Help improve the engineering model

The engineering model on this site is a set of requirements, patterns, framework mappings and evidence formats. It only improves when someone tests it against a real system and records where it holds and where it does not.

Ways to contribute

Nine of these paths open a GitHub issue form that asks for the fields needed to act on the report; the tenth is a pull request. Each needs a GitHub account; this site sends nothing.

Open for review now: the draft control specifications in the open control profiles, the draft research notes and the incident cases they draw on, all built on what AI governance means in engineering terms.

  1. Review a control profile Test one control against an environment you know: does it hold as written, and what evidence could you produce?
  2. Propose a failure mode A way an AI system or agent breaks that a control should catch, backed by a public record.
  3. Contribute an implementation example A configuration, pipeline step, test, runtime policy or evidence export that implements a control, with the record it leaves.
  4. Map a control to a framework clause Link a control to a clause of a law, standard or framework, with the official URL and how strong the mapping is.
  5. Correct a technical error A wrong requirement, evidence statement, mapping, threat id, version or date, with the source that shows it.
  6. Review a research note Check a draft note, one section of it or a single claim against its sources.
  7. Propose an incident case A documented incident, the failure behind it and the control that would have caught it.
  8. Propose an obligation row An obligation missing from the register, with its instrument, its date and its status.
  9. Suggest a source A stronger primary source for a claim, or a claim that still needs one.
  10. Open a pull request For a change you can make yourself: the contributing guide sets the rules every pull request follows.

What a good control review contains

A review is useful when someone else can repeat it. Whether the control holds or fails, it states these six things.

The control review form asks for each of them. A review that finds a control holds as written is as useful as one that finds a gap.

Licence, versions and credit

Everything on this site is licensed CC BY 4.0, and so is a contribution once it is merged. Each release is archived on Zenodo: version 0.5.0 is DOI 10.5281/zenodo.22956197, and the concept DOI 10.5281/zenodo.22857084 always resolves to the latest release. Citation metadata is in CITATION.cff, and every change is recorded in the changelog.

Accepted substantive contributions are credited by name in bok/CONTRIBUTORS.md, shown on the contributors page; contributing does not by itself confer co-authorship. A control profile or research note moves from draft to published only once a credited reviewer has reviewed it; the methodology sets out how sources, review and corrections work.

Review the first control profile

Draft controls for AI evaluation environments, each open for technical review.