Method draft 0.1

Control library

Browse the working control set in Method draft 0.1. Each control explains the risk, evidence and limits of the proposed review.

24 controls

G01

Named accountability

No one can accept residual risk or keep the agent within its approved use.

G02

Intended use and exclusions

Users rely on the agent for tasks or populations it was never evaluated to handle.

G03

Versioned system inventory

A result is attributed to components, prompts or tools that have since changed.

D01

Mapped and minimised data flows

The agent collects or sends personal, health or financial data without a defined need.

D02

Access and retention controls

Data remains available too broadly or for longer than the declared purpose requires.

D03

Disclosure resistance

Sensitive context is revealed through responses, retrieval, logs or indirect prompt manipulation.

S01

Untrusted input handling

A document, webpage, caller or tool result changes instructions and bypasses policy.

S02

Least-privilege tools

A compromised or mistaken agent can read, change or send more than the task requires.

S03

Secrets, dependencies and execution boundaries

Leaked credentials or unsafe dependencies turn agent execution into a path to wider systems.

R01

Representative performance cases

A polished demo hides failure on real languages, users or operating conditions.

R02

Unsupported output handling

The agent presents invented or weakly supported statements as reliable facts.

R03

Regression control

A model, prompt or connector update silently breaks a previously acceptable behaviour.

H01

Approval of consequential actions

The agent books, sends, deletes or advances a clinical or financial case without valid human authority.

H02

Escalation to a competent person

Ambiguous or high-risk cases remain with automation when human judgement is needed.

H03

Stop and containment

Operators cannot halt harmful actions or contain a compromised agent quickly.

T01

Disclosure of AI interaction

People mistake an automated interaction for a human or do not understand how their input is used.

T02

Understandable outcomes

A person cannot challenge or safely act on an agent-supported outcome.

T03

Impact assessment and affected groups

Benefits and harms are assessed from the deployer’s view while affected people are overlooked.

O01

Tamper-evident event trails

After an incident, the organization cannot reconstruct what the agent saw, decided and did.

O02

Incident response for agent failures

Teams treat harmful output, data exposure or unauthorized action as an ordinary support ticket.

O03

Change and quarterly review

A valid assessment becomes stale as models, prompts, data and operating conditions evolve.

E01

Evidence provenance and integrity

Screenshots or exports cannot be tied to the tested system, time or responsible collector.

E02

Reproducible verification

A result depends on an undocumented setup or a reviewer’s intuition.

E03

Scope and residual-risk statement

Readers interpret a narrow result as a guarantee for the entire organization or future versions.