Assurance & Audit

Board-Ready Governance Artifacts

Structured templates for demonstrating ACR conformance to boards, auditors, and third-party assessors. Each artifact maps directly to ACR Standard v1.0.1 requirements.

How to Use These Artifacts

  • 1.Download or copy the template for the artifact you need
  • 2.Fill in organization-specific details (bracketed fields)
  • 3.Attach evidence references linking to your implementation
  • 4.Use the completed artifacts as part of your conformance assessment or board reporting package

Agent System Card

P1 - Identity & Purpose Binding

Provides a structured, board-readable summary of an agent's identity, purpose, capabilities, constraints, and risk classification. Required for Level 2+ conformance as the authoritative agent record.

Audience:Board members, Risk committees, Compliance officers, Auditors

Escalation Authority Matrix

P6 - Human Authority

Defines who may approve which categories of actions, delegation limits, backup approvers, and timeout behavior. Required by §20 for Level 3 conformance.

Audience:Security operations, Agent operators, Compliance officers

Risk Acceptance Memo

Cross-Pillar

Documents explicit acceptance of residual risk when an agent is deployed with known control gaps or reduced conformance scope. Provides audit trail for risk-based decisions.

Audience:Board members, Risk committees, Legal, External auditors

Incident Evidence Bundle Manifest

P4 - Execution Observability / P5 - Containment

Defines the required contents of an ACR incident evidence bundle. Used to reconstruct any incident end-to-end from exported evidence, as required by Level 3 conformance.

Audience:Incident responders, Forensic analysts, Auditors, Legal

Containment Drill Report

P5 - Self-Healing & Containment

Template for quarterly kill-switch and safe-state testing required by §19. Documents test execution, timing, outcomes, and remediation of any failures.

Audience:Security operations, Platform engineering, Auditors

Vendor Assessment Questionnaire

Cross-Pillar

Structured questionnaire for evaluating third-party AI agent vendors or platforms against ACR conformance requirements. Maps each question to specific ACR standard sections.

Audience:Procurement, Third-party risk management, Security architecture