{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-028.json",
  "source": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-028",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-AGENT-028",
    "profile": "agent-runtime",
    "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-028",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-028.json",
    "title": "Prompts under change control",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "The system prompt, tool descriptions and policy bundle are versioned and owned, hashed in the registry and in every trace, and changed only through the regression suite and a canary rollout with the previous hash ready to restore, with a check on whether the purpose changed.",
    "failureModes": [
      "The production prompt is edited outside the pipeline, for example in a vendor console, so the registry and the traces still name the old version and an incident replays a configuration that never ran.",
      "A prompt, tool description or policy bundle change ships with no passing regression run, or with no hash in the registry and the traces.",
      "A change alters what the system is for and no one asks whether the purpose changed."
    ],
    "scope": "Every agent that calls tools, in production or in an evaluation harness.",
    "enforcementPoints": [
      "pre_merge",
      "deploy"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Prompt manifest; eval run per change; rollout record",
        "schemaId": null,
        "schema": null,
        "layer": 4
      }
    ],
    "failureResponse": {
      "effect": "alert",
      "text": "To be specified."
    },
    "layer": 4,
    "secondaryLayers": [],
    "patterns": [
      {
        "slug": "eval-gate-in-ci",
        "title": "Eval Gate in CI",
        "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci"
      }
    ],
    "seeds": [
      {
        "id": "prompt-change-control",
        "title": "Prompts under change control",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#prompts-as-configuration-under-change-control"
      }
    ],
    "derivedFrom": [],
    "mappings": {
      "obligations": [],
      "iso42001": [],
      "nistAiRmf": [],
      "owasp": [],
      "atlas": [],
      "aiuc1": [
        "E004"
      ],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 27,
        "title": "Governing AI agents",
        "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Prompts as configuration under change control\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#prompts-as-configuration-under-change-control",
        "verified": "primary"
      },
      {
        "n": 8,
        "title": "AIUC-1 requirements",
        "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
        "url": "https://standard.aiuc-1.com/llms.txt",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Keep prompts in the repository with a named owner and two reviewers, and let the pipeline refuse a prompt manifest whose named evaluation run has not passed.",
      "Treat the system prompt as configuration, not a secret and not a control: no credentials in it, and nothing that must hold enforced by it; that belongs in the gateway."
    ],
    "openQuestions": [
      "Verification procedure and evidence schema to be specified; requires technical review."
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
