Part 2 of 2. The questions that show whether your AI architecture is ready to scale.
Treasury's Financial Services AI Risk Management Framework runs to 230 control objectives. It's a solid foundation, and so is the NIST AI Risk Management Framework it builds on. Both give your team the right terms and goals. Neither gives you a quick way to check whether the AI setup you already run actually works.
In Part 1, we covered why governance is the real constraint on AI at scale, and the three breakthroughs that put governed agentic AI within reach. These seven questions are the practical test. They'll show you where your AI architecture is solid and where the gaps are, so you know exactly where to start.
The seven questions at a glance
- Where is AI used, and by whom?
- Do we know every agent that exists, including the ones nobody registered?
- Who is asking, and on whose behalf?
- Is this action allowed?
- What did it cost?
- What may this agent see?
- What happened, and can we prove it?
