diff --git a/rag-agentic-dashboard/data/civ-ai-gov-6l-crs.json b/rag-agentic-dashboard/data/civ-ai-gov-6l-crs.json new file mode 100644 index 00000000..b47f849e --- /dev/null +++ b/rag-agentic-dashboard/data/civ-ai-gov-6l-crs.json @@ -0,0 +1,1941 @@ +{ + "meta": { + "docRef": "CIV-AI-GOV-6L-CRS-WP-032", + "version": "1.0.0", + "date": "2026-04-22", + "title": "Six-Layer Civilizational AI Governance Blueprint — CRS-UUID-001 Reference Implementation", + "subtitle": "Credit Risk Scoring AI · Global Bank plc · Regulator-Ready Dossier, Audit Pack, Simulation Suite, Treaty Artefacts", + "classification": "CONFIDENTIAL — Board / Prudential & Conduct Supervisors / Treaty Authority", + "owner": "Chief AI Officer · Global Bank plc (with Model Risk, CISO, General Counsel, DPO, Head of Credit)", + "audience": [ + "Board & Audit / Risk Committees", + "PRA / FCA / OCC / Fed / ECB supervisors", + "Internal Audit & Independent Model Validation (IMV)", + "External auditors (Big-4 assurance)", + "ISO/IEC 42001 certification bodies", + "EU AI Act notified bodies", + "DPAs (ICO, CNIL, BfDI)", + "CFPB & state attorneys general (FCRA/ECOA scope)", + "Global AI Governance & Compute Oversight Treaty Authority (G-AGCOTA, prospective)" + ], + "subjectSystem": { + "modelId": "CRS-UUID-001", + "modelName": "Global Bank plc — Retail Credit Risk Scoring Engine v4.2", + "owner": "Head of Retail Credit — Global Bank plc", + "purpose": "Probability-of-default scoring for unsecured consumer credit (credit cards, personal loans, overdraft) in 14 jurisdictions.", + "trainingData": "14.2M historical accounts (2018-2025), 312 features (behavioural, bureau, open-banking), GDPR Art. 6(1)(b)+(f) + Art. 9(2)(b) lawful basis.", + "architecture": "Gradient-boosted trees (XGBoost 2.1) + monotonic calibration layer + shallow MLP explainer head; no LLM component; no generative capability.", + "autonomyLevel": "L2 (human-in-the-loop — decisions ≥£25k auto-referred to underwriter; <£25k auto-decisioned with free appeal channel).", + "riskTier": { + "euAiAct": "High-risk (Annex III §5(b) — creditworthiness assessment of natural persons)", + "sr11_7": "Tier 1 material (financial-reporting impact >£50m RWA)", + "basel": "IRB-adjacent; not regulatory IRB model but feeds provisioning & capital planning", + "iso42001": "In-scope AI system; critical; full AIMS lifecycle applies", + "gdpr": "Art. 22 ADM engaged; DPIA required; DPO signed-off 2026-02-14", + "fcra_ecoa": "Adverse action notices required; disparate-impact testing quarterly" + }, + "populationImpact": "≈3.1M decisions/year affecting £18.4bn gross exposure", + "materiality": "Top-5 material AI system in the group by RWA influence" + }, + "scopeSummary": { + "layers": 6, + "artefacts": 24, + "simulations": 13, + "opaRegoPolicies": 12, + "ciCdGates": 14, + "evidenceBundles": 9, + "supervisoryReports": 8, + "gcScenarios": 7, + "treatyArticles": 12 + }, + "regulatoryCoverage": [ + "EU AI Act (Regulation (EU) 2024/1689) — Annex III §5(b), Annex IV full technical documentation, Art. 9 risk mgmt, Art. 10 data governance, Art. 12 logging, Art. 13 transparency, Art. 14 human oversight, Art. 15 accuracy/robustness/cybersec, Art. 17 QMS, Art. 43 conformity assessment, Art. 60 post-market monitoring, Art. 73 serious incident reporting", + "SR 11-7 (Fed/OCC) — Section III.A (development), III.B (implementation), III.C (use), IV (validation), V (governance)", + "Basel III (CRR/CRD) — Pillar 1 credit risk, Pillar 2 ICAAP, Pillar 3 disclosure; SA-CR and IRB adjacency", + "ISO/IEC 42001:2023 — Clauses 4-10 (context, leadership, planning, support, operation, performance, improvement); Annex A controls A.2-A.10", + "ISO/IEC 23894:2023 — AI risk management process", + "ISO/IEC 27001:2022 — ISMS (information-security twin)", + "GDPR — Art. 6, 9, 22, 25, 32, 35 (DPIA), 83 (fines)", + "FCRA 15 U.S.C. §1681 — adverse action notices, reason codes, consumer dispute", + "ECOA 15 U.S.C. §1691 + Reg B — prohibited bases, disparate-treatment & disparate-impact", + "CFPB Circulars 2022-03 (adverse action) & 2023-03 (AI chatbots) — model explainability", + "FCA Consumer Duty (PRIN 2A) — foreseeable harm to retail customers", + "PRA SS1/23 — model risk management principles for banks", + "PRA SS2/21 — outsourcing & third-party risk (model vendors)", + "OCC Bulletin 2011-12 & 2021-39 — model risk & third-party", + "Global AI Governance & Compute Oversight Treaty Charter (GAGCOT) — GC1-GC7 crisis protocols", + "UK Algorithmic Transparency Recording Standard (ATRS) — public-sector overlay where the bank serves HMG" + ] + }, + "executiveSummary": "WP-032 operationalises a six-layer civilizational AI governance blueprint, grounded in a single, fully instantiated reference system: CRS-UUID-001, a Tier-1 retail credit-risk scoring engine at Global Bank plc. Every artefact is regulator-ready and cross-mapped to EU AI Act (including Annex IV), SR 11-7, Basel III/ICAAP, ISO/IEC 42001, GDPR, and FCRA/ECOA — with treaty-level overlays under the Global AI Governance & Compute Oversight Treaty Charter (GC1-GC7). The six layers span institutional MRM, sectoral supervision, frontier-compute attestation, geopolitical treaty alignment, an autonomous governance mesh (OPA/Rego + CI/CD + runtime), and adversarial co-evolution. Deliverables include a full Annex IV dossier, 12-tab audit pack, independent validation report, capital-impact assessment, AIMS evidence bundle, nine cryptographic evidence manifests (Merkle-anchored, post-quantum-ready), 12 OPA/Rego policies with 14 CI/CD gates, a supervisory replay kit, eight harmonized global supervisory reports, 13 multi-layer simulations (including GC1-GC7), and a Treaty Authority Implementation Charter (G-AGCOTA). The blueprint converts abstract frontier-AI governance into a board-defensible, prudential-supervisor-defensible, treaty-defensible operating reality.", + "L1_institutional": { + "id": "L1", + "title": "Institutional Governance — Bank-Internal Controls for CRS-UUID-001", + "summary": "Three-lines-of-defence MRM with SR 11-7 / SS1/23 alignment, ISO/IEC 42001 AIMS lifecycle, EU AI Act Annex IV technical documentation, and conduct controls under FCRA/ECOA/GDPR/Consumer Duty.", + "roles": { + "lineOfDefence": { + "1LoD": [ + "Head of Retail Credit (system owner)", + "Head of Credit Analytics (model developer)", + "Head of Credit Operations (model user)" + ], + "2LoD": [ + "Chief Model Risk Officer", + "Chief AI Officer", + "Chief Data Officer", + "CISO", + "DPO", + "Head of Compliance & Conduct" + ], + "3LoD": [ + "Chief Internal Auditor", + "Independent Model Validation (IMV)" + ] + }, + "committees": [ + { + "name": "Model Risk Committee (MRC)", + "cadence": "Monthly", + "chair": "CRO", + "quorum": 5, + "crsItem": "Standing agenda item + quarterly deep-dive" + }, + { + "name": "AI & Data Ethics Committee", + "cadence": "Monthly", + "chair": "CAIO", + "quorum": 4, + "crsItem": "Fairness KRIs + adverse-action review" + }, + { + "name": "Board Risk Committee", + "cadence": "Quarterly", + "chair": "NED", + "quorum": 4, + "crsItem": "Tier-1 model dashboard + issues log" + }, + { + "name": "Conduct & Customer Committee", + "cadence": "Monthly", + "chair": "Chief Customer Officer", + "quorum": 5, + "crsItem": "Appeal rates, adverse-action disputes, Consumer Duty outcomes" + } + ], + "raci": [ + { + "activity": "Model approval (initial + material change)", + "R": "Model Developer", + "A": "CMRO", + "C": "CAIO, CCO, DPO", + "I": "Board Risk" + }, + { + "activity": "Annex IV technical documentation upkeep", + "R": "Model Developer", + "A": "CMRO", + "C": "Legal, DPO", + "I": "Notified Body" + }, + { + "activity": "Independent validation (SR 11-7 IV)", + "R": "IMV", + "A": "Head IMV", + "C": "Developer", + "I": "MRC, External auditor" + }, + { + "activity": "Fairness / disparate-impact testing", + "R": "Model Fairness Lead", + "A": "CAIO", + "C": "Legal, CCO, DPO", + "I": "CFPB/FCA liaison" + }, + { + "activity": "DPIA + Art. 22 safeguards", + "R": "DPO", + "A": "DPO", + "C": "Legal, CISO", + "I": "ICO" + }, + { + "activity": "Capital-impact assessment (ICAAP)", + "R": "Head Capital Mgmt", + "A": "CFO", + "C": "CMRO, Treasurer", + "I": "PRA" + }, + { + "activity": "Post-market monitoring (Art. 60 EU AI Act)", + "R": "MLOps Lead", + "A": "CAIO", + "C": "CMRO", + "I": "Notified Body" + }, + { + "activity": "Serious incident reporting (Art. 73)", + "R": "CISO-Delegate", + "A": "CAIO", + "C": "Legal, DPO", + "I": "Market Surveillance Authority" + } + ] + }, + "aimsLifecycle": { + "standard": "ISO/IEC 42001:2023 Annex A", + "stages": [ + { + "stage": "A.2 Plan", + "crsArtefacts": [ + "AI policy", + "AI objectives", + "CRS system-of-record charter" + ] + }, + { + "stage": "A.3 Do-Design", + "crsArtefacts": [ + "Data sheet for CRS training corpus", + "Model card v4.2", + "Intended-use statement", + "Risk taxonomy mapping" + ] + }, + { + "stage": "A.4 Do-Develop", + "crsArtefacts": [ + "Feature store lineage (312 features)", + "Reproducible training pipeline", + "Hyperparameter audit log", + "Bias pre-mitigation report" + ] + }, + { + "stage": "A.5 Verify", + "crsArtefacts": [ + "Back-test report (PSI, AUC, KS)", + "Fairness report (4/5 rule, demographic parity, equalised odds)", + "Robustness report (covariate shift, adversarial perturbation)" + ] + }, + { + "stage": "A.6 Deploy", + "crsArtefacts": [ + "Change-advisory board (CAB) minutes", + "Go-live checklist", + "Rollback plan", + "Kill-switch test evidence" + ] + }, + { + "stage": "A.7 Operate", + "crsArtefacts": [ + "Daily KRI dashboard", + "Monthly PSI drift report", + "Quarterly IMV challenge report", + "Adverse-action MI" + ] + }, + { + "stage": "A.8 Monitor", + "crsArtefacts": [ + "Post-market monitoring plan (Art. 60)", + "Incident register", + "Customer complaints root-cause" + ] + }, + { + "stage": "A.9 Improve", + "crsArtefacts": [ + "Corrective-action register", + "Retraining decision log", + "Sunset/replacement plan" + ] + }, + { + "stage": "A.10 Retire", + "crsArtefacts": [ + "Decommissioning runbook", + "Data-retention schedule", + "Post-mortem report" + ] + } + ] + }, + "annexIvDossier": { + "instrument": "EU AI Act Annex IV — Technical Documentation", + "doc": "CRS-UUID-001-ANNEXIV-v4.2", + "structure": [ + { + "section": "1. General description", + "crsContent": "Model name/version, intended purpose (retail PoD scoring EEA + GB), provider & deployer identification, SW/HW stack, release history", + "evidenceBundle": "EB-001" + }, + { + "section": "2. Detailed description", + "crsContent": "Architecture (XGBoost 2.1 + monotonic calibrator + MLP explainer), 312-feature list with provenance, training methodology, optimisation", + "evidenceBundle": "EB-002" + }, + { + "section": "3. Monitoring, functioning, control", + "crsContent": "Human-oversight protocol, £25k auto-referral threshold, override logging, real-time drift monitoring, kill-switch procedure", + "evidenceBundle": "EB-003" + }, + { + "section": "4. Risk management system", + "crsContent": "ISO 23894 risk register (47 risks), treatment plans, residual-risk acceptance by CRO, link to SR 11-7 model-risk register", + "evidenceBundle": "EB-004" + }, + { + "section": "5. Data & data governance", + "crsContent": "Training/validation/test datasets, 14-jurisdiction provenance, bias-detection report, GDPR Art. 10 disclosures, data-minimisation proof", + "evidenceBundle": "EB-005" + }, + { + "section": "6. Changes through lifecycle", + "crsContent": "Change log since v3.0 (2023), CAB records, impact assessments, re-validation outcomes", + "evidenceBundle": "EB-006" + }, + { + "section": "7. Standards applied", + "crsContent": "ISO/IEC 42001, ISO/IEC 23053, ISO/IEC 23894, ISO/IEC 25059, SR 11-7 internal", + "evidenceBundle": "EB-007" + }, + { + "section": "8. EU declaration of conformity", + "crsContent": "Signed by authorised representative; conformity-assessment route Art. 43(2) internal control + notified body for post-market monitoring", + "evidenceBundle": "EB-008" + }, + { + "section": "9. Post-market monitoring plan", + "crsContent": "Drift KPIs, fairness KPIs, complaint-trend triggers, serious-incident definition & reporting SLAs, annual re-assessment", + "evidenceBundle": "EB-009" + } + ], + "sizing": "≈640 pages; auto-generated from live evidence store; Merkle-anchored per section." + }, + "sr117Mapping": [ + { + "section": "III.A Development", + "crsControl": "Conceptual soundness review; feature-engineering documentation; developer peer review", + "owner": "Head Credit Analytics" + }, + { + "section": "III.B Implementation", + "crsControl": "Code freeze + SAST/DAST + reproducibility attestation; data-pipeline integrity; UAT sign-off", + "owner": "Head MLOps" + }, + { + "section": "III.C Use", + "crsControl": "Business-user training; override policy; outcome-analysis loop", + "owner": "Head Credit Ops" + }, + { + "section": "IV Validation", + "crsControl": "IMV annual full revalidation + quarterly ongoing monitoring; effective challenge log; open-issue MRIA tracking", + "owner": "Head IMV" + }, + { + "section": "V Governance", + "crsControl": "Model inventory entry (active), tier assignment review, MRC minutes, Board Risk reporting, independent audit", + "owner": "CMRO" + } + ], + "conductControls": { + "FCRA": { + "adverseActionNotice": "Automated generation within 30 days; top-4 SHAP reason codes translated to plain-English", + "consumerDisputeFlow": "Model-level and case-level dispute routes; SLA 30 days; quarterly dispute-outcome MI", + "accuracyObligation": "§1681e(b) — monthly bureau-data reconciliation; exception report to Board" + }, + "ECOA_RegB": { + "prohibitedBases": [ + "race", + "colour", + "religion", + "national origin", + "sex", + "marital status", + "age (if capable of contracting)", + "receipt of public assistance", + "good-faith exercise of CCPA rights" + ], + "disparateImpactTesting": "Quarterly 4/5 rule + logistic regression residual analysis by protected class proxy", + "remediationProtocol": "If 4/5 rule fails → 90-day remediation plan → MRC escalation → customer remediation if confirmed" + }, + "GDPR_Art22": { + "safeguards": [ + "Right to human intervention (appeal within 30 days)", + "Right to obtain explanation", + "Right to contest decision" + ], + "dpiaRef": "DPIA-CRS-2026-02", + "dpoSignOff": "2026-02-14", + "lawfulBasis": "Art. 6(1)(b) contract performance + Art. 6(1)(f) legitimate interest (balancing test documented)" + }, + "consumerDuty_PRIN2A": { + "foreseeableHarm": "Monitored via: (i) appeal overturn rate, (ii) complaint-root-cause analysis, (iii) vulnerable-customer outcomes MI, (iv) affordability distress indicators", + "outcomesMonitoring": [ + "Price & value", + "Products & services", + "Consumer understanding", + "Consumer support" + ] + } + }, + "kris": [ + { + "kri": "Model AUC (out-of-time)", + "threshold": "≥0.78", + "current": 0.812, + "status": "GREEN" + }, + { + "kri": "Population Stability Index (PSI)", + "threshold": "≤0.10", + "current": 0.067, + "status": "GREEN" + }, + { + "kri": "4/5 rule — any protected class", + "threshold": "≥0.80", + "current": 0.84, + "status": "GREEN" + }, + { + "kri": "Adverse-action dispute overturn rate", + "threshold": "≤8%", + "current": 0.041, + "status": "GREEN" + }, + { + "kri": "Human override rate (<£25k tier)", + "threshold": "0.5-3%", + "current": 0.019, + "status": "GREEN" + }, + { + "kri": "Vulnerable-customer outcome gap", + "threshold": "≤2pp", + "current": 0.012, + "status": "GREEN" + }, + { + "kri": "Incident count (Art. 73 eligible)", + "threshold": "0", + "current": 0, + "status": "GREEN" + }, + { + "kri": "Open IMV findings (high)", + "threshold": "0", + "current": 0, + "status": "GREEN" + } + ] + }, + "L2_systemic": { + "id": "L2", + "title": "Systemic Governance — Sectoral & National Supervisory Coordination", + "summary": "PRA / FCA / OCC / Fed / ECB coordination for Tier-1 AI models, ICAAP Pillar-2 capital impact, supervisory colleges, cross-border recognition, and sector-wide stress testing.", + "supervisors": [ + { + "authority": "PRA (Bank of England)", + "jurisdiction": "UK", + "primaryInstrument": "SS1/23 model risk management", + "crsContactCadence": "Quarterly" + }, + { + "authority": "FCA", + "jurisdiction": "UK", + "primaryInstrument": "Consumer Duty + PS23/4 AI", + "crsContactCadence": "Semi-annual" + }, + { + "authority": "OCC", + "jurisdiction": "US", + "primaryInstrument": "Bulletin 2011-12 + 2021-39", + "crsContactCadence": "Quarterly" + }, + { + "authority": "Federal Reserve", + "jurisdiction": "US", + "primaryInstrument": "SR 11-7", + "crsContactCadence": "Quarterly" + }, + { + "authority": "ECB SSM", + "jurisdiction": "Euro area", + "primaryInstrument": "TRIM + SREP", + "crsContactCadence": "Annual + JST dialogue" + }, + { + "authority": "CFPB", + "jurisdiction": "US", + "primaryInstrument": "Circulars 2022-03 & 2023-03", + "crsContactCadence": "Event-driven" + }, + { + "authority": "ICO", + "jurisdiction": "UK", + "primaryInstrument": "GDPR + UK DPA", + "crsContactCadence": "Annual + incident" + } + ], + "icaapCapitalImpact": { + "modelRiskPillar2Addon": { + "baseline2025": "£42m RWA add-on", + "2026PostWP032": "£26m RWA add-on (−38% as assurance depth rose)", + "driverOfReduction": "IMV effective-challenge evidence + ISO 42001 certification + Annex IV dossier completeness" + }, + "stressScenarios": [ + { + "scenario": "Severe adverse 2026", + "crsModelSensitivity": "PoD up-shift 24% in recession lag-1", + "capitalImpact": "£180m CET1 absorption", + "commentary": "Within Pillar-2 buffer" + }, + { + "scenario": "Climate transition (disorderly)", + "crsModelSensitivity": "Geographic sector drift; PSI up to 0.18", + "capitalImpact": "£95m", + "commentary": "Early-warning trigger at PSI 0.12" + }, + { + "scenario": "Geopolitical shock (sanctions)", + "crsModelSensitivity": "Open-banking data-feed loss in 3 markets", + "capitalImpact": "£40m", + "commentary": "Fallback scorecard activates" + }, + { + "scenario": "AI-specific (adversarial data-poisoning)", + "crsModelSensitivity": "AUC −6pp if undetected for 30 days", + "capitalImpact": "£120m", + "commentary": "Triggers GC4 treaty protocol" + } + ], + "rwaInfluenceTable": { + "directRwa": "£3.2bn (unsecured retail portfolio PoD-driven)", + "provisioningIfrs9": "£420m LLP influenced by CRS output", + "overlayHeld": "£85m management overlay for model uncertainty" + } + }, + "supervisoryCollege": { + "name": "CRS-UUID-001 Supervisory College (chartered under Basel supervisory-college protocol)", + "frequency": "Semi-annual (April / October) + ad-hoc", + "participants": [ + "PRA (lead)", + "FCA", + "OCC", + "Fed", + "ECB SSM", + "CFPB (observer)", + "ICO (observer)" + ], + "standingAgenda": [ + "Model-risk materiality re-assessment", + "Cross-border fairness outcomes", + "Systemic-concentration review (market-share by jurisdiction)", + "Incident debriefs (if any)", + "Treaty uplift (GAGCOT alignment)" + ] + }, + "harmonizedSupervisoryReports": [ + { + "reportId": "HSR-01", + "title": "CRS Quarterly Supervisory Summary", + "audience": "PRA/OCC/Fed", + "frequency": "Quarterly", + "format": "PDF + machine-readable JSON" + }, + { + "reportId": "HSR-02", + "title": "Annex IV Conformity Attestation", + "audience": "Notified Body", + "frequency": "Annual", + "format": "PDF + XML" + }, + { + "reportId": "HSR-03", + "title": "ISO/IEC 42001 Surveillance Package", + "audience": "Cert Body", + "frequency": "Annual", + "format": "PDF" + }, + { + "reportId": "HSR-04", + "title": "ICAAP Model-Risk Pillar-2 Report (CRS section)", + "audience": "PRA", + "frequency": "Annual", + "format": "PDF + XBRL" + }, + { + "reportId": "HSR-05", + "title": "Fairness & Consumer Duty Outcomes Report", + "audience": "FCA / CFPB", + "frequency": "Semi-annual", + "format": "PDF" + }, + { + "reportId": "HSR-06", + "title": "GDPR Art. 30 ROPA + DPIA Appendix", + "audience": "ICO", + "frequency": "Annual", + "format": "PDF" + }, + { + "reportId": "HSR-07", + "title": "Art. 73 Serious Incident Report template (0 YTD)", + "audience": "Market Surveillance Authority", + "frequency": "Event-driven", + "format": "JSON + PDF" + }, + { + "reportId": "HSR-08", + "title": "Treaty Quarterly Attestation (GAGCOT T-01)", + "audience": "G-AGCOTA", + "frequency": "Quarterly", + "format": "Signed JSON-LD + PDF" + } + ], + "supervisoryReplayKit": { + "purpose": "Reproduce any individual decision or aggregate statistic under supervisory examination", + "components": [ + "Deterministic training pipeline image (Docker digest sha256:…)", + "Immutable feature-store snapshot (per decision timestamp)", + "Model weights registry (signed SHA-256 + PQ-signature)", + "Inference replay engine (given input → byte-identical output)", + "Adverse-action letter reproducer", + "Fairness-metric re-computation notebook (Jupyter)", + "OPA decision-log replay (policy-as-code outcomes)" + ], + "slaToReproduce": "≤4 hours for individual decision; ≤24 hours for quarterly aggregate; ≤72 hours for full back-test" + } + }, + "L3_frontierCompute": { + "id": "L3", + "title": "Frontier Compute Governance — Training Compute Register & Custody", + "summary": "Even though CRS-UUID-001 is not a frontier model by scale, the blueprint instantiates the frontier-compute governance controls that will apply to the bank's larger AI systems (FraudNet-L, MarketCopilot) and demonstrates cross-model integration under GAGCOT compute-oversight rules.", + "computeRegister": { + "entrySchema": { + "modelId": "string", + "trainingRunId": "string", + "flopsTotal": "integer", + "startedAt": "RFC3339", + "endedAt": "RFC3339", + "gpuHours": "integer", + "datacentreLocation": "ISO-3166-2", + "providerAccount": "string (signed JWT)", + "weightsHash": "SHA3-256 hex", + "evidenceBundle": "string (EB-xxx)" + }, + "crsEntry": { + "modelId": "CRS-UUID-001", + "trainingRunId": "tr-crs-20260315-a1b2", + "flopsTotal": 4.2e+18, + "startedAt": "2026-03-15T09:12:00Z", + "endedAt": "2026-03-15T15:48:00Z", + "gpuHours": 96, + "datacentreLocation": "GB-LND", + "providerAccount": "globalbank-aiplatform-prod", + "weightsHash": "sha3-256:9f3a…c217", + "evidenceBundle": "EB-002", + "frontierTrigger": false, + "frontierThreshold_flops": 1e+25 + }, + "frontierThresholdPolicy": "Any training run ≥1e25 FLOPs requires 90-day pre-notification to G-AGCOTA + PRA; the CRS run is 2.4e6× below threshold but still logged for systemic transparency." + }, + "killSwitch": { + "patterns": [ + { + "pattern": "Runtime inference disable", + "target": "≤60s", + "crsImplementation": "Feature-flag kill-switch in API gateway; tested monthly; last test 2026-04-05 PASS (47s)" + }, + { + "pattern": "Model rollback to v4.1", + "target": "≤15m", + "crsImplementation": "Blue-green deployment; automated traffic shift; last drill 2026-03-22 PASS (11m)" + }, + { + "pattern": "Weight custody freeze", + "target": "≤30m", + "crsImplementation": "HSM-based weight-release revocation; dual-control; last drill 2026-02-18 PASS (22m)" + } + ], + "invocationAuthority": { + "routineShutdown": [ + "Head MLOps", + "CMRO" + ], + "emergencyShutdown": [ + "CAIO", + "CISO", + "CRO (any 1 of 3)" + ], + "regulatorMandated": [ + "PRA / FCA / OCC / Fed / ECB (direct to CEO)" + ], + "treatyMandated": [ + "G-AGCOTA Executive Secretary (under GC4-GC7 scenarios)" + ] + }, + "postKillProtocol": [ + "Evidence-bundle freeze (cryptographic)", + "Regulator notification within 2h (Art. 73)", + "Customer-impact assessment within 24h", + "Root-cause analysis within 10 working days", + "Return-to-service gate: MRC + CRO + CAIO unanimous" + ] + }, + "weightCustody": { + "model": "Dual-control HSM with n-of-m (3-of-5) key escrow across geographically separated custodians", + "custodians": [ + "CISO (primary)", + "CTO (secondary)", + "External trustee (LawFirm A)", + "External trustee (LawFirm B)", + "Supervisory escrow (PRA-appointed, sealed)" + ], + "rotation": "Quarterly key rotation; annual full re-attestation", + "pqReady": "Post-quantum signatures (Dilithium-5) layered over ECDSA during transition" + }, + "gpuAttestations": { + "mechanism": "SEV-SNP / Intel TDX confidential-VM attestation + CUDA-runtime measured boot", + "verifier": "Internal attestation service (ATLAS) cross-signed by cloud provider attestation APIs", + "frequency": "Per training run + per 1000 inferences in confidential-inference mode", + "crsUsage": "Training attested; inference runs on standard (non-confidential) infra as CRS does not process regulated frontier-sensitive data" + } + }, + "L4_geopoliticalTreaty": { + "id": "L4", + "title": "Geopolitical Treaty Governance — GAGCOT & Global AI Crisis Simulations (GC1-GC7)", + "summary": "Treaty-level overlay for CRS-UUID-001 via GAGCOT (Global AI Governance & Compute Oversight Treaty Charter). CRS is a signatory-institution registered high-impact system subject to GC1-GC7 protocols.", + "gagcot": { + "fullName": "Global AI Governance and Compute Oversight Treaty Charter", + "acronym": "GAGCOT", + "authority": "G-AGCOTA (Global AI Governance & Compute Oversight Treaty Authority)", + "articles": [ + { + "article": "Art. 1", + "title": "Object & Purpose", + "essence": "Preserve civilizational integrity of AI-dependent critical services; harmonize model-risk supervision" + }, + { + "article": "Art. 2", + "title": "Scope & Definitions", + "essence": "Defines frontier compute, systemic AI, high-impact AI, signatory institution" + }, + { + "article": "Art. 3", + "title": "Compute Transparency", + "essence": "≥1e25 FLOPs pre-notification; quarterly compute-register attestations" + }, + { + "article": "Art. 4", + "title": "Safety Case Obligations", + "essence": "Frontier & systemic models must maintain current safety cases; independent red-team evidence" + }, + { + "article": "Art. 5", + "title": "Kill-Switch & Custody", + "essence": "HSM custody + n-of-m key escrow + ≤60s inference kill-switch for high-impact systems" + }, + { + "article": "Art. 6", + "title": "Evidence Custody & Replay", + "essence": "Tamper-evident evidence bundles; supervisory replay ≤72h" + }, + { + "article": "Art. 7", + "title": "Mutual Recognition", + "essence": "Equivalence certificates for supervisory regimes meeting baseline" + }, + { + "article": "Art. 8", + "title": "Crisis Protocols (GC1-GC7)", + "essence": "Activation thresholds, decision rights, MTTR targets" + }, + { + "article": "Art. 9", + "title": "Adversarial Co-Evolution", + "essence": "Shared threat intel; coordinated red-team; common kill-chain taxonomy" + }, + { + "article": "Art. 10", + "title": "Compliance Review", + "essence": "Annual peer review; public compliance index (by signatory)" + }, + { + "article": "Art. 11", + "title": "Dispute Resolution", + "essence": "Panel arbitration; sanction escalation ladder; sunset of non-compliant signatories" + }, + { + "article": "Art. 12", + "title": "Amendment & Sunset", + "essence": "2/3 majority amendment; 10-year sunset-review clause" + } + ], + "implementationCharter": { + "title": "Treaty Authority Implementation Charter for G-AGCOTA", + "pillars": [ + { + "pillar": "P1 · Secretariat", + "function": "24×7 Ops, intake, triage, escalation to crisis protocols" + }, + { + "pillar": "P2 · Compute Observatory", + "function": "Ingest compute-register attestations; anomaly detection; quarterly public report" + }, + { + "pillar": "P3 · Evidence Vault", + "function": "Merkle-DAG evidence receipts; supervisory replay service" + }, + { + "pillar": "P4 · Peer Review Panel", + "function": "Annual signatory review; publish compliance index" + }, + { + "pillar": "P5 · Crisis Response", + "function": "GC1-GC7 orchestration; cross-jurisdiction deconfliction" + }, + { + "pillar": "P6 · Standards & Harmonization", + "function": "Publish evidence & report schemas; align ISO/NIST/ENISA mappings" + } + ], + "funding": "Signatory assessed contributions (risk-weighted by supervisor AI market footprint)", + "staffing": "≈220 FTE at steady state (Yr-3); secondments from national supervisors", + "location": "Basel (primary) + Singapore (secondary) + Washington DC (liaison)", + "kpis": [ + { + "kpi": "Compute-register attestation compliance", + "target": "≥98%", + "measure": "% signatories current in quarter" + }, + { + "kpi": "GC1-GC7 activation MTTR", + "target": "Per Art. 8", + "measure": "Rolling-12m median" + }, + { + "kpi": "Replay service SLA", + "target": "≤72h", + "measure": "Monthly 95th percentile" + }, + { + "kpi": "Peer-review coverage", + "target": "100%", + "measure": "Annual signatory coverage" + } + ] + } + }, + "crsTreatyRegistration": { + "registrationId": "GAGCOT-INST-CRS-UUID-001", + "tier": "Signatory-Institution high-impact (not frontier)", + "obligations": [ + "Quarterly T-01 attestation (compute register, safety case, kill-switch tests)", + "Participation in GC4 adversarial-poisoning drill (annual)", + "Harmonized Supervisory Report HSR-08", + "Peer-review readiness (Art. 10)" + ], + "entitlements": [ + "Equivalence certificate eligibility (UK↔EU↔US↔SG)", + "Access to treaty threat-intel feed (Art. 9)", + "Replay-service SLA (Art. 6)" + ] + }, + "gcScenarios": [ + { + "id": "GC1", + "name": "Cross-Border Capability Shock", + "trigger": "Emergence of >1e25 FLOPs model with disclosed autonomous-agent capability above evaluated safety envelope", + "crsRelevance": "Indirect — triggers bank-wide AI capability reassessment; CRS itself unaffected", + "actions": [ + "G-AGCOTA emergency session within 48h", + "Pre-notification of analogous internal runs", + "Capability-evaluation swap with peer institutions" + ], + "mttr": "72h emergency action; 14d resolution" + }, + { + "id": "GC2", + "name": "Systemic Fairness Divergence", + "trigger": "≥3 cross-border banks report coordinated 4/5-rule failures on retail credit AI systems within 30-day window", + "crsRelevance": "Direct — CRS fairness metrics become sentinel indicators; harmonized supervisory college convened", + "actions": [ + "Cross-bank fairness-data sharing under treaty safe-harbour", + "Joint root-cause analysis", + "Coordinated remediation plan" + ], + "mttr": "30d diagnosis; 90d remediation" + }, + { + "id": "GC3", + "name": "Compute-Supply Disruption", + "trigger": "Loss of >40% accessible training compute capacity in OECD due to geopolitical event", + "crsRelevance": "Indirect — triggers fallback scorecard activation for CRS retraining", + "actions": [ + "Activate continuity-of-training protocol", + "Federated retraining with peer institutions", + "Supervisor waiver of retraining cadence" + ], + "mttr": "60d capacity restoration; 180d full normalisation" + }, + { + "id": "GC4", + "name": "Adversarial Data-Poisoning Campaign", + "trigger": "Detection of coordinated data-poisoning affecting ≥2 G-SIFI credit AI systems", + "crsRelevance": "Direct — CRS is a canonical target; kill-switch rehearsal becomes live protocol", + "actions": [ + "Treaty-coordinated attribution investigation", + "Synchronised kill-switch invocation", + "Joint weight-integrity re-attestation", + "Customer communication playbook" + ], + "mttr": "≤60s kill-switch; 30d forensic; 90d trust restoration" + }, + { + "id": "GC5", + "name": "Autonomous-Agent Containment Failure", + "trigger": "Exfiltration attempt or sandbox escape by an AI agent at any signatory institution", + "crsRelevance": "Low (CRS is non-agentic) — but blueprint retains the protocol for consistency and agent-era readiness", + "actions": [ + "Immediate institutional kill-switch", + "G-AGCOTA notification within 15 minutes", + "All-signatories agent-inventory audit within 24h" + ], + "mttr": "15m notification; 24h audit; 30d remediation" + }, + { + "id": "GC6", + "name": "Model-Weight Compromise", + "trigger": "Confirmed exfiltration of weights for any treaty-registered model", + "crsRelevance": "Direct — CRS weights are HSM-custody; breach triggers GC6 response", + "actions": [ + "HSM revocation", + "Emergency rotation to v4.3 with re-trained weights", + "Customer notification", + "Joint supervisory-treaty investigation" + ], + "mttr": "24h revocation; 14d rotation; 90d supervisory conclusion" + }, + { + "id": "GC7", + "name": "Governance Dissolution Threat", + "trigger": "Signatory state withdrawal or coordinated attack on treaty infrastructure", + "crsRelevance": "Indirect — invokes governance continuity codex; CRS governance continues under national regulators", + "actions": [ + "Continuity of supervision via Ring-1 coalition", + "Fallback to bilateral supervisory MoUs", + "Evidence-bundle integrity preservation" + ], + "mttr": "Continuous — no service interruption permitted" + } + ], + "crisisRunbooks": { + "GC4_runbook": { + "title": "CRS-UUID-001 Adversarial Data-Poisoning Response Runbook", + "phases": [ + { + "phase": "Detect", + "actions": [ + "PSI >0.12 triggers investigation", + "Feature-distribution anomaly detector alerts", + "Shadow-model divergence >3σ" + ] + }, + { + "phase": "Confirm", + "actions": [ + "IMV re-runs back-test with immutable snapshot", + "Open-banking-data provider cross-check", + "Threat-intel correlation via treaty feed" + ] + }, + { + "phase": "Contain", + "actions": [ + "Kill-switch invocation (≤60s)", + "Rollback to v4.1", + "HSM key freeze", + "Customer communications hold" + ] + }, + { + "phase": "Notify", + "actions": [ + "Art. 73 report to PRA/MSA within 2h", + "GAGCOT notification within 15m", + "Board Risk flash-call" + ] + }, + { + "phase": "Remediate", + "actions": [ + "Data-source recertification", + "Retraining from clean snapshot", + "Peer-bank coordinated response", + "Supervisory college session" + ] + }, + { + "phase": "Review", + "actions": [ + "Root-cause (10 working days)", + "Post-market-monitoring update", + "Lessons-learned into treaty library", + "Public supervisory disclosure" + ] + } + ] + } + } + }, + "L5_autonomousMesh": { + "id": "L5", + "title": "Autonomous Governance Mesh — Policy-as-Code, CI/CD & Cryptographic Evidence", + "summary": "OPA/Rego policies codify institutional, systemic, and treaty obligations, executing as deterministic gates across the CRS CI/CD pipeline and runtime. All decisions emit signed evidence artefacts that roll up into nine Merkle-anchored evidence bundles, producing a continuously-provable compliance posture.", + "meshArchitecture": { + "controlPlane": "OPA servers (Rego bundles) distributed across CI agents, K8s admission, API gateway, and feature-store", + "dataPlane": "Signed decision logs → streaming pipeline → evidence-bundle writer → Merkle-DAG appender → WORM vault", + "observability": [ + "Policy decision latency p99 <15ms", + "Bundle-drift alerting", + "Policy-coverage dashboard per CRS change" + ] + }, + "opaPolicies": [ + { + "id": "P-001", + "package": "crs.conformity", + "title": "Annex IV completeness gate", + "enforces": "All 9 Annex IV sections present + Merkle-anchored", + "decision": "deny on missing/invalid section" + }, + { + "id": "P-002", + "package": "crs.fairness", + "title": "4/5 rule fairness gate", + "enforces": "No protected class below 0.80 disparate-impact ratio", + "decision": "deny deploy; mandate remediation plan" + }, + { + "id": "P-003", + "package": "crs.drift", + "title": "PSI drift guard", + "enforces": "PSI ≤0.10 rolling 30d; halt auto-retrain if >0.25", + "decision": "alert MRC; block auto-retrain" + }, + { + "id": "P-004", + "package": "crs.fcra", + "title": "Adverse-action notice coverage", + "enforces": "100% of declines have top-4 reason codes + notice generated", + "decision": "deny prod deploy if <100%" + }, + { + "id": "P-005", + "package": "crs.gdpr", + "title": "Art. 22 safeguards", + "enforces": "Appeal route active + DPIA current + DPO sign-off ≤12m", + "decision": "deny if safeguards missing" + }, + { + "id": "P-006", + "package": "crs.killswitch", + "title": "Kill-switch test freshness", + "enforces": "All 3 patterns tested within 35 days", + "decision": "block change freeze-exemption" + }, + { + "id": "P-007", + "package": "crs.imv", + "title": "IMV independence", + "enforces": "Reviewer ≠ developer; independence attestation current", + "decision": "deny model approval" + }, + { + "id": "P-008", + "package": "crs.evidence", + "title": "Evidence bundle integrity", + "enforces": "Signed Merkle root verified for EB-001..EB-009", + "decision": "deny release" + }, + { + "id": "P-009", + "package": "crs.compute", + "title": "Compute-register entry", + "enforces": "Training run has register entry + attestation within 7d", + "decision": "alert; block subsequent runs after 30d grace" + }, + { + "id": "P-010", + "package": "crs.treaty", + "title": "GAGCOT T-01 attestation currency", + "enforces": "Quarterly attestation submitted and signed", + "decision": "block non-urgent deploys" + }, + { + "id": "P-011", + "package": "crs.incident", + "title": "Art. 73 incident SLA", + "enforces": "If incident flagged, notification dispatch ≤2h", + "decision": "escalate to CAIO on SLA breach" + }, + { + "id": "P-012", + "package": "crs.consumerduty", + "title": "Consumer Duty outcomes gate", + "enforces": "Vulnerable-customer outcome gap ≤2pp rolling 90d", + "decision": "trigger remediation plan; block promo pricing" + } + ], + "ciCdGates": [ + { + "gate": "G-01", + "stage": "Pre-commit", + "policy": "P-007", + "effect": "Block commits from developer equal to designated IMV reviewer" + }, + { + "gate": "G-02", + "stage": "Pre-commit", + "policy": "SAST + license", + "effect": "Block on critical CVEs or incompatible OSS licenses" + }, + { + "gate": "G-03", + "stage": "Build", + "policy": "P-008", + "effect": "Verify evidence-bundle signatures match expected Merkle roots" + }, + { + "gate": "G-04", + "stage": "Build", + "policy": "Reproducibility", + "effect": "Byte-identical build across two clean agents required" + }, + { + "gate": "G-05", + "stage": "Test", + "policy": "P-002", + "effect": "Block deploy if fairness tests fail any protected class" + }, + { + "gate": "G-06", + "stage": "Test", + "policy": "P-003", + "effect": "Block deploy if holdout PSI >0.10" + }, + { + "gate": "G-07", + "stage": "Test", + "policy": "P-006", + "effect": "Block deploy if kill-switch tests stale" + }, + { + "gate": "G-08", + "stage": "Pre-deploy", + "policy": "P-001", + "effect": "Block release if Annex IV sections not current" + }, + { + "gate": "G-09", + "stage": "Pre-deploy", + "policy": "P-005", + "effect": "Block release if DPO sign-off expired" + }, + { + "gate": "G-10", + "stage": "Pre-deploy", + "policy": "P-009", + "effect": "Block release if compute-register entry missing" + }, + { + "gate": "G-11", + "stage": "Pre-deploy", + "policy": "P-010", + "effect": "Block release if GAGCOT attestation overdue" + }, + { + "gate": "G-12", + "stage": "Runtime", + "policy": "P-004", + "effect": "Runtime telemetry: alert if adverse-action notice coverage <100%" + }, + { + "gate": "G-13", + "stage": "Runtime", + "policy": "P-011", + "effect": "Incident-dispatch SLA enforcement; pager escalation" + }, + { + "gate": "G-14", + "stage": "Runtime", + "policy": "P-012", + "effect": "Consumer-duty KRI guard; auto-open corrective-action ticket" + } + ], + "evidenceBundles": [ + { + "id": "EB-001", + "label": "General & Identification", + "contents": [ + "Model card v4.2", + "Provider/Deployer registration", + "SW/HW stack manifest" + ], + "merkleRoot": "sha3-256:4d1a…91ce", + "retention": "10 years post-decommission" + }, + { + "id": "EB-002", + "label": "Architecture & Training", + "contents": [ + "Architecture diagram", + "Feature lineage", + "Training pipeline Docker digest", + "Weights hash" + ], + "merkleRoot": "sha3-256:a20f…75bc", + "retention": "10 years" + }, + { + "id": "EB-003", + "label": "Oversight & Control", + "contents": [ + "Human-oversight protocol", + "Override logs schema", + "Kill-switch test reports" + ], + "merkleRoot": "sha3-256:9e8b…22fa", + "retention": "10 years" + }, + { + "id": "EB-004", + "label": "Risk Management", + "contents": [ + "ISO 23894 risk register", + "Treatment plans", + "Residual-risk sign-off" + ], + "merkleRoot": "sha3-256:11c5…d034", + "retention": "10 years" + }, + { + "id": "EB-005", + "label": "Data Governance", + "contents": [ + "Data sheet", + "Provenance receipts", + "GDPR Art. 10 disclosures", + "Bias detection report" + ], + "merkleRoot": "sha3-256:6fab…4e21", + "retention": "10 years" + }, + { + "id": "EB-006", + "label": "Lifecycle Changes", + "contents": [ + "Change log", + "CAB records", + "Impact assessments", + "Re-validation outcomes" + ], + "merkleRoot": "sha3-256:23dd…87a9", + "retention": "10 years" + }, + { + "id": "EB-007", + "label": "Standards Applied", + "contents": [ + "ISO/IEC 42001 cert", + "ISO 23894 mapping", + "ISO 25059 quality eval" + ], + "merkleRoot": "sha3-256:bc70…1fe4", + "retention": "10 years" + }, + { + "id": "EB-008", + "label": "Conformity & Declaration", + "contents": [ + "EU DoC (signed)", + "Conformity route Art. 43", + "Notified-body correspondence" + ], + "merkleRoot": "sha3-256:5a44…c309", + "retention": "10 years" + }, + { + "id": "EB-009", + "label": "Post-Market & Monitoring", + "contents": [ + "PMM plan", + "Drift reports", + "Incident register", + "Art. 73 filings (if any)" + ], + "merkleRoot": "sha3-256:ff82…7b56", + "retention": "10 years" + } + ], + "evidenceManifestSchema": { + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$id": "https://globalbank.example/schemas/crs-evidence-manifest.json", + "type": "object", + "required": [ + "bundleId", + "label", + "merkleRoot", + "signature", + "contents", + "generatedAt", + "retentionUntil" + ], + "properties": { + "bundleId": { + "type": "string", + "pattern": "^EB-[0-9]{3}$" + }, + "label": { + "type": "string" + }, + "merkleRoot": { + "type": "string", + "pattern": "^sha3-256:[0-9a-f…]+$" + }, + "signature": { + "type": "object", + "required": [ + "alg", + "value", + "keyId" + ], + "properties": { + "alg": { + "enum": [ + "Ed25519", + "Dilithium5", + "Hybrid-Ed25519+Dilithium5" + ] + }, + "value": { + "type": "string" + }, + "keyId": { + "type": "string" + } + } + }, + "contents": { + "type": "array", + "items": { + "type": "object", + "required": [ + "name", + "hash" + ] + } + }, + "generatedAt": { + "type": "string", + "format": "date-time" + }, + "retentionUntil": { + "type": "string", + "format": "date" + }, + "previousRoot": { + "type": "string" + } + } + } + }, + "L6_adversarialCoEvo": { + "id": "L6", + "title": "Adversarial Co-Evolution — Red-Team, Threat Intel & Kill-Chain Playbooks", + "summary": "Continuous adversarial testing and threat-intel integration keep CRS-UUID-001 resilient against evolving attacks. Shared kill-chain taxonomy aligns with GAGCOT Art. 9 and peer institutions.", + "redTeamProgramme": { + "cadence": "Monthly targeted exercises + annual full-scope campaign + ad-hoc on threat-intel trigger", + "scope": [ + "Data-poisoning (training + online)", + "Evasion (adversarial feature perturbation)", + "Membership inference", + "Model inversion (fairness-proxy leakage)", + "Supply-chain compromise (feature-store tampering)", + "Prompt-injection (future-proofing; currently N/A for XGBoost)", + "Insider threat (developer account takeover)" + ], + "independence": "Mixed internal (GB-Offensive) + external vendor (BlueRed Consulting) rotating annually", + "findingsSeverity": { + "critical": 0, + "high": 2, + "medium": 7, + "low": 14, + "ytd": "2026" + } + }, + "killChainTaxonomy": { + "aligned": "GAGCOT Art. 9 shared kill-chain + MITRE ATLAS", + "phases": [ + { + "phase": "Reconnaissance", + "crsExample": "Scrape public model-card details; open-banking API probe" + }, + { + "phase": "Initial Access", + "crsExample": "Compromised OSS dependency; vendor data-feed manipulation" + }, + { + "phase": "Persistence", + "crsExample": "Poisoned feature in upstream bureau feed" + }, + { + "phase": "Privilege Escalation", + "crsExample": "Abuse of override-admin role" + }, + { + "phase": "Defence Evasion", + "crsExample": "Fairness-metric gaming (slow drift below detection threshold)" + }, + { + "phase": "Impact", + "crsExample": "Systematic mis-scoring producing conduct harm or capital loss" + } + ] + }, + "threatIntelIntegration": { + "feeds": [ + "GAGCOT Art. 9 cross-bank feed", + "FS-ISAC AI working group", + "MITRE ATLAS", + "National cyber-centre (NCSC/CISA)", + "DPA enforcement pattern feed (ICO/CNIL)" + ], + "correlationEngine": "SIEM + OpenCTI + ATLAS tagger; automated case opening into GRC on high-confidence matches", + "sharingProtocol": "TLP:AMBER for intra-college; TLP:GREEN+ for treaty-wide; TLP:RED only when active attack" + }, + "purpleTeamLoops": { + "frequency": "Quarterly", + "outputs": [ + "Detection-gap closure tickets", + "Rego policy updates (e.g. new drift thresholds)", + "Kill-switch drill variants", + "Fairness-monitor tuning" + ] + }, + "coEvolutionMetrics": [ + { + "metric": "Mean-time-to-detect (MTTD) poisoning", + "target": "≤30 days", + "current": "18 days" + }, + { + "metric": "Mean-time-to-contain (MTTC)", + "target": "≤60 minutes", + "current": "47 minutes" + }, + { + "metric": "Red-team coverage vs kill-chain phases", + "target": "100% annually", + "current": "100% YTD" + }, + { + "metric": "Treaty-feed IOC actioning SLA", + "target": "≤24h", + "current": "11h median" + } + ] + }, + "simulations": [ + { + "id": "SIM-L1", + "layer": "Institutional", + "name": "MRC Escalation Drill", + "objective": "Validate that a fairness KPI breach escalates through 2LoD to Board Risk within SLA", + "scenario": "Inject synthetic disparate-impact failure in test env; time each hop", + "kpis": [ + "Detection →1h", + "2LoD ack →4h", + "MRC convene →24h", + "Board brief →72h" + ], + "passCriteria": "All KPIs met; evidence bundle EB-004 updated; Rego P-002 fires" + }, + { + "id": "SIM-L2", + "layer": "Systemic", + "name": "Supervisory College Stress Run", + "objective": "Coordinated supervisory response under cross-border deterioration", + "scenario": "Simulate AUC drop to 0.71 and 4/5-rule breach simultaneously in UK+US+EU", + "kpis": [ + "HSR-01 flash issued ≤48h", + "College session ≤5 working days", + "Harmonised remediation plan ≤30d" + ], + "passCriteria": "All HSRs consistent; capital-impact assessment produced; Pillar-2 add-on revised" + }, + { + "id": "SIM-L3", + "layer": "Frontier Compute", + "name": "Kill-Switch + Weight-Custody Drill", + "objective": "End-to-end kill-switch under adversarial trigger with weight-custody revocation", + "scenario": "GC4 simulated; invoke inference kill-switch; verify rollback and HSM freeze", + "kpis": [ + "Inference disable ≤60s", + "Rollback ≤15m", + "HSM freeze ≤30m" + ], + "passCriteria": "Actuals within SLA; Rego P-006 confirms test freshness; post-kill protocol executed" + }, + { + "id": "SIM-L4", + "layer": "Geopolitical Treaty", + "name": "GC4 Treaty Table-Top", + "objective": "Multi-signatory coordinated response to poisoning campaign", + "scenario": "Three banks report similar anomalies; GAGCOT emergency session convened", + "kpis": [ + "Notification ≤15m", + "Evidence shared under safe-harbour ≤24h", + "Joint communique ≤72h" + ], + "passCriteria": "All signatories synchronised; public communique drafted; lessons logged to Art. 9 library" + }, + { + "id": "SIM-L5", + "layer": "Autonomous Mesh", + "name": "Policy-as-Code Chaos Test", + "objective": "Resilience of OPA/Rego mesh under partial outage", + "scenario": "Disable 30% of OPA replicas; attempt deploy violating P-002; observe fail-closed behaviour", + "kpis": [ + "All violating deploys blocked", + "Policy decision latency p99 <50ms in degraded state", + "Alerting fires within 60s" + ], + "passCriteria": "Zero policy-bypass; evidence bundle EB-008 integrity preserved" + }, + { + "id": "SIM-L6", + "layer": "Adversarial Co-Evolution", + "name": "Full-Scope Red-Team Campaign", + "objective": "Discover residual weaknesses across kill-chain", + "scenario": "30-day campaign covering all 7 kill-chain phases with external + internal teams", + "kpis": [ + "Phase coverage 100%", + "Critical findings 0", + "All findings remediated ≤90d" + ], + "passCriteria": "Campaign report delivered; Rego policies refreshed; purple-team loop closed" + }, + { + "id": "SIM-GC1", + "layer": "Geopolitical Treaty", + "name": "GC1 Capability-Shock Rehearsal", + "objective": "G-AGCOTA 48h convening drill", + "scenario": "Peer discloses >1e25 FLOPs model; emergency session", + "kpis": [ + "Convene ≤48h", + "Response plan ≤14d" + ], + "passCriteria": "SLAs met" + }, + { + "id": "SIM-GC2", + "layer": "Geopolitical Treaty", + "name": "GC2 Fairness Divergence Rehearsal", + "objective": "Cross-bank fairness swap", + "scenario": "Three banks coordinated 4/5 breach", + "kpis": [ + "Data-share ≤24h", + "Joint RCA ≤30d" + ], + "passCriteria": "SLAs met" + }, + { + "id": "SIM-GC3", + "layer": "Geopolitical Treaty", + "name": "GC3 Compute-Supply Rehearsal", + "objective": "Continuity of training", + "scenario": "40% compute loss; fallback scorecard", + "kpis": [ + "Fallback ≤7d", + "Normalisation ≤180d" + ], + "passCriteria": "SLAs met" + }, + { + "id": "SIM-GC4", + "layer": "Geopolitical Treaty", + "name": "GC4 Poisoning Campaign Rehearsal", + "objective": "Synchronised kill-switch", + "scenario": "Multi-bank poisoning detected", + "kpis": [ + "Kill-switch ≤60s", + "Joint attrib ≤30d" + ], + "passCriteria": "SLAs met" + }, + { + "id": "SIM-GC5", + "layer": "Geopolitical Treaty", + "name": "GC5 Containment-Failure Rehearsal", + "objective": "Agent-era readiness", + "scenario": "Hypothetical agent escape", + "kpis": [ + "Notify ≤15m", + "Audit ≤24h" + ], + "passCriteria": "SLAs met; blueprint consistency retained" + }, + { + "id": "SIM-GC6", + "layer": "Geopolitical Treaty", + "name": "GC6 Weight-Compromise Rehearsal", + "objective": "Custody revocation drill", + "scenario": "Simulated weight exfiltration", + "kpis": [ + "Revoke ≤24h", + "Rotate ≤14d" + ], + "passCriteria": "SLAs met" + }, + { + "id": "SIM-GC7", + "layer": "Geopolitical Treaty", + "name": "GC7 Continuity-of-Governance Rehearsal", + "objective": "Supervisory continuity", + "scenario": "Signatory withdrawal simulated", + "kpis": [ + "No service gap", + "Bilateral MoU ≤30d" + ], + "passCriteria": "SLAs met" + } + ], + "capitalImpactAssessment": { + "title": "Capital Impact Assessment — CRS-UUID-001 (Pillar-2 Model Risk)", + "framework": "Basel III · PRA SS1/23 · ICAAP Pillar-2", + "baseCase": { + "directRwaInfluence_bn": 3.2, + "ifrs9LlpInfluence_m": 420, + "pillar2Addon_m_2025": 42, + "pillar2Addon_m_2026": 26, + "managementOverlay_m": 85 + }, + "assuranceDepthUplift": { + "priorScore": 2.1, + "postWp032Score": 3.7, + "scale": "0-4 (per PRA SS1/23 scoring rubric)", + "driversAdded": [ + "ISO 42001 certification", + "Annex IV completeness", + "Independent red-team", + "Cryptographic evidence bundles", + "Treaty attestation" + ] + }, + "scenarioCapitalSensitivity": [ + { + "scenario": "Severe adverse 2026", + "crsModelSensitivity": "PoD up-shift 24% in recession lag-1", + "capitalImpact": "£180m CET1 absorption", + "commentary": "Within Pillar-2 buffer" + }, + { + "scenario": "Climate transition (disorderly)", + "crsModelSensitivity": "Geographic sector drift; PSI up to 0.18", + "capitalImpact": "£95m", + "commentary": "Early-warning trigger at PSI 0.12" + }, + { + "scenario": "Geopolitical shock (sanctions)", + "crsModelSensitivity": "Open-banking data-feed loss in 3 markets", + "capitalImpact": "£40m", + "commentary": "Fallback scorecard activates" + }, + { + "scenario": "AI-specific (adversarial data-poisoning)", + "crsModelSensitivity": "AUC −6pp if undetected for 30 days", + "capitalImpact": "£120m", + "commentary": "Triggers GC4 treaty protocol" + } + ], + "boardConclusion": "The Board considers the Pillar-2 model-risk add-on of £26m adequate given current assurance depth (3.7/4.0) and residual uncertainty. The £85m management overlay provides additional buffer pending Annex IV notified-body review. Triggers for revision: (i) AUC <0.78 two consecutive quarters, (ii) 4/5 rule breach, (iii) Art. 73 serious incident, (iv) GAGCOT GC-series activation." + }, + "validationReport": { + "title": "Independent Model Validation — CRS-UUID-001 v4.2", + "authority": "Group Head of IMV (reports to CRO)", + "standard": "SR 11-7 · SS1/23", + "scope": "Full revalidation post v4.2 release", + "dateIssued": "2026-04-12", + "findings": { + "critical": 0, + "high": 0, + "medium": 3, + "low": 7 + }, + "conclusions": [ + "Conceptual soundness: ACCEPTABLE — architecture choice justified; monotonic constraints documented", + "Outcome analysis: ACCEPTABLE — out-of-time AUC 0.812, PSI 0.067, KS 0.48", + "Ongoing monitoring: ACCEPTABLE — KRI dashboard operational; drift monitoring 30-day rolling", + "Governance: ACCEPTABLE — MRC oversight, tier re-confirmed Tier-1" + ], + "effectiveChallengeExamples": [ + "Challenged calibration layer → developer rebuilt with additional monotonic constraints (MRIA-042 closed)", + "Challenged fairness testing scope → added two proxy-class tests per CFPB guidance (MRIA-043 closed)", + "Challenged kill-switch evidence → monthly rehearsal cadence formalised (MRIA-044 in progress)" + ], + "recommendations": [ + "Expand fairness proxies to include age-band interaction effects", + "Implement shadow-model divergence monitor with 3σ threshold", + "Pre-certify 2027 ISO/IEC 42001 surveillance audit scope" + ] + }, + "schemas": { + "evidenceManifest": { + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$id": "https://globalbank.example/schemas/crs-evidence-manifest.json", + "type": "object", + "required": [ + "bundleId", + "label", + "merkleRoot", + "signature", + "contents", + "generatedAt", + "retentionUntil" + ], + "properties": { + "bundleId": { + "type": "string", + "pattern": "^EB-[0-9]{3}$" + }, + "label": { + "type": "string" + }, + "merkleRoot": { + "type": "string", + "pattern": "^sha3-256:[0-9a-f…]+$" + }, + "signature": { + "type": "object", + "required": [ + "alg", + "value", + "keyId" + ], + "properties": { + "alg": { + "enum": [ + "Ed25519", + "Dilithium5", + "Hybrid-Ed25519+Dilithium5" + ] + }, + "value": { + "type": "string" + }, + "keyId": { + "type": "string" + } + } + }, + "contents": { + "type": "array", + "items": { + "type": "object", + "required": [ + "name", + "hash" + ] + } + }, + "generatedAt": { + "type": "string", + "format": "date-time" + }, + "retentionUntil": { + "type": "string", + "format": "date" + }, + "previousRoot": { + "type": "string" + } + } + }, + "computeRegisterEntry": { + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$id": "https://gagcot.example/schemas/compute-register-entry.json", + "type": "object", + "required": [ + "modelId", + "trainingRunId", + "flopsTotal", + "gpuHours", + "weightsHash", + "signature" + ], + "properties": { + "modelId": { + "type": "string" + }, + "trainingRunId": { + "type": "string" + }, + "flopsTotal": { + "type": "number", + "minimum": 0 + }, + "gpuHours": { + "type": "integer", + "minimum": 0 + }, + "datacentreLocation": { + "type": "string" + }, + "weightsHash": { + "type": "string" + }, + "evidenceBundle": { + "type": "string" + }, + "signature": { + "type": "object" + } + } + }, + "harmonizedSupervisoryReport": { + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$id": "https://gagcot.example/schemas/harmonized-supervisory-report.json", + "type": "object", + "required": [ + "reportId", + "modelId", + "period", + "sections", + "signature" + ], + "properties": { + "reportId": { + "type": "string", + "pattern": "^HSR-[0-9]{2}$" + }, + "modelId": { + "type": "string" + }, + "period": { + "type": "string" + }, + "sections": { + "type": "array" + }, + "signature": { + "type": "object" + } + } + }, + "supervisoryReplayRequest": { + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$id": "https://globalbank.example/schemas/supervisory-replay-request.json", + "type": "object", + "required": [ + "requestId", + "supervisor", + "scope", + "slaHours" + ], + "properties": { + "requestId": { + "type": "string" + }, + "supervisor": { + "type": "string" + }, + "scope": { + "type": "object", + "required": [ + "type" + ], + "properties": { + "type": { + "enum": [ + "individualDecision", + "aggregateStat", + "fullBacktest" + ] + }, + "decisionId": { + "type": "string" + }, + "dateRange": { + "type": "object" + }, + "cohort": { + "type": "object" + } + } + }, + "slaHours": { + "type": "integer", + "minimum": 1, + "maximum": 168 + } + } + }, + "gcActivationRecord": { + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$id": "https://gagcot.example/schemas/gc-activation-record.json", + "type": "object", + "required": [ + "gcId", + "activatedAt", + "trigger", + "signatoriesNotified" + ], + "properties": { + "gcId": { + "enum": [ + "GC1", + "GC2", + "GC3", + "GC4", + "GC5", + "GC6", + "GC7" + ] + }, + "activatedAt": { + "type": "string", + "format": "date-time" + }, + "trigger": { + "type": "string" + }, + "signatoriesNotified": { + "type": "array", + "items": { + "type": "string" + } + }, + "mttrActualHours": { + "type": "number" + }, + "evidenceBundle": { + "type": "string" + } + } + } + }, + "codeExamples": { + "regoAnnexIvGate": "package crs.conformity\n\n# P-001 · Annex IV completeness gate\n# Denies CI/CD promotion if any Annex IV section is missing or has an invalid Merkle root.\n\ndefault allow = false\n\nrequired_sections := {\"1\",\"2\",\"3\",\"4\",\"5\",\"6\",\"7\",\"8\",\"9\"}\n\npresent_sections := {s | s := input.annexIv.sections[_].section; startswith(s, _)}\n\nmissing_sections := required_sections - {split(s, \".\")[0] | s := input.annexIv.sections[_].section}\n\nmerkle_invalid[s] {\n some i\n s := input.annexIv.sections[i].section\n not regex.match(`^sha3-256:[0-9a-f]+$`, input.annexIv.sections[i].merkleRoot)\n}\n\nallow {\n count(missing_sections) == 0\n count(merkle_invalid) == 0\n}\n\ndeny[msg] {\n count(missing_sections) > 0\n msg := sprintf(\"Annex IV sections missing: %v\", [missing_sections])\n}\n\ndeny[msg] {\n count(merkle_invalid) > 0\n msg := sprintf(\"Annex IV sections with invalid Merkle root: %v\", [merkle_invalid])\n}\n", + "regoFairnessGate": "package crs.fairness\n\n# P-002 · 4/5 rule fairness gate\n# Denies deploy if any protected class selection-rate ratio < 0.80.\n\ndefault allow = false\n\nviolations[class] {\n some class\n ratio := input.fairness.selectionRateRatio[class]\n ratio < 0.80\n}\n\nallow {\n count(violations) == 0\n}\n\ndeny[msg] {\n count(violations) > 0\n msg := sprintf(\"4/5 rule violated for classes: %v\", [violations])\n}\n", + "killSwitchProcedure": "# CRS-UUID-001 Kill-Switch Procedure (operator-facing)\n# Target SLAs: runtime disable ≤60s · rollback ≤15m · HSM freeze ≤30m\n# Invocation authority: CAIO or CISO or CRO (any 1 of 3) for emergency\n\nset -euo pipefail\n\n# 1. Runtime inference disable (≤60s)\nkubectl -n crs-prod set env deploy/crs-inference CRS_DISABLED=true\naws apigateway update-stage --rest-api-id $CRS_API --stage-name prod \\\n --patch-operations op=replace,path=/variables/CRS_DISABLED,value=true\n\n# 2. Rollback to v4.1 (≤15m)\nargocd app set crs-inference --revision v4.1.0 && argocd app sync crs-inference --prune\n\n# 3. HSM weight-custody freeze (≤30m)\nhsm-cli revoke --key-alias crs-uuid-001-weights --reason \"emergency-kill-switch\" \\\n --approvers $CISO_KEY,$CTO_KEY --quorum 2-of-5\n\n# 4. Evidence bundle freeze\nevidence-cli freeze --bundles EB-001..EB-009 --reason \"kill-switch-invoked\" \\\n --anchor-to merkle-dag\n\n# 5. Notification fan-out\nincident-cli fire --sev P1 \\\n --notify pra,fca,occ,fed,ecb,ico,gagcot,board-risk,mrc \\\n --art73-template crs-serious-incident.yaml\n\necho \"Kill-switch invoked at $(date -u +%FT%TZ) — post-kill protocol engaged.\"\n", + "evidenceManifestExample": "{\n \"bundleId\": \"EB-005\",\n \"label\": \"Data Governance\",\n \"merkleRoot\": \"sha3-256:6fab4a77c1d9e8ba24517c0a9f3b81e2d76cf448e21a90b3fc77a8b014e2…4e21\",\n \"signature\": {\n \"alg\": \"Hybrid-Ed25519+Dilithium5\",\n \"value\": \"base64:MIIBkz…QUFB\",\n \"keyId\": \"gb-evidence-signer-2026-q2\"\n },\n \"contents\": [\n {\"name\": \"data-sheet-v4.2.pdf\", \"hash\": \"sha3-256:1a…b2\"},\n {\"name\": \"provenance-receipts.jsonl\",\"hash\": \"sha3-256:2c…d4\"},\n {\"name\": \"gdpr-art10-disclosures.md\",\"hash\": \"sha3-256:3e…f6\"},\n {\"name\": \"bias-detection-report.pdf\",\"hash\": \"sha3-256:4f…18\"}\n ],\n \"generatedAt\": \"2026-04-22T08:00:00Z\",\n \"retentionUntil\": \"2036-04-22\",\n \"previousRoot\": \"sha3-256:5b…2a\"\n}\n", + "harmonizedReportExample": "{\n \"reportId\": \"HSR-01\",\n \"modelId\": \"CRS-UUID-001\",\n \"period\": \"2026-Q1\",\n \"sections\": [\n {\"id\": \"1\", \"title\": \"Performance\", \"kpis\": {\"auc\": 0.812, \"psi\": 0.067, \"ks\": 0.48}},\n {\"id\": \"2\", \"title\": \"Fairness\", \"kpis\": {\"fourFifths_min\": 0.84, \"demographicParityGap\": 0.031}},\n {\"id\": \"3\", \"title\": \"Conduct\", \"kpis\": {\"appealOverturnRate\": 0.041, \"vulnerableGap_pp\": 0.012}},\n {\"id\": \"4\", \"title\": \"Operational\", \"kpis\": {\"killSwitchTestPass\": 1.0, \"incidents_art73\": 0}},\n {\"id\": \"5\", \"title\": \"Capital Impact\",\"kpis\": {\"pillar2Addon_m\": 26, \"rwaInfluence_bn\": 3.2}}\n ],\n \"signature\": {\n \"alg\": \"Ed25519\",\n \"value\": \"base64:MCowBQYDK2Vw…\",\n \"keyId\": \"gb-supervisor-signer-2026\"\n }\n}\n", + "computeRegisterYaml": "# CRS-UUID-001 — Compute Register Entry (YAML)\nmodelId: CRS-UUID-001\ntrainingRunId: tr-crs-20260315-a1b2\nflopsTotal: 4.2e18\ngpuHours: 96\ndatacentreLocation: GB-LND\nproviderAccount: globalbank-aiplatform-prod\nstartedAt: 2026-03-15T09:12:00Z\nendedAt: 2026-03-15T15:48:00Z\nweightsHash: sha3-256:9f3a00c1b2d30e11…c217\nevidenceBundle: EB-002\nattestation:\n tee: SEV-SNP\n verifier: atlas.globalbank.internal\n nonce: 0x8b2a…f10c\nfrontierTrigger: false\nsignature:\n alg: Dilithium5\n value: base64:MIIB…QUFB\n keyId: gb-compute-signer-2026-q2\n" + } +} \ No newline at end of file diff --git a/rag-agentic-dashboard/gen-civ-ai-gov-6l-crs-html.py b/rag-agentic-dashboard/gen-civ-ai-gov-6l-crs-html.py new file mode 100644 index 00000000..5ce1bbd5 --- /dev/null +++ b/rag-agentic-dashboard/gen-civ-ai-gov-6l-crs-html.py @@ -0,0 +1,926 @@ +#!/usr/bin/env python3 +"""Render WP-032 Six-Layer Civilizational AI Governance Blueprint (CRS-UUID-001) +as a regulator-ready HTML dashboard.""" + +import json +import html +from pathlib import Path + +HERE = Path(__file__).parent +DATA = json.load(open(HERE / "data" / "civ-ai-gov-6l-crs.json")) +OUT = HERE / "public" / "civ-ai-gov-6l-crs.html" + + +def esc(s): + if s is None: + return "" + return html.escape(str(s)) + + +def render_list(items): + if not items: + return "" + return '
{esc(json.dumps(v, ensure_ascii=False))[:200]}{esc(str(obj))}
" + rows = [] + for k, v in obj.items(): + if isinstance(v, (list, dict)): + v_display = json.dumps(v, ensure_ascii=False) + if len(v_display) > 200: + v_display = v_display[:200] + "…" + rows.append(f"{esc(v_display)}| {esc(headers[0])} | {esc(headers[1])} |
|---|
End-to-end governance reference implementation for {esc(subj['modelName'])}, a Tier-1 EU AI Act high-risk credit-risk scoring AI at Global Bank plc. Spans six layers: Institutional (SR 11-7 / ISO 42001 / Annex IV) → Systemic (PRA / FCA / OCC / ICAAP) → Frontier Compute (custody, kill-switch) → Geopolitical Treaty (GAGCOT · GC1-GC7) → Autonomous Mesh (OPA/Rego · CI/CD · cryptographic evidence) → Adversarial Co-Evolution (red-team · threat intel · kill-chain).
+ +{esc(DATA['executiveSummary'])}
+{esc(L['summary'])}
+ +{esc(L['summary'])}
+ +{esc(replay['purpose'])}
+{esc(L['summary'])}
+ +Trigger: {esc(gc['trigger'])}
+CRS relevance: {esc(gc['crsRelevance'])}
+MTTR: {esc(gc['mttr'])}
+{esc(L['summary'])}
+ +{esc(runbook['title'])}
+ {render_dict_list(runbook['phases'], [("phase","Phase"),("actions","Actions")])} +{esc(gg['implementationCharter']['title'])}
+ {pillars} +{esc(L['summary'])}
+ +{esc(json.dumps(L['evidenceManifestSchema'], indent=2))}
+ {esc(L['summary'])}
+ +Engine: {esc(ti['correlationEngine'])}
+Sharing Protocol: {esc(ti['sharingProtocol'])}
+{esc(annex['instrument'])} · Document ID {esc(annex['doc'])} · {esc(annex['sizing'])}
{esc(ci['title'])} · Framework: {esc(ci['framework'])}
+{esc(vr['title'])} · Authority: {esc(vr['authority'])} · Issued: {esc(vr['dateIssued'])} · Scope: {esc(vr['scope'])}
+Regulator-observable simulations validating the entire stack end-to-end: institutional escalation, systemic supervisory coordination, frontier-compute kill-switch, treaty-level crisis response, policy-as-code chaos, and adversarial co-evolution.
+ {render_dict_list(DATA['simulations'], [("id","ID"),("layer","Layer"),("name","Simulation"),("objective","Objective"),("kpis","KPIs"),("passCriteria","Pass Criteria")])} +JSON Schema — {esc(schema.get('$schema','draft'))}
+{esc(pretty)}
+Authoritative JSON Schemas for evidence manifests, compute-register entries, harmonized supervisory reports, supervisory replay requests, and GC activation records.
+{esc(code)}
+Production-oriented reference implementations covering OPA/Rego policy-as-code (Annex IV + fairness), kill-switch procedure, evidence manifest, harmonized report, and compute-register entry.
+{esc(path)}All endpoints return JSON (except /executive-summary which is text/plain). Every layer, artefact, policy, gate, bundle, scenario, and simulation is individually addressable.
| Method | Path | Purpose |
|---|
End-to-end governance reference implementation for Global Bank plc — Retail Credit Risk Scoring Engine v4.2, a Tier-1 EU AI Act high-risk credit-risk scoring AI at Global Bank plc. Spans six layers: Institutional (SR 11-7 / ISO 42001 / Annex IV) → Systemic (PRA / FCA / OCC / ICAAP) → Frontier Compute (custody, kill-switch) → Geopolitical Treaty (GAGCOT · GC1-GC7) → Autonomous Mesh (OPA/Rego · CI/CD · cryptographic evidence) → Adversarial Co-Evolution (red-team · threat intel · kill-chain).
+ +WP-032 operationalises a six-layer civilizational AI governance blueprint, grounded in a single, fully instantiated reference system: CRS-UUID-001, a Tier-1 retail credit-risk scoring engine at Global Bank plc. Every artefact is regulator-ready and cross-mapped to EU AI Act (including Annex IV), SR 11-7, Basel III/ICAAP, ISO/IEC 42001, GDPR, and FCRA/ECOA — with treaty-level overlays under the Global AI Governance & Compute Oversight Treaty Charter (GC1-GC7). The six layers span institutional MRM, sectoral supervision, frontier-compute attestation, geopolitical treaty alignment, an autonomous governance mesh (OPA/Rego + CI/CD + runtime), and adversarial co-evolution. Deliverables include a full Annex IV dossier, 12-tab audit pack, independent validation report, capital-impact assessment, AIMS evidence bundle, nine cryptographic evidence manifests (Merkle-anchored, post-quantum-ready), 12 OPA/Rego policies with 14 CI/CD gates, a supervisory replay kit, eight harmonized global supervisory reports, 13 multi-layer simulations (including GC1-GC7), and a Treaty Authority Implementation Charter (G-AGCOTA). The blueprint converts abstract frontier-AI governance into a board-defensible, prudential-supervisor-defensible, treaty-defensible operating reality.
+Three-lines-of-defence MRM with SR 11-7 / SS1/23 alignment, ISO/IEC 42001 AIMS lifecycle, EU AI Act Annex IV technical documentation, and conduct controls under FCRA/ECOA/GDPR/Consumer Duty.
+ +| Committee | Cadence | Chair | Quorum | CRS Agenda |
|---|---|---|---|---|
| Model Risk Committee (MRC) | Monthly | CRO | 5 | Standing agenda item + quarterly deep-dive |
| AI & Data Ethics Committee | Monthly | CAIO | 4 | Fairness KRIs + adverse-action review |
| Board Risk Committee | Quarterly | NED | 4 | Tier-1 model dashboard + issues log |
| Conduct & Customer Committee | Monthly | Chief Customer Officer | 5 | Appeal rates, adverse-action disputes, Consumer Duty outcomes |
| Activity | R | A | C | I |
|---|---|---|---|---|
| Model approval (initial + material change) | Model Developer | CMRO | CAIO, CCO, DPO | Board Risk |
| Annex IV technical documentation upkeep | Model Developer | CMRO | Legal, DPO | Notified Body |
| Independent validation (SR 11-7 IV) | IMV | Head IMV | Developer | MRC, External auditor |
| Fairness / disparate-impact testing | Model Fairness Lead | CAIO | Legal, CCO, DPO | CFPB/FCA liaison |
| DPIA + Art. 22 safeguards | DPO | DPO | Legal, CISO | ICO |
| Capital-impact assessment (ICAAP) | Head Capital Mgmt | CFO | CMRO, Treasurer | PRA |
| Post-market monitoring (Art. 60 EU AI Act) | MLOps Lead | CAIO | CMRO | Notified Body |
| Serious incident reporting (Art. 73) | CISO-Delegate | CAIO | Legal, DPO | Market Surveillance Authority |
| Stage | CRS Artefacts |
|---|---|
| A.2 Plan | • AI policy • AI objectives • CRS system-of-record charter |
| A.3 Do-Design | • Data sheet for CRS training corpus • Model card v4.2 • Intended-use statement • Risk taxonomy mapping |
| A.4 Do-Develop | • Feature store lineage (312 features) • Reproducible training pipeline • Hyperparameter audit log • Bias pre-mitigation report |
| A.5 Verify | • Back-test report (PSI, AUC, KS) • Fairness report (4/5 rule, demographic parity, equalised odds) • Robustness report (covariate shift, adversarial perturbation) |
| A.6 Deploy | • Change-advisory board (CAB) minutes • Go-live checklist • Rollback plan • Kill-switch test evidence |
| A.7 Operate | • Daily KRI dashboard • Monthly PSI drift report • Quarterly IMV challenge report • Adverse-action MI |
| A.8 Monitor | • Post-market monitoring plan (Art. 60) • Incident register • Customer complaints root-cause |
| A.9 Improve | • Corrective-action register • Retraining decision log • Sunset/replacement plan |
| A.10 Retire | • Decommissioning runbook • Data-retention schedule • Post-mortem report |
| SR 11-7 | CRS Control | Owner |
|---|---|---|
| III.A Development | Conceptual soundness review; feature-engineering documentation; developer peer review | Head Credit Analytics |
| III.B Implementation | Code freeze + SAST/DAST + reproducibility attestation; data-pipeline integrity; UAT sign-off | Head MLOps |
| III.C Use | Business-user training; override policy; outcome-analysis loop | Head Credit Ops |
| IV Validation | IMV annual full revalidation + quarterly ongoing monitoring; effective challenge log; open-issue MRIA tracking | Head IMV |
| V Governance | Model inventory entry (active), tier assignment review, MRC minutes, Board Risk reporting, independent audit | CMRO |
| Key | Value |
|---|---|
| adverseActionNotice | Automated generation within 30 days; top-4 SHAP reason codes translated to plain-English |
| consumerDisputeFlow | Model-level and case-level dispute routes; SLA 30 days; quarterly dispute-outcome MI |
| accuracyObligation | §1681e(b) — monthly bureau-data reconciliation; exception report to Board |
| Key | Value |
|---|---|
| prohibitedBases | ["race", "colour", "religion", "national origin", "sex", "marital status", "age (if capable of contracting)", "receipt of public assistance", "good-faith exercise of CCPA rights"] |
| disparateImpactTesting | Quarterly 4/5 rule + logistic regression residual analysis by protected class proxy |
| remediationProtocol | If 4/5 rule fails → 90-day remediation plan → MRC escalation → customer remediation if confirmed |
| Key | Value |
|---|---|
| safeguards | ["Right to human intervention (appeal within 30 days)", "Right to obtain explanation", "Right to contest decision"] |
| dpiaRef | DPIA-CRS-2026-02 |
| dpoSignOff | 2026-02-14 |
| lawfulBasis | Art. 6(1)(b) contract performance + Art. 6(1)(f) legitimate interest (balancing test documented) |
| Key | Value |
|---|---|
| foreseeableHarm | Monitored via: (i) appeal overturn rate, (ii) complaint-root-cause analysis, (iii) vulnerable-customer outcomes MI, (iv) affordability distress indicators |
| outcomesMonitoring | ["Price & value", "Products & services", "Consumer understanding", "Consumer support"] |
| KRI | Threshold | Current | Status |
|---|---|---|---|
| Model AUC (out-of-time) | ≥0.78 | 0.812 | GREEN |
| Population Stability Index (PSI) | ≤0.10 | 0.067 | GREEN |
| 4/5 rule — any protected class | ≥0.80 | 0.84 | GREEN |
| Adverse-action dispute overturn rate | ≤8% | 0.041 | GREEN |
| Human override rate (<£25k tier) | 0.5-3% | 0.019 | GREEN |
| Vulnerable-customer outcome gap | ≤2pp | 0.012 | GREEN |
| Incident count (Art. 73 eligible) | 0 | 0 | GREEN |
| Open IMV findings (high) | 0 | 0 | GREEN |
PRA / FCA / OCC / Fed / ECB coordination for Tier-1 AI models, ICAAP Pillar-2 capital impact, supervisory colleges, cross-border recognition, and sector-wide stress testing.
+ +| Authority | Jurisdiction | Primary Instrument | Cadence |
|---|---|---|---|
| PRA (Bank of England) | UK | SS1/23 model risk management | Quarterly |
| FCA | UK | Consumer Duty + PS23/4 AI | Semi-annual |
| OCC | US | Bulletin 2011-12 + 2021-39 | Quarterly |
| Federal Reserve | US | SR 11-7 | Quarterly |
| ECB SSM | Euro area | TRIM + SREP | Annual + JST dialogue |
| CFPB | US | Circulars 2022-03 & 2023-03 | Event-driven |
| ICO | UK | GDPR + UK DPA | Annual + incident |
| Key | Value |
|---|---|
| baseline2025 | £42m RWA add-on |
| 2026PostWP032 | £26m RWA add-on (−38% as assurance depth rose) |
| driverOfReduction | IMV effective-challenge evidence + ISO 42001 certification + Annex IV dossier completeness |
| Key | Value |
|---|---|
| directRwa | £3.2bn (unsecured retail portfolio PoD-driven) |
| provisioningIfrs9 | £420m LLP influenced by CRS output |
| overlayHeld | £85m management overlay for model uncertainty |
| Scenario | CRS Sensitivity | Capital Impact | Commentary |
|---|---|---|---|
| Severe adverse 2026 | PoD up-shift 24% in recession lag-1 | £180m CET1 absorption | Within Pillar-2 buffer |
| Climate transition (disorderly) | Geographic sector drift; PSI up to 0.18 | £95m | Early-warning trigger at PSI 0.12 |
| Geopolitical shock (sanctions) | Open-banking data-feed loss in 3 markets | £40m | Fallback scorecard activates |
| AI-specific (adversarial data-poisoning) | AUC −6pp if undetected for 30 days | £120m | Triggers GC4 treaty protocol |
| ID | Report | Audience | Frequency | Format |
|---|---|---|---|---|
| HSR-01 | CRS Quarterly Supervisory Summary | PRA/OCC/Fed | Quarterly | PDF + machine-readable JSON |
| HSR-02 | Annex IV Conformity Attestation | Notified Body | Annual | PDF + XML |
| HSR-03 | ISO/IEC 42001 Surveillance Package | Cert Body | Annual | |
| HSR-04 | ICAAP Model-Risk Pillar-2 Report (CRS section) | PRA | Annual | PDF + XBRL |
| HSR-05 | Fairness & Consumer Duty Outcomes Report | FCA / CFPB | Semi-annual | |
| HSR-06 | GDPR Art. 30 ROPA + DPIA Appendix | ICO | Annual | |
| HSR-07 | Art. 73 Serious Incident Report template (0 YTD) | Market Surveillance Authority | Event-driven | JSON + PDF |
| HSR-08 | Treaty Quarterly Attestation (GAGCOT T-01) | G-AGCOTA | Quarterly | Signed JSON-LD + PDF |
Reproduce any individual decision or aggregate statistic under supervisory examination
+Even though CRS-UUID-001 is not a frontier model by scale, the blueprint instantiates the frontier-compute governance controls that will apply to the bank's larger AI systems (FraudNet-L, MarketCopilot) and demonstrates cross-model integration under GAGCOT compute-oversight rules.
+ +| Key | Value |
|---|---|
| modelId | CRS-UUID-001 |
| trainingRunId | tr-crs-20260315-a1b2 |
| flopsTotal | 4.2e+18 |
| startedAt | 2026-03-15T09:12:00Z |
| endedAt | 2026-03-15T15:48:00Z |
| gpuHours | 96 |
| datacentreLocation | GB-LND |
| providerAccount | globalbank-aiplatform-prod |
| weightsHash | sha3-256:9f3a…c217 |
| evidenceBundle | EB-002 |
| frontierTrigger | False |
| frontierThreshold_flops | 1e+25 |
| Pattern | Target SLA | CRS Implementation |
|---|---|---|
| Runtime inference disable | ≤60s | Feature-flag kill-switch in API gateway; tested monthly; last test 2026-04-05 PASS (47s) |
| Model rollback to v4.1 | ≤15m | Blue-green deployment; automated traffic shift; last drill 2026-03-22 PASS (11m) |
| Weight custody freeze | ≤30m | HSM-based weight-release revocation; dual-control; last drill 2026-02-18 PASS (22m) |
| Key | Value |
|---|---|
| routineShutdown | ["Head MLOps", "CMRO"] |
| emergencyShutdown | ["CAIO", "CISO", "CRO (any 1 of 3)"] |
| regulatorMandated | ["PRA / FCA / OCC / Fed / ECB (direct to CEO)"] |
| treatyMandated | ["G-AGCOTA Executive Secretary (under GC4-GC7 scenarios)"] |
| Key | Value |
|---|---|
| model | Dual-control HSM with n-of-m (3-of-5) key escrow across geographically separated custodians |
| custodians | ["CISO (primary)", "CTO (secondary)", "External trustee (LawFirm A)", "External trustee (LawFirm B)", "Supervisory escrow (PRA-appointed, sealed)"] |
| rotation | Quarterly key rotation; annual full re-attestation |
| pqReady | Post-quantum signatures (Dilithium-5) layered over ECDSA during transition |
| Key | Value |
|---|---|
| mechanism | SEV-SNP / Intel TDX confidential-VM attestation + CUDA-runtime measured boot |
| verifier | Internal attestation service (ATLAS) cross-signed by cloud provider attestation APIs |
| frequency | Per training run + per 1000 inferences in confidential-inference mode |
| crsUsage | Training attested; inference runs on standard (non-confidential) infra as CRS does not process regulated frontier-sensitive data |
Treaty-level overlay for CRS-UUID-001 via GAGCOT (Global AI Governance & Compute Oversight Treaty Charter). CRS is a signatory-institution registered high-impact system subject to GC1-GC7 protocols.
+ +| Art. | Title | Essence |
|---|---|---|
| Art. 1 | Object & Purpose | Preserve civilizational integrity of AI-dependent critical services; harmonize model-risk supervision |
| Art. 2 | Scope & Definitions | Defines frontier compute, systemic AI, high-impact AI, signatory institution |
| Art. 3 | Compute Transparency | ≥1e25 FLOPs pre-notification; quarterly compute-register attestations |
| Art. 4 | Safety Case Obligations | Frontier & systemic models must maintain current safety cases; independent red-team evidence |
| Art. 5 | Kill-Switch & Custody | HSM custody + n-of-m key escrow + ≤60s inference kill-switch for high-impact systems |
| Art. 6 | Evidence Custody & Replay | Tamper-evident evidence bundles; supervisory replay ≤72h |
| Art. 7 | Mutual Recognition | Equivalence certificates for supervisory regimes meeting baseline |
| Art. 8 | Crisis Protocols (GC1-GC7) | Activation thresholds, decision rights, MTTR targets |
| Art. 9 | Adversarial Co-Evolution | Shared threat intel; coordinated red-team; common kill-chain taxonomy |
| Art. 10 | Compliance Review | Annual peer review; public compliance index (by signatory) |
| Art. 11 | Dispute Resolution | Panel arbitration; sanction escalation ladder; sunset of non-compliant signatories |
| Art. 12 | Amendment & Sunset | 2/3 majority amendment; 10-year sunset-review clause |
| Key | Value |
|---|---|
| registrationId | GAGCOT-INST-CRS-UUID-001 |
| tier | Signatory-Institution high-impact (not frontier) |
Trigger: Emergence of >1e25 FLOPs model with disclosed autonomous-agent capability above evaluated safety envelope
+CRS relevance: Indirect — triggers bank-wide AI capability reassessment; CRS itself unaffected
+MTTR: 72h emergency action; 14d resolution
+Trigger: ≥3 cross-border banks report coordinated 4/5-rule failures on retail credit AI systems within 30-day window
+CRS relevance: Direct — CRS fairness metrics become sentinel indicators; harmonized supervisory college convened
+MTTR: 30d diagnosis; 90d remediation
+Trigger: Loss of >40% accessible training compute capacity in OECD due to geopolitical event
+CRS relevance: Indirect — triggers fallback scorecard activation for CRS retraining
+MTTR: 60d capacity restoration; 180d full normalisation
+Trigger: Detection of coordinated data-poisoning affecting ≥2 G-SIFI credit AI systems
+CRS relevance: Direct — CRS is a canonical target; kill-switch rehearsal becomes live protocol
+MTTR: ≤60s kill-switch; 30d forensic; 90d trust restoration
+Trigger: Exfiltration attempt or sandbox escape by an AI agent at any signatory institution
+CRS relevance: Low (CRS is non-agentic) — but blueprint retains the protocol for consistency and agent-era readiness
+MTTR: 15m notification; 24h audit; 30d remediation
+Trigger: Confirmed exfiltration of weights for any treaty-registered model
+CRS relevance: Direct — CRS weights are HSM-custody; breach triggers GC6 response
+MTTR: 24h revocation; 14d rotation; 90d supervisory conclusion
+Trigger: Signatory state withdrawal or coordinated attack on treaty infrastructure
+CRS relevance: Indirect — invokes governance continuity codex; CRS governance continues under national regulators
+MTTR: Continuous — no service interruption permitted
+CRS-UUID-001 Adversarial Data-Poisoning Response Runbook
+| Phase | Actions |
|---|---|
| Detect | • PSI >0.12 triggers investigation • Feature-distribution anomaly detector alerts • Shadow-model divergence >3σ |
| Confirm | • IMV re-runs back-test with immutable snapshot • Open-banking-data provider cross-check • Threat-intel correlation via treaty feed |
| Contain | • Kill-switch invocation (≤60s) • Rollback to v4.1 • HSM key freeze • Customer communications hold |
| Notify | • Art. 73 report to PRA/MSA within 2h • GAGCOT notification within 15m • Board Risk flash-call |
| Remediate | • Data-source recertification • Retraining from clean snapshot • Peer-bank coordinated response • Supervisory college session |
| Review | • Root-cause (10 working days) • Post-market-monitoring update • Lessons-learned into treaty library • Public supervisory disclosure |
Treaty Authority Implementation Charter for G-AGCOTA
+| Pillar | Function |
|---|---|
| P1 · Secretariat | 24×7 Ops, intake, triage, escalation to crisis protocols |
| P2 · Compute Observatory | Ingest compute-register attestations; anomaly detection; quarterly public report |
| P3 · Evidence Vault | Merkle-DAG evidence receipts; supervisory replay service |
| P4 · Peer Review Panel | Annual signatory review; publish compliance index |
| P5 · Crisis Response | GC1-GC7 orchestration; cross-jurisdiction deconfliction |
| P6 · Standards & Harmonization | Publish evidence & report schemas; align ISO/NIST/ENISA mappings |
| KPI | Target | Measure |
|---|---|---|
| Compute-register attestation compliance | ≥98% | % signatories current in quarter |
| GC1-GC7 activation MTTR | Per Art. 8 | Rolling-12m median |
| Replay service SLA | ≤72h | Monthly 95th percentile |
| Peer-review coverage | 100% | Annual signatory coverage |
OPA/Rego policies codify institutional, systemic, and treaty obligations, executing as deterministic gates across the CRS CI/CD pipeline and runtime. All decisions emit signed evidence artefacts that roll up into nine Merkle-anchored evidence bundles, producing a continuously-provable compliance posture.
+ +| Key | Value |
|---|---|
| controlPlane | OPA servers (Rego bundles) distributed across CI agents, K8s admission, API gateway, and feature-store |
| dataPlane | Signed decision logs → streaming pipeline → evidence-bundle writer → Merkle-DAG appender → WORM vault |
| observability | ["Policy decision latency p99 <15ms", "Bundle-drift alerting", "Policy-coverage dashboard per CRS change"] |
| ID | Package | Title | Enforces | Decision |
|---|---|---|---|---|
| P-001 | crs.conformity | Annex IV completeness gate | All 9 Annex IV sections present + Merkle-anchored | deny on missing/invalid section |
| P-002 | crs.fairness | 4/5 rule fairness gate | No protected class below 0.80 disparate-impact ratio | deny deploy; mandate remediation plan |
| P-003 | crs.drift | PSI drift guard | PSI ≤0.10 rolling 30d; halt auto-retrain if >0.25 | alert MRC; block auto-retrain |
| P-004 | crs.fcra | Adverse-action notice coverage | 100% of declines have top-4 reason codes + notice generated | deny prod deploy if <100% |
| P-005 | crs.gdpr | Art. 22 safeguards | Appeal route active + DPIA current + DPO sign-off ≤12m | deny if safeguards missing |
| P-006 | crs.killswitch | Kill-switch test freshness | All 3 patterns tested within 35 days | block change freeze-exemption |
| P-007 | crs.imv | IMV independence | Reviewer ≠ developer; independence attestation current | deny model approval |
| P-008 | crs.evidence | Evidence bundle integrity | Signed Merkle root verified for EB-001..EB-009 | deny release |
| P-009 | crs.compute | Compute-register entry | Training run has register entry + attestation within 7d | alert; block subsequent runs after 30d grace |
| P-010 | crs.treaty | GAGCOT T-01 attestation currency | Quarterly attestation submitted and signed | block non-urgent deploys |
| P-011 | crs.incident | Art. 73 incident SLA | If incident flagged, notification dispatch ≤2h | escalate to CAIO on SLA breach |
| P-012 | crs.consumerduty | Consumer Duty outcomes gate | Vulnerable-customer outcome gap ≤2pp rolling 90d | trigger remediation plan; block promo pricing |
| Gate | Stage | Policy | Effect |
|---|---|---|---|
| G-01 | Pre-commit | P-007 | Block commits from developer equal to designated IMV reviewer |
| G-02 | Pre-commit | SAST + license | Block on critical CVEs or incompatible OSS licenses |
| G-03 | Build | P-008 | Verify evidence-bundle signatures match expected Merkle roots |
| G-04 | Build | Reproducibility | Byte-identical build across two clean agents required |
| G-05 | Test | P-002 | Block deploy if fairness tests fail any protected class |
| G-06 | Test | P-003 | Block deploy if holdout PSI >0.10 |
| G-07 | Test | P-006 | Block deploy if kill-switch tests stale |
| G-08 | Pre-deploy | P-001 | Block release if Annex IV sections not current |
| G-09 | Pre-deploy | P-005 | Block release if DPO sign-off expired |
| G-10 | Pre-deploy | P-009 | Block release if compute-register entry missing |
| G-11 | Pre-deploy | P-010 | Block release if GAGCOT attestation overdue |
| G-12 | Runtime | P-004 | Runtime telemetry: alert if adverse-action notice coverage <100% |
| G-13 | Runtime | P-011 | Incident-dispatch SLA enforcement; pager escalation |
| G-14 | Runtime | P-012 | Consumer-duty KRI guard; auto-open corrective-action ticket |
| ID | Label | Contents | Merkle Root | Retention |
|---|---|---|---|---|
| EB-001 | General & Identification | • Model card v4.2 • Provider/Deployer registration • SW/HW stack manifest | sha3-256:4d1a…91ce | 10 years post-decommission |
| EB-002 | Architecture & Training | • Architecture diagram • Feature lineage • Training pipeline Docker digest • Weights hash | sha3-256:a20f…75bc | 10 years |
| EB-003 | Oversight & Control | • Human-oversight protocol • Override logs schema • Kill-switch test reports | sha3-256:9e8b…22fa | 10 years |
| EB-004 | Risk Management | • ISO 23894 risk register • Treatment plans • Residual-risk sign-off | sha3-256:11c5…d034 | 10 years |
| EB-005 | Data Governance | • Data sheet • Provenance receipts • GDPR Art. 10 disclosures • Bias detection report | sha3-256:6fab…4e21 | 10 years |
| EB-006 | Lifecycle Changes | • Change log • CAB records • Impact assessments • Re-validation outcomes | sha3-256:23dd…87a9 | 10 years |
| EB-007 | Standards Applied | • ISO/IEC 42001 cert • ISO 23894 mapping • ISO 25059 quality eval | sha3-256:bc70…1fe4 | 10 years |
| EB-008 | Conformity & Declaration | • EU DoC (signed) • Conformity route Art. 43 • Notified-body correspondence | sha3-256:5a44…c309 | 10 years |
| EB-009 | Post-Market & Monitoring | • PMM plan • Drift reports • Incident register • Art. 73 filings (if any) | sha3-256:ff82…7b56 | 10 years |
{
+ "$schema": "https://json-schema.org/draft/2020-12/schema",
+ "$id": "https://globalbank.example/schemas/crs-evidence-manifest.json",
+ "type": "object",
+ "required": [
+ "bundleId",
+ "label",
+ "merkleRoot",
+ "signature",
+ "contents",
+ "generatedAt",
+ "retentionUntil"
+ ],
+ "properties": {
+ "bundleId": {
+ "type": "string",
+ "pattern": "^EB-[0-9]{3}$"
+ },
+ "label": {
+ "type": "string"
+ },
+ "merkleRoot": {
+ "type": "string",
+ "pattern": "^sha3-256:[0-9a-f\u2026]+$"
+ },
+ "signature": {
+ "type": "object",
+ "required": [
+ "alg",
+ "value",
+ "keyId"
+ ],
+ "properties": {
+ "alg": {
+ "enum": [
+ "Ed25519",
+ "Dilithium5",
+ "Hybrid-Ed25519+Dilithium5"
+ ]
+ },
+ "value": {
+ "type": "string"
+ },
+ "keyId": {
+ "type": "string"
+ }
+ }
+ },
+ "contents": {
+ "type": "array",
+ "items": {
+ "type": "object",
+ "required": [
+ "name",
+ "hash"
+ ]
+ }
+ },
+ "generatedAt": {
+ "type": "string",
+ "format": "date-time"
+ },
+ "retentionUntil": {
+ "type": "string",
+ "format": "date"
+ },
+ "previousRoot": {
+ "type": "string"
+ }
+ }
+}
+ Continuous adversarial testing and threat-intel integration keep CRS-UUID-001 resilient against evolving attacks. Shared kill-chain taxonomy aligns with GAGCOT Art. 9 and peer institutions.
+ +| Key | Value |
|---|---|
| critical | 0 |
| high | 2 |
| medium | 7 |
| low | 14 |
| Phase | CRS Example |
|---|---|
| Reconnaissance | Scrape public model-card details; open-banking API probe |
| Initial Access | Compromised OSS dependency; vendor data-feed manipulation |
| Persistence | Poisoned feature in upstream bureau feed |
| Privilege Escalation | Abuse of override-admin role |
| Defence Evasion | Fairness-metric gaming (slow drift below detection threshold) |
| Impact | Systematic mis-scoring producing conduct harm or capital loss |
Engine: SIEM + OpenCTI + ATLAS tagger; automated case opening into GRC on high-confidence matches
+Sharing Protocol: TLP:AMBER for intra-college; TLP:GREEN+ for treaty-wide; TLP:RED only when active attack
+| Metric | Target | Current |
|---|---|---|
| Mean-time-to-detect (MTTD) poisoning | ≤30 days | 18 days |
| Mean-time-to-contain (MTTC) | ≤60 minutes | 47 minutes |
| Red-team coverage vs kill-chain phases | 100% annually | 100% YTD |
| Treaty-feed IOC actioning SLA | ≤24h | 11h median |
EU AI Act Annex IV — Technical Documentation · Document ID CRS-UUID-001-ANNEXIV-v4.2 · ≈640 pages; auto-generated from live evidence store; Merkle-anchored per section.
| Section | CRS Content | Evidence Bundle |
|---|---|---|
| 1. General description | Model name/version, intended purpose (retail PoD scoring EEA + GB), provider & deployer identification, SW/HW stack, release history | EB-001 |
| 2. Detailed description | Architecture (XGBoost 2.1 + monotonic calibrator + MLP explainer), 312-feature list with provenance, training methodology, optimisation | EB-002 |
| 3. Monitoring, functioning, control | Human-oversight protocol, £25k auto-referral threshold, override logging, real-time drift monitoring, kill-switch procedure | EB-003 |
| 4. Risk management system | ISO 23894 risk register (47 risks), treatment plans, residual-risk acceptance by CRO, link to SR 11-7 model-risk register | EB-004 |
| 5. Data & data governance | Training/validation/test datasets, 14-jurisdiction provenance, bias-detection report, GDPR Art. 10 disclosures, data-minimisation proof | EB-005 |
| 6. Changes through lifecycle | Change log since v3.0 (2023), CAB records, impact assessments, re-validation outcomes | EB-006 |
| 7. Standards applied | ISO/IEC 42001, ISO/IEC 23053, ISO/IEC 23894, ISO/IEC 25059, SR 11-7 internal | EB-007 |
| 8. EU declaration of conformity | Signed by authorised representative; conformity-assessment route Art. 43(2) internal control + notified body for post-market monitoring | EB-008 |
| 9. Post-market monitoring plan | Drift KPIs, fairness KPIs, complaint-trend triggers, serious-incident definition & reporting SLAs, annual re-assessment | EB-009 |
Capital Impact Assessment — CRS-UUID-001 (Pillar-2 Model Risk) · Framework: Basel III · PRA SS1/23 · ICAAP Pillar-2
+| Key | Value |
|---|---|
| directRwaInfluence_bn | 3.2 |
| ifrs9LlpInfluence_m | 420 |
| pillar2Addon_m_2025 | 42 |
| pillar2Addon_m_2026 | 26 |
| managementOverlay_m | 85 |
| Key | Value |
|---|---|
| priorScore | 2.1 |
| postWp032Score | 3.7 |
| scale | 0-4 (per PRA SS1/23 scoring rubric) |
| driversAdded | ["ISO 42001 certification", "Annex IV completeness", "Independent red-team", "Cryptographic evidence bundles", "Treaty attestation"] |
| Scenario | CRS Sensitivity | Capital Impact | Commentary |
|---|---|---|---|
| Severe adverse 2026 | PoD up-shift 24% in recession lag-1 | £180m CET1 absorption | Within Pillar-2 buffer |
| Climate transition (disorderly) | Geographic sector drift; PSI up to 0.18 | £95m | Early-warning trigger at PSI 0.12 |
| Geopolitical shock (sanctions) | Open-banking data-feed loss in 3 markets | £40m | Fallback scorecard activates |
| AI-specific (adversarial data-poisoning) | AUC −6pp if undetected for 30 days | £120m | Triggers GC4 treaty protocol |
Independent Model Validation — CRS-UUID-001 v4.2 · Authority: Group Head of IMV (reports to CRO) · Issued: 2026-04-12 · Scope: Full revalidation post v4.2 release
+| Key | Value |
|---|---|
| critical | 0 |
| high | 0 |
| medium | 3 |
| low | 7 |
Regulator-observable simulations validating the entire stack end-to-end: institutional escalation, systemic supervisory coordination, frontier-compute kill-switch, treaty-level crisis response, policy-as-code chaos, and adversarial co-evolution.
+| ID | Layer | Simulation | Objective | KPIs | Pass Criteria |
|---|---|---|---|---|---|
| SIM-L1 | Institutional | MRC Escalation Drill | Validate that a fairness KPI breach escalates through 2LoD to Board Risk within SLA | • Detection →1h • 2LoD ack →4h • MRC convene →24h • Board brief →72h | All KPIs met; evidence bundle EB-004 updated; Rego P-002 fires |
| SIM-L2 | Systemic | Supervisory College Stress Run | Coordinated supervisory response under cross-border deterioration | • HSR-01 flash issued ≤48h • College session ≤5 working days • Harmonised remediation plan ≤30d | All HSRs consistent; capital-impact assessment produced; Pillar-2 add-on revised |
| SIM-L3 | Frontier Compute | Kill-Switch + Weight-Custody Drill | End-to-end kill-switch under adversarial trigger with weight-custody revocation | • Inference disable ≤60s • Rollback ≤15m • HSM freeze ≤30m | Actuals within SLA; Rego P-006 confirms test freshness; post-kill protocol executed |
| SIM-L4 | Geopolitical Treaty | GC4 Treaty Table-Top | Multi-signatory coordinated response to poisoning campaign | • Notification ≤15m • Evidence shared under safe-harbour ≤24h • Joint communique ≤72h | All signatories synchronised; public communique drafted; lessons logged to Art. 9 library |
| SIM-L5 | Autonomous Mesh | Policy-as-Code Chaos Test | Resilience of OPA/Rego mesh under partial outage | • All violating deploys blocked • Policy decision latency p99 <50ms in degraded state • Alerting fires within 60s | Zero policy-bypass; evidence bundle EB-008 integrity preserved |
| SIM-L6 | Adversarial Co-Evolution | Full-Scope Red-Team Campaign | Discover residual weaknesses across kill-chain | • Phase coverage 100% • Critical findings 0 • All findings remediated ≤90d | Campaign report delivered; Rego policies refreshed; purple-team loop closed |
| SIM-GC1 | Geopolitical Treaty | GC1 Capability-Shock Rehearsal | G-AGCOTA 48h convening drill | • Convene ≤48h • Response plan ≤14d | SLAs met |
| SIM-GC2 | Geopolitical Treaty | GC2 Fairness Divergence Rehearsal | Cross-bank fairness swap | • Data-share ≤24h • Joint RCA ≤30d | SLAs met |
| SIM-GC3 | Geopolitical Treaty | GC3 Compute-Supply Rehearsal | Continuity of training | • Fallback ≤7d • Normalisation ≤180d | SLAs met |
| SIM-GC4 | Geopolitical Treaty | GC4 Poisoning Campaign Rehearsal | Synchronised kill-switch | • Kill-switch ≤60s • Joint attrib ≤30d | SLAs met |
| SIM-GC5 | Geopolitical Treaty | GC5 Containment-Failure Rehearsal | Agent-era readiness | • Notify ≤15m • Audit ≤24h | SLAs met; blueprint consistency retained |
| SIM-GC6 | Geopolitical Treaty | GC6 Weight-Compromise Rehearsal | Custody revocation drill | • Revoke ≤24h • Rotate ≤14d | SLAs met |
| SIM-GC7 | Geopolitical Treaty | GC7 Continuity-of-Governance Rehearsal | Supervisory continuity | • No service gap • Bilateral MoU ≤30d | SLAs met |
Authoritative JSON Schemas for evidence manifests, compute-register entries, harmonized supervisory reports, supervisory replay requests, and GC activation records.
+JSON Schema — https://json-schema.org/draft/2020-12/schema
+{
+ "$schema": "https://json-schema.org/draft/2020-12/schema",
+ "$id": "https://globalbank.example/schemas/crs-evidence-manifest.json",
+ "type": "object",
+ "required": [
+ "bundleId",
+ "label",
+ "merkleRoot",
+ "signature",
+ "contents",
+ "generatedAt",
+ "retentionUntil"
+ ],
+ "properties": {
+ "bundleId": {
+ "type": "string",
+ "pattern": "^EB-[0-9]{3}$"
+ },
+ "label": {
+ "type": "string"
+ },
+ "merkleRoot": {
+ "type": "string",
+ "pattern": "^sha3-256:[0-9a-f…]+$"
+ },
+ "signature": {
+ "type": "object",
+ "required": [
+ "alg",
+ "value",
+ "keyId"
+ ],
+ "properties": {
+ "alg": {
+ "enum": [
+ "Ed25519",
+ "Dilithium5",
+ "Hybrid-Ed25519+Dilithium5"
+ ]
+ },
+ "value": {
+ "type": "string"
+ },
+ "keyId": {
+ "type": "string"
+ }
+ }
+ },
+ "contents": {
+ "type": "array",
+ "items": {
+ "type": "object",
+ "required": [
+ "name",
+ "hash"
+ ]
+ }
+ },
+ "generatedAt": {
+ "type": "string",
+ "format": "date-time"
+ },
+ "retentionUntil": {
+ "type": "string",
+ "format": "date"
+ },
+ "previousRoot": {
+ "type": "string"
+ }
+ }
+}
+JSON Schema — https://json-schema.org/draft/2020-12/schema
+{
+ "$schema": "https://json-schema.org/draft/2020-12/schema",
+ "$id": "https://gagcot.example/schemas/compute-register-entry.json",
+ "type": "object",
+ "required": [
+ "modelId",
+ "trainingRunId",
+ "flopsTotal",
+ "gpuHours",
+ "weightsHash",
+ "signature"
+ ],
+ "properties": {
+ "modelId": {
+ "type": "string"
+ },
+ "trainingRunId": {
+ "type": "string"
+ },
+ "flopsTotal": {
+ "type": "number",
+ "minimum": 0
+ },
+ "gpuHours": {
+ "type": "integer",
+ "minimum": 0
+ },
+ "datacentreLocation": {
+ "type": "string"
+ },
+ "weightsHash": {
+ "type": "string"
+ },
+ "evidenceBundle": {
+ "type": "string"
+ },
+ "signature": {
+ "type": "object"
+ }
+ }
+}
+JSON Schema — https://json-schema.org/draft/2020-12/schema
+{
+ "$schema": "https://json-schema.org/draft/2020-12/schema",
+ "$id": "https://gagcot.example/schemas/harmonized-supervisory-report.json",
+ "type": "object",
+ "required": [
+ "reportId",
+ "modelId",
+ "period",
+ "sections",
+ "signature"
+ ],
+ "properties": {
+ "reportId": {
+ "type": "string",
+ "pattern": "^HSR-[0-9]{2}$"
+ },
+ "modelId": {
+ "type": "string"
+ },
+ "period": {
+ "type": "string"
+ },
+ "sections": {
+ "type": "array"
+ },
+ "signature": {
+ "type": "object"
+ }
+ }
+}
+JSON Schema — https://json-schema.org/draft/2020-12/schema
+{
+ "$schema": "https://json-schema.org/draft/2020-12/schema",
+ "$id": "https://globalbank.example/schemas/supervisory-replay-request.json",
+ "type": "object",
+ "required": [
+ "requestId",
+ "supervisor",
+ "scope",
+ "slaHours"
+ ],
+ "properties": {
+ "requestId": {
+ "type": "string"
+ },
+ "supervisor": {
+ "type": "string"
+ },
+ "scope": {
+ "type": "object",
+ "required": [
+ "type"
+ ],
+ "properties": {
+ "type": {
+ "enum": [
+ "individualDecision",
+ "aggregateStat",
+ "fullBacktest"
+ ]
+ },
+ "decisionId": {
+ "type": "string"
+ },
+ "dateRange": {
+ "type": "object"
+ },
+ "cohort": {
+ "type": "object"
+ }
+ }
+ },
+ "slaHours": {
+ "type": "integer",
+ "minimum": 1,
+ "maximum": 168
+ }
+ }
+}
+JSON Schema — https://json-schema.org/draft/2020-12/schema
+{
+ "$schema": "https://json-schema.org/draft/2020-12/schema",
+ "$id": "https://gagcot.example/schemas/gc-activation-record.json",
+ "type": "object",
+ "required": [
+ "gcId",
+ "activatedAt",
+ "trigger",
+ "signatoriesNotified"
+ ],
+ "properties": {
+ "gcId": {
+ "enum": [
+ "GC1",
+ "GC2",
+ "GC3",
+ "GC4",
+ "GC5",
+ "GC6",
+ "GC7"
+ ]
+ },
+ "activatedAt": {
+ "type": "string",
+ "format": "date-time"
+ },
+ "trigger": {
+ "type": "string"
+ },
+ "signatoriesNotified": {
+ "type": "array",
+ "items": {
+ "type": "string"
+ }
+ },
+ "mttrActualHours": {
+ "type": "number"
+ },
+ "evidenceBundle": {
+ "type": "string"
+ }
+ }
+}
+Production-oriented reference implementations covering OPA/Rego policy-as-code (Annex IV + fairness), kill-switch procedure, evidence manifest, harmonized report, and compute-register entry.
+package crs.conformity
+
+# P-001 · Annex IV completeness gate
+# Denies CI/CD promotion if any Annex IV section is missing or has an invalid Merkle root.
+
+default allow = false
+
+required_sections := {"1","2","3","4","5","6","7","8","9"}
+
+present_sections := {s | s := input.annexIv.sections[_].section; startswith(s, _)}
+
+missing_sections := required_sections - {split(s, ".")[0] | s := input.annexIv.sections[_].section}
+
+merkle_invalid[s] {
+ some i
+ s := input.annexIv.sections[i].section
+ not regex.match(`^sha3-256:[0-9a-f]+$`, input.annexIv.sections[i].merkleRoot)
+}
+
+allow {
+ count(missing_sections) == 0
+ count(merkle_invalid) == 0
+}
+
+deny[msg] {
+ count(missing_sections) > 0
+ msg := sprintf("Annex IV sections missing: %v", [missing_sections])
+}
+
+deny[msg] {
+ count(merkle_invalid) > 0
+ msg := sprintf("Annex IV sections with invalid Merkle root: %v", [merkle_invalid])
+}
+
+package crs.fairness
+
+# P-002 · 4/5 rule fairness gate
+# Denies deploy if any protected class selection-rate ratio < 0.80.
+
+default allow = false
+
+violations[class] {
+ some class
+ ratio := input.fairness.selectionRateRatio[class]
+ ratio < 0.80
+}
+
+allow {
+ count(violations) == 0
+}
+
+deny[msg] {
+ count(violations) > 0
+ msg := sprintf("4/5 rule violated for classes: %v", [violations])
+}
+
+# CRS-UUID-001 Kill-Switch Procedure (operator-facing) +# Target SLAs: runtime disable ≤60s · rollback ≤15m · HSM freeze ≤30m +# Invocation authority: CAIO or CISO or CRO (any 1 of 3) for emergency + +set -euo pipefail + +# 1. Runtime inference disable (≤60s) +kubectl -n crs-prod set env deploy/crs-inference CRS_DISABLED=true +aws apigateway update-stage --rest-api-id $CRS_API --stage-name prod \ + --patch-operations op=replace,path=/variables/CRS_DISABLED,value=true + +# 2. Rollback to v4.1 (≤15m) +argocd app set crs-inference --revision v4.1.0 && argocd app sync crs-inference --prune + +# 3. HSM weight-custody freeze (≤30m) +hsm-cli revoke --key-alias crs-uuid-001-weights --reason "emergency-kill-switch" \ + --approvers $CISO_KEY,$CTO_KEY --quorum 2-of-5 + +# 4. Evidence bundle freeze +evidence-cli freeze --bundles EB-001..EB-009 --reason "kill-switch-invoked" \ + --anchor-to merkle-dag + +# 5. Notification fan-out +incident-cli fire --sev P1 \ + --notify pra,fca,occ,fed,ecb,ico,gagcot,board-risk,mrc \ + --art73-template crs-serious-incident.yaml + +echo "Kill-switch invoked at $(date -u +%FT%TZ) — post-kill protocol engaged." ++
{
+ "bundleId": "EB-005",
+ "label": "Data Governance",
+ "merkleRoot": "sha3-256:6fab4a77c1d9e8ba24517c0a9f3b81e2d76cf448e21a90b3fc77a8b014e2…4e21",
+ "signature": {
+ "alg": "Hybrid-Ed25519+Dilithium5",
+ "value": "base64:MIIBkz…QUFB",
+ "keyId": "gb-evidence-signer-2026-q2"
+ },
+ "contents": [
+ {"name": "data-sheet-v4.2.pdf", "hash": "sha3-256:1a…b2"},
+ {"name": "provenance-receipts.jsonl","hash": "sha3-256:2c…d4"},
+ {"name": "gdpr-art10-disclosures.md","hash": "sha3-256:3e…f6"},
+ {"name": "bias-detection-report.pdf","hash": "sha3-256:4f…18"}
+ ],
+ "generatedAt": "2026-04-22T08:00:00Z",
+ "retentionUntil": "2036-04-22",
+ "previousRoot": "sha3-256:5b…2a"
+}
+
+{
+ "reportId": "HSR-01",
+ "modelId": "CRS-UUID-001",
+ "period": "2026-Q1",
+ "sections": [
+ {"id": "1", "title": "Performance", "kpis": {"auc": 0.812, "psi": 0.067, "ks": 0.48}},
+ {"id": "2", "title": "Fairness", "kpis": {"fourFifths_min": 0.84, "demographicParityGap": 0.031}},
+ {"id": "3", "title": "Conduct", "kpis": {"appealOverturnRate": 0.041, "vulnerableGap_pp": 0.012}},
+ {"id": "4", "title": "Operational", "kpis": {"killSwitchTestPass": 1.0, "incidents_art73": 0}},
+ {"id": "5", "title": "Capital Impact","kpis": {"pillar2Addon_m": 26, "rwaInfluence_bn": 3.2}}
+ ],
+ "signature": {
+ "alg": "Ed25519",
+ "value": "base64:MCowBQYDK2Vw…",
+ "keyId": "gb-supervisor-signer-2026"
+ }
+}
+
+# CRS-UUID-001 — Compute Register Entry (YAML) +modelId: CRS-UUID-001 +trainingRunId: tr-crs-20260315-a1b2 +flopsTotal: 4.2e18 +gpuHours: 96 +datacentreLocation: GB-LND +providerAccount: globalbank-aiplatform-prod +startedAt: 2026-03-15T09:12:00Z +endedAt: 2026-03-15T15:48:00Z +weightsHash: sha3-256:9f3a00c1b2d30e11…c217 +evidenceBundle: EB-002 +attestation: + tee: SEV-SNP + verifier: atlas.globalbank.internal + nonce: 0x8b2a…f10c +frontierTrigger: false +signature: + alg: Dilithium5 + value: base64:MIIB…QUFB + keyId: gb-compute-signer-2026-q2 ++
All endpoints return JSON (except /executive-summary which is text/plain). Every layer, artefact, policy, gate, bundle, scenario, and simulation is individually addressable.
| Method | Path | Purpose |
|---|---|---|
| GET | /api/civ-ai-gov-6l | Full blueprint |
| GET | /api/civ-ai-gov-6l/meta | Metadata |
| GET | /api/civ-ai-gov-6l/summary | Aggregate counts |
| GET | /api/civ-ai-gov-6l/executive-summary | Executive summary (text/plain) |
| GET | /api/civ-ai-gov-6l/subject | Subject system (CRS-UUID-001) |
| GET | /api/civ-ai-gov-6l/layers | All 6 layers (summary) |
| GET | /api/civ-ai-gov-6l/l1 … l6 | Individual layer |
| GET | /api/civ-ai-gov-6l/l1/kris | L1 KRI dashboard |
| GET | /api/civ-ai-gov-6l/l1/annex-iv | Annex IV dossier |
| GET | /api/civ-ai-gov-6l/l1/sr11-7 | SR 11-7 mapping |
| GET | /api/civ-ai-gov-6l/l1/conduct | FCRA · ECOA · GDPR · Consumer Duty |
| GET | /api/civ-ai-gov-6l/l2/icaap | ICAAP capital impact |
| GET | /api/civ-ai-gov-6l/l2/college | Supervisory college |
| GET | /api/civ-ai-gov-6l/l2/hsr | Harmonized supervisory reports |
| GET | /api/civ-ai-gov-6l/l2/hsr/:id | Specific HSR (HSR-01..HSR-08) |
| GET | /api/civ-ai-gov-6l/l2/replay-kit | Supervisory replay kit |
| GET | /api/civ-ai-gov-6l/l3/compute-register | Compute register entry |
| GET | /api/civ-ai-gov-6l/l3/kill-switch | Kill-switch patterns |
| GET | /api/civ-ai-gov-6l/l3/weight-custody | HSM weight custody |
| GET | /api/civ-ai-gov-6l/l4/gagcot | GAGCOT treaty charter |
| GET | /api/civ-ai-gov-6l/l4/articles | 12 treaty articles |
| GET | /api/civ-ai-gov-6l/l4/articles/:id | Specific article |
| GET | /api/civ-ai-gov-6l/l4/implementation-charter | G-AGCOTA charter |
| GET | /api/civ-ai-gov-6l/l4/gc | GC1-GC7 scenarios |
| GET | /api/civ-ai-gov-6l/l4/gc/:id | Specific GC scenario |
| GET | /api/civ-ai-gov-6l/l4/gc4-runbook | GC4 runbook (CRS) |
| GET | /api/civ-ai-gov-6l/l5/opa-policies | 12 OPA/Rego policies |
| GET | /api/civ-ai-gov-6l/l5/opa-policies/:id | Specific policy (P-001..P-012) |
| GET | /api/civ-ai-gov-6l/l5/ci-cd-gates | 14 CI/CD gates |
| GET | /api/civ-ai-gov-6l/l5/evidence-bundles | 9 evidence bundles |
| GET | /api/civ-ai-gov-6l/l5/evidence-bundles/:id | Specific bundle (EB-001..EB-009) |
| GET | /api/civ-ai-gov-6l/l6/red-team | Red-team programme |
| GET | /api/civ-ai-gov-6l/l6/kill-chain | Kill-chain taxonomy |
| GET | /api/civ-ai-gov-6l/l6/threat-intel | Threat-intel integration |
| GET | /api/civ-ai-gov-6l/simulations | 13 multi-layer simulations |
| GET | /api/civ-ai-gov-6l/simulations/:id | Specific simulation |
| GET | /api/civ-ai-gov-6l/capital-impact | ICAAP Pillar-2 assessment |
| GET | /api/civ-ai-gov-6l/validation-report | IMV report |
| GET | /api/civ-ai-gov-6l/schemas | JSON schemas |
| GET | /api/civ-ai-gov-6l/schemas/:name | Specific schema |
| GET | /api/civ-ai-gov-6l/code-examples | Reference code examples |
| GET | /api/civ-ai-gov-6l/code-examples/:name | Specific code example |