Skip to content

Control Matrix (Working Draft)

This matrix links core control domains to tiers and to standard documents.

Legend

  • MUST: required for compliance at this tier
  • SHOULD: recommended best practice at this tier

Controls by Domain

Control DomainTier 0Tier 1Tier 2Tier 3Primary Standards
Transparency & ExplainabilitySHOULDMUSTMUSTMUST02_ai_standards/transparency_and_explainability.md
Bias/FairnessSHOULDSHOULDMUSTMUST02_ai_standards/fairness_and_justice.md
Safety & SecuritySHOULDMUSTMUSTMUST02_ai_standards/safety.md
Accountability & TraceabilitySHOULDMUSTMUSTMUST02_ai_standards/accountability.md
Privacy & Non-InferenceSHOULDMUSTMUSTMUST02_ai_standards/privacy_and_non_inference.md
Supply Chain & ProvenanceSHOULDMUSTMUSTMUST01_governance/supply_chain_and_provenance.md
ConsultationSHOULDSHOULDMUSTMUST01_governance/consultation_framework.md
Crypto DestabilizationSHOULDSHOULDMUST (as applicable)MUST03_quantum_standards/cryptographic_and_security_risk.md
Dual-Use GovernanceSHOULDSHOULDMUST (as applicable)MUST03_quantum_standards/national_security.md, 03_quantum_standards/research_limits.md
Moratorium CapabilityMAYMAYSHOULDMUST03_quantum_standards/research_limits.md
Ethical MetricsSHOULDSHOULDMUSTMUST04_risk_framework/ethical_metrics.md, 05_audit_and_assurance/metrics.md
AI–Quantum ConvergenceSHOULDSHOULDMUST (as applicable)MUST (as applicable)04_risk_framework/ai_quantum_convergence.md
Audit & AssuranceMAYSHOULDMUSTMUST05_audit_and_assurance/*
Environmental/Societal ImpactSHOULDSHOULDMUSTMUST01_governance/environmental_and_resource_ethics.md, 05_audit_and_assurance/metrics.md

Notes

  • “As applicable” means the system plausibly touches the described risk pathway (e.g., quantum capability relevant to crypto security).
  • This matrix is expected to evolve as domain standards become more granular.