Control area 01Accountability, purpose, and inventory
Confirm who owns the AI Worker, what it is allowed to do, and how it is classified.
GSAQ-01
Is a named human owner accountable for the AI Worker's purpose, operation, escalation, pause, and retirement?
Expected verification: Passport owner, sponsor, operator, reviewer, and escalation role assignments.
GSAQ-02
Are the business purpose, intended outcome, users, trust boundary, permitted work, and prohibited work explicitly defined?
Expected verification: Current Passport purpose and scope, prohibited actions, decision consequence, and success criteria.
GSAQ-03
Is the AI Worker inventoried with a risk tier, lifecycle state, review status, and reassessment date?
Expected verification: Registry entry, risk rationale, current lifecycle state, review date, and renewal trigger.
Control area 02Data, models, and tool boundaries
Check that the AI Worker's information, dependencies, and technical capabilities are explicitly bounded.
GSAQ-04
Are approved data classes, sources, retention, memory, retrieval, privacy, residency, and redaction boundaries documented?
Expected verification: Data classification, source approvals, memory/RAG constraints, retention, and sensitive-data handling evidence.
GSAQ-05
Are models, providers, dependencies, limitations, shared responsibilities, and change controls reviewed?
Expected verification: Vendor Model Passport, provider review, dependency inventory, limitations, and change monitoring.
GSAQ-06
Are tools, APIs, connectors, actions, resources, credentials, destinations, and prohibited actions explicitly bounded?
Expected verification: Tool/API/Connector Registry, least-privilege permissions, credential custody, destination allowlists, and denial tests.
Control area 03Human oversight and controlled execution
Verify that consequential activity cannot bypass policy, review, or action-time authority.
GSAQ-07
Do Toll Gates and Human Review block consequential, sensitive, uncertain, or out-of-scope work before action?
Expected verification: Policy and Toll Gate decisions, Human Review Items, reviewer accountability, separation of duties, and fail-closed tests.
GSAQ-08
For execution-capable profiles, must each action have current scoped authority and route through controlled execution?
Expected verification: Short-lived Runtime Permit, Action Broker mediation, exact action/resource binding, deny-by-default behavior, and outcome evidence.
GSAQ-09
Has the AI Worker been evaluated for prompt injection, excessive agency, unsafe delegation, tool misuse, exfiltration, and output failure?
Expected verification: Risk-based evaluations, adversarial tests, structured-output validation, failure analysis, and remediation records.
Control area 04Evidence, resilience, and lifecycle
Confirm that decisions can be reconstructed and the AI Worker can be contained, reassessed, or retired.
GSAQ-10
Can reviewers reconstruct material decisions, actions, denials, exceptions, evidence, and outcomes without exposing sensitive content?
Expected verification: Workflow Events, Evidence Records, Stamps, decision records, integrity references, retention, redaction, and Audit Export.
GSAQ-11
Are monitoring, alerting, escalation, incident response, pause, disable, rollback, recovery, and restart controls assigned and tested?
Expected verification: Monitoring ownership, trigger thresholds, response runbooks, kill switch, rollback path, recovery rehearsal, and restart approval.
GSAQ-12
Do material changes, incidents, drift, expired evidence, provider changes, and scope changes trigger reassessment or lifecycle action?
Expected verification: Renewal cadence, material-change rules, evidence expiration, suspension/revocation criteria, and retirement records.