Purpose & accountable owner
Document intended task, affected users, business owner and prohibited uses.
Responsible AI assurance
A reusable control framework for evaluating AI systems before and after deployment. It extends Raeburn's existing AI transparency, model cards, responsible-use policy and governance reference architecture.
Document intended task, affected users, business owner and prohibited uses.
Classify inputs/outputs, personal/confidential data, retention and provider boundaries.
Use task-specific test sets, error taxonomy, citation/grounding checks and acceptance thresholds.
Test prompt injection, untrusted content, data exfiltration, excessive agency, tool misuse and permission boundaries.
Record tools/actions, reversibility, financial/external consequence, approval gates, spend/iteration limits and kill path.
Assess affected groups, accessibility, contestability and plausible adverse impacts proportionate to use.
Measure failure rate, fallback, timeout, provider dependency, observability and incident response.
Track latency, token/compute cost and quality/cost trade-offs rather than benchmark quality alone.
Define when review is mandatory, reviewer competence, escalation and who remains accountable.
Re-evaluate material model, prompt, tool, data-source and permission changes; retain version/evidence history.
Inventory → Impact screen → Evaluation plan → Tested → Approved with controls → Monitored → Re-evaluated/retired. A framework assessment is not a statutory certification or guarantee of safety.