AASIFWorked example · read-only
STEP 7 OF 7

Your AASIF Safety Concept

Your Safety Concept opens with the executive summary. Resolve open checks, then export it as PDF or Word; both come from the same saved snapshot.

  1. 1Resolve blocking checks
  2. 2Review open points and deviations
  3. 3Save a version and export

Live draft · changes as you edit

AASIF SAFETY CONCEPT

Supplier invoice payment agent

Pay approved supplier invoices on time with less manual effort

Use casePay approved supplier invoices on time with less manual effort
Date2026-10-10
Document versionlive draft
Snapshot—
Flow AI-SILAI-SIL 3
Statusdraft (specified)

Legend entries mean "contributes to" a framework or standard — never a statement of conformity.

Test version: generated by the AASIF test tool with an uncalibrated Logic Pack. Not for confidential data and not a certification.

4 open points

0 · Executive summary

0.1 Classification at a glance

Classification
Flow AI-SIL 3 · Safety Integrity Level 3
Driving hazard
The level is driven by H06 Manipulated input or goal hijack (prompt injection, poisoned documents or memory): S3 (organization S3, persons S1), E3, C3 → AI-SIL 3, critical even if rare.
Status
draft (specified)
Go-live readiness
No go-live blockers

0.2 Top risks

IDHazardAI-SILWorst credible harm
Manipulated input or goal hijack (prompt injection, poisoned documents or memory) · critical even if rareAI-SIL 3Major or existential financial loss; major sanction or license risk; severe reputational crisis
Wrong decision or action from incorrect output (hallucination, misreasoning)AI-SIL 2Material financial loss for the business unit; customer-visible incident; regulatory finding
Irreversible commitment executed before review (payment, contract, deletion, external message)AI-SIL 2Material financial loss for the business unit; customer-visible incident; regulatory finding

0.3 Decisions and sign-offs needed

  • GA09 Failure mid-action · owner: Engineering / IT
  • GA10 Error discovered afterwards · owner: Process owner + legal
  • GA11 Objection by an affected person · owner: Legal / compliance
  • GA15 Switch-off and fallback · owner: Process owner
  • C08 · Flow AI-SIL ≥ 3 → expert review of the classification recommended (independence per T5) · independence I2 (independent of the responsible team)

0.4 Commitments before go-live

Required measures (++)
46
Of which in Phase 0
46
Recommended measures added (+)
4
Balance over the top hazards
12 prevent · 6 detect & recover
IDTop measures
Authenticated and validated inter-agent messaging
Output and egress control (no auto-rendered external links or images; egress allow-list)
Kill switch: halt and lock autonomous action
Decision logging (inputs, actions, model version, rationale)
Untrusted content isolation (external content treated as data; provenance marked)

0.5 Legal obligations and regulatory flags

IDObligationRequired measures
Art. 4 · AI literacy of staff dealing with the AI systemM39
Art. 50 · Transparency: persons are informed that they interact with an AI systemM34
  • T02 · Do decisions affect persons outside the organization (customers, applicants, citizens)? · yes
  • T13 · Does the agent communicate directly with humans (chat, email, voice)? · yes

Contributes to: EU AI Act Art. 10, Art. 10, 15, Art. 10, 26, 27, Art. 12, 15, Art. 12, 19, 26, Art. 13, 14 …; ISO/IEC 42001 A.10, A.3, A.4, A.5, A.5, A.7, A.6 …; NIST AI RMF GOVERN, MANAGE, MAP, MEASURE; Singapore MGF D1, D2, D3, D4 (see 5.1).

0.6 Review and approval

ActivityRequired independence
Review of the AI-SIL classificationI2 · independent of the responsible team
Review of the AASIF Safety ConceptI2 · independent of the responsible team

C08 · Flow AI-SIL ≥ 3 → expert review of the classification recommended (independence per T5)

Sign-offName and roleDateSignature
Accountable owner
Reviewer
Bow-tie view of top hazards · 3.1
PreventUntrusted content isolation (external content treated as data; provenance marked)Unknown-unsafe exploration (red-teaming, adversarial edge cases)Authenticated and validated inter-agent messagingOutput and egress control (no auto-rendered external links or images; egress allow-list)
Manipulated input or goal hijack (prompt injection, poisoned documents or memory)AI-SIL 3S3 · critical even if rare
Detect & recoverBehavioral anomaly and drift detection against a baselineDecision logging (inputs, actions, model version, rationale)Kill switch: halt and lock autonomous action
PreventInput and context validity check (data quality, staleness, domain match)Scenario-based evaluation before release (representative, edge and failure cases)Answers and statements only from authoritative, versioned sources; otherwise hand over to a humanData provenance and quality gateKnown-unsafe scenarios detected and routed to humans
Wrong decision or action from incorrect output (hallucination, misreasoning)AI-SIL 2
Detect & recoverEscalation on uncertainty (calibrated uncertainty signal plus escalation rule; no raw confidence %)Behavioral anomaly and drift detection against a baselineDefined safe state and degradation modesDecision logging (inputs, actions, model version, rationale)
PreventReversibility by design: prefer reversible actions; staging or undo for irreversible onesApproval gate for irreversible or above-threshold actionsEnvironment separation (sandbox or staging; gated production writes) and tested restore
Irreversible commitment executed before review (payment, contract, deletion, external message)AI-SIL 2
Detect & recoverDecision context package for reviewers (reasoning summary, evidence, flags)Defined safe state and degradation modesKill switch: halt and lock autonomous action

1 · Use case and scope

1.1 Purpose and scope

What should the agent achieve for the business?
Pay approved supplier invoices on time with less manual effort
Where does it sit in the business process? What happens before and after?
After invoice receipt and order matching in the ERP; before the daily bank payment run
What must the agent never do? Which cases are excluded?
Never change bank details; no payments to suppliers not in the vendor master; no splitting of invoices to stay below limits

1.2 Item definition and agent actions

How autonomous is the agent?
acts and informs
Who is affected by its outcomes?
internal teams, suppliers
Organization context
private · Manufacturing, about 5,000 employees, private company
Which data does the agent use?
confidential, untrusted external · Supplier invoices received by email (external), vendor master, bank details
Which systems and tools can the agent use?
ERP read/write, payment API, email
Does it work with other agents or other organizations' systems?
yes · Ordering agent (internal) sends purchase orders; House bank payment API (external system)
How do humans oversee it today?
Accounts payable clerks review exceptions and all payments above €10k · 40 per hour
How many decisions does the agent make?
800 per day
Which model or product powers it, and who controls updates?
vendor-managed · Vendor LLM, updates by the vendor
Does the agent's output inform decisions about people, money or regulated controls, even if a person makes the final call?
yes
Where is the agent used? (jurisdictions)
EU / EEA
IDAction (verb + object)What does the action change in the world?Can the effect be undone?Typical and maximum size of the effectHow often does the agent take this action?Does a human check before the effect happens?Which inputs does the action rely on?Is the maximum effect of this action material for the organization?Does the result reach people outside the organization, now or later (e.g. in a client deliverable, a publication or a letter)?If a person checks before the effect: does this check meet all four criteria of a qualified human gate?
Matches invoice to purchase orderinternal recordfully and instantlyOne invoice record; typical €2k, maximum €250kmany times per day or continuouson exceptions onlyInvoice PDF from supplier email (untrusted), purchase order from the ordering agentmaterialno–
Pays supplier invoicemoney movementwith effort or costTypical €2k, maximum €250kmany times per day or continuouson exceptions onlyMatched invoice, vendor master bank detailsmaterialyes–
Sends payment advice email to supplierexternal messagenot at allOne supplier contact per paymentmany times per day or continuousneverPayment record, supplier contact dataimmaterialyes–

1.3 Roles and accountability

ResponsibilityRole or groupOwns
Accountable role (GA13)Head of accounts payable is accountable; deputy: AP team leadAgent decisions · M35 Named accountable owner and responsibility matrix (value chain + three lines of defense)
Expert groupProcess ownerScope & authority · Human oversight · Monitoring · open point GA15
Expert groupIT architectureScope & authority · Multi-agent
Expert groupHRHuman oversight
Expert groupworks council (DACH)Human oversight
Expert groupEngineering / IT operationsSafe state · Monitoring
Expert groupEngineeringLogging
Expert groupinternal auditLogging
Expert groupEngineering / QAValidation
Expert groupCISOSecurity-for-safety · Multi-agent
Expert groupData protection officerData & rights
Expert grouplegal / complianceData & rights · open point GA11
Expert groupRisk / complianceGovernance
Expert groupmanagementGovernance
Expert groupEngineering / ITopen point GA09
Expert groupProcess owner + legalopen point GA10

2 · Risk assessment

2.1 Grey areas and decisions

IDSituationScopeDesign decisionOwner
Missing datawhole flowStop and escalate to accounts payable; never guess missing order numbersProcess owner
Conflicting informationwhole flowEscalate when invoice and order amounts differ by more than 2%Process owner
Limit reachedwhole flowBlock and escalate; never split an invoice to stay below the €10k limitProcess owner + risk
Uncertaintywhole flowEscalate with context; never proceed with a flag for paymentsProcess owner
Out-of-scope requestwhole flowRefuse, log and route to a humanProcess owner + CISO
First-time or unusual casewhole flowFirst invoice from a new country goes to a humanProcess owner
Human unavailablewhole flowSafe default: do not pay; notify the deputy approverProcess owner
Suspected manipulationwhole flowFreeze the payment and verify bank details by phone through a known contact; alert securityCISO + process owner
Changed rules or contextwhole flowHead of accounts payable owns rule updates; regulation changes trigger re-classificationProcess owner + compliance
Accountabilitywhole flowHead of accounts payable is accountable; deputy: AP team leadManagement
Data boundarieswhole flowNever use or store employee bank details; supplier bank details only from the vendor masterData protection officer

4 open points — see 4.1.

2.2 Hazards and ratings

IDHazardSourceS orgS personECAI-SILS3ReasonsOverridesNote
Wrong decision or action from incorrect output (hallucination, misreasoning)guide_word G02S2S1E4C2AI-SIL 2–RH12: Step 'Pays supplier invoice' moves money and its maximum size is material (A08): at least S2 for the organization or for the affected persons (R-S-FLOOR). · RH14: The agent decides about, or informs decisions about, suppliers: consider at least S2 for them (73% of such hazards in the 60 cases were rated S2 or higher). · RH21: Step 'Matches invoice to purchase order' runs many times per day; for 'Wrong output' the hazard situation usually occurs about as often as that (E4). · RH05: Starting point: in the 60 reference cases the harm of 'Wrong output' could typically be corrected only with effort or delay (C2). Confirm it for your case.––
Action beyond authorized scope (wrong tool, wrong amount, wrong recipient)trigger T07S2S1E3C2AI-SIL 1–RH12: Step 'Pays supplier invoice' moves money and its maximum size is material (A08): at least S2 for the organization or for the affected persons (R-S-FLOOR). · RH14: The agent decides about, or informs decisions about, suppliers: consider at least S2 for them (73% of such hazards in the 60 cases were rated S2 or higher). · RH21: Step 'Pays supplier invoice' runs many times per day; for 'Beyond authority' the hazard situation usually occurs somewhat less often (E3). · RH05: Starting point: in the 60 reference cases the harm of 'Beyond authority' could typically be corrected only with effort or delay (C2). Confirm it for your case.––
Irreversible commitment executed before review (payment, contract, deletion, external message)trigger T01S2S1E4C2AI-SIL 2–RH12: Step 'Pays supplier invoice' moves money and its maximum size is material (A08): at least S2 for the organization or for the affected persons (R-S-FLOOR). · RH14: The agent decides about, or informs decisions about, suppliers: consider at least S2 for them (73% of such hazards in the 60 cases were rated S2 or higher). · RH21: Step 'Pays supplier invoice' runs many times per day; for 'Irreversible before review' the hazard situation usually occurs about as often as that (E4). · RH05: Starting point: in the 60 reference cases the harm of 'Irreversible before review' typically could not be corrected (C3). Confirm it for your case.––
Correct behavior causes harm: misspecified objective or shortcut (reward hacking)trigger T14 (unsure)S2S1E3C1AI-SIL 0–RH12: Step 'Pays supplier invoice' moves money and its maximum size is material (A08): at least S2 for the organization or for the affected persons (R-S-FLOOR). · RH14: The agent decides about, or informs decisions about, suppliers: consider at least S2 for them (73% of such hazards in the 60 cases were rated S2 or higher). · RH21: Step 'Matches invoice to purchase order' runs many times per day; for 'Right but harmful' the hazard situation usually occurs about as often as that (E4). · RH05: Starting point: in the 60 reference cases the harm of 'Right but harmful' could typically be corrected only with effort or delay (C2). Confirm it for your case. · RH22: Once step 'Sends payment advice email to supplier' has taken effect, it cannot be undone. Ask whether the harm can still be corrected before it causes real damage.––
Out-of-envelope context (new domain, market, population or data shift)guide_word G11S2S1E2C2AI-SIL 0–RH14: The agent decides about, or informs decisions about, suppliers: consider at least S2 for them (73% of such hazards in the 60 cases were rated S2 or higher). · RH21: Step 'Matches invoice to purchase order' runs many times per day; for 'Outside the design envelope' the hazard situation usually occurs somewhat less often (E3). · RH05: Starting point: in the 60 reference cases the harm of 'Outside the design envelope' could typically be corrected only with effort or delay (C2). Confirm it for your case.––
Manipulated input or goal hijack (prompt injection, poisoned documents or memory)trigger T06S3S1E3C3AI-SIL 3critical even if rareRH12: Step 'Pays supplier invoice' moves money and its maximum size is material (A08): at least S2 for the organization or for the affected persons (R-S-FLOOR). · RH14: The agent decides about, or informs decisions about, suppliers: consider at least S2 for them (73% of such hazards in the 60 cases were rated S2 or higher). · RH21: Step 'Matches invoice to purchase order' runs many times per day; for 'Manipulated input' the hazard situation usually occurs somewhat less often (E3). · RH05: Starting point: in the 60 reference cases the harm of 'Manipulated input' could typically be corrected only with effort or delay (C2). Confirm it for your case.––
Unfair or discriminatory outcome for affected personstrigger T02S1S2E3C2AI-SIL 1–RH12: Step 'Pays supplier invoice' moves money and its maximum size is material (A08): at least S2 for the organization or for the affected persons (R-S-FLOOR). · RH14: The agent decides about, or informs decisions about, suppliers: consider at least S2 for them (73% of such hazards in the 60 cases were rated S2 or higher). · RH21: Step 'Pays supplier invoice' runs many times per day; for 'Unfair outcome' the hazard situation usually occurs somewhat less often (E3). · RH05: Starting point: in the 60 reference cases the harm of 'Unfair outcome' could typically be corrected only with effort or delay (C2). Confirm it for your case.––
Cascading or emergent failure across agentstrigger T09S2S1E4C2AI-SIL 2–RH14: The agent decides about, or informs decisions about, suppliers: consider at least S2 for them (73% of such hazards in the 60 cases were rated S2 or higher). · RH21: Step 'Matches invoice to purchase order' runs many times per day; for 'Cascade' the hazard situation usually occurs somewhat less often (E3). · RH05: Starting point: in the 60 reference cases the harm of 'Cascade' could typically be corrected only with effort or delay (C2). Confirm it for your case.––
Ineffective human oversight (automation bias, rubber-stamping)guide_word G14S2S1E3C2AI-SIL 1–RH12: Step 'Pays supplier invoice' moves money and its maximum size is material (A08): at least S2 for the organization or for the affected persons (R-S-FLOOR). · RH14: The agent decides about, or informs decisions about, suppliers: consider at least S2 for them (73% of such hazards in the 60 cases were rated S2 or higher). · RH21: Step 'Pays supplier invoice' runs many times per day; for 'Ineffective oversight' the hazard situation usually occurs about as often as that (E4). · RH05: Starting point: in the 60 reference cases the harm of 'Ineffective oversight' could typically be corrected only with effort or delay (C2). Confirm it for your case.––
Untraceable decision (no evidence for audit or incident analysis)guide_word G13S2S1E2C3AI-SIL 1–RH12: Step 'Pays supplier invoice' moves money and its maximum size is material (A08): at least S2 for the organization or for the affected persons (R-S-FLOOR). · RH14: The agent decides about, or informs decisions about, suppliers: consider at least S2 for them (73% of such hazards in the 60 cases were rated S2 or higher). · RH21: Step 'Matches invoice to purchase order' runs many times per day; for 'Untraceable decision' the hazard situation usually occurs about as often as that (E4). · RH05: Starting point: in the 60 reference cases the harm of 'Untraceable decision' could typically be corrected only with effort or delay (C2). Confirm it for your case. · RH22: Once step 'Sends payment advice email to supplier' has taken effect, it cannot be undone. Ask whether the harm can still be corrected before it causes real damage.––
Runaway consumption or loop (cost, rate, resources)guide_word G07S2S1E4C2AI-SIL 2–RH12: Step 'Pays supplier invoice' moves money and its maximum size is material (A08): at least S2 for the organization or for the affected persons (R-S-FLOOR). · RH14: The agent decides about, or informs decisions about, suppliers: consider at least S2 for them (73% of such hazards in the 60 cases were rated S2 or higher). · RH21: Step 'Pays supplier invoice' runs many times per day; for 'Runaway loop' the hazard situation usually occurs somewhat less often (E3). · RH05: Starting point: in the 60 reference cases the harm of 'Runaway loop' could typically be corrected at once (C1). Confirm it for your case.––
Third-party component failure or compromise (model, tool, plugin, agent product)trigger T11S2S1E2C2AI-SIL 0–RH12: Step 'Pays supplier invoice' moves money and its maximum size is material (A08): at least S2 for the organization or for the affected persons (R-S-FLOOR). · RH14: The agent decides about, or informs decisions about, suppliers: consider at least S2 for them (73% of such hazards in the 60 cases were rated S2 or higher). · RH21: Step 'Matches invoice to purchase order' runs many times per day; for 'Third-party failure' the hazard situation usually occurs much less often (E2). · RH05: Starting point: in the 60 reference cases the harm of 'Third-party failure' could typically be corrected only with effort or delay (C2). Confirm it for your case. · RH22: Once step 'Sends payment advice email to supplier' has taken effect, it cannot be undone. Ask whether the harm can still be corrected before it causes real damage.––
Misleading communication to humans (undisclosed AI, overtrust, impersonation)trigger T13S1S1E4C1AI-SIL 0–RH14: The agent decides about, or informs decisions about, suppliers: consider at least S2 for them (73% of such hazards in the 60 cases were rated S2 or higher). · RH21: Step 'Sends payment advice email to supplier' runs many times per day; for 'Misleading communication' the hazard situation usually occurs about as often as that (E4). · RH05: Starting point: in the 60 reference cases the harm of 'Misleading communication' could typically be corrected only with effort or delay (C2). Confirm it for your case. · RH22: Once step 'Sends payment advice email to supplier' has taken effect, it cannot be undone. Ask whether the harm can still be corrected before it causes real damage.––
Required action not performed (silent omission)guide_word G01S2S1E3C1AI-SIL 0–RH12: Step 'Pays supplier invoice' moves money and its maximum size is material (A08): at least S2 for the organization or for the affected persons (R-S-FLOOR). · RH14: The agent decides about, or informs decisions about, suppliers: consider at least S2 for them (73% of such hazards in the 60 cases were rated S2 or higher). · RH21: Step 'Pays supplier invoice' runs many times per day; for 'Silent omission' the hazard situation usually occurs somewhat less often (E3). · RH05: Starting point: in the 60 reference cases the harm of 'Silent omission' could typically be corrected at once (C1). Confirm it for your case.––
Flow AI-SIL (highest)
AI-SIL 3

Hazards marked not relevant

IDHazardReason
Sensitive data disclosure or privacy breachPersonal data limited to sole-trader bank details from the vendor master; covered by GA14
Silent degradation after model, prompt or context changeCovered by H14 (vendor-managed model) for this flow

2.3 Rights, regulatory flags and legal obligations

IDQuestionAnswerFlag
Do decisions affect persons outside the organization (customers, applicants, citizens)?yesRuns fundamental-rights screening
Is the deployer a public body, a provider of public services or using AI for credit scoring or life/health-insurance pricing?noFlags a legally mandatory FRIA (EU AI Act Art. 27)
Is the use case possibly in an EU AI Act Annex III area (e.g. employment, credit, education, essential services)?noFlags high-risk obligations; recommends expert review
Does the agent communicate directly with humans (chat, email, voice)?yesAI disclosure (EU AI Act Art. 50)

Legal obligations (t18) · the listed measures contribute to these obligations

IDRegimeReferenceObligationMeasures (contribute to)
EU AI ActArt. 4AI literacy of staff dealing with the AI systemM39
EU AI ActArt. 50Transparency: persons are informed that they interact with an AI systemM34

3 · Measures and verification

3.1 Bow-tie view of top hazards

PreventUntrusted content isolation (external content treated as data; provenance marked)Unknown-unsafe exploration (red-teaming, adversarial edge cases)Authenticated and validated inter-agent messagingOutput and egress control (no auto-rendered external links or images; egress allow-list)
Manipulated input or goal hijack (prompt injection, poisoned documents or memory)AI-SIL 3S3 · critical even if rare
Detect & recoverBehavioral anomaly and drift detection against a baselineDecision logging (inputs, actions, model version, rationale)Kill switch: halt and lock autonomous action
PreventInput and context validity check (data quality, staleness, domain match)Scenario-based evaluation before release (representative, edge and failure cases)Answers and statements only from authoritative, versioned sources; otherwise hand over to a humanData provenance and quality gateKnown-unsafe scenarios detected and routed to humans
Wrong decision or action from incorrect output (hallucination, misreasoning)AI-SIL 2
Detect & recoverEscalation on uncertainty (calibrated uncertainty signal plus escalation rule; no raw confidence %)Behavioral anomaly and drift detection against a baselineDefined safe state and degradation modesDecision logging (inputs, actions, model version, rationale)
PreventReversibility by design: prefer reversible actions; staging or undo for irreversible onesApproval gate for irreversible or above-threshold actionsEnvironment separation (sandbox or staging; gated production writes) and tested restore
Irreversible commitment executed before review (payment, contract, deletion, external message)AI-SIL 2
Detect & recoverDecision context package for reviewers (reasoning summary, evidence, flags)Defined safe state and degradation modesKill switch: halt and lock autonomous action

3.2 Measures by phase

Phase 0 · Before go-live

All ++ measures (prevent and detect & recover) · all decided grey areas implemented · undecided grey areas linked to S3 hazards resolved

IDMeasureGradeBarrierControl typeHow you'll do itVerificationReviewed byStatus
Item definition and operating envelope documented (task, authority, action space, contexts allowed)++PreventProcess–V1 Design review–specified
Least-privilege, scoped and non-transferable agent authority++PreventStructural–V1 Design review; V2 Control audit–specified
Hard action limits enforced outside the model (value caps, rate limits, allow-lists)++PreventRule-based–V1 Design review; V3 Scenario-based evaluation (evals)–specified
Reversibility by design: prefer reversible actions; staging or undo for irreversible ones++PreventStructural–V1 Design review; V3 Scenario-based evaluation (evals)–specified
Oversight mode defined per action class (in / on / out of the loop)++PreventProcess–V1 Design review–specified
Approval gate for irreversible or above-threshold actions++PreventStructural–V1 Design review; V3 Scenario-based evaluation (evals)–specified
Oversight sufficiency test (Sufficient / Nominal / Insufficient / Theatrical), incl. measured error-detection rate of reviewers++Detect & recoverProcess–V2 Control audit; V5 Runtime monitoring and log review–specified
Oversight metrics monitored (override rate, response time, outlier reviewers)++Detect & recoverProcess–V5 Runtime monitoring and log review–specified
Decision context package for reviewers (reasoning summary, evidence, flags)++Detect & recoverModel-based–V3 Scenario-based evaluation (evals)–specified
Defined safe state and degradation modes++Detect & recoverStructural–V1 Design review; V3 Scenario-based evaluation (evals)–specified
Escalation on uncertainty (calibrated uncertainty signal plus escalation rule; no raw confidence %)++Detect & recoverModel-based–V3 Scenario-based evaluation (evals)–specified
Kill switch: halt and lock autonomous action++Detect & recoverStructural–V3 Scenario-based evaluation (evals)–specified
Behavioral anomaly and drift detection against a baseline++Detect & recoverModel-based–V5 Runtime monitoring and log review–specified
Outcome monitoring beyond the target metric (second-order effects)++Detect & recoverProcess–V5 Runtime monitoring and log review–specified
Input and context validity check (data quality, staleness, domain match)++PreventRule-based–V3 Scenario-based evaluation (evals)–specified
Incident and near-miss reporting process++Detect & recoverProcess–V2 Control audit–specified
Decision logging (inputs, actions, model version, rationale)++Detect & recoverStructural–V2 Control audit; V5 Runtime monitoring and log review–specified
Log retention and audit access defined++Detect & recoverGovernance–V2 Control audit–specified
Scenario-based evaluation before release (representative, edge and failure cases)++PreventProcess–V3 Scenario-based evaluation (evals)–specified
Known-unsafe scenarios detected and routed to humans++PreventRule-based–V3 Scenario-based evaluation (evals)–specified
Unknown-unsafe exploration (red-teaming, adversarial edge cases)++PreventProcess–V4 Adversarial testing (red-teaming)–specified
Staged deployment (shadow → limited → full)++PreventProcess–V2 Control audit–specified
Regression re-test after model, prompt or tool change++Detect & recoverProcess–V6 Periodic re-testing–specified
Untrusted content isolation (external content treated as data; provenance marked)++PreventPrompt-layer / Structural–V4 Adversarial testing (red-teaming)–specified
Tool-call validation and safe output handling (schema checks, sandboxed execution)++PreventRule-based–V3 Scenario-based evaluation (evals); V4 Adversarial testing (red-teaming)–specified
Secrets and credential isolation (no secrets in context, short-lived tokens)++PreventStructural–V2 Control audit–specified
Supply-chain vetting of models, tools and agent products++PreventGovernance–V2 Control audit; V7 Independent assessment / certification–specified
Data provenance and quality gate++PreventProcess–V2 Control audit–specified
Fundamental-rights screening; formal FRIA where Art. 27 applies++PreventProcess–V2 Control audit–specified
Bias and fairness testing on affected groups++PreventProcess–V3 Scenario-based evaluation (evals)–specified
Transparency to affected persons (AI disclosure, explanation, appeal path)++BothProcess–V2 Control audit–specified
Named accountable owner and responsibility matrix (value chain + three lines of defense)++PreventGovernance–V2 Control audit–specified
Re-classification triggers defined and monitored++Detect & recoverProcess–V2 Control audit; V6 Periodic re-testing–specified
Independent safety assessment before go-live++PreventProcess–V7 Independent assessment / certification–specified
Operator and user training; AI literacy; end-user responsibility++PreventProcess–V2 Control audit–specified
Agent interaction map and trust boundaries (freedom from interference)++PreventStructural–V1 Design review–specified
Authenticated and validated inter-agent messaging++PreventStructural–V4 Adversarial testing (red-teaming)–specified
Network circuit breakers (aggregate thresholds regardless of contributing agent)++Detect & recoverRule-based–V3 Scenario-based evaluation (evals)–specified
Independence check for decomposed or layered controls (no shared base model, context or memory)++PreventProcess–V1 Design review; V7 Independent assessment / certification–specified
Answers and statements only from authoritative, versioned sources; otherwise hand over to a human++PreventRule-based–V3 Scenario-based evaluation (evals)–specified
No commitments, offers or exceptions outside the agent's authority; such requests are routed to a human++PreventRule-based–V1 Design review; V3 Scenario-based evaluation (evals)–specified
Lawful-basis review of decision logic and data items before go-live and after rule changes++PreventProcess–V2 Control audit–specified
Data minimization in agent context and outputs++PreventStructural–V2 Control audit–specified
Output and egress control (no auto-rendered external links or images; egress allow-list)++PreventStructural–V1 Design review; V4 Adversarial testing (red-teaming)–specified
Environment separation (sandbox or staging; gated production writes) and tested restore++PreventStructural–V1 Design review; V3 Scenario-based evaluation (evals)–specified
Audit by sampling of autonomous decisions++Detect & recoverProcess–V5 Runtime monitoring and log review–specified

Phase 1 · Within 3 months

All + measures · open points without S3 link

IDMeasureGradeBarrierControl typeHow you'll do itVerificationReviewed byStatus
Unique agent identity registered in an agent catalog+PreventStructural–V2 Control audit–specified
Tamper-evident logs+Detect & recoverStructural–V2 Control audit–specified
Minimum development process capability+PreventProcess–V2 Control audit–specified
Cross-firm interface contract (assume / guarantee safety obligations)+PreventGovernance–V2 Control audit–specified

Phase 2 · Continuous

Runtime monitoring (M14, M15), oversight metrics (M09), re-testing (M25), re-classification (M36), periodic audits (T5)

None.

3.3 Deviations

No deviations.

4 · Open points and lifecycle

4.1 Open points by expert group

Engineering / IT

IDOpen pointLinked hazardsGo-live blocker
Failure mid-actionH16, H01no

Process owner + legal

IDOpen pointLinked hazardsGo-live blocker
Error discovered afterwardsH03, H12no

Legal / compliance

IDOpen pointLinked hazardsGo-live blocker
Objection by an affected personH08, H15no

Process owner

IDOpen pointLinked hazardsGo-live blocker
Switch-off and fallbackH16, H11no

Expert review

IDOpen pointLinked hazardsGo-live blocker
Marked unsureH04no

4.2 Re-classification triggers

M36
Re-classification triggers defined and monitored
Can the model or provider change outside the deployer's control?
yes

The classification must follow changes in use and technology.

5 · Compliance legend

5.1 Contribution table

Legend entries mean "contributes to" a framework or standard — never a statement of conformity. Status: indicative, to verify.

IDMeasureContributes to: EU AI ActISO/IEC 42001NIST AI RMFSingapore MGFVerification schemes
Item definition and operating envelope documented (task, authority, action space, contexts allowed)Art. 9, 11Cl. 6, 8; A.6MAPD1 Assess and bound risks upfrontDesign review
Least-privilege, scoped and non-transferable agent authorityArt. 15, 26A.6, A.9MANAGED1 Assess and bound risks upfront; D3 Implement technical controls and processesISO 27001, AIUC-1
Unique agent identity registered in an agent catalogArt. 26A.6GOVERND1 Assess and bound risks upfront–
Hard action limits enforced outside the model (value caps, rate limits, allow-lists)Art. 9, 15A.6MANAGED3 Implement technical controls and processesAIUC-1
Reversibility by design: prefer reversible actions; staging or undo for irreversible onesArt. 9, 14A.6MANAGED3 Implement technical controls and processes–
Oversight mode defined per action class (in / on / out of the loop)Art. 14, 26A.9GOVERND2 Make humans meaningfully accountable–
Approval gate for irreversible or above-threshold actionsArt. 14A.9MANAGED2 Make humans meaningfully accountable; D3 Implement technical controls and processes–
Oversight sufficiency test (Sufficient / Nominal / Insufficient / Theatrical), incl. measured error-detection rate of reviewersArt. 14A.9MEASURED2 Make humans meaningfully accountable–
Oversight metrics monitored (override rate, response time, outlier reviewers)Art. 14, 26A.9MEASURED2 Make humans meaningfully accountable–
Decision context package for reviewers (reasoning summary, evidence, flags)Art. 13, 14A.8, A.9MANAGED2 Make humans meaningfully accountable–
Defined safe state and degradation modesArt. 9, 15A.6MANAGED3 Implement technical controls and processes–
Escalation on uncertainty (calibrated uncertainty signal plus escalation rule; no raw confidence %)Art. 14, 15A.6MANAGED3 Implement technical controls and processes–
Kill switch: halt and lock autonomous actionArt. 14A.6, A.9MANAGED3 Implement technical controls and processes–
Behavioral anomaly and drift detection against a baselineArt. 15, 72Cl. 9; A.6MEASURED3 Implement technical controls and processes–
Outcome monitoring beyond the target metric (second-order effects)Art. 9, 72Cl. 9MEASURED3 Implement technical controls and processes–
Input and context validity check (data quality, staleness, domain match)Art. 10, 15A.7MEASURED3 Implement technical controls and processes–
Incident and near-miss reporting processArt. 73Cl. 10MANAGED3 Implement technical controls and processes–
Decision logging (inputs, actions, model version, rationale)Art. 12, 19, 26A.6MEASURED3 Implement technical controls and processesAIUC-1
Tamper-evident logsArt. 12, 15A.6MANAGED3 Implement technical controls and processesISO 27001
Log retention and audit access definedArt. 19, 26Cl. 7.5GOVERND3 Implement technical controls and processesISO 27001
Scenario-based evaluation before release (representative, edge and failure cases)Art. 9, 15A.6MEASURED3 Implement technical controls and processesAIUC-1
Known-unsafe scenarios detected and routed to humansArt. 9A.6MEASURED3 Implement technical controls and processes–
Unknown-unsafe exploration (red-teaming, adversarial edge cases)Art. 9, 15A.6MEASURED3 Implement technical controls and processesAIUC-1
Staged deployment (shadow → limited → full)Art. 9A.6MANAGED1 Assess and bound risks upfront; D3 Implement technical controls and processes–
Regression re-test after model, prompt or tool changeArt. 9, 15A.6MEASURED3 Implement technical controls and processesAIUC-1
Untrusted content isolation (external content treated as data; provenance marked)Art. 15A.6MANAGED3 Implement technical controls and processesAIUC-1, ISO 27001
Tool-call validation and safe output handling (schema checks, sandboxed execution)Art. 15A.6MANAGED3 Implement technical controls and processesAIUC-1
Secrets and credential isolation (no secrets in context, short-lived tokens)Art. 15A.6MANAGED3 Implement technical controls and processesISO 27001, SOC 2
Supply-chain vetting of models, tools and agent productsArt. 25, 26A.10GOVERND1 Assess and bound risks upfrontAIUC-1, ISO 27001
Data provenance and quality gateArt. 10A.7MAPD1 Assess and bound risks upfront–
Fundamental-rights screening; formal FRIA where Art. 27 appliesArt. 27A.5MAPD1 Assess and bound risks upfront–
Bias and fairness testing on affected groupsArt. 10A.5, A.7MEASURED1 Assess and bound risks upfront; D3 Implement technical controls and processes–
Transparency to affected persons (AI disclosure, explanation, appeal path)Art. 26, 50, 86A.8GOVERND4 Enable end-user responsibility–
Named accountable owner and responsibility matrix (value chain + three lines of defense)Art. 17, 26Cl. 5; A.3GOVERND2 Make humans meaningfully accountableISO 42001
Re-classification triggers defined and monitoredArt. 9, 72Cl. 9, 10MANAGED1 Assess and bound risks upfront–
Minimum development process capabilityArt. 17Cl. 8; A.6GOVERND3 Implement technical controls and processesISO 42001
Independent safety assessment before go-liveArt. 43Cl. 9MEASURED2 Make humans meaningfully accountableArt. 43 conformity assessment, AIUC-1
Operator and user training; AI literacy; end-user responsibilityArt. 4, 26Cl. 7.2; A.4GOVERND4 Enable end-user responsibility–
Agent interaction map and trust boundaries (freedom from interference)Art. 15A.6MAPD3 Implement technical controls and processes–
Authenticated and validated inter-agent messagingArt. 15A.6MANAGED3 Implement technical controls and processesAIUC-1
Network circuit breakers (aggregate thresholds regardless of contributing agent)Art. 9, 15A.6MANAGED3 Implement technical controls and processes–
Independence check for decomposed or layered controls (no shared base model, context or memory)Art. 15A.6MEASURED3 Implement technical controls and processes–
Cross-firm interface contract (assume / guarantee safety obligations)Art. 25A.10GOVERND1 Assess and bound risks upfront–
Answers and statements only from authoritative, versioned sources; otherwise hand over to a humanArt. 13, 15A.6, A.8MANAGED3 Implement technical controls and processes–
No commitments, offers or exceptions outside the agent's authority; such requests are routed to a humanArt. 14, 26A.6GOVERND1 Assess and bound risks upfront; D3 Implement technical controls and processes–
Lawful-basis review of decision logic and data items before go-live and after rule changesArt. 10, 26, 27A.5, A.7MAPD1 Assess and bound risks upfront–
Data minimization in agent context and outputsArt. 10A.7MANAGED3 Implement technical controls and processes–
Output and egress control (no auto-rendered external links or images; egress allow-list)Art. 15A.6MANAGED3 Implement technical controls and processes–
Environment separation (sandbox or staging; gated production writes) and tested restoreArt. 9, 15A.6MANAGED3 Implement technical controls and processes–
Audit by sampling of autonomous decisionsArt. 14, 26, 72A.9; Cl. 9MEASURED2 Make humans meaningfully accountable; D3 Implement technical controls and processes–

Annex A · Implementation binding

To be filled by engineering: how each requirement is implemented (tool, configuration, process).

IDRequirementImplemented by (tool, configuration, process)
Item definition and operating envelope documented (task, authority, action space, contexts allowed)
Least-privilege, scoped and non-transferable agent authority
Unique agent identity registered in an agent catalog
Hard action limits enforced outside the model (value caps, rate limits, allow-lists)
Reversibility by design: prefer reversible actions; staging or undo for irreversible ones
Oversight mode defined per action class (in / on / out of the loop)
Approval gate for irreversible or above-threshold actions
Oversight sufficiency test (Sufficient / Nominal / Insufficient / Theatrical), incl. measured error-detection rate of reviewers
Oversight metrics monitored (override rate, response time, outlier reviewers)
Decision context package for reviewers (reasoning summary, evidence, flags)
Defined safe state and degradation modes
Escalation on uncertainty (calibrated uncertainty signal plus escalation rule; no raw confidence %)
Kill switch: halt and lock autonomous action
Behavioral anomaly and drift detection against a baseline
Outcome monitoring beyond the target metric (second-order effects)
Input and context validity check (data quality, staleness, domain match)
Incident and near-miss reporting process
Decision logging (inputs, actions, model version, rationale)
Tamper-evident logs
Log retention and audit access defined
Scenario-based evaluation before release (representative, edge and failure cases)
Known-unsafe scenarios detected and routed to humans
Unknown-unsafe exploration (red-teaming, adversarial edge cases)
Staged deployment (shadow → limited → full)
Regression re-test after model, prompt or tool change
Untrusted content isolation (external content treated as data; provenance marked)
Tool-call validation and safe output handling (schema checks, sandboxed execution)
Secrets and credential isolation (no secrets in context, short-lived tokens)
Supply-chain vetting of models, tools and agent products
Data provenance and quality gate
Fundamental-rights screening; formal FRIA where Art. 27 applies
Bias and fairness testing on affected groups
Transparency to affected persons (AI disclosure, explanation, appeal path)
Named accountable owner and responsibility matrix (value chain + three lines of defense)
Re-classification triggers defined and monitored
Minimum development process capability
Independent safety assessment before go-live
Operator and user training; AI literacy; end-user responsibility
Agent interaction map and trust boundaries (freedom from interference)
Authenticated and validated inter-agent messaging
Network circuit breakers (aggregate thresholds regardless of contributing agent)
Independence check for decomposed or layered controls (no shared base model, context or memory)
Cross-firm interface contract (assume / guarantee safety obligations)
Answers and statements only from authoritative, versioned sources; otherwise hand over to a human
No commitments, offers or exceptions outside the agent's authority; such requests are routed to a human
Lawful-basis review of decision logic and data items before go-live and after rule changes
Data minimization in agent context and outputs
Output and egress control (no auto-rendered external links or images; egress allow-list)
Environment separation (sandbox or staging; gated production writes) and tested restore
Audit by sampling of autonomous decisions

Annex B · Change log and self-check

Version history

Live draft — not saved as a version yet.

Five-point self-check

CheckResult
Understanding: every agent action is described (C01)yes
Grey areas: every grey area is decided or an open pointyes
Side effects: every relevant hazard is ratedyes
Countermeasures: no ++ deviation without rationale and owner (C10)yes
Reasoning: no open point linked to a critical-even-if-rare hazard (C09)yes

Annex C · Glossary and assumptions

Glossary

TermDefinition
Agent / agentic AIAn AI system that takes actions toward a goal with some autonomy, e.g. calling tools, sending messages or making payments.
ActionSomething the agent does that changes the world, e.g. "pays supplier invoice".
HazardA way the agent could cause harm, e.g. paying the wrong recipient.
HarmDamage to the organization or to affected persons: financial, reputational, regulatory, operational, rights, health or safety.
Severity (S)How bad the harm would be: the higher of harm to the organization and harm to affected persons.
AI-SILAI Safety Integrity Level 0–4: how much engineering rigor the flow needs. Derived from S, E and C.
Critical-even-if-rareA hazard with the highest severity (S3), always shown even if its AI-SIL is low.
Grey areaAgent behavior that has not been decided yet, e.g. what happens when data is missing.
Guide wordA short prompt like "too much" or "too late" used to think through what could go wrong with an action.
MeasureA requirement that reduces risk: a design rule, control, process or check.
Safe stateThe predefined behavior the agent switches to when something is wrong, e.g. pause and hand over to a human.
Human oversight (in / on / out of the loop)Human approves before the action / monitors and can intervene / is not involved in the individual action.
Oversight sufficiencyWhether human review is real: enough time, information and authority to intervene. Otherwise it is "theatrical".
DecompositionSplitting a safety goal across independent elements, e.g. the agent and a deterministic guard, so that each carries part of the rigor. Written X(Y): rigor X, goal Y.
IndependenceTwo layers are independent only if they do not share the same model, data or blind spots.
VerificationProof that a measure is implemented and works: review, audit, evals, red-teaming, monitoring or assessment.
FRIAFundamental rights impact assessment under EU AI Act Art. 27; legally required for certain deployers.
AASIF Safety ConceptThe living document per business flow with scope, risks, AI-SIL, measures, roadmap and contributions to regulations.
Contributes toHow AASIF describes its link to regulations and standards: a measure supports an obligation; it does not certify compliance.
Hazard situationThe situation in which a hazard can occur. Exposure counts how often it occurs, not how often the agent runs.
ElementA part of the architecture that carries part of a safety goal: the agent, a guard, a human gate, a separation or a diverse model.
Qualified human gateA human check that meets four criteria (independent source check; competence, time and authority; measured detection rate; logged and auditable). Since v0.6 it can be used as decomposition pattern DP4; it never lowers C by itself.

Assumptions

This Safety Concept docks into the organization's existing management system (e.g. ISO/IEC 42001); it does not replace it.

Ratings, decisions and measures reflect the answers given at the date of this document and must be re-opened when a re-classification trigger occurs.

Test version: generated by the AASIF test tool with an uncalibrated Logic Pack. Not for confidential data and not a certification.

Annex D · Quality checks and traceability

Quality checks · 15 of 18 passed

IDCheckResult
At least one agent action is definedpassed
Each action has been run through all guide words (T8), or a guide word is marked not applicableopen: ACT-01:G01, ACT-01:G02, ACT-01:G03, ACT-01:G04, ACT-01:G06, ACT-01:G08, ACT-01:G09, ACT-01:G10, ACT-01:G11, ACT-01:G12, ACT-01:G13, ACT-01:G14, ACT-01:G15, ACT-01:G16, ACT-02:G01, ACT-02:G02, ACT-02:G03, ACT-02:G04, ACT-02:G05, ACT-02:G06, ACT-02:G07, ACT-02:G08, ACT-02:G09, ACT-02:G10, ACT-03:G01, ACT-03:G02, ACT-03:G03, ACT-03:G05, ACT-03:G06, ACT-03:G09, ACT-03:G10
Each hazard type (malfunction, SOTIF, security, rights, oversight, accountability, lifecycle; multi-agent if T09 = yes) has at least one hazard selected or marked not relevantpassed
A pre-selected hazard marked "not relevant" needs a one-line reasonpassed
"Unsure" counts as relevant and adds an expert-review flagnoted: T14
Action marked 'not at all' undoable (A03) but harm rated C1open: H15
E0 proposed although I14 = yes or T19 = yes (not allowed)passed
Flow AI-SIL ≥ 3 → expert review of the classification recommended (independence per T5)open: Expert review of the classification recommended
Undecided grey area linked to an S3 hazard → listed as go-live blockerpassed
A deselected ++ measure needs a rationale and an ownerpassed
T09 = yes → network assessment measures (M40–M43) includednoted: M40, M41, M42, M43
T7 T03 = yes → formal FRIA shown as legally requiredpassed
Every S3 hazard appears in section 2.4 and is considered for the bow-tie viewnoted: H06
Five-point self-check offered at the end (understanding, grey areas, side effects, countermeasures, reasoning)not evaluated
T04 = yes (possible EU AI Act Annex III use) and flow AI-SIL < 2 → review the ratings; the AI-SIL is not overriddenpassed
An action with A02 = physical actuation → scope notice (t21): the domain functional-safety standard governs that action and its safety function; AASIF rates the remaining hazards of the flow and states the exclusion in the Safety Conceptpassed
DP4 (qualified human gate) needs evidence text for each of the four A10 criteria on every linked actionnot evaluated
Short path chosen but full rating gives flow AI-SIL ≥ 2 or any S3 → prompt to complete the full analysispassed
Applicable legal obligations (t18) are listed in section 2.5 and their measures marked 'required by law'noted: LO01, LO04
Internal action with A09 = yes but every linked hazard rated S1 → review severitypassed
Split not allowed for the hazard's AI-SIL, element above its cap, or pattern does not cover the hazard → decomposition rejected with reasonnot evaluated
Any independence question IQ1–IQ7 answered yes or unsure, or evidence missing → decomposition rejected with reasonnot evaluated
Valid decomposition → M43 required and section 3.5 generatednot evaluated
Decomposed hazard without safe-state confirmation for the non-agent element (D-R5)not evaluated

Traceability

Logic Pack
v0.6.5 (0.6.4 + human-review round 2 presentation data (Safety Concept structure, explainer, step texts); classification, selection and grading unchanged)
SHA-256 checksum
5e5f6cb7250bfcc70d113a8a3e776cbeb6bdf18562467a5086be5025133dd8d6
Snapshot
live draft
AI suggestions
on

Classification is deterministic — AI only adapts wording and suggests, you confirm.