{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-010.json",
  "source": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-010",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-ASSURE-010",
    "profile": "assurance-and-evidence",
    "url": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-010",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-010.json",
    "title": "Model Artefacts Signed at Build and Verified Before Load",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Every model artefact is signed at build through a manifest of each file and its digest and carries build provenance (what built it, by what process, from which inputs), and a runtime loads it only after verifying the signature, the signer, the digests and the provenance against the registry entry of the version deployed, writing an evidence record either way.",
    "failureModes": [
      "A tampered or malicious model file loads with the privileges of the serving process.",
      "A model that skipped the eval gate reaches production through a manual copy or a moved tag.",
      "After an incident, nobody can prove which weights produced the outputs in question.",
      "A model is allowed or refused at load and no evidence record of the verification is written."
    ],
    "scope": "Model weights and their companion files, from training jobs to registries to serving clusters, including fine-tunes of bases pulled from public hubs. The artefacts an evaluation run loads are covered by AIGE-CTL-EVAL-008, and the admission of MCP servers by AIGE-CTL-AGENT-018.",
    "enforcementPoints": [
      "deploy",
      "runtime"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Signed manifest of every model file and its digest, with SLSA build provenance, recorded in the registry entry",
        "schemaId": null,
        "schema": null,
        "layer": 2
      },
      {
        "artefact": "Verification at load: signature, signer, file digests and provenance checked against the registry entry, with the decision",
        "schemaId": "evidence-record",
        "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
        "layer": 4
      }
    ],
    "failureResponse": {
      "effect": "deny",
      "text": "The serving platform's admission control refuses a model whose signature, signer identity, file digests or provenance do not match the registry entry, and writes an evidence record either way."
    },
    "layer": 2,
    "secondaryLayers": [
      4
    ],
    "patterns": [
      {
        "slug": "model-artefact-integrity",
        "title": "Model Artefact Integrity",
        "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity"
      },
      {
        "slug": "aibom",
        "title": "AIBOM",
        "url": "https://aigovernanceengineer.com/patterns/aibom"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "pattern",
        "ref": "model-artefact-integrity",
        "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity"
      },
      {
        "kind": "schema",
        "ref": "evidence-record",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-evidence-record"
      },
      {
        "kind": "chapter",
        "ref": "governing-development",
        "url": "https://aigovernanceengineer.com/bok/governing-development"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART15",
          "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART55",
          "name": "EU AI Act Art. 55 GPAI models with systemic risk",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art55"
        },
        {
          "id": "AIGE-OBL-ISO42001-A6",
          "name": "A.6 AI system life cycle",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6"
        },
        {
          "id": "AIGE-OBL-ISO42001-A10",
          "name": "A.10 Third-party and customer relationships",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a10"
        },
        {
          "id": "AIGE-OBL-NISTRMF-MANAGE",
          "name": "MANAGE",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage"
        },
        {
          "id": "AIGE-OBL-OWASP-LLM",
          "name": "Top 10 for LLM Applications 2026",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-llm"
        },
        {
          "id": "AIGE-OBL-OWASP-AGENTIC",
          "name": "Top 10 for Agentic Applications 2026",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
        }
      ],
      "iso42001": [
        {
          "id": "A.6.2.5",
          "title": "AI system deployment"
        },
        {
          "id": "A.10.3",
          "title": "Suppliers"
        }
      ],
      "nistAiRmf": [
        {
          "id": "MANAGE 3.2",
          "title": "Pre-trained models which are used for development are monitored as part of AI system regular monitoring and maintenance."
        },
        {
          "id": "MEASURE 2.7",
          "title": "Security and resilience are evaluated and documented"
        }
      ],
      "owasp": [
        {
          "id": "llm04-2026",
          "externalId": "LLM04:2026",
          "name": "Supply Chain",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-llm04-2026"
        },
        {
          "id": "asi04",
          "externalId": "ASI04",
          "name": "Agentic Supply Chain Vulnerabilities",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-asi04"
        }
      ],
      "atlas": [
        {
          "id": "aml-t0010",
          "externalId": "AML.T0010",
          "name": "AI Supply Chain Compromise",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-aml-t0010"
        }
      ],
      "aiuc1": [],
      "csaAicm": [],
      "other": [
        {
          "framework": "MITRE ATLAS mitigation",
          "ref": "AML.M0013",
          "note": "Code Signing"
        },
        {
          "framework": "MITRE ATLAS mitigation",
          "ref": "AML.M0014",
          "note": "Verify AI Artifacts"
        }
      ]
    },
    "references": [
      {
        "n": 20,
        "title": "Pattern: Model Artefact Integrity",
        "text": "Pattern: Model Artefact Integrity (AI Governance Engineering Body of Knowledge v0.5.0, chapter 05 pattern catalogue). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity",
        "verified": "primary"
      },
      {
        "n": 7,
        "title": "Governing AI development",
        "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Reproducibility and linked versioning\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-development#reproducibility-and-linked-versioning",
        "verified": "primary"
      },
      {
        "n": 21,
        "title": "An Introduction to the OpenSSF Model Signing (OMS) Specification",
        "text": "An Introduction to the OpenSSF Model Signing (OMS) Specification (detached signature over a manifest of file hashes, in the Sigstore bundle format; PKI-agnostic). OpenSSF. 2025-06-25.",
        "url": "https://openssf.org/blog/2025/06/25/an-introduction-to-the-openssf-model-signing-oms-specification/",
        "verified": "primary"
      },
      {
        "n": 22,
        "title": "model-transparency: supply chain security for ML",
        "text": "model-transparency: supply chain security for ML (signs a statement of file paths and digests through Sigstore or conventional keys; verification recomputes the hashes). Sigstore (GitHub). 2026.",
        "url": "https://github.com/sigstore/model-transparency",
        "verified": "primary"
      },
      {
        "n": 23,
        "title": "SLSA specification v1.2, Build track basics",
        "text": "SLSA specification v1.2, Build track basics (Build L1 provenance exists, L2 hosted build platform, L3 hardened builds; provenance describes what built the artefact, by what process and from which top-level inputs). OpenSSF SLSA project. n.d. (accessed 2026-09-24).",
        "url": "https://slsa.dev/spec/v1.2/build-track-basics",
        "verified": "primary"
      },
      {
        "n": 24,
        "title": "OWASP GenAI LLM Top 10 2026",
        "text": "OWASP GenAI LLM Top 10 2026 (LLM01:2026 Prompt Injection to LLM10:2026 Improper Output Handling; resource page dated 3 Aug 2026). OWASP GenAI Security Project. 2026-08-03.",
        "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
        "verified": "primary"
      },
      {
        "n": 8,
        "title": "OWASP Top 10 for Agentic Applications for 2026",
        "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
        "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
        "verified": "primary"
      },
      {
        "n": 25,
        "title": "MITRE ATLAS data, release v2026.09",
        "text": "MITRE ATLAS data, release v2026.09 (16 tactics, 120 techniques, 88 sub-techniques, 40 mitigations; technique names and technique-to-mitigation links read from dist/v6/ATLAS-2026.09.yaml). MITRE. 2026-09-15.",
        "url": "https://github.com/mitre-atlas/atlas-data/releases/tag/v2026.09",
        "verified": "primary"
      },
      {
        "n": 4,
        "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
        "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (MEASURE and MANAGE subcategories cited by id, mapped only where the official text matches the control). NIST. 2023-01-26.",
        "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
        "verified": "primary"
      },
      {
        "n": 5,
        "title": "ISO/IEC 42001:2023, AI management systems",
        "text": "ISO/IEC 42001:2023, AI management systems (Annex A control ids and clause numbers cited by number and short title only; the text of the standard was not opened). ISO/IEC. 2023-12.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      },
      {
        "n": 3,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744 (the articles each control maps to, as chapters 14 and 18 restate them). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Sign a manifest of file digests at build: the OpenSSF Model Signing (OMS) specification puts a detached signature over such a manifest in the Sigstore bundle format and is PKI-agnostic; its reference implementation, model-signing, recomputes the hashes on verification.",
      "Record provenance as SLSA provenance (https://slsa.dev/provenance/v1): Build L1 means provenance exists, L2 a hosted build platform and L3 hardened builds. Include the base model digest and the dataset admission records among the inputs, and list the same artefacts in the AIBOM.",
      "Budget for the verification latency at load, small next to model load times but real for fast scale-out; the pattern's example found a hand-copied model that had never passed the current eval gate, refused on a digest mismatch."
    ],
    "openQuestions": [
      "Verification procedure to be specified: the derivation adds no check its source material does not state; requires technical review.",
      "Which SLSA Build level should a model build reach before its provenance is trusted at load, and should that depend on the risk tier of the system?"
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
