{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-003.json",
  "source": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-003",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-ASSURE-003",
    "profile": "assurance-and-evidence",
    "url": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-003",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-003.json",
    "title": "Signed Test Report Against the Plan",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Each test campaign ends in a dated, signed test report that sets the eval result of every planned suite against the frozen plan, records deviations and waivers, and concludes against the plan's exit criteria; the release gate does not open without a current one.",
    "failureModes": [
      "A release goes ahead with no test report against the frozen plan, or with a stale one.",
      "A planned suite has no result in the report, or a deviation from the plan is not recorded.",
      "A failed suite is waived with no approving role recorded.",
      "The report is not signed off by the responsible role, or its conclusion does not follow from the results against the exit criteria."
    ],
    "scope": "Test campaigns whose results feed a release decision. The go/no-go record the release gate writes, and what else it reads, are out of scope; runs excluded or re-scored after validity checks are reported under AIGE-CTL-EVAL-009.",
    "enforcementPoints": [
      "deploy"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Test report: the test plan executed, the eval result per planned suite, counts passed, failed and waived, deviations and waivers, conclusion and a dated sign-off by role",
        "schemaId": "test-report",
        "schema": "https://aigovernanceengineer.com/schemas/test-report.v1.json",
        "layer": 3
      }
    ],
    "failureResponse": {
      "effect": "deny",
      "text": "The release gate refuses to open while the test report against the frozen plan is missing or stale."
    },
    "layer": 3,
    "secondaryLayers": [],
    "patterns": [
      {
        "slug": "eval-gate-in-ci",
        "title": "Eval Gate in CI",
        "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "schema",
        "ref": "test-report",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-test-report"
      },
      {
        "kind": "pattern",
        "ref": "eval-gate-in-ci",
        "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci"
      },
      {
        "kind": "chapter",
        "ref": "governing-development",
        "url": "https://aigovernanceengineer.com/bok/governing-development"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART9",
          "name": "EU AI Act Art. 9 risk management system",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art9"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART11",
          "name": "EU AI Act Art. 11 technical documentation (Annex IV)",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art11"
        },
        {
          "id": "AIGE-OBL-ISO42001-A6",
          "name": "A.6 AI system life cycle",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6"
        },
        {
          "id": "AIGE-OBL-NISTRMF-MEASURE",
          "name": "MEASURE",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure"
        }
      ],
      "iso42001": [
        {
          "id": "A.6.2.4",
          "title": "AI system verification and validation"
        }
      ],
      "nistAiRmf": [
        {
          "id": "MEASURE 2.3",
          "title": "Performance or assurance criteria measured for deployment-like conditions"
        }
      ],
      "owasp": [],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 10,
        "title": "Governing AI development",
        "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"The go/no-go gate\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-development#the-gono-go-gate",
        "verified": "primary"
      },
      {
        "n": 1,
        "title": "Governing AI development",
        "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"A test plan before the first run\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-development#a-test-plan-before-the-first-run",
        "verified": "primary"
      },
      {
        "n": 2,
        "title": "Pattern: Eval Gate in CI",
        "text": "Pattern: Eval Gate in CI (AI Governance Engineering Body of Knowledge v0.5.0, chapter 05 pattern catalogue). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci",
        "verified": "primary"
      },
      {
        "n": 3,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744 (the articles each control maps to, as chapters 14 and 18 restate them). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
        "verified": "primary"
      },
      {
        "n": 4,
        "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
        "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (MEASURE and MANAGE subcategories cited by id, mapped only where the official text matches the control). NIST. 2023-01-26.",
        "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
        "verified": "primary"
      },
      {
        "n": 5,
        "title": "ISO/IEC 42001:2023, AI management systems",
        "text": "ISO/IEC 42001:2023, AI management systems (Annex A control ids and clause numbers cited by number and short title only; the text of the standard was not opened). ISO/IEC. 2023-12.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      }
    ],
    "implementationNotes": [
      "The release gate reads the records the earlier gates produced; a test report against the frozen plan is one of them, and the gate writes a signed go/no-go record with its conditions, filed against the registry entry.",
      "Sign off by role, not by personal name, as the schema asks, and release in stages (shadow, canary, limited pilot, general availability), each with exit criteria from the test plan."
    ],
    "openQuestions": [
      "Verification procedure to be specified: the derivation adds no check its source material does not state; requires technical review.",
      "When a waiver in the report expires after release, is the release gated again or only the waived suite rerun?"
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
