Patterns

33 reusable patterns for engineering the governance of AI systems. Each names the artefact you ship, where it sits in the pipeline, what runs when and the evidence it leaves, and each lives in one of the five layers of the stack.

How to read the catalogue

Every pattern follows the same fields (summary, objectives, context, problem, solution, consequences, related patterns) and ends with a Maps to line and its own numbered sources. The template, the pattern map and a short summary of each pattern are in chapter 05; the layers themselves are in chapter 04. Mappings are illustrative, not a claim of conformity.

Layer 01 Govern-as-Code

Write the rule as code. Read Layer 01 in chapter 04.

  • Policy Card

    A governance rule written as a machine-readable card that the pipeline and the runtime both evaluate, leaving a verdict on every check.

    Maps to EU AI Act Art. 9 · ISO/IEC 42001 · NIST AI RMF (Govern) · CSA AICM · OWASP Agentic ASI02/ASI03

  • FRIA-as-Code

    Every impact assessment (ISO/IEC 42005 AIIA, DPIA, FRIA) kept as one versioned fact base, linked to its controls and reopened when the system changes.

    Also Layer 02 Inventory & Transparency

    Maps to EU AI Act Art. 27 (FRIA), Art. 9 · GDPR Art. 35 (DPIA) · ISO/IEC 42005 · NIST AI RMF (Map)

  • Framework Crosswalk

    A map from each control to the framework clauses it serves, generated from the controls: an index for reuse, never proof that a control fires.

    Also Layer 05 Assurance & Continuous Compliance

    Maps to EU AI Act (cross-cutting) · ISO/IEC 42001 · NIST AI RMF (Govern) · CSA AICM · OWASP Agent Control Standard

  • Use-Case Intake & Risk Tiering

    One intake path for every AI use case: a structured use-case record, a tier computed from its risk profile, and the gates that tier switches on.

    Also Layer 02 Inventory & Transparency

    Maps to EU AI Act Art. 3(12), Art. 5, Art. 6(3)–(4), Art. 49(2), Annex III · ISO/IEC 42001 A.5.2, A.9.4 · NIST AI RMF (Govern 1.3, 1.6; Map 1.1, 1.5, 5.1)

  • AI Threat Model

    A versioned threat model per AI system: STRIDE extended with AI-specific attacks, where every threat resolves to a mitigation and the test that proves it.

    Also Layer 03 Evals & Red Teaming as Evidence

    Maps to EU AI Act Art. 15(5), Art. 55(1)(d) · ISO/IEC 42001 A.6.2.2, A.6.2.4 · NIST AI RMF (Map 5.1; Measure 2.7) · OWASP LLM01:2026, LLM05:2026 · OWASP Agentic ASI02/ASI03/ASI04 · MITRE ATLAS

  • Dataset Admission Gate

    A policy-as-code gate that lets a training, evaluation or retrieval job read only datasets with a complete, signed admission record for that use.

    Also Layer 02 Inventory & Transparency

    Maps to EU AI Act Art. 10(2)–(4), Art. 4a · GDPR Art. 5(1)(b), Art. 6(4) · ISO/IEC 42001 A.7.2, A.7.4, A.7.5, A.7.6 · NIST AI RMF (Map 2.3, 4.1) · OWASP LLM05:2026

Layer 02 Inventory & Transparency

Inventory what is running. Read Layer 02 in chapter 04.

  • Agent Registry

    A runtime-aware inventory of every model, service and agent, each with an owner, a scope and an expiry, written by the deploy pipeline, not by hand.

    Maps to EU AI Act Art. 49/71, Art. 11 · ISO/IEC 42001 · NIST AI RMF (Map) · CSA AICM · OWASP Agentic ASI10

  • AIBOM

    An AI bill of materials emitted at build, recording models, datasets, weights and their provenance in a standard format beside the registry entry.

    Maps to EU AI Act Art. 11, Art. 53 (GPAI documentation) · ISO/IEC 42001 · NIST AI RMF (Map) · CSA AICM

  • Model Card as Control Evidence

    Model and data cards regenerated from the pipeline as structured evidence, so transparency documents describe the system as it runs today.

    Maps to EU AI Act Art. 11, Art. 13 (transparency) · ISO/IEC 42001, ISO/IEC 42005 · NIST AI RMF (Map, Measure)

  • Shadow-AI Discovery

    Continuous discovery of AI systems and agents running without a registry entry, reconciled against the registry so the inventory matches production.

    Maps to EU AI Act Art. 49/71 · ISO/IEC 42001 · NIST AI RMF (Map) · CSA AICM · OWASP Agentic ASI10

  • Vendor / Model Due-Diligence Gate

    A structured due-diligence gate for bought and API-only AI that records what you can and cannot verify before the system reaches production.

    Also Layer 05 Assurance & Continuous Compliance

    Maps to EU AI Act Art. 25 (value-chain responsibilities), Art. 26 (deployer duties), Art. 27 (FRIA), Art. 53 (GPAI documentation) · ISO/IEC 42001 Annex A.10 · GPAI Code of Practice · NIST AI RMF (Map, Govern)

  • Training-Data Rights Ledger

    A per-source ledger of the right to train: acquisition channel, licence, opt-out check and permitted uses, joined to lineage so each model knows its sources.

    Maps to EU AI Act Art. 10(2)(b), Art. 53(1)(c)–(d) · Directive (EU) 2019/790 Art. 4(3) · GDPR Art. 5(1)(b), Art. 6(4) · ISO/IEC 42001 A.7.3, A.7.5 · NIST AI RMF (Govern 6.1; Map 4.1)

  • Model Artefact Integrity

    Sign every model artefact at build, attach build provenance, refuse code-executing formats, and verify signature and digests before a runtime loads it.

    Also Layer 04 Runtime Controls & Observability

    Maps to EU AI Act Art. 15(5), Art. 55(1)(d) · ISO/IEC 42001 A.6.2.5, A.10.3 · NIST AI RMF (Govern 6.1; Manage 3.2; Measure 2.7) · OWASP LLM04:2026 · OWASP Agentic ASI04 · MITRE ATLAS

  • Rights Requests Against Models

    Route each data-subject request to every place the person's data sits, from source systems to model weights, and close it with a fulfilment record.

    Also Layer 05 Assurance & Continuous Compliance

    Maps to GDPR Art. 12(3), Arts. 15–17, Art. 21 · EU AI Act Art. 26(6) · ISO/IEC 42001 A.7 · NIST AI RMF MEASURE 2.10, GOVERN 1.1 · OWASP LLM02:2026

  • Downstream Use Register

    Intended and prohibited uses as a Policy Card, every consumer of a system's outputs recorded against its registry entry, and provenance stamped on outputs.

    Also Layer 01 Govern-as-Code

    Maps to EU AI Act Art. 3(13), Art. 9(2)(b), Art. 25(1)(c), Art. 50(2) · ISO/IEC 42001 A.8.2, A.9.4, A.10.4 · NIST AI RMF MAP 1.1, MAP 3.3, MANAGE 1.4 · OWASP LLM10:2026, OWASP Agentic ASI08

Layer 03 Evals & Red Teaming as Evidence

Run evals as evidence. Read Layer 03 in chapter 04.

  • Eval Gate in CI

    An evaluation suite wired into CI so a model or agent ships only above a documented threshold: the eval run is the control, its result the evidence.

    Maps to EU AI Act Art. 15, Art. 55 · ISO/IEC 42001 · NIST AI RMF (Measure) · OWASP Agentic ASI01/ASI02

  • Adversarial Red-Team Suite

    A versioned adversarial suite built from a threat taxonomy, run in CI or on a schedule, whose findings are triaged, recorded and fed back as tests.

    Maps to EU AI Act Art. 9, Art. 15, Art. 55 (GPAI) · ISO/IEC 42001 · NIST AI RMF (Measure) · OWASP Agentic ASI01/ASI02

  • Fairness Eval Suite

    A versioned fairness suite in CI: group and intersectional metrics with intervals, a proxy scan and a counterfactual test, judged against a policy fixed first.

    Maps to EU AI Act Art. 10(2)(f)–(g), Art. 13(3)(b)(v), Art. 15(4), Art. 4a · NYC Local Law 144 · 29 CFR 1607.4(D) · ISO/IEC 42001 A.5.4, A.6.2.4 · ISO/IEC TR 24027 · NIST AI RMF (Measure 2.11)

Layer 04 Runtime Controls & Observability

Hold the line at runtime. Read Layer 04 in chapter 04.

  • Runtime Guardrail

    Input and output guardrails on the live request path that enforce the system's Policy Card on every call and emit a decision event for each one.

    Maps to EU AI Act Art. 14, Art. 15 · ISO/IEC 42001 · NIST AI RMF (Manage) · OWASP Agentic ASI02/ASI03

  • Kill Switch / Circuit Breaker

    A tested mechanism that stops one agent or class of agents at the point of action, revoking its access without breaking the rest of the fleet.

    Maps to EU AI Act Art. 14, Art. 15 · ISO/IEC 42001 · NIST AI RMF (Manage) · CSA AICM · OWASP Agentic ASI02/ASI10

  • Agent Identity & Scoped Credentials

    Every agent gets its own identity, owner, bounded scope and expiry before it acts, so its actions are attributable and its access revocable.

    Maps to EU AI Act Art. 12, Art. 14, Art. 15 · ISO/IEC 42001 · NIST AI RMF (Manage) · CSA AICM · OWASP Agentic ASI03

  • Human-in-the-loop Gate

    A human approval step at a defined high-consequence decision point, so an agent's autonomy stops exactly where the stakes justify the latency.

    Maps to EU AI Act Art. 14 · ISO/IEC 42001 · NIST AI RMF (Manage) · OWASP Agentic ASI02

  • Explanation Artefact

    One explanation record per consequential decision, with pinned model, method and reason codes, tested for fidelity and reused for every explanation duty.

    Also Layer 05 Assurance & Continuous Compliance

    Maps to EU AI Act Art. 86, Art. 26(11), Art. 13(3)(b)(iv) · GDPR Art. 15(1)(h), Art. 22 · Regulation B (12 CFR 1002.9) · ISO/IEC 42001 A.8.2 · NIST AI RMF (Measure 2.8, 2.9)

  • Decision Notice & Contest Path

    A notice at the point of an automated decision, keyed to its decision record, and a contest path to a reviewer with the power to change the outcome.

    Also Layer 05 Assurance & Continuous Compliance

    Maps to EU AI Act Art. 26(11), Art. 86 · GDPR Art. 13(2)(f), Art. 15(1)(h), Art. 22 · UK GDPR Arts. 22A–22D · ECOA / Regulation B 12 CFR 1002.9 · ISO/IEC 42001 A.8.2, A.9.2 · NIST AI RMF MEASURE 3.3, MANAGE 4.1, MAP 3.5

  • Sanctioned AI Gateway

    Approved AI tools behind single sign-on and one gateway that applies data-class rules, logs use and checks a current acceptable-use attestation.

    Also Layer 02 Inventory & Transparency

    Maps to EU AI Act Art. 4 · GDPR Art. 5(1)(c) · ISO/IEC 42001 A.2, A.9.2, A.10.3 · NIST AI RMF GOVERN 2.2, GOVERN 6.1, MANAGE 3.1 · OWASP LLM02:2026

  • Staged Rollout with Rollback Criteria

    Release every model, prompt or vendor-version change through shadow, pilot and canary stages whose rollback criteria are registered before each stage starts.

    Maps to EU AI Act Art. 26(5), Art. 60 · ISO/IEC 42001 A.6.2.5, A.6.2.6 · NIST AI RMF MANAGE 1.1, MEASURE 2.3, MANAGE 2.4

  • Drift & Fairness Monitor

    Production signals for drift, quality and fairness by group, each with a threshold, an owner and a pre-agreed consequence, written as evidence.

    Also Layer 05 Assurance & Continuous Compliance

    Maps to EU AI Act Art. 4a, Art. 15(4), Art. 26(5), Art. 72 · NYC Local Law 144 · ISO/IEC 42001 A.5.4, A.6.2.6 · NIST AI RMF MEASURE 2.4, MEASURE 2.11, MEASURE 3.1, MANAGE 4.1

  • Deactivation, Localisation & Retirement Runbook

    A drilled runbook to degrade, switch off by jurisdiction or retire an AI system, with named triggers, a decision authority and evidence at each step.

    Also Layer 02 Inventory & Transparency

    Maps to EU AI Act Art. 5, Art. 18, Art. 20, Art. 26(5), Art. 26(6), Art. 79 · ISO/IEC 42001 A.6.2.5, A.6.2.6 · NIST AI RMF GOVERN 1.7, MANAGE 2.4, MANAGE 4.1 · OWASP Agentic ASI10

Layer 05 Assurance & Continuous Compliance

Close with continuous assurance. Read Layer 05 in chapter 04.

  • Continuous Assurance Telemetry

    Control decisions streamed into one assurance store as they happen, so whether a control works is a live query, not a point-in-time attestation.

    Maps to EU AI Act Art. 72 · ISO/IEC 42001 · NIST AI RMF (Manage, Govern) · CSA AICM

  • Incident Pipeline

    The plumbing that detects, triages and reports serious AI incidents within the legal window, with timelines and templates encoded, not remembered.

    Maps to EU AI Act Art. 72, Art. 73, Art. 55 (GPAI) · ISO/IEC 42001 · NIST AI RMF (Manage)

  • Machine-Readable Evidence (OSCAL)

    Control evidence emitted in a machine-readable standard format, OSCAL first, so an audit becomes a query and the same records feed assurance.

    Maps to EU AI Act Art. 12, Art. 17, Art. 72 · ISO/IEC 42001 · NIST AI RMF (Manage, Govern)

  • Claims Substantiation Gate

    A claims register that ties each public statement about an AI system's accuracy, fairness or capability to the eval run behind it, and pulls stale claims.

    Also Layer 03 Evals & Red Teaming as Evidence

    Maps to EU AI Act Art. 3(12), Art. 13(3)(b)(ii), Art. 15(3) · FTC Act s. 5 · Directive 2005/29/EC Art. 5 · DMCC Act 2024 s. 225 · ISO/IEC 42001 A.8.2, A.8.5 · NIST AI RMF (Measure 2.3, 2.5)

  • Disclosure & Notification Pipeline

    Disclosures and notices generated from the registry, from versioned templates per audience and clock, with every notice sent recorded as evidence.

    Also Layer 02 Inventory & Transparency

    Maps to EU AI Act Art. 26(5), Art. 26(7), Art. 26(11), Art. 50 · GDPR Art. 33, Art. 34 · Korea AI Basic Act Art. 31 · ISO/IEC 42001 A.8.2, A.8.3, A.8.4, A.8.5 · NIST AI RMF MANAGE 4.3, GOVERN 4.2, GOVERN 5.1