{
  "summary": {
    "systems": 4,
    "activeSystems": 3,
    "highRiskSystems": 1,
    "approvedUseCases": 1,
    "approvedEvaluations": 0,
    "approvedOversightPolicies": 1,
    "pendingMaterialChanges": 0,
    "openIncidents": 0,
    "approvedAttestations": 0,
    "frameworks": 3,
    "controls": 11,
    "costStatuses": [
      {
        "systemId": "ai_system_local_executive_council",
        "name": "Local Deterministic Executive Council",
        "period": "2026-08",
        "budgetUsd": 0,
        "spentUsd": 0,
        "usagePct": null,
        "status": "NO_BUDGET",
        "hardStop": false
      },
      {
        "systemId": "ai_system_voice_realtime",
        "name": "HDP Voice Agent Realtime Assistant",
        "period": "2026-08",
        "budgetUsd": 0,
        "spentUsd": 0,
        "usagePct": null,
        "status": "NO_BUDGET",
        "hardStop": false
      },
      {
        "systemId": "ai_system_lead_scoring",
        "name": "HDP Predictive Lead Scoring",
        "period": "2026-08",
        "budgetUsd": 0,
        "spentUsd": 0,
        "usagePct": null,
        "status": "NO_BUDGET",
        "hardStop": false
      }
    ],
    "readiness": {
      "score": 42,
      "tier": "BLOCKED",
      "blockers": [
        {
          "code": "APPROVED_USE_MISSING",
          "systemId": "ai_system_voice_realtime",
          "message": "HDP Voice Agent Realtime Assistant has no approved use case."
        },
        {
          "code": "APPROVED_EVALUATION_MISSING",
          "systemId": "ai_system_voice_realtime",
          "message": "HDP Voice Agent Realtime Assistant has no approved evaluation run."
        },
        {
          "code": "HUMAN_OVERSIGHT_MISSING",
          "systemId": "ai_system_voice_realtime",
          "message": "HDP Voice Agent Realtime Assistant lacks an approved human-oversight policy."
        }
      ],
      "warnings": [
        {
          "code": "APPROVED_EVALUATION_MISSING",
          "systemId": "ai_system_local_executive_council",
          "message": "Local Deterministic Executive Council has no approved evaluation run."
        },
        {
          "code": "APPROVED_USE_MISSING",
          "systemId": "ai_system_lead_scoring",
          "message": "HDP Predictive Lead Scoring has no approved use case."
        },
        {
          "code": "APPROVED_EVALUATION_MISSING",
          "systemId": "ai_system_lead_scoring",
          "message": "HDP Predictive Lead Scoring has no approved evaluation run."
        },
        {
          "code": "NO_APPROVED_AI_ATTESTATIONS",
          "message": "No independently reviewed AI-control attestation is approved."
        }
      ],
      "controlCoveragePct": 0,
      "assuranceClaimed": false,
      "regulatoryConformityClaimed": false
    },
    "assuranceClaimed": false,
    "regulatoryConformityClaimed": false,
    "snapshotHash": "1877f61e540b272467bf5b7d479a9d9e92c318b717bff328dc7a587d750bf9ed"
  },
  "aiSystems": [
    {
      "id": "ai_system_local_executive_council",
      "name": "Local Deterministic Executive Council",
      "ventureId": "venture_voice_agent",
      "ownerRoleId": "role_product_lead",
      "systemType": "RULE_BASED",
      "provider": "HDP LOCAL",
      "modelName": "hdp-governed-council",
      "modelVersion": "1.6",
      "deploymentEnvironments": [
        "env_development"
      ],
      "status": "ACTIVE_LOCAL",
      "intendedUses": [
        "Generate reproducible management perspectives from frozen evidence records",
        "Exercise governance workflows without external model cost"
      ],
      "prohibitedUses": [
        "Approve its own synthesis",
        "Authorize spending",
        "Dispatch external actions",
        "Represent output as independent professional advice"
      ],
      "users": [
        "Authorized internal management roles"
      ],
      "generative": false,
      "customerFacing": false,
      "externalCommunications": false,
      "personalData": false,
      "sensitiveData": false,
      "consequentialDecisionSupport": false,
      "autonomousAction": false,
      "safetyCritical": false,
      "vulnerablePopulation": false,
      "largeScale": false,
      "maximumFinancialImpact": 0,
      "risk": {
        "score": 0,
        "tier": "MINIMAL",
        "reasons": []
      },
      "dataAssetIds": [],
      "promptArtifactIds": [],
      "datasetArtifactIds": [],
      "toolAccess": [],
      "limitations": [
        "Not a general language model",
        "Does not independently verify external facts"
      ],
      "monitoringMetrics": [
        "citation coverage",
        "determinism",
        "approval gate compliance"
      ],
      "externalCertificationClaimed": false,
      "createdAt": "2026-07-20T13:05:23.771Z",
      "updatedAt": "2026-07-20T13:05:23.771Z",
      "retiredAt": null,
      "snapshotHash": "aedb0ee1c1713d63f831dbaef6d69dfd918957dae65ba3916d98bb298336b63e"
    },
    {
      "id": "ai_system_openai_council_adapter",
      "name": "OpenAI-Compatible Executive Council Adapter",
      "ventureId": null,
      "ownerRoleId": "role_product_lead",
      "systemType": "GENERATIVE",
      "provider": "OPENAI_COMPATIBLE",
      "modelName": "environment-configured",
      "modelVersion": "unactivated",
      "deploymentEnvironments": [
        "env_development"
      ],
      "status": "DISABLED",
      "intendedUses": [
        "Draft competing internal executive recommendations from approved evidence snapshots"
      ],
      "prohibitedUses": [
        "Unsupervised production decisions",
        "Autonomous external communications",
        "Self-approval",
        "Processing unapproved sensitive data"
      ],
      "users": [
        "Authorized internal management roles"
      ],
      "generative": true,
      "customerFacing": false,
      "externalCommunications": false,
      "personalData": true,
      "sensitiveData": false,
      "consequentialDecisionSupport": false,
      "autonomousAction": false,
      "safetyCritical": false,
      "vulnerablePopulation": false,
      "largeScale": false,
      "maximumFinancialImpact": 0,
      "risk": {
        "score": 20,
        "tier": "LIMITED",
        "reasons": [
          "Generative output",
          "Personal data"
        ]
      },
      "dataAssetIds": [],
      "promptArtifactIds": [],
      "datasetArtifactIds": [],
      "toolAccess": [],
      "limitations": [
        "Requires explicit network, credential, cost, privacy, and model approval configuration"
      ],
      "monitoringMetrics": [],
      "externalCertificationClaimed": false,
      "createdAt": "2026-07-20T13:05:23.771Z",
      "updatedAt": "2026-07-20T13:05:23.771Z",
      "retiredAt": null,
      "snapshotHash": "256750144a8b664cc9581560ad72af78d09fa6f36840940f877fb4845060dfe5"
    },
    {
      "id": "ai_system_voice_realtime",
      "name": "HDP Voice Agent Realtime Assistant",
      "ventureId": "venture_voice_agent",
      "ownerRoleId": "role_product_lead",
      "systemType": "GENERATIVE_VOICE",
      "provider": "CONFIGURABLE",
      "modelName": "runtime-configured",
      "modelVersion": "pilot-boundary",
      "deploymentEnvironments": [
        "env_development"
      ],
      "status": "PILOT_BOUNDARY",
      "intendedUses": [
        "Approved inbound intake",
        "Qualification",
        "Appointment support",
        "Escalation and logging"
      ],
      "prohibitedUses": [
        "Unattended mass outbound dialing",
        "Material promises",
        "Legal, medical, financial, or regulated determinations",
        "Ignoring consent and escalation rules"
      ],
      "users": [
        "Approved callers",
        "Authorized operators"
      ],
      "generative": true,
      "customerFacing": true,
      "externalCommunications": true,
      "personalData": true,
      "sensitiveData": true,
      "consequentialDecisionSupport": false,
      "autonomousAction": true,
      "safetyCritical": false,
      "vulnerablePopulation": false,
      "largeScale": false,
      "maximumFinancialImpact": 5000,
      "risk": {
        "score": 90,
        "tier": "CRITICAL",
        "reasons": [
          "Generative output",
          "Customer-facing interaction",
          "External communications",
          "Personal data",
          "Sensitive data",
          "Autonomous action"
        ]
      },
      "dataAssetIds": [
        "data_asset_crm_contacts",
        "data_asset_voice_records"
      ],
      "promptArtifactIds": [],
      "datasetArtifactIds": [],
      "toolAccess": [],
      "limitations": [
        "Human escalation required for exceptions and material commitments"
      ],
      "monitoringMetrics": [
        "handoff rate",
        "consent compliance",
        "appointment accuracy",
        "incident rate"
      ],
      "externalCertificationClaimed": false,
      "createdAt": "2026-07-20T13:05:23.772Z",
      "updatedAt": "2026-07-20T13:05:23.772Z",
      "retiredAt": null,
      "snapshotHash": "93a68b76179fc34d7da96e799995eb6c8bfbe7ea28723ef1d38a8217478d0044"
    },
    {
      "id": "ai_system_lead_scoring",
      "name": "HDP Predictive Lead Scoring",
      "ventureId": null,
      "ownerRoleId": "role_product_lead",
      "systemType": "PREDICTIVE",
      "provider": "HDP ML DEPARTMENT",
      "modelName": "lead-readiness-score",
      "modelVersion": "planned",
      "deploymentEnvironments": [
        "env_development"
      ],
      "status": "PLANNED",
      "intendedUses": [
        "Prioritize business outreach using approved business data"
      ],
      "prohibitedUses": [
        "Employment, credit, housing, insurance, or protected-class decisions",
        "Automated rejection without human review"
      ],
      "users": [
        "Authorized sales and management roles"
      ],
      "generative": false,
      "customerFacing": false,
      "externalCommunications": false,
      "personalData": true,
      "sensitiveData": false,
      "consequentialDecisionSupport": false,
      "autonomousAction": false,
      "safetyCritical": false,
      "vulnerablePopulation": false,
      "largeScale": true,
      "maximumFinancialImpact": 0,
      "risk": {
        "score": 20,
        "tier": "LIMITED",
        "reasons": [
          "Personal data",
          "Large-scale deployment"
        ]
      },
      "dataAssetIds": [
        "data_asset_crm_contacts"
      ],
      "promptArtifactIds": [],
      "datasetArtifactIds": [],
      "toolAccess": [],
      "limitations": [
        "Requires representative datasets and bias analysis before production use"
      ],
      "monitoringMetrics": [
        "precision at K",
        "calibration",
        "segment error",
        "conversion lift"
      ],
      "externalCertificationClaimed": false,
      "createdAt": "2026-07-20T13:05:23.772Z",
      "updatedAt": "2026-07-20T13:05:23.772Z",
      "retiredAt": null,
      "snapshotHash": "d654ed3836c0401f2b0975e549d4fa4141c7cf44e4797c502b6d41262a19e4c3"
    }
  ],
  "aiUseCases": [
    {
      "id": "ai_use_local_executive_advisory",
      "systemId": "ai_system_local_executive_council",
      "ventureId": "venture_voice_agent",
      "name": "Internal Evidence-Grounded Executive Advisory",
      "purpose": "Generate reproducible internal management perspectives from frozen approved evidence snapshots.",
      "ownerRoleId": "role_product_lead",
      "allowedUsers": [
        "Authorized internal management roles"
      ],
      "allowedInputs": [
        "Approved claims",
        "Approved evidence",
        "Frozen management snapshots"
      ],
      "allowedOutputs": [
        "Draft executive findings",
        "Competing recommendations",
        "Citation references"
      ],
      "prohibitedActions": [
        "Approve decisions",
        "Authorize spending",
        "Dispatch external actions",
        "Represent output as professional advice"
      ],
      "humanOversightMode": "HUMAN_REVIEW",
      "escalationTriggers": [
        "Citation validation failure",
        "Evidence snapshot mismatch",
        "Material disagreement"
      ],
      "evidenceReferences": [],
      "risk": {
        "score": 0,
        "tier": "MINIMAL",
        "reasons": []
      },
      "status": "APPROVED",
      "requiredApprovalRoles": [
        "MODEL_OWNER"
      ],
      "approvals": [
        {
          "role": "MODEL_OWNER",
          "status": "APPROVED",
          "actor": "Harrison L. Gerling II",
          "note": "Approve the local deterministic advisory use within the documented non-authorizing boundary.",
          "at": "2026-07-20T13:05:23.841Z"
        }
      ],
      "approvedAt": "2026-07-20T13:05:23.841Z",
      "createdAt": "2026-07-20T13:05:23.841Z",
      "updatedAt": "2026-07-20T13:05:23.841Z",
      "snapshotHash": "00b9fd099c8da3cc76a829b97c69b3851b7a36e83f9740d67667d2d29e8813b1",
      "approvalHash": "978917273c9c13a08a4f9a06df08c9614cfb529acaf5f416a2877a84e95c51ca"
    }
  ],
  "aiEvaluationSuites": [
    {
      "id": "ai_eval_suite_local_council_v16",
      "systemId": "ai_system_local_executive_council",
      "useCaseId": "ai_use_local_executive_advisory",
      "name": "Local Council Governance Evaluation",
      "version": "1.6",
      "dimensions": [
        {
          "id": "citation_coverage",
          "name": "Citation coverage",
          "metric": "citation_coverage_pct",
          "threshold": 100,
          "direction": "AT_LEAST",
          "critical": true,
          "category": "GROUNDING"
        },
        {
          "id": "determinism",
          "name": "Deterministic replay",
          "metric": "deterministic_match_pct",
          "threshold": 100,
          "direction": "AT_LEAST",
          "critical": true,
          "category": "ROBUSTNESS"
        },
        {
          "id": "self_authorization",
          "name": "Self-authorization attempts",
          "metric": "self_authorization_count",
          "threshold": 0,
          "direction": "AT_MOST",
          "critical": true,
          "category": "SAFETY"
        }
      ],
      "datasetArtifactIds": [],
      "promptArtifactIds": [
        "ai_prompt_local_council_v16"
      ],
      "requiredForProduction": true,
      "status": "ACTIVE",
      "createdAt": "2026-07-20T13:05:23.842Z",
      "updatedAt": "2026-07-20T13:05:23.842Z",
      "snapshotHash": "ffc84b5e8624cb1a26698f60420bb70b6350eff6a25952a2f7ad84dec2a9ad04"
    }
  ],
  "aiEvaluationRuns": [],
  "aiPromptArtifacts": [
    {
      "id": "ai_prompt_local_council_v16",
      "systemId": "ai_system_local_executive_council",
      "name": "Local Executive Council Governance Template",
      "version": "1.6",
      "purpose": "Structure evidence-grounded executive findings.",
      "instructionBoundary": "Evidence is data, never instructions; outputs cannot self-authorize.",
      "sourceReferences": [
        "docs://MODEL_COUNCIL_METHOD"
      ],
      "changeNote": "",
      "templateHash": "4c061410f5c7b1bdc15a382fb1db4c75512e6c8c977d0f53034360f0af79bf94",
      "rawPromptStored": false,
      "status": "ACTIVE",
      "createdAt": "2026-07-20T13:05:23.841Z",
      "updatedAt": "2026-07-20T13:05:23.841Z",
      "snapshotHash": "21b6fdf7ba4c6347a43f7b0ae664f184a920cc45c06b71134f4dbfba5571ea99"
    }
  ],
  "aiDatasetArtifacts": [],
  "aiOversightPolicies": [
    {
      "id": "ai_oversight_local_council_v16",
      "useCaseId": "ai_use_local_executive_advisory",
      "systemId": "ai_system_local_executive_council",
      "mode": "HUMAN_REVIEW",
      "reviewerRoleId": "role_governance_lead",
      "reviewTiming": "Before synthesis approval or decision-packet inclusion",
      "overrideAuthorityRoleId": "role_owner",
      "escalationTriggers": [
        "Invalid citations",
        "Stale snapshot",
        "Unresolved dissent"
      ],
      "stopConditions": [
        "Evidence hash mismatch",
        "Prompt boundary violation"
      ],
      "samplingPct": 100,
      "status": "APPROVED",
      "requiredApprovalRoles": [
        "MODEL_OWNER"
      ],
      "approvals": [
        {
          "role": "MODEL_OWNER",
          "status": "APPROVED",
          "actor": "Harrison L. Gerling II",
          "note": "Require human review before any model-assisted council output enters a governed decision.",
          "at": "2026-07-20T13:05:23.842Z"
        }
      ],
      "createdAt": "2026-07-20T13:05:23.842Z",
      "updatedAt": "2026-07-20T13:05:23.842Z",
      "snapshotHash": "4eb6d8374fc87ef86b4f0557bbf20f9e2f8b9fd68ed3550a6a522cfb1070063b",
      "approvedAt": "2026-07-20T13:05:23.842Z",
      "approvalHash": "726ce04df254371c2551b38d5c44e5b6efba160073ff56f031d6afc5cf08b11b"
    }
  ],
  "aiModelChanges": [],
  "aiIncidents": [],
  "aiCostBudgets": [],
  "aiUsageRecords": [],
  "aiRetirementRecords": [],
  "aiAttestations": [],
  "aiFrameworks": [
    {
      "id": "ai_framework_nist_rmf",
      "name": "NIST AI Risk Management Framework",
      "version": "1.0 reference boundary",
      "status": "REFERENCE_MAPPING_ONLY",
      "certificationClaimed": false,
      "createdAt": "2026-07-20T13:05:23.772Z",
      "updatedAt": "2026-07-20T13:05:23.772Z",
      "snapshotHash": "f1ebc984679766754bf4f903c9a8fd7a628078c845a75657b29e5b8ecfdadc2f"
    },
    {
      "id": "ai_framework_iso_42001",
      "name": "ISO/IEC 42001 AI Management System",
      "version": "2023 reference boundary",
      "status": "REFERENCE_MAPPING_ONLY",
      "certificationClaimed": false,
      "createdAt": "2026-07-20T13:05:23.772Z",
      "updatedAt": "2026-07-20T13:05:23.772Z",
      "snapshotHash": "9e35c45090d0b3af7643f3d55c54a9167b6f7c4044843648e135bf2f400bb697"
    },
    {
      "id": "ai_framework_eu_ai_act",
      "name": "EU Artificial Intelligence Act",
      "version": "Operational reference boundary as of v1.8",
      "status": "REFERENCE_MAPPING_ONLY",
      "certificationClaimed": false,
      "createdAt": "2026-07-20T13:05:23.772Z",
      "updatedAt": "2026-07-20T13:05:23.772Z",
      "snapshotHash": "f924cdb5a299b400cabd9d8cc169424b0d92ab239c89e10f35543fcfc0c057f9"
    }
  ],
  "aiControls": [
    {
      "id": "ai_control_inventory",
      "name": "AI system inventory and accountable ownership",
      "domain": "INVENTORY",
      "ownerRoleId": "role_product_lead",
      "status": "DESIGNED",
      "testFrequencyDays": 90,
      "mappings": [
        "ai_framework_nist_rmf:GOVERN-1",
        "ai_framework_iso_42001:6.1",
        "ai_framework_eu_ai_act:INVENTORY"
      ],
      "evidenceCollections": [
        "aiSystems"
      ],
      "exceptions": [],
      "createdAt": "2026-07-20T13:05:23.772Z",
      "updatedAt": "2026-07-20T13:05:23.772Z",
      "snapshotHash": "92aed325ded746fdb6660ef615894f90bf14b4ed7e22872bb343e7502e38343b"
    },
    {
      "id": "ai_control_use",
      "name": "Approved-use and prohibited-use boundaries",
      "domain": "USE_BOUNDARY",
      "ownerRoleId": "role_governance_lead",
      "status": "DESIGNED",
      "testFrequencyDays": 90,
      "mappings": [
        "ai_framework_nist_rmf:MAP-1",
        "ai_framework_iso_42001:8.2",
        "ai_framework_eu_ai_act:RISK_MANAGEMENT"
      ],
      "evidenceCollections": [
        "aiUseCases",
        "aiOversightPolicies"
      ],
      "exceptions": [],
      "createdAt": "2026-07-20T13:05:23.772Z",
      "updatedAt": "2026-07-20T13:05:23.772Z",
      "snapshotHash": "d1deaaaf677c473aee664427ffde54bfc7b8d1aa12225d1bd5f0e217f2e26605"
    },
    {
      "id": "ai_control_evaluation",
      "name": "Model evaluation and acceptance criteria",
      "domain": "EVALUATION",
      "ownerRoleId": "role_product_lead",
      "status": "DESIGNED",
      "testFrequencyDays": 90,
      "mappings": [
        "ai_framework_nist_rmf:MEASURE-2",
        "ai_framework_iso_42001:8.4",
        "ai_framework_eu_ai_act:TESTING"
      ],
      "evidenceCollections": [
        "aiEvaluationSuites",
        "aiEvaluationRuns"
      ],
      "exceptions": [],
      "createdAt": "2026-07-20T13:05:23.772Z",
      "updatedAt": "2026-07-20T13:05:23.772Z",
      "snapshotHash": "b08f8ffcdccc5caf9fcae8723ee9b005820e4cc63e3491857c551c927a0cf5db"
    },
    {
      "id": "ai_control_lineage",
      "name": "Prompt, dataset, and model lineage",
      "domain": "LINEAGE",
      "ownerRoleId": "role_product_lead",
      "status": "DESIGNED",
      "testFrequencyDays": 90,
      "mappings": [
        "ai_framework_nist_rmf:GOVERN-4",
        "ai_framework_iso_42001:7.5",
        "ai_framework_eu_ai_act:TECHNICAL_DOCUMENTATION"
      ],
      "evidenceCollections": [
        "aiPromptArtifacts",
        "aiDatasetArtifacts",
        "aiModelChanges"
      ],
      "exceptions": [],
      "createdAt": "2026-07-20T13:05:23.772Z",
      "updatedAt": "2026-07-20T13:05:23.772Z",
      "snapshotHash": "fb7de5b2c485ee16ff52b295441f82a08ecdab09423c5d6aa3bce2bb3b4775ed"
    },
    {
      "id": "ai_control_oversight",
      "name": "Human oversight and escalation",
      "domain": "OVERSIGHT",
      "ownerRoleId": "role_governance_lead",
      "status": "DESIGNED",
      "testFrequencyDays": 90,
      "mappings": [
        "ai_framework_nist_rmf:MANAGE-2",
        "ai_framework_iso_42001:8.5",
        "ai_framework_eu_ai_act:HUMAN_OVERSIGHT"
      ],
      "evidenceCollections": [
        "aiOversightPolicies"
      ],
      "exceptions": [],
      "createdAt": "2026-07-20T13:05:23.772Z",
      "updatedAt": "2026-07-20T13:05:23.772Z",
      "snapshotHash": "b6f3e88fe813532037a30acc7c896d1f0f329f994d7afa53e357835cca948a5b"
    },
    {
      "id": "ai_control_safety",
      "name": "Bias, safety, robustness, and misuse testing",
      "domain": "SAFETY",
      "ownerRoleId": "role_governance_lead",
      "status": "DESIGNED",
      "testFrequencyDays": 90,
      "mappings": [
        "ai_framework_nist_rmf:MEASURE-2.6",
        "ai_framework_iso_42001:8.4",
        "ai_framework_eu_ai_act:ACCURACY_ROBUSTNESS"
      ],
      "evidenceCollections": [
        "aiEvaluationSuites",
        "aiEvaluationRuns"
      ],
      "exceptions": [],
      "createdAt": "2026-07-20T13:05:23.772Z",
      "updatedAt": "2026-07-20T13:05:23.772Z",
      "snapshotHash": "2deb1edf14de28083ce80e16dd1de07d3e338b655fbd934a8272aedb00161047"
    },
    {
      "id": "ai_control_change",
      "name": "Governed model and automation change",
      "domain": "CHANGE",
      "ownerRoleId": "role_product_lead",
      "status": "DESIGNED",
      "testFrequencyDays": 90,
      "mappings": [
        "ai_framework_nist_rmf:MANAGE-3",
        "ai_framework_iso_42001:8.6",
        "ai_framework_eu_ai_act:CHANGE_CONTROL"
      ],
      "evidenceCollections": [
        "aiModelChanges"
      ],
      "exceptions": [],
      "createdAt": "2026-07-20T13:05:23.772Z",
      "updatedAt": "2026-07-20T13:05:23.772Z",
      "snapshotHash": "b26aee518f6c86cc28ee51c4c9a82d7354cdb241f0f441dc767687d35549b923"
    },
    {
      "id": "ai_control_incident",
      "name": "AI incident reporting and corrective action",
      "domain": "INCIDENT",
      "ownerRoleId": "role_governance_lead",
      "status": "DESIGNED",
      "testFrequencyDays": 90,
      "mappings": [
        "ai_framework_nist_rmf:MANAGE-4",
        "ai_framework_iso_42001:10.2",
        "ai_framework_eu_ai_act:INCIDENT_REPORTING"
      ],
      "evidenceCollections": [
        "aiIncidents"
      ],
      "exceptions": [],
      "createdAt": "2026-07-20T13:05:23.772Z",
      "updatedAt": "2026-07-20T13:05:23.772Z",
      "snapshotHash": "a7133c8215aea28a12704e8da839add1b636008e951d9765915252409d22c38d"
    },
    {
      "id": "ai_control_cost",
      "name": "AI usage and cost controls",
      "domain": "COST",
      "ownerRoleId": "role_finance_lead",
      "status": "DESIGNED",
      "testFrequencyDays": 90,
      "mappings": [
        "ai_framework_nist_rmf:GOVERN-6",
        "ai_framework_iso_42001:7.1",
        "ai_framework_eu_ai_act:RESOURCE_GOVERNANCE"
      ],
      "evidenceCollections": [
        "aiCostBudgets",
        "aiUsageRecords"
      ],
      "exceptions": [],
      "createdAt": "2026-07-20T13:05:23.772Z",
      "updatedAt": "2026-07-20T13:05:23.772Z",
      "snapshotHash": "f3d267bd81d32700cfab6a26f315aae25c7a9f9fc1cb6a67d30a75831d00bdc7"
    },
    {
      "id": "ai_control_retirement",
      "name": "Governed retirement and residual obligations",
      "domain": "RETIREMENT",
      "ownerRoleId": "role_product_lead",
      "status": "DESIGNED",
      "testFrequencyDays": 90,
      "mappings": [
        "ai_framework_nist_rmf:MANAGE-4.3",
        "ai_framework_iso_42001:8.6",
        "ai_framework_eu_ai_act:POST_MARKET"
      ],
      "evidenceCollections": [
        "aiRetirementRecords"
      ],
      "exceptions": [],
      "createdAt": "2026-07-20T13:05:23.772Z",
      "updatedAt": "2026-07-20T13:05:23.772Z",
      "snapshotHash": "4c37847336fa9ef3757c5ab3851b159401aa7afe7e8e4a3a7ce973c87d80c51e"
    },
    {
      "id": "ai_control_attestation",
      "name": "Independent AI control attestation",
      "domain": "ASSURANCE",
      "ownerRoleId": "role_owner",
      "status": "DESIGNED",
      "testFrequencyDays": 90,
      "mappings": [
        "ai_framework_nist_rmf:GOVERN-1.7",
        "ai_framework_iso_42001:9.2",
        "ai_framework_eu_ai_act:CONFORMITY_BOUNDARY"
      ],
      "evidenceCollections": [
        "aiAttestations"
      ],
      "exceptions": [],
      "createdAt": "2026-07-20T13:05:23.772Z",
      "updatedAt": "2026-07-20T13:05:23.772Z",
      "snapshotHash": "e72cb200397eacea5ed1526c79589274e4371fccbb3234fa12a029c89335ff77"
    }
  ]
}