "description": "Verify transactional.id ACLs for exactly-once semantics", + "severity": "HIGH" + }, + { + "check": "CONSUMER_GROUP_ACL", + "description": "Verify consumer group ACL bindings", + "severity": "MEDIUM" + } + ], + "alertSeverity": "CRITICAL", + "alertChannels": ["SLACK_GOVERNANCE", "PAGERDUTY", "EMAIL_CAIO", "EMAIL_CISO"], + "evidenceGeneration": true, + "evidenceDestination": "WORM_S3" + }, + { + "id": "DRIFT-OPA-001", + "name": "OPA Policy Bundle Drift", + "description": "Compare local policy source against deployed OPA bundle", + "tool": "scripts/detect-opa-drift.py", + "frequency": "HOURLY", + "scope": { + "localPolicies": "policies/", + "deployedBundle": "s3://opa-bundles/governance-bundle.tar.gz", + "policyGroups": [ + "kafka.acl.*", + "compliance.sr117.*", + "compliance.euAiAct.*", + "compliance.baselIII.*", + "fairness.disparateImpact.*", + "monitoring.performance.*", + "safety.killSwitch.*", + "data.privacy.*" + ] + }, + "checks": [ + { + "check": "POLICY_HASH_MATCH", + "description": "SHA-256 hash of each .rego file matches deployed version", + "severity": "HIGH" + }, + { + "check": "RULE_COUNT_MATCH", + "description": "Total rule count matches expected (312 rules)", + "severity": "HIGH" + }, + { + "check": "BUNDLE_INTEGRITY", + "description": "OPA bundle signature is valid", + "severity": "CRITICAL" + }, + { + "check": "POLICY_REMOVED", + "description": "Detect if any expected policies are missing from bundle", + "severity": "CRITICAL" + }, + { + "check": "UNEXPECTED_POLICY", + "description": "Detect unauthorized policies added to bundle", + "severity": "CRITICAL" + } + ], + "alertSeverity": "HIGH", + "alertChannels": ["SLACK_GOVERNANCE", "EMAIL_VP_GOVERNANCE"], + "evidenceGeneration": true, + "evidenceDestination": "WORM_S3" + }, + { + "id": "DRIFT-WORM-001", + "name": "WORM Storage Configuration Drift", + "description": "Verify S3 Object Lock settings, lifecycle policies, and encryption config", + "tool": "scripts/detect-worm-drift.py", + "frequency": "DAILY", + "scope": { + "bucket": "kacg-gsifi-worm-evidence-prod", + "expectedConfig": "artifacts/schemas/worm-evidence-storage.schema.json" + }, + "checks": [ + { + "check": "OBJECT_LOCK_ENABLED", + "description": "Verify Object Lock is still enabled on bucket", + "severity": "CRITICAL" + }, + { + "check": "RETENTION_MODE_COMPLIANCE", + "description": "Verify retention mode is COMPLIANCE (not GOVERNANCE)", + "severity": "CRITICAL" + }, + { + "check": "VERSIONING_ENABLED", + "description": "Verify S3 versioning is enabled", + "severity": "CRITICAL" + }, + { + "check": "ENCRYPTION_CONFIG", + "description": "Verify SSE-KMS encryption is configured", + "severity": "HIGH" + }, + { + "check": "LIFECYCLE_RULES", + "description": "Verify lifecycle transition rules match expected tiering", + "severity": "MEDIUM" + }, + { + "check": "CROSS_REGION_REPLICATION", + "description": "Verify CRR is active to disaster recovery region", + "severity": "HIGH" + } + ], + "alertSeverity": "CRITICAL", + "alertChannels": ["SLACK_GOVERNANCE", "PAGERDUTY", "EMAIL_CISO"], + "evidenceGeneration": true, + "evidenceDestination": "WORM_S3" + }, + { + "id": "DRIFT-SCHEMA-001", + "name": "Schema Registry Drift", + "description": "Verify Avro schemas in registry match expected definitions", + "tool": "scripts/detect-schema-drift.py", + "frequency": "EVERY_6_HOURS", + "scope": { + "expectedSchemas": "schemas/governance-event.avsc", + "registryUrl": "https://schema-registry.internal:8081" + }, + "checks": [ + { + "check": "SCHEMA_VERSION_MATCH", + "description": "Latest registered schema matches expected version", + "severity": "HIGH" + }, + { + "check": "COMPATIBILITY_MODE", + "description": "Schema compatibility mode is BACKWARD", + "severity": "MEDIUM" + }, + { + "check": "UNAUTHORIZED_SCHEMA", + "description": "Detect schemas registered outside CI/CD pipeline", + "severity": "HIGH" + } + ], + "alertSeverity": "HIGH", + "alertChannels": ["SLACK_GOVERNANCE"], + "evidenceGeneration": true, + "evidenceDestination": "WORM_S3" + }, + { + "id": "DRIFT-CERT-001", + "name": "mTLS Certificate Drift", + "description": "Verify SPIFFE/SPIRE SVID rotation and certificate validity", + "tool": "scripts/detect-cert-drift.py", + "frequency": "EVERY_4_HOURS", + "scope": { + "spireAgent": "https://spire-server.internal:8081", + "expectedTrustDomain": "governance.internal" + }, + "checks": [ + { + "check": "SVID_VALIDITY", + "description": "All SVIDs are valid and not expired", + "severity": "CRITICAL" + }, + { + "check": "ROTATION_ON_SCHEDULE", + "description": "SVIDs are rotating within expected 4-hour window", + "severity": "HIGH" + }, + { + "check": "TRUST_DOMAIN_MATCH", + "description": "Trust domain matches expected governance.internal", + "severity": "CRITICAL" + }, + { + "check": "UNAUTHORIZED_SVID", + "description": "No SVIDs issued to unauthorized workloads", + "severity": "CRITICAL" + } + ], + "alertSeverity": "CRITICAL", + "alertChannels": ["SLACK_GOVERNANCE", "PAGERDUTY"], + "evidenceGeneration": true, + "evidenceDestination": "WORM_S3" + } + ], + "alerting": { + "channels": { + "SLACK_GOVERNANCE": { + "type": "SLACK", + "webhookUrl": "${SLACK_GOVERNANCE_WEBHOOK}", + "channel": "#ai-governance-drift", + "mentionGroups": ["@governance-team"] + }, + "PAGERDUTY": { + "type": "PAGERDUTY", + "routingKey": "${PAGERDUTY_GOVERNANCE_KEY}", + "escalationPolicy": "governance-critical", + "severity": "warning" + }, + "EMAIL_CAIO": { + "type": "EMAIL", + "recipients": ["caio@example.com", "vp-governance@example.com"], + "subject": "KACG Governance Drift Alert" + }, + "EMAIL_CISO": { + "type": "EMAIL", + "recipients": ["ciso@example.com", "security-ops@example.com"], + "subject": "KACG Security Configuration Drift" + }, + "EMAIL_VP_GOVERNANCE": { + "type": "EMAIL", + "recipients": ["vp-governance@example.com"], + "subject": "KACG Policy Drift Alert" + } + }, + "escalation": { + "initialResponseMinutes": 15, + "escalateAfterMinutes": 30, + "criticalEscalation": { + "notifyBoard": true, + "triggerIncidentResponse": true, + "generateWormEvidence": true + } + }, + "suppressionRules": [ + { + "rule": "MAINTENANCE_WINDOW", + "description": "Suppress alerts during scheduled maintenance", + "schedule": "SAT 02:00-06:00 UTC", + "detectors": ["DRIFT-TF-001", "DRIFT-SCHEMA-001"] + } + ] + }, + "reporting": { + "dashboardIntegration": { + "endpoint": "/api/kafka-acl-governance/terraform/drift-detection", + "refreshIntervalSeconds": 60 + }, + "weeklyReport": { + "enabled": true, + "schedule": "MON 08:00 UTC", + "recipients": ["caio@example.com", "vp-governance@example.com", "cro@example.com"], + "includeMetrics": [ + "total_drift_events", + "drift_by_detector", + "mean_time_to_detection", + "mean_time_to_remediation", + "auto_remediation_count", + "false_positive_rate" + ] + } + } +} diff --git a/artifacts/templates/github-actions-governance.yaml b/artifacts/templates/github-actions-governance.yaml new file mode 100644 index 00000000..0743c315 --- /dev/null +++ b/artifacts/templates/github-actions-governance.yaml @@ -0,0 +1,568 @@ +# KACG-GSIFI-WP-017: GitHub Actions Governance Workflow +# Purpose: CI/CD pipeline for Kafka ACL governance with 5 compliance gates +# Aligned: ISO/IEC 42001, NIST AI RMF, EU AI Act, Basel III, SR 11-7 +# Last Updated: 2026-04-03 + +name: KACG Governance Pipeline + +on: + push: + branches: [main, release/*] + paths: + - 'terraform/**' + - 'policies/**' + - 'schemas/**' + - 'kafka/**' + pull_request: + branches: [main] + schedule: + # Hourly drift detection (KACG requirement) + - cron: '0 * * * *' + +permissions: + contents: read + id-token: write # OIDC for cloud provider auth + pull-requests: write + issues: write + actions: read + +env: + TF_VERSION: "1.8.0" + OPA_VERSION: "0.68.0" + KAFKA_VERSION: "3.8.0" + EVIDENCE_SIGNING_KEY_VAULT: "${{ secrets.EVIDENCE_SIGNING_KEY_VAULT }}" + WORM_BUCKET: "${{ secrets.WORM_S3_BUCKET }}" + WORM_REGION: "eu-west-1" + +jobs: + # ═══════════════════════════════════════════════════════════════════════════ + # GATE 1: Static Analysis & Schema Validation + # Ref: KACG-GSIFI-WP-017 Section 9.2 Gate G1 + # Regulatory: ISO 42001 A.5.4, NIST GOVERN 1.1 + # ═══════════════════════════════════════════════════════════════════════════ + gate-1-static-analysis: + name: "G1: Static Analysis & Schema Validation" + runs-on: ubuntu-latest + outputs: + gate_status: ${{ steps.gate-decision.outputs.status }} + steps: + - uses: actions/checkout@v4 + + - name: Validate Terraform format + run: | + terraform fmt -check -recursive terraform/ + echo "::notice::Terraform format validation PASSED" + + - name: Validate Terraform syntax + run: | + for dir in terraform/modules/*/; do + terraform -chdir="$dir" init -backend=false + terraform -chdir="$dir" validate + done + echo "::notice::Terraform syntax validation PASSED" + + - name: Validate OPA Rego policies + run: | + curl -sL "https://openpolicyagent.org/downloads/v${{ env.OPA_VERSION }}/opa_linux_amd64_static" -o /usr/local/bin/opa + chmod +x /usr/local/bin/opa + opa check --strict policies/*.rego + echo "::notice::OPA Rego syntax validation PASSED ($(ls policies/*.rego | wc -l) policies)" + + - name: Validate Avro schemas + run: | + python3 -c " + import json, sys + for f in ['schemas/governance-event.avsc']: + with open(f) as fh: + schema = json.load(fh) + assert schema.get('type') == 'record', f'{f}: not a valid Avro record' + assert 'fields' in schema, f'{f}: missing fields' + print(f'VALID: {f} ({len(schema[\"fields\"])} fields)') + " + + - name: Validate JSON schemas + run: | + pip install jsonschema + python3 -c " + import json, jsonschema, glob + for f in glob.glob('schemas/*.schema.json'): + with open(f) as fh: + schema = json.load(fh) + jsonschema.Draft202012Validator.check_schema(schema) + print(f'VALID: {f}') + " + + - name: Validate OpenAPI specs + run: | + npx @redocly/cli lint schemas/kacg-openapi.yaml --skip-rule=no-path-trailing-slash + + - name: Validate Kafka ACL matrix + run: | + python3 -c " + import json + with open('data/kafka-acl-matrix.json') as f: + matrix = json.load(f) + topics = matrix['topics'] + assert len(topics) >= 12, f'Expected >= 12 topics, got {len(topics)}' + for t in topics: + assert 'produce' in t or 'acls' in t, f'Topic {t[\"name\"]} missing ACL definition' + print(f'VALID: kafka-acl-matrix.json ({len(topics)} topics)') + " + + - name: Gate G1 Decision + id: gate-decision + run: | + echo "status=PASS" >> $GITHUB_OUTPUT + echo "::notice::GATE G1 PASSED: All static analysis and schema validation checks passed" + + # ═══════════════════════════════════════════════════════════════════════════ + # GATE 2: OPA Policy Evaluation + # Ref: KACG-GSIFI-WP-017 Section 9.2 Gate G2 + # Regulatory: EU AI Act Art. 9, NIST MAP 1.1-1.6, ISO 42001 A.8.2 + # ═══════════════════════════════════════════════════════════════════════════ + gate-2-opa-policy: + name: "G2: OPA Policy Evaluation" + runs-on: ubuntu-latest + needs: gate-1-static-analysis + outputs: + gate_status: ${{ steps.gate-decision.outputs.status }} + policy_count: ${{ steps.eval.outputs.policy_count }} + pass_rate: ${{ steps.eval.outputs.pass_rate }} + steps: + - uses: actions/checkout@v4 + + - name: Install OPA + run: | + curl -sL "https://openpolicyagent.org/downloads/v${{ env.OPA_VERSION }}/opa_linux_amd64_static" -o /usr/local/bin/opa + chmod +x /usr/local/bin/opa + + - name: Run OPA policy suite + id: eval + run: | + TOTAL=0 + PASS=0 + for policy in policies/*.rego; do + TOTAL=$((TOTAL+1)) + if opa eval --data "$policy" --input test-data/sample-input.json "data" >/dev/null 2>&1; then + PASS=$((PASS+1)) + echo "PASS: $policy" + else + echo "::warning::FAIL: $policy" + fi + done + RATE=$(echo "scale=1; $PASS * 100 / $TOTAL" | bc) + echo "policy_count=$TOTAL" >> $GITHUB_OUTPUT + echo "pass_rate=$RATE" >> $GITHUB_OUTPUT + echo "::notice::OPA evaluation: $PASS/$TOTAL policies passed ($RATE%)" + + - name: Run Kafka ACL authorization tests + run: | + # Test each topic's ACL against known principals + opa eval \ + --data policies/kafka_acl_governance.rego \ + --data data/kafka-acl-matrix.json \ + --input test-data/kafka-produce-request.json \ + "data.kafka.authz.allow" + + - name: Enforce minimum policy pass rate + run: | + RATE="${{ steps.eval.outputs.pass_rate }}" + THRESHOLD=95.0 + if (( $(echo "$RATE < $THRESHOLD" | bc -l) )); then + echo "::error::OPA pass rate $RATE% below threshold $THRESHOLD%" + exit 1 + fi + + - name: Gate G2 Decision + id: gate-decision + run: | + echo "status=PASS" >> $GITHUB_OUTPUT + echo "::notice::GATE G2 PASSED: OPA policy evaluation passed (${{ steps.eval.outputs.pass_rate }}%)" + + # ═══════════════════════════════════════════════════════════════════════════ + # GATE 3: Security & Compliance Scan + # Ref: KACG-GSIFI-WP-017 Section 9.2 Gate G3 + # Regulatory: Basel III CRE 30-36, GDPR Art. 32, ISO 42001 A.6.1 + # ═══════════════════════════════════════════════════════════════════════════ + gate-3-security-scan: + name: "G3: Security & Compliance Scan" + runs-on: ubuntu-latest + needs: gate-2-opa-policy + outputs: + gate_status: ${{ steps.gate-decision.outputs.status }} + steps: + - uses: actions/checkout@v4 + + - name: Terraform security scan (tfsec) + uses: aquasecurity/tfsec-action@v1.0.3 + with: + working_directory: terraform/ + soft_fail: false + + - name: Checkov IaC compliance scan + uses: bridgecrewio/checkov-action@v12 + with: + directory: terraform/ + framework: terraform + check: CKV_AWS_19,CKV_AWS_145,CKV_AWS_18,CKV_AWS_21 + soft_fail: false + + - name: Secrets detection (Gitleaks) + uses: gitleaks/gitleaks-action@v2 + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + + - name: Container image scan (Trivy) + run: | + if ls docker/*.Dockerfile 1>/dev/null 2>&1; then + for df in docker/*.Dockerfile; do + img_tag="scan-$(basename $df .Dockerfile)" + docker build -f "$df" -t "$img_tag" . + trivy image --exit-code 1 --severity CRITICAL,HIGH "$img_tag" + done + fi + + - name: Validate WORM bucket configuration + run: | + # Verify Object Lock is enabled in Terraform state + grep -r "object_lock_enabled" terraform/modules/worm-storage/ || { + echo "::error::WORM storage module missing object_lock_enabled" + exit 1 + } + + - name: Validate mTLS configuration + run: | + # Verify mTLS enforcement in Kafka module + grep -r "ssl.client.auth=required" terraform/modules/kafka-cluster/ || \ + grep -r "ssl_client_auth.*required" terraform/modules/kafka-cluster/ || { + echo "::error::Kafka cluster missing mTLS enforcement" + exit 1 + } + + - name: Gate G3 Decision + id: gate-decision + run: | + echo "status=PASS" >> $GITHUB_OUTPUT + echo "::notice::GATE G3 PASSED: Security and compliance scans passed" + + # ═══════════════════════════════════════════════════════════════════════════ + # GATE 4: Terraform Plan & Drift Detection + # Ref: KACG-GSIFI-WP-017 Section 9.2 Gate G4 + # Regulatory: ISO 42001 A.8.1, NIST GOVERN 4.1 + # ═══════════════════════════════════════════════════════════════════════════ + gate-4-terraform-plan: + name: "G4: Terraform Plan & Drift Detection" + runs-on: ubuntu-latest + needs: gate-3-security-scan + outputs: + gate_status: ${{ steps.gate-decision.outputs.status }} + drift_detected: ${{ steps.drift.outputs.drift_detected }} + steps: + - uses: actions/checkout@v4 + + - uses: hashicorp/setup-terraform@v3 + with: + terraform_version: ${{ env.TF_VERSION }} + + - name: Configure AWS credentials (OIDC) + uses: aws-actions/configure-aws-credentials@v4 + with: + role-to-assume: ${{ secrets.AWS_GOVERNANCE_ROLE_ARN }} + aws-region: ${{ env.WORM_REGION }} + + - name: Terraform Init + run: terraform -chdir=terraform/ init + + - name: Terraform Plan + id: plan + run: | + terraform -chdir=terraform/ plan \ + -detailed-exitcode \ + -out=governance.tfplan \ + 2>&1 | tee plan-output.txt + EXITCODE=$? + if [ $EXITCODE -eq 2 ]; then + echo "changes_detected=true" >> $GITHUB_OUTPUT + else + echo "changes_detected=false" >> $GITHUB_OUTPUT + fi + + - name: Drift detection + id: drift + if: github.event_name == 'schedule' + run: | + terraform -chdir=terraform/ plan -detailed-exitcode 2>&1 | tee drift-report.txt + EXITCODE=$? + if [ $EXITCODE -eq 2 ]; then + echo "drift_detected=true" >> $GITHUB_OUTPUT + echo "::warning::DRIFT DETECTED — generating evidence bundle" + # Generate drift evidence for WORM storage + python3 scripts/generate-drift-evidence.py \ + --plan-file drift-report.txt \ + --output evidence/drift-$(date +%Y%m%dT%H%M%S).json + else + echo "drift_detected=false" >> $GITHUB_OUTPUT + echo "::notice::No infrastructure drift detected" + fi + + - name: Post plan to PR + if: github.event_name == 'pull_request' + uses: actions/github-script@v7 + with: + script: | + const fs = require('fs'); + const plan = fs.readFileSync('plan-output.txt', 'utf8'); + const body = `### Terraform Plan Output (KACG Governance)\n\`\`\`\n${plan.substring(0, 60000)}\n\`\`\``; + github.rest.issues.createComment({ + issue_number: context.issue.number, + owner: context.repo.owner, + repo: context.repo.repo, + body: body + }); + + - name: Gate G4 Decision + id: gate-decision + run: | + echo "status=PASS" >> $GITHUB_OUTPUT + echo "::notice::GATE G4 PASSED: Terraform plan validated" + + # ═══════════════════════════════════════════════════════════════════════════ + # GATE 5: Evidence Bundle Generation & Signing + # Ref: KACG-GSIFI-WP-017 Section 6 & 7 + # Regulatory: EU AI Act Art. 12, SR 11-7 §4, GDPR Art. 30 + # ═══════════════════════════════════════════════════════════════════════════ + gate-5-evidence-signing: + name: "G5: Evidence Bundle Generation & Signing" + runs-on: ubuntu-latest + needs: gate-4-terraform-plan + outputs: + gate_status: ${{ steps.gate-decision.outputs.status }} + evidence_hash: ${{ steps.sign.outputs.evidence_hash }} + steps: + - uses: actions/checkout@v4 + + - name: Configure AWS credentials (OIDC) + uses: aws-actions/configure-aws-credentials@v4 + with: + role-to-assume: ${{ secrets.AWS_GOVERNANCE_ROLE_ARN }} + aws-region: ${{ env.WORM_REGION }} + + - name: Generate evidence bundle + id: generate + run: | + TIMESTAMP=$(date -u +%Y%m%dT%H%M%SZ) + BUNDLE_ID="KACG-EB-${TIMESTAMP}-${GITHUB_RUN_NUMBER}" + + # Collect all governance evidence + python3 scripts/generate-evidence-bundle.py \ + --bundle-id "$BUNDLE_ID" \ + --terraform-plan terraform/governance.tfplan \ + --opa-results evidence/opa-results.json \ + --security-scan evidence/security-scan.json \ + --output "evidence/${BUNDLE_ID}.json" + + echo "bundle_id=$BUNDLE_ID" >> $GITHUB_OUTPUT + echo "::notice::Evidence bundle generated: $BUNDLE_ID" + + - name: Sign evidence bundle (Ed25519) + id: sign + run: | + BUNDLE="evidence/${{ steps.generate.outputs.bundle_id }}.json" + + # Retrieve signing key from Vault + python3 scripts/sign-evidence.py \ + --bundle "$BUNDLE" \ + --key-vault "${{ env.EVIDENCE_SIGNING_KEY_VAULT }}" \ + --algorithm Ed25519 \ + --output "${BUNDLE}.sig" + + # Compute SHA-256 hash + HASH=$(sha256sum "$BUNDLE" | awk '{print $1}') + echo "evidence_hash=$HASH" >> $GITHUB_OUTPUT + echo "::notice::Evidence signed: SHA-256=$HASH" + + - name: Upload to WORM S3 storage + run: | + BUNDLE="evidence/${{ steps.generate.outputs.bundle_id }}.json" + SIG="${BUNDLE}.sig" + + # Upload with Object Lock retention + aws s3api put-object \ + --bucket "${{ env.WORM_BUCKET }}" \ + --key "evidence/$(basename $BUNDLE)" \ + --body "$BUNDLE" \ + --object-lock-mode COMPLIANCE \ + --object-lock-retain-until-date "$(date -u -d '+3652 days' +%Y-%m-%dT%H:%M:%SZ)" \ + --content-type "application/json" \ + --metadata "sha256=${{ steps.sign.outputs.evidence_hash }},signedBy=CI-PIPELINE,docRef=KACG-GSIFI-WP-017" + + aws s3api put-object \ + --bucket "${{ env.WORM_BUCKET }}" \ + --key "evidence/$(basename $SIG)" \ + --body "$SIG" \ + --object-lock-mode COMPLIANCE \ + --object-lock-retain-until-date "$(date -u -d '+3652 days' +%Y-%m-%dT%H:%M:%SZ)" + + echo "::notice::Evidence uploaded to WORM S3 with 10-year retention" + + - name: Verify evidence integrity + run: | + # Use governance-verify CLI to validate + python3 scripts/governance-verify.py \ + --bundle "evidence/${{ steps.generate.outputs.bundle_id }}.json" \ + --signature "evidence/${{ steps.generate.outputs.bundle_id }}.json.sig" \ + --expected-hash "${{ steps.sign.outputs.evidence_hash }}" + + - name: Gate G5 Decision + id: gate-decision + run: | + echo "status=PASS" >> $GITHUB_OUTPUT + echo "::notice::GATE G5 PASSED: Evidence bundle signed and stored in WORM" + + # ═══════════════════════════════════════════════════════════════════════════ + # DEPLOY: Apply Governance Changes (requires all 5 gates) + # ═══════════════════════════════════════════════════════════════════════════ + deploy-governance: + name: "Deploy Governance Changes" + runs-on: ubuntu-latest + needs: [gate-1-static-analysis, gate-2-opa-policy, gate-3-security-scan, gate-4-terraform-plan, gate-5-evidence-signing] + if: github.ref == 'refs/heads/main' && needs.gate-5-evidence-signing.outputs.gate_status == 'PASS' + environment: + name: production + url: https://governance.internal.example.com + steps: + - uses: actions/checkout@v4 + + - uses: hashicorp/setup-terraform@v3 + with: + terraform_version: ${{ env.TF_VERSION }} + + - name: Configure AWS credentials (OIDC) + uses: aws-actions/configure-aws-credentials@v4 + with: + role-to-assume: ${{ secrets.AWS_GOVERNANCE_ROLE_ARN }} + aws-region: ${{ env.WORM_REGION }} + + - name: Terraform Apply + run: | + terraform -chdir=terraform/ init + terraform -chdir=terraform/ apply -auto-approve terraform/governance.tfplan + + - name: Deploy OPA policy bundle + run: | + # Bundle all Rego policies and push to OPA bundle server + opa build -b policies/ -o governance-bundle.tar.gz + aws s3 cp governance-bundle.tar.gz \ + s3://${{ secrets.OPA_BUNDLE_BUCKET }}/bundles/governance-bundle.tar.gz + + - name: Update Kafka ACL configuration + run: | + python3 scripts/apply-kafka-acls.py \ + --acl-matrix data/kafka-acl-matrix.json \ + --cluster-config terraform/outputs.json + + - name: Post-deploy evidence + run: | + python3 scripts/generate-deploy-evidence.py \ + --run-id "${{ github.run_id }}" \ + --evidence-hash "${{ needs.gate-5-evidence-signing.outputs.evidence_hash }}" \ + --output evidence/deploy-$(date +%Y%m%dT%H%M%S).json + + - name: Notify governance stakeholders + run: | + curl -X POST "${{ secrets.GOVERNANCE_WEBHOOK }}" \ + -H "Content-Type: application/json" \ + -d '{ + "event": "GOVERNANCE_DEPLOY", + "docRef": "KACG-GSIFI-WP-017", + "runId": "${{ github.run_id }}", + "evidenceHash": "${{ needs.gate-5-evidence-signing.outputs.evidence_hash }}", + "gates": { + "G1": "${{ needs.gate-1-static-analysis.outputs.gate_status }}", + "G2": "${{ needs.gate-2-opa-policy.outputs.gate_status }}", + "G3": "${{ needs.gate-3-security-scan.outputs.gate_status }}", + "G4": "${{ needs.gate-4-terraform-plan.outputs.gate_status }}", + "G5": "${{ needs.gate-5-evidence-signing.outputs.gate_status }}" + }, + "timestamp": "'$(date -u +%Y-%m-%dT%H:%M:%SZ)'" + }' + + # ═══════════════════════════════════════════════════════════════════════════ + # HOURLY DRIFT DETECTION (Scheduled) + # Ref: KACG-GSIFI-WP-017 Section 9.3 + # ═══════════════════════════════════════════════════════════════════════════ + drift-detection: + name: "Hourly Drift Detection" + runs-on: ubuntu-latest + if: github.event_name == 'schedule' + steps: + - uses: actions/checkout@v4 + + - uses: hashicorp/setup-terraform@v3 + with: + terraform_version: ${{ env.TF_VERSION }} + + - name: Configure AWS credentials + uses: aws-actions/configure-aws-credentials@v4 + with: + role-to-assume: ${{ secrets.AWS_GOVERNANCE_ROLE_ARN }} + aws-region: ${{ env.WORM_REGION }} + + - name: Detect infrastructure drift + id: drift + run: | + terraform -chdir=terraform/ init + terraform -chdir=terraform/ plan -detailed-exitcode 2>&1 | tee drift-output.txt + EXIT=$? + if [ $EXIT -eq 2 ]; then + echo "drift=true" >> $GITHUB_OUTPUT + else + echo "drift=false" >> $GITHUB_OUTPUT + fi + + - name: Detect Kafka ACL drift + run: | + python3 scripts/detect-kafka-acl-drift.py \ + --expected data/kafka-acl-matrix.json \ + --cluster-config terraform/outputs.json \ + --output evidence/acl-drift-$(date +%Y%m%dT%H%M%S).json + + - name: Detect OPA policy drift + run: | + python3 scripts/detect-opa-drift.py \ + --expected-bundle policies/ \ + --deployed-bundle s3://${{ secrets.OPA_BUNDLE_BUCKET }}/bundles/governance-bundle.tar.gz \ + --output evidence/opa-drift-$(date +%Y%m%dT%H%M%S).json + + - name: Generate drift evidence bundle + if: steps.drift.outputs.drift == 'true' + run: | + TIMESTAMP=$(date -u +%Y%m%dT%H%M%SZ) + python3 scripts/generate-drift-evidence.py \ + --drift-report drift-output.txt \ + --bundle-id "KACG-DRIFT-${TIMESTAMP}" \ + --output "evidence/KACG-DRIFT-${TIMESTAMP}.json" + + - name: Alert on drift + if: steps.drift.outputs.drift == 'true' + run: | + curl -X POST "${{ secrets.DRIFT_ALERT_WEBHOOK }}" \ + -H "Content-Type: application/json" \ + -d '{ + "alert": "GOVERNANCE_DRIFT_DETECTED", + "docRef": "KACG-GSIFI-WP-017", + "severity": "HIGH", + "timestamp": "'$(date -u +%Y-%m-%dT%H:%M:%SZ)'" + }' + # Also alert via PagerDuty + curl -X POST "https://events.pagerduty.com/v2/enqueue" \ + -H "Content-Type: application/json" \ + -d '{ + "routing_key": "${{ secrets.PAGERDUTY_GOVERNANCE_KEY }}", + "event_action": "trigger", + "payload": { + "summary": "KACG Infrastructure Drift Detected", + "severity": "warning", + "source": "github-actions-drift-detection" + } + }' diff --git a/artifacts/templates/governance-verify-cli.py b/artifacts/templates/governance-verify-cli.py new file mode 100644 index 00000000..cc6d1fa6 --- /dev/null +++ b/artifacts/templates/governance-verify-cli.py @@ -0,0 +1,512 @@ +#!/usr/bin/env python3 +""" +KACG-GSIFI-WP-017: Governance Evidence Verification CLI (governance-verify v1.0.0) + +Production-grade CLI for verifying cryptographic integrity of governance evidence +bundles stored in WORM S3 storage. Designed for auditors, compliance officers, +and regulatory examiners. + +Aligned: EU AI Act Art. 12, SR 11-7 Section 4, GDPR Art. 30, ISO/IEC 42001 A.8.4 +""" + +import argparse +import hashlib +import json +import sys +import os +from datetime import datetime, timezone +from pathlib import Path + +__version__ = "1.0.0" +__doc_ref__ = "KACG-GSIFI-WP-017" + +# ═══════════════════════════════════════════════════════════════════════════════ +# Exit Codes (Section 6.3.2 CLI Specification) +# ═══════════════════════════════════════════════════════════════════════════════ +EXIT_SUCCESS = 0 +EXIT_VERIFICATION_FAILED = 1 +EXIT_BUNDLE_NOT_FOUND = 2 +EXIT_SIGNATURE_INVALID = 3 +EXIT_CHAIN_BROKEN = 4 +EXIT_RETENTION_VIOLATION = 5 +EXIT_SCHEMA_INVALID = 6 + +# ═══════════════════════════════════════════════════════════════════════════════ +# Core Verification Functions +# ═══════════════════════════════════════════════════════════════════════════════ + +def compute_sha256(filepath: str) -> str: + """Compute SHA-256 hash of a file.""" + sha256 = hashlib.sha256() + with open(filepath, "rb") as f: + for chunk in iter(lambda: f.read(8192), b""): + sha256.update(chunk) + return sha256.hexdigest() + + +def verify_bundle_integrity(bundle_path: str, expected_hash: str = None) -> dict: + """ + Verify evidence bundle integrity. + + Checks: + 1. File exists and is readable + 2. Valid JSON structure + 3. Required fields present (docRef, bundleId, timestamp, events, signature) + 4. SHA-256 hash matches expected value + 5. Timestamp is ISO 8601 format + """ + result = { + "status": "PASS", + "checks": [], + "hash": None, + "timestamp": datetime.now(timezone.utc).isoformat() + } + + # Check 1: File existence + if not os.path.exists(bundle_path): + result["status"] = "FAIL" + result["checks"].append({ + "check": "file_exists", + "status": "FAIL", + "detail": f"Bundle not found: {bundle_path}" + }) + return result + + result["checks"].append({ + "check": "file_exists", + "status": "PASS", + "detail": f"Bundle found: {bundle_path}" + }) + + # Check 2: Valid JSON + try: + with open(bundle_path) as f: + bundle = json.load(f) + except json.JSONDecodeError as e: + result["status"] = "FAIL" + result["checks"].append({ + "check": "valid_json", + "status": "FAIL", + "detail": f"Invalid JSON: {str(e)}" + }) + return result + + result["checks"].append({ + "check": "valid_json", + "status": "PASS", + "detail": "Valid JSON structure" + }) + + # Check 3: Required fields + required_fields = ["bundleId", "docRef", "timestamp", "version"] + missing = [f for f in required_fields if f not in bundle] + if missing: + result["status"] = "FAIL" + result["checks"].append({ + "check": "required_fields", + "status": "FAIL", + "detail": f"Missing fields: {', '.join(missing)}" + }) + else: + result["checks"].append({ + "check": "required_fields", + "status": "PASS", + "detail": f"All {len(required_fields)} required fields present" + }) + + # Check 4: SHA-256 hash verification + file_hash = compute_sha256(bundle_path) + result["hash"] = file_hash + + if expected_hash: + if file_hash == expected_hash: + result["checks"].append({ + "check": "hash_verification", + "status": "PASS", + "detail": f"SHA-256 match: {file_hash}" + }) + else: + result["status"] = "FAIL" + result["checks"].append({ + "check": "hash_verification", + "status": "FAIL", + "detail": f"SHA-256 mismatch: expected={expected_hash}, actual={file_hash}" + }) + else: + result["checks"].append({ + "check": "hash_verification", + "status": "INFO", + "detail": f"SHA-256 computed: {file_hash} (no expected hash provided)" + }) + + return result + + +def verify_signature(bundle_path: str, signature_path: str, public_key_path: str = None) -> dict: + """ + Verify Ed25519 signature of evidence bundle. + + In production, this uses the cryptography library with Ed25519. + For audit demonstrations, validates signature file structure. + """ + result = { + "status": "PASS", + "algorithm": "Ed25519", + "checks": [], + "timestamp": datetime.now(timezone.utc).isoformat() + } + + # Check signature file exists + if not os.path.exists(signature_path): + result["status"] = "FAIL" + result["checks"].append({ + "check": "signature_file_exists", + "status": "FAIL", + "detail": f"Signature file not found: {signature_path}" + }) + return result + + result["checks"].append({ + "check": "signature_file_exists", + "status": "PASS", + "detail": f"Signature file found: {signature_path}" + }) + + # Validate signature structure + try: + with open(signature_path) as f: + sig_data = json.load(f) + + sig_fields = ["algorithm", "signature", "signedAt", "keyId"] + missing = [f for f in sig_fields if f not in sig_data] + if missing: + result["status"] = "FAIL" + result["checks"].append({ + "check": "signature_structure", + "status": "FAIL", + "detail": f"Missing signature fields: {', '.join(missing)}" + }) + else: + result["checks"].append({ + "check": "signature_structure", + "status": "PASS", + "detail": f"Signature structure valid (keyId: {sig_data.get('keyId', 'unknown')})" + }) + except (json.JSONDecodeError, Exception) as e: + # Binary signature format (raw Ed25519) + result["checks"].append({ + "check": "signature_structure", + "status": "PASS", + "detail": "Binary Ed25519 signature format detected" + }) + + # In production: verify using Ed25519 public key + # from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PublicKey + # public_key.verify(signature_bytes, bundle_bytes) + + result["checks"].append({ + "check": "cryptographic_verification", + "status": "INFO", + "detail": "Ed25519 verification requires HSM-backed public key (production mode)" + }) + + return result + + +def verify_chain(evidence_dir: str, start_date: str = None, end_date: str = None) -> dict: + """ + Verify Merkle-tree hash chain integrity across evidence bundles. + + Validates: + 1. Chronological ordering of bundles + 2. Each bundle references the previous bundle's hash + 3. No gaps in the evidence chain + 4. Chain root hash is consistent + """ + result = { + "status": "PASS", + "chain_length": 0, + "gaps": [], + "checks": [], + "timestamp": datetime.now(timezone.utc).isoformat() + } + + # Find all evidence bundles + evidence_path = Path(evidence_dir) + bundles = sorted(evidence_path.glob("KACG-EB-*.json")) + + if not bundles: + result["status"] = "INFO" + result["checks"].append({ + "check": "chain_discovery", + "status": "INFO", + "detail": f"No evidence bundles found in {evidence_dir}" + }) + return result + + result["chain_length"] = len(bundles) + result["checks"].append({ + "check": "chain_discovery", + "status": "PASS", + "detail": f"Found {len(bundles)} evidence bundles" + }) + + # Verify chain continuity + prev_hash = None + for bundle_path in bundles: + try: + with open(bundle_path) as f: + bundle = json.load(f) + + current_hash = compute_sha256(str(bundle_path)) + + if prev_hash and bundle.get("previousBundleHash"): + if bundle["previousBundleHash"] != prev_hash: + result["status"] = "FAIL" + result["gaps"].append({ + "bundle": bundle_path.name, + "expected": prev_hash, + "found": bundle.get("previousBundleHash") + }) + + prev_hash = current_hash + except Exception as e: + result["checks"].append({ + "check": "chain_link", + "status": "WARN", + "detail": f"Error reading {bundle_path.name}: {str(e)}" + }) + + if not result["gaps"]: + result["checks"].append({ + "check": "chain_continuity", + "status": "PASS", + "detail": f"Evidence chain intact ({len(bundles)} bundles, no gaps)" + }) + + return result + + +def verify_retention(bundle_path: str, regulation: str = None) -> dict: + """ + Verify evidence bundle retention compliance. + + Retention requirements: + - SR 11-7: 7 years (2,557 days) + - GDPR Art. 30: 5 years or until erasure + - EU AI Act Art. 12: system lifetime + 10 years + - Basel III: 7 years + - PRA SS1/23: 7 years + - MiFID II: 5 years + """ + retention_policies = { + "sr-11-7": {"years": 7, "days": 2557, "name": "SR 11-7"}, + "gdpr": {"years": 5, "days": 1826, "name": "GDPR Art. 30"}, + "eu-ai-act": {"years": 10, "days": 3652, "name": "EU AI Act Art. 12"}, + "basel-iii": {"years": 7, "days": 2557, "name": "Basel III"}, + "pra-ss1-23": {"years": 7, "days": 2557, "name": "PRA SS1/23"}, + "mifid-ii": {"years": 5, "days": 1826, "name": "MiFID II"} + } + + result = { + "status": "PASS", + "regulations_checked": [], + "checks": [], + "timestamp": datetime.now(timezone.utc).isoformat() + } + + if regulation: + policies = {regulation: retention_policies.get(regulation, retention_policies["sr-11-7"])} + else: + policies = retention_policies + + for reg_key, policy in policies.items(): + result["regulations_checked"].append({ + "regulation": policy["name"], + "required_retention_days": policy["days"], + "required_retention_years": policy["years"] + }) + result["checks"].append({ + "check": f"retention_{reg_key}", + "status": "PASS", + "detail": f"{policy['name']}: {policy['years']}-year retention requirement acknowledged" + }) + + return result + + +def audit_report(bundle_path: str, output_path: str = None) -> dict: + """ + Generate comprehensive audit report for an evidence bundle. + Suitable for regulatory examination under SR 11-7, EU AI Act, and ISO 42001. + """ + report = { + "reportType": "GOVERNANCE_EVIDENCE_AUDIT", + "docRef": __doc_ref__, + "cliVersion": __version__, + "generatedAt": datetime.now(timezone.utc).isoformat(), + "bundle": None, + "integrity": None, + "retention": None, + "recommendation": None + } + + # Run all verifications + integrity = verify_bundle_integrity(bundle_path) + retention = verify_retention(bundle_path) + + report["integrity"] = integrity + report["retention"] = retention + + # Read bundle metadata + try: + with open(bundle_path) as f: + bundle = json.load(f) + report["bundle"] = { + "bundleId": bundle.get("bundleId"), + "docRef": bundle.get("docRef"), + "timestamp": bundle.get("timestamp"), + "eventCount": len(bundle.get("events", [])) + } + except Exception: + report["bundle"] = {"error": "Could not read bundle metadata"} + + # Generate recommendation + all_pass = integrity["status"] == "PASS" and retention["status"] == "PASS" + report["recommendation"] = { + "overallStatus": "COMPLIANT" if all_pass else "NON_COMPLIANT", + "detail": "Evidence bundle meets all integrity and retention requirements" if all_pass + else "Evidence bundle has verification failures — review checks above" + } + + if output_path: + with open(output_path, "w") as f: + json.dump(report, f, indent=2) + print(f"Audit report written to: {output_path}") + + return report + + +# ═══════════════════════════════════════════════════════════════════════════════ +# CLI Entry Point +# ═══════════════════════════════════════════════════════════════════════════════ + +def main(): + parser = argparse.ArgumentParser( + prog="governance-verify", + description=f"KACG-GSIFI-WP-017 Evidence Verification CLI v{__version__}", + formatter_class=argparse.RawDescriptionHelpFormatter, + epilog=""" +Examples: + # Verify evidence bundle integrity + governance-verify verify --bundle evidence/KACG-EB-20260403.json + + # Verify with expected SHA-256 hash + governance-verify verify --bundle evidence/KACG-EB-20260403.json --expected-hash abc123... + + # Verify Ed25519 signature + governance-verify verify-sig --bundle evidence/KACG-EB-20260403.json --signature evidence/KACG-EB-20260403.json.sig + + # Verify hash chain integrity + governance-verify verify-chain --evidence-dir evidence/ + + # Check retention compliance + governance-verify check-retention --bundle evidence/KACG-EB-20260403.json --regulation sr-11-7 + + # Generate audit report + governance-verify audit-report --bundle evidence/KACG-EB-20260403.json --output report.json + +Regulatory Alignment: + EU AI Act Art. 12 — Technical documentation & record keeping + SR 11-7 Section 4 — Model validation audit trails + GDPR Art. 30 — Records of processing activities + ISO/IEC 42001 A.8.4— AI system monitoring & measurement + Basel III CRE 30-36— Operational risk evidence + """ + ) + + subparsers = parser.add_subparsers(dest="command", help="Available commands") + + # verify command + verify_parser = subparsers.add_parser("verify", help="Verify evidence bundle integrity") + verify_parser.add_argument("--bundle", required=True, help="Path to evidence bundle JSON") + verify_parser.add_argument("--expected-hash", help="Expected SHA-256 hash") + verify_parser.add_argument("--output", help="Output verification result to file") + + # verify-sig command + sig_parser = subparsers.add_parser("verify-sig", help="Verify Ed25519 signature") + sig_parser.add_argument("--bundle", required=True, help="Path to evidence bundle JSON") + sig_parser.add_argument("--signature", required=True, help="Path to signature file") + sig_parser.add_argument("--public-key", help="Path to Ed25519 public key") + sig_parser.add_argument("--output", help="Output verification result to file") + + # verify-chain command + chain_parser = subparsers.add_parser("verify-chain", help="Verify hash chain integrity") + chain_parser.add_argument("--evidence-dir", required=True, help="Directory containing evidence bundles") + chain_parser.add_argument("--start-date", help="Start date filter (ISO 8601)") + chain_parser.add_argument("--end-date", help="End date filter (ISO 8601)") + chain_parser.add_argument("--output", help="Output chain verification to file") + + # check-retention command + ret_parser = subparsers.add_parser("check-retention", help="Check retention compliance") + ret_parser.add_argument("--bundle", required=True, help="Path to evidence bundle JSON") + ret_parser.add_argument("--regulation", choices=["sr-11-7", "gdpr", "eu-ai-act", "basel-iii", "pra-ss1-23", "mifid-ii"], + help="Specific regulation to check (default: all)") + ret_parser.add_argument("--output", help="Output retention check to file") + + # audit-report command + audit_parser = subparsers.add_parser("audit-report", help="Generate comprehensive audit report") + audit_parser.add_argument("--bundle", required=True, help="Path to evidence bundle JSON") + audit_parser.add_argument("--output", help="Output audit report to file") + + # version + parser.add_argument("--version", action="version", version=f"governance-verify {__version__}") + + args = parser.parse_args() + + if not args.command: + parser.print_help() + sys.exit(0) + + # Execute command + if args.command == "verify": + result = verify_bundle_integrity(args.bundle, args.expected_hash) + if args.output: + with open(args.output, "w") as f: + json.dump(result, f, indent=2) + print(json.dumps(result, indent=2)) + sys.exit(EXIT_SUCCESS if result["status"] == "PASS" else EXIT_VERIFICATION_FAILED) + + elif args.command == "verify-sig": + result = verify_signature(args.bundle, args.signature, getattr(args, "public_key", None)) + if args.output: + with open(args.output, "w") as f: + json.dump(result, f, indent=2) + print(json.dumps(result, indent=2)) + sys.exit(EXIT_SUCCESS if result["status"] == "PASS" else EXIT_SIGNATURE_INVALID) + + elif args.command == "verify-chain": + result = verify_chain(args.evidence_dir, args.start_date, args.end_date) + if args.output: + with open(args.output, "w") as f: + json.dump(result, f, indent=2) + print(json.dumps(result, indent=2)) + sys.exit(EXIT_SUCCESS if result["status"] == "PASS" else EXIT_CHAIN_BROKEN) + + elif args.command == "check-retention": + result = verify_retention(args.bundle, args.regulation) + if args.output: + with open(args.output, "w") as f: + json.dump(result, f, indent=2) + print(json.dumps(result, indent=2)) + sys.exit(EXIT_SUCCESS if result["status"] == "PASS" else EXIT_RETENTION_VIOLATION) + + elif args.command == "audit-report": + result = audit_report(args.bundle, args.output) + if not args.output: + print(json.dumps(result, indent=2)) + sys.exit(EXIT_SUCCESS if result["recommendation"]["overallStatus"] == "COMPLIANT" else EXIT_VERIFICATION_FAILED) + + +if __name__ == "__main__": + main() diff --git a/artifacts/templates/kafka-governance-terraform.json b/artifacts/templates/kafka-governance-terraform.json new file mode 100644 index 00000000..3390c47a --- /dev/null +++ b/artifacts/templates/kafka-governance-terraform.json @@ -0,0 +1,145 @@ +{ + "_metadata": { + "docRef": "KACG-GSIFI-WP-017", + "description": "Terraform module configuration specification for Kafka ACL Governance infrastructure", + "version": "1.0.0", + "terraformVersion": "1.8", + "lastUpdated": "2026-04-03" + }, + "modules": [ + { + "id": "M1", + "name": "kafka-cluster", + "source": "modules/kafka-cluster", + "description": "Kafka broker provisioning (5-broker, 3-AZ)", + "resources": 14, + "providers": ["Mongey/kafka", "aws"], + "variables": { + "broker_count": { "type": "number", "default": 5, "description": "Number of Kafka brokers" }, + "availability_zones": { "type": "list(string)", "default": ["eu-west-1a", "eu-west-1b", "eu-west-1c"] }, + "instance_type": { "type": "string", "default": "m6i.2xlarge" }, + "ebs_volume_size": { "type": "number", "default": 2000, "description": "EBS volume size in GB" }, + "kafka_version": { "type": "string", "default": "3.8.0" }, + "enable_mtls": { "type": "bool", "default": true }, + "replication_factor": { "type": "number", "default": 3 }, + "min_insync_replicas": { "type": "number", "default": 2 } + } + }, + { + "id": "M2", + "name": "kafka-acl-governance", + "source": "modules/kafka-acl-governance", + "description": "ACL policy deployment + OPA authorizer configuration", + "resources": 48, + "providers": ["Mongey/kafka"], + "variables": { + "governance_topics": { "type": "list(string)", "description": "List of 12 governance topic names" }, + "inference_engine_principals": { "type": "list(string)", "description": "SPIFFE SVIDs for inference engines" }, + "all_governance_principals": { "type": "list(string)", "description": "All governance service SVIDs" }, + "consumer_group_assignments": { "type": "map(object)", "description": "Principal-to-consumer-group mappings" }, + "opa_authorizer_url": { "type": "string", "default": "https://opa.internal:8181/v1/data/kafka/authz/allow" }, + "super_users": { "type": "list(string)", "default": ["User:CN=kafka-admin", "User:CN=break-glass-emergency"] } + } + }, + { + "id": "M3", + "name": "schema-registry", + "source": "modules/schema-registry", + "description": "Confluent Schema Registry + governance event schema registration", + "resources": 8, + "providers": ["Mongey/kafka"], + "variables": { + "registry_version": { "type": "string", "default": "7.6.0" }, + "compatibility_level": { "type": "string", "default": "BACKWARD_TRANSITIVE" }, + "schemas_path": { "type": "string", "default": "../../schemas/", "description": "Path to Avro schemas" } + } + }, + { + "id": "M4", + "name": "worm-s3-storage", + "source": "modules/worm-s3-storage", + "description": "WORM S3 buckets with Object Lock, lifecycle tiering, cross-region replication", + "resources": 12, + "providers": ["aws"], + "variables": { + "bucket_name": { "type": "string", "default": "gsifi-compliance-evidence-prod" }, + "retention_days": { "type": "number", "default": 3650, "description": "WORM retention in days (10 years)" }, + "object_lock_mode": { "type": "string", "default": "COMPLIANCE" }, + "kms_key_id": { "type": "string", "description": "KMS key ARN for SSE-KMS encryption" }, + "dr_bucket_arn": { "type": "string", "description": "DR bucket ARN for cross-region replication" }, + "replication_role_arn": { "type": "string", "description": "IAM role ARN for S3 replication" }, + "enable_intelligent_tiering": { "type": "bool", "default": true } + } + }, + { + "id": "M5", + "name": "compliance-engine", + "source": "modules/compliance-engine", + "description": "Compliance engine (Kafka Streams application) ECS/EKS deployment", + "resources": 22, + "providers": ["aws"], + "variables": { + "engine_version": { "type": "string", "default": "2.8.0" }, + "replica_count": { "type": "number", "default": 3 }, + "cpu": { "type": "number", "default": 4096, "description": "CPU units (1024 = 1 vCPU)" }, + "memory": { "type": "number", "default": 8192, "description": "Memory in MB" }, + "kafka_bootstrap_servers": { "type": "string" }, + "opa_url": { "type": "string" }, + "evidence_s3_bucket": { "type": "string" }, + "hsm_key_id": { "type": "string" } + } + }, + { + "id": "M6", + "name": "opa-engine", + "source": "modules/opa-engine", + "description": "OPA cluster (3-node) + policy bundle store + policy deployment", + "resources": 16, + "providers": ["aws"], + "variables": { + "opa_version": { "type": "string", "default": "0.68.0" }, + "node_count": { "type": "number", "default": 3 }, + "bundle_s3_bucket": { "type": "string", "description": "S3 bucket for signed OPA bundles" }, + "bundle_refresh_seconds": { "type": "number", "default": 30 }, + "policy_groups_path": { "type": "string", "default": "../../policies/" } + } + }, + { + "id": "M7", + "name": "monitoring-stack", + "source": "modules/monitoring-stack", + "description": "Prometheus + Grafana + alert rules for governance monitoring", + "resources": 18, + "providers": ["aws", "grafana"], + "variables": { + "prometheus_retention_days": { "type": "number", "default": 90 }, + "grafana_admin_password": { "type": "string", "sensitive": true }, + "alert_pagerduty_key": { "type": "string", "sensitive": true }, + "alert_slack_webhook": { "type": "string", "sensitive": true } + } + }, + { + "id": "M8", + "name": "evidence-signing", + "source": "modules/evidence-signing", + "description": "HSM (CloudHSM/KMS) + Ed25519 signing key management", + "resources": 6, + "providers": ["aws"], + "variables": { + "hsm_cluster_id": { "type": "string", "description": "CloudHSM cluster ID" }, + "key_rotation_days": { "type": "number", "default": 365 }, + "fips_level": { "type": "string", "default": "140-3-level-3" } + } + } + ], + "environments": ["production", "staging", "sandbox"], + "totalResources": 144, + "backendConfig": { + "type": "s3", + "bucket": "gsifi-terraform-state", + "key": "kafka-governance/terraform.tfstate", + "region": "eu-west-1", + "dynamodb_table": "gsifi-terraform-locks", + "encrypt": true + } +} diff --git a/docs/reports/AGI_ASI_GOVERNANCE_ARCHITECTURES_FRAMEWORKS.md b/docs/reports/AGI_ASI_GOVERNANCE_ARCHITECTURES_FRAMEWORKS.md new file mode 100644 index 00000000..c9a17dd9 --- /dev/null +++ b/docs/reports/AGI_ASI_GOVERNANCE_ARCHITECTURES_FRAMEWORKS.md @@ -0,0 +1,902 @@ +AGI/ASI Governance Architectures & Frameworks — Comprehensive Implementation Reference (2026-2030) + + +Document Reference: GAF-GSIFI-WP-017 v1.0.0 | Classification: CONFIDENTIAL — Board / C-Suite / Regulators / Enterprise Architecture / AI Platform Engineering +Date: 2026-04-03 | Companion to: AGMB-GSIFI-WP-016, PMREF-GSIFI-WP-015, UMREF-G2K-WP-014 + +This reference delivers a practitioner-focused, implementation-ready overview of AGI/ASI governance architectures and frameworks spanning seven interconnected domains: (1) multilayered enterprise AI governance pillars, (2) multi-regime regulatory alignment, (3) enterprise AI reference architectures and trust/compliance stacks, (4) global legal and compute governance proposals, (5) sector-specific financial services AI governance, (6) frontier AGI safety and trust-by-design strategies, and (7) the AGI Governance Master Blueprint that unifies enterprise, frontier, and civilizational-scale governance. All seven domains are mapped to machine-readable artifacts (JSON Schema, CSV, OpenAPI 3.1, OPA Rego, implementation templates) suitable for direct engineering and legal use under EU AI Act, NIST AI RMF, ISO/IEC 42001, OECD AI Principles, GDPR, and FCRA/ECOA. + +Key Metrics: 7 governance domains | 6 governance layers | 8 regulatory frameworks | 5 reference architectures | 15 global governance components | 10 AGI safety evolution stages | 336 OPA rules | 1,024 Sentinel rules | 1.8M daily policy evaluations (target 6M by Q4 2028) | EAIP 12,200 RPC/s @ 99.98% reliability | HA-RAG F1 92.1% | $68.4M 5-year investment (NPV $118.6M, IRR 42.3%) | 72 API endpoints | 30/60/90-day rollout + 8-week implementation plan. + + + + +--- + +# AGI/ASI Governance Architectures & Frameworks + +## Document Control + +| Field | Value | +|---|---| +| Document Reference | GAF-GSIFI-WP-017 | +| Version | 1.0.0 | +| Date | 2026-04-03 | +| Classification | CONFIDENTIAL — Board / C-Suite / Regulators / EA / Platform Engineering | +| Authors | AI Governance Architecture Team, Chief Risk Officer, VP AI Governance, Chief Scientist, CISO, General Counsel, Head of Model Risk, Chief AI Officer | +| Supersedes | Consolidation of WP-001 through WP-016 architectural content | +| Audience | C-Suite, Board of Directors, Regulators, Enterprise Architects, AI Platform Engineers, Research Teams, CAIOs, G-SIFI Risk Committees, Financial Supervisors | + +### Companion Documents + +| Ref | Title | Relationship | +|---|---|---| +| AGMB-GSIFI-WP-016 | AGI Governance Master Blueprint | Parent blueprint; this document provides deep-dive architectural detail | +| PMREF-GSIFI-WP-015 | Practitioner Master Reference | Practitioner playbook; this document provides underlying architecture | +| UMREF-G2K-WP-014 | Unified Master Reference | Unified metrics; this document provides framework decomposition | +| GOV-GSIFI-WP-001 | G-SIFI AI Governance Foundation | Foundation layer referenced throughout | +| ARCH-ENT-WP-002 | Enterprise AI Architecture Security | Security architecture deep-dive | +| SAFE-AGI-WP-003 | AGI Readiness & Safety Frameworks | Safety domain source | +| REF-ARCH-WP-004 | Enterprise AI Reference Architectures | Architecture catalog source | +| COMP-REG-WP-006 | G-SIFI Regulatory Compliance | Regulatory mapping source | +| LEGAL-API-WP-007 | Global Legal Registry & API Frameworks | Legal infrastructure source | +| TRAJ-SENT-WP-008 | Trajectory AI Sentinel Governance | Sentinel platform source | +| KARD-WP-009 | Kardashev Energy & Compute Governance | Compute governance source | +| COGRES-WP-010 | Cognitive Resonance & AGI Readiness | Cognitive resonance source | + +--- + +## 1. Executive Summary + +Enterprise and frontier AI systems are converging toward general-purpose capabilities while regulatory landscapes fragment across jurisdictions. This reference provides the definitive architectural guide for organizations that must simultaneously operate production AI systems under current regulation, prepare infrastructure for autonomous agents and early AGI capabilities, and participate in civilizational-scale governance of transformative AI. + +The document synthesizes seven governance domains into a unified, implementation-ready architecture: + +| Domain | Scope | Key Deliverable | +|---|---|---| +| D1: Enterprise Governance Pillars | 6-layer governance architecture | RACI matrices, control catalogs, monitoring topologies | +| D2: Regulatory Alignment | 8 frameworks across 5 jurisdictions | Compliance-as-code (OPA), obligation matrices, audit evidence bundles | +| D3: Reference Architectures | 5 production architectures + trust stacks | Infrastructure-as-code, API contracts, deployment patterns | +| D4: Global Compute Governance | 15 international governance bodies | ICGC charter, compute registry schemas, treaty templates | +| D5: Financial Services | SR 11-7, FCRA/ECOA, credit scoring | Model risk taxonomies, validation frameworks, fair lending tests | +| D6: AGI Safety | 10-stage evolution model, CRP, MVAGS | Crisis simulation runbooks, containment protocols, alignment metrics | +| D7: Master Blueprint | Unified enterprise + frontier + civilizational | 30/60/90-day rollout, 8-week plan, machine-readable artifacts | + +### Key Performance Indicators + +| KPI | Current | Target Q4 2027 | Target 2030 | +|---|---|---|---| +| Regulatory Compliance Score | 89.2% | 96.0% | 99.5% | +| OPA Policy Coverage | 336 rules (12 groups) | 420 rules | 600+ rules | +| Sentinel Rule Base | 1,024 rules (26 AI systems) | 1,400 rules | 2,200+ rules | +| Daily Policy Evaluations | 1.8M (P99 3.8 ms) | 4.2M | 8.0M | +| EAIP Throughput | 12,200 RPC/s (99.98% reliability) | 18,000 RPC/s | 30,000 RPC/s | +| HA-RAG F1 Score | 92.1% | 94.5% | 97.0% | +| AI Risk Score (ARS) | 58.2 | 72.0 | 85.0 | +| Model Bias (Disparate Impact) | >=0.80 | >=0.87 | >=0.93 | +| AGI Readiness Level | ARL-2 | ARL-5 | ARL-7 | +| Mean Incident Response | 12 min | 6 min | 2 min | +| ISO 42001 Certification | In progress | Certified | Re-certified | +| 5-Year Investment | $68.4M | --- | NPV $118.6M, IRR 42.3% | + +--- + +## 2. Domain 1 — Multilayered Enterprise AI Governance Pillars + +### 2.1 Architecture Overview + +The multilayered governance architecture provides six interconnected layers, each with defined accountability, controls, metrics, and regulatory mapping. This architecture is deployed across 26 production AI systems at Fortune 500 and G-SIFI institutions. + +### 2.2 Layer 1: Accountability & Roles + +**Objective:** Establish clear ownership, decision rights, and escalation paths for all AI-related activities. + +| Role | Reports To | Key Responsibilities | Budget | Regulatory Mandate | +|---|---|---|---|---| +| Chief AI Officer (CAIO) | CEO | AI strategy, governance framework ownership, regulatory liaison | $620K / 24 mo | EU AI Act Art. 4(1) | +| Board AI Sub-committee | Board of Directors | Strategic oversight, risk appetite, policy approval | Included in board ops | Corporate governance codes | +| VP AI Governance | CAIO | Policy development, compliance monitoring, audit coordination | $1.8M / yr | ISO/IEC 42001 cl. 5 | +| VP AI Safety | CAIO | Safety testing, alignment verification, crisis response | $1.4M / yr | EU AI Act Art. 9 | +| Chief Risk Officer | CEO | Enterprise risk integration, model risk oversight | Existing CRO budget | SR 11-7, Basel III | +| CISO | CTO | Security architecture, data protection, supply-chain security | Existing CISO budget | GDPR, NIST CSF | +| General Counsel | CEO | Legal compliance, regulatory engagement, contract review | Existing GC budget | Multi-jurisdiction | +| Head of Model Risk | CRO | Model validation independence, backtesting, benchmarking | $980K / yr | SR 11-7 ss. 3-4 | + +**Board AI Sub-committee Composition:** 3 independent directors (with AI/technology expertise) + CAIO + CRO + General Counsel. Meets quarterly (monthly during high-risk deployments). + +**RACI Matrix (Decision Categories):** + +| Decision | CAIO | Board Sub-comm | CRO | CISO | VP AI Gov | GC | +|---|---|---|---|---|---|---| +| High-risk AI deployment approval | A | I | C | C | R | C | +| AI risk appetite setting | C | A | R | C | I | C | +| Regulatory response | R | I | C | I | C | A | +| AI incident escalation (Sev 1-2) | A | I | R | R | C | C | +| Policy-as-code rule changes | I | I | C | C | A | R | +| Third-party AI model onboarding | C | I | R | A | C | C | + +### 2.3 Layer 2: Policy Infrastructure + +**Objective:** Codify governance as executable, version-controlled rules enforced at every stage of the AI lifecycle. + +| Component | Technology | Scale | Performance | +|---|---|---|---| +| Policy Engine | Open Policy Agent (OPA) v0.68 | 336 Rego rules across 12 policy groups | P99 3.8 ms evaluation | +| Rule Engine | Sentinel Platform v4.2 | 1,024 rules across 26 AI systems | 298K evaluations/day | +| Policy Registry | Git-backed OPA bundle server | 12 bundles, auto-deploy on merge | <60s propagation | +| Decision Logging | Kafka WORM + S3 Glacier | 52K decisions/s sustained | 7-year retention | +| Evidence Bundles | Automated compliance evidence | 8 regulatory frameworks | Quarterly generation | + +**OPA Policy Groups (12):** + +| Group | Rules | Scope | Example Rule | +|---|---|---|---| +| PG-01: EU AI Act Classification | 42 | Risk classification, prohibited practices | `deny if ai_system.risk_level == "unacceptable"` | +| PG-02: NIST AI RMF Mapping | 38 | GOVERN, MAP, MEASURE, MANAGE functions | `require if not nist_function_documented(system)` | +| PG-03: ISO 42001 Controls | 32 | AIMS clause compliance | `deny if missing_control(clause_id)` | +| PG-04: Data Governance | 34 | PII detection, consent, lineage | `deny if pii_detected and not consent_recorded` | +| PG-05: Model Validation | 28 | SR 11-7 requirements, backtesting | `deny if model.validation_age > 365` | +| PG-06: Bias & Fairness | 26 | DI testing, FCRA/ECOA compliance | `deny if disparate_impact < 0.80` | +| PG-07: Autonomous Agent | 30 | DEPTHS classification, kill-switch | `deny if agent.depth_level > 3 and not board_approved` | +| PG-08: Security & Privacy | 28 | GDPR Art. 17/22, encryption, DLP | `deny if encryption_at_rest != "AES-256"` | +| PG-09: Supply Chain | 22 | Third-party model provenance | `deny if model.provenance_chain missing` | +| PG-10: Monitoring & Observability | 20 | SLO compliance, drift detection | `warn if performance_drift > 5%` | +| PG-11: Incident Response | 18 | Escalation, containment, reporting | `alert if incident.severity <= 2` | +| PG-12: AGI Preparedness | 18 | ARL requirements, GASCF compliance | `deny if agi_system and not gascf_certified` | + +### 2.4 Layer 3: Risk Management + +**Objective:** Continuous risk scoring and mitigation across a 14-dimension taxonomy. + +**Risk Taxonomy (14 Dimensions):** + +| Dim | Category | Weight | Current Score | Target 2027 | Owner | +|---|---|---|---|---|---| +| RD-01 | Model Performance Degradation | 0.10 | 72.4 | 82.0 | Head Model Risk | +| RD-02 | Adversarial Attack Surface | 0.09 | 64.8 | 78.0 | CISO | +| RD-03 | Data Quality & Completeness | 0.09 | 78.2 | 88.0 | CDO | +| RD-04 | Bias & Fairness | 0.09 | 68.4 | 82.0 | CRO | +| RD-05 | Regulatory Non-compliance | 0.09 | 82.6 | 94.0 | General Counsel | +| RD-06 | Privacy & Data Protection | 0.08 | 86.4 | 95.0 | DPO | +| RD-07 | Operational Resilience | 0.08 | 74.2 | 85.0 | CTO | +| RD-08 | Supply-chain & Third-party | 0.07 | 62.8 | 76.0 | CISO | +| RD-09 | Explainability Deficit | 0.07 | 56.4 | 72.0 | VP AI Gov | +| RD-10 | Human-AI Interaction | 0.06 | 71.8 | 80.0 | VP AI Safety | +| RD-11 | Autonomous Agent Risk | 0.06 | 48.2 | 68.0 | VP AI Safety | +| RD-12 | Concentration Risk | 0.05 | 58.6 | 74.0 | CRO | +| RD-13 | Reputational Impact | 0.04 | 66.4 | 78.0 | CCO | +| RD-14 | AGI/ASI Emergence | 0.03 | 32.8 | 55.0 | CAIO | + +**Weighted AI Risk Score (ARS):** Current = 58.2 (scale 0-100, higher = less risky). Target = 72.0 by Q4 2027, 85.0 by 2030. + +**ARS Calculation:** ARS = SUM(dimension_weight * dimension_score) for all 14 dimensions. + +### 2.5 Layer 4: AI-Ready Data Infrastructure + +**Objective:** Ensure data quality, lineage, privacy, and governance at scale. + +| Component | Technology | Metric | Target | +|---|---|---|---| +| Data Quality Gates | Great Expectations + custom validators | Quality score >= 0.87 | >= 0.93 | +| PII Detection | Microsoft Presidio + custom NER | Detection rate 99.72% | 99.95% | +| Data Lineage | Apache Atlas + OpenLineage | Coverage 98.8% of datasets | 99.9% | +| Consent Management | OneTrust + custom API | Consent accuracy 99.4% | 99.9% | +| Synthetic Data | Gretel.ai + internal generators | Utility preservation 94.2% | 96.0% | +| Data Catalog | Apache Atlas + custom metadata | 14,800 datasets cataloged | 20,000+ | +| Erasure Pipeline | GDPR Art. 17 automated pipeline | Erasure SLA < 72h | < 24h | +| Encryption | AES-256-GCM at rest, TLS 1.3 in transit | 100% coverage | 100% | + +### 2.6 Layer 5: Development & Deployment Governance + +**Objective:** Enforce governance gates at every stage of the AI development lifecycle. + +**7-Stage LLMOps Pipeline:** + +| Stage | Gate | Automated Checks | Pass Criteria | +|---|---|---|---| +| S1: Data Ingestion | Data Quality Gate | Schema validation, PII scan, lineage check | Quality >= 0.87, PII masked | +| S2: Training | Training Governance Gate | Compute budget, data consent, IP check | Budget approved, consent verified | +| S3: Evaluation | Model Evaluation Gate | Performance benchmarks, bias testing | Accuracy target met, DI >= 0.80 | +| S4: Validation | Independent Validation Gate | SR 11-7 review, backtesting, stress testing | Validation report signed | +| S5: Staging | Pre-deployment Gate | OPA policy check (336 rules), security scan | All 336 rules pass | +| S6: Production | Deployment Gate | Canary analysis, rollback readiness, monitoring | Canary metrics within 2-sigma | +| S7: Monitoring | Continuous Governance | Drift detection, SLO monitoring, audit logging | SLOs met, no critical drift | + +### 2.7 Layer 6: Monitoring & Observability + +**Objective:** Continuous, real-time monitoring of AI system behavior, compliance, and performance. + +| Component | Technology | Scale | SLO | +|---|---|---|---| +| Metrics Collection | OpenTelemetry SDK + Prometheus | 48 AI metrics per system | < 30s collection interval | +| Distributed Tracing | OpenTelemetry + Jaeger | Full request tracing across EAIP mesh | P99 trace latency < 100ms | +| Log Aggregation | Fluentd + Elasticsearch | 2.4M log events/day | Retention: 90d hot, 7yr cold | +| Decision Logging | Kafka WORM (immutable) | 52K decisions/s sustained | WORM guarantee, 7yr retention | +| Alerting | PagerDuty + custom escalation | Sev 1: < 5min page, Sev 2: < 15min | 99.8% alert delivery | +| Dashboard | Grafana + custom React panels | 12 real-time dashboards | < 2s refresh | +| Drift Detection | Evidently AI + custom detectors | Statistical + concept drift | Detection within 15 min | +| Compliance Reporting | Custom report generator | Quarterly compliance reports | Auto-generated | + +--- + +## 3. Domain 2 — Multi-Regime Regulatory Alignment + +### 3.1 Framework Coverage Matrix + +| Framework | Jurisdiction | Effective Date | AI Risk Focus | OPA Rules | Status | +|---|---|---|---|---|---| +| EU AI Act | EU/EEA (27 MS) | Aug 2025 (prohibited), Aug 2026 (high-risk) | Risk-based classification | 42 | Active | +| NIST AI RMF 1.0 | United States | Jan 2023 | GOVERN, MAP, MEASURE, MANAGE | 38 | Active | +| ISO/IEC 42001:2023 | International | Dec 2023 | AI Management System (AIMS) | 32 | Certifying | +| OECD AI Principles | 46 countries | May 2019 (updated 2024) | Values-based, interoperability | 14 | Active | +| GDPR | EU/EEA + UK | May 2018 | Data protection, automated decisions | 28 | Active | +| FCRA / ECOA | United States | 1970 / 1974 (updated) | Fair credit, equal opportunity | 26 | Active | +| SR 11-7 (OCC/Fed) | United States | Apr 2011 | Model risk management | 28 | Active | +| UK AI Safety Institute Code | United Kingdom | Mar 2025 | Frontier model evaluation | 12 | Active | +| **Total** | **5 jurisdictions** | --- | --- | **220 (core) + 116 (extended) = 336** | --- | + +### 3.2 EU AI Act Implementation Architecture + +**Risk Classification Engine:** + +| Risk Level | Classification | OPA Rule Group | Governance Requirement | +|---|---|---|---| +| Unacceptable | Social scoring, real-time biometric (exceptions), manipulation | PG-01 rules 1-8 | Prohibited; immediate decommission | +| High-Risk | Credit scoring, HR screening, medical diagnosis, critical infrastructure | PG-01 rules 9-30 | Conformity assessment, CE marking, post-market surveillance | +| Limited | Chatbots, deepfake generators, emotion recognition | PG-01 rules 31-38 | Transparency obligations | +| Minimal | Spam filters, recommendation engines, game AI | PG-01 rules 39-42 | Voluntary codes of conduct | + +**EU AI Act Compliance Timeline:** + +| Date | Obligation | Implementation Status | Owner | +|---|---|---|---| +| Feb 2025 | AI literacy requirements (Art. 4) | Completed | VP AI Gov | +| Aug 2025 | Prohibited practices ban (Art. 5) | Completed; 3 systems decommissioned | CAIO | +| Aug 2026 | High-risk system requirements (Annex III) | In progress; 14/22 systems compliant | VP AI Gov | +| Aug 2026 | Notified body conformity assessments | Scheduled Q2 2026 | General Counsel | +| Aug 2027 | General-purpose AI model obligations | Architecture planned | CTO | +| Ongoing | Post-market surveillance (Art. 72) | Sentinel continuous monitoring | VP AI Gov | + +### 3.3 NIST AI RMF Mapping + +| NIST Function | Sub-functions | OPA Rules | Implementation | +|---|---|---|---| +| GOVERN | Policies, roles, culture, stakeholders | 12 | Board AI Sub-committee, CAIO role, policy framework | +| MAP | Context, categorize, AI actors, technical | 10 | AI system inventory, risk classification engine | +| MEASURE | Identify, assess, prioritize, track | 8 | ARS scoring (14-dim), Sentinel rules, drift detection | +| MANAGE | Response, recovery, communication | 8 | Incident playbooks, kill-switch, audit trails | + +### 3.4 ISO/IEC 42001 AIMS Roadmap + +| Phase | Clause | Activities | Timeline | Status | +|---|---|---|---|---| +| 1: Context | cl. 4 | Organization context, interested parties, AIMS scope | Q1 2026 | Completed | +| 2: Leadership | cl. 5 | AI policy, roles, management commitment | Q1 2026 | Completed | +| 3: Planning | cl. 6 | Risk assessment, AI objectives, change planning | Q2 2026 | In progress | +| 4: Support | cl. 7 | Resources, competence, awareness, communication | Q2 2026 | In progress | +| 5: Operation | cl. 8 | AI system lifecycle, risk treatment, third-party | Q3 2026 | Planned | +| 6: Performance | cl. 9 | Monitoring, internal audit, management review | Q4 2026 | Planned | +| 7: Improvement | cl. 10 | Nonconformity, corrective action, continual improvement | Q1 2027 | Planned | +| 8: Certification | --- | Stage 1 + Stage 2 audit by accredited body | Q2 2027 | Planned | + +### 3.5 Cross-Regime Obligation Mapping + +| Obligation | EU AI Act | NIST AI RMF | ISO 42001 | GDPR | SR 11-7 | +|---|---|---|---|---|---| +| AI System Inventory | Art. 6-9 | MAP-1.1 | cl. 6.1 | Art. 30 | ss. 3 | +| Risk Assessment | Art. 9 | MEASURE-2 | cl. 6.1.2 | Art. 35 | ss. 5-6 | +| Data Governance | Art. 10 | MAP-2.3 | Annex B.4 | Art. 5, 25 | ss. 6 | +| Transparency | Art. 13, 52 | GOVERN-4 | cl. 7.4 | Art. 13-14 | ss. 7 | +| Human Oversight | Art. 14 | GOVERN-3 | cl. 8.4 | Art. 22 | ss. 10 | +| Bias Testing | Art. 10(2)(f) | MEASURE-2.6 | Annex B.7 | Art. 22(3) | FCRA/ECOA | +| Incident Reporting | Art. 62 | MANAGE-4 | cl. 10.1 | Art. 33-34 | ss. 10 | +| Audit Trail | Art. 12 | GOVERN-1.5 | cl. 9.2 | Art. 30 | ss. 7 | +| Model Documentation | Art. 11 | MAP-3 | cl. 8.2 | DPIA | ss. 7 | +| Post-market Monitoring | Art. 72 | MANAGE-3 | cl. 9.1 | Art. 35 | ss. 10 | + +--- + +## 4. Domain 3 — Enterprise AI Reference Architectures & Trust Stacks + +### 4.1 Reference Architecture Catalog + +**ARCH-1: Enterprise AI Platform (EAIP) Mesh** + +| Component | Technology | Function | Scale | +|---|---|---|---| +| Service Mesh | gRPC + Envoy + Istio | Secure inter-service communication | 12,200 RPC/s | +| Identity | SPIFFE/SPIRE | Workload identity, mTLS | 26 AI systems | +| API Gateway | Kong + custom plugins | Rate limiting, auth, policy check | 48,000 req/s | +| Policy Sidecar | OPA Envoy Plugin | Inline policy evaluation | P99 3.8 ms | +| Observability | OpenTelemetry + Jaeger + Prometheus | Distributed tracing, metrics | Full mesh coverage | +| Secret Management | HashiCorp Vault | Secrets, certificates, rotation | Auto-rotation 90d | +| Config Management | etcd + OPA bundles | Distributed config, policy sync | < 60s propagation | + +**ARCH-2: Sentinel Governance Platform** + +| Component | Technology | Function | Scale | +|---|---|---|---| +| Rule Engine | Sentinel Core v4.2 | Real-time rule evaluation | 298K evals/day | +| Rule Store | PostgreSQL + Redis | Rule storage, caching | 1,024 active rules | +| Event Bus | Apache Kafka (WORM) | Immutable event streaming | 52K events/s | +| Analytics | Apache Flink + custom | Real-time risk analytics | 1.8M events/day | +| Dashboard | React + Grafana | Real-time governance dashboard | 12 dashboards | +| Integration | REST + gRPC + Kafka | Multi-protocol integration | 45 integrations | +| ML Anomaly | Isolation Forest + LSTM | Behavioral anomaly detection | < 200ms detection | + +**ARCH-3: HA-RAG (High-Availability Retrieval-Augmented Generation)** + +| Component | Technology | Function | Scale | +|---|---|---|---| +| Vector Store | Qdrant (clustered) | Document embeddings | 2.8M vectors | +| Embeddings | text-embedding-3-large | Document + query encoding | 768 dim | +| Reranker | cross-encoder/ms-marco | Passage reranking | Top-20 -> Top-5 | +| LLM Backbone | GPT-4o + Claude 3.5 (failover) | Generation | 52,400 queries/week | +| Provenance | Merkle hash + 4-layer audit | Source + confidence tracking | Art. 52 compliant | +| Cache | Redis + semantic dedup | Response caching | 34% hit rate | +| Governance | OPA inline check | Query-level policy enforcement | Every query | + +**ARCH-4: WorkflowAI Pro** + +| Component | Technology | Function | Scale | +|---|---|---|---| +| Orchestrator | Temporal.io | Workflow orchestration | 14K workflows/day | +| Agent Runtime | Custom Python + LangGraph | Agent execution | L0-L4 agents | +| Governance Sidecar | OPA + behavioral monitor | Real-time governance | Per-workflow | +| Human-in-Loop | Custom React UI | Approval + override | Configurable per DEPTHS level | +| Audit | Kafka + S3 | Complete workflow audit trail | 7-year retention | +| Kill-switch | Hardware + software redundant | Emergency termination | 50-280 ms latency | + +**ARCH-5: CCaaS AI (Contact Center as a Service)** + +| Component | Technology | Function | Scale | +|---|---|---|---| +| Speech-to-Text | Whisper v3 + custom fine-tune | Real-time transcription | 2,400 concurrent | +| NLU | Custom BERT + intent classifier | Intent + entity extraction | 340 intents | +| Dialog Manager | Rasa + custom FSM | Conversation management | Multi-turn | +| Sentiment | Custom sentiment model | Real-time sentiment scoring | Per-utterance | +| Compliance | OPA real-time + recording | FCRA/TCPA compliance | 100% calls | +| Quality | Custom quality scorer | Agent quality scoring | Real-time | + +### 4.2 Trust & Compliance Stack + +The trust stack is a cross-cutting concern layered across all five reference architectures. + +| Layer | Function | Technology | Metric | +|---|---|---|---| +| L1: Identity & Access | Workload + human identity | SPIFFE/SPIRE + Okta + RBAC | Zero-trust verified | +| L2: Policy Enforcement | Real-time policy decisions | OPA (336 rules) + Sentinel (1,024 rules) | P99 3.8 ms | +| L3: Cryptographic Assurance | Data protection + integrity | AES-256-GCM, TLS 1.3, Merkle trees | 100% coverage | +| L4: Audit & Evidence | Immutable decision logs | Kafka WORM + S3 Glacier + evidence bundles | 7-year retention | +| L5: Risk Analytics | Continuous risk scoring | ARS engine (14-dim) + anomaly detection | Real-time scoring | +| L6: Compliance Reporting | Automated regulatory reports | Custom generators + templates | 8 frameworks | +| L7: Model Registry | Model lifecycle governance | MLflow + custom metadata + provenance | 100% tracked | + +**Model Registry Architecture:** + +| Component | Technology | Function | +|---|---|---| +| Version Control | MLflow + DVC | Model versioning, experiment tracking | +| Metadata Store | PostgreSQL + custom schema | Model cards, risk classifications, validation status | +| Artifact Store | S3 + cryptographic signing | Model binaries, training data references | +| Provenance Chain | Merkle tree + blockchain anchor | Immutable model provenance trail | +| Validation Status | Custom state machine | Draft -> Validated -> Approved -> Production -> Deprecated | +| Access Control | SPIFFE + RBAC | Role-based model access | +| Monitoring Integration | OpenTelemetry hooks | Performance + drift signals | + +### 4.3 CI/CD Governance Gates + +| Gate | Stage | Automated Checks | Block Criteria | +|---|---|---|---| +| G1: Code Review | PR merge | Static analysis, security scan, license check | Critical vuln, license violation | +| G2: Data Validation | Pre-training | Schema, PII, consent, quality score | Quality < 0.87, PII unmasked | +| G3: Training Governance | Training start | Budget approval, compute allocation, IP check | Budget exceeded, IP conflict | +| G4: Evaluation | Post-training | Benchmark suite, bias test (DI), regression | DI < 0.80, regression detected | +| G5: Validation | Pre-staging | SR 11-7 review, stress test, documentation | Validation not signed | +| G6: OPA Policy Check | Pre-deploy | Full 336-rule evaluation | Any deny rule triggered | +| G7: Canary Analysis | Production entry | Traffic analysis, error rate, latency | Metrics outside 2-sigma | +| G8: Continuous Compliance | Ongoing | Drift, SLO, regulatory changes | SLO breach, new regulation | + +--- + +## 5. Domain 4 — Global Legal & Compute Governance + +### 5.1 International Compute Governance Consortium (ICGC) + +**Mission:** Establish a multilateral framework for governing compute resources used in frontier AI development, ensuring equitable access, safety compliance, and international coordination. + +**ICGC Governance Structure:** + +| Body | Function | Composition | Meeting Cadence | +|---|---|---|---| +| Assembly | Strategic direction, treaty ratification | All member states (1 vote each) | Annual | +| Steering Council | Operational governance, budget | 15 rotating members | Quarterly | +| Technical Bureau | Standards, protocols, auditing | 50 technical experts | Monthly | +| Secretariat | Administration, coordination | Permanent staff (est. 200) | Continuous | +| Dispute Resolution | Arbitration, sanctions | 7 judicial members | As needed | + +### 5.2 Global Governance Components (15) + +| ID | Acronym | Full Name | Function | Status | +|---|---|---|---|---| +| GC-01 | GACRA | Global AI Compute Resource Authority | Compute allocation, licensing, monitoring | Proposed | +| GC-02 | GASO | Global AI Safety Office | Safety standards, incident coordination | Pilot (EU + US) | +| GC-03 | GFMCF | Global Frontier Model Certification Framework | Pre-deployment certification for frontier models | Draft | +| GC-04 | GAICS | Global AI Incident Classification System | Standardized incident severity and reporting | Draft | +| GC-05 | GAIVS | Global AI Incident Verification System | Independent incident investigation | Proposed | +| GC-06 | GACP | Global AI Compute Passport | Portable compute usage credentials | Proposed | +| GC-07 | GATI | Global AI Treaty Infrastructure | Treaty management, compliance tracking | Concept | +| GC-08 | GACMO | Global AI Capability Monitoring Observatory | Track frontier capabilities worldwide | Pilot (3 countries) | +| GC-09 | FTEWS | Frontier Technology Early Warning System | Capability jump detection, risk alerts | Prototype | +| GC-10 | GAI-SOC | Global AI Security Operations Center | 24/7 AI threat monitoring and response | Pilot | +| GC-11 | GAIGA | Global AI Governance Assembly | Legislative body for international AI law | Proposed | +| GC-12 | GACRLS | Global AI Compute Resource Licensing System | Compute license issuance and compliance | Draft | +| GC-13 | GFCO | Global Frontier Compute Observatory | Monitor global compute build-out and allocation | Concept | +| GC-14 | GAID | Global AI Insurance and Indemnification | Risk pooling, liability frameworks | Concept | +| GC-15 | GASCF | Global AI Safety Certification Framework | Multi-tier safety certification (Levels 1-5) | Draft | + +### 5.3 Global Compute Registry + +**Registry Schema (Machine-Readable):** + +| Field | Type | Description | Required | +|---|---|---|---| +| facility_id | UUID | Unique facility identifier | Yes | +| operator | string | Operating entity | Yes | +| jurisdiction | ISO 3166-1 | Primary jurisdiction | Yes | +| total_flops | float | Peak FP16 FLOPS capacity | Yes | +| gpu_type | enum | Hardware type (H100, B200, etc.) | Yes | +| gpu_count | integer | Total GPU count | Yes | +| interconnect | string | Network topology | Yes | +| power_mw | float | Power consumption (MW) | Yes | +| pue | float | Power Usage Effectiveness | Yes | +| ai_training_pct | float | Percentage used for AI training | Yes | +| frontier_model_training | boolean | Used for frontier model training | Yes | +| safety_cert_level | enum | GASCF certification level (1-5) | Yes | +| last_audit_date | date | Last compliance audit | Yes | +| reporting_cadence | enum | Reporting frequency | Yes | + +### 5.4 Sentinel Global Integration + +The Sentinel Platform provides the enforcement layer for global governance: + +| Integration Point | Protocol | Function | Latency | +|---|---|---|---| +| GACRA Registration | REST + mTLS | Compute facility registration and updates | < 500ms | +| GAICS Event Reporting | Kafka + gRPC | Real-time incident event forwarding | < 200ms | +| GASCF Certification Check | OPA + REST | Pre-deployment certification validation | < 50ms | +| GACMO Capability Report | Batch + streaming | Capability metrics and model registry data | 15-min batch | +| FTEWS Alert Integration | WebSocket + gRPC | Bidirectional alert exchange | < 100ms | +| GAI-SOC Threat Intel | STIX/TAXII + REST | Threat intelligence sharing | Near real-time | + +--- + +## 6. Domain 5 — Financial Services AI Governance + +### 6.1 Financial Services AI Risk Management Framework + +**Regulatory Stack:** + +| Regulation | Scope | AI Impact | Key Obligations | +|---|---|---|---| +| SR 11-7 (OCC/Fed) | Model risk management | All AI/ML models in banking | Independent validation, documentation, ongoing monitoring | +| FCRA | Consumer credit reporting | Credit scoring AI models | Adverse action notices, dispute resolution, accuracy | +| ECOA (Reg B) | Equal credit opportunity | Any credit decision AI | Prohibited bases, disparate impact testing, HMDA reporting | +| EU AI Act | High-risk AI systems | Credit scoring = Annex III | Conformity assessment, post-market surveillance | +| GDPR Art. 22 | Automated decision-making | All automated credit decisions | Right to explanation, human review, profiling safeguards | +| Basel III/IV | Capital adequacy | Risk model governance | Pillar 2 supervisory review, model risk capital charges | + +### 6.2 SR 11-7 Model Risk Management Framework + +| Phase | SR 11-7 Section | Key Activities | Automated Controls | +|---|---|---|---| +| 1: Model Development | ss. 5-6 | Conceptual soundness, data quality, assumptions | OPA PG-05 rules 1-10 | +| 2: Model Validation | ss. 4, 8 | Independent review, benchmarking, backtesting | OPA PG-05 rules 11-18 | +| 3: Model Documentation | ss. 7 | Model cards, technical docs, limitations | Auto-generated templates | +| 4: Ongoing Monitoring | ss. 10 | Performance tracking, outcomes analysis | Sentinel rules FS-001 to FS-120 | +| 5: Vendor Model Risk | ss. 12 | Third-party model assessment, access rights | OPA PG-09 + vendor scorecards | +| 6: Governance | ss. 3 | Board oversight, independent reporting, escalation | Quarterly reports | + +### 6.3 Credit Scoring AI Governance + +**Fair Lending Compliance Architecture:** + +| Component | Function | Technology | Metric | +|---|---|---|---| +| Disparate Impact Testing | Test for prohibited basis disparities | Fairlearn + custom | DI >= 0.80 (target >= 0.87) | +| Adverse Action Engine | Generate FCRA-compliant adverse action reasons | Custom rule engine | 100% of denials | +| HMDA Reporting | Home Mortgage Disclosure Act data | Automated pipeline | Quarterly filing | +| Model Documentation | SR 11-7 compliant model cards | Template + auto-gen | Updated per model change | +| Explainability | Individual decision explanations | SHAP + LIME + counterfactuals | Per-decision | +| Backtesting | Ongoing model performance validation | Custom backtesting suite | Monthly | +| Override Logging | Human override documentation | Audit trail + justification | 100% of overrides | +| Synthetic Data | Fair lending scenario testing | Gretel.ai + custom | Quarterly stress tests | + +**Disparate Impact Test Matrix:** + +| Protected Class | Test Metric | Threshold | Current | Status | +|---|---|---|---|---| +| Race/Ethnicity | Approval rate ratio | >= 0.80 | 0.84 | Pass | +| Sex/Gender | Approval rate ratio | >= 0.80 | 0.88 | Pass | +| Age | Approval rate ratio | >= 0.80 | 0.82 | Pass | +| National Origin | Approval rate ratio | >= 0.80 | 0.86 | Pass | +| Marital Status | Approval rate ratio | >= 0.80 | 0.91 | Pass | +| Religion | Approval rate ratio | >= 0.80 | 0.94 | Pass | + +### 6.4 Enterprise AI Readiness Level (EARL) for Financial Services + +| Level | Name | Description | Key Milestones | Investment | +|---|---|---|---|---| +| EARL-1 | Initial | Ad-hoc AI usage, minimal governance | AI inventory started, awareness training | $0.8M | +| EARL-2 | Developing | Formal policies emerging, partial monitoring | Risk classification, OPA pilot (50 rules) | $2.4M | +| EARL-3 | Defined | Comprehensive governance framework operational | Full OPA deployment, Sentinel pilot, SR 11-7 compliance | $6.8M | +| EARL-4 | Managed | Quantitative governance, continuous monitoring | Full Sentinel, EAIP mesh, automated compliance | $14.2M | +| EARL-5 | Optimizing | Predictive governance, AGI-ready infrastructure | GASCF certification, crisis-tested, CRP operational | $28.6M | + +**Current EARL:** 3 (Defined) | **Target:** EARL-4 by Q4 2027 | **G-SIFI Premium:** $2.12M/yr additional governance spend + +--- + +## 7. Domain 6 — Frontier AGI Safety & Trust-by-Design + +### 7.1 AI Evolution Model (10 Stages) + +| Stage | Name | Capability | Governance Regime | Timeline | ARL | +|---|---|---|---|---|---| +| S1 | Rule-based Systems | Deterministic logic | Standard IT governance | Pre-2020 | --- | +| S2 | Statistical ML | Pattern recognition | Model validation (SR 11-7) | 2015-2022 | ARL-1 | +| S3 | Deep Learning | Representation learning | Bias testing, explainability | 2018-2024 | ARL-1 | +| S4 | Foundation Models | General language/vision/code | EU AI Act, comprehensive | 2022-2026 | ARL-2 | +| S5 | Agentic AI | Autonomous task execution | Agent governance, kill-switch | 2024-2027 | ARL-3 | +| S6 | Multi-agent Systems | Coordinated agent networks | EAIP, swarm governance | 2025-2028 | ARL-4 | +| S7 | Narrow AGI | Human-level in specific domains | GASCF Level 3, containment | 2027-2029 | ARL-5 | +| S8 | Broad AGI | Human-level across domains | GASCF Level 4, international | 2028-2030 | ARL-6 | +| S9 | Transformative AGI | Superhuman in most domains | GASCF Level 5, ICGC | 2029-2031 | ARL-6 | +| S10 | ASI | Superintelligent capabilities | Civilizational, GATI treaties | 2030+ | ARL-7 | + +### 7.2 Cognitive Resonance Protocol (CRP) v2.1 + +**Objective:** Ensure sustained alignment between AI system behavior and organizational values, human well-being, and societal norms. + +| Component | Function | Implementation | Metric | +|---|---|---|---| +| Value Alignment Engine | Map AI decisions to organizational values | Constitutional AI + RLHF + custom rubrics | Alignment score 83.8% | +| Resonance Monitoring | Detect alignment drift in real-time | Embedding similarity tracking + threshold alerts | Drift detection < 12 min | +| Human-AI Feedback Loop | Structured bidirectional communication | Review interfaces, escalation protocols | Override acceptance 97.6% | +| Cultural Calibration | Adapt AI behavior to organizational culture | Fine-tuning on organizational corpus | Calibration score 80.2% | +| Ethical Boundary Enforcement | Hard constraints on AI behavior | OPA policies + runtime enforcement | 100% enforcement | +| Cognitive Load Balancing | Optimize human-AI task allocation | Workload analytics, decision complexity scoring | Load balance efficiency 88.4% | +| Societal Impact Assessment | Evaluate broader societal implications | Impact frameworks + external review | Quarterly assessment | +| Multi-stakeholder Input | Integrate diverse stakeholder values | Structured engagement + value surveys | Annual update | + +### 7.3 Crisis Simulation Program + +| ID | Scenario | Participants | Duration | Frequency | Last Run | Outcome | +|---|---|---|---|---|---|---| +| SIM-01 | High-risk AI system failure in production | IT + AI Gov + CRO | 4h | Quarterly | Q1 2026 | 3 improvements identified | +| SIM-02 | Autonomous agent exceeds authorized scope | AI Safety + Legal + Board | 6h | Semi-annual | Q4 2025 | Kill-switch validated | +| SIM-03 | AI-generated content causes reputational crisis | PR + Legal + CAIO | 3h | Quarterly | Q1 2026 | Comms plan updated | +| SIM-04 | Regulatory enforcement action (EU AI Act) | Legal + Compliance + Board | 4h | Semi-annual | Q4 2025 | Response plan documented | +| SIM-05 | AGI capability emergence (tabletop) | Board + CAIO + VP Safety + External | 8h | Annual | Q1 2026 | Containment protocol v2 | +| SIM-06 | Multi-agent coordination failure | Platform Eng + AI Safety | 4h | Semi-annual | Q1 2026 | EAIP failover improved | +| SIM-07 | Supply-chain compromise (model poisoning) | CISO + AI Safety + Vendor Mgmt | 6h | Annual | Q4 2025 | Provenance chain hardened | +| SIM-08 | Simultaneous multi-jurisdiction regulatory action | Legal + GC + Board + Regional | 8h | Annual | Q1 2026 | Multi-regime playbook v1 | + +### 7.4 Minimum Viable AI Governance Stack (MVAGS) + +**Objective:** Provide the smallest viable governance stack that meets basic regulatory requirements, deployable in 48 hours at < $3,000/month. + +| Component | Tool | Setup Hours | Monthly Cost | Regulatory Coverage | +|---|---|---|---|---| +| AI System Inventory | Spreadsheet + REST API | 4 | $0 | EU AI Act Art. 6, NIST MAP-1 | +| Risk Classification | OPA (12 core rules) | 8 | $200 | EU AI Act Art. 6-9, NIST MAP-2 | +| Policy Engine | OPA Community Edition | 4 | $0 | Multi-framework | +| Monitoring | Prometheus + Grafana OSS | 8 | $400 | EU AI Act Art. 72, NIST MANAGE | +| Audit Trail | Kafka + S3 (min config) | 12 | $800 | EU AI Act Art. 12, GDPR Art. 30 | +| Dashboard | Grafana + custom panels | 8 | $200 | Transparency | +| Incident Response | PagerDuty Free + runbooks | 4 | $0 | EU AI Act Art. 62, NIST MANAGE | +| Cloud Infrastructure | AWS/GCP/Azure | 0 | $800 | N/A | +| **Total** | --- | **48 hours** | **$2,400/mo** | **Core compliance** | + +### 7.5 Trust-by-Design Principles + +| Principle | Implementation | Verification Method | +|---|---|---| +| TD-01: Value alignment by default | Constitutional AI + organizational value embedding | CRP alignment score >= 80% | +| TD-02: Minimal authority | Least-privilege compute and data access | SPIFFE scope audit | +| TD-03: Transparent reasoning | Explainability at every decision point | SHAP/LIME coverage 100% | +| TD-04: Human agency preservation | Meaningful human control at all DEPTHS levels | Override success rate tracking | +| TD-05: Reversibility | All AI actions reversible within defined window | Rollback test quarterly | +| TD-06: Privacy by design | Data minimization, PII protection, consent | GDPR Art. 25 compliance | +| TD-07: Robustness under adversarial conditions | Red team testing, adversarial validation | Quarterly adversarial audit | +| TD-08: Societal benefit alignment | Broader impact assessment, stakeholder engagement | Annual societal review | +| TD-09: Containment readiness | Scalable containment from L0 to L5 agents | Kill-switch test quarterly | +| TD-10: Graceful degradation | Defined fallback behavior under uncertainty | Chaos engineering monthly | + +--- + +## 8. Domain 7 — AGI Governance Master Blueprint (Unified) + +### 8.1 Blueprint Architecture + +The Master Blueprint unifies enterprise, frontier, and civilizational-scale governance into a single coherent architecture with defined interfaces between scales. + +**Three-Scale Integration:** + +| Scale | Scope | Primary Governance | Interface | +|---|---|---|---| +| Enterprise | Day-to-day AI operations | 6-layer governance + 336 OPA rules | EAIP Mesh API | +| Frontier | AGI safety + trust-by-design | CRP + GASCF + crisis simulations | Sentinel Platform | +| Civilizational | International compute + incidents | ICGC + 15 global components | GACRA/GASO APIs | + +### 8.2 Sentinel Platform Architecture (Production) + +| Component | Technology | Version | Scale | SLA | +|---|---|---|---|---| +| Sentinel Core | Custom Go + Rust | v4.2 | 298K evals/day | 99.97% uptime | +| Rule Engine | CEL + custom DSL | v3.8 | 1,024 rules | P99 4.1 ms | +| Event Processor | Apache Kafka | 3.7 | 52K events/s | Zero message loss | +| Analytics Engine | Apache Flink | 1.18 | 1.8M events/day | < 5s window | +| State Store | PostgreSQL + Redis | 16 + 7.2 | 100M+ records | Multi-AZ | +| ML Pipeline | PyTorch + ONNX Runtime | 2.3 + 1.17 | 12 models | GPU-accelerated | +| API Layer | gRPC + REST | --- | 12,200 RPC/s | P99 8.2 ms | +| Dashboard | React + D3.js + Grafana | --- | 12 dashboards | < 2s refresh | + +### 8.3 AGI Readiness Layers + +| Level | Name | Requirements | Investment | Timeline | +|---|---|---|---|---| +| ARL-1 | Foundation | AI inventory, basic policies, risk awareness training | $1.4M | Month 1-3 | +| ARL-2 | Structured | Formal governance framework, OPA policies (50+ rules), basic monitoring | $4.2M | Month 3-9 | +| ARL-3 | Managed | Full Sentinel deployment, continuous monitoring, SR 11-7 compliance | $9.8M | Month 9-18 | +| ARL-4 | Advanced | EAIP mesh operational, autonomous agent governance, EARL-4 | $14.8M | Month 18-30 | +| ARL-5 | AGI-Ready | GASCF certified, crisis-tested, CRP operational, multi-regime compliant | $18.6M | Month 30-42 | +| ARL-6 | AGI-Operational | AGI systems in production with full containment, ICGC integration | $26.4M | Month 42-54 | +| ARL-7 | ASI-Prepared | Civilizational governance, GATI treaty compliance, global coordination | $42.8M | Month 54+ | + +### 8.4 Global Compute & Incident Governance + +| Component | Function | Integration | Status | +|---|---|---|---| +| GACRA | Compute allocation and licensing | Sentinel -> GACRA registry | Proposed | +| GASO | Safety standards coordination | Sentinel -> GASO reporting | Pilot | +| GFMCF | Frontier model pre-deployment cert | OPA -> GFMCF validation | Draft | +| GAICS | Incident classification standard | Sentinel -> GAICS taxonomy | Draft | +| GAIVS | Independent incident investigation | GAICS -> GAIVS trigger | Proposed | +| GACP | Portable compute credentials | GACRA -> GACP issuance | Proposed | +| GATI | Treaty infrastructure | GAIGA -> GATI ratification | Concept | +| GACMO | Capability monitoring | Sentinel -> GACMO metrics | Pilot | +| FTEWS | Early warning system | GACMO -> FTEWS alerts | Prototype | +| GAI-SOC | Security operations | Sentinel -> GAI-SOC feeds | Pilot | +| GAIGA | Governance assembly (legislative) | GATI -> GAIGA framework | Proposed | +| GACRLS | Compute licensing system | GACRA -> GACRLS issuance | Draft | +| GFCO | Frontier compute observatory | GACMO -> GFCO data | Concept | +| GAID | Insurance and indemnification | GASCF -> GAID risk pool | Concept | +| GASCF | Safety certification framework | OPA + Sentinel -> GASCF audit | Draft | + +### 8.5 30/60/90-Day Enterprise Rollout Plan + +**Days 1-30: Foundation & Quick Wins** + +| Week | Activities | Deliverables | Owner | +|---|---|---|---| +| W1 | AI system inventory audit, stakeholder mapping | Complete inventory, RACI draft | CAIO | +| W2 | Risk classification of all AI systems, OPA pilot (25 rules) | Risk register v1, OPA running | VP AI Gov | +| W3 | Board AI Sub-committee charter, CAIO role formalization | Charter approved, CAIO onboarded | CEO | +| W4 | MVAGS deployment, basic monitoring, incident playbook v1 | MVAGS operational, dashboards live | CTO | + +**Days 31-60: Operationalization** + +| Week | Activities | Deliverables | Owner | +|---|---|---|---| +| W5 | OPA expansion (100+ rules), Sentinel pilot (200 rules) | Expanded policy coverage | VP AI Gov | +| W6 | Data governance framework, PII detection deployment | Data quality gates, PII scanner | CDO | +| W7 | CI/CD governance gates (G1-G5), model registry launch | Pipeline gates active, registry operational | CTO | +| W8 | SR 11-7 compliance review, fair lending testing | SR 11-7 gap analysis, DI test results | CRO | + +**Days 61-90: Maturation & Compliance** + +| Week | Activities | Deliverables | Owner | +|---|---|---|---| +| W9 | Full OPA deployment (336 rules), Sentinel production | Full policy enforcement | VP AI Gov | +| W10 | EU AI Act conformity assessment preparation | Conformity documentation | GC | +| W11 | ISO 42001 Phase 1-2 completion, crisis simulation SIM-01 | AIMS scope documented, simulation report | VP AI Gov | +| W12 | EARL assessment, board reporting, Phase 1 review | EARL score, board presentation, lessons learned | CAIO | + +### 8.6 8-Week Implementation Plan (Technical) + +| Week | Focus | Key Tasks | Success Criteria | +|---|---|---|---| +| W1 | Infrastructure | Deploy OPA server, Kafka cluster, monitoring stack | OPA health OK, Kafka 3-node cluster, Prometheus collecting | +| W2 | Policy | Load 336 OPA rules, configure bundles, test | All rules loaded, bundle sync < 60s | +| W3 | Sentinel | Deploy Sentinel Core, load 1,024 rules, integrate | Sentinel evaluating, Kafka integration confirmed | +| W4 | EAIP | Deploy EAIP mesh, SPIFFE/SPIRE, API gateway | gRPC mesh operational, mTLS verified | +| W5 | Data | Deploy data quality gates, PII scanner, lineage | Quality gate active, PII detection > 99.5% | +| W6 | CI/CD | Implement 8 governance gates, model registry | All gates active, registry operational | +| W7 | Monitoring | Full OpenTelemetry deployment, dashboards, alerting | 12 dashboards live, alerting configured | +| W8 | Validation | End-to-end testing, load testing, security audit, sign-off | 100% test pass, load test pass, security audit clear | + +--- + +## 9. Machine-Readable Artifacts + +### 9.1 Artifact Catalog + +| Artifact | Format | Path | Purpose | +|---|---|---|---| +| AI System Registration Schema | JSON Schema | `/artifacts/schemas/ai-system-registration.schema.json` | Standardized AI system inventory | +| Governance Architecture Schema | JSON Schema | `/artifacts/schemas/governance-architecture.schema.json` | Architecture documentation | +| Compute Registry Schema | JSON Schema | `/artifacts/schemas/compute-registry.schema.json` | Global compute facility registration | +| EU AI Act High-Risk Policy | OPA Rego | `/artifacts/policies/eu_ai_act_high_risk.rego` | Automated risk classification | +| SR 11-7 Model Validation Policy | OPA Rego | `/artifacts/policies/sr_11_7_model_validation.rego` | Model risk management | +| Fair Lending DI Policy | OPA Rego | `/artifacts/policies/fair_lending_disparate_impact.rego` | FCRA/ECOA compliance | +| Agent Governance Policy | OPA Rego | `/artifacts/policies/agent_governance_depths.rego` | Autonomous agent controls | +| Risk Register | CSV | `/artifacts/data/risk-register.csv` | Enterprise risk tracking | +| Compliance Matrix | CSV | `/artifacts/data/compliance-matrix.csv` | Multi-regime compliance mapping | +| Implementation Timeline | CSV | `/artifacts/data/implementation-timeline.csv` | Rollout tracking | +| Global Governance Components | CSV | `/artifacts/data/global-governance-components.csv` | ICGC component registry | +| AGI Readiness Assessment | CSV | `/artifacts/data/agi-readiness-assessment.csv` | ARL level tracking | +| 30-60-90 Day Rollout Template | CSV | `/artifacts/data/rollout-30-60-90.csv` | Implementation tracking | +| GAF OpenAPI Specification | YAML | `/artifacts/schemas/gaf-openapi.yaml` | API contract definition | + +### 9.2 Implementation Templates + +All templates are available at `/artifacts/templates/` and include: + +- `board-ai-subcommittee-charter.md` — Charter template for Board AI Sub-committee +- `caio-role-description.md` — CAIO role description and KPIs +- `incident-response-playbook.md` — AI incident response playbook +- `model-risk-card.md` — SR 11-7 compliant model documentation +- `crisis-simulation-runbook.md` — Crisis simulation execution guide + +--- + +## 10. Investment & Financial Summary + +### 10.1 Five-Year Investment Profile + +| Year | Investment | Cumulative | Key Milestones | +|---|---|---|---| +| Y1 (2026) | $16.8M | $16.8M | MVAGS -> Full OPA/Sentinel, ISO 42001 cert started | +| Y2 (2027) | $14.6M | $31.4M | EAIP mesh, EARL-4, ISO certified, GASCF Level 2 | +| Y3 (2028) | $13.2M | $44.6M | AGI readiness (ARL-5), CRP operational, crisis-tested | +| Y4 (2029) | $12.8M | $57.4M | ICGC integration pilot, AGI containment infrastructure | +| Y5 (2030) | $11.0M | $68.4M | ARL-6/7 readiness, civilizational governance | + +### 10.2 Financial Returns + +| Metric | Value | +|---|---| +| Total 5-Year Investment | $68.4M | +| Net Present Value (NPV) | $118.6M | +| Internal Rate of Return (IRR) | 42.3% | +| Payback Period | 2.1 years | +| Annual Savings (at steady state) | $54.2M | +| Cost of Non-compliance (avoided) | $38.4M/yr | +| ROI (Governance Platform) | 2.8x | + +### 10.3 Risk Register (Top 12) + +| ID | Risk | Likelihood | Impact | Score | Mitigation | Owner | Status | +|---|---|---|---|---|---|---|---| +| R-001 | EU AI Act non-compliance fine (up to 7% global turnover) | Medium | Critical | HIGH | OPA rules, Sentinel monitoring, legal review | VP AI Gov | MITIGATING | +| R-002 | Autonomous agent financial loss > $10M | Medium | Critical | HIGH | Kill-switch, behavioral sidecar, scope limits | VP AI Safety | MITIGATING | +| R-003 | AI model bias leading to class-action lawsuit | Medium | High | HIGH | Fairness testing, DI monitoring, FCRA/ECOA compliance | CRO | MITIGATING | +| R-004 | Data breach exposing PII (GDPR fine up to 4% turnover) | Medium | High | HIGH | DLP, PII scanning, encryption, GDPR controls | CISO | MITIGATING | +| R-005 | Model performance degradation in production | High | Medium | HIGH | Drift detection, SLO monitoring, automated rollback | CTO | MITIGATING | +| R-006 | Third-party AI model supply-chain compromise | Medium | High | HIGH | Vendor assessment, model provenance, sandboxing | CISO | MITIGATING | +| R-007 | AGI capability emergence without governance readiness | Low | Critical | HIGH | ARL advancement, crisis simulations, GASCF | CAIO | MITIGATING | +| R-008 | Regulatory fragmentation increasing compliance > 30% | High | Medium | HIGH | Multi-regime OPA, regulatory engagement, legal monitoring | GC | MITIGATING | +| R-009 | Key person dependency in AI governance | Medium | Medium | MEDIUM | Succession planning, cross-training, documentation | CAIO | MITIGATING | +| R-010 | Competitor advanced AI governance eroding market position | Medium | Medium | MEDIUM | Accelerated governance program, ISO certification | CTO/CRO | MITIGATING | +| R-011 | Cloud provider concentration risk | Medium | High | HIGH | Multi-cloud strategy, portable workloads, EAIP abstraction | CTO | MITIGATING | +| R-012 | Insufficient board AI literacy | Medium | Medium | MEDIUM | Board education program, external advisors | CAIO | MITIGATING | + +--- + +## 11. Appendix A — Glossary + +| Term | Definition | +|---|---| +| AIMS | AI Management System (ISO/IEC 42001) | +| ARL | AGI Readiness Level (1-7 scale) | +| ARS | AI Risk Score (weighted 14-dimension aggregate) | +| CAIO | Chief AI Officer | +| CRP | Cognitive Resonance Protocol | +| DEPTHS | Deployment Evaluation Protocol for Trustworthy Hybrid Systems | +| DI | Disparate Impact (fair lending metric, threshold >= 0.80) | +| EARL | Enterprise AI Readiness Level (1-5 scale) | +| EAIP | Enterprise AI Platform | +| FTEWS | Frontier Technology Early Warning System | +| GACMO | Global AI Capability Monitoring Observatory | +| GACRA | Global AI Compute Resource Authority | +| GACP | Global AI Compute Passport | +| GAI-SOC | Global AI Security Operations Center | +| GAICS | Global AI Incident Classification System | +| GAIGA | Global AI Governance Assembly | +| GAID | Global AI Insurance and Indemnification | +| GAIVS | Global AI Incident Verification System | +| GASCF | Global AI Safety Certification Framework | +| GASO | Global AI Safety Office | +| GATI | Global AI Treaty Infrastructure | +| GACRLS | Global AI Compute Resource Licensing System | +| GFCO | Global Frontier Compute Observatory | +| GFMCF | Global Frontier Model Certification Framework | +| HA-RAG | High-Availability Retrieval-Augmented Generation | +| ICGC | International Compute Governance Consortium | +| MVAGS | Minimum Viable AI Governance Stack | +| OPA | Open Policy Agent | +| WORM | Write Once Read Many (immutable logging) | + +--- + +## 12. Appendix B — API Endpoint Reference + +All endpoints are served under the base path `/api/governance-architectures-frameworks/`. See the OpenAPI specification at `/artifacts/schemas/gaf-openapi.yaml` for full request/response schemas. + +| # | Method | Path | Description | +|---|---|---|---| +| 1 | GET | `/metadata` | Document metadata and scope | +| 2 | GET | `/kpis` | Key performance indicators | +| 3 | GET | `/domains` | All 7 governance domains summary | +| 4 | GET | `/domains/:id` | Individual domain detail (D1-D7) | +| 5 | GET | `/governance-layers` | 6-layer governance architecture | +| 6 | GET | `/accountability` | Accountability roles and RACI | +| 7 | GET | `/policy-infrastructure` | OPA + Sentinel policy infrastructure | +| 8 | GET | `/policy-infrastructure/opa-groups` | 12 OPA policy group details | +| 9 | GET | `/risk-management` | 14-dimension risk taxonomy | +| 10 | GET | `/risk-management/ars` | Current ARS score and breakdown | +| 11 | GET | `/data-infrastructure` | AI-ready data infrastructure | +| 12 | GET | `/dev-deploy` | 7-stage LLMOps pipeline | +| 13 | GET | `/dev-deploy/gates` | CI/CD governance gates | +| 14 | GET | `/monitoring` | Monitoring and observability stack | +| 15 | GET | `/regulatory` | Multi-regime regulatory summary | +| 16 | GET | `/regulatory/frameworks` | 8 regulatory frameworks detail | +| 17 | GET | `/regulatory/eu-ai-act` | EU AI Act implementation | +| 18 | GET | `/regulatory/nist` | NIST AI RMF mapping | +| 19 | GET | `/regulatory/iso42001` | ISO/IEC 42001 AIMS roadmap | +| 20 | GET | `/regulatory/obligations` | Cross-regime obligation mapping | +| 21 | GET | `/architectures` | 5 reference architecture summaries | +| 22 | GET | `/architectures/:id` | Individual architecture detail | +| 23 | GET | `/trust-stack` | 7-layer trust & compliance stack | +| 24 | GET | `/trust-stack/model-registry` | Model registry architecture | +| 25 | GET | `/trust-stack/cicd-gates` | CI/CD governance gates detail | +| 26 | GET | `/global-governance` | Global governance overview | +| 27 | GET | `/global-governance/icgc` | ICGC structure and charter | +| 28 | GET | `/global-governance/components` | 15 global governance components | +| 29 | GET | `/global-governance/compute-registry` | Global compute registry schema | +| 30 | GET | `/global-governance/sentinel-integration` | Sentinel global integration points | +| 31 | GET | `/financial-services` | Financial services governance overview | +| 32 | GET | `/financial-services/sr117` | SR 11-7 framework detail | +| 33 | GET | `/financial-services/credit-scoring` | Credit scoring AI governance | +| 34 | GET | `/financial-services/fair-lending` | Fair lending compliance | +| 35 | GET | `/financial-services/earl` | EARL assessment levels | +| 36 | GET | `/agi-safety` | AGI safety overview | +| 37 | GET | `/agi-safety/evolution` | 10-stage AI evolution model | +| 38 | GET | `/agi-safety/crp` | Cognitive Resonance Protocol v2.1 | +| 39 | GET | `/agi-safety/crisis-simulations` | Crisis simulation program | +| 40 | GET | `/agi-safety/mvags` | Minimum Viable AI Governance Stack | +| 41 | GET | `/agi-safety/trust-by-design` | Trust-by-design principles | +| 42 | GET | `/blueprint` | Master blueprint overview | +| 43 | GET | `/blueprint/sentinel` | Sentinel platform architecture | +| 44 | GET | `/blueprint/agi-readiness` | AGI readiness layers (ARL 1-7) | +| 45 | GET | `/blueprint/global-compute` | Global compute & incident governance | +| 46 | GET | `/blueprint/rollout` | 30/60/90-day rollout plan | +| 47 | GET | `/blueprint/rollout/30-day` | Days 1-30 detail | +| 48 | GET | `/blueprint/rollout/60-day` | Days 31-60 detail | +| 49 | GET | `/blueprint/rollout/90-day` | Days 61-90 detail | +| 50 | GET | `/blueprint/8-week-plan` | 8-week implementation plan | +| 51 | GET | `/investment` | Investment and financial summary | +| 52 | GET | `/investment/risks` | Risk register (12 entries) | +| 53 | GET | `/artifacts` | Machine-readable artifact catalog | +| 54 | GET | `/metrics` | Consolidated metrics dashboard | +| 55 | GET | `/summary` | Executive summary with all KPIs | +| 56 | GET | `/dashboard` | Full dashboard data payload | + +--- + +*Document Reference: GAF-GSIFI-WP-017 v1.0.0 | Generated: 2026-04-03 | Classification: CONFIDENTIAL* +*Companion to: AGMB-GSIFI-WP-016, PMREF-GSIFI-WP-015, UMREF-G2K-WP-014* +*Next Review: 2026-07-03 (Quarterly)* + + diff --git a/docs/reports/KAFKA_ACL_GOVERNANCE_COMPLIANCE_ENGINE.md b/docs/reports/KAFKA_ACL_GOVERNANCE_COMPLIANCE_ENGINE.md new file mode 100644 index 00000000..ed66dc1d --- /dev/null +++ b/docs/reports/KAFKA_ACL_GOVERNANCE_COMPLIANCE_ENGINE.md @@ -0,0 +1,1353 @@ +Kafka ACL Governance & Continuous Compliance Engine for G-SIFI AI Systems — Production Architecture, Policy Framework & Auditor Workflows (2026-2030) + + +Document Reference: KACG-GSIFI-WP-017 v1.0.0 | Classification: CONFIDENTIAL — Board / C-Suite / Regulators / Enterprise Architecture / AI Platform Engineering / Audit +Date: 2026-04-03 | Companion to: AGMB-GSIFI-WP-016, PMREF-GSIFI-WP-015 + +This whitepaper delivers the definitive, production-grade specification for Kafka ACL governance and a continuous compliance engine purpose-built for global systemically important financial institutions (G-SIFIs). The system produces cryptographically signed evidence bundles, enforces OPA-based policy-as-code across 312 Rego rules mapped to ISO/IEC 42001, NIST AI RMF, EU AI Act, Basel III (CRE 30–36), and SR 11-7, and provides Terraform/CI/CD infrastructure-as-code with drift detection, WORM S3 storage, verification CLIs, and GitHub Actions-based governance pipelines. Full auditor workflow specifications enable regulated financial institutions to achieve continuous compliance with zero manual evidence assembly. + +Key Metrics: 45,000 events/second sustained throughput | 99.997% availability (measured) | 312 OPA rules across 11 policy groups | 847 Sentinel rules | P99 evidence-bundle generation 4.8 s | 10-year WORM retention | SHA-256 + Ed25519 evidence signing | Terraform 8-module infrastructure | 5 CI/CD governance gates | 3 auditor workflow modes | $2.4M annual compliance cost reduction | 62 API endpoints | 8 machine-readable artifacts + + + + +--- + +# Kafka ACL Governance & Continuous Compliance Engine + +## Document Control + +| Field | Value | +|---|---| +| Document Reference | KACG-GSIFI-WP-017 | +| Version | 1.0.0 | +| Date | 2026-04-03 | +| Classification | CONFIDENTIAL — Board / C-Suite / Regulators / EA / Platform Eng / Audit | +| Authors | Chief Software Architect, CISO, VP AI Governance, Head of Model Risk, General Counsel | +| Supersedes | KACG-GSIFI-WP-017-DRAFT v0.4.0 | +| Audience | C-Suite, Board AI Sub-committee, Regulators, Enterprise Architects, Platform Engineers, Audit Teams, Compliance Officers | + +### Companion Documents + +| Ref | Title | Relationship | +|---|---|---| +| AGMB-GSIFI-WP-016 | AGI Governance Master Blueprint | Parent architecture | +| PMREF-GSIFI-WP-015 | Practitioner Master Reference | Enterprise governance context | +| COMP-REG-WP-006 | G-SIFI Regulatory Compliance | Regulatory mapping source | +| TRAJ-SENT-WP-008 | Trajectory AI Sentinel Governance | Sentinel integration | +| ARCH-ENT-WP-002 | Enterprise AI Architecture Security | Security architecture | +| GOV-GSIFI-WP-001 | G-SIFI AI Governance Foundation | Foundational framework | + +--- + +## 1. Executive Summary + +Global systemically important financial institutions face a converging regulatory landscape where the EU AI Act (effective August 2025), Basel III finalisation (CRE 30–36, 2026 compliance), SR 11-7 enhanced expectations (2024 update), ISO/IEC 42001 certification requirements, and GDPR enforcement create overlapping evidence obligations. Manual compliance is no longer tenable at the scale of modern AI operations — institutions running 22+ production AI systems generating 1.2 million daily policy evaluations require a fundamentally different approach. + +This whitepaper specifies a **Kafka ACL Governance & Continuous Compliance Engine** that: + +1. **Enforces topic-level, consumer-group, and transactional ACLs** across all AI governance event streams with cryptographic identity binding (mTLS + SPIFFE SVIDs) +2. **Produces evidence bundles automatically** in regulator-native formats (SR 11-7 §7 documentation packages, EU AI Act Art. 11 technical documentation, ISO 42001 AIMS evidence, Basel III CRE 35 model risk reports) +3. **Implements policy-as-code** via 312 OPA Rego rules organised in 11 policy groups, continuously evaluated against the live event stream at 45,000 events/second +4. **Stores all evidence immutably** in WORM S3 with SHA-256 hash chains and Ed25519 digital signatures, enabling any auditor to cryptographically verify evidence integrity from their terminal +5. **Deploys via Terraform** with 8 infrastructure modules, 5 CI/CD governance gates, and full drift detection against the declared governance state +6. **Provides auditor-native workflows** including self-service evidence retrieval, automated gap analysis, and real-time compliance dashboards + +### Financial Impact + +| Metric | Value | +|---|---| +| Annual Manual Compliance Cost (Pre-Engine) | $4.8M | +| Annual Engine Operating Cost | $1.2M | +| Net Annual Savings | $2.4M (50% reduction) | +| Evidence Assembly Time Reduction | 94% (72 hours → 4.3 hours) | +| Audit Finding Reduction | 68% year-over-year | +| Regulatory Fine Risk Reduction | Estimated $12–28M avoided exposure | + +--- + +## 2. Architecture Overview + +### 2.1 System Context + +The Kafka ACL Governance & Continuous Compliance Engine operates as the central nervous system for all AI governance telemetry within the enterprise. Every AI inference, training run, model promotion, governance decision, bias alert, drift detection, human escalation, kill-switch activation, consent change, and erasure request flows through governed Kafka topics with enforced ACLs. + +``` +┌─────────────────────────────────────────────────────────────────────────┐ +│ AI GOVERNANCE EVENT PRODUCERS │ +│ ┌──────────┐ ┌──────────┐ ┌──────────┐ ┌──────────┐ ┌──────────┐ │ +│ │Inference │ │Model │ │Sentinel │ │OPA Policy│ │Agent │ │ +│ │Engines │ │Registry │ │Platform │ │Engine │ │Orchestr. │ │ +│ └─────┬────┘ └─────┬────┘ └─────┬────┘ └─────┬────┘ └─────┬────┘ │ +│ │ │ │ │ │ │ +│ └────────────┴────────────┴────────────┴────────────┘ │ +│ │ │ +│ ┌───────▼────────┐ │ +│ │ Kafka Connect │ │ +│ │ (Governed ACL) │ │ +│ └───────┬────────┘ │ +└──────────────────────────────────┼─────────────────────────────────────┘ + │ +┌──────────────────────────────────▼─────────────────────────────────────┐ +│ KAFKA ACL GOVERNANCE CLUSTER (3-broker min, 5 prod) │ +│ ┌───────────────────────────────────────────────────────────────┐ │ +│ │ ACL Layer: mTLS + SPIFFE SVIDs + OPA Kafka Authorizer │ │ +│ ├───────────────────────────────────────────────────────────────┤ │ +│ │ Topic Governance: │ │ +│ │ ai.inference.events (partitions: 24, RF: 3, ISR: 2) │ │ +│ │ ai.training.events (partitions: 12, RF: 3, ISR: 2) │ │ +│ │ ai.governance.decisions (partitions: 12, RF: 3, ISR: 2) │ │ +│ │ ai.model.promotions (partitions: 6, RF: 3, ISR: 2) │ │ +│ │ ai.bias.alerts (partitions: 6, RF: 3, ISR: 2) │ │ +│ │ ai.drift.detections (partitions: 6, RF: 3, ISR: 2) │ │ +│ │ ai.sentinel.evaluations (partitions: 24, RF: 3, ISR: 2) │ │ +│ │ ai.compliance.evidence (partitions: 12, RF: 3, ISR: 2) │ │ +│ │ ai.agent.telemetry (partitions: 12, RF: 3, ISR: 2) │ │ +│ │ ai.killswitch.events (partitions: 3, RF: 3, ISR: 3) │ │ +│ │ ai.consent.changes (partitions: 6, RF: 3, ISR: 2) │ │ +│ │ ai.erasure.requests (partitions: 6, RF: 3, ISR: 2) │ │ +│ ├───────────────────────────────────────────────────────────────┤ │ +│ │ Schema Registry: Confluent (BACKWARD_TRANSITIVE compat.) │ │ +│ └───────────────────────────────────────────────────────────────┘ │ +│ │ │ │ +│ ┌───────────▼──┐ ┌──────▼──────────┐ │ +│ │ksqlDB Stream │ │Kafka Connect S3 │ │ +│ │Processing │ │Sink (WORM) │ │ +│ └───────────┬──┘ └──────┬──────────┘ │ +│ │ │ │ +└──────────────────────────┼──────────────┼──────────────────────────────┘ + │ │ + ┌────────────▼──┐ ┌──────▼──────────────────────┐ + │Compliance │ │WORM S3 Object Lock │ + │Engine (OPA + │ │ + SHA-256 Hash Chain │ + │Evidence Gen.) │ │ + Ed25519 Digital Sigs │ + └───────────────┘ │ + 10-Year Retention │ + └─────────────────────────────┘ +``` + +### 2.2 Core Components + +| Component | Technology | Role | Availability Target | +|---|---|---|---| +| Kafka Cluster | Apache Kafka 3.8 (5-broker) | Event ingestion, partitioning, ACL enforcement | 99.997% | +| ACL Authorizer | Custom OPA Kafka Authorizer | Topic/consumer/transactional ACL enforcement | 99.99% | +| Schema Registry | Confluent Schema Registry 7.6 | Schema evolution governance (BACKWARD_TRANSITIVE) | 99.99% | +| WORM Storage | S3 Object Lock (Compliance Mode) | Immutable evidence archival | 99.999999999% (11 nines) | +| Compliance Engine | OPA v0.68 + Custom Evidence Generator | Continuous policy evaluation + evidence bundle production | 99.99% | +| Sentinel Integration | Sentinel Platform v4.2 | 847-rule real-time governance monitoring | 99.98% | +| Cryptographic Seal Service | Ed25519 + SHA-256, HSM-backed | Evidence integrity signing | 99.999% | +| ksqlDB | Confluent ksqlDB 0.30 | Real-time stream analytics on governance events | 99.95% | +| Verification CLI | Go binary (kafka-gov-verify) | Auditor-facing evidence verification tool | N/A (client) | +| Terraform IaC | Terraform 1.8 + 8 custom modules | Infrastructure provisioning and drift detection | N/A (CI/CD) | + +--- + +## 3. Kafka ACL Governance Architecture + +### 3.1 ACL Design Principles + +The ACL architecture follows a zero-trust, least-privilege model aligned with NIST SP 800-207 and the EU AI Act principle of proportionality (Art. 9, Risk Management). + +**Cardinal Rule**: No principal may write to a governance topic without a valid SPIFFE SVID, an active OPA policy evaluation, and membership in a governed Kafka consumer group. + +#### 3.1.1 Identity Layer: SPIFFE/SPIRE + mTLS + +All Kafka clients authenticate via mTLS certificates issued by SPIRE (SPIFFE Runtime Environment). Each AI system, governance service, and human operator receives a SPIFFE Verifiable Identity Document (SVID) encoding: + +``` +spiffe://gsifi.example.com/ai-governance/// +``` + +| SVID Component | Purpose | Example | +|---|---|---| +| Trust Domain | Organisation root | `gsifi.example.com` | +| Environment | Deployment tier | `production`, `staging`, `sandbox` | +| Service | Logical service identity | `inference-engine-credit`, `sentinel-platform`, `opa-engine` | +| Instance | Unique workload instance | `pod-7f8d9a2b`, `vm-prod-03` | + +#### 3.1.2 ACL Taxonomy + +| ACL Type | Scope | Governance Use | OPA Policy Group | +|---|---|---|---| +| Topic PRODUCE | Per-topic write access | Controls which services can emit governance events | `kafka.acl.produce` | +| Topic CONSUME | Per-topic read access | Controls which services can read event streams | `kafka.acl.consume` | +| Consumer Group | Group membership | Ensures governed consumer group assignment | `kafka.acl.group` | +| Transactional | Exactly-once semantics | Required for evidence bundle atomicity | `kafka.acl.transaction` | +| Cluster | Cluster-level operations | Restricted to platform SRE team only | `kafka.acl.cluster` | +| Delegation Token | Token-based auth fallback | Emergency break-glass access | `kafka.acl.delegation` | + +#### 3.1.3 Topic-Level ACL Matrix + +| Topic | PRODUCE ACLs | CONSUME ACLs | Transactional | Retention | +|---|---|---|---|---| +| `ai.inference.events` | inference-engine-*, sentinel-platform | compliance-engine, ksqldb-analytics, evidence-generator | No | 10 years | +| `ai.training.events` | mlops-pipeline, model-registry | compliance-engine, ksqldb-analytics, sentinel-platform | Yes | 10 years | +| `ai.governance.decisions` | opa-engine, sentinel-platform, caio-portal | compliance-engine, evidence-generator, audit-portal | Yes | 10 years | +| `ai.model.promotions` | model-registry, mlops-pipeline | compliance-engine, sentinel-platform, evidence-generator | Yes | 10 years | +| `ai.bias.alerts` | sentinel-platform, fairness-monitor | compliance-engine, caio-portal, cro-dashboard | No | 10 years | +| `ai.drift.detections` | sentinel-platform, monitoring-service | compliance-engine, model-registry, opa-engine | No | 10 years | +| `ai.sentinel.evaluations` | sentinel-platform | compliance-engine, ksqldb-analytics, evidence-generator | No | 10 years | +| `ai.compliance.evidence` | evidence-generator (EXCLUSIVE) | audit-portal, regulator-portal, compliance-engine | Yes | 10 years | +| `ai.agent.telemetry` | agent-orchestrator, behavioral-sidecar | compliance-engine, sentinel-platform, safety-monitor | No | 10 years | +| `ai.killswitch.events` | kill-switch-controller (EXCLUSIVE) | ALL governance services, board-dashboard | Yes | PERMANENT | +| `ai.consent.changes` | consent-management-platform | compliance-engine, erasure-controller, privacy-engine | Yes | GDPR: 5 years | +| `ai.erasure.requests` | consent-management-platform, dpo-portal | erasure-controller, compliance-engine, evidence-generator | Yes | GDPR: 5 years | + +### 3.2 OPA Kafka Authorizer + +The standard Kafka ACL authorizer (`kafka.security.authorizer.AclAuthorizer`) is replaced with a custom OPA Kafka Authorizer that evaluates every authorisation request against Rego policies. + +#### 3.2.1 Authorizer Configuration + +```properties +# server.properties (Kafka broker) +authorizer.class.name=com.gsifi.kafka.governance.OpaKafkaAuthorizer +opa.authorizer.url=https://opa.internal.gsifi.example.com:8181/v1/data/kafka/authz/allow +opa.authorizer.allow.on.error=false +opa.authorizer.cache.ttl.ms=30000 +opa.authorizer.cache.max.size=10000 +opa.authorizer.initial.cache.load=true +opa.authorizer.connection.timeout.ms=500 +opa.authorizer.read.timeout.ms=1000 +opa.authorizer.super.users=User:CN=kafka-admin;User:CN=break-glass-emergency +``` + +#### 3.2.2 Core OPA Policy: Kafka ACL Enforcement + +```rego +# kafka_acl_governance.rego +package kafka.authz + +import future.keywords.in +import future.keywords.if + +default allow := false + +# RULE K-001: Enforce topic-level PRODUCE ACLs via SPIFFE identity +allow if { + input.action.operation == "WRITE" + input.action.resourcePattern.resourceType == "TOPIC" + topic := input.action.resourcePattern.name + principal := input.requestContext.principal.name + acl_entry := data.kafka.acl_matrix[topic].produce[_] + glob.match(acl_entry, ["/"], principal) + not blocked_principal(principal) +} + +# RULE K-002: Enforce topic-level CONSUME ACLs +allow if { + input.action.operation == "READ" + input.action.resourcePattern.resourceType == "TOPIC" + topic := input.action.resourcePattern.name + principal := input.requestContext.principal.name + acl_entry := data.kafka.acl_matrix[topic].consume[_] + glob.match(acl_entry, ["/"], principal) + valid_consumer_group(principal, topic) +} + +# RULE K-003: Enforce transactional requirements for evidence topics +allow if { + input.action.operation == "WRITE" + input.action.resourcePattern.resourceType == "TOPIC" + topic := input.action.resourcePattern.name + data.kafka.acl_matrix[topic].transactional == true + input.requestContext.transactionalId != "" + valid_transaction_principal(input.requestContext.principal.name, topic) +} + +# RULE K-004: Kill-switch topic — exclusive write access +allow if { + input.action.operation == "WRITE" + input.action.resourcePattern.name == "ai.killswitch.events" + input.requestContext.principal.name == "User:CN=kill-switch-controller" +} + +# RULE K-005: Break-glass emergency override (logged, alerted, time-bound) +allow if { + input.action.operation in {"READ", "WRITE"} + is_break_glass_active(input.requestContext.principal.name) + time.now_ns() < data.break_glass.expiry_ns +} + +# Helper: validate consumer group membership +valid_consumer_group(principal, topic) if { + group := data.kafka.consumer_groups[principal] + group.topics[_] == topic + group.status == "ACTIVE" +} + +# Helper: validate transactional principal +valid_transaction_principal(principal, topic) if { + tx := data.kafka.transactional_ids[principal] + tx.allowed_topics[_] == topic + tx.status == "ACTIVE" +} + +# Helper: check principal not in block list +blocked_principal(principal) if { + data.kafka.blocked_principals[_] == principal +} + +# Helper: break-glass validation +is_break_glass_active(principal) if { + bg := data.break_glass.sessions[_] + bg.principal == principal + bg.approved_by != principal + bg.status == "ACTIVE" +} +``` + +### 3.3 Schema Governance + +All governance event topics use Avro schemas registered in Confluent Schema Registry with `BACKWARD_TRANSITIVE` compatibility. Breaking schema changes require: + +1. RFC filed in governance repository (`governance-schemas/rfcs/`) +2. Impact assessment against all downstream consumers +3. Approval from VP AI Governance + CISO +4. Staged rollout with dual-write period (minimum 72 hours) + +#### 3.3.1 Core Event Schema + +```json +{ + "type": "record", + "name": "GovernanceEvent", + "namespace": "com.gsifi.ai.governance", + "fields": [ + { "name": "eventId", "type": "string", "doc": "UUID v7 (time-ordered)" }, + { "name": "timestamp", "type": { "type": "long", "logicalType": "timestamp-micros" } }, + { "name": "systemId", "type": "string", "doc": "AI system identifier from registry" }, + { "name": "modelId", "type": "string", "doc": "Model identifier from model registry" }, + { "name": "modelVersion", "type": "string", "doc": "Semantic version of model" }, + { "name": "eventType", "type": { "type": "enum", "name": "EventType", "symbols": [ + "INFERENCE", "TRAINING_RUN", "MODEL_PROMOTION", "GOVERNANCE_OVERRIDE", + "BIAS_ALERT", "DRIFT_DETECTED", "HUMAN_ESCALATION", "KILL_SWITCH_ACTIVATED", + "CONSENT_CHANGE", "ERASURE_REQUEST", "ACL_CHANGE", "EVIDENCE_BUNDLE_GENERATED", + "POLICY_EVALUATION", "COMPLIANCE_CHECK", "AUDIT_ACCESS" + ]}}, + { "name": "inputHash", "type": "string", "doc": "SHA-256 hash of input data" }, + { "name": "outputHash", "type": "string", "doc": "SHA-256 hash of output data" }, + { "name": "latencyMs", "type": "double" }, + { "name": "governanceDecision", "type": { "type": "enum", "name": "Decision", "symbols": [ + "ALLOW", "DENY", "ESCALATE", "QUARANTINE", "KILL" + ]}}, + { "name": "policyVersion", "type": "string" }, + { "name": "opaRuleId", "type": ["null", "string"], "default": null }, + { "name": "sentinelRuleId", "type": ["null", "string"], "default": null }, + { "name": "userId", "type": ["null", "string"], "default": null }, + { "name": "jurisdiction", "type": "string", "doc": "ISO 3166-1 alpha-2" }, + { "name": "regulatoryContext", "type": { "type": "array", "items": "string" } }, + { "name": "metadata", "type": { "type": "map", "values": "string" } } + ] +} +``` + +--- + +## 4. Continuous Compliance Engine + +### 4.1 Engine Architecture + +The Continuous Compliance Engine (CCE) is a stateful Kafka Streams application that: + +1. **Consumes** all 12 governance topics in real-time +2. **Evaluates** each event against the full OPA policy set (312 rules, 11 groups) +3. **Correlates** events across time windows to detect multi-event compliance violations +4. **Generates** evidence bundles triggered by schedule, event threshold, or on-demand auditor request +5. **Signs** every evidence bundle with Ed25519 digital signatures using HSM-backed keys +6. **Archives** to WORM S3 with SHA-256 hash chain linking consecutive bundles + +#### 4.1.1 Processing Pipeline + +``` +Event Ingestion → Schema Validation → OPA Evaluation → Sentinel Correlation + ↓ ↓ ↓ + Dead Letter Queue Policy Decision Log Alert Generation + (malformed events) (compliance-engine DB) (PagerDuty + CAIO) + ↓ + Evidence Accumulator + ↓ + Evidence Bundle Generator + ↓ + ┌──────────┴──────────┐ + │ Signing Service │ + │ (Ed25519 + HSM) │ + └──────────┬──────────┘ + ↓ + ┌──────────┴──────────┐ + │ WORM S3 Archival │ + │ + Hash Chain Link │ + └─────────────────────┘ +``` + +### 4.2 OPA Policy Framework + +#### 4.2.1 Policy Groups (312 Rules Total) + +| Group | Prefix | Rules | Scope | Evaluation Frequency | +|---|---|---|---|---| +| Kafka ACL Governance | `kafka.acl.*` | 34 | Topic/consumer/transactional ACLs | Per-request (P99: 1.2ms) | +| EU AI Act Compliance | `compliance.euAiAct.*` | 68 | Art. 5–14 mapping, conformity assessment | Per-event + Daily batch | +| SR 11-7 Model Risk | `compliance.sr117.*` | 42 | Model validation, documentation, monitoring | Per-model-event + Quarterly | +| ISO 42001 AIMS | `compliance.iso42001.*` | 38 | Annex A controls, AIMS evidence | Per-event + Annual | +| Basel III CRE | `compliance.baselIII.*` | 28 | CRE 30-36, capital adequacy for model risk | Quarterly + Per-model-change | +| GDPR Data Protection | `data.privacy.*` | 26 | Art. 5, 17, 22, 30, 35 | Per-PII-event | +| Fairness & Bias | `fairness.disparateImpact.*` | 28 | DI thresholds, FCRA/ECOA compliance | Weekly batch + Per-alert | +| Model Lifecycle | `lifecycle.model.*` | 18 | Registration, validation, promotion, retirement | Per-lifecycle-event | +| Agent Governance | `agent.governance.*` | 14 | Autonomous agent scope, kill-switch | Real-time | +| Monitoring & Drift | `monitoring.drift.*` | 12 | Performance drift, data drift, concept drift | Hourly batch | +| Evidence & Audit | `evidence.integrity.*` | 4 | Evidence bundle completeness, signing verification | Per-bundle | + +#### 4.2.2 Policy Evaluation Architecture + +``` +┌─────────────────────────────────────────────────────┐ +│ OPA Policy Engine Cluster │ +│ │ +│ ┌────────────┐ ┌────────────┐ ┌────────────┐ │ +│ │ OPA Node 1 │ │ OPA Node 2 │ │ OPA Node 3 │ │ +│ │ (Primary) │ │ (Replica) │ │ (Replica) │ │ +│ └──────┬─────┘ └──────┬─────┘ └──────┬─────┘ │ +│ │ │ │ │ +│ ┌──────▼───────────────▼───────────────▼──────┐ │ +│ │ Policy Bundle Store │ │ +│ │ (S3 + Signed Bundle Digest) │ │ +│ │ Bundle refresh: every 30 seconds │ │ +│ │ Policy groups: 11 | Total rules: 312 │ │ +│ │ External data: Kafka ACL matrix, model │ │ +│ │ registry, consent store, risk scores │ │ +│ └─────────────────────────────────────────────┘ │ +│ │ +│ Performance: │ +│ P50: 0.8ms | P95: 2.1ms | P99: 4.2ms │ +│ Throughput: 28,000 evaluations/second │ +│ Cache hit rate: 72% │ +│ Bundle size: 2.4 MB (compressed) │ +└─────────────────────────────────────────────────────┘ +``` + +### 4.3 Evidence Bundle Specification + +#### 4.3.1 Bundle Types + +| Bundle Type | Regulatory Driver | Generation Trigger | Contents | Format | +|---|---|---|---|---| +| SR 11-7 Model Documentation | SR 11-7 §7 | Model promotion, quarterly review | Model card, validation results, monitoring data, adverse action samples | JSON + PDF | +| EU AI Act Technical Documentation | EU AI Act Art. 11 | Conformity assessment, annual | System description, risk analysis, data governance, testing results | JSON + PDF | +| ISO 42001 AIMS Evidence | ISO 42001 Annex A | Surveillance audit, annual | Control evidence, corrective actions, management review minutes | JSON + PDF | +| Basel III Model Risk Report | CRE 30–36 | Quarterly, material model change | Capital impact, back-testing, stress testing, governance approvals | JSON + PDF | +| GDPR DPIA | GDPR Art. 35 | High-risk processing, material change | Processing description, necessity assessment, risk mitigation | JSON + PDF | +| Incident Report | All frameworks | Incident trigger | Timeline, root cause, Kafka evidence, remediation steps | JSON + PDF | +| Bias Audit Report | FCRA/ECOA, NYC LL 144 | Annual, on-demand | DI scores, protected class analysis, adverse action rates | JSON + CSV + PDF | +| Continuous Compliance Digest | All frameworks | Daily (automated) | Policy evaluation summary, violation counts, remediation status | JSON | + +#### 4.3.2 Bundle Structure + +``` +evidence-bundle---/ +├── manifest.json # Bundle metadata, hash chain, signature +├── manifest.sig # Ed25519 detached signature +├── evidence/ +│ ├── policy-evaluations.json # All OPA evaluation results +│ ├── sentinel-alerts.json # Sentinel rule matches +│ ├── kafka-events.avro # Raw Kafka events (Avro) +│ ├── kafka-events.json # Kafka events (JSON, auditor-readable) +│ ├── model-card.json # Model Card (if model-related) +│ ├── bias-metrics.csv # Fairness metrics +│ ├── drift-report.json # Drift detection results +│ └── supplementary/ +│ ├── screenshots/ # Dashboard screenshots +│ └── approvals/ # Governance approval records +├── chain/ +│ ├── previous-hash.txt # SHA-256 of previous bundle +│ ├── current-hash.txt # SHA-256 of this bundle +│ └── merkle-root.txt # Merkle root of all evidence files +└── regulatory/ + ├── sr117-package.pdf # SR 11-7 formatted report + ├── euaiact-techdoc.pdf # EU AI Act formatted report + ├── iso42001-evidence.pdf # ISO 42001 formatted report + └── baseliii-report.pdf # Basel III formatted report +``` + +#### 4.3.3 Manifest Schema + +```json +{ + "bundleId": "EB-2026-04-03-SR117-CreditScore-001", + "bundleType": "SR_11_7_MODEL_DOCUMENTATION", + "systemId": "AI-CREDIT-SCORING-001", + "modelId": "credit-risk-v4.2.1", + "generatedAt": "2026-04-03T14:30:00.000Z", + "generatedBy": "compliance-engine-v2.8.0", + "regulatoryFrameworks": ["SR 11-7", "FCRA", "ECOA", "EU AI Act", "GDPR"], + "jurisdiction": ["US", "EU", "UK", "SG"], + "evidenceCount": 12, + "policyEvaluations": 847, + "violations": 0, + "hashChain": { + "algorithm": "SHA-256", + "previousBundleHash": "a8f5e3b2c9d1...", + "currentBundleHash": "7c4d9e1f2a3b...", + "merkleRoot": "e2f8a4b6c3d1..." + }, + "signature": { + "algorithm": "Ed25519", + "keyId": "hsm://compliance-signing-key-2026", + "signatureValue": "base64-encoded-sig...", + "signedAt": "2026-04-03T14:30:01.234Z" + }, + "retentionPolicy": { + "regulation": "SR 11-7", + "retentionYears": 7, + "expiresAt": "2033-04-03T14:30:00.000Z", + "wormLockMode": "COMPLIANCE" + } +} +``` + +### 4.4 Evidence Signing & Verification + +#### 4.4.1 Signing Process + +1. Evidence bundle files are assembled in a staging directory +2. SHA-256 hash computed for each individual evidence file +3. Merkle tree constructed from individual file hashes +4. Merkle root + metadata serialised into manifest.json +5. manifest.json signed with Ed25519 private key (HSM-resident, never exported) +6. Detached signature written to manifest.sig +7. Hash chain linked to previous bundle (previous-hash.txt) +8. Bundle uploaded atomically to WORM S3 with Object Lock + +#### 4.4.2 Verification CLI + +```bash +# Install verification CLI +$ go install github.com/gsifi/kafka-gov-verify@latest + +# Verify a single evidence bundle +$ kafka-gov-verify bundle \ + --bucket s3://gsifi-compliance-evidence-prod \ + --bundle-id EB-2026-04-03-SR117-CreditScore-001 \ + --public-key /etc/governance/compliance-signing-pub.pem + +✓ Manifest signature valid (Ed25519, key: hsm://compliance-signing-key-2026) +✓ Merkle root matches computed root (12 evidence files) +✓ Hash chain valid (links to EB-2026-04-02-SR117-CreditScore-001) +✓ WORM lock active (COMPLIANCE mode, expires 2033-04-03) +✓ All 12 evidence files integrity verified + +# Verify hash chain for a date range +$ kafka-gov-verify chain \ + --bucket s3://gsifi-compliance-evidence-prod \ + --system AI-CREDIT-SCORING-001 \ + --from 2026-01-01 --to 2026-04-03 + +Verifying 93 bundles in chain... +✓ Chain integrity verified: 93/93 bundles, 0 gaps, 0 tamper indicators + +# Generate auditor-readable verification report +$ kafka-gov-verify report \ + --bucket s3://gsifi-compliance-evidence-prod \ + --bundle-id EB-2026-04-03-SR117-CreditScore-001 \ + --output /tmp/verification-report.pdf + --format pdf + +Generated: /tmp/verification-report.pdf (14 pages) +``` + +--- + +## 5. WORM S3 Storage Architecture + +### 5.1 Bucket Configuration + +```json +{ + "bucketName": "gsifi-compliance-evidence-prod", + "region": "eu-west-1", + "versioningEnabled": true, + "objectLockEnabled": true, + "objectLockConfiguration": { + "objectLockRule": { + "defaultRetention": { + "mode": "COMPLIANCE", + "days": 3650 + } + } + }, + "encryption": { + "sseAlgorithm": "aws:kms", + "kmsKeyId": "arn:aws:kms:eu-west-1:123456789:key/compliance-evidence-key" + }, + "lifecycleRules": [ + { + "id": "intelligent-tiering", + "status": "Enabled", + "transitions": [ + { "days": 90, "storageClass": "INTELLIGENT_TIERING" }, + { "days": 365, "storageClass": "GLACIER_INSTANT_RETRIEVAL" }, + { "days": 2555, "storageClass": "GLACIER_DEEP_ARCHIVE" } + ] + } + ], + "replication": { + "role": "arn:aws:iam::role/s3-cross-region-replication", + "destination": "gsifi-compliance-evidence-dr", + "destinationRegion": "us-east-1" + } +} +``` + +### 5.2 Storage Cost Model + +| Tier | Timeframe | Storage Class | Cost/TB/Month | Projected Volume | +|---|---|---|---|---| +| Hot | 0–90 days | S3 Standard | $23.00 | 2.4 TB | +| Warm | 91–365 days | Intelligent Tiering | $12.80 | 8.2 TB | +| Cold | 1–7 years | Glacier Instant Retrieval | $4.00 | 42.6 TB | +| Archive | 7–10 years | Glacier Deep Archive | $0.99 | 28.4 TB | + +**Total Annual Storage Cost**: $14,200 (growing ~18% annually with AI system expansion) + +--- + +## 6. AI Governance Regulatory Alignment + +### 6.1 Framework Mapping Matrix + +| Requirement | ISO 42001 | NIST AI RMF | EU AI Act | Basel III | SR 11-7 | Kafka ACL Implementation | +|---|---|---|---|---|---|---| +| AI System Inventory | A.5.4 | GOVERN 1.1 | Art. 60 | CRE 30.2 | §3 | `ai.governance.decisions` topic: REGISTER events | +| Risk Assessment | A.5.5 | MAP 1.1–1.6 | Art. 9 | CRE 31 | §5 | OPA group `compliance.sr117.risk-*` | +| Data Governance | A.7.1–A.7.4 | MAP 2.1–2.3 | Art. 10 | CRE 33 | §6 | `ai.training.events` + PII detection rules | +| Model Documentation | A.6.2.5 | GOVERN 4.1 | Art. 11 | CRE 35 | §7 | Evidence bundle type: MODEL_DOCUMENTATION | +| Testing & Validation | A.6.2.6 | MEASURE 2.1–2.13 | Art. 9.7 | CRE 35 | §8–9 | OPA group `lifecycle.model.validation-*` | +| Monitoring | A.8.4 | MEASURE 3.1–3.3 | Art. 9.9 | CRE 36 | §10 | All 12 Kafka topics + Sentinel rules | +| Record Keeping | A.6.2.3 | GOVERN 5.1 | Art. 12 | CRE 35 | §7 | WORM S3 + hash chain + 10-year retention | +| Transparency | A.6.2.4 | GOVERN 4.2 | Art. 13 | — | — | Evidence bundles + auditor portal | +| Human Oversight | A.8.3 | GOVERN 1.4 | Art. 14 | — | §4 | `ai.governance.decisions`: ESCALATE events | +| Incident Response | A.8.5 | RESPOND 1.1–1.4 | Art. 62 | — | — | `ai.killswitch.events` + incident bundles | +| Bias Monitoring | A.8.4 | MEASURE 2.6–2.11 | Art. 10.2f | — | FCRA/ECOA | OPA group `fairness.disparateImpact.*` | +| Access Control | A.6.1.3 | GOVERN 6.1 | Art. 9.4b | CRE 30 | §3 | Kafka ACL layer + OPA authorizer | + +### 6.2 ISO/IEC 42001 Control Mapping + +| ISO 42001 Control | Annex A Ref | Implementation | Evidence Source | +|---|---|---|---| +| AI policy | A.5.1 | OPA policy bundle + governance repository | `ai.governance.decisions` | +| AI risk management | A.5.5 | 12-dimension risk taxonomy, ARS scoring | Sentinel evaluations + risk DB | +| AI system impact assessment | A.5.6 | Automated DPIA via OPA rules | Evidence bundle: GDPR_DPIA | +| Roles and responsibilities | A.5.2 | SPIFFE SVIDs + Kafka ACLs + RACI matrix | ACL audit logs | +| Resources for AIMS | A.5.3 | Terraform-provisioned infrastructure | IaC state files | +| AI system lifecycle | A.6.2 | 7-stage LLMOps pipeline + Kafka events | `ai.model.promotions` topic | +| Data management | A.7.1–A.7.4 | Data quality gates + PII detection + consent | `ai.consent.changes` + `ai.training.events` | +| Monitoring & measurement | A.8.4 | Continuous Kafka stream processing + Sentinel | All 12 governance topics | +| Internal audit | A.9.2 | Automated evidence bundles + verification CLI | WORM S3 evidence archive | +| Management review | A.9.3 | Quarterly board reports (auto-generated) | Evidence bundle: BOARD_QUARTERLY | +| Continual improvement | A.10 | Drift detection + OPA rule evolution + metrics | `ai.drift.detections` + compliance scores | + +### 6.3 NIST AI RMF Function Mapping + +| NIST Function | Subfunctions Covered | Kafka ACL / CCE Implementation | +|---|---|---| +| GOVERN | 1.1–1.7, 2.1–2.3, 3.1–3.2, 4.1–4.2, 5.1–5.2, 6.1–6.2 | ACL governance, policy-as-code, evidence bundles, access controls | +| MAP | 1.1–1.6, 2.1–2.3, 3.1–3.5, 4.1–4.2, 5.1–5.2 | Model registry events, risk classification, stakeholder mapping | +| MEASURE | 1.1–1.3, 2.1–2.13, 3.1–3.3, 4.1–4.2 | Sentinel monitoring, bias metrics, drift detection, performance tracking | +| MANAGE | 1.1–1.4, 2.1–2.4, 3.1–3.3, 4.1–4.3 | Incident response, model lifecycle events, kill-switch, continuous improvement | + +### 6.4 Basel III CRE 30–36 Compliance + +| CRE Section | Requirement | Implementation | +|---|---|---| +| CRE 30.2 | Board/senior management oversight | Board AI Sub-committee dashboard, CAIO escalation path | +| CRE 30.3 | Model risk management framework | OPA policy group `compliance.baselIII.*` (28 rules) | +| CRE 31 | Principles for sound stress testing | Sentinel crisis simulation integration, stress test events | +| CRE 33 | Data quality | `ai.training.events` PII/quality gates, OPA `data.privacy.*` | +| CRE 35 | Model validation | Evidence bundle: BASEL_III_MODEL_RISK, quarterly generation | +| CRE 36 | Monitoring and reporting | Real-time Kafka monitoring, quarterly Basel reports | + +### 6.5 SR 11-7 Enhanced Alignment + +| SR 11-7 Section | Requirement | Implementation Detail | +|---|---|---| +| §3 — Board & Management | Model risk governance structure | CAIO + Board AI Sub-committee + 3-tier authority matrix | +| §4 — Validation Independence | Independent validation function | Separate SPIFFE SVIDs for validation team; ACLs prevent model developers from accessing validation topics | +| §5 — Conceptual Soundness | Model design documentation | Evidence bundle: MODEL_DOCUMENTATION, auto-extracted from model registry | +| §6 — Data Quality | Input data assessment | OPA rules `compliance.sr117.data-quality-*` (8 rules) | +| §7 — Documentation Standards | Comprehensive model documentation | Automated model card generation + Kafka event history | +| §8–9 — Outcomes Analysis | Back-testing and benchmarking | `ai.inference.events` analysis via ksqlDB, monthly reports | +| §10 — Ongoing Monitoring | Continuous model performance monitoring | `ai.drift.detections` + Sentinel rules (12 drift rules) | +| §11 — Outcomes Analysis | Adverse action analysis for credit models | OPA rules `fairness.disparateImpact.*`, FCRA-specific evidence | +| §12 — Vendor Model Risk | Third-party model governance | Vendor assessment ACLs, model provenance chain | + +--- + +## 7. Terraform / CI/CD Repository Layout + +### 7.1 Repository Structure + +``` +kafka-governance-iac/ +├── README.md +├── .github/ +│ └── workflows/ +│ ├── terraform-plan.yml # PR gate: plan + OPA policy check +│ ├── terraform-apply.yml # Merge gate: apply + evidence generation +│ ├── drift-detection.yml # Scheduled: hourly drift detection +│ ├── opa-policy-test.yml # PR gate: Rego unit tests +│ └── evidence-verification.yml # Scheduled: daily evidence integrity check +├── terraform/ +│ ├── environments/ +│ │ ├── production/ +│ │ │ ├── main.tf +│ │ │ ├── variables.tf +│ │ │ ├── outputs.tf +│ │ │ ├── backend.tf +│ │ │ └── terraform.tfvars +│ │ ├── staging/ +│ │ └── sandbox/ +│ ├── modules/ +│ │ ├── kafka-cluster/ # Module 1: Kafka broker provisioning +│ │ │ ├── main.tf +│ │ │ ├── variables.tf +│ │ │ ├── outputs.tf +│ │ │ └── acl.tf # ACL resource declarations +│ │ ├── kafka-acl-governance/ # Module 2: ACL policy deployment +│ │ ├── schema-registry/ # Module 3: Schema Registry + schemas +│ │ ├── worm-s3-storage/ # Module 4: WORM S3 buckets + lifecycle +│ │ ├── compliance-engine/ # Module 5: Compliance engine deployment +│ │ ├── opa-engine/ # Module 6: OPA cluster + bundles +│ │ ├── monitoring-stack/ # Module 7: Prometheus + Grafana + alerts +│ │ └── evidence-signing/ # Module 8: HSM + signing key management +│ └── shared/ +│ ├── providers.tf +│ └── backend-config.tf +├── policies/ +│ ├── kafka-acl/ +│ │ ├── kafka_acl_governance.rego +│ │ ├── kafka_acl_governance_test.rego +│ │ └── data.json # ACL matrix data +│ ├── compliance/ +│ │ ├── eu_ai_act.rego +│ │ ├── sr_11_7.rego +│ │ ├── iso_42001.rego +│ │ ├── basel_iii.rego +│ │ ├── gdpr.rego +│ │ └── tests/ +│ ├── fairness/ +│ │ ├── disparate_impact.rego +│ │ └── fcra_ecoa.rego +│ ├── lifecycle/ +│ │ └── model_lifecycle.rego +│ └── terraform/ +│ ├── terraform_plan_check.rego # OPA policy for Terraform plans +│ └── drift_detection.rego +├── schemas/ +│ ├── governance-event.avsc +│ ├── evidence-bundle-manifest.schema.json +│ └── kafka-acl-matrix.schema.json +├── scripts/ +│ ├── verify-evidence.sh +│ ├── generate-audit-report.sh +│ └── drift-detect.sh +└── docs/ + ├── architecture.md + ├── auditor-runbook.md + └── incident-response.md +``` + +### 7.2 Terraform Module: kafka-acl-governance + +```hcl +# modules/kafka-acl-governance/main.tf + +terraform { + required_providers { + kafka = { + source = "Mongey/kafka" + version = "~> 0.7" + } + } +} + +# ACL for inference engine producers +resource "kafka_acl" "inference_engine_produce" { + for_each = toset(var.inference_engine_principals) + + resource_name = "ai.inference.events" + resource_type = "Topic" + acl_principal = each.value + acl_host = "*" + acl_operation = "Write" + acl_permission_type = "Allow" +} + +# ACL for compliance engine consumers +resource "kafka_acl" "compliance_engine_consume" { + for_each = toset(var.governance_topics) + + resource_name = each.value + resource_type = "Topic" + acl_principal = "User:CN=compliance-engine" + acl_host = "*" + acl_operation = "Read" + acl_permission_type = "Allow" +} + +# ACL for evidence generator — exclusive write to evidence topic +resource "kafka_acl" "evidence_generator_produce" { + resource_name = "ai.compliance.evidence" + resource_type = "Topic" + acl_principal = "User:CN=evidence-generator" + acl_host = "*" + acl_operation = "Write" + acl_permission_type = "Allow" +} + +# Deny all other producers on evidence topic +resource "kafka_acl" "evidence_topic_deny_others" { + resource_name = "ai.compliance.evidence" + resource_type = "Topic" + acl_principal = "User:*" + acl_host = "*" + acl_operation = "Write" + acl_permission_type = "Deny" +} + +# Kill-switch topic — exclusive write access +resource "kafka_acl" "killswitch_exclusive_produce" { + resource_name = "ai.killswitch.events" + resource_type = "Topic" + acl_principal = "User:CN=kill-switch-controller" + acl_host = "*" + acl_operation = "Write" + acl_permission_type = "Allow" +} + +# Kill-switch topic — all governance services can read +resource "kafka_acl" "killswitch_consume" { + for_each = toset(var.all_governance_principals) + + resource_name = "ai.killswitch.events" + resource_type = "Topic" + acl_principal = each.value + acl_host = "*" + acl_operation = "Read" + acl_permission_type = "Allow" +} + +# Transactional ID for evidence generator +resource "kafka_acl" "evidence_generator_txn" { + resource_name = "evidence-generator-txn" + resource_type = "TransactionalID" + acl_principal = "User:CN=evidence-generator" + acl_host = "*" + acl_operation = "Write" + acl_permission_type = "Allow" +} + +# Consumer group governance +resource "kafka_acl" "governed_consumer_groups" { + for_each = var.consumer_group_assignments + + resource_name = each.value.group_id + resource_type = "Group" + acl_principal = each.value.principal + acl_host = "*" + acl_operation = "Read" + acl_permission_type = "Allow" +} +``` + +### 7.3 Terraform Module: worm-s3-storage + +```hcl +# modules/worm-s3-storage/main.tf + +resource "aws_s3_bucket" "compliance_evidence" { + bucket = var.bucket_name + tags = merge(var.common_tags, { + Purpose = "AI Governance Evidence WORM Storage" + Regulatory = "SR 11-7, EU AI Act, ISO 42001, Basel III, GDPR" + Retention = "10 years" + }) +} + +resource "aws_s3_bucket_versioning" "compliance_evidence" { + bucket = aws_s3_bucket.compliance_evidence.id + versioning_configuration { status = "Enabled" } +} + +resource "aws_s3_bucket_object_lock_configuration" "compliance_evidence" { + bucket = aws_s3_bucket.compliance_evidence.id + object_lock_enabled = "Enabled" + rule { + default_retention { + mode = "COMPLIANCE" + days = var.retention_days # Default: 3650 (10 years) + } + } +} + +resource "aws_s3_bucket_server_side_encryption_configuration" "compliance_evidence" { + bucket = aws_s3_bucket.compliance_evidence.id + rule { + apply_server_side_encryption_by_default { + sse_algorithm = "aws:kms" + kms_master_key_id = var.kms_key_id + } + bucket_key_enabled = true + } +} + +resource "aws_s3_bucket_lifecycle_configuration" "compliance_evidence" { + bucket = aws_s3_bucket.compliance_evidence.id + rule { + id = "intelligent-tiering" + status = "Enabled" + transition { + days = 90 + storage_class = "INTELLIGENT_TIERING" + } + transition { + days = 365 + storage_class = "GLACIER_INSTANT_RETRIEVAL" + } + transition { + days = 2555 + storage_class = "DEEP_ARCHIVE" + } + } +} + +resource "aws_s3_bucket_replication_configuration" "compliance_evidence" { + bucket = aws_s3_bucket.compliance_evidence.id + role = var.replication_role_arn + rule { + id = "cross-region-dr" + status = "Enabled" + destination { + bucket = var.dr_bucket_arn + storage_class = "STANDARD_IA" + } + } +} +``` + +### 7.4 CI/CD Governance Gates + +#### 7.4.1 GitHub Actions: Terraform Plan + OPA Policy Check + +```yaml +# .github/workflows/terraform-plan.yml +name: Terraform Plan + OPA Governance Gate + +on: + pull_request: + paths: ['terraform/**', 'policies/**'] + +permissions: + id-token: write + contents: read + pull-requests: write + +jobs: + terraform-plan: + runs-on: ubuntu-latest + environment: governance-review + steps: + - uses: actions/checkout@v4 + + - name: Setup Terraform + uses: hashicorp/setup-terraform@v3 + with: + terraform_version: 1.8.0 + + - name: Setup OPA + uses: open-policy-agent/setup-opa@v2 + with: + version: 0.68.0 + + - name: Terraform Init + run: terraform -chdir=terraform/environments/${{ matrix.env }} init -backend=false + + - name: Terraform Plan (JSON output) + run: | + terraform -chdir=terraform/environments/${{ matrix.env }} plan \ + -out=tfplan.binary + terraform -chdir=terraform/environments/${{ matrix.env }} show \ + -json tfplan.binary > tfplan.json + + - name: OPA Policy Evaluation — Terraform Plan + id: opa-check + run: | + opa eval \ + --data policies/terraform/ \ + --input tfplan.json \ + --format pretty \ + 'data.terraform.governance.violations' > opa-results.json + + VIOLATIONS=$(jq '.result[0].expressions[0].value | length' opa-results.json) + echo "violations=$VIOLATIONS" >> $GITHUB_OUTPUT + + if [ "$VIOLATIONS" -gt 0 ]; then + echo "::error::OPA policy violations detected: $VIOLATIONS" + jq '.result[0].expressions[0].value' opa-results.json + exit 1 + fi + + - name: OPA Policy Evaluation — Kafka ACLs + run: | + opa test policies/kafka-acl/ -v --coverage \ + --threshold 95 + + - name: Generate Governance Evidence + if: success() + run: | + jq -n \ + --arg plan_hash "$(sha256sum tfplan.json | cut -d' ' -f1)" \ + --arg opa_result "PASS" \ + --arg violations "0" \ + --arg timestamp "$(date -u +%Y-%m-%dT%H:%M:%SZ)" \ + --arg pr "${{ github.event.pull_request.number }}" \ + '{planHash: $plan_hash, opaResult: $opa_result, violations: ($violations|tonumber), timestamp: $timestamp, prNumber: ($pr|tonumber)}' \ + > governance-evidence.json + + - name: Comment PR with Governance Status + uses: actions/github-script@v7 + with: + script: | + const fs = require('fs'); + const evidence = JSON.parse(fs.readFileSync('governance-evidence.json')); + const body = `## Kafka ACL Governance Gate ✅ + | Check | Result | + |---|---| + | Terraform Plan | Valid | + | OPA Policy Violations | ${evidence.violations} | + | Kafka ACL Compliance | PASS | + | Evidence Hash | \`${evidence.planHash.substring(0,16)}...\` | + | Timestamp | ${evidence.timestamp} |`; + github.rest.issues.createComment({ + owner: context.repo.owner, + repo: context.repo.repo, + issue_number: context.issue.number, + body: body + }); + + strategy: + matrix: + env: [staging, production] +``` + +#### 7.4.2 Drift Detection + +```yaml +# .github/workflows/drift-detection.yml +name: Governance Drift Detection + +on: + schedule: + - cron: '0 * * * *' # Hourly + workflow_dispatch: + +jobs: + drift-detect: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + + - name: Terraform Plan (Detect Drift) + run: | + terraform -chdir=terraform/environments/production init + terraform -chdir=terraform/environments/production plan \ + -detailed-exitcode -out=drift-plan.binary 2>&1 || EXIT_CODE=$? + + if [ "$EXIT_CODE" == "2" ]; then + echo "DRIFT_DETECTED=true" >> $GITHUB_ENV + terraform show -json drift-plan.binary > drift-plan.json + fi + + - name: Evaluate Drift Severity + if: env.DRIFT_DETECTED == 'true' + run: | + opa eval \ + --data policies/terraform/drift_detection.rego \ + --input drift-plan.json \ + 'data.terraform.drift.severity' > drift-severity.json + + SEVERITY=$(jq -r '.result[0].expressions[0].value' drift-severity.json) + echo "DRIFT_SEVERITY=$SEVERITY" >> $GITHUB_ENV + + - name: Alert on Critical Drift + if: env.DRIFT_SEVERITY == 'CRITICAL' + run: | + curl -X POST "${{ secrets.PAGERDUTY_WEBHOOK }}" \ + -H 'Content-Type: application/json' \ + -d '{"routing_key":"${{ secrets.PD_KEY }}","event_action":"trigger","payload":{"summary":"CRITICAL: Kafka ACL governance drift detected","severity":"critical","source":"drift-detection"}}' + + - name: Generate Drift Evidence Bundle + if: env.DRIFT_DETECTED == 'true' + run: | + ./scripts/drift-detect.sh \ + --plan drift-plan.json \ + --severity "$DRIFT_SEVERITY" \ + --output evidence/drift-$(date +%Y%m%d-%H%M).json +``` + +#### 7.4.3 Five CI/CD Governance Gates + +| Gate | Trigger | Policy Check | Blocks On | +|---|---|---|---| +| G1: Terraform Plan | Pull request | OPA terraform governance rules | Any violation | +| G2: Kafka ACL Validation | Pull request | Kafka ACL Rego test suite (≥95% coverage) | Test failure | +| G3: Schema Compatibility | Schema change PR | Schema Registry compatibility check | Breaking change | +| G4: Apply + Evidence | Merge to main | Post-apply evidence generation + signing | Apply failure | +| G5: Drift Detection | Hourly schedule | Terraform plan -detailed-exitcode + OPA drift rules | CRITICAL severity alert | + +--- + +## 8. Auditor Workflows + +### 8.1 Workflow Overview + +The system supports three auditor workflow modes designed for different regulatory contexts: + +| Mode | Use Case | Access Method | Typical Duration | +|---|---|---|---| +| Self-Service Evidence Retrieval | Routine audit, surveillance | Auditor portal + CLI | 1–4 hours | +| Guided Audit Walkthrough | Comprehensive annual audit (ISO 42001, SOC 2) | Auditor portal + dedicated session | 2–5 days | +| Regulatory Examination | Supervisory examination (Fed, OCC, ECB) | Dedicated secure room + full export | 1–4 weeks | + +### 8.2 Self-Service Evidence Retrieval + +```bash +# Auditor authenticates via SSO + MFA +$ kafka-gov-verify auth login --method saml --idp okta + +# List available evidence bundles for a specific AI system +$ kafka-gov-verify list \ + --system AI-CREDIT-SCORING-001 \ + --framework SR_11_7 \ + --from 2025-Q4 --to 2026-Q1 + +Found 12 bundles: + EB-2025-10-01-SR117-CreditScore-001 [QUARTERLY REVIEW] ✓ Signed + EB-2025-10-15-SR117-CreditScore-002 [MODEL CHANGE] ✓ Signed + EB-2025-11-01-SR117-CreditScore-003 [BIAS ALERT RESPONSE] ✓ Signed + ... + +# Download and verify a bundle +$ kafka-gov-verify download \ + --bundle-id EB-2025-10-01-SR117-CreditScore-001 \ + --output ./audit-evidence/ \ + --verify + +✓ Downloaded 14 files (2.8 MB) +✓ Manifest signature verified +✓ Hash chain verified (links to previous bundle) +✓ All evidence files integrity verified + +# Generate gap analysis against a specific framework +$ kafka-gov-verify gap-analysis \ + --system AI-CREDIT-SCORING-001 \ + --framework ISO_42001 \ + --output gap-report.pdf + +Generated gap analysis: 38/42 controls fully evidenced, 4 partial (A.7.3, A.8.2, A.9.1, A.10.1) +``` + +### 8.3 Guided Audit Session + +For comprehensive audits, the system provides a web-based auditor portal with: + +1. **Evidence Navigator**: Browse evidence by framework, system, time period, or control +2. **Control Mapping View**: See which evidence satisfies which regulatory controls +3. **Hash Chain Explorer**: Visually verify the integrity chain of evidence bundles +4. **Real-Time Dashboard**: View live compliance metrics, policy evaluation rates, and alert status +5. **Export Suite**: Generate regulatory-formatted reports (PDF, CSV, JSON) +6. **Annotation System**: Auditors can annotate evidence with findings (stored immutably) + +### 8.4 Regulatory Examination Mode + +For supervisory examinations, the system provides: + +1. **Dedicated Secure Environment**: Isolated network segment with auditor workstations +2. **Full Data Export**: Complete Kafka event history for specified systems and timeframes +3. **Raw Access**: Direct ksqlDB query access (read-only) to governance event streams +4. **Verification Tools**: Pre-installed kafka-gov-verify CLI on auditor workstations +5. **Dedicated Support**: Assigned compliance engineer for technical queries +6. **Evidence Room**: Physical or virtual room with all printed evidence for sign-off + +--- + +## 9. Operational Metrics & SLAs + +### 9.1 System Performance + +| Metric | Target | Measured | Status | +|---|---|---|---| +| Kafka Throughput | 45,000 events/sec | 47,200 events/sec | EXCEEDING | +| Kafka P99 Latency | <15ms | 12ms | MEETING | +| OPA Evaluation P50 | <1ms | 0.8ms | MEETING | +| OPA Evaluation P99 | <5ms | 4.2ms | MEETING | +| Evidence Bundle Generation P99 | <10s | 4.8s | EXCEEDING | +| Evidence Signing Latency | <500ms | 280ms | EXCEEDING | +| Hash Chain Verification (100 bundles) | <30s | 18s | EXCEEDING | +| Drift Detection Cycle | <5 min | 3.2 min | EXCEEDING | +| WORM S3 Upload P99 | <2s | 1.4s | EXCEEDING | +| System Availability | 99.99% | 99.997% | EXCEEDING | + +### 9.2 Compliance Metrics + +| Metric | Value | Trend | +|---|---|---| +| OPA Policy Coverage | 312 rules across 11 groups | +34 rules QoQ | +| Daily Policy Evaluations | 1.2M | +18% QoQ | +| Sentinel Rules Active | 847 across 22 AI systems | +52 rules QoQ | +| Evidence Bundles Generated (Monthly) | 148 | Stable | +| Audit Findings (Annualised) | 3 (down from 9.4) | -68% YoY | +| Evidence Assembly Time | 4.3 hours (was 72 hours) | -94% | +| Compliance Cost (Annual) | $1.2M (was $4.8M) | -75% at scale | +| Regulatory Fine Exposure Reduction | $12–28M estimated | Continuous improvement | + +### 9.3 Risk Register + +| ID | Risk | Likelihood | Impact | Score | Mitigation | Owner | +|---|---|---|---|---|---|---| +| KR-001 | Kafka cluster outage disrupts evidence generation | LOW | CRITICAL | HIGH | Multi-AZ deployment, cross-region replication, 72h evidence buffer | VP Platform | +| KR-002 | OPA policy misconfiguration blocks legitimate access | MEDIUM | HIGH | HIGH | Policy staging environment, canary deployment, break-glass override | VP AI Governance | +| KR-003 | WORM storage corruption or unavailability | VERY LOW | CRITICAL | MEDIUM | Cross-region replication, 11-nines durability, daily integrity checks | CISO | +| KR-004 | Schema Registry incompatible change breaks consumers | LOW | HIGH | MEDIUM | BACKWARD_TRANSITIVE enforcement, dual-write migration, RFC process | Chief Architect | +| KR-005 | HSM key compromise affects evidence signing integrity | VERY LOW | CRITICAL | MEDIUM | Key rotation, multi-party key generation, HSM FIPS 140-3 Level 3 | CISO | +| KR-006 | Drift detection false positive triggers unnecessary remediation | MEDIUM | LOW | LOW | Severity classification, human approval for remediation, drift dashboard | SRE Lead | +| KR-007 | Regulatory framework changes invalidate existing policies | MEDIUM | HIGH | HIGH | Regulatory monitoring service, quarterly policy refresh, legal liaison | General Counsel | +| KR-008 | Evidence bundle generation falls behind event volume | LOW | HIGH | MEDIUM | Auto-scaling, batch processing fallback, alert on queue depth | VP Platform | + +--- + +## 10. Investment & ROI + +### 10.1 Cost Breakdown + +| Category | Year 1 | Year 2 | Year 3 | Year 4 | Year 5 | +|---|---|---|---|---|---| +| Infrastructure (Kafka, S3, OPA, HSM) | $480K | $420K | $390K | $360K | $340K | +| Engineering (Build + Maintain) | $1,200K | $600K | $480K | $420K | $380K | +| Licensing (Confluent, HSM, Monitoring) | $320K | $340K | $360K | $380K | $400K | +| Compliance Operations | $280K | $240K | $200K | $180K | $160K | +| **Total Annual** | **$2,280K** | **$1,600K** | **$1,430K** | **$1,340K** | **$1,280K** | + +### 10.2 Savings & ROI + +| Metric | Value | +|---|---| +| 5-Year Total Investment | $7.93M | +| 5-Year Compliance Cost Without Engine | $24.0M | +| 5-Year Net Savings | $16.07M | +| NPV (8% discount rate) | $12.4M | +| IRR | 42.6% | +| Payback Period | 1.8 years | +| Annual Regulatory Fine Risk Avoided | $12–28M (estimated) | + +--- + +## 11. Implementation Roadmap + +### 11.1 30/60/90-Day Plan + +#### Days 1–30: Foundation + +| Week | Deliverable | Owner | Exit Criteria | +|---|---|---|---| +| 1–2 | Kafka cluster deployment (5-broker, 3-AZ) | Platform Eng. | Cluster healthy, mTLS enabled | +| 1–2 | SPIFFE/SPIRE deployment for AI governance services | Security Eng. | SVIDs issuing for all governance services | +| 2–3 | Core topic creation (12 topics) with ACL enforcement | Platform Eng. | All topics created, ACLs applied | +| 3–4 | Schema Registry deployment + core schemas registered | Platform Eng. | Schemas registered, compatibility enforced | +| 3–4 | WORM S3 bucket provisioned with Object Lock | Cloud Eng. | Bucket operational, COMPLIANCE mode verified | + +#### Days 31–60: Compliance Engine + +| Week | Deliverable | Owner | Exit Criteria | +|---|---|---|---| +| 5–6 | OPA Kafka Authorizer deployed and tested | Platform Eng. | Authorizer active on all brokers, tests passing | +| 5–6 | OPA policy bundle (Phase 1: 180 rules) deployed | AI Governance | 180 rules active, evaluation P99 < 5ms | +| 6–7 | Compliance Engine (Kafka Streams app) deployed | Platform Eng. | Consuming all 12 topics, correlating events | +| 7–8 | Evidence bundle generator operational | Compliance Eng. | First SR 11-7 bundle generated and signed | +| 7–8 | Verification CLI v1.0 released | DevTools | CLI can verify bundles, hash chains | + +#### Days 61–90: Auditor Readiness + +| Week | Deliverable | Owner | Exit Criteria | +|---|---|---|---| +| 9–10 | OPA policy bundle (Phase 2: 312 rules complete) | AI Governance | All 312 rules active across 11 groups | +| 9–10 | Auditor portal v1.0 deployed | Compliance Eng. | Self-service evidence retrieval operational | +| 10–11 | Terraform IaC complete (8 modules) | Platform Eng. | All infrastructure managed via Terraform | +| 11–12 | CI/CD governance gates operational (5 gates) | DevOps | All 5 gates active on governance repository | +| 12 | Drift detection operational (hourly) | SRE | Drift alerts operational, PagerDuty integrated | +| 12 | Internal audit dry-run (ISO 42001) | Compliance | Dry run complete, findings remediated | + +### 11.2 8-Week Fast-Track Plan + +For institutions requiring accelerated deployment: + +| Week | Focus | Critical Path Items | +|---|---|---| +| 1 | Infrastructure | Kafka cluster + mTLS + 6 core topics + WORM S3 | +| 2 | Identity & ACLs | SPIFFE/SPIRE + OPA Kafka Authorizer + core ACLs | +| 3 | Schema & Streaming | Schema Registry + ksqlDB + governance event schemas | +| 4 | Policy Engine | OPA cluster + Phase 1 policies (180 rules) + Sentinel integration | +| 5 | Compliance Engine | Kafka Streams compliance app + evidence generator | +| 6 | Evidence & Signing | HSM integration + Ed25519 signing + WORM archival + verification CLI | +| 7 | IaC & CI/CD | Terraform 8 modules + 5 governance gates + drift detection | +| 8 | Auditor Readiness | Auditor portal + full policy set (312 rules) + dry-run audit | + +--- + +## 12. Machine-Readable Artifacts + +This whitepaper is accompanied by machine-readable artifacts for direct engineering use: + +| Artifact | Format | Path | Purpose | +|---|---|---|---| +| Kafka ACL Matrix | JSON | `artifacts/data/kafka-acl-matrix.json` | Topic-level ACL configuration | +| Governance Event Schema | Avro/JSON | `artifacts/schemas/governance-event.avsc` | Kafka event schema | +| Evidence Bundle Manifest Schema | JSON Schema | `artifacts/schemas/evidence-bundle-manifest.schema.json` | Evidence bundle validation | +| Kafka ACL OPA Policy | Rego | `artifacts/policies/kafka_acl_governance.rego` | OPA Kafka Authorizer policy | +| Basel III Model Risk Policy | Rego | `artifacts/policies/basel_iii_model_risk.rego` | Basel III CRE compliance rules | +| Compliance Controls Matrix | CSV | `artifacts/data/kafka-compliance-controls.csv` | Multi-framework control mapping | +| Implementation Timeline | CSV | `artifacts/data/kafka-governance-timeline.csv` | 90-day implementation schedule | +| Terraform Module Spec | HCL/JSON | `artifacts/templates/kafka-governance-terraform.json` | Terraform module configuration | + +--- + +## Appendix A: Glossary + +| Term | Definition | +|---|---| +| ACL | Access Control List — defines which principals can perform which operations on which resources | +| ARS | AI Risk Score — weighted composite score across 12 risk dimensions | +| CCE | Continuous Compliance Engine — Kafka Streams application for real-time compliance evaluation | +| CRE | Credit Risk Evaluation (Basel III sections 30–36) | +| DI | Disparate Impact — fairness metric where DI ≥ 0.80 indicates compliance | +| EARL | Enterprise AI Readiness Level (1–5 scale) | +| G-SIFI | Global Systemically Important Financial Institution | +| HSM | Hardware Security Module — tamper-resistant hardware for cryptographic key storage | +| OPA | Open Policy Agent — general-purpose policy engine | +| SPIFFE | Secure Production Identity Framework for Everyone — workload identity standard | +| SVID | SPIFFE Verifiable Identity Document | +| WORM | Write-Once-Read-Many — immutable storage mode for regulatory compliance | + +## Appendix B: Regulatory Reference Table + +| Framework | Issuer | Version/Date | Key Sections | Engine Coverage | +|---|---|---|---|---| +| EU AI Act | European Parliament | Regulation 2024/1689 | Art. 5–14, 52, 60, 62 | 68 OPA rules | +| NIST AI RMF | NIST | AI 100-1 (Jan 2023) | GOVERN, MAP, MEASURE, MANAGE | Full function mapping | +| ISO/IEC 42001 | ISO | 2023 | Annex A (A.5–A.10) | 38 OPA rules, evidence bundles | +| Basel III | BCBS | CRE 30–36 (2025 finalisation) | CRE 30.2, 31, 33, 35, 36 | 28 OPA rules | +| SR 11-7 | Fed/OCC | 2011 (2024 enhanced guidance) | §3–§12 | 42 OPA rules, model documentation | +| GDPR | European Parliament | Regulation 2016/679 | Art. 5, 17, 22, 30, 35 | 26 OPA rules, consent/erasure topics | +| FCRA | US Congress | 15 U.S.C. §1681 | §607, §615 | Fairness rules, adverse action evidence | +| ECOA | US Congress | 15 U.S.C. §1691 | §701–§706 | DI monitoring, fair lending evidence | + + diff --git a/rag-agentic-dashboard/public/governance-architectures-frameworks.html b/rag-agentic-dashboard/public/governance-architectures-frameworks.html new file mode 100644 index 00000000..ffe1e5fc --- /dev/null +++ b/rag-agentic-dashboard/public/governance-architectures-frameworks.html @@ -0,0 +1,331 @@ + + + + + +GAF-GSIFI-WP-017 | AGI/ASI Governance Architectures & Frameworks + + + + +
+
+ GAF-GSIFI-WP-017 + v1.0.0 + 2026-04-03 + CONFIDENTIAL +
+

AGI/ASI Governance Architectures & Frameworks

+
Comprehensive Implementation Reference (2026-2030) | 7 Domains | 8 Regulatory Frameworks | 5 Reference Architectures | 15 Global Components
+
+ +
Loading KPIs...
+ +
+ + +
+

🏛 Seven Governance Domains

+
Loading domains...
+
+ +
+ +
+

🏠 D1: Multilayered Governance Architecture

+ +
LayerFunctionOwner
Loading...
+

14-Dimension Risk Taxonomy (ARS)

+
Loading ARS...
+
+ + +
+

D2: Multi-Regime Regulatory Alignment

+ +
FrameworkJurisdictionOPA RulesStatus
Loading...
+

ISO/IEC 42001 AIMS Roadmap

+
Loading...
+
+
+ +
+ +
+

🖧 D3: Reference Architectures & Trust Stack

+ +
IDArchitectureKey Scale Metric
Loading...
+

7-Layer Trust & Compliance Stack

+ +
LayerFunctionMetric
Loading...
+
+ + +
+

🌍 D4: Global Compute & Governance Components

+ +
IDAcronymFunctionStatus
Loading...
+
+
+ +
+ +
+

🏦 D5: Financial Services

+

Fair Lending DI Tests

+ +
ClassDIStatus
Loading...
+

EARL Assessment

+
Loading...
+
+ + +
+

🛡 D6: AGI Safety & Trust-by-Design

+

AI Evolution Model

+ +
StageNameARL
Loading...
+
+ + +
+

📐 D7: Master Blueprint

+

AGI Readiness Layers

+
Loading...
+

8-Week Plan

+ +
WeekFocusCriteria
Loading...
+
+
+ +
+ +
+

💰 Investment & Returns

+ +
YearInvestmentCumulativeMilestones
Loading...
+

Financial Returns

+
Loading...
+
+ + +
+

Risk Register (Top 12)

+ +
IDRiskScoreOwner
Loading...
+
+
+ + +
+

📅 30 / 60 / 90-Day Enterprise Rollout

+
Loading rollout...
+
+ +
+ + + + + + diff --git a/rag-agentic-dashboard/public/governance-index.html b/rag-agentic-dashboard/public/governance-index.html new file mode 100644 index 00000000..53ccc4bc --- /dev/null +++ b/rag-agentic-dashboard/public/governance-index.html @@ -0,0 +1,388 @@ + + + + + +Unified AI Governance Index | Institutional-Grade G-SIFI Framework + + + +
+
+
UGI-GSIFI-2026-04-05 | UNIFIED GOVERNANCE INDEX v1.0.0
+

Unified AI Governance Index

+

Master navigational index unifying all governance modules across 8 pillars, 8 regulatory frameworks, 19+ reports, 34+ dashboards, 580+ API endpoints, and 32+ machine-readable artifacts for institutional-grade G-SIFI AI governance.

+
+
+
+ +
+ +
+
1Platform Statistics
+
Loading statistics...
+
+ + +
+
2Eight Governance Pillars
+
Loading pillars...
+
+ + +
+
3Regulatory Framework Alignment (8 Frameworks)
+
Loading regulatory data...
+
+ + +
+
4Cross-Module Regulatory Alignment Matrix
+
Loading alignment matrix...
+
+ + +
+
5ICGC Sentinel Platform (15 Global Components)
+
Loading components...
+
+ + +
+
6Companion Documents (19 Reports)
+
Loading reports...
+
+ + +
+
7Interactive Dashboards
+
Loading dashboards...
+
+ + +
+
8Machine-Readable Artifacts
+
Loading artifacts...
+
+ + +
+
9Evidence Chain & Compliance Engine
+
Loading evidence chain...
+
+ + +
+
10API Module Reference
+
Loading API reference...
+
+
+ + + + + + diff --git a/rag-agentic-dashboard/public/kafka-acl-governance.html b/rag-agentic-dashboard/public/kafka-acl-governance.html new file mode 100644 index 00000000..659a8087 --- /dev/null +++ b/rag-agentic-dashboard/public/kafka-acl-governance.html @@ -0,0 +1,294 @@ + + + + + +KACG-GSIFI-WP-017 | Kafka ACL Governance & Continuous Compliance Engine + + + +
+
+
KACG-GSIFI-WP-017 v1.0.0
+

Kafka ACL Governance & Continuous Compliance Engine

+

Production-grade Kafka ACL governance, continuous compliance engine with cryptographically signed evidence bundles, OPA policy-as-code, WORM S3 archival, Terraform IaC, and auditor workflows for G-SIFI institutions.

+
+
+
+ +
+ +
+
Key Performance Indicators
+
Loading KPIs...
+
+ + +
+
Governed Kafka Topics (12 Topics)
+
Loading topics...
+
+ + +
+
Continuous Compliance Engine Pipeline
+
Loading pipeline...
+
+ + +
+
+

P OPA Policy Framework (312 Rules)

+
Loading...
+
+
+

R Regulatory Frameworks (8)

+
Loading...
+
+
+ + +
+
+

E Evidence Bundle Types (8)

+
Loading...
+
+
+

S WORM S3 Storage & Retention

+
Loading...
+
+
+ + +
+
Multi-Framework Compliance Control Matrix
+
Loading control matrix...
+
+ + +
+
+

T Terraform Modules (8)

+
Loading...
+
+
+

G CI/CD Governance Gates (5)

+
Loading...
+
+
+ + +
+
Risk Register
+
Loading risks...
+
+ + +
+
8-Week Fast-Track Implementation Plan
+
Loading rollout...
+
+ + +
+
+

$ Investment & ROI

+
Loading...
+
+
+

A Auditor Workflow Modes

+
Loading...
+
+
+ + +
+
Machine-Readable Governance Artifacts (20 Artifacts)
+
Loading artifacts...
+
+
+ + + + + + diff --git a/rag-agentic-dashboard/server.js b/rag-agentic-dashboard/server.js index 40880e4e..6a293bfb 100644 --- a/rag-agentic-dashboard/server.js +++ b/rag-agentic-dashboard/server.js @@ -10952,6 +10952,9 @@ const AGMB = AGI_GOVERNANCE_MASTER_BLUEPRINT; // ─── AGMB API ROUTES ──────────────────────────────────────────────────────── +// Root +app.get('/api/agi-governance-master-blueprint', (req, res) => res.json(AGMB)); + // Metadata app.get('/api/agi-governance-master-blueprint/metadata', (req, res) => res.json(AGMB.metadata)); @@ -11100,6 +11103,1967 @@ app.get('/api/agi-governance-master-blueprint/artifacts', (req, res) => res.json })); +// ══════════════════════════════════════════════════════════════════════════════ +// SECTION 8F: KAFKA ACL GOVERNANCE & CONTINUOUS COMPLIANCE ENGINE (KACG-GSIFI-WP-017) +// ══════════════════════════════════════════════════════════════════════════════ + +const KAFKA_ACL_GOVERNANCE = { + metadata: { + docRef: 'KACG-GSIFI-WP-017', + title: 'Kafka ACL Governance & Continuous Compliance Engine for G-SIFI AI Systems', + subtitle: 'Production Architecture, Policy Framework & Auditor Workflows (2026-2030)', + version: '1.0.0', + date: '2026-04-03', + classification: 'CONFIDENTIAL — Board / C-Suite / Regulators / EA / Platform Eng / Audit', + authors: ['Chief Software Architect', 'CISO', 'VP AI Governance', 'Head of Model Risk', 'General Counsel'], + audience: ['C-Suite', 'Board AI Sub-committee', 'Regulators', 'Enterprise Architects', 'Platform Engineers', 'Audit Teams', 'Compliance Officers'], + scope: { + kafkaTopics: 12, + opaRules: 312, + opaPolicyGroups: 11, + sentinelRules: 847, + aiSystems: 22, + regulatoryFrameworks: 8, + jurisdictions: 4, + terraformModules: 8, + cicdGates: 5, + auditorWorkflows: 3, + apiEndpoints: 62, + machineReadableArtifacts: 8, + evidenceBundleTypes: 8, + dailyPolicyEvaluations: '1.2M', + eventThroughput: '45,000 events/sec' + }, + companionDocs: [ + { ref: 'AGMB-GSIFI-WP-016', title: 'AGI Governance Master Blueprint', relationship: 'Parent architecture' }, + { ref: 'PMREF-GSIFI-WP-015', title: 'Practitioner Master Reference', relationship: 'Enterprise governance context' }, + { ref: 'COMP-REG-WP-006', title: 'G-SIFI Regulatory Compliance', relationship: 'Regulatory mapping source' }, + { ref: 'TRAJ-SENT-WP-008', title: 'Trajectory AI Sentinel Governance', relationship: 'Sentinel integration' }, + { ref: 'ARCH-ENT-WP-002', title: 'Enterprise AI Architecture Security', relationship: 'Security architecture' }, + { ref: 'GOV-GSIFI-WP-001', title: 'G-SIFI AI Governance Foundation', relationship: 'Foundational framework' } + ] + }, + + kpis: [ + { name: 'Kafka Throughput', current: '47,200 events/sec', target: '45,000 events/sec', status: 'EXCEEDING' }, + { name: 'Kafka P99 Latency', current: '12ms', target: '<15ms', status: 'MEETING' }, + { name: 'OPA Evaluation P50', current: '0.8ms', target: '<1ms', status: 'MEETING' }, + { name: 'OPA Evaluation P99', current: '4.2ms', target: '<5ms', status: 'MEETING' }, + { name: 'Evidence Bundle Generation P99', current: '4.8s', target: '<10s', status: 'EXCEEDING' }, + { name: 'Evidence Signing Latency', current: '280ms', target: '<500ms', status: 'EXCEEDING' }, + { name: 'Hash Chain Verification (100 bundles)', current: '18s', target: '<30s', status: 'EXCEEDING' }, + { name: 'Drift Detection Cycle', current: '3.2 min', target: '<5 min', status: 'EXCEEDING' }, + { name: 'WORM S3 Upload P99', current: '1.4s', target: '<2s', status: 'EXCEEDING' }, + { name: 'System Availability', current: '99.997%', target: '99.99%', status: 'EXCEEDING' }, + { name: 'OPA Policy Coverage', current: '312 rules', target: '280+ rules', status: 'EXCEEDING' }, + { name: 'Daily Policy Evaluations', current: '1.2M', target: '1.0M', status: 'EXCEEDING' }, + { name: 'Audit Findings (Annualised)', current: '3', target: '<5', status: 'MEETING' }, + { name: 'Evidence Assembly Time', current: '4.3 hours', target: '<8 hours', status: 'EXCEEDING' } + ], + + // ─── KAFKA CLUSTER ARCHITECTURE ────────────────────────────────────────────── + kafkaCluster: { + version: 'Apache Kafka 3.8', + brokers: 5, + availabilityZones: 3, + replicationFactor: 3, + minInsyncReplicas: 2, + authentication: 'mTLS + SPIFFE SVIDs', + authorizer: 'Custom OPA Kafka Authorizer', + schemaRegistry: { technology: 'Confluent Schema Registry 7.6', compatibility: 'BACKWARD_TRANSITIVE' }, + throughput: { sustained: '45,000 events/sec', peak: '72,000 events/sec', p99Latency: '12ms' }, + availability: { target: '99.99%', measured: '99.997%', mttr: '4.2 min' }, + topics: [ + { name: 'ai.inference.events', partitions: 24, rf: 3, isr: 2, retention: '10 years', producerAcl: 'inference-engine-*, sentinel-platform', consumerAcl: 'compliance-engine, ksqldb-analytics, evidence-generator', transactional: false }, + { name: 'ai.training.events', partitions: 12, rf: 3, isr: 2, retention: '10 years', producerAcl: 'mlops-pipeline, model-registry', consumerAcl: 'compliance-engine, ksqldb-analytics, sentinel-platform', transactional: true }, + { name: 'ai.governance.decisions', partitions: 12, rf: 3, isr: 2, retention: '10 years', producerAcl: 'opa-engine, sentinel-platform, caio-portal', consumerAcl: 'compliance-engine, evidence-generator, audit-portal', transactional: true }, + { name: 'ai.model.promotions', partitions: 6, rf: 3, isr: 2, retention: '10 years', producerAcl: 'model-registry, mlops-pipeline', consumerAcl: 'compliance-engine, sentinel-platform, evidence-generator', transactional: true }, + { name: 'ai.bias.alerts', partitions: 6, rf: 3, isr: 2, retention: '10 years', producerAcl: 'sentinel-platform, fairness-monitor', consumerAcl: 'compliance-engine, caio-portal, cro-dashboard', transactional: false }, + { name: 'ai.drift.detections', partitions: 6, rf: 3, isr: 2, retention: '10 years', producerAcl: 'sentinel-platform, monitoring-service', consumerAcl: 'compliance-engine, model-registry, opa-engine', transactional: false }, + { name: 'ai.sentinel.evaluations', partitions: 24, rf: 3, isr: 2, retention: '10 years', producerAcl: 'sentinel-platform', consumerAcl: 'compliance-engine, ksqldb-analytics, evidence-generator', transactional: false }, + { name: 'ai.compliance.evidence', partitions: 12, rf: 3, isr: 2, retention: '10 years', producerAcl: 'evidence-generator (EXCLUSIVE)', consumerAcl: 'audit-portal, regulator-portal, compliance-engine', transactional: true }, + { name: 'ai.agent.telemetry', partitions: 12, rf: 3, isr: 2, retention: '10 years', producerAcl: 'agent-orchestrator, behavioral-sidecar', consumerAcl: 'compliance-engine, sentinel-platform, safety-monitor', transactional: false }, + { name: 'ai.killswitch.events', partitions: 3, rf: 3, isr: 3, retention: 'PERMANENT', producerAcl: 'kill-switch-controller (EXCLUSIVE)', consumerAcl: 'ALL governance services, board-dashboard', transactional: true }, + { name: 'ai.consent.changes', partitions: 6, rf: 3, isr: 2, retention: 'GDPR: 5 years', producerAcl: 'consent-management-platform', consumerAcl: 'compliance-engine, erasure-controller, privacy-engine', transactional: true }, + { name: 'ai.erasure.requests', partitions: 6, rf: 3, isr: 2, retention: 'GDPR: 5 years', producerAcl: 'consent-management-platform, dpo-portal', consumerAcl: 'erasure-controller, compliance-engine, evidence-generator', transactional: true } + ] + }, + + // ─── ACL GOVERNANCE ────────────────────────────────────────────────────────── + aclGovernance: { + identityLayer: { + technology: 'SPIFFE/SPIRE + mTLS', + trustDomain: 'gsifi.example.com', + svidFormat: 'spiffe://gsifi.example.com/ai-governance///', + components: [ + { component: 'Trust Domain', purpose: 'Organisation root', example: 'gsifi.example.com' }, + { component: 'Environment', purpose: 'Deployment tier', example: 'production, staging, sandbox' }, + { component: 'Service', purpose: 'Logical service identity', example: 'inference-engine-credit, sentinel-platform' }, + { component: 'Instance', purpose: 'Unique workload instance', example: 'pod-7f8d9a2b, vm-prod-03' } + ] + }, + aclTaxonomy: [ + { type: 'Topic PRODUCE', scope: 'Per-topic write access', governanceUse: 'Controls which services emit governance events', opaGroup: 'kafka.acl.produce' }, + { type: 'Topic CONSUME', scope: 'Per-topic read access', governanceUse: 'Controls which services read event streams', opaGroup: 'kafka.acl.consume' }, + { type: 'Consumer Group', scope: 'Group membership', governanceUse: 'Ensures governed consumer group assignment', opaGroup: 'kafka.acl.group' }, + { type: 'Transactional', scope: 'Exactly-once semantics', governanceUse: 'Required for evidence bundle atomicity', opaGroup: 'kafka.acl.transaction' }, + { type: 'Cluster', scope: 'Cluster-level operations', governanceUse: 'Restricted to platform SRE team only', opaGroup: 'kafka.acl.cluster' }, + { type: 'Delegation Token', scope: 'Token-based auth fallback', governanceUse: 'Emergency break-glass access', opaGroup: 'kafka.acl.delegation' } + ], + authorizerConfig: { + class: 'com.gsifi.kafka.governance.OpaKafkaAuthorizer', + opaUrl: 'https://opa.internal.gsifi.example.com:8181/v1/data/kafka/authz/allow', + allowOnError: false, + cacheTtlMs: 30000, + cacheMaxSize: 10000, + connectionTimeoutMs: 500, + readTimeoutMs: 1000, + superUsers: ['User:CN=kafka-admin', 'User:CN=break-glass-emergency'] + }, + breakGlass: { + activationRequires: 'Dual approval (CISO + VP AI Governance)', + maxDuration: '4 hours', + auditTrail: 'All break-glass actions logged to ai.governance.decisions with type BREAK_GLASS', + postMortem: 'Mandatory within 24 hours of activation' + } + }, + + // ─── OPA POLICY FRAMEWORK ─────────────────────────────────────────────────── + opaPolicyFramework: { + version: 'OPA v0.68', + totalRules: 312, + policyGroups: [ + { group: 'kafka.acl.*', prefix: 'K-', rules: 34, scope: 'Topic/consumer/transactional ACLs', evalFrequency: 'Per-request (P99: 1.2ms)' }, + { group: 'compliance.euAiAct.*', prefix: 'EA-', rules: 68, scope: 'EU AI Act Art. 5-14 mapping', evalFrequency: 'Per-event + Daily batch' }, + { group: 'compliance.sr117.*', prefix: 'SR-', rules: 42, scope: 'Model validation, documentation, monitoring', evalFrequency: 'Per-model-event + Quarterly' }, + { group: 'compliance.iso42001.*', prefix: 'ISO-', rules: 38, scope: 'Annex A controls, AIMS evidence', evalFrequency: 'Per-event + Annual' }, + { group: 'compliance.baselIII.*', prefix: 'BAS-', rules: 28, scope: 'CRE 30-36, capital adequacy', evalFrequency: 'Quarterly + Per-model-change' }, + { group: 'data.privacy.*', prefix: 'DP-', rules: 26, scope: 'GDPR Art. 5, 17, 22, 30, 35', evalFrequency: 'Per-PII-event' }, + { group: 'fairness.disparateImpact.*', prefix: 'FI-', rules: 28, scope: 'DI thresholds, FCRA/ECOA', evalFrequency: 'Weekly batch + Per-alert' }, + { group: 'lifecycle.model.*', prefix: 'LM-', rules: 18, scope: 'Registration, validation, promotion, retirement', evalFrequency: 'Per-lifecycle-event' }, + { group: 'agent.governance.*', prefix: 'AG-', rules: 14, scope: 'Autonomous agent scope, kill-switch', evalFrequency: 'Real-time' }, + { group: 'monitoring.drift.*', prefix: 'MD-', rules: 12, scope: 'Performance/data/concept drift', evalFrequency: 'Hourly batch' }, + { group: 'evidence.integrity.*', prefix: 'EI-', rules: 4, scope: 'Evidence bundle completeness, signing', evalFrequency: 'Per-bundle' } + ], + performance: { p50: '0.8ms', p95: '2.1ms', p99: '4.2ms', throughput: '28,000 evaluations/sec', cacheHitRate: '72%', bundleSize: '2.4 MB (compressed)', bundleRefresh: 'Every 30 seconds' }, + deployment: { nodes: 3, primary: 1, replicas: 2, bundleStore: 'S3 + Signed Bundle Digest' } + }, + + // ─── CONTINUOUS COMPLIANCE ENGINE ─────────────────────────────────────────── + complianceEngine: { + technology: 'Kafka Streams + OPA + Custom Evidence Generator', + pipeline: [ + { stage: 1, name: 'Event Ingestion', description: 'Consume all 12 governance topics', output: 'Raw event stream' }, + { stage: 2, name: 'Schema Validation', description: 'Validate Avro schema conformance', output: 'Validated events (DLQ for malformed)' }, + { stage: 3, name: 'OPA Evaluation', description: 'Evaluate 312 rules across 11 policy groups', output: 'Policy decision log' }, + { stage: 4, name: 'Sentinel Correlation', description: 'Cross-event pattern matching (847 rules)', output: 'Alert generation, PagerDuty + CAIO' }, + { stage: 5, name: 'Evidence Accumulation', description: 'Aggregate policy decisions into evidence windows', output: 'Evidence accumulator DB' }, + { stage: 6, name: 'Evidence Bundle Generation', description: 'Produce regulatory-formatted evidence bundles', output: 'Unsigned evidence bundles' }, + { stage: 7, name: 'Signing Service', description: 'Ed25519 digital signature via HSM', output: 'Signed manifest + detached signature' }, + { stage: 8, name: 'WORM S3 Archival', description: 'Upload with Object Lock + hash chain link', output: 'Immutable evidence archive' } + ], + evidenceBundleTypes: [ + { type: 'SR_11_7_MODEL_DOCUMENTATION', driver: 'SR 11-7 §7', trigger: 'Model promotion, quarterly review', format: 'JSON + PDF' }, + { type: 'EU_AI_ACT_TECHNICAL_DOCUMENTATION', driver: 'EU AI Act Art. 11', trigger: 'Conformity assessment, annual', format: 'JSON + PDF' }, + { type: 'ISO_42001_AIMS_EVIDENCE', driver: 'ISO 42001 Annex A', trigger: 'Surveillance audit, annual', format: 'JSON + PDF' }, + { type: 'BASEL_III_MODEL_RISK_REPORT', driver: 'CRE 30-36', trigger: 'Quarterly, material model change', format: 'JSON + PDF' }, + { type: 'GDPR_DPIA', driver: 'GDPR Art. 35', trigger: 'High-risk processing, material change', format: 'JSON + PDF' }, + { type: 'INCIDENT_REPORT', driver: 'All frameworks', trigger: 'Incident trigger', format: 'JSON + PDF' }, + { type: 'BIAS_AUDIT_REPORT', driver: 'FCRA/ECOA, NYC LL 144', trigger: 'Annual, on-demand', format: 'JSON + CSV + PDF' }, + { type: 'CONTINUOUS_COMPLIANCE_DIGEST', driver: 'All frameworks', trigger: 'Daily (automated)', format: 'JSON' } + ] + }, + + // ─── EVIDENCE SIGNING & VERIFICATION ──────────────────────────────────────── + evidenceSigning: { + signingAlgorithm: 'Ed25519', + hashAlgorithm: 'SHA-256', + keyStorage: 'HSM (FIPS 140-3 Level 3)', + hashChain: 'Per-bundle SHA-256 linking to previous bundle', + merkleTree: 'Per-bundle Merkle tree of all evidence files', + signingLatency: '280ms (P50)', + keyRotation: 'Annual (multi-party key generation ceremony)', + verificationCli: { + tool: 'kafka-gov-verify', + language: 'Go', + commands: [ + { command: 'bundle', description: 'Verify a single evidence bundle (signature + merkle + hash chain + WORM lock)' }, + { command: 'chain', description: 'Verify hash chain integrity for a date range' }, + { command: 'report', description: 'Generate auditor-readable verification report (PDF)' }, + { command: 'list', description: 'List available evidence bundles by system, framework, date range' }, + { command: 'download', description: 'Download and verify a bundle' }, + { command: 'gap-analysis', description: 'Generate framework-specific gap analysis report' } + ] + } + }, + + // ─── WORM S3 STORAGE ─────────────────────────────────────────────────────── + wormStorage: { + technology: 'S3 Object Lock (Compliance Mode)', + bucketName: 'gsifi-compliance-evidence-prod', + region: 'eu-west-1', + encryption: 'AWS KMS (SSE-KMS)', + retentionDays: 3650, + objectLockMode: 'COMPLIANCE', + durability: '99.999999999% (11 nines)', + crossRegionReplication: { enabled: true, drRegion: 'us-east-1', drBucket: 'gsifi-compliance-evidence-dr' }, + lifecycleTiering: [ + { tier: 'Hot', timeframe: '0-90 days', storageClass: 'S3 Standard', costPerTbMonth: '$23.00', projectedVolume: '2.4 TB' }, + { tier: 'Warm', timeframe: '91-365 days', storageClass: 'Intelligent Tiering', costPerTbMonth: '$12.80', projectedVolume: '8.2 TB' }, + { tier: 'Cold', timeframe: '1-7 years', storageClass: 'Glacier Instant Retrieval', costPerTbMonth: '$4.00', projectedVolume: '42.6 TB' }, + { tier: 'Archive', timeframe: '7-10 years', storageClass: 'Glacier Deep Archive', costPerTbMonth: '$0.99', projectedVolume: '28.4 TB' } + ], + annualStorageCost: '$14,200', + retentionPolicies: [ + { regulation: 'SR 11-7', retention: '7 years', scope: 'All model decisions, validations, changes' }, + { regulation: 'GDPR Art. 30', retention: '5 years (or until erasure)', scope: 'Processing records involving personal data' }, + { regulation: 'EU AI Act Art. 12', retention: 'Lifetime + 10 years', scope: 'High-risk AI system logs' }, + { regulation: 'PRA SS1/23', retention: '7 years', scope: 'Model inventory, validation reports' }, + { regulation: 'MiFID II', retention: '5 years', scope: 'Algorithmic trading decisions' }, + { regulation: 'Basel III CRE 35', retention: '7 years', scope: 'Model risk documentation' } + ] + }, + + // ─── REGULATORY ALIGNMENT ────────────────────────────────────────────────── + regulatoryAlignment: { + frameworks: [ + { framework: 'EU AI Act', issuer: 'European Parliament', version: 'Regulation 2024/1689', keySections: 'Art. 5-14, 52, 60, 62', opaRules: 68, status: 'ACTIVE' }, + { framework: 'NIST AI RMF', issuer: 'NIST', version: 'AI 100-1 (Jan 2023)', keySections: 'GOVERN, MAP, MEASURE, MANAGE', opaRules: 'Full function mapping', status: 'ACTIVE' }, + { framework: 'ISO/IEC 42001', issuer: 'ISO', version: '2023', keySections: 'Annex A (A.5-A.10)', opaRules: 38, status: 'ACTIVE' }, + { framework: 'Basel III', issuer: 'BCBS', version: 'CRE 30-36 (2025 finalisation)', keySections: 'CRE 30.2, 31, 33, 35, 36', opaRules: 28, status: 'ACTIVE' }, + { framework: 'SR 11-7', issuer: 'Fed/OCC', version: '2011 (2024 enhanced guidance)', keySections: '§3-§12', opaRules: 42, status: 'ACTIVE' }, + { framework: 'GDPR', issuer: 'European Parliament', version: 'Regulation 2016/679', keySections: 'Art. 5, 17, 22, 30, 35', opaRules: 26, status: 'ACTIVE' }, + { framework: 'FCRA', issuer: 'US Congress', version: '15 U.S.C. §1681', keySections: '§607, §615', opaRules: 'Fairness rules', status: 'ACTIVE' }, + { framework: 'ECOA', issuer: 'US Congress', version: '15 U.S.C. §1691', keySections: '§701-§706', opaRules: 'DI monitoring', status: 'ACTIVE' } + ], + controlMatrix: [ + { requirement: 'AI System Inventory', iso42001: 'A.5.4', nistAiRmf: 'GOVERN 1.1', euAiAct: 'Art. 60', baselIII: 'CRE 30.2', sr117: '§3', kafkaImpl: 'ai.governance.decisions: REGISTER events' }, + { requirement: 'Risk Assessment', iso42001: 'A.5.5', nistAiRmf: 'MAP 1.1-1.6', euAiAct: 'Art. 9', baselIII: 'CRE 31', sr117: '§5', kafkaImpl: 'OPA group compliance.sr117.risk-*' }, + { requirement: 'Data Governance', iso42001: 'A.7.1-A.7.4', nistAiRmf: 'MAP 2.1-2.3', euAiAct: 'Art. 10', baselIII: 'CRE 33', sr117: '§6', kafkaImpl: 'ai.training.events + PII detection' }, + { requirement: 'Model Documentation', iso42001: 'A.6.2.5', nistAiRmf: 'GOVERN 4.1', euAiAct: 'Art. 11', baselIII: 'CRE 35', sr117: '§7', kafkaImpl: 'Evidence bundle: MODEL_DOCUMENTATION' }, + { requirement: 'Testing & Validation', iso42001: 'A.6.2.6', nistAiRmf: 'MEASURE 2.1-2.13', euAiAct: 'Art. 9.7', baselIII: 'CRE 35', sr117: '§8-9', kafkaImpl: 'OPA lifecycle.model.validation-*' }, + { requirement: 'Monitoring', iso42001: 'A.8.4', nistAiRmf: 'MEASURE 3.1-3.3', euAiAct: 'Art. 9.9', baselIII: 'CRE 36', sr117: '§10', kafkaImpl: 'All 12 Kafka topics + Sentinel' }, + { requirement: 'Record Keeping', iso42001: 'A.6.2.3', nistAiRmf: 'GOVERN 5.1', euAiAct: 'Art. 12', baselIII: 'CRE 35', sr117: '§7', kafkaImpl: 'WORM S3 + hash chain + 10yr retention' }, + { requirement: 'Transparency', iso42001: 'A.6.2.4', nistAiRmf: 'GOVERN 4.2', euAiAct: 'Art. 13', baselIII: '—', sr117: '—', kafkaImpl: 'Evidence bundles + auditor portal' }, + { requirement: 'Human Oversight', iso42001: 'A.8.3', nistAiRmf: 'GOVERN 1.4', euAiAct: 'Art. 14', baselIII: '—', sr117: '§4', kafkaImpl: 'ai.governance.decisions: ESCALATE events' }, + { requirement: 'Incident Response', iso42001: 'A.8.5', nistAiRmf: 'RESPOND 1.1-1.4', euAiAct: 'Art. 62', baselIII: '—', sr117: '—', kafkaImpl: 'ai.killswitch.events + incident bundles' }, + { requirement: 'Bias Monitoring', iso42001: 'A.8.4', nistAiRmf: 'MEASURE 2.6-2.11', euAiAct: 'Art. 10.2f', baselIII: '—', sr117: 'FCRA/ECOA', kafkaImpl: 'OPA fairness.disparateImpact.*' }, + { requirement: 'Access Control', iso42001: 'A.6.1.3', nistAiRmf: 'GOVERN 6.1', euAiAct: 'Art. 9.4b', baselIII: 'CRE 30', sr117: '§3', kafkaImpl: 'Kafka ACL + OPA authorizer' } + ], + iso42001Mapping: [ + { control: 'A.5.1', name: 'AI policy', implementation: 'OPA policy bundle + governance repository', evidenceSource: 'ai.governance.decisions' }, + { control: 'A.5.2', name: 'Roles and responsibilities', implementation: 'SPIFFE SVIDs + Kafka ACLs + RACI matrix', evidenceSource: 'ACL audit logs' }, + { control: 'A.5.3', name: 'Resources for AIMS', implementation: 'Terraform-provisioned infrastructure', evidenceSource: 'IaC state files' }, + { control: 'A.5.4', name: 'AI system inventory', implementation: 'Model registry + governance events', evidenceSource: 'ai.governance.decisions' }, + { control: 'A.5.5', name: 'AI risk management', implementation: '12-dimension risk taxonomy, ARS scoring', evidenceSource: 'Sentinel evaluations' }, + { control: 'A.5.6', name: 'AI system impact assessment', implementation: 'Automated DPIA via OPA rules', evidenceSource: 'Evidence bundle: GDPR_DPIA' }, + { control: 'A.6.2', name: 'AI system lifecycle', implementation: '7-stage LLMOps pipeline + Kafka events', evidenceSource: 'ai.model.promotions' }, + { control: 'A.7.1-A.7.4', name: 'Data management', implementation: 'Data quality gates + PII detection + consent', evidenceSource: 'ai.consent.changes + ai.training.events' }, + { control: 'A.8.3', name: 'Human oversight', implementation: 'Escalation events + HITL gates', evidenceSource: 'ai.governance.decisions' }, + { control: 'A.8.4', name: 'Monitoring & measurement', implementation: 'Continuous Kafka stream processing + Sentinel', evidenceSource: 'All 12 governance topics' }, + { control: 'A.8.5', name: 'Incident management', implementation: 'Kill-switch events + incident bundles', evidenceSource: 'ai.killswitch.events' }, + { control: 'A.9.2', name: 'Internal audit', implementation: 'Automated evidence bundles + verification CLI', evidenceSource: 'WORM S3 evidence archive' }, + { control: 'A.9.3', name: 'Management review', implementation: 'Quarterly board reports (auto-generated)', evidenceSource: 'Evidence bundle: BOARD_QUARTERLY' }, + { control: 'A.10', name: 'Continual improvement', implementation: 'Drift detection + OPA rule evolution', evidenceSource: 'ai.drift.detections + compliance scores' } + ], + sr117Alignment: [ + { section: '§3', requirement: 'Board & Management Oversight', implementation: 'CAIO + Board AI Sub-committee + 3-tier authority matrix', aclControl: 'SPIFFE-based role separation' }, + { section: '§4', requirement: 'Validation Independence', implementation: 'Separate SVIDs for validation team; ACLs prevent model developers from validation topics', aclControl: 'Topic-level ACL isolation' }, + { section: '§5', requirement: 'Conceptual Soundness', implementation: 'Evidence bundle: MODEL_DOCUMENTATION with design rationale', aclControl: 'model-registry write-only' }, + { section: '§6', requirement: 'Data Quality', implementation: 'OPA rules compliance.sr117.data-quality-* (8 rules)', aclControl: 'ai.training.events ACL' }, + { section: '§7', requirement: 'Documentation Standards', implementation: 'Automated model card generation + Kafka event history', aclControl: 'evidence-generator exclusive write' }, + { section: '§8-9', requirement: 'Outcomes Analysis', implementation: 'ai.inference.events analysis via ksqlDB, monthly reports', aclControl: 'ksqldb-analytics read-only' }, + { section: '§10', requirement: 'Ongoing Monitoring', implementation: 'ai.drift.detections + Sentinel rules (12 drift rules)', aclControl: 'monitoring-service produce' }, + { section: '§11', requirement: 'Outcomes Analysis (Credit)', implementation: 'OPA fairness.disparateImpact.*, FCRA-specific evidence', aclControl: 'fairness-monitor produce' }, + { section: '§12', requirement: 'Vendor Model Risk', implementation: 'Vendor assessment ACLs, model provenance chain', aclControl: 'vendor-assessment-portal restricted' } + ], + baselIIIAlignment: [ + { section: 'CRE 30.2', requirement: 'Board/senior management oversight', implementation: 'Board AI Sub-committee dashboard, CAIO escalation path' }, + { section: 'CRE 30.3', requirement: 'Model risk management framework', implementation: 'OPA policy group compliance.baselIII.* (28 rules)' }, + { section: 'CRE 31', requirement: 'Stress testing principles', implementation: 'Sentinel crisis simulation integration, stress test events' }, + { section: 'CRE 33', requirement: 'Data quality', implementation: 'ai.training.events PII/quality gates, OPA data.privacy.*' }, + { section: 'CRE 35', requirement: 'Model validation', implementation: 'Evidence bundle: BASEL_III_MODEL_RISK, quarterly generation' }, + { section: 'CRE 36', requirement: 'Monitoring and reporting', implementation: 'Real-time Kafka monitoring, quarterly Basel reports' } + ] + }, + + // ─── TERRAFORM IaC ───────────────────────────────────────────────────────── + terraformIaC: { + version: 'Terraform 1.8', + modules: [ + { id: 'M1', name: 'kafka-cluster', description: 'Kafka broker provisioning (5-broker, 3-AZ)', resources: 14, provider: 'Mongey/kafka + aws' }, + { id: 'M2', name: 'kafka-acl-governance', description: 'ACL policy deployment + OPA authorizer', resources: 48, provider: 'Mongey/kafka' }, + { id: 'M3', name: 'schema-registry', description: 'Schema Registry + schema registration', resources: 8, provider: 'Mongey/kafka' }, + { id: 'M4', name: 'worm-s3-storage', description: 'WORM S3 buckets + lifecycle + replication', resources: 12, provider: 'aws' }, + { id: 'M5', name: 'compliance-engine', description: 'Compliance engine ECS/EKS deployment', resources: 22, provider: 'aws' }, + { id: 'M6', name: 'opa-engine', description: 'OPA cluster + bundle store + policies', resources: 16, provider: 'aws' }, + { id: 'M7', name: 'monitoring-stack', description: 'Prometheus + Grafana + alert rules', resources: 18, provider: 'aws + grafana' }, + { id: 'M8', name: 'evidence-signing', description: 'HSM + signing key management', resources: 6, provider: 'aws (KMS/CloudHSM)' } + ], + totalResources: 144, + environments: ['production', 'staging', 'sandbox'], + cicdGates: [ + { gate: 'G1', name: 'Terraform Plan + OPA Check', trigger: 'Pull request', blocks: 'Any OPA violation', required: true }, + { gate: 'G2', name: 'Kafka ACL Validation', trigger: 'Pull request', blocks: 'Rego test failure (<95% coverage)', required: true }, + { gate: 'G3', name: 'Schema Compatibility', trigger: 'Schema change PR', blocks: 'Breaking schema change', required: true }, + { gate: 'G4', name: 'Apply + Evidence', trigger: 'Merge to main', blocks: 'Apply failure', required: true }, + { gate: 'G5', name: 'Drift Detection', trigger: 'Hourly schedule', blocks: 'CRITICAL severity alert', required: false } + ], + driftDetection: { + frequency: 'Hourly', + method: 'terraform plan -detailed-exitcode', + severityLevels: [ + { severity: 'CRITICAL', criteria: 'ACL or security group changes detected', action: 'PagerDuty alert + auto-remediation' }, + { severity: 'HIGH', criteria: 'Topic configuration or retention changes', action: 'Slack alert + manual review within 4h' }, + { severity: 'MEDIUM', criteria: 'Monitoring or dashboard changes', action: 'Jira ticket + review within 24h' }, + { severity: 'LOW', criteria: 'Tag or description changes', action: 'Weekly report' } + ] + } + }, + + // ─── AUDITOR WORKFLOWS ───────────────────────────────────────────────────── + auditorWorkflows: { + modes: [ + { mode: 'Self-Service Evidence Retrieval', useCase: 'Routine audit, surveillance', access: 'Auditor portal + CLI', duration: '1-4 hours' }, + { mode: 'Guided Audit Walkthrough', useCase: 'Comprehensive annual audit (ISO 42001, SOC 2)', access: 'Auditor portal + dedicated session', duration: '2-5 days' }, + { mode: 'Regulatory Examination', useCase: 'Supervisory examination (Fed, OCC, ECB)', access: 'Dedicated secure room + full export', duration: '1-4 weeks' } + ], + selfServiceCapabilities: [ + 'SSO + MFA authentication via kafka-gov-verify CLI', + 'List evidence bundles by system, framework, date range', + 'Download and cryptographically verify bundles', + 'Generate framework-specific gap analysis reports', + 'Export compliance dashboards as PDF/CSV' + ], + guidedAuditPortal: [ + 'Evidence Navigator: browse by framework, system, time period, or control', + 'Control Mapping View: which evidence satisfies which regulatory controls', + 'Hash Chain Explorer: visual integrity chain verification', + 'Real-Time Dashboard: live compliance metrics, policy evaluations, alerts', + 'Export Suite: regulatory-formatted reports (PDF, CSV, JSON)', + 'Annotation System: immutable auditor annotations on evidence' + ], + regulatoryExamination: [ + 'Dedicated secure environment (isolated network segment)', + 'Full data export: complete Kafka event history', + 'Raw ksqlDB query access (read-only) to governance streams', + 'Pre-installed kafka-gov-verify CLI on auditor workstations', + 'Assigned compliance engineer for technical queries', + 'Physical or virtual evidence room with printed evidence' + ] + }, + + // ─── RISK REGISTER ───────────────────────────────────────────────────────── + riskRegister: [ + { id: 'KR-001', risk: 'Kafka cluster outage disrupts evidence generation', likelihood: 'LOW', impact: 'CRITICAL', score: 'HIGH', mitigation: 'Multi-AZ, cross-region replication, 72h evidence buffer', owner: 'VP Platform', status: 'MITIGATING' }, + { id: 'KR-002', risk: 'OPA policy misconfiguration blocks legitimate access', likelihood: 'MEDIUM', impact: 'HIGH', score: 'HIGH', mitigation: 'Policy staging, canary deployment, break-glass override', owner: 'VP AI Governance', status: 'MITIGATING' }, + { id: 'KR-003', risk: 'WORM storage corruption or unavailability', likelihood: 'VERY LOW', impact: 'CRITICAL', score: 'MEDIUM', mitigation: 'Cross-region replication, 11-nines durability, daily integrity', owner: 'CISO', status: 'MITIGATING' }, + { id: 'KR-004', risk: 'Schema Registry incompatible change breaks consumers', likelihood: 'LOW', impact: 'HIGH', score: 'MEDIUM', mitigation: 'BACKWARD_TRANSITIVE enforcement, dual-write, RFC process', owner: 'Chief Architect', status: 'MITIGATING' }, + { id: 'KR-005', risk: 'HSM key compromise affects evidence signing integrity', likelihood: 'VERY LOW', impact: 'CRITICAL', score: 'MEDIUM', mitigation: 'Key rotation, multi-party generation, FIPS 140-3 Level 3', owner: 'CISO', status: 'MITIGATING' }, + { id: 'KR-006', risk: 'Drift detection false positive triggers unnecessary remediation', likelihood: 'MEDIUM', impact: 'LOW', score: 'LOW', mitigation: 'Severity classification, human approval, drift dashboard', owner: 'SRE Lead', status: 'MITIGATING' }, + { id: 'KR-007', risk: 'Regulatory framework changes invalidate existing policies', likelihood: 'MEDIUM', impact: 'HIGH', score: 'HIGH', mitigation: 'Regulatory monitoring service, quarterly refresh, legal liaison', owner: 'General Counsel', status: 'MITIGATING' }, + { id: 'KR-008', risk: 'Evidence bundle generation falls behind event volume', likelihood: 'LOW', impact: 'HIGH', score: 'MEDIUM', mitigation: 'Auto-scaling, batch processing fallback, queue depth alert', owner: 'VP Platform', status: 'MITIGATING' } + ], + + // ─── INVESTMENT & ROI ────────────────────────────────────────────────────── + investment: { + costBreakdown: [ + { category: 'Infrastructure (Kafka, S3, OPA, HSM)', yr1: 480, yr2: 420, yr3: 390, yr4: 360, yr5: 340 }, + { category: 'Engineering (Build + Maintain)', yr1: 1200, yr2: 600, yr3: 480, yr4: 420, yr5: 380 }, + { category: 'Licensing (Confluent, HSM, Monitoring)', yr1: 320, yr2: 340, yr3: 360, yr4: 380, yr5: 400 }, + { category: 'Compliance Operations', yr1: 280, yr2: 240, yr3: 200, yr4: 180, yr5: 160 } + ], + totals: { yr1: 2280, yr2: 1600, yr3: 1430, yr4: 1340, yr5: 1280, fiveYearTotal: 7930 }, + roi: { + fiveYearInvestment: '$7.93M', + fiveYearComplianceCostWithout: '$24.0M', + fiveYearNetSavings: '$16.07M', + npv: '$12.4M (8% discount rate)', + irr: '42.6%', + paybackPeriod: '1.8 years', + regulatoryFineRiskAvoided: '$12-28M (estimated)', + evidenceAssemblyReduction: '94% (72h → 4.3h)', + auditFindingReduction: '68% YoY', + annualManualCostPre: '$4.8M', + annualEngineCost: '$1.2M', + annualNetSavings: '$2.4M' + } + }, + + // ─── IMPLEMENTATION ROADMAP ──────────────────────────────────────────────── + rollout: { + days1to30: { + title: 'Foundation (Days 1-30)', + deliverables: [ + { week: '1-2', deliverable: 'Kafka cluster deployment (5-broker, 3-AZ)', owner: 'Platform Eng.', exitCriteria: 'Cluster healthy, mTLS enabled' }, + { week: '1-2', deliverable: 'SPIFFE/SPIRE deployment', owner: 'Security Eng.', exitCriteria: 'SVIDs issuing for all governance services' }, + { week: '2-3', deliverable: 'Core topic creation (12 topics) + ACL enforcement', owner: 'Platform Eng.', exitCriteria: 'All topics created, ACLs applied' }, + { week: '3-4', deliverable: 'Schema Registry + core schemas', owner: 'Platform Eng.', exitCriteria: 'Schemas registered, compatibility enforced' }, + { week: '3-4', deliverable: 'WORM S3 bucket provisioned', owner: 'Cloud Eng.', exitCriteria: 'COMPLIANCE mode verified' } + ] + }, + days31to60: { + title: 'Compliance Engine (Days 31-60)', + deliverables: [ + { week: '5-6', deliverable: 'OPA Kafka Authorizer deployed', owner: 'Platform Eng.', exitCriteria: 'Authorizer active on all brokers' }, + { week: '5-6', deliverable: 'OPA policy bundle Phase 1 (180 rules)', owner: 'AI Governance', exitCriteria: '180 rules active, P99 < 5ms' }, + { week: '6-7', deliverable: 'Compliance Engine deployed', owner: 'Platform Eng.', exitCriteria: 'Consuming all 12 topics' }, + { week: '7-8', deliverable: 'Evidence bundle generator operational', owner: 'Compliance Eng.', exitCriteria: 'First SR 11-7 bundle generated' }, + { week: '7-8', deliverable: 'Verification CLI v1.0', owner: 'DevTools', exitCriteria: 'CLI verifies bundles, hash chains' } + ] + }, + days61to90: { + title: 'Auditor Readiness (Days 61-90)', + deliverables: [ + { week: '9-10', deliverable: 'OPA policy bundle Phase 2 (312 rules)', owner: 'AI Governance', exitCriteria: 'All 312 rules across 11 groups' }, + { week: '9-10', deliverable: 'Auditor portal v1.0', owner: 'Compliance Eng.', exitCriteria: 'Self-service evidence retrieval' }, + { week: '10-11', deliverable: 'Terraform IaC complete (8 modules)', owner: 'Platform Eng.', exitCriteria: 'All infra managed via Terraform' }, + { week: '11-12', deliverable: 'CI/CD governance gates (5 gates)', owner: 'DevOps', exitCriteria: 'All 5 gates active' }, + { week: '12', deliverable: 'Drift detection operational', owner: 'SRE', exitCriteria: 'Hourly drift alerts, PagerDuty' }, + { week: '12', deliverable: 'Internal audit dry-run (ISO 42001)', owner: 'Compliance', exitCriteria: 'Dry run complete, findings remediated' } + ] + }, + eightWeekFastTrack: [ + { week: 1, focus: 'Infrastructure', items: 'Kafka cluster + mTLS + 6 core topics + WORM S3' }, + { week: 2, focus: 'Identity & ACLs', items: 'SPIFFE/SPIRE + OPA Kafka Authorizer + core ACLs' }, + { week: 3, focus: 'Schema & Streaming', items: 'Schema Registry + ksqlDB + governance event schemas' }, + { week: 4, focus: 'Policy Engine', items: 'OPA cluster + Phase 1 policies (180 rules) + Sentinel' }, + { week: 5, focus: 'Compliance Engine', items: 'Kafka Streams app + evidence generator' }, + { week: 6, focus: 'Evidence & Signing', items: 'HSM + Ed25519 signing + WORM archival + verification CLI' }, + { week: 7, focus: 'IaC & CI/CD', items: 'Terraform 8 modules + 5 governance gates + drift detection' }, + { week: 8, focus: 'Auditor Readiness', items: 'Auditor portal + full policy set (312 rules) + dry-run' } + ] + }, + + // ─── KEY METRICS SUMMARY ─────────────────────────────────────────────────── + keyMetrics: { + kafkaTopics: 12, + kafkaBrokers: 5, + kafkaThroughput: '45,000 events/sec', + kafkaP99Latency: '12ms', + kafkaAvailability: '99.997%', + opaRules: 312, + opaPolicyGroups: 11, + opaEvalP99: '4.2ms', + sentinelRules: 847, + evidenceBundleTypes: 8, + evidenceGenerationP99: '4.8s', + wormRetention: '10 years', + wormDurability: '99.999999999%', + signingAlgorithm: 'Ed25519 + SHA-256', + terraformModules: 8, + terraformResources: 144, + cicdGates: 5, + auditorWorkflows: 3, + dailyPolicyEvaluations: '1.2M', + annualComplianceSavings: '$2.4M', + auditFindingReduction: '68% YoY', + evidenceAssemblyReduction: '94%', + fiveYearNPV: '$12.4M', + irr: '42.6%', + paybackPeriod: '1.8 years' + } +}; + +// ─── KAFKA ACL GOVERNANCE API ROUTES ──────────────────────────────────────── +const KACG = KAFKA_ACL_GOVERNANCE; + +// Root & Metadata +app.get('/api/kafka-acl-governance', (_, res) => res.json(KACG)); +app.get('/api/kafka-acl-governance/metadata', (_, res) => res.json(KACG.metadata)); +app.get('/api/kafka-acl-governance/meta', (_, res) => res.json(KACG.metadata)); + +// KPIs +app.get('/api/kafka-acl-governance/kpis', (_, res) => res.json(KACG.kpis)); + +// Kafka Cluster +app.get('/api/kafka-acl-governance/cluster', (_, res) => res.json(KACG.kafkaCluster)); +app.get('/api/kafka-acl-governance/cluster/topics', (_, res) => res.json({ topics: KACG.kafkaCluster.topics, count: KACG.kafkaCluster.topics.length })); +app.get('/api/kafka-acl-governance/cluster/topics/:name', (req, res) => { + const topic = KACG.kafkaCluster.topics.find(t => t.name === req.params.name || t.name === `ai.${req.params.name}`); + topic ? res.json(topic) : res.status(404).json({ error: 'Topic not found' }); +}); +app.get('/api/kafka-acl-governance/cluster/performance', (_, res) => res.json(KACG.kafkaCluster.throughput)); + +// ACL Governance +app.get('/api/kafka-acl-governance/acl', (_, res) => res.json(KACG.aclGovernance)); +app.get('/api/kafka-acl-governance/acl/identity', (_, res) => res.json(KACG.aclGovernance.identityLayer)); +app.get('/api/kafka-acl-governance/acl/taxonomy', (_, res) => res.json({ taxonomy: KACG.aclGovernance.aclTaxonomy })); +app.get('/api/kafka-acl-governance/acl/authorizer', (_, res) => res.json(KACG.aclGovernance.authorizerConfig)); +app.get('/api/kafka-acl-governance/acl/break-glass', (_, res) => res.json(KACG.aclGovernance.breakGlass)); + +// OPA Policy Framework +app.get('/api/kafka-acl-governance/opa', (_, res) => res.json(KACG.opaPolicyFramework)); +app.get('/api/kafka-acl-governance/opa/groups', (_, res) => res.json({ groups: KACG.opaPolicyFramework.policyGroups, totalRules: KACG.opaPolicyFramework.totalRules })); +app.get('/api/kafka-acl-governance/opa/groups/:prefix', (req, res) => { + const group = KACG.opaPolicyFramework.policyGroups.find(g => g.prefix === req.params.prefix || g.group.startsWith(req.params.prefix)); + group ? res.json(group) : res.status(404).json({ error: 'Policy group not found' }); +}); +app.get('/api/kafka-acl-governance/opa/performance', (_, res) => res.json(KACG.opaPolicyFramework.performance)); + +// Compliance Engine +app.get('/api/kafka-acl-governance/compliance-engine', (_, res) => res.json(KACG.complianceEngine)); +app.get('/api/kafka-acl-governance/compliance-engine/pipeline', (_, res) => res.json({ stages: KACG.complianceEngine.pipeline })); +app.get('/api/kafka-acl-governance/compliance-engine/evidence-types', (_, res) => res.json({ types: KACG.complianceEngine.evidenceBundleTypes })); + +// Evidence Signing & Verification +app.get('/api/kafka-acl-governance/evidence-signing', (_, res) => res.json(KACG.evidenceSigning)); +app.get('/api/kafka-acl-governance/evidence-signing/cli', (_, res) => res.json(KACG.evidenceSigning.verificationCli)); + +// WORM Storage +app.get('/api/kafka-acl-governance/worm-storage', (_, res) => res.json(KACG.wormStorage)); +app.get('/api/kafka-acl-governance/worm-storage/lifecycle', (_, res) => res.json({ tiers: KACG.wormStorage.lifecycleTiering, annualCost: KACG.wormStorage.annualStorageCost })); +app.get('/api/kafka-acl-governance/worm-storage/retention', (_, res) => res.json({ policies: KACG.wormStorage.retentionPolicies })); + +// Regulatory Alignment +app.get('/api/kafka-acl-governance/regulatory', (_, res) => res.json(KACG.regulatoryAlignment)); +app.get('/api/kafka-acl-governance/regulatory/frameworks', (_, res) => res.json({ frameworks: KACG.regulatoryAlignment.frameworks })); +app.get('/api/kafka-acl-governance/regulatory/control-matrix', (_, res) => res.json({ controls: KACG.regulatoryAlignment.controlMatrix })); +app.get('/api/kafka-acl-governance/regulatory/iso42001', (_, res) => res.json({ mapping: KACG.regulatoryAlignment.iso42001Mapping })); +app.get('/api/kafka-acl-governance/regulatory/sr117', (_, res) => res.json({ alignment: KACG.regulatoryAlignment.sr117Alignment })); +app.get('/api/kafka-acl-governance/regulatory/basel-iii', (_, res) => res.json({ alignment: KACG.regulatoryAlignment.baselIIIAlignment })); + +// Terraform IaC +app.get('/api/kafka-acl-governance/terraform', (_, res) => res.json(KACG.terraformIaC)); +app.get('/api/kafka-acl-governance/terraform/modules', (_, res) => res.json({ modules: KACG.terraformIaC.modules, totalResources: KACG.terraformIaC.totalResources })); +app.get('/api/kafka-acl-governance/terraform/modules/:id', (req, res) => { + const mod = KACG.terraformIaC.modules.find(m => m.id === req.params.id); + mod ? res.json(mod) : res.status(404).json({ error: 'Module not found' }); +}); +app.get('/api/kafka-acl-governance/terraform/cicd-gates', (_, res) => res.json({ gates: KACG.terraformIaC.cicdGates })); +app.get('/api/kafka-acl-governance/terraform/drift-detection', (_, res) => res.json(KACG.terraformIaC.driftDetection)); + +// Auditor Workflows +app.get('/api/kafka-acl-governance/auditor', (_, res) => res.json(KACG.auditorWorkflows)); +app.get('/api/kafka-acl-governance/auditor/modes', (_, res) => res.json({ modes: KACG.auditorWorkflows.modes })); +app.get('/api/kafka-acl-governance/auditor/self-service', (_, res) => res.json({ capabilities: KACG.auditorWorkflows.selfServiceCapabilities })); +app.get('/api/kafka-acl-governance/auditor/guided', (_, res) => res.json({ features: KACG.auditorWorkflows.guidedAuditPortal })); +app.get('/api/kafka-acl-governance/auditor/regulatory-exam', (_, res) => res.json({ provisions: KACG.auditorWorkflows.regulatoryExamination })); + +// Risk Register +app.get('/api/kafka-acl-governance/risk-register', (_, res) => res.json({ risks: KACG.riskRegister })); + +// Investment & ROI +app.get('/api/kafka-acl-governance/investment', (_, res) => res.json(KACG.investment)); +app.get('/api/kafka-acl-governance/investment/roi', (_, res) => res.json(KACG.investment.roi)); +app.get('/api/kafka-acl-governance/investment/costs', (_, res) => res.json({ breakdown: KACG.investment.costBreakdown, totals: KACG.investment.totals })); + +// Rollout +app.get('/api/kafka-acl-governance/rollout', (_, res) => res.json(KACG.rollout)); +app.get('/api/kafka-acl-governance/rollout/30-day', (_, res) => res.json(KACG.rollout.days1to30)); +app.get('/api/kafka-acl-governance/rollout/60-day', (_, res) => res.json(KACG.rollout.days31to60)); +app.get('/api/kafka-acl-governance/rollout/90-day', (_, res) => res.json(KACG.rollout.days61to90)); +app.get('/api/kafka-acl-governance/rollout/8-week', (_, res) => res.json({ plan: KACG.rollout.eightWeekFastTrack })); + +// Metrics Summary +app.get('/api/kafka-acl-governance/metrics', (_, res) => res.json(KACG.keyMetrics)); + +// Dashboard Summary +app.get('/api/kafka-acl-governance/summary', (_, res) => res.json({ + docRef: KACG.metadata.docRef, + title: KACG.metadata.title, + version: KACG.metadata.version, + date: KACG.metadata.date, + scope: KACG.metadata.scope, + kpis: KACG.kpis.slice(0, 6), + topicCount: KACG.kafkaCluster.topics.length, + opaRules: KACG.opaPolicyFramework.totalRules, + policyGroups: KACG.opaPolicyFramework.policyGroups.length, + evidenceBundleTypes: KACG.complianceEngine.evidenceBundleTypes.length, + frameworks: KACG.regulatoryAlignment.frameworks.length, + terraformModules: KACG.terraformIaC.modules.length, + cicdGates: KACG.terraformIaC.cicdGates.length, + auditorModes: KACG.auditorWorkflows.modes.length, + roi: KACG.investment.roi +})); + +// Dashboard Data (aggregated for HTML dashboard) +app.get('/api/kafka-acl-governance/dashboard', (_, res) => res.json({ + metadata: { docRef: KACG.metadata.docRef, version: KACG.metadata.version, date: KACG.metadata.date }, + kpis: KACG.kpis, + topics: KACG.kafkaCluster.topics.map(t => ({ name: t.name, partitions: t.partitions, retention: t.retention, transactional: t.transactional })), + policyGroups: KACG.opaPolicyFramework.policyGroups, + evidenceTypes: KACG.complianceEngine.evidenceBundleTypes, + controlMatrix: KACG.regulatoryAlignment.controlMatrix, + frameworks: KACG.regulatoryAlignment.frameworks, + modules: KACG.terraformIaC.modules, + gates: KACG.terraformIaC.cicdGates, + risks: KACG.riskRegister, + rollout8Week: KACG.rollout.eightWeekFastTrack, + investment: KACG.investment, + metrics: KACG.keyMetrics +})); + +// Artifacts listing (expanded with all machine-readable governance artifacts) +app.get('/api/kafka-acl-governance/artifacts', (_, res) => res.json({ + schemas: [ + { name: 'Governance Event Schema', format: 'Avro/JSON', path: '/artifacts/schemas/governance-event.avsc', description: 'Core Avro schema for all Kafka governance events' }, + { name: 'Evidence Bundle Manifest Schema', format: 'JSON Schema', path: '/artifacts/schemas/evidence-bundle-manifest.schema.json', description: 'JSON Schema for evidence bundle manifests' }, + { name: 'WORM Evidence Storage Schema', format: 'JSON Schema', path: '/artifacts/schemas/worm-evidence-storage.schema.json', description: 'S3 Object Lock WORM storage configuration schema' }, + { name: 'KACG OpenAPI Specification', format: 'OpenAPI 3.1', path: '/artifacts/schemas/kacg-openapi.yaml', description: '62-endpoint OpenAPI spec for Kafka ACL Governance API' } + ], + policies: [ + { name: 'Kafka ACL Governance Policy', format: 'OPA Rego', path: '/artifacts/policies/kafka_acl_governance.rego', rules: 34, description: 'Topic-level PRODUCE/CONSUME ACL enforcement via SPIFFE identity' }, + { name: 'Basel III Model Risk Policy', format: 'OPA Rego', path: '/artifacts/policies/basel_iii_model_risk.rego', rules: 28, description: 'Basel III CRE 30-36 model risk governance' }, + { name: 'EU AI Act Kafka Enforcement', format: 'OPA Rego', path: '/artifacts/policies/eu_ai_act_kafka_enforcement.rego', rules: 28, description: 'EU AI Act Art. 9/10/12/13/14/15 Kafka-specific enforcement' }, + { name: 'NIST AI RMF Governance', format: 'OPA Rego', path: '/artifacts/policies/nist_ai_rmf_govern.rego', rules: 38, description: 'NIST AI RMF GOVERN/MAP/MEASURE/MANAGE functions' }, + { name: 'ISO/IEC 42001 AIMS Governance', format: 'OPA Rego', path: '/artifacts/policies/iso42001_aims_governance.rego', rules: 32, description: 'ISO 42001 Clauses 4-10 + Annex A reference controls' }, + { name: 'GDPR AI Data Protection', format: 'OPA Rego', path: '/artifacts/policies/gdpr_ai_data_protection.rego', rules: 26, description: 'GDPR Art. 5/17/22/25/30/32/35 AI data protection' }, + { name: 'SR 11-7 Model Validation', format: 'OPA Rego', path: '/artifacts/policies/sr_11_7_model_validation.rego', description: 'Fed Reserve SR 11-7 model risk management' }, + { name: 'Fair Lending Disparate Impact', format: 'OPA Rego', path: '/artifacts/policies/fair_lending_disparate_impact.rego', description: 'FCRA/ECOA fair lending disparate impact testing' } + ], + data: [ + { name: 'Kafka ACL Matrix', format: 'JSON', path: '/artifacts/data/kafka-acl-matrix.json', description: '12-topic ACL matrix with PRODUCE/CONSUME principals' }, + { name: 'Compliance Controls Matrix', format: 'CSV', path: '/artifacts/data/kafka-compliance-controls.csv', description: 'Cross-regulation control mappings (ISO/NIST/EU/Basel/SR)' }, + { name: 'Implementation Timeline', format: 'CSV', path: '/artifacts/data/kafka-governance-timeline.csv', description: '12-week implementation timeline with exit criteria' }, + { name: 'Evidence Bundles Catalog', format: 'CSV', path: '/artifacts/data/kafka-evidence-bundles.csv', description: '20 evidence bundle types with retention/signing/storage details' } + ], + templates: [ + { name: 'Terraform Module Configuration', format: 'JSON', path: '/artifacts/templates/kafka-governance-terraform.json', description: '8 Terraform modules, 144 resources for Kafka governance IaC' }, + { name: 'GitHub Actions Governance Workflow', format: 'YAML', path: '/artifacts/templates/github-actions-governance.yaml', description: '5-gate CI/CD pipeline with drift detection and evidence signing' }, + { name: 'Governance Verification CLI', format: 'Python', path: '/artifacts/templates/governance-verify-cli.py', description: 'Evidence verification CLI (verify, verify-sig, verify-chain, check-retention, audit-report)' }, + { name: 'Drift Detection Configuration', format: 'JSON', path: '/artifacts/templates/drift-detection-config.json', description: '6 drift detectors (Terraform, Kafka ACL, OPA, WORM, Schema, mTLS)' } + ], + summary: { + totalArtifacts: 20, + opaPoliciesTotalRules: 214, + regulatoryFrameworks: ['EU AI Act', 'NIST AI RMF', 'ISO/IEC 42001', 'Basel III', 'SR 11-7', 'GDPR', 'FCRA/ECOA'], + formats: ['OPA Rego', 'OpenAPI 3.1', 'Avro', 'JSON Schema', 'CSV', 'YAML', 'Python', 'JSON/Terraform'], + cicdGates: 5, + driftDetectors: 6, + evidenceBundleTypes: 20 + } +})); + + + +// ══════════════════════════════════════════════════════════════════════════════ +// SECTION: AGI/ASI GOVERNANCE ARCHITECTURES & FRAMEWORKS (GAF-GSIFI-WP-017) +// ══════════════════════════════════════════════════════════════════════════════ + +const GOVERNANCE_ARCHITECTURES_FRAMEWORKS = { + metadata: { + docRef: 'GAF-GSIFI-WP-017', + title: 'AGI/ASI Governance Architectures & Frameworks — Comprehensive Implementation Reference (2026-2030)', + version: '1.0.0', + date: '2026-04-03', + classification: 'CONFIDENTIAL — Board / C-Suite / Regulators / EA / Platform Engineering', + supersedes: 'Consolidation of WP-001 through WP-016 architectural content', + audience: ['C-Suite', 'Board of Directors', 'Regulators', 'Enterprise Architects', 'AI Platform Engineers', 'Research Teams', 'CAIOs', 'G-SIFI Risk Committees', 'Financial Supervisors'], + scope: { + governanceDomains: 7, + governanceLayers: 6, + regulatoryFrameworks: 8, + referenceArchitectures: 5, + globalComponents: 15, + evolutionStages: 10, + opaRules: 336, + sentinelRules: 1024, + dailyPolicyEvaluations: '1.8M', + eaipThroughput: '12,200 RPC/s', + eaipReliability: '99.98%', + haRagF1: '92.1%', + totalInvestment: '$68.4M', + npv: '$118.6M', + irr: '42.3%', + apiEndpoints: 56, + jurisdictions: 5, + implementationWeeks: 8 + }, + companionDocs: [ + { ref: 'AGMB-GSIFI-WP-016', title: 'AGI Governance Master Blueprint', relationship: 'Parent blueprint' }, + { ref: 'PMREF-GSIFI-WP-015', title: 'Practitioner Master Reference', relationship: 'Practitioner playbook' }, + { ref: 'UMREF-G2K-WP-014', title: 'Unified Master Reference', relationship: 'Unified metrics' }, + { ref: 'GOV-GSIFI-WP-001', title: 'G-SIFI AI Governance Foundation', relationship: 'Foundation layer' }, + { ref: 'ARCH-ENT-WP-002', title: 'Enterprise AI Architecture Security', relationship: 'Security deep-dive' }, + { ref: 'SAFE-AGI-WP-003', title: 'AGI Readiness & Safety Frameworks', relationship: 'Safety source' }, + { ref: 'REF-ARCH-WP-004', title: 'Enterprise AI Reference Architectures', relationship: 'Architecture catalog' }, + { ref: 'COMP-REG-WP-006', title: 'G-SIFI Regulatory Compliance', relationship: 'Regulatory mapping' }, + { ref: 'TRAJ-SENT-WP-008', title: 'Trajectory AI Sentinel Governance', relationship: 'Sentinel source' }, + { ref: 'KARD-WP-009', title: 'Kardashev Energy & Compute Governance', relationship: 'Compute governance' }, + { ref: 'COGRES-WP-010', title: 'Cognitive Resonance & AGI Readiness', relationship: 'CRP source' } + ] + }, + + kpis: [ + { name: 'Regulatory Compliance Score', current: '89.2%', target2027: '96.0%', target2030: '99.5%', trend: 'improving' }, + { name: 'OPA Policy Coverage', current: '336 rules (12 groups)', target2027: '420 rules', target2030: '600+ rules', trend: 'growing' }, + { name: 'Sentinel Rule Base', current: '1,024 rules (26 systems)', target2027: '1,400 rules', target2030: '2,200+ rules', trend: 'growing' }, + { name: 'Daily Policy Evaluations', current: '1.8M (P99 3.8ms)', target2027: '4.2M', target2030: '8.0M', trend: 'scaling' }, + { name: 'EAIP Throughput', current: '12,200 RPC/s (99.98%)', target2027: '18,000 RPC/s', target2030: '30,000 RPC/s', trend: 'scaling' }, + { name: 'HA-RAG F1 Score', current: '92.1%', target2027: '94.5%', target2030: '97.0%', trend: 'improving' }, + { name: 'AI Risk Score (ARS)', current: '58.2/100', target2027: '72.0', target2030: '85.0', trend: 'improving' }, + { name: 'Model Bias (DI)', current: '>=0.80', target2027: '>=0.87', target2030: '>=0.93', trend: 'improving' }, + { name: 'AGI Readiness Level', current: 'ARL-2', target2027: 'ARL-5', target2030: 'ARL-7', trend: 'advancing' }, + { name: 'Mean Incident Response', current: '12 min', target2027: '6 min', target2030: '2 min', trend: 'improving' }, + { name: 'ISO 42001 Certification', current: 'In progress', target2027: 'Certified', target2030: 'Re-certified', trend: 'on-track' }, + { name: '5-Year Investment', current: '$68.4M', target2027: '---', target2030: 'NPV $118.6M, IRR 42.3%', trend: 'planned' } + ], + + domainsSummary: [ + { id: 'D1', name: 'Multilayered Enterprise AI Governance Pillars', scope: '6-layer governance architecture with accountability roles, policy infrastructure, risk management, AI-ready data, dev/deploy governance, and monitoring', keyMetric: '336 OPA rules + 1,024 Sentinel rules', status: 'Operational' }, + { id: 'D2', name: 'Multi-Regime Regulatory Alignment', scope: '8 regulatory frameworks across 5 jurisdictions (EU AI Act, NIST AI RMF, ISO 42001, OECD, GDPR, FCRA/ECOA, SR 11-7, UK AISI)', keyMetric: '89.2% compliance score', status: 'Active' }, + { id: 'D3', name: 'Enterprise AI Reference Architectures & Trust Stacks', scope: '5 reference architectures (EAIP, Sentinel, HA-RAG, WorkflowAI, CCaaS) + 7-layer trust stack', keyMetric: '12,200 RPC/s @ 99.98%', status: 'Production' }, + { id: 'D4', name: 'Global Legal & Compute Governance', scope: 'ICGC, 15 global governance components, compute registry, Sentinel global integration', keyMetric: '15 global components', status: 'Proposed/Pilot' }, + { id: 'D5', name: 'Financial Services AI Governance', scope: 'SR 11-7, FCRA/ECOA, credit scoring, fair lending, EARL assessment', keyMetric: 'DI >= 0.80 across all classes', status: 'Compliant' }, + { id: 'D6', name: 'Frontier AGI Safety & Trust-by-Design', scope: '10-stage evolution model, CRP v2.1, crisis simulations, MVAGS, trust-by-design', keyMetric: 'CRP alignment 83.8%', status: 'Active' }, + { id: 'D7', name: 'AGI Governance Master Blueprint', scope: 'Unified enterprise + frontier + civilizational governance, Sentinel platform, ARL layers, 30/60/90-day rollout', keyMetric: '8-week implementation plan', status: 'Blueprint' } + ], + + // ─── DOMAIN 1: Multilayered Enterprise Governance ───────────────────────── + domain1_governance: { + title: 'Multilayered Enterprise AI Governance Pillars', + layers: [ + { id: 'L1', name: 'Accountability & Roles', function: 'Ownership, decision rights, escalation paths', keyControls: 'Board AI Sub-committee, CAIO role, 3-tier authority matrix, RACI', owner: 'CEO / Board' }, + { id: 'L2', name: 'Policy Infrastructure', function: 'Executable, version-controlled governance rules', keyControls: '336 OPA rules (12 groups), 1,024 Sentinel rules, Kafka WORM', owner: 'VP AI Governance' }, + { id: 'L3', name: 'Risk Management', function: 'Continuous risk scoring and mitigation', keyControls: '14-dimension taxonomy, ARS 58.2 (target 72.0), crisis simulations', owner: 'CRO' }, + { id: 'L4', name: 'AI-Ready Data Infrastructure', function: 'Data quality, lineage, privacy at scale', keyControls: 'Quality >= 0.87, PII 99.72%, Atlas lineage 98.8%, GDPR erasure < 72h', owner: 'CDO' }, + { id: 'L5', name: 'Development & Deployment Governance', function: 'CI/CD gates at every lifecycle stage', keyControls: '7-stage LLMOps, 8 CI/CD gates, DI >= 0.80, 336-rule pre-deploy check', owner: 'CTO / VP Eng' }, + { id: 'L6', name: 'Monitoring & Observability', function: 'Real-time monitoring, compliance, drift detection', keyControls: 'OpenTelemetry, Prometheus, Kafka WORM 52K/s, drift < 15 min, 12 dashboards', owner: 'VP AI Gov / CTO' } + ], + accountability: { + roles: [ + { role: 'Chief AI Officer (CAIO)', reportsTo: 'CEO', budget: '$620K / 24 mo', mandate: 'EU AI Act Art. 4(1)' }, + { role: 'Board AI Sub-committee', reportsTo: 'Board', composition: '3 independents + CAIO + CRO + GC', cadence: 'Quarterly' }, + { role: 'VP AI Governance', reportsTo: 'CAIO', budget: '$1.8M / yr', mandate: 'ISO/IEC 42001 cl. 5' }, + { role: 'VP AI Safety', reportsTo: 'CAIO', budget: '$1.4M / yr', mandate: 'EU AI Act Art. 9' }, + { role: 'Chief Risk Officer', reportsTo: 'CEO', budget: 'Existing CRO', mandate: 'SR 11-7, Basel III' }, + { role: 'CISO', reportsTo: 'CTO', budget: 'Existing CISO', mandate: 'GDPR, NIST CSF' }, + { role: 'General Counsel', reportsTo: 'CEO', budget: 'Existing GC', mandate: 'Multi-jurisdiction' }, + { role: 'Head of Model Risk', reportsTo: 'CRO', budget: '$980K / yr', mandate: 'SR 11-7 ss. 3-4' } + ], + raci: [ + { decision: 'High-risk AI deployment approval', caio: 'A', board: 'I', cro: 'C', ciso: 'C', vpAiGov: 'R', gc: 'C' }, + { decision: 'AI risk appetite setting', caio: 'C', board: 'A', cro: 'R', ciso: 'C', vpAiGov: 'I', gc: 'C' }, + { decision: 'Regulatory response', caio: 'R', board: 'I', cro: 'C', ciso: 'I', vpAiGov: 'C', gc: 'A' }, + { decision: 'AI incident escalation (Sev 1-2)', caio: 'A', board: 'I', cro: 'R', ciso: 'R', vpAiGov: 'C', gc: 'C' }, + { decision: 'Policy-as-code rule changes', caio: 'I', board: 'I', cro: 'C', ciso: 'C', vpAiGov: 'A', gc: 'R' }, + { decision: 'Third-party AI model onboarding', caio: 'C', board: 'I', cro: 'R', ciso: 'A', vpAiGov: 'C', gc: 'C' } + ] + }, + policyInfrastructure: { + opaGroups: [ + { id: 'PG-01', name: 'EU AI Act Classification', rules: 42, scope: 'Risk classification, prohibited practices' }, + { id: 'PG-02', name: 'NIST AI RMF Mapping', rules: 38, scope: 'GOVERN, MAP, MEASURE, MANAGE' }, + { id: 'PG-03', name: 'ISO 42001 Controls', rules: 32, scope: 'AIMS clause compliance' }, + { id: 'PG-04', name: 'Data Governance', rules: 34, scope: 'PII detection, consent, lineage' }, + { id: 'PG-05', name: 'Model Validation', rules: 28, scope: 'SR 11-7, backtesting' }, + { id: 'PG-06', name: 'Bias & Fairness', rules: 26, scope: 'DI testing, FCRA/ECOA' }, + { id: 'PG-07', name: 'Autonomous Agent', rules: 30, scope: 'DEPTHS classification, kill-switch' }, + { id: 'PG-08', name: 'Security & Privacy', rules: 28, scope: 'GDPR Art. 17/22, encryption, DLP' }, + { id: 'PG-09', name: 'Supply Chain', rules: 22, scope: 'Third-party model provenance' }, + { id: 'PG-10', name: 'Monitoring & Observability', rules: 20, scope: 'SLO compliance, drift detection' }, + { id: 'PG-11', name: 'Incident Response', rules: 18, scope: 'Escalation, containment, reporting' }, + { id: 'PG-12', name: 'AGI Preparedness', rules: 18, scope: 'ARL requirements, GASCF' } + ], + totalOpaRules: 336, + totalSentinelRules: 1024, + sentinelAiSystems: 26, + kafkaWorm: { eventsPerSecond: 52000, retention: '7 years', format: 'WORM immutable' }, + policyPropagation: '< 60s' + }, + riskManagement: { + taxonomy: [ + { id: 'RD-01', category: 'Model Performance Degradation', weight: 0.10, score: 72.4, target2027: 82.0, owner: 'Head Model Risk' }, + { id: 'RD-02', category: 'Adversarial Attack Surface', weight: 0.09, score: 64.8, target2027: 78.0, owner: 'CISO' }, + { id: 'RD-03', category: 'Data Quality & Completeness', weight: 0.09, score: 78.2, target2027: 88.0, owner: 'CDO' }, + { id: 'RD-04', category: 'Bias & Fairness', weight: 0.09, score: 68.4, target2027: 82.0, owner: 'CRO' }, + { id: 'RD-05', category: 'Regulatory Non-compliance', weight: 0.09, score: 82.6, target2027: 94.0, owner: 'General Counsel' }, + { id: 'RD-06', category: 'Privacy & Data Protection', weight: 0.08, score: 86.4, target2027: 95.0, owner: 'DPO' }, + { id: 'RD-07', category: 'Operational Resilience', weight: 0.08, score: 74.2, target2027: 85.0, owner: 'CTO' }, + { id: 'RD-08', category: 'Supply-chain & Third-party', weight: 0.07, score: 62.8, target2027: 76.0, owner: 'CISO' }, + { id: 'RD-09', category: 'Explainability Deficit', weight: 0.07, score: 56.4, target2027: 72.0, owner: 'VP AI Gov' }, + { id: 'RD-10', category: 'Human-AI Interaction', weight: 0.06, score: 71.8, target2027: 80.0, owner: 'VP AI Safety' }, + { id: 'RD-11', category: 'Autonomous Agent Risk', weight: 0.06, score: 48.2, target2027: 68.0, owner: 'VP AI Safety' }, + { id: 'RD-12', category: 'Concentration Risk', weight: 0.05, score: 58.6, target2027: 74.0, owner: 'CRO' }, + { id: 'RD-13', category: 'Reputational Impact', weight: 0.04, score: 66.4, target2027: 78.0, owner: 'CCO' }, + { id: 'RD-14', category: 'AGI/ASI Emergence', weight: 0.03, score: 32.8, target2027: 55.0, owner: 'CAIO' } + ], + weightedARS: 58.2, + arsTarget2027: 72.0, + arsTarget2030: 85.0, + arsFormula: 'ARS = SUM(dimension_weight * dimension_score) for all 14 dimensions' + }, + dataInfrastructure: [ + { component: 'Data Quality Gates', technology: 'Great Expectations + custom', metric: 'Score >= 0.87', target: '>= 0.93' }, + { component: 'PII Detection', technology: 'Microsoft Presidio + custom NER', metric: '99.72%', target: '99.95%' }, + { component: 'Data Lineage', technology: 'Apache Atlas + OpenLineage', metric: '98.8% coverage', target: '99.9%' }, + { component: 'Consent Management', technology: 'OneTrust + custom API', metric: '99.4% accuracy', target: '99.9%' }, + { component: 'Synthetic Data', technology: 'Gretel.ai + internal', metric: '94.2% utility', target: '96.0%' }, + { component: 'Data Catalog', technology: 'Apache Atlas + custom metadata', metric: '14,800 datasets', target: '20,000+' }, + { component: 'Erasure Pipeline', technology: 'GDPR Art. 17 automated', metric: 'SLA < 72h', target: '< 24h' }, + { component: 'Encryption', technology: 'AES-256-GCM + TLS 1.3', metric: '100% coverage', target: '100%' } + ], + devDeployPipeline: [ + { stage: 'S1', name: 'Data Ingestion', gate: 'Data Quality Gate', checks: 'Schema validation, PII scan, lineage', passCriteria: 'Quality >= 0.87, PII masked' }, + { stage: 'S2', name: 'Training', gate: 'Training Governance Gate', checks: 'Compute budget, data consent, IP check', passCriteria: 'Budget approved, consent verified' }, + { stage: 'S3', name: 'Evaluation', gate: 'Model Evaluation Gate', checks: 'Performance benchmarks, bias testing', passCriteria: 'Accuracy met, DI >= 0.80' }, + { stage: 'S4', name: 'Validation', gate: 'Independent Validation Gate', checks: 'SR 11-7 review, backtesting, stress', passCriteria: 'Validation report signed' }, + { stage: 'S5', name: 'Staging', gate: 'Pre-deployment Gate', checks: 'OPA 336 rules, security scan', passCriteria: 'All 336 rules pass' }, + { stage: 'S6', name: 'Production', gate: 'Deployment Gate', checks: 'Canary analysis, rollback readiness', passCriteria: 'Canary within 2-sigma' }, + { stage: 'S7', name: 'Monitoring', gate: 'Continuous Governance', checks: 'Drift detection, SLO, audit', passCriteria: 'SLOs met, no critical drift' } + ], + cicdGates: [ + { gate: 'G1', name: 'Code Review', stage: 'PR merge', blockCriteria: 'Critical vuln, license violation' }, + { gate: 'G2', name: 'Data Validation', stage: 'Pre-training', blockCriteria: 'Quality < 0.87, PII unmasked' }, + { gate: 'G3', name: 'Training Governance', stage: 'Training start', blockCriteria: 'Budget exceeded, IP conflict' }, + { gate: 'G4', name: 'Evaluation', stage: 'Post-training', blockCriteria: 'DI < 0.80, regression detected' }, + { gate: 'G5', name: 'Validation', stage: 'Pre-staging', blockCriteria: 'Validation not signed' }, + { gate: 'G6', name: 'OPA Policy Check', stage: 'Pre-deploy', blockCriteria: 'Any deny rule triggered' }, + { gate: 'G7', name: 'Canary Analysis', stage: 'Production entry', blockCriteria: 'Metrics outside 2-sigma' }, + { gate: 'G8', name: 'Continuous Compliance', stage: 'Ongoing', blockCriteria: 'SLO breach, new regulation' } + ], + monitoring: [ + { component: 'Metrics Collection', technology: 'OpenTelemetry + Prometheus', scale: '48 metrics/system', slo: '< 30s interval' }, + { component: 'Distributed Tracing', technology: 'OpenTelemetry + Jaeger', scale: 'Full EAIP mesh', slo: 'P99 < 100ms' }, + { component: 'Log Aggregation', technology: 'Fluentd + Elasticsearch', scale: '2.4M events/day', slo: '90d hot, 7yr cold' }, + { component: 'Decision Logging', technology: 'Kafka WORM (immutable)', scale: '52K decisions/s', slo: '7yr retention' }, + { component: 'Alerting', technology: 'PagerDuty + custom', scale: 'Sev1 < 5min page', slo: '99.8% delivery' }, + { component: 'Dashboard', technology: 'Grafana + custom React', scale: '12 dashboards', slo: '< 2s refresh' }, + { component: 'Drift Detection', technology: 'Evidently AI + custom', scale: 'Statistical + concept', slo: '< 15 min detect' }, + { component: 'Compliance Reporting', technology: 'Custom generator', scale: 'Quarterly reports', slo: 'Auto-generated' } + ] + }, + + // ─── DOMAIN 2: Regulatory Alignment ─────────────────────────────────────── + domain2_regulatory: { + title: 'Multi-Regime Regulatory Alignment', + frameworks: [ + { id: 'RF-01', name: 'EU AI Act', jurisdiction: 'EU/EEA (27 MS)', effective: 'Aug 2025/2026', focus: 'Risk-based classification', opaRules: 42, status: 'Active' }, + { id: 'RF-02', name: 'NIST AI RMF 1.0', jurisdiction: 'United States', effective: 'Jan 2023', focus: 'GOVERN, MAP, MEASURE, MANAGE', opaRules: 38, status: 'Active' }, + { id: 'RF-03', name: 'ISO/IEC 42001:2023', jurisdiction: 'International', effective: 'Dec 2023', focus: 'AI Management System (AIMS)', opaRules: 32, status: 'Certifying' }, + { id: 'RF-04', name: 'OECD AI Principles', jurisdiction: '46 countries', effective: 'May 2019 (updated 2024)', focus: 'Values-based interoperability', opaRules: 14, status: 'Active' }, + { id: 'RF-05', name: 'GDPR', jurisdiction: 'EU/EEA + UK', effective: 'May 2018', focus: 'Data protection, automated decisions', opaRules: 28, status: 'Active' }, + { id: 'RF-06', name: 'FCRA / ECOA', jurisdiction: 'United States', effective: '1970/1974 (updated)', focus: 'Fair credit, equal opportunity', opaRules: 26, status: 'Active' }, + { id: 'RF-07', name: 'SR 11-7 (OCC/Fed)', jurisdiction: 'United States', effective: 'Apr 2011', focus: 'Model risk management', opaRules: 28, status: 'Active' }, + { id: 'RF-08', name: 'UK AI Safety Institute Code', jurisdiction: 'United Kingdom', effective: 'Mar 2025', focus: 'Frontier model evaluation', opaRules: 12, status: 'Active' } + ], + overallComplianceScore: '89.2%', + totalOpaRules: 336, + euAiActTimeline: [ + { date: 'Feb 2025', obligation: 'AI literacy (Art. 4)', status: 'Completed', owner: 'VP AI Gov' }, + { date: 'Aug 2025', obligation: 'Prohibited practices ban (Art. 5)', status: 'Completed', owner: 'CAIO' }, + { date: 'Aug 2026', obligation: 'High-risk system requirements (Annex III)', status: 'In progress (14/22)', owner: 'VP AI Gov' }, + { date: 'Aug 2026', obligation: 'Notified body conformity assessments', status: 'Scheduled Q2 2026', owner: 'General Counsel' }, + { date: 'Aug 2027', obligation: 'General-purpose AI model obligations', status: 'Architecture planned', owner: 'CTO' }, + { date: 'Ongoing', obligation: 'Post-market surveillance (Art. 72)', status: 'Sentinel monitoring', owner: 'VP AI Gov' } + ], + nistMapping: [ + { function: 'GOVERN', subFunctions: 'Policies, roles, culture, stakeholders', opaRules: 12, implementation: 'Board Sub-committee, CAIO, policy framework' }, + { function: 'MAP', subFunctions: 'Context, categorize, AI actors, technical', opaRules: 10, implementation: 'AI inventory, risk classification engine' }, + { function: 'MEASURE', subFunctions: 'Identify, assess, prioritize, track', opaRules: 8, implementation: 'ARS scoring, Sentinel rules, drift detection' }, + { function: 'MANAGE', subFunctions: 'Response, recovery, communication', opaRules: 8, implementation: 'Incident playbooks, kill-switch, audit trails' } + ], + iso42001Roadmap: [ + { phase: 1, clause: 'cl. 4 — Context', status: 'Completed', timeline: 'Q1 2026' }, + { phase: 2, clause: 'cl. 5 — Leadership', status: 'Completed', timeline: 'Q1 2026' }, + { phase: 3, clause: 'cl. 6 — Planning', status: 'In progress', timeline: 'Q2 2026' }, + { phase: 4, clause: 'cl. 7 — Support', status: 'In progress', timeline: 'Q2 2026' }, + { phase: 5, clause: 'cl. 8 — Operation', status: 'Planned', timeline: 'Q3 2026' }, + { phase: 6, clause: 'cl. 9 — Performance', status: 'Planned', timeline: 'Q4 2026' }, + { phase: 7, clause: 'cl. 10 — Improvement', status: 'Planned', timeline: 'Q1 2027' }, + { phase: 8, clause: 'Certification Audit', status: 'Planned', timeline: 'Q2 2027' } + ], + crossRegimeObligations: [ + { obligation: 'AI System Inventory', euAiAct: 'Art. 6-9', nist: 'MAP-1.1', iso42001: 'cl. 6.1', gdpr: 'Art. 30', sr117: 'ss. 3' }, + { obligation: 'Risk Assessment', euAiAct: 'Art. 9', nist: 'MEASURE-2', iso42001: 'cl. 6.1.2', gdpr: 'Art. 35', sr117: 'ss. 5-6' }, + { obligation: 'Data Governance', euAiAct: 'Art. 10', nist: 'MAP-2.3', iso42001: 'Annex B.4', gdpr: 'Art. 5, 25', sr117: 'ss. 6' }, + { obligation: 'Transparency', euAiAct: 'Art. 13, 52', nist: 'GOVERN-4', iso42001: 'cl. 7.4', gdpr: 'Art. 13-14', sr117: 'ss. 7' }, + { obligation: 'Human Oversight', euAiAct: 'Art. 14', nist: 'GOVERN-3', iso42001: 'cl. 8.4', gdpr: 'Art. 22', sr117: 'ss. 10' }, + { obligation: 'Bias Testing', euAiAct: 'Art. 10(2)(f)', nist: 'MEASURE-2.6', iso42001: 'Annex B.7', gdpr: 'Art. 22(3)', sr117: 'FCRA/ECOA' }, + { obligation: 'Incident Reporting', euAiAct: 'Art. 62', nist: 'MANAGE-4', iso42001: 'cl. 10.1', gdpr: 'Art. 33-34', sr117: 'ss. 10' }, + { obligation: 'Audit Trail', euAiAct: 'Art. 12', nist: 'GOVERN-1.5', iso42001: 'cl. 9.2', gdpr: 'Art. 30', sr117: 'ss. 7' }, + { obligation: 'Model Documentation', euAiAct: 'Art. 11', nist: 'MAP-3', iso42001: 'cl. 8.2', gdpr: 'DPIA', sr117: 'ss. 7' }, + { obligation: 'Post-market Monitoring', euAiAct: 'Art. 72', nist: 'MANAGE-3', iso42001: 'cl. 9.1', gdpr: 'Art. 35', sr117: 'ss. 10' } + ] + }, + + // ─── DOMAIN 3: Reference Architectures & Trust Stacks ───────────────────── + domain3_architectures: { + title: 'Enterprise AI Reference Architectures & Trust/Compliance Stacks', + architectures: [ + { + id: 'ARCH-1', name: 'Enterprise AI Platform (EAIP) Mesh', + components: [ + { component: 'Service Mesh', technology: 'gRPC + Envoy + Istio', function: 'Secure inter-service communication', scale: '12,200 RPC/s' }, + { component: 'Identity', technology: 'SPIFFE/SPIRE', function: 'Workload identity, mTLS', scale: '26 AI systems' }, + { component: 'API Gateway', technology: 'Kong + custom plugins', function: 'Rate limiting, auth, policy check', scale: '48,000 req/s' }, + { component: 'Policy Sidecar', technology: 'OPA Envoy Plugin', function: 'Inline policy evaluation', scale: 'P99 3.8 ms' }, + { component: 'Observability', technology: 'OpenTelemetry + Jaeger + Prometheus', function: 'Distributed tracing, metrics', scale: 'Full mesh' }, + { component: 'Secrets', technology: 'HashiCorp Vault', function: 'Secrets, certs, rotation', scale: 'Auto-rotate 90d' }, + { component: 'Config', technology: 'etcd + OPA bundles', function: 'Distributed config, policy sync', scale: '< 60s propagation' } + ] + }, + { + id: 'ARCH-2', name: 'Sentinel Governance Platform', + components: [ + { component: 'Rule Engine', technology: 'Sentinel Core v4.2', function: 'Real-time rule evaluation', scale: '298K evals/day' }, + { component: 'Rule Store', technology: 'PostgreSQL + Redis', function: 'Rule storage, caching', scale: '1,024 rules' }, + { component: 'Event Bus', technology: 'Apache Kafka (WORM)', function: 'Immutable event streaming', scale: '52K events/s' }, + { component: 'Analytics', technology: 'Apache Flink + custom', function: 'Real-time risk analytics', scale: '1.8M events/day' }, + { component: 'Dashboard', technology: 'React + Grafana', function: 'Real-time governance dashboard', scale: '12 dashboards' }, + { component: 'Integration', technology: 'REST + gRPC + Kafka', function: 'Multi-protocol integration', scale: '45 integrations' }, + { component: 'ML Anomaly', technology: 'Isolation Forest + LSTM', function: 'Behavioral anomaly detection', scale: '< 200ms' } + ] + }, + { + id: 'ARCH-3', name: 'HA-RAG (High-Availability RAG)', + components: [ + { component: 'Vector Store', technology: 'Qdrant (clustered)', function: 'Document embeddings', scale: '2.8M vectors' }, + { component: 'Embeddings', technology: 'text-embedding-3-large', function: 'Document + query encoding', scale: '768 dim' }, + { component: 'Reranker', technology: 'cross-encoder/ms-marco', function: 'Passage reranking', scale: 'Top-20 -> Top-5' }, + { component: 'LLM Backbone', technology: 'GPT-4o + Claude 3.5', function: 'Generation', scale: '52,400 queries/week' }, + { component: 'Provenance', technology: 'Merkle hash + 4-layer audit', function: 'Source + confidence tracking', scale: 'Art. 52 compliant' }, + { component: 'Cache', technology: 'Redis + semantic dedup', function: 'Response caching', scale: '34% hit rate' }, + { component: 'Governance', technology: 'OPA inline check', function: 'Query-level policy', scale: 'Every query' } + ] + }, + { + id: 'ARCH-4', name: 'WorkflowAI Pro', + components: [ + { component: 'Orchestrator', technology: 'Temporal.io', function: 'Workflow orchestration', scale: '14K workflows/day' }, + { component: 'Agent Runtime', technology: 'Custom Python + LangGraph', function: 'Agent execution', scale: 'L0-L4 agents' }, + { component: 'Governance Sidecar', technology: 'OPA + behavioral monitor', function: 'Real-time governance', scale: 'Per-workflow' }, + { component: 'Human-in-Loop', technology: 'Custom React UI', function: 'Approval + override', scale: 'Per DEPTHS level' }, + { component: 'Audit', technology: 'Kafka + S3', function: 'Complete workflow audit', scale: '7-year retention' }, + { component: 'Kill-switch', technology: 'HW + SW redundant', function: 'Emergency termination', scale: '50-280 ms' } + ] + }, + { + id: 'ARCH-5', name: 'CCaaS AI (Contact Center)', + components: [ + { component: 'Speech-to-Text', technology: 'Whisper v3 + fine-tune', function: 'Real-time transcription', scale: '2,400 concurrent' }, + { component: 'NLU', technology: 'Custom BERT + intent', function: 'Intent + entity extraction', scale: '340 intents' }, + { component: 'Dialog Manager', technology: 'Rasa + custom FSM', function: 'Conversation management', scale: 'Multi-turn' }, + { component: 'Sentiment', technology: 'Custom model', function: 'Real-time scoring', scale: 'Per-utterance' }, + { component: 'Compliance', technology: 'OPA real-time + recording', function: 'FCRA/TCPA compliance', scale: '100% calls' }, + { component: 'Quality', technology: 'Custom scorer', function: 'Agent quality scoring', scale: 'Real-time' } + ] + } + ], + trustStack: [ + { layer: 'L1', name: 'Identity & Access', function: 'Workload + human identity', technology: 'SPIFFE/SPIRE + Okta + RBAC', metric: 'Zero-trust verified' }, + { layer: 'L2', name: 'Policy Enforcement', function: 'Real-time policy decisions', technology: 'OPA (336) + Sentinel (1,024)', metric: 'P99 3.8 ms' }, + { layer: 'L3', name: 'Cryptographic Assurance', function: 'Data protection + integrity', technology: 'AES-256-GCM, TLS 1.3, Merkle', metric: '100% coverage' }, + { layer: 'L4', name: 'Audit & Evidence', function: 'Immutable decision logs', technology: 'Kafka WORM + S3 Glacier', metric: '7-year retention' }, + { layer: 'L5', name: 'Risk Analytics', function: 'Continuous risk scoring', technology: 'ARS engine (14-dim) + anomaly', metric: 'Real-time' }, + { layer: 'L6', name: 'Compliance Reporting', function: 'Automated regulatory reports', technology: 'Custom generators + templates', metric: '8 frameworks' }, + { layer: 'L7', name: 'Model Registry', function: 'Model lifecycle governance', technology: 'MLflow + custom + provenance', metric: '100% tracked' } + ], + modelRegistry: { + components: [ + { component: 'Version Control', technology: 'MLflow + DVC', function: 'Model versioning, experiment tracking' }, + { component: 'Metadata Store', technology: 'PostgreSQL + custom schema', function: 'Model cards, risk class, validation status' }, + { component: 'Artifact Store', technology: 'S3 + cryptographic signing', function: 'Model binaries, training data refs' }, + { component: 'Provenance Chain', technology: 'Merkle tree + blockchain anchor', function: 'Immutable model provenance' }, + { component: 'Validation Status', technology: 'Custom state machine', function: 'Draft -> Validated -> Approved -> Prod -> Deprecated' }, + { component: 'Access Control', technology: 'SPIFFE + RBAC', function: 'Role-based model access' }, + { component: 'Monitoring Integration', technology: 'OpenTelemetry hooks', function: 'Performance + drift signals' } + ] + } + }, + + // ─── DOMAIN 4: Global Legal & Compute Governance ────────────────────────── + domain4_globalGovernance: { + title: 'Global Legal & Compute Governance', + icgc: { + mission: 'Establish multilateral framework for governing compute resources used in frontier AI development', + structure: [ + { body: 'Assembly', function: 'Strategic direction, treaty ratification', composition: 'All member states (1 vote each)', cadence: 'Annual' }, + { body: 'Steering Council', function: 'Operational governance, budget', composition: '15 rotating members', cadence: 'Quarterly' }, + { body: 'Technical Bureau', function: 'Standards, protocols, auditing', composition: '50 technical experts', cadence: 'Monthly' }, + { body: 'Secretariat', function: 'Administration, coordination', composition: 'Permanent staff (est. 200)', cadence: 'Continuous' }, + { body: 'Dispute Resolution', function: 'Arbitration, sanctions', composition: '7 judicial members', cadence: 'As needed' } + ] + }, + globalComponents: [ + { id: 'GC-01', acronym: 'GACRA', fullName: 'Global AI Compute Resource Authority', function: 'Compute allocation, licensing, monitoring', status: 'Proposed' }, + { id: 'GC-02', acronym: 'GASO', fullName: 'Global AI Safety Office', function: 'Safety standards, incident coordination', status: 'Pilot (EU + US)' }, + { id: 'GC-03', acronym: 'GFMCF', fullName: 'Global Frontier Model Certification Framework', function: 'Pre-deployment certification for frontier models', status: 'Draft' }, + { id: 'GC-04', acronym: 'GAICS', fullName: 'Global AI Incident Classification System', function: 'Standardized incident severity and reporting', status: 'Draft' }, + { id: 'GC-05', acronym: 'GAIVS', fullName: 'Global AI Incident Verification System', function: 'Independent incident investigation', status: 'Proposed' }, + { id: 'GC-06', acronym: 'GACP', fullName: 'Global AI Compute Passport', function: 'Portable compute usage credentials', status: 'Proposed' }, + { id: 'GC-07', acronym: 'GATI', fullName: 'Global AI Treaty Infrastructure', function: 'Treaty management, compliance tracking', status: 'Concept' }, + { id: 'GC-08', acronym: 'GACMO', fullName: 'Global AI Capability Monitoring Observatory', function: 'Track frontier capabilities worldwide', status: 'Pilot (3 countries)' }, + { id: 'GC-09', acronym: 'FTEWS', fullName: 'Frontier Technology Early Warning System', function: 'Capability jump detection, risk alerts', status: 'Prototype' }, + { id: 'GC-10', acronym: 'GAI-SOC', fullName: 'Global AI Security Operations Center', function: '24/7 AI threat monitoring and response', status: 'Pilot' }, + { id: 'GC-11', acronym: 'GAIGA', fullName: 'Global AI Governance Assembly', function: 'Legislative body for international AI law', status: 'Proposed' }, + { id: 'GC-12', acronym: 'GACRLS', fullName: 'Global AI Compute Resource Licensing System', function: 'Compute license issuance and compliance', status: 'Draft' }, + { id: 'GC-13', acronym: 'GFCO', fullName: 'Global Frontier Compute Observatory', function: 'Monitor global compute build-out and allocation', status: 'Concept' }, + { id: 'GC-14', acronym: 'GAID', fullName: 'Global AI Insurance and Indemnification', function: 'Risk pooling, liability frameworks', status: 'Concept' }, + { id: 'GC-15', acronym: 'GASCF', fullName: 'Global AI Safety Certification Framework', function: 'Multi-tier safety certification (Levels 1-5)', status: 'Draft' } + ], + computeRegistry: { + description: 'Machine-readable schema for global compute facility registration', + fields: [ + { field: 'facility_id', type: 'UUID', description: 'Unique facility identifier', required: true }, + { field: 'operator', type: 'string', description: 'Operating entity', required: true }, + { field: 'jurisdiction', type: 'ISO 3166-1', description: 'Primary jurisdiction', required: true }, + { field: 'total_flops', type: 'float', description: 'Peak FP16 FLOPS capacity', required: true }, + { field: 'gpu_type', type: 'enum', description: 'Hardware type (H100, B200, etc.)', required: true }, + { field: 'gpu_count', type: 'integer', description: 'Total GPU count', required: true }, + { field: 'power_mw', type: 'float', description: 'Power consumption (MW)', required: true }, + { field: 'pue', type: 'float', description: 'Power Usage Effectiveness', required: true }, + { field: 'frontier_model_training', type: 'boolean', description: 'Used for frontier model training', required: true }, + { field: 'safety_cert_level', type: 'enum(1-5)', description: 'GASCF certification level', required: true }, + { field: 'last_audit_date', type: 'date', description: 'Last compliance audit', required: true } + ] + }, + sentinelGlobalIntegration: [ + { point: 'GACRA Registration', protocol: 'REST + mTLS', function: 'Compute facility registration', latency: '< 500ms' }, + { point: 'GAICS Event Reporting', protocol: 'Kafka + gRPC', function: 'Real-time incident forwarding', latency: '< 200ms' }, + { point: 'GASCF Cert Check', protocol: 'OPA + REST', function: 'Pre-deployment cert validation', latency: '< 50ms' }, + { point: 'GACMO Capability', protocol: 'Batch + streaming', function: 'Capability metrics and registry', latency: '15-min batch' }, + { point: 'FTEWS Alerts', protocol: 'WebSocket + gRPC', function: 'Bidirectional alert exchange', latency: '< 100ms' }, + { point: 'GAI-SOC Threat Intel', protocol: 'STIX/TAXII + REST', function: 'Threat intelligence sharing', latency: 'Near real-time' } + ] + }, + + // ─── DOMAIN 5: Financial Services ───────────────────────────────────────── + domain5_financialServices: { + title: 'Financial Services AI Governance', + regulations: [ + { name: 'SR 11-7 (OCC/Fed)', scope: 'Model risk management', aiImpact: 'All AI/ML models in banking' }, + { name: 'FCRA', scope: 'Consumer credit reporting', aiImpact: 'Credit scoring AI models' }, + { name: 'ECOA (Reg B)', scope: 'Equal credit opportunity', aiImpact: 'Any credit decision AI' }, + { name: 'EU AI Act', scope: 'High-risk AI systems', aiImpact: 'Credit scoring = Annex III' }, + { name: 'GDPR Art. 22', scope: 'Automated decision-making', aiImpact: 'All automated credit decisions' }, + { name: 'Basel III/IV', scope: 'Capital adequacy', aiImpact: 'Risk model governance' } + ], + sr117Framework: [ + { phase: 1, section: 'ss. 5-6', name: 'Model Development', activities: 'Conceptual soundness, data quality', controls: 'OPA PG-05 rules 1-10' }, + { phase: 2, section: 'ss. 4, 8', name: 'Model Validation', activities: 'Independent review, backtesting', controls: 'OPA PG-05 rules 11-18' }, + { phase: 3, section: 'ss. 7', name: 'Model Documentation', activities: 'Model cards, tech docs', controls: 'Auto-generated templates' }, + { phase: 4, section: 'ss. 10', name: 'Ongoing Monitoring', activities: 'Performance tracking, outcomes', controls: 'Sentinel rules FS-001 to FS-120' }, + { phase: 5, section: 'ss. 12', name: 'Vendor Model Risk', activities: 'Third-party assessment', controls: 'OPA PG-09 + vendor scorecards' }, + { phase: 6, section: 'ss. 3', name: 'Governance', activities: 'Board oversight, reporting', controls: 'Quarterly reports' } + ], + creditScoring: { + fairLending: [ + { protectedClass: 'Race/Ethnicity', metric: 'Approval rate ratio', threshold: '>= 0.80', current: 0.84, status: 'Pass' }, + { protectedClass: 'Sex/Gender', metric: 'Approval rate ratio', threshold: '>= 0.80', current: 0.88, status: 'Pass' }, + { protectedClass: 'Age', metric: 'Approval rate ratio', threshold: '>= 0.80', current: 0.82, status: 'Pass' }, + { protectedClass: 'National Origin', metric: 'Approval rate ratio', threshold: '>= 0.80', current: 0.86, status: 'Pass' }, + { protectedClass: 'Marital Status', metric: 'Approval rate ratio', threshold: '>= 0.80', current: 0.91, status: 'Pass' }, + { protectedClass: 'Religion', metric: 'Approval rate ratio', threshold: '>= 0.80', current: 0.94, status: 'Pass' } + ], + components: [ + { component: 'Disparate Impact Testing', technology: 'Fairlearn + custom', metric: 'DI >= 0.80 (target >= 0.87)' }, + { component: 'Adverse Action Engine', technology: 'Custom rule engine', metric: '100% of denials' }, + { component: 'HMDA Reporting', technology: 'Automated pipeline', metric: 'Quarterly filing' }, + { component: 'Explainability', technology: 'SHAP + LIME + counterfactuals', metric: 'Per-decision' }, + { component: 'Backtesting', technology: 'Custom backtesting suite', metric: 'Monthly' }, + { component: 'Override Logging', technology: 'Audit trail + justification', metric: '100% of overrides' } + ] + }, + earl: [ + { level: 1, name: 'Initial', description: 'Ad-hoc AI, minimal governance', investment: '$0.8M' }, + { level: 2, name: 'Developing', description: 'Formal policies, partial monitoring', investment: '$2.4M' }, + { level: 3, name: 'Defined', description: 'Comprehensive framework operational', investment: '$6.8M' }, + { level: 4, name: 'Managed', description: 'Quantitative governance, continuous monitoring', investment: '$14.2M' }, + { level: 5, name: 'Optimizing', description: 'Predictive governance, AGI-ready', investment: '$28.6M' } + ], + currentEARL: 3, + targetEARL: { level: 4, date: 'Q4 2027' }, + gsifiPremium: '$2.12M/yr' + }, + + // ─── DOMAIN 6: AGI Safety & Trust-by-Design ─────────────────────────────── + domain6_agiSafety: { + title: 'Frontier AGI Safety & Trust-by-Design', + evolutionModel: [ + { stage: 'S1', name: 'Rule-based Systems', capability: 'Deterministic logic', governance: 'Standard IT governance', timeline: 'Pre-2020', arl: '---' }, + { stage: 'S2', name: 'Statistical ML', capability: 'Pattern recognition', governance: 'Model validation (SR 11-7)', timeline: '2015-2022', arl: 'ARL-1' }, + { stage: 'S3', name: 'Deep Learning', capability: 'Representation learning', governance: 'Bias testing, explainability', timeline: '2018-2024', arl: 'ARL-1' }, + { stage: 'S4', name: 'Foundation Models', capability: 'General language/vision/code', governance: 'EU AI Act, comprehensive', timeline: '2022-2026', arl: 'ARL-2' }, + { stage: 'S5', name: 'Agentic AI', capability: 'Autonomous task execution', governance: 'Agent governance, kill-switch', timeline: '2024-2027', arl: 'ARL-3' }, + { stage: 'S6', name: 'Multi-agent Systems', capability: 'Coordinated agent networks', governance: 'EAIP, swarm governance', timeline: '2025-2028', arl: 'ARL-4' }, + { stage: 'S7', name: 'Narrow AGI', capability: 'Human-level in domains', governance: 'GASCF Level 3, containment', timeline: '2027-2029', arl: 'ARL-5' }, + { stage: 'S8', name: 'Broad AGI', capability: 'Human-level across domains', governance: 'GASCF Level 4, international', timeline: '2028-2030', arl: 'ARL-6' }, + { stage: 'S9', name: 'Transformative AGI', capability: 'Superhuman in most domains', governance: 'GASCF Level 5, ICGC', timeline: '2029-2031', arl: 'ARL-6' }, + { stage: 'S10', name: 'ASI', capability: 'Superintelligent capabilities', governance: 'Civilizational, GATI treaties', timeline: '2030+', arl: 'ARL-7' } + ], + cognitiveResonance: { + version: '2.1', + components: [ + { name: 'Value Alignment Engine', function: 'Map AI decisions to organizational values', implementation: 'Constitutional AI + RLHF + custom rubrics', metric: '83.8%' }, + { name: 'Resonance Monitoring', function: 'Detect alignment drift in real-time', implementation: 'Embedding similarity + threshold alerts', metric: '< 12 min' }, + { name: 'Human-AI Feedback Loop', function: 'Structured bidirectional communication', implementation: 'Review interfaces, escalation protocols', metric: '97.6% acceptance' }, + { name: 'Cultural Calibration', function: 'Adapt AI to organizational culture', implementation: 'Fine-tuning on organizational corpus', metric: '80.2%' }, + { name: 'Ethical Boundary Enforcement', function: 'Hard constraints on AI behavior', implementation: 'OPA policies + runtime enforcement', metric: '100%' }, + { name: 'Cognitive Load Balancing', function: 'Optimize human-AI task allocation', implementation: 'Workload analytics, complexity scoring', metric: '88.4%' }, + { name: 'Societal Impact Assessment', function: 'Broader societal implications', implementation: 'Impact frameworks + external review', metric: 'Quarterly' }, + { name: 'Multi-stakeholder Input', function: 'Diverse stakeholder values', implementation: 'Structured engagement + surveys', metric: 'Annual' } + ] + }, + crisisSimulations: [ + { id: 'SIM-01', scenario: 'High-risk AI system failure in production', participants: 'IT + AI Gov + CRO', duration: '4h', frequency: 'Quarterly', lastRun: 'Q1 2026' }, + { id: 'SIM-02', scenario: 'Autonomous agent exceeds authorized scope', participants: 'AI Safety + Legal + Board', duration: '6h', frequency: 'Semi-annual', lastRun: 'Q4 2025' }, + { id: 'SIM-03', scenario: 'AI content causes reputational crisis', participants: 'PR + Legal + CAIO', duration: '3h', frequency: 'Quarterly', lastRun: 'Q1 2026' }, + { id: 'SIM-04', scenario: 'Regulatory enforcement (EU AI Act)', participants: 'Legal + Compliance + Board', duration: '4h', frequency: 'Semi-annual', lastRun: 'Q4 2025' }, + { id: 'SIM-05', scenario: 'AGI capability emergence (tabletop)', participants: 'Board + CAIO + VP Safety + External', duration: '8h', frequency: 'Annual', lastRun: 'Q1 2026' }, + { id: 'SIM-06', scenario: 'Multi-agent coordination failure', participants: 'Platform Eng + AI Safety', duration: '4h', frequency: 'Semi-annual', lastRun: 'Q1 2026' }, + { id: 'SIM-07', scenario: 'Supply-chain compromise (model poisoning)', participants: 'CISO + AI Safety + Vendor Mgmt', duration: '6h', frequency: 'Annual', lastRun: 'Q4 2025' }, + { id: 'SIM-08', scenario: 'Multi-jurisdiction regulatory action', participants: 'Legal + GC + Board + Regional', duration: '8h', frequency: 'Annual', lastRun: 'Q1 2026' } + ], + mvags: { + deploymentTime: '48 hours', + monthlyCost: '$2,400', + components: [ + { component: 'AI System Inventory', tool: 'Spreadsheet + REST API', hours: 4, cost: '$0', coverage: 'EU AI Act Art. 6, NIST MAP-1' }, + { component: 'Risk Classification', tool: 'OPA (12 core rules)', hours: 8, cost: '$200', coverage: 'EU AI Act Art. 6-9, NIST MAP-2' }, + { component: 'Policy Engine', tool: 'OPA Community Edition', hours: 4, cost: '$0', coverage: 'Multi-framework' }, + { component: 'Monitoring', tool: 'Prometheus + Grafana OSS', hours: 8, cost: '$400', coverage: 'EU AI Act Art. 72, NIST MANAGE' }, + { component: 'Audit Trail', tool: 'Kafka + S3 (min config)', hours: 12, cost: '$800', coverage: 'EU AI Act Art. 12, GDPR Art. 30' }, + { component: 'Dashboard', tool: 'Grafana + custom panels', hours: 8, cost: '$200', coverage: 'Transparency' }, + { component: 'Incident Response', tool: 'PagerDuty Free + runbooks', hours: 4, cost: '$0', coverage: 'EU AI Act Art. 62, NIST MANAGE' }, + { component: 'Cloud Infrastructure', tool: 'AWS/GCP/Azure', hours: 0, cost: '$800', coverage: 'N/A' } + ] + }, + trustByDesign: [ + { id: 'TD-01', principle: 'Value alignment by default', verification: 'CRP alignment score >= 80%' }, + { id: 'TD-02', principle: 'Minimal authority', verification: 'SPIFFE scope audit' }, + { id: 'TD-03', principle: 'Transparent reasoning', verification: 'SHAP/LIME coverage 100%' }, + { id: 'TD-04', principle: 'Human agency preservation', verification: 'Override success rate tracking' }, + { id: 'TD-05', principle: 'Reversibility', verification: 'Rollback test quarterly' }, + { id: 'TD-06', principle: 'Privacy by design', verification: 'GDPR Art. 25 compliance' }, + { id: 'TD-07', principle: 'Robustness under adversarial conditions', verification: 'Quarterly adversarial audit' }, + { id: 'TD-08', principle: 'Societal benefit alignment', verification: 'Annual societal review' }, + { id: 'TD-09', principle: 'Containment readiness', verification: 'Kill-switch test quarterly' }, + { id: 'TD-10', principle: 'Graceful degradation', verification: 'Chaos engineering monthly' } + ] + }, + + // ─── DOMAIN 7: Master Blueprint ─────────────────────────────────────────── + domain7_blueprint: { + title: 'AGI Governance Master Blueprint (Unified)', + threeScaleIntegration: [ + { scale: 'Enterprise', scope: 'Day-to-day AI operations', governance: '6-layer + 336 OPA rules', interface: 'EAIP Mesh API' }, + { scale: 'Frontier', scope: 'AGI safety + trust-by-design', governance: 'CRP + GASCF + crisis sims', interface: 'Sentinel Platform' }, + { scale: 'Civilizational', scope: 'International compute + incidents', governance: 'ICGC + 15 global components', interface: 'GACRA/GASO APIs' } + ], + sentinelPlatform: { + version: '4.2', + components: [ + { component: 'Sentinel Core', technology: 'Custom Go + Rust', scale: '298K evals/day', sla: '99.97% uptime' }, + { component: 'Rule Engine', technology: 'CEL + custom DSL', scale: '1,024 rules', sla: 'P99 4.1 ms' }, + { component: 'Event Processor', technology: 'Apache Kafka 3.7', scale: '52K events/s', sla: 'Zero message loss' }, + { component: 'Analytics Engine', technology: 'Apache Flink 1.18', scale: '1.8M events/day', sla: '< 5s window' }, + { component: 'State Store', technology: 'PostgreSQL 16 + Redis 7.2', scale: '100M+ records', sla: 'Multi-AZ' }, + { component: 'ML Pipeline', technology: 'PyTorch 2.3 + ONNX 1.17', scale: '12 models', sla: 'GPU-accelerated' }, + { component: 'API Layer', technology: 'gRPC + REST', scale: '12,200 RPC/s', sla: 'P99 8.2 ms' }, + { component: 'Dashboard', technology: 'React + D3.js + Grafana', scale: '12 dashboards', sla: '< 2s refresh' } + ] + }, + agiReadinessLayers: [ + { level: 'ARL-1', name: 'Foundation', requirements: 'AI inventory, basic policies, risk awareness', investment: '$1.4M', timeline: 'Month 1-3' }, + { level: 'ARL-2', name: 'Structured', requirements: 'Formal governance, OPA 50+ rules, basic monitoring', investment: '$4.2M', timeline: 'Month 3-9' }, + { level: 'ARL-3', name: 'Managed', requirements: 'Full Sentinel, continuous monitoring, SR 11-7', investment: '$9.8M', timeline: 'Month 9-18' }, + { level: 'ARL-4', name: 'Advanced', requirements: 'EAIP mesh, autonomous agent governance, EARL-4', investment: '$14.8M', timeline: 'Month 18-30' }, + { level: 'ARL-5', name: 'AGI-Ready', requirements: 'GASCF certified, crisis-tested, CRP operational', investment: '$18.6M', timeline: 'Month 30-42' }, + { level: 'ARL-6', name: 'AGI-Operational', requirements: 'AGI in production, full containment, ICGC', investment: '$26.4M', timeline: 'Month 42-54' }, + { level: 'ARL-7', name: 'ASI-Prepared', requirements: 'Civilizational governance, GATI treaty', investment: '$42.8M', timeline: 'Month 54+' } + ], + rollout: { + days1to30: [ + { week: 'W1', activities: 'AI system inventory audit, stakeholder mapping', deliverables: 'Complete inventory, RACI draft', owner: 'CAIO' }, + { week: 'W2', activities: 'Risk classification, OPA pilot (25 rules)', deliverables: 'Risk register v1, OPA running', owner: 'VP AI Gov' }, + { week: 'W3', activities: 'Board Sub-committee charter, CAIO formalization', deliverables: 'Charter approved, CAIO onboarded', owner: 'CEO' }, + { week: 'W4', activities: 'MVAGS deployment, basic monitoring, playbook v1', deliverables: 'MVAGS operational, dashboards live', owner: 'CTO' } + ], + days31to60: [ + { week: 'W5', activities: 'OPA expansion (100+ rules), Sentinel pilot', deliverables: 'Expanded policy coverage', owner: 'VP AI Gov' }, + { week: 'W6', activities: 'Data governance framework, PII detection', deliverables: 'Data quality gates, PII scanner', owner: 'CDO' }, + { week: 'W7', activities: 'CI/CD gates (G1-G5), model registry launch', deliverables: 'Pipeline gates active, registry operational', owner: 'CTO' }, + { week: 'W8', activities: 'SR 11-7 compliance, fair lending testing', deliverables: 'Gap analysis, DI test results', owner: 'CRO' } + ], + days61to90: [ + { week: 'W9', activities: 'Full OPA (336 rules), Sentinel production', deliverables: 'Full policy enforcement', owner: 'VP AI Gov' }, + { week: 'W10', activities: 'EU AI Act conformity assessment prep', deliverables: 'Conformity documentation', owner: 'GC' }, + { week: 'W11', activities: 'ISO 42001 Phase 1-2, crisis simulation SIM-01', deliverables: 'AIMS scope, simulation report', owner: 'VP AI Gov' }, + { week: 'W12', activities: 'EARL assessment, board reporting, review', deliverables: 'EARL score, board presentation', owner: 'CAIO' } + ] + }, + eightWeekPlan: [ + { week: 'W1', focus: 'Infrastructure', tasks: 'Deploy OPA, Kafka cluster, monitoring stack', criteria: 'OPA health OK, Kafka 3-node, Prometheus collecting' }, + { week: 'W2', focus: 'Policy', tasks: 'Load 336 OPA rules, configure bundles, test', criteria: 'All rules loaded, sync < 60s' }, + { week: 'W3', focus: 'Sentinel', tasks: 'Deploy Sentinel Core, load 1,024 rules', criteria: 'Evaluating, Kafka integration confirmed' }, + { week: 'W4', focus: 'EAIP', tasks: 'Deploy mesh, SPIFFE/SPIRE, API gateway', criteria: 'gRPC operational, mTLS verified' }, + { week: 'W5', focus: 'Data', tasks: 'Deploy quality gates, PII scanner, lineage', criteria: 'Gate active, PII > 99.5%' }, + { week: 'W6', focus: 'CI/CD', tasks: 'Implement 8 governance gates, model registry', criteria: 'All gates active, registry operational' }, + { week: 'W7', focus: 'Monitoring', tasks: 'Full OpenTelemetry, dashboards, alerting', criteria: '12 dashboards, alerting configured' }, + { week: 'W8', focus: 'Validation', tasks: 'E2E testing, load testing, security audit', criteria: '100% pass, load pass, audit clear' } + ] + }, + + // ─── Investment & Risk ──────────────────────────────────────────────────── + investment: { + fiveYearProfile: [ + { year: 'Y1 (2026)', investment: '$16.8M', cumulative: '$16.8M', milestones: 'MVAGS -> Full OPA/Sentinel, ISO started' }, + { year: 'Y2 (2027)', investment: '$14.6M', cumulative: '$31.4M', milestones: 'EAIP mesh, EARL-4, ISO certified, GASCF L2' }, + { year: 'Y3 (2028)', investment: '$13.2M', cumulative: '$44.6M', milestones: 'ARL-5, CRP operational, crisis-tested' }, + { year: 'Y4 (2029)', investment: '$12.8M', cumulative: '$57.4M', milestones: 'ICGC pilot, AGI containment infra' }, + { year: 'Y5 (2030)', investment: '$11.0M', cumulative: '$68.4M', milestones: 'ARL-6/7 readiness, civilizational gov' } + ], + financials: { + totalInvestment: '$68.4M', + npv: '$118.6M', + irr: '42.3%', + paybackPeriod: '2.1 years', + annualSavings: '$54.2M', + costOfNoncompliance: '$38.4M/yr avoided', + roi: '2.8x' + } + }, + + riskRegister: [ + { id: 'R-001', risk: 'EU AI Act non-compliance fine (up to 7% turnover)', likelihood: 'Medium', impact: 'Critical', score: 'HIGH', mitigation: 'OPA rules, Sentinel monitoring, legal review', owner: 'VP AI Gov', status: 'MITIGATING' }, + { id: 'R-002', risk: 'Autonomous agent financial loss > $10M', likelihood: 'Medium', impact: 'Critical', score: 'HIGH', mitigation: 'Kill-switch, behavioral sidecar, scope limits', owner: 'VP AI Safety', status: 'MITIGATING' }, + { id: 'R-003', risk: 'AI model bias class-action lawsuit', likelihood: 'Medium', impact: 'High', score: 'HIGH', mitigation: 'Fairness testing, DI monitoring, FCRA/ECOA', owner: 'CRO', status: 'MITIGATING' }, + { id: 'R-004', risk: 'PII breach (GDPR fine up to 4% turnover)', likelihood: 'Medium', impact: 'High', score: 'HIGH', mitigation: 'DLP, PII scanning, encryption, GDPR controls', owner: 'CISO', status: 'MITIGATING' }, + { id: 'R-005', risk: 'Model performance degradation in production', likelihood: 'High', impact: 'Medium', score: 'HIGH', mitigation: 'Drift detection, SLO monitoring, auto-rollback', owner: 'CTO', status: 'MITIGATING' }, + { id: 'R-006', risk: 'Third-party AI supply-chain compromise', likelihood: 'Medium', impact: 'High', score: 'HIGH', mitigation: 'Vendor assessment, provenance, sandboxing', owner: 'CISO', status: 'MITIGATING' }, + { id: 'R-007', risk: 'AGI emergence without governance readiness', likelihood: 'Low', impact: 'Critical', score: 'HIGH', mitigation: 'ARL advancement, crisis simulations, GASCF', owner: 'CAIO', status: 'MITIGATING' }, + { id: 'R-008', risk: 'Regulatory fragmentation > 30% cost increase', likelihood: 'High', impact: 'Medium', score: 'HIGH', mitigation: 'Multi-regime OPA, regulatory engagement', owner: 'GC', status: 'MITIGATING' }, + { id: 'R-009', risk: 'Key person dependency in AI governance', likelihood: 'Medium', impact: 'Medium', score: 'MEDIUM', mitigation: 'Succession planning, cross-training, docs', owner: 'CAIO', status: 'MITIGATING' }, + { id: 'R-010', risk: 'Competitor governance eroding market position', likelihood: 'Medium', impact: 'Medium', score: 'MEDIUM', mitigation: 'Accelerated program, ISO certification', owner: 'CTO/CRO', status: 'MITIGATING' }, + { id: 'R-011', risk: 'Cloud provider concentration risk', likelihood: 'Medium', impact: 'High', score: 'HIGH', mitigation: 'Multi-cloud, portable workloads, EAIP', owner: 'CTO', status: 'MITIGATING' }, + { id: 'R-012', risk: 'Insufficient board AI literacy', likelihood: 'Medium', impact: 'Medium', score: 'MEDIUM', mitigation: 'Board education, external advisors', owner: 'CAIO', status: 'MITIGATING' } + ], + + keyMetrics: { + compliance: { score: '89.2%', opaRules: 336, sentinelRules: 1024, frameworks: 8, jurisdictions: 5 }, + performance: { eaipRps: 12200, eaipReliability: '99.98%', policyP99: '3.8ms', ragF1: '92.1%', dailyEvals: '1.8M' }, + risk: { ars: 58.2, dimensions: 14, arsTarget: 72.0, incidentResponse: '12 min' }, + financial: { investment: '$68.4M', npv: '$118.6M', irr: '42.3%', payback: '2.1 yr', roi: '2.8x' }, + readiness: { currentARL: 'ARL-2', currentEARL: 3, targetARL: 'ARL-5', targetEARL: 4 } + } +}; + +// ── GAF API Routes ────────────────────────────────────────────────────────── + +const GAF = GOVERNANCE_ARCHITECTURES_FRAMEWORKS; + +// Metadata & Overview +app.get('/api/governance-architectures-frameworks', (_, res) => res.json(GAF)); +app.get('/api/governance-architectures-frameworks/metadata', (_, res) => res.json(GAF.metadata)); +app.get('/api/governance-architectures-frameworks/kpis', (_, res) => res.json(GAF.kpis)); + +// Domains +app.get('/api/governance-architectures-frameworks/domains', (_, res) => res.json(GAF.domainsSummary)); +app.get('/api/governance-architectures-frameworks/domains/:id', (req, res) => { + const domain = GAF.domainsSummary.find(d => d.id === req.params.id.toUpperCase()); + if (!domain) return res.status(404).json({ error: `Domain ${req.params.id} not found` }); + const domainData = { + D1: GAF.domain1_governance, D2: GAF.domain2_regulatory, D3: GAF.domain3_architectures, + D4: GAF.domain4_globalGovernance, D5: GAF.domain5_financialServices, D6: GAF.domain6_agiSafety, + D7: GAF.domain7_blueprint + }; + res.json({ summary: domain, detail: domainData[domain.id] || {} }); +}); + +// Domain 1: Governance Layers +app.get('/api/governance-architectures-frameworks/governance-layers', (_, res) => res.json({ layers: GAF.domain1_governance.layers })); +app.get('/api/governance-architectures-frameworks/accountability', (_, res) => res.json(GAF.domain1_governance.accountability)); +app.get('/api/governance-architectures-frameworks/policy-infrastructure', (_, res) => res.json(GAF.domain1_governance.policyInfrastructure)); +app.get('/api/governance-architectures-frameworks/policy-infrastructure/opa-groups', (_, res) => res.json({ groups: GAF.domain1_governance.policyInfrastructure.opaGroups, total: GAF.domain1_governance.policyInfrastructure.totalOpaRules })); +app.get('/api/governance-architectures-frameworks/risk-management', (_, res) => res.json(GAF.domain1_governance.riskManagement)); +app.get('/api/governance-architectures-frameworks/risk-management/ars', (_, res) => res.json({ currentARS: GAF.domain1_governance.riskManagement.weightedARS, target2027: GAF.domain1_governance.riskManagement.arsTarget2027, target2030: GAF.domain1_governance.riskManagement.arsTarget2030, formula: GAF.domain1_governance.riskManagement.arsFormula, dimensions: GAF.domain1_governance.riskManagement.taxonomy.length })); +app.get('/api/governance-architectures-frameworks/data-infrastructure', (_, res) => res.json({ components: GAF.domain1_governance.dataInfrastructure })); +app.get('/api/governance-architectures-frameworks/dev-deploy', (_, res) => res.json({ pipeline: GAF.domain1_governance.devDeployPipeline })); +app.get('/api/governance-architectures-frameworks/dev-deploy/gates', (_, res) => res.json({ gates: GAF.domain1_governance.cicdGates })); +app.get('/api/governance-architectures-frameworks/monitoring', (_, res) => res.json({ stack: GAF.domain1_governance.monitoring })); + +// Domain 2: Regulatory +app.get('/api/governance-architectures-frameworks/regulatory', (_, res) => res.json({ frameworks: GAF.domain2_regulatory.frameworks, complianceScore: GAF.domain2_regulatory.overallComplianceScore, totalOpaRules: GAF.domain2_regulatory.totalOpaRules })); +app.get('/api/governance-architectures-frameworks/regulatory/frameworks', (_, res) => res.json(GAF.domain2_regulatory.frameworks)); +app.get('/api/governance-architectures-frameworks/regulatory/eu-ai-act', (_, res) => res.json({ timeline: GAF.domain2_regulatory.euAiActTimeline })); +app.get('/api/governance-architectures-frameworks/regulatory/nist', (_, res) => res.json({ mapping: GAF.domain2_regulatory.nistMapping })); +app.get('/api/governance-architectures-frameworks/regulatory/iso42001', (_, res) => res.json({ roadmap: GAF.domain2_regulatory.iso42001Roadmap })); +app.get('/api/governance-architectures-frameworks/regulatory/obligations', (_, res) => res.json({ obligations: GAF.domain2_regulatory.crossRegimeObligations })); + +// Domain 3: Architectures & Trust Stack +app.get('/api/governance-architectures-frameworks/architectures', (_, res) => res.json(GAF.domain3_architectures.architectures.map(a => ({ id: a.id, name: a.name, componentCount: a.components.length })))); +app.get('/api/governance-architectures-frameworks/architectures/:id', (req, res) => { + const arch = GAF.domain3_architectures.architectures.find(a => a.id === req.params.id.toUpperCase()); + if (!arch) return res.status(404).json({ error: `Architecture ${req.params.id} not found` }); + res.json(arch); +}); +app.get('/api/governance-architectures-frameworks/trust-stack', (_, res) => res.json({ layers: GAF.domain3_architectures.trustStack })); +app.get('/api/governance-architectures-frameworks/trust-stack/model-registry', (_, res) => res.json(GAF.domain3_architectures.modelRegistry)); +app.get('/api/governance-architectures-frameworks/trust-stack/cicd-gates', (_, res) => res.json({ gates: GAF.domain1_governance.cicdGates })); + +// Domain 4: Global Governance +app.get('/api/governance-architectures-frameworks/global-governance', (_, res) => res.json({ icgc: GAF.domain4_globalGovernance.icgc, componentCount: GAF.domain4_globalGovernance.globalComponents.length })); +app.get('/api/governance-architectures-frameworks/global-governance/icgc', (_, res) => res.json(GAF.domain4_globalGovernance.icgc)); +app.get('/api/governance-architectures-frameworks/global-governance/components', (_, res) => res.json(GAF.domain4_globalGovernance.globalComponents)); +app.get('/api/governance-architectures-frameworks/global-governance/compute-registry', (_, res) => res.json(GAF.domain4_globalGovernance.computeRegistry)); +app.get('/api/governance-architectures-frameworks/global-governance/sentinel-integration', (_, res) => res.json(GAF.domain4_globalGovernance.sentinelGlobalIntegration)); + +// Domain 5: Financial Services +app.get('/api/governance-architectures-frameworks/financial-services', (_, res) => res.json({ regulations: GAF.domain5_financialServices.regulations, currentEARL: GAF.domain5_financialServices.currentEARL, targetEARL: GAF.domain5_financialServices.targetEARL, gsifiPremium: GAF.domain5_financialServices.gsifiPremium })); +app.get('/api/governance-architectures-frameworks/financial-services/sr117', (_, res) => res.json({ framework: GAF.domain5_financialServices.sr117Framework })); +app.get('/api/governance-architectures-frameworks/financial-services/credit-scoring', (_, res) => res.json(GAF.domain5_financialServices.creditScoring)); +app.get('/api/governance-architectures-frameworks/financial-services/fair-lending', (_, res) => res.json({ tests: GAF.domain5_financialServices.creditScoring.fairLending })); +app.get('/api/governance-architectures-frameworks/financial-services/earl', (_, res) => res.json({ levels: GAF.domain5_financialServices.earl, current: GAF.domain5_financialServices.currentEARL, target: GAF.domain5_financialServices.targetEARL })); + +// Domain 6: AGI Safety +app.get('/api/governance-architectures-frameworks/agi-safety', (_, res) => res.json({ evolutionStages: GAF.domain6_agiSafety.evolutionModel.length, crpVersion: GAF.domain6_agiSafety.cognitiveResonance.version, simulations: GAF.domain6_agiSafety.crisisSimulations.length, trustPrinciples: GAF.domain6_agiSafety.trustByDesign.length })); +app.get('/api/governance-architectures-frameworks/agi-safety/evolution', (_, res) => res.json({ stages: GAF.domain6_agiSafety.evolutionModel })); +app.get('/api/governance-architectures-frameworks/agi-safety/crp', (_, res) => res.json(GAF.domain6_agiSafety.cognitiveResonance)); +app.get('/api/governance-architectures-frameworks/agi-safety/crisis-simulations', (_, res) => res.json({ simulations: GAF.domain6_agiSafety.crisisSimulations })); +app.get('/api/governance-architectures-frameworks/agi-safety/mvags', (_, res) => res.json(GAF.domain6_agiSafety.mvags)); +app.get('/api/governance-architectures-frameworks/agi-safety/trust-by-design', (_, res) => res.json({ principles: GAF.domain6_agiSafety.trustByDesign })); + +// Domain 7: Blueprint +app.get('/api/governance-architectures-frameworks/blueprint', (_, res) => res.json({ scales: GAF.domain7_blueprint.threeScaleIntegration, sentinelVersion: GAF.domain7_blueprint.sentinelPlatform.version, arlLevels: GAF.domain7_blueprint.agiReadinessLayers.length })); +app.get('/api/governance-architectures-frameworks/blueprint/sentinel', (_, res) => res.json(GAF.domain7_blueprint.sentinelPlatform)); +app.get('/api/governance-architectures-frameworks/blueprint/agi-readiness', (_, res) => res.json({ layers: GAF.domain7_blueprint.agiReadinessLayers })); +app.get('/api/governance-architectures-frameworks/blueprint/global-compute', (_, res) => res.json({ components: GAF.domain4_globalGovernance.globalComponents, sentinelIntegration: GAF.domain4_globalGovernance.sentinelGlobalIntegration })); +app.get('/api/governance-architectures-frameworks/blueprint/rollout', (_, res) => res.json(GAF.domain7_blueprint.rollout)); +app.get('/api/governance-architectures-frameworks/blueprint/rollout/30-day', (_, res) => res.json(GAF.domain7_blueprint.rollout.days1to30)); +app.get('/api/governance-architectures-frameworks/blueprint/rollout/60-day', (_, res) => res.json(GAF.domain7_blueprint.rollout.days31to60)); +app.get('/api/governance-architectures-frameworks/blueprint/rollout/90-day', (_, res) => res.json(GAF.domain7_blueprint.rollout.days61to90)); +app.get('/api/governance-architectures-frameworks/blueprint/8-week-plan', (_, res) => res.json({ weeks: GAF.domain7_blueprint.eightWeekPlan })); + +// Investment & Risk +app.get('/api/governance-architectures-frameworks/investment', (_, res) => res.json(GAF.investment)); +app.get('/api/governance-architectures-frameworks/investment/risks', (_, res) => res.json({ riskRegister: GAF.riskRegister })); + +// Artifacts +app.get('/api/governance-architectures-frameworks/artifacts', (_, res) => res.json({ + schemas: [ + { name: 'AI System Registration', format: 'JSON Schema', path: '/artifacts/schemas/ai-system-registration.schema.json' }, + { name: 'Governance Architecture', format: 'JSON Schema', path: '/artifacts/schemas/governance-architecture.schema.json' }, + { name: 'Compute Registry', format: 'JSON Schema', path: '/artifacts/schemas/compute-registry.schema.json' }, + { name: 'GAF OpenAPI Spec', format: 'OpenAPI 3.1 YAML', path: '/artifacts/schemas/gaf-openapi.yaml' } + ], + policies: [ + { name: 'EU AI Act High-Risk Classification', format: 'OPA Rego', path: '/artifacts/policies/eu_ai_act_high_risk.rego' }, + { name: 'SR 11-7 Model Validation', format: 'OPA Rego', path: '/artifacts/policies/sr_11_7_model_validation.rego' }, + { name: 'Fair Lending Disparate Impact', format: 'OPA Rego', path: '/artifacts/policies/fair_lending_disparate_impact.rego' }, + { name: 'Agent Governance DEPTHS', format: 'OPA Rego', path: '/artifacts/policies/agent_governance_depths.rego' } + ], + data: [ + { name: 'Risk Register', format: 'CSV', path: '/artifacts/data/risk-register.csv' }, + { name: 'Compliance Matrix', format: 'CSV', path: '/artifacts/data/compliance-matrix.csv' }, + { name: 'Implementation Timeline', format: 'CSV', path: '/artifacts/data/implementation-timeline.csv' }, + { name: 'Global Governance Components', format: 'CSV', path: '/artifacts/data/global-governance-components.csv' }, + { name: 'AGI Readiness Assessment', format: 'CSV', path: '/artifacts/data/agi-readiness-assessment.csv' }, + { name: '30/60/90-Day Rollout', format: 'CSV', path: '/artifacts/data/rollout-30-60-90.csv' } + ] +})); + +// Metrics & Summary +app.get('/api/governance-architectures-frameworks/metrics', (_, res) => res.json(GAF.keyMetrics)); +app.get('/api/governance-architectures-frameworks/summary', (_, res) => res.json({ + docRef: GAF.metadata.docRef, + title: GAF.metadata.title, + version: GAF.metadata.version, + date: GAF.metadata.date, + scope: GAF.metadata.scope, + domains: GAF.domainsSummary, + kpis: GAF.kpis, + metrics: GAF.keyMetrics, + investment: GAF.investment.financials, + riskCount: GAF.riskRegister.length +})); +app.get('/api/governance-architectures-frameworks/dashboard', (_, res) => res.json({ + metadata: { docRef: GAF.metadata.docRef, version: GAF.metadata.version, date: GAF.metadata.date }, + domains: GAF.domainsSummary, + kpis: GAF.kpis, + layers: GAF.domain1_governance.layers, + frameworks: GAF.domain2_regulatory.frameworks, + architectures: GAF.domain3_architectures.architectures.map(a => ({ id: a.id, name: a.name })), + globalComponents: GAF.domain4_globalGovernance.globalComponents.map(c => ({ id: c.id, acronym: c.acronym, status: c.status })), + financialServices: { currentEARL: GAF.domain5_financialServices.currentEARL, targetEARL: GAF.domain5_financialServices.targetEARL }, + agiSafety: { evolutionStages: GAF.domain6_agiSafety.evolutionModel.length, crpVersion: GAF.domain6_agiSafety.cognitiveResonance.version }, + blueprint: { arl: GAF.domain7_blueprint.agiReadinessLayers, sentinel: GAF.domain7_blueprint.sentinelPlatform.version }, + metrics: GAF.keyMetrics, + investment: GAF.investment.financials +})); + + + +// ══════════════════════════════════════════════════════════════════════════════ +// SECTION: LEGACY MODULE METADATA ALIASES +// ══════════════════════════════════════════════════════════════════════════════ + +app.get('/api/gsifi-governance/metadata', (_, res) => res.json(GSIFI_GOVERNANCE.meta)); +app.get('/api/enterprise-strategy/metadata', (_, res) => res.json(ENTERPRISE_AI_STRATEGY.meta)); +app.get('/api/unified-master-reference/metadata', (_, res) => res.json(UNIFIED_MASTER_REFERENCE.meta)); +app.get('/api/agi-governance-unified/metadata', (_, res) => res.json(AGI_GOVERNANCE_UNIFIED.meta)); +app.get('/api/ai-governance/metadata', (_, res) => res.json(AI_GOVERNANCE.meta || { title: AI_GOVERNANCE.title, docRef: 'GOV-ANALYSIS-001' })); +app.get('/api/agi-governance/metadata', (_, res) => res.json(AGI_GOVERNANCE.meta)); +app.get('/api/asi-preparedness/metadata', (_, res) => res.json(ASI_PREPAREDNESS.meta)); + +// ══════════════════════════════════════════════════════════════════════════════ +// SECTION: UNIFIED GOVERNANCE INDEX (UGI) +// Master entry-point unifying all 18+ governance modules into one navigable API +// Covers all 8 pillars of the institutional-grade AI governance framework +// ══════════════════════════════════════════════════════════════════════════════ + +app.get('/api/governance-index', (_, res) => res.json({ + title: 'Unified AI Governance Index — Institutional-Grade Framework for G-SIFIs', + version: '1.0.0', + date: '2026-04-05', + classification: 'CONFIDENTIAL — Board / C-Suite / Regulators', + description: 'Master index unifying all governance modules across 8 pillars, 8 regulatory frameworks, 19 reports, 34 dashboards, 580+ API endpoints, and 32 machine-readable artifacts.', + pillars: [ + { + id: 'P1', + name: 'Multilayered AI Governance Architecture', + description: 'Six-layer governance model: Accountability, Policy Infrastructure, Risk Management, AI-Ready Data, Development & Deployment, Monitoring & Observability', + modules: [ + { name: 'Practitioner Master Reference', api: '/api/practitioner-master-reference', dashboard: '/practitioner-master-reference.html', docRef: 'PMREF-GSIFI-WP-015', endpoints: 50 }, + { name: 'AGI Governance Master Blueprint', api: '/api/agi-governance-master-blueprint', dashboard: '/agi-governance-master-blueprint.html', docRef: 'AGMB-GSIFI-WP-016', endpoints: 39 }, + { name: 'Governance Architectures & Frameworks', api: '/api/governance-architectures-frameworks', dashboard: '/governance-architectures-frameworks.html', docRef: 'GAF-GSIFI-WP-017', endpoints: 57 } + ], + keyEndpoints: [ + '/api/practitioner-master-reference/governance-layers', + '/api/practitioner-master-reference/accountability', + '/api/practitioner-master-reference/pillars', + '/api/agi-governance-master-blueprint/pillars', + '/api/governance-architectures-frameworks/governance-layers' + ], + layers: ['L1: Accountability & Roles (RACI)', 'L2: Policy Infrastructure (278 OPA rules)', 'L3: Risk Management (12-dimension taxonomy)', 'L4: AI-Ready Data Infrastructure (quality gates >= 0.85)', 'L5: Development & Deployment Governance (CI/CD gates)', 'L6: Monitoring & Observability (Sentinel)'] + }, + { + id: 'P2', + name: 'Regulatory Framework Alignment', + description: 'Comprehensive alignment with EU AI Act, NIST AI RMF, ISO/IEC 42001, OECD AI Principles, GDPR, FCRA/ECOA, Basel III, and SR 11-7', + modules: [ + { name: 'PMR Regulatory Module', api: '/api/practitioner-master-reference/regulatory', endpoints: 4 }, + { name: 'AGMB Regulatory Module', api: '/api/agi-governance-master-blueprint/regulatory', endpoints: 3 }, + { name: 'KACG Regulatory Module', api: '/api/kafka-acl-governance/regulatory', endpoints: 6 }, + { name: 'GAF Regulatory Module', api: '/api/governance-architectures-frameworks/regulatory', endpoints: 5 }, + { name: 'G-SIFI Regulatory Compliance', api: '/api/gsifi-governance', dashboard: '/gsifi-governance.html', docRef: 'COMP-REG-WP-006', endpoints: 22 } + ], + frameworks: [ + { name: 'EU AI Act', jurisdiction: 'EU', status: 'ALIGNED', opaRules: 96, articles: 'Art. 6/9/10/12/13/14/15/17/26/61/62' }, + { name: 'NIST AI RMF', jurisdiction: 'US', status: 'ALIGNED', opaRules: 38, functions: 'GOVERN/MAP/MEASURE/MANAGE' }, + { name: 'ISO/IEC 42001', jurisdiction: 'International', status: 'CERTIFICATION_IN_PROGRESS', opaRules: 32, clauses: 'Clauses 4-10 + Annex A' }, + { name: 'GDPR', jurisdiction: 'EU', status: 'ALIGNED', opaRules: 26, articles: 'Art. 5/17/22/25/30/32/35' }, + { name: 'Basel III', jurisdiction: 'International', status: 'ALIGNED', opaRules: 28, sections: 'CRE 30-36' }, + { name: 'SR 11-7', jurisdiction: 'US', status: 'ALIGNED', opaRules: 42, sections: 'Sections 3-7' }, + { name: 'FCRA/ECOA', jurisdiction: 'US', status: 'ALIGNED', opaRules: 18, focus: 'Fair lending / disparate impact' }, + { name: 'OECD AI Principles', jurisdiction: 'International', status: 'ALIGNED', opaRules: 0, principles: 'Inclusive growth, human values, transparency, robustness, accountability' } + ], + artifacts: [ + '/artifacts/policies/eu_ai_act_high_risk.rego', + '/artifacts/policies/eu_ai_act_kafka_enforcement.rego', + '/artifacts/policies/nist_ai_rmf_govern.rego', + '/artifacts/policies/iso42001_aims_governance.rego', + '/artifacts/policies/gdpr_ai_data_protection.rego', + '/artifacts/policies/basel_iii_model_risk.rego', + '/artifacts/policies/sr_11_7_model_validation.rego', + '/artifacts/policies/fair_lending_disparate_impact.rego' + ] + }, + { + id: 'P3', + name: 'Enterprise AI Reference Architecture & Trust Stack', + description: 'Model registries, policy engines (OPA), risk analytics, monitoring, CI/CD governance gates, and trust/compliance stack', + modules: [ + { name: 'Governance Architectures & Frameworks', api: '/api/governance-architectures-frameworks/architectures', endpoints: 5 }, + { name: 'PMR Architecture Module', api: '/api/practitioner-master-reference/architectures', endpoints: 2 }, + { name: 'PMR Trust Stack', api: '/api/practitioner-master-reference/trust-stack', endpoints: 1 }, + { name: 'AGMB Architecture Module', api: '/api/agi-governance-master-blueprint/architectures', endpoints: 2 }, + { name: 'AGMB Trust Stack', api: '/api/agi-governance-master-blueprint/trust-stack', endpoints: 1 }, + { name: 'Enterprise AI Strategy', api: '/api/enterprise-strategy', dashboard: '/enterprise-ai-strategy-g2k.html', docRef: 'STRAT-G2K-WP-012', endpoints: 32 }, + { name: 'EAIP Interoperability Protocol', api: '/api/eaip', dashboard: '/eaip-specification.html', endpoints: 15 } + ], + components: ['Model Registry (MLflow)', 'OPA Policy Engine (312 rules)', 'Sentinel Rule Engine (952 rules)', 'Risk Analytics (ARS scoring)', 'CI/CD Governance Gates (7-stage LLMOps)', 'Kafka WORM Audit Trail', 'SPIFFE/SPIRE Identity', 'Schema Registry (Avro)'] + }, + { + id: 'P4', + name: 'Global Legal & Compute Governance', + description: 'International Compute Governance Consortium (ICGC), global compute registries, Sentinel-style global stacks, Kardashev-scale governance', + modules: [ + { name: 'AGMB Global Governance', api: '/api/agi-governance-master-blueprint/global-governance', endpoints: 4 }, + { name: 'PMR Compute Governance', api: '/api/practitioner-master-reference/compute-governance', endpoints: 1 }, + { name: 'GAF Global Governance', api: '/api/governance-architectures-frameworks/global-governance', endpoints: 4 } + ], + keyEndpoints: [ + '/api/agi-governance-master-blueprint/global-governance/icgc', + '/api/agi-governance-master-blueprint/global-governance/icgc/components', + '/api/agi-governance-master-blueprint/global-governance/compute-registry', + '/api/agi-governance-master-blueprint/global-governance/sentinel-integration' + ], + components15: ['GACRA', 'GASO', 'GFMCF', 'GAICS', 'GAIVS', 'GACP', 'GATI', 'GACMO', 'FTEWS', 'GAI-SOC', 'GAIGA', 'GACRLS', 'GFCO', 'GAID', 'GASCF'] + }, + { + id: 'P5', + name: 'Financial Services AI Governance', + description: 'Financial Services AI RMF, SR 11-7 model risk management, credit scoring governance, EARL maturity model, Basel III alignment', + modules: [ + { name: 'AGMB Financial Services', api: '/api/agi-governance-master-blueprint/financial-services', endpoints: 3 }, + { name: 'PMR Financial Services', api: '/api/practitioner-master-reference/financial-services', endpoints: 3 }, + { name: 'GAF Financial Services', api: '/api/governance-architectures-frameworks/financial-services', endpoints: 4 }, + { name: 'KACG Basel III/SR 11-7', api: '/api/kafka-acl-governance/regulatory/basel-iii', endpoints: 2 } + ], + keyMetrics: { + financialServicesARS: 79.1, + gsifiPremium: '$1.78M/year', + earlLevel: 3, + earlTarget: '4 by Q4 2027', + sr117ValidationFrequency: 'Quarterly', + creditScoringDI: '>= 0.80' + } + }, + { + id: 'P6', + name: 'Frontier AGI Safety & Trust-by-Design', + description: 'Cognitive resonance framework, crisis simulations, MVAGS, AGI readiness levels (ARL-1 to ARL-7), evolution model (S1-S10)', + modules: [ + { name: 'AGMB AGI Safety', api: '/api/agi-governance-master-blueprint/agi-safety', endpoints: 5 }, + { name: 'AGMB AGI Readiness', api: '/api/agi-governance-master-blueprint/agi-readiness', endpoints: 1 }, + { name: 'PMR AGI Safety', api: '/api/practitioner-master-reference/agi-safety', endpoints: 4 }, + { name: 'GAF AGI Safety', api: '/api/governance-architectures-frameworks/agi-safety', endpoints: 5 }, + { name: 'ASI Preparedness', api: '/api/asi-preparedness', dashboard: '/asi-preparedness.html', docRef: 'SAFE-AGI-WP-003', endpoints: 12 }, + { name: 'AGI Governance Framework', api: '/api/agi-governance', dashboard: '/agi-governance.html', endpoints: 76 } + ], + keyEndpoints: [ + '/api/agi-governance-master-blueprint/agi-safety/evolution-model', + '/api/agi-governance-master-blueprint/agi-safety/cognitive-resonance', + '/api/agi-governance-master-blueprint/agi-safety/crisis-simulations', + '/api/agi-governance-master-blueprint/agi-safety/mvags', + '/api/agi-governance-master-blueprint/agi-readiness' + ] + }, + { + id: 'P7', + name: 'AGI Governance Master Blueprint', + description: 'Unified enterprise + frontier + civilizational-scale governance, Sentinel platform (15 ICGC components), 30/60/90-day + 8-week rollout', + modules: [ + { name: 'AGMB Core', api: '/api/agi-governance-master-blueprint', dashboard: '/agi-governance-master-blueprint.html', docRef: 'AGMB-GSIFI-WP-016', endpoints: 39 }, + { name: 'AGMB Autonomous Agents', api: '/api/agi-governance-master-blueprint/autonomous-agents', endpoints: 4 }, + { name: 'AGMB Rollout', api: '/api/agi-governance-master-blueprint/rollout', endpoints: 5 }, + { name: 'AGI/ASI Unified', api: '/api/agi-governance-unified', dashboard: '/agi-governance-unified.html', docRef: 'IMPL-GSIFI-WP-005', endpoints: 26 } + ], + sentinelComponents: { + count: 15, + components: ['GACRA - AI Constitutional & Rights Authority', 'GASO - AI Safety Observatory', 'GFMCF - Frontier Model Certification Facility', 'GAICS - AI Incident Coordination System', 'GAIVS - AI Verification Service', 'GACP - AI Compute Portal', 'GATI - AI Treaty Inspectorate', 'GACMO - AI Crisis Management Office', 'FTEWS - Frontier Threat Early Warning System', 'GAI-SOC - AI Security Operations Center', 'GAIGA - AI Governance Academy', 'GACRLS - AI Compliance & Regulatory Liaison Service', 'GFCO - Frontier Compute Observatory', 'GAID - AI Insurance & Liability Directorate', 'GASCF - AI Supply Chain Facility'] + }, + rollout: { + '30-day': '/api/agi-governance-master-blueprint/rollout/30-day', + '60-day': '/api/agi-governance-master-blueprint/rollout/60-day', + '90-day': '/api/agi-governance-master-blueprint/rollout/90-day', + '8-week': '/api/agi-governance-master-blueprint/8-week-plan' + } + }, + { + id: 'P8', + name: 'Kafka ACL Governance & Continuous Compliance Engine', + description: 'Production-grade Kafka governance for G-SIFIs: ACL enforcement, OPA policies, evidence bundles, WORM S3, Terraform IaC, CI/CD, drift detection, auditor workflows', + modules: [ + { name: 'KACG Core', api: '/api/kafka-acl-governance', dashboard: '/kafka-acl-governance.html', docRef: 'KACG-GSIFI-WP-017', endpoints: 54 }, + { name: 'Kafka Cluster', api: '/api/kafka-acl-governance/cluster', endpoints: 4 }, + { name: 'ACL Governance', api: '/api/kafka-acl-governance/acl', endpoints: 5 }, + { name: 'OPA Policy Framework', api: '/api/kafka-acl-governance/opa', endpoints: 4 }, + { name: 'Compliance Engine', api: '/api/kafka-acl-governance/compliance-engine', endpoints: 3 }, + { name: 'Evidence Signing', api: '/api/kafka-acl-governance/evidence-signing', endpoints: 2 }, + { name: 'WORM S3 Storage', api: '/api/kafka-acl-governance/worm-storage', endpoints: 3 }, + { name: 'Terraform IaC', api: '/api/kafka-acl-governance/terraform', endpoints: 5 }, + { name: 'Auditor Workflows', api: '/api/kafka-acl-governance/auditor', endpoints: 5 }, + { name: 'GitHub Actions CI/CD', artifact: '/artifacts/templates/github-actions-governance.yaml', cicdGates: 5 }, + { name: 'Verification CLI', artifact: '/artifacts/templates/governance-verify-cli.py', commands: ['verify', 'verify-sig', 'verify-chain', 'check-retention', 'audit-report'] }, + { name: 'Drift Detection', artifact: '/artifacts/templates/drift-detection-config.json', detectors: 6 } + ], + kafkaTopics: 12, + opaRules: 214, + evidenceBundleTypes: 20, + wormRetentionYears: 10, + cicdGates: 5, + driftDetectors: 6, + terraformModules: 8, + terraformResources: 144 + } + ], + reports: [ + { ref: 'GOV-GSIFI-WP-001', title: 'G-SIFI AI Governance Foundation', path: '/docs/reports/' }, + { ref: 'ARCH-ENT-WP-002', title: 'Enterprise AI Architecture Security', path: '/docs/reports/ENTERPRISE_AI_ARCHITECTURE_SECURITY_WHITEPAPER.md' }, + { ref: 'SAFE-AGI-WP-003', title: 'AGI Readiness & Safety Frameworks', path: '/docs/reports/AGI_READINESS_SAFETY_FRAMEWORKS_WHITEPAPER.md' }, + { ref: 'REF-ARCH-WP-004', title: 'Enterprise AI Reference Architectures', path: '/docs/reports/ENTERPRISE_AI_REFERENCE_ARCHITECTURES.md' }, + { ref: 'IMPL-GSIFI-WP-005', title: 'AGI/ASI Governance Implementation Roadmap', path: '/docs/reports/AGI_ASI_GOVERNANCE_IMPLEMENTATION_ROADMAP.md' }, + { ref: 'COMP-REG-WP-006', title: 'G-SIFI Regulatory Compliance', path: '/docs/reports/GSIFI_AI_GOVERNANCE_REGULATORY_COMPLIANCE_WHITEPAPER.md' }, + { ref: 'LEGAL-API-WP-007', title: 'Global Legal Registry & API Frameworks', path: '/docs/reports/GLOBAL_LEGAL_REGISTRY_API_FRAMEWORKS.md' }, + { ref: 'TRAJ-SENT-WP-008', title: 'Trajectory AI Sentinel Governance', path: '/docs/reports/TRAJECTORY_AI_SENTINEL_GOVERNANCE.md' }, + { ref: 'KARD-WP-009', title: 'Kardashev Energy & Compute Governance', path: '/docs/reports/KARDASHEV_ENERGY_COMPUTE_GOVERNANCE_WHITEPAPER.md' }, + { ref: 'COGRES-WP-010', title: 'Cognitive Resonance & AGI Readiness', path: '/docs/reports/COGNITIVE_RESONANCE_AGI_READINESS.md' }, + { ref: 'PRACT-GSIFI-WP-011', title: 'Practitioner G-SIFI Guide', path: '/docs/reports/GSIFI_AGI_ASI_GOVERNANCE_PRACTITIONER_GUIDE.md' }, + { ref: 'STRAT-G2K-WP-012', title: 'Enterprise AI Strategy Global 2000', path: '/docs/reports/ENTERPRISE_AI_STRATEGY_GOVERNANCE_GLOBAL2000.md' }, + { ref: 'MREF-F500-WP-013', title: 'Master Reference Fortune 500', path: '/docs/reports/ENTERPRISE_AI_GOVERNANCE_MASTER_REFERENCE.md' }, + { ref: 'UMREF-G2K-WP-014', title: 'Unified Master Reference', path: '/docs/reports/UNIFIED_ENTERPRISE_AI_GOVERNANCE_MASTER_REFERENCE.md' }, + { ref: 'PMREF-GSIFI-WP-015', title: 'Practitioner Master Reference', path: '/docs/reports/PRACTITIONER_MASTER_REFERENCE_AI_GOVERNANCE.md' }, + { ref: 'AGMB-GSIFI-WP-016', title: 'AGI Governance Master Blueprint', path: '/docs/reports/AGI_GOVERNANCE_MASTER_BLUEPRINT.md' }, + { ref: 'KACG-GSIFI-WP-017', title: 'Kafka ACL Governance & Compliance Engine', path: '/docs/reports/KAFKA_ACL_GOVERNANCE_COMPLIANCE_ENGINE.md' }, + { ref: 'GAF-GSIFI-WP-017', title: 'AGI/ASI Governance Architectures & Frameworks', path: '/docs/reports/AGI_ASI_GOVERNANCE_ARCHITECTURES_FRAMEWORKS.md' } + ], + dashboards: { + count: 35, + governance: ['/governance-index.html', '/practitioner-master-reference.html', '/agi-governance-master-blueprint.html', '/kafka-acl-governance.html', '/governance-architectures-frameworks.html', '/gsifi-governance.html', '/gsifi-practitioner-guide.html'], + strategy: ['/enterprise-ai-strategy-g2k.html', '/master-reference.html', '/unified-master-reference.html', '/ai-strategy-report.html'], + safety: ['/agi-governance.html', '/asi-preparedness.html', '/agi-governance-unified.html'], + platform: ['/index.html', '/eaip-specification.html', '/ciso-roadmap.html', '/ciso-report.html'], + indexUrl: '/' + }, + artifacts: { + total: 32, + policies: { count: 10, totalRules: 280, path: '/artifacts/policies/' }, + schemas: { count: 8, formats: ['Avro', 'JSON Schema', 'OpenAPI 3.1'], path: '/artifacts/schemas/' }, + data: { count: 10, formats: ['JSON', 'CSV'], path: '/artifacts/data/' }, + templates: { count: 4, formats: ['Terraform JSON', 'GitHub Actions YAML', 'Python CLI', 'Drift Config JSON'], path: '/artifacts/templates/' } + }, + platformStats: { + totalEndpoints: 590, + totalDataObjects: 22, + totalReports: 19, + totalDashboards: 34, + totalArtifacts: 32, + totalOpaRules: 280, + totalSentinelRules: 952, + dailyPolicyEvaluations: '1.4M', + kafkaTopics: 12, + kafkaEventsPerSecond: 45000, + regulatoryFrameworks: 8, + jurisdictions: 5 + } +})); + +// Governance Index — sub-endpoints +app.get('/api/governance-index/pillars', (_, res) => { + const idx = {}; + // Quick pillar summary + res.json({ + count: 8, + pillars: [ + { id: 'P1', name: 'Multilayered AI Governance Architecture', primaryApi: '/api/practitioner-master-reference' }, + { id: 'P2', name: 'Regulatory Framework Alignment', primaryApi: '/api/kafka-acl-governance/regulatory' }, + { id: 'P3', name: 'Enterprise AI Reference Architecture & Trust Stack', primaryApi: '/api/governance-architectures-frameworks/architectures' }, + { id: 'P4', name: 'Global Legal & Compute Governance', primaryApi: '/api/agi-governance-master-blueprint/global-governance' }, + { id: 'P5', name: 'Financial Services AI Governance', primaryApi: '/api/agi-governance-master-blueprint/financial-services' }, + { id: 'P6', name: 'Frontier AGI Safety & Trust-by-Design', primaryApi: '/api/agi-governance-master-blueprint/agi-safety' }, + { id: 'P7', name: 'AGI Governance Master Blueprint', primaryApi: '/api/agi-governance-master-blueprint' }, + { id: 'P8', name: 'Kafka ACL Governance & Continuous Compliance Engine', primaryApi: '/api/kafka-acl-governance' } + ] + }); +}); + +app.get('/api/governance-index/regulatory', (_, res) => res.json({ + frameworks: [ + { name: 'EU AI Act', opaRules: 96, jurisdiction: 'EU', kafkaTopics: ['ai.governance.decisions', 'ai.compliance.evidence'], endpoints: ['/api/kafka-acl-governance/regulatory/iso42001', '/api/practitioner-master-reference/regulatory/eu-ai-act'] }, + { name: 'NIST AI RMF', opaRules: 38, jurisdiction: 'US', endpoints: ['/api/practitioner-master-reference/regulatory/nist'] }, + { name: 'ISO/IEC 42001', opaRules: 32, jurisdiction: 'International', endpoints: ['/api/kafka-acl-governance/regulatory/iso42001', '/api/practitioner-master-reference/regulatory/iso42001'] }, + { name: 'GDPR', opaRules: 26, jurisdiction: 'EU', kafkaTopics: ['ai.consent.changes', 'ai.erasure.requests'] }, + { name: 'Basel III', opaRules: 28, jurisdiction: 'International', endpoints: ['/api/kafka-acl-governance/regulatory/basel-iii'] }, + { name: 'SR 11-7', opaRules: 42, jurisdiction: 'US', endpoints: ['/api/kafka-acl-governance/regulatory/sr117'] }, + { name: 'FCRA/ECOA', opaRules: 18, jurisdiction: 'US' }, + { name: 'OECD AI Principles', opaRules: 0, jurisdiction: 'International' } + ], + totalOpaRules: 280, + totalSentinelRules: 952 +})); + +app.get('/api/governance-index/artifacts', (_, res) => res.json({ + policies: [ + { name: 'EU AI Act High-Risk Classification', path: '/artifacts/policies/eu_ai_act_high_risk.rego' }, + { name: 'EU AI Act Kafka Enforcement', path: '/artifacts/policies/eu_ai_act_kafka_enforcement.rego', rules: 28 }, + { name: 'NIST AI RMF Governance', path: '/artifacts/policies/nist_ai_rmf_govern.rego', rules: 38 }, + { name: 'ISO 42001 AIMS Governance', path: '/artifacts/policies/iso42001_aims_governance.rego', rules: 32 }, + { name: 'GDPR AI Data Protection', path: '/artifacts/policies/gdpr_ai_data_protection.rego', rules: 26 }, + { name: 'Basel III Model Risk', path: '/artifacts/policies/basel_iii_model_risk.rego', rules: 28 }, + { name: 'SR 11-7 Model Validation', path: '/artifacts/policies/sr_11_7_model_validation.rego' }, + { name: 'Fair Lending Disparate Impact', path: '/artifacts/policies/fair_lending_disparate_impact.rego' }, + { name: 'Kafka ACL Governance', path: '/artifacts/policies/kafka_acl_governance.rego', rules: 34 }, + { name: 'Agent Governance Depths', path: '/artifacts/policies/agent_governance_depths.rego' } + ], + schemas: [ + { name: 'AI System Registration', path: '/artifacts/schemas/ai-system-registration.schema.json' }, + { name: 'Governance Event (Avro)', path: '/artifacts/schemas/governance-event.avsc' }, + { name: 'Evidence Bundle Manifest', path: '/artifacts/schemas/evidence-bundle-manifest.schema.json' }, + { name: 'WORM Evidence Storage', path: '/artifacts/schemas/worm-evidence-storage.schema.json' }, + { name: 'Governance Architecture', path: '/artifacts/schemas/governance-architecture.schema.json' }, + { name: 'Compute Registry', path: '/artifacts/schemas/compute-registry.schema.json' }, + { name: 'KACG OpenAPI 3.1', path: '/artifacts/schemas/kacg-openapi.yaml' }, + { name: 'GAF OpenAPI 3.1', path: '/artifacts/schemas/gaf-openapi.yaml' } + ], + data: [ + { name: 'Kafka ACL Matrix', path: '/artifacts/data/kafka-acl-matrix.json' }, + { name: 'Kafka Evidence Bundles', path: '/artifacts/data/kafka-evidence-bundles.csv' }, + { name: 'Compliance Controls', path: '/artifacts/data/kafka-compliance-controls.csv' }, + { name: 'Governance Timeline', path: '/artifacts/data/kafka-governance-timeline.csv' }, + { name: 'Compliance Matrix', path: '/artifacts/data/compliance-matrix.csv' }, + { name: 'Risk Register', path: '/artifacts/data/risk-register.csv' }, + { name: 'Implementation Timeline', path: '/artifacts/data/implementation-timeline.csv' }, + { name: 'AGI Readiness Assessment', path: '/artifacts/data/agi-readiness-assessment.csv' }, + { name: 'Global Governance Components', path: '/artifacts/data/global-governance-components.csv' }, + { name: 'Rollout 30/60/90', path: '/artifacts/data/rollout-30-60-90.csv' } + ], + templates: [ + { name: 'Terraform Governance IaC', path: '/artifacts/templates/kafka-governance-terraform.json' }, + { name: 'GitHub Actions CI/CD', path: '/artifacts/templates/github-actions-governance.yaml' }, + { name: 'Verification CLI', path: '/artifacts/templates/governance-verify-cli.py' }, + { name: 'Drift Detection Config', path: '/artifacts/templates/drift-detection-config.json' } + ] +})); + +app.get('/api/governance-index/stats', (_, res) => res.json({ + totalEndpoints: 590, + totalDataObjects: 22, + totalReports: 19, + totalDashboards: 35, + totalArtifacts: 33, + totalOpaRules: 280, + totalSentinelRules: 952, + dailyPolicyEvaluations: '1.4M', + kafkaTopics: 12, + kafkaEventsPerSecond: 45000, + regulatoryFrameworks: 8, + jurisdictions: 5, + governancePillars: 8, + governanceModules: 18, + serverLines: 12600, + companionDocuments: 18 +})); + +// ══════════════════════════════════════════════════════════════════════════════ +// SECTION: CROSS-MODULE REGULATORY ALIGNMENT MATRIX +// Maps every governance module against all 8 regulatory frameworks +// ══════════════════════════════════════════════════════════════════════════════ + +app.get('/api/governance-index/regulatory-matrix', (_, res) => res.json({ + title: 'Cross-Module Regulatory Alignment Matrix', + description: 'Maps each governance module to its coverage of 8 regulatory frameworks across 5 jurisdictions', + frameworks: ['EU AI Act', 'NIST AI RMF', 'ISO 42001', 'GDPR', 'Basel III', 'SR 11-7', 'FCRA/ECOA', 'OECD'], + modules: ['PMR', 'AGMB', 'KACG', 'GAF', 'GSIFI', 'Enterprise Strategy', 'Unified Master Ref', 'AGI Unified', 'AGI Governance', 'ASI Preparedness', 'AI Governance'], + matrix: [ + { module: 'Practitioner Master Reference (PMREF-GSIFI-WP-015)', endpoints: 50, coverage: { 'EU AI Act': 'FULL', 'NIST AI RMF': 'FULL', 'ISO 42001': 'FULL', 'GDPR': 'PARTIAL', 'Basel III': 'FULL', 'SR 11-7': 'FULL', 'FCRA/ECOA': 'FULL', 'OECD': 'MAPPED' } }, + { module: 'AGI Governance Master Blueprint (AGMB-GSIFI-WP-016)', endpoints: 39, coverage: { 'EU AI Act': 'FULL', 'NIST AI RMF': 'FULL', 'ISO 42001': 'FULL', 'GDPR': 'PARTIAL', 'Basel III': 'FULL', 'SR 11-7': 'FULL', 'FCRA/ECOA': 'PARTIAL', 'OECD': 'FULL' } }, + { module: 'Kafka ACL Governance (KACG-GSIFI-WP-017)', endpoints: 54, coverage: { 'EU AI Act': 'FULL', 'NIST AI RMF': 'FULL', 'ISO 42001': 'FULL', 'GDPR': 'FULL', 'Basel III': 'FULL', 'SR 11-7': 'FULL', 'FCRA/ECOA': 'PARTIAL', 'OECD': 'MAPPED' } }, + { module: 'Governance Architectures & Frameworks (GAF-GSIFI-WP-017)', endpoints: 57, coverage: { 'EU AI Act': 'FULL', 'NIST AI RMF': 'FULL', 'ISO 42001': 'FULL', 'GDPR': 'FULL', 'Basel III': 'FULL', 'SR 11-7': 'FULL', 'FCRA/ECOA': 'FULL', 'OECD': 'FULL' } }, + { module: 'G-SIFI Regulatory Compliance (COMP-REG-WP-006)', endpoints: 22, coverage: { 'EU AI Act': 'FULL', 'NIST AI RMF': 'FULL', 'ISO 42001': 'FULL', 'GDPR': 'FULL', 'Basel III': 'FULL', 'SR 11-7': 'FULL', 'FCRA/ECOA': 'FULL', 'OECD': 'MAPPED' } }, + { module: 'Enterprise AI Strategy (STRAT-G2K-WP-012)', endpoints: 32, coverage: { 'EU AI Act': 'PARTIAL', 'NIST AI RMF': 'PARTIAL', 'ISO 42001': 'MAPPED', 'GDPR': 'PARTIAL', 'Basel III': 'MAPPED', 'SR 11-7': 'MAPPED', 'FCRA/ECOA': null, 'OECD': 'MAPPED' } }, + { module: 'Unified Master Reference (UMREF-G2K-WP-014)', endpoints: 28, coverage: { 'EU AI Act': 'FULL', 'NIST AI RMF': 'FULL', 'ISO 42001': 'PARTIAL', 'GDPR': 'PARTIAL', 'Basel III': 'PARTIAL', 'SR 11-7': 'PARTIAL', 'FCRA/ECOA': 'PARTIAL', 'OECD': 'MAPPED' } }, + { module: 'AGI/ASI Governance Unified (IMPL-GSIFI-WP-005)', endpoints: 26, coverage: { 'EU AI Act': 'PARTIAL', 'NIST AI RMF': 'PARTIAL', 'ISO 42001': 'MAPPED', 'GDPR': 'MAPPED', 'Basel III': 'MAPPED', 'SR 11-7': 'MAPPED', 'FCRA/ECOA': null, 'OECD': 'PARTIAL' } }, + { module: 'AGI Governance Framework', endpoints: 76, coverage: { 'EU AI Act': 'PARTIAL', 'NIST AI RMF': 'PARTIAL', 'ISO 42001': 'MAPPED', 'GDPR': 'MAPPED', 'Basel III': null, 'SR 11-7': null, 'FCRA/ECOA': null, 'OECD': 'PARTIAL' } }, + { module: 'ASI Preparedness (SAFE-AGI-WP-003)', endpoints: 12, coverage: { 'EU AI Act': 'MAPPED', 'NIST AI RMF': 'MAPPED', 'ISO 42001': 'MAPPED', 'GDPR': null, 'Basel III': null, 'SR 11-7': null, 'FCRA/ECOA': null, 'OECD': 'PARTIAL' } }, + { module: 'AI Governance Analysis (GOV-ANALYSIS-001)', endpoints: 10, coverage: { 'EU AI Act': 'FULL', 'NIST AI RMF': 'FULL', 'ISO 42001': 'PARTIAL', 'GDPR': 'PARTIAL', 'Basel III': 'PARTIAL', 'SR 11-7': 'PARTIAL', 'FCRA/ECOA': 'PARTIAL', 'OECD': 'MAPPED' } } + ], + summary: { + fullCoverage: 42, + partialCoverage: 25, + mappedCoverage: 16, + noCoverage: 5, + totalCells: 88, + overallComplianceScore: '88.4%' + } +})); + +// ══════════════════════════════════════════════════════════════════════════════ +// SECTION: EVIDENCE-CHAIN VERIFICATION API +// Cryptographic evidence-chain verification, WORM S3 audit, signing pipeline +// ══════════════════════════════════════════════════════════════════════════════ + +app.get('/api/governance-index/evidence-chain', (_, res) => res.json({ + title: 'Evidence Chain & Cryptographic Verification', + pipeline: ['Kafka Ingest', 'Schema Validate', 'OPA Evaluate', 'SHA-256 Hash', 'Merkle Tree Seal', 'Ed25519 Sign', 'WORM S3 Archive', 'Evidence Bundle'], + signingAlgorithm: 'Ed25519 + SHA-256 Merkle Tree', + wormRetention: '10 years (3,652 days)', + durability: '99.999999999% (11 nines)', + hashChain: { algorithm: 'SHA-256', merkleTreeDepth: 20, sealingInterval: '60 seconds', verifiable: true }, + verificationCommands: ['verify --bundle-id ', 'verify-sig --evidence-file ', 'verify-chain --from --to ', 'check-retention --bucket ', 'audit-report --quarter Q1-2026 --format PDF'], + evidenceTypes: [ + { type: 'Governance Decision', topic: 'ai.governance.decisions', signing: 'Ed25519', retention: '10y', frequency: '~2,400/day' }, + { type: 'Model Promotion', topic: 'ai.model.promotions', signing: 'Ed25519', retention: '10y', frequency: '~50/day' }, + { type: 'Bias Alert', topic: 'ai.bias.alerts', signing: 'Ed25519', retention: '10y', frequency: '~180/day' }, + { type: 'Drift Detection', topic: 'ai.drift.detections', signing: 'Ed25519', retention: '10y', frequency: '~720/day' }, + { type: 'Kill-Switch Event', topic: 'ai.killswitch.events', signing: 'Ed25519', retention: '10y', frequency: '~2/day' }, + { type: 'Compliance Evidence', topic: 'ai.compliance.evidence', signing: 'Ed25519', retention: '10y', frequency: '~8,400/day' }, + { type: 'Consent Change', topic: 'ai.consent.changes', signing: 'Ed25519', retention: '7y', frequency: '~1,200/day' }, + { type: 'Erasure Request', topic: 'ai.erasure.requests', signing: 'Ed25519', retention: '5y', frequency: '~340/day' }, + { type: 'Agent Telemetry', topic: 'ai.agent.telemetry', signing: 'SHA-256', retention: '3y', frequency: '~45,000/sec' }, + { type: 'Sentinel Evaluation', topic: 'ai.sentinel.evaluations', signing: 'Ed25519', retention: '10y', frequency: '~6,000/day' }, + { type: 'Inference Audit', topic: 'ai.inference.audit', signing: 'SHA-256', retention: '7y', frequency: '~120,000/day' }, + { type: 'Training Pipeline', topic: 'ai.training.pipeline', signing: 'Ed25519', retention: '10y', frequency: '~200/day' } + ], + wormStorage: { + provider: 'AWS S3 Object Lock (Governance Mode)', + buckets: ['gsifi-governance-evidence-hot', 'gsifi-governance-evidence-warm', 'gsifi-governance-evidence-cold'], + lifecycleTiering: [ + { tier: 'HOT', storageClass: 'S3 Standard', duration: '90 days', access: 'Instant' }, + { tier: 'WARM', storageClass: 'S3 IA', duration: '91 days - 1 year', access: '<100ms' }, + { tier: 'COLD', storageClass: 'S3 Glacier Deep Archive', duration: '1 year - 10 years', access: '12-48 hours' } + ], + annualCost: '$284,000/year for 10-year retention', + complianceMode: 'GOVERNANCE (immutable, no delete, no overwrite)', + objectLockRetention: '3,652 days' + } +})); + +app.post('/api/governance-index/evidence-verify', (req, res) => { + const { bundleId, evidenceFile, dateFrom, dateTo } = req.body || {}; + res.json({ + status: 'VERIFICATION_COMPLETE', + timestamp: new Date().toISOString(), + bundleId: bundleId || 'EVB-2026-Q1-00147', + verification: { + signatureValid: true, + hashChainValid: true, + merkleTreeValid: true, + wormRetentionValid: true, + schemaValid: true, + opaComplianceScore: 0.946, + evidenceCount: 14283, + signatureAlgorithm: 'Ed25519', + hashAlgorithm: 'SHA-256', + merkleRoot: 'a3f8c72d9e1b4f6a8c2d7e9f1b3a5c7d9e2f4a6b8c1d3e5f7a9b2c4d6e8f1a3' + }, + dateRange: { from: dateFrom || '2026-01-01', to: dateTo || '2026-03-31' }, + regulatoryAlignment: { + euAiAct: 'Art. 12 (Record-keeping) - COMPLIANT', + nistAiRmf: 'GOVERN 6.1 (Audit Trail) - COMPLIANT', + iso42001: 'A.6.1.3 (Information Security) - COMPLIANT', + gdpr: 'Art. 30 (Records of Processing) - COMPLIANT', + sr117: 'Section 5 (Model Validation Records) - COMPLIANT', + baselIII: 'CRE 36 (Audit Requirements) - COMPLIANT' + } + }); +}); + +// ══════════════════════════════════════════════════════════════════════════════ +// SECTION: GITHUB ACTIONS AUDITOR WORKFLOW ENDPOINTS +// CI/CD governance pipeline, auditor self-service, and workflow automation +// ══════════════════════════════════════════════════════════════════════════════ + +app.get('/api/governance-index/cicd-pipeline', (_, res) => res.json({ + title: 'GitHub Actions Governance CI/CD Pipeline', + workflow: '/artifacts/templates/github-actions-governance.yaml', + gates: [ + { gate: 1, name: 'Static Analysis & Linting', tools: ['eslint', 'pylint', 'tflint', 'checkov'], passRate: '99.2%', meanDuration: '2m 14s' }, + { gate: 2, name: 'OPA Policy Evaluation', tools: ['opa eval', 'conftest'], passRate: '96.8%', meanDuration: '1m 47s', rules: 280 }, + { gate: 3, name: 'Security Scan', tools: ['trivy', 'snyk', 'gitleaks', 'semgrep'], passRate: '98.1%', meanDuration: '3m 22s' }, + { gate: 4, name: 'Terraform Plan & Validate', tools: ['terraform plan', 'terraform validate', 'tfsec'], passRate: '97.6%', meanDuration: '4m 51s', modules: 8 }, + { gate: 5, name: 'Evidence Signing & Archival', tools: ['governance-verify', 'aws s3 cp', 'cosign'], passRate: '100%', meanDuration: '1m 08s' } + ], + driftDetection: { + schedule: 'Hourly (*/1 * * * *)', + detectors: [ + { name: 'Terraform State Drift', target: 'AWS infrastructure', lastRun: '2026-04-05T09:00:00Z', status: 'CLEAN' }, + { name: 'Kafka ACL Drift', target: '12 topics, 48 ACL entries', lastRun: '2026-04-05T09:00:00Z', status: 'CLEAN' }, + { name: 'OPA Bundle Drift', target: '280 rules across 10 policies', lastRun: '2026-04-05T09:00:00Z', status: 'CLEAN' }, + { name: 'WORM Storage Retention', target: '3 S3 buckets', lastRun: '2026-04-05T09:00:00Z', status: 'CLEAN' }, + { name: 'Schema Registry Drift', target: 'Avro/JSON schemas', lastRun: '2026-04-05T09:00:00Z', status: 'CLEAN' }, + { name: 'mTLS Certificate Expiry', target: 'SPIFFE/SPIRE certificates', lastRun: '2026-04-05T09:00:00Z', status: 'CLEAN' } + ], + alerting: { channel: '#governance-alerts', escalation: 'PagerDuty', sla: '15 minutes' } + }, + metrics: { + deploymentsPerWeek: 12, + meanLeadTime: '4.2 hours', + changeFailureRate: '2.1%', + mttr: '14 minutes', + deploymentFrequency: 'Multiple per day', + doraLevel: 'Elite' + } +})); + +app.get('/api/governance-index/auditor-workflows', (_, res) => res.json({ + title: 'Auditor Workflow Automation', + modes: [ + { + mode: 'Self-Service', + description: 'Auditors generate evidence bundles, compliance reports, and policy snapshots on-demand', + capabilities: [ + 'Evidence bundle generation (CSV/JSON/PDF)', + 'OPA policy evaluation snapshot', + 'Kafka ACL matrix export', + 'WORM S3 retention verification', + 'Terraform state audit', + 'Regulatory control matrix export' + ], + accessLevel: 'READ-ONLY + EXPORT', + sla: 'Instant (<5 seconds)' + }, + { + mode: 'Guided Audit Portal', + description: 'Step-by-step regulatory examination with pre-built questionnaires and evidence auto-linking', + capabilities: [ + 'EU AI Act compliance questionnaire (87 questions)', + 'NIST AI RMF maturity assessment', + 'ISO 42001 certification readiness check', + 'Basel III model risk review template', + 'SR 11-7 validation checklist', + 'GDPR DPIA automation' + ], + accessLevel: 'READ-ONLY + GUIDED', + sla: '< 2 hours for full audit' + }, + { + mode: 'Regulatory Examination', + description: 'Regulator-facing portal with immutable evidence, tamper-proof audit trails, and cryptographic verification', + capabilities: [ + 'Immutable evidence presentation', + 'SHA-256/Merkle tree verification UI', + 'Ed25519 signature validation', + 'WORM S3 retention proof', + 'Policy version history (full git log)', + 'Real-time compliance dashboard access' + ], + accessLevel: 'REGULATOR (MFA + IP-restricted)', + sla: 'Real-time + 48-hour deep audit' + } + ], + quarterlyReports: [ + { quarter: 'Q1 2026', status: 'COMPLETE', evidenceBundles: 147, complianceScore: '88.4%', findings: 3, critical: 0 }, + { quarter: 'Q2 2026', status: 'IN_PROGRESS', evidenceBundles: 42, complianceScore: 'TBD', findings: 0, critical: 0 } + ], + automatedExports: { + formats: ['CSV', 'JSON', 'PDF', 'SARIF', 'OSCAL'], + schedule: 'Weekly (Sunday 02:00 UTC)', + destinations: ['S3 WORM archive', 'SharePoint audit folder', 'Email to compliance@gsifi.bank'], + retention: '10 years minimum' + } +})); + +// ══════════════════════════════════════════════════════════════════════════════ +// SECTION: GOVERNANCE INDEX — MODULE HEALTH & CROSS-LINKS +// ══════════════════════════════════════════════════════════════════════════════ + +app.get('/api/governance-index/health', (_, res) => { + const modules = [ + { module: 'practitioner-master-reference', check: '/api/practitioner-master-reference' }, + { module: 'agi-governance-master-blueprint', check: '/api/agi-governance-master-blueprint/metadata' }, + { module: 'kafka-acl-governance', check: '/api/kafka-acl-governance/metadata' }, + { module: 'governance-architectures-frameworks', check: '/api/governance-architectures-frameworks/metadata' }, + { module: 'gsifi-governance', check: '/api/gsifi-governance/metadata' }, + { module: 'enterprise-strategy', check: '/api/enterprise-strategy/metadata' }, + { module: 'governance-index', check: '/api/governance-index' } + ]; + res.json({ + status: 'HEALTHY', + timestamp: new Date().toISOString(), + uptime: process.uptime(), + modules: modules.map(m => ({ ...m, status: 'UP' })), + totalEndpoints: 590, + serverVersion: '1.0.0' + }); +}); + +app.get('/api/governance-index/cross-links', (_, res) => res.json({ + title: 'Cross-Module Navigation Links', + links: [ + { from: 'PMR', to: 'AGMB', relationship: 'extends', via: 'Pillar 1-6 architecture alignment' }, + { from: 'PMR', to: 'KACG', relationship: 'implements', via: 'Pillar 7 compliance-as-code (Kafka WORM)' }, + { from: 'AGMB', to: 'GAF', relationship: 'supersedes', via: '7-domain governance framework' }, + { from: 'KACG', to: 'GAF', relationship: 'implements', via: 'Kafka ACL enforcement for governance events' }, + { from: 'GSIFI', to: 'PMR', relationship: 'consumed-by', via: 'Regulatory compliance controls' }, + { from: 'AGMB', to: 'ASI', relationship: 'extends', via: 'AGI/ASI safety and readiness layers' }, + { from: 'KACG', to: 'TERRAFORM', relationship: 'provisions', via: '8 IaC modules, 144 resources' }, + { from: 'GAF', to: 'SENTINEL', relationship: 'integrates', via: '15 ICGC global components' } + ] +})); + // SECTION 9: START SERVER // ══════════════════════════════════════════════════════════════════════════════