The Attestor Generative and Agentic AI Assurance Standard turns a complex AI system into a single, defensible risk rating. Its defining feature is transparency: every rating is reproducible and traceable to specific components — never a black-box number.
Each AI system is mapped as a whole and every component is classified by its function — the reasoning model, retrieval, action tools, guardrails, human checkpoints, and controls. Governance follows function, so the same discipline applies whether a component is built in-house or bought from a vendor.
| Component | Role in the score |
|---|---|
| Orchestrator | The reasoning model — sets the base risk level. |
| Retrieval / RAG | Grounds the model in data — adds complexity and can raise data sensitivity. |
| Action tools | What the system can do in the world — drive autonomy and complexity. |
| Guardrails & rules | Bright-line and model-based limits — reduce risk when present and tested. |
| Human-in-the-loop | A human checkpoint — caps autonomy and earns credited oversight. |
| Monitoring, kill-switch, evidence vault | Detective and preventive controls — credited when operational. |
Components drive a structured score that captures the system’s inherent risk, its autonomy, and the quality of its controls:
| Input | What it captures |
|---|---|
| Base | The inherent risk of the system’s reasoning — from internal-only assistance to autonomous, consequential decisions. |
| Data sensitivity | The sensitivity of the data it can access — from anonymized to customer PII to material non-public information. |
| Complexity | The attack surface — how many tools and data sources the system connects to. |
| Autonomy | How far it can act without a human — read-only, human-gated, or fully autonomous execution. |
| Controls | Credited reductions for controls that are present and tested — rules, guardrails, human oversight, monitoring, kill-switches, and immutable evidence. |
Because the score is built this way, it is defensible. An institution — or its examiner — can see exactly why a system scored as it did, and exactly which control changes would move it. There is no arbitrary judgment to explain away.
The residual score maps to a tier that sets how often the system is validated and how it is reported — so oversight is proportionate to risk.
| Risk tier | Validation cadence | Reporting |
|---|---|---|
| Low | Annual | Annual summary |
| Medium | Bi-annual | Semi-annual status |
| High | Quarterly | Quarterly dashboard; CRO escalation |
| Critical | Monthly | Board Risk Committee; sign-off to operate |
| Unacceptable | Not deployable as designed | Redesign required before deployment |
The standard is built to satisfy the intent of SR 26-2 and to align with the NIST AI Risk Management Framework, so the output slots directly into an institution’s existing model risk governance.
| NIST AI RMF function | How the standard addresses it |
|---|---|
| GOVERN | Roles, review cadence, and sign-off thresholds tied to the risk tier. |
| MAP | System decomposition and component classification — context and categorization. |
| MEASURE | The residual-risk score and assembled-system testing — evaluation of trustworthiness. |
| MANAGE | Ongoing monitoring, material-change triggers, and tiered escalation and reporting. |
A short scoping conversation lets us decompose one of your systems, score it, and show you the evidence the standard produces.
Start a conversation