Risk-management framework · 19 categories
Instead of interviewing your teams to work out what your AI can do, Provenant tells you — and it stays true as the system changes.
Provenant does it. You can show it before your agent runs.
Where the standard asks you to prevent something the model might do, Provenant limits how far it gets.
Where the standard asks you for a plan, a policy or a test, Provenant hands you what it needs.
| Ref | Requirement | How | Mechanism |
|---|---|---|---|
| GOVERN 1 | Policies, processes and practices for AI risk | Evidenced | Your policy and your enforcement are the same document |
| GOVERN 2 | Accountability structures | Evidenced | You know who approved what, and what they saw |
| GOVERN 3 | Workforce diversity, equity and accessibility | N/A | |
| GOVERN 4 | Culture that considers and communicates AI risk | N/A | |
| GOVERN 5 | Engagement with relevant AI actors | N/A | |
| GOVERN 6 | Third-party software, data and supply chain | Evidenced | Your vendor list writes itself |
| MAP 1 | Context established and understood | Evidenced | You start from a complete picture of what the system does and sees |
| MAP 2 | Categorisation of the AI system | Evidenced | Written for you instead of surveyed |
| MAP 3 | AI capabilities, usage, goals and expected benefits | Enforced | You can see everything your AI can do before it runs |
| MAP 4 | Risks and benefits mapped across all components | Evidenced | You start from a complete list |
| MAP 5 | Impacts to people and society characterised | Contained | You know how far an impact could reach |
| MEASURE 1 | Appropriate methods and metrics applied | Evidenced | You can evaluate everything instead of sampling |
| MEASURE 2 | Systems evaluated for trustworthy characteristics | Contained | How far the model's weaknesses can reach is capped |
| MEASURE 3 | Mechanisms for tracking risks over time | Enforced | Every decision recorded as it happens |
| MEASURE 4 | Feedback about efficacy gathered and assessed | Evidenced | The record is what you feed back |
| MANAGE 1 | Risks prioritised, responded to and managed | Evidenced | You prioritise over a complete list, not a discovered one |
| MANAGE 2 | Strategies to maximise benefit and minimise harm | Contained | How far harm can reach is capped |
| MANAGE 3 | Third-party risks and benefits managed | Evidenced | Your vendor list writes itself |
| MANAGE 4 | Risk treatments, response and recovery documented | Enforced | You have both halves — what happened, and what could have |