Governance / L2 detail
Policies
Linked Level 3 activities
Level 3
AI usage policies
Extend acceptable use into explicit autonomy tiers, defined agent red lines, permitted action classes, tool boundaries, and approval thresholds (and link these to enforcement mechanisms in architecture/policy enforcement)
Open Level 3 detail
Level 3
Policy suite uplift across risk taxonomy
Update the broader policy suite impacted by agents (eg responsible AI/data ethics, AI usage, privacy, cyber, resilience/operational risk, third-party risk, data quality, model risk/validation) and align definitions/requirements across them
Open Level 3 detail
Level 3
Responsible agent rules
Move from static principles to scenario-based rules for autonomous choices and trade-offs (eg prioritisation, customer impact, escalation)
Open Level 3 detail
Level 3
Compliance framework definitions
Expand compliance definitions from “AI use case” to explicit objects - agents, agent bundles, foundation models, connectors, tools, and AI platforms - and define required records, controls, and responsibilities per object
Open Level 3 detail
Level 3
Third-party agreements and procurement clauses for agents
Update supplier due diligence and contract clauses for agent connectors/tools (data use, logging, breach handling, residency, sub-processors, change notification, audit rights)
Open Level 3 detail
Level 3
AI risk appetite statements and autonomy bounds
Update risk appetite to include measurable autonomy limits (impact thresholds, decision classes, spend caps, customer harm tolerance, override requirements)
Open Level 3 detail
Level 3
Accountability policy and ownership model
Extend from “model owner” to defined owners for foundation models, agent service/bundle, solution design, infrastructure design, connector use, and tool ownership with clear obligations
Open Level 3 detail
Level 3
Data retention policies (agent memory and traces)
Extend retention to agent memory, action traces, and tool outputs, aligned to privacy, evidencing, and dispute requirements
Open Level 3 detail