Org org_SAMPLE0001 · manufacturing · region eu-central-1. Coverage: 2026-05-27T00:00:00.000Z to 2026-08-25T00:00:00.000Z.
Mapping is referenced to the published 'Six Controls Carriers Now Require' framework (EPC Group, 2026) and the standards underwriters reference: NIST AI RMF, ISO/IEC 42001, and AIUC-1. Reference to a framework is for evidence structuring, not an endorsement or guarantee of coverage.
Each control references a standard underwriters recognize (EPC Group, 2026): NIST AI RMF, ISO/IEC 42001, and AIUC-1. Status reflects Sentinel-derived evidence; org-supplied items are flagged as findings when missing.
| Control | Status | Sentinel evidence | Org-supplied evidence |
|---|---|---|---|
| 01 · Documented Human Kill Switch | PARTIAL | Policy changes are signed by a named admin identity (audit trail, 23 entries). | Kill-switch runbook + named approver + a recent test record (org-supplied). |
| 02 · Human-in-the-Loop AI Inventory | EVIDENCED | 8 AI tools inventoried from browser telemetry. 3 agent registry entries (override owner = policy audit actor). | — |
| 03 · Data Provenance & Classification | PARTIAL | Per-tool classification: category, risk tier, vendor posture (enterprise/consumer/hybrid). | Data-flow provenance for tools handling customer/employee/financial data (org-supplied). |
| 04 · Named Accountable AI Executive | PARTIAL | Policy is published by a named admin identity (audit actor recorded per change). | Named accountable AI executive + sign-off attestation (org-supplied). |
| 05 · Deepfake-Resistant Authentication | GAP | — | Out-of-band verification for workflows AI agents touch: email/video are no longer proof of identity (org-supplied). |
| 06 · Microsoft-Stack Enforcement Evidence | PARTIAL | DNR enforcement is live: policy v7; 214 blocked / 89 warned events in window (audit-grade feed). | Entra workload identity · Purview grounding enforcement · Defender/M365 audit exports (org-supplied). |
Score 100/100 · tier CRITICAL (rule version 1.1).
| Severity | Finding | Evidence | Remediation |
|---|---|---|---|
| CRITICAL | 2 high-risk AI tools in use | host=chat.openai.com risk=high devices=38 · host=claude.ai risk=high devices=22 | Map to approved-use policy; restrict via policy block/warn + DNR enforcement. |
| HIGH | 5 consumer-tier AI tools without enterprise controls | host=chat.openai.com posture=consumer events=4210 · host=claude.ai posture=consumer events=1980 · host=midjourney.com posture=consumer events=310 · host=gamma.app posture=consumer events=240 · host=elevenlabs.io posture=consumer events=96 | Assess need; prefer enterprise-tier equivalents or add compensating controls. |
| MED | 1 agent in the registry without identity enrichment | agents=1 | Configure Entra ID / Google Workspace connectors (backend/.env) and run enrichment. |
| MED | 1 agent-enrichment connector not active | google-workspace=not-configured | Supply connector keys (owner action O-ENV) and re-run enrichment. |
| MED | 303 enforcement events (214 blocked, 89 warned) | blocked=214 · warned=89 | Review the violations feed; refine policy; run user-awareness on warned hosts. |
Gaps are reported as findings, not hidden. Where a data source is unavailable or immature (e.g., a vendor with no admin API), the report states the coverage limitation and the evidence an organization would need to supply — absence of evidence is a finding, never a silent gap.
This report does not assess high-risk AI systems under Annex I/III of the EU AI Act, nor employment-decision outputs under FCRA/ADM regimes; it evidences observable AI usage and governance posture only.