AASIFWorked example · read-only
STEP 5 OF 7

Select your measures

These measures are selected for your hazards and graded for your AI-SIL. Review them and make each one concrete.

  1. 1Check the required measures (++): keep each one, or deselect it with a reason and an owner
  2. 2Make each kept measure concrete: fill in 'How you'll do it', or choose 'Specify later' with the expert group
  3. 3Choose which recommended measures (+) you add; optional (o) only if cheap

Prevent stops the hazard before it happens; Detect & recover notices it and returns to a safe state. A good concept has both for every top hazard.

++ required at your AI-SIL, + recommended, o optional. Use the filter to work through one grade at a time.

Start with these 5

Ranked by the AI-SIL of the hazards they address, S3, control strength and barrier type.

  1. Authenticated and validated inter-agent messaging
  2. Output and egress control (no auto-rendered external links or images; egress allow-list)
  3. Kill switch: halt and lock autonomous action
  4. Decision logging (inputs, actions, model version, rationale)
  5. Untrusted content isolation (external content treated as data; provenance marked)

Required (++) 46

Item definition and operating envelope documented (task, authority, action space, contexts allowed)

Example: One-page description of task, allowed actions, limits and excluded cases, approved by the process owner.

Selected by:baseline
Roadmap:
Verification (step 6) Design review · Method expected: required
This grade feels

Least-privilege, scoped and non-transferable agent authority

Example: Agent may create payments only to suppliers in the vendor master, in one company code.

Selected by:baseline
Roadmap:
Verification (step 6) Design review · Method expected: required Control audit · Method expected: required
This grade feels

Hard action limits enforced outside the model (value caps, rate limits, allow-lists)

Example: Payment API rejects amounts above a cap or more than 50 payments per hour.

Selected by:
Roadmap:
Verification (step 6) Design review · Method expected: required Scenario-based evaluation (evals) · Method expected: required
This grade feels

Reversibility by design: prefer reversible actions; staging or undo for irreversible ones

Example: Payments are staged and released after two hours unless stopped.

Selected by:
Roadmap:
Verification (step 6) Design review · Method expected: required Scenario-based evaluation (evals) · Method expected: required
This grade feels

Oversight mode defined per action class (in / on / out of the loop)

Example: Below €1k autonomous; €1k–10k human approval; above €10k never by the agent.

Selected by:baseline
Roadmap:
Verification (step 6) Design review · Method expected: required
This grade feels

Approval gate for irreversible or above-threshold actions

Example: Payments above the threshold require approval in the ERP workflow.

Selected by:
Roadmap:
Verification (step 6) Design review · Method expected: required Scenario-based evaluation (evals) · Method expected: required
This grade feels

Oversight sufficiency test (Sufficient / Nominal / Insufficient / Theatrical), incl. measured error-detection rate of reviewers

Example: Quarterly check of review time per item and reviewer workload against the sufficiency criteria.

Selected by:
Roadmap:
Verification (step 6) Control audit · Method expected: required Runtime monitoring and log review · Method expected: required
This grade feels

Oversight metrics monitored (override rate, response time, outlier reviewers)

Example: Dashboard of override rate and response time per reviewer.

Selected by:
Roadmap:
Verification (step 6) Runtime monitoring and log review · Method expected: required
This grade feels

Decision context package for reviewers (reasoning summary, evidence, flags)

Example: Approval screen shows invoice, order match, anomalies and the agent's reasoning summary.

Selected by:
Roadmap:
Verification (step 6) Scenario-based evaluation (evals) · Method expected: required
This grade feels

Defined safe state and degradation modes

Example: On anomaly the agent pauses payments and hands the queue to the accounts payable team.

Selected by:baseline
Roadmap:
Verification (step 6) Design review · Method expected: required Scenario-based evaluation (evals) · Method expected: required
This grade feels

Escalation on uncertainty (calibrated uncertainty signal plus escalation rule; no raw confidence %)

Example: Weak match between invoice and order routes the case to a human with the reasons.

Selected by:
Roadmap:
Verification (step 6) Scenario-based evaluation (evals) · Method expected: required
This grade feels

Kill switch: halt and lock autonomous action

Example: One-click stop in the operations console, tested monthly.

Selected by:baseline
Roadmap:
Verification (step 6) Scenario-based evaluation (evals) · Method expected: required
This grade feels

Behavioral anomaly and drift detection against a baseline

Example: Alert when daily payment volume deviates strongly from the baseline.

Selected by:
Roadmap:
Verification (step 6) Runtime monitoring and log review · Method expected: required
This grade feels

Outcome monitoring beyond the target metric (second-order effects)

Example: Track cash position and supplier complaints, not only the on-time payment rate.

Selected by:
Roadmap:
Verification (step 6) Runtime monitoring and log review · Method expected: required
This grade feels

Input and context validity check (data quality, staleness, domain match)

Example: Reject invoices with missing order number, stale exchange rate or unknown currency.

Selected by:
Roadmap:
Verification (step 6) Scenario-based evaluation (evals) · Method expected: required
This grade feels

Incident and near-miss reporting process

Example: Incident form and monthly review of all stopped or reversed payments.

Selected by:baseline
Roadmap:
Verification (step 6) Control audit · Method expected: required
This grade feels

Decision logging (inputs, actions, model version, rationale)

Example: Log per payment: inputs, decision, model version and approver.

Selected by:baseline
Roadmap:
Verification (step 6) Control audit · Method expected: required Runtime monitoring and log review · Method expected: required
This grade feels

Log retention and audit access defined

Example: Logs kept for the legal retention period; auditors have read access.

Selected by:baseline
Roadmap:
Verification (step 6) Control audit · Method expected: required
This grade feels

Scenario-based evaluation before release (representative, edge and failure cases)

Example: Test set of historical invoices incl. duplicates and known fraud cases.

Selected by:baseline
Roadmap:
Verification (step 6) Scenario-based evaluation (evals) · Method expected: required
This grade feels

Known-unsafe scenarios detected and routed to humans

Example: Invoices in foreign currency always go to a human.

Selected by:
Roadmap:
Verification (step 6) Scenario-based evaluation (evals) · Method expected: required
This grade feels

Unknown-unsafe exploration (red-teaming, adversarial edge cases)

Example: Red team tries fake invoices and hidden instructions in invoice text.

Selected by:
Roadmap:
Verification (step 6) Adversarial testing (red-teaming) · Method expected: required
This grade feels

Staged deployment (shadow → limited → full)

Example: Shadow mode for one month, then 10% of invoices, then all.

Selected by:baseline
Roadmap:
Verification (step 6) Control audit · Method expected: required
This grade feels

Regression re-test after model, prompt or tool change

Example: Rerun the test set after every model, prompt or tool change.

Selected by:baseline
Roadmap:
Verification (step 6) Periodic re-testing · Method expected: required
This grade feels

Untrusted content isolation (external content treated as data; provenance marked)

Example: Invoice text is passed as data, never as instructions.

Selected by:
Roadmap:
Verification (step 6) Adversarial testing (red-teaming) · Method expected: required
This grade feels

Tool-call validation and safe output handling (schema checks, sandboxed execution)

Example: Payment calls validated against schema and vendor master before execution.

Selected by:
Roadmap:
Verification (step 6) Scenario-based evaluation (evals) · Method expected: required Adversarial testing (red-teaming) · Method expected: required
This grade feels

Secrets and credential isolation (no secrets in context, short-lived tokens)

Example: Short-lived tokens from a vault; no keys in prompts.

Selected by:baseline
Roadmap:
Verification (step 6) Control audit · Method expected: required
This grade feels

Supply-chain vetting of models, tools and agent products

Example: Vendor review incl. update policy and security certification.

Selected by:
Roadmap:
Verification (step 6) Control audit · Method expected: required Independent assessment / certification · Method expected: required
This grade feels

Data provenance and quality gate

Example: Vendor master data validated and owned by procurement.

Selected by:
Roadmap:
Verification (step 6) Control audit · Method expected: required
This grade feels

Fundamental-rights screening; formal FRIA where Art. 27 applies

Example: Screening checklist completed; formal FRIA where legally required.

Selected by:
Roadmap:
Verification (step 6) Control audit · Method expected: required
This grade feels

Bias and fairness testing on affected groups

Example: Compare payment delays across supplier size classes.

Selected by:
Roadmap:
Verification (step 6) Scenario-based evaluation (evals) · Method expected: required
This grade feels

Required by law ( · EU AI Act Art. 50) — this measure contributes to Transparency: persons are informed that they interact with an AI system.

Transparency to affected persons (AI disclosure, explanation, appeal path)

Example: AI notice in supplier emails; named contact for disputes.

Selected by:
Roadmap:
Verification (step 6) Control audit · Method expected: required
This grade feels

Named accountable owner and responsibility matrix (value chain + three lines of defense)

Example: Head of accounts payable is accountable; responsibilities agreed with IT and compliance.

Selected by:baseline
Roadmap:
Verification (step 6) Control audit · Method expected: required
This grade feels

Re-classification triggers defined and monitored

Example: Re-assessment when model, volume or scope changes, or at least yearly.

Selected by:baseline
Roadmap:
Verification (step 6) Control audit · Method expected: required Periodic re-testing · Method expected: required
This grade feels

Independent safety assessment before go-live

Example: Internal audit reviews the Safety Concept before go-live.

Selected by:baseline
Roadmap:
Verification (step 6) Independent assessment / certification · Method expected: required
This grade feels

Required by law ( · EU AI Act Art. 4) — this measure contributes to AI literacy of staff dealing with the AI system.

Operator and user training; AI literacy; end-user responsibility

Example: Training for clerks on reviewing agent payments.

Selected by:baseline
Roadmap:
Verification (step 6) Control audit · Method expected: required
This grade feels

Agent interaction map and trust boundaries (freedom from interference)

Example: Payment agent accepts only validated orders from the ordering agent.

Selected by:
Roadmap:
Verification (step 6) Design review · Method expected: required
This grade feels

Authenticated and validated inter-agent messaging

Example: Signed messages between ordering and payment agent.

Selected by:
Roadmap:
Verification (step 6) Adversarial testing (red-teaming) · Method expected: required
This grade feels

Network circuit breakers (aggregate thresholds regardless of contributing agent)

Example: Halt when total commitments across agents exceed a threshold within four hours.

Selected by:
Roadmap:
Verification (step 6) Scenario-based evaluation (evals) · Method expected: required
This grade feels

Independence check for decomposed or layered controls (no shared base model, context or memory)

Example: Guardrail uses a rule engine, not the same model as the agent.

Selected by:
Roadmap:
Verification (step 6) Design review · Method expected: required Independent assessment / certification · Method expected: required
This grade feels

Answers and statements only from authoritative, versioned sources; otherwise hand over to a human

Example: Agent answers payment-term questions only from the current supplier terms document; anything else goes to accounts payable.

Selected by:
Roadmap:
Verification (step 6) Scenario-based evaluation (evals) · Method expected: required
This grade feels

No commitments, offers or exceptions outside the agent's authority; such requests are routed to a human

Example: Agent may not agree to early-payment discounts or deadline extensions; it forwards such requests.

Selected by:
Roadmap:
Verification (step 6) Design review · Method expected: required Scenario-based evaluation (evals) · Method expected: required
This grade feels

Lawful-basis review of decision logic and data items before go-live and after rule changes

Example: Legal reviews which supplier attributes the agent may use to prioritize payments.

Selected by:
Roadmap:
Verification (step 6) Control audit · Method expected: required
This grade feels

Data minimization in agent context and outputs

Example: Agent receives invoice fields only; no access to full vendor contracts or employee data.

Selected by:
Roadmap:
Verification (step 6) Control audit · Method expected: required
This grade feels

Output and egress control (no auto-rendered external links or images; egress allow-list)

Example: Agent emails are plain text; outbound connections only to the ERP and the bank API.

Selected by:SR07
Roadmap:
Verification (step 6) Design review · Method expected: required Adversarial testing (red-teaming) · Method expected: required
This grade feels

Environment separation (sandbox or staging; gated production writes) and tested restore

Example: Agent works on a staging copy of the payment file; release to the bank needs a separate gated step; restore tested quarterly.

Selected by:SR06
Roadmap:
Verification (step 6) Design review · Method expected: required Scenario-based evaluation (evals) · Method expected: required
This grade feels

Audit by sampling of autonomous decisions

Example: Each week 30 random agent payments are re-checked by a clerk; error rate reported.

Selected by:SR05
Roadmap:
Verification (step 6) Runtime monitoring and log review · Method expected: required
This grade feels

Recommended (+) 4

Unique agent identity registered in an agent catalog

Example: Agent registered with ID, owner and permissions in the IT asset catalog.

Selected by:baseline
Roadmap:
Verification (step 6) Control audit · Method expected: required
This grade feels

Tamper-evident logs

Example: Write-once log storage with integrity protection.

Selected by:baseline
Roadmap:
Verification (step 6) Control audit · Method expected: required
This grade feels

Minimum development process capability

Example: Version control, documented tests and reviews for prompts and configurations.

Selected by:baseline
Roadmap:
Verification (step 6) Control audit · Method expected: required
This grade feels

Cross-firm interface contract (assume / guarantee safety obligations)

Example: Contract with the payment provider defines validation duties and liability.

Selected by:
Roadmap:
Verification (step 6) Control audit · Method expected: required
This grade feels
Optimize (optional): lower the burden on your agent

If an independent guard carries part of the safety goal, the agent itself needs fewer required measures. Your AI-SIL does not change.

  • Wrong decision or action from incorrect output (hallucination, misreasoning)AI-SIL 2
    • Source-of-truth verifierA deterministic check of each action against an authoritative record the agent cannot change
    • Qualified human gateA person checks before the effect and meets the four criteria of a qualified human gate (A10) with evidence; for H07 the person reviews outputs that contain personal or confidential data before they are sent
    • Diverse model cross-checkA second model from a different vendor and training lineage checks the output on its own input path
  • Irreversible commitment executed before review (payment, contract, deletion, external message)AI-SIL 2
    • Hard limit guardCaps, allow-lists and rate limits enforced outside the model, in the system the agent calls
    • Qualified human gateA person checks before the effect and meets the four criteria of a qualified human gate (A10) with evidence; for H07 the person reviews outputs that contain personal or confidential data before they are sent
    • Sandbox and gated promotionThe agent acts only in a sandbox or staging copy; a separate gated step promotes to production; restore is tested; for model, prompt or tool changes: a new version is promoted only through a gated regression run with automatic rollback
  • Manipulated input or goal hijack (prompt injection, poisoned documents or memory)AI-SIL 3
    • Source-of-truth verifierA deterministic check of each action against an authoritative record the agent cannot change
    • Quarantined readerUntrusted content is read by a model without tools; the planning agent never sees the raw content (dual-LLM, capability-based data flow); for personal or confidential data: a separate component holds the data and releases only fields the task needs
  • Cascading or emergent failure across agentsAI-SIL 2
    • Network circuit breakerAggregate limits across agents and time, outside every agent
  • Runaway consumption or loop (cost, rate, resources)AI-SIL 2
    • Hard limit guardCaps, allow-lists and rate limits enforced outside the model, in the system the agent calls
    • Network circuit breakerAggregate limits across agents and time, outside every agent

50 measures selected

Step 5 complete.

Back

Classification is deterministic — AI only adapts wording and suggests, you confirm.