NEW

Start with the pressure: sales, launch, abuse, agents, data, or guardrails

Deliverablesdeliverable
deliverable
public-sample

AI Control Gap Assessment

A gap assessment mapping missing, partial, implemented, and validated AI controls to evidence, owners, remediation, release blockers, and buyer impact.

12-24 pages
Client deliverable
public-sample
12-24 pages
Primary decision enabled
Constrained pilot may continue, but enterprise expansion requires validated retrieval authorization, tool action-class enforcement, approval bundles, and trace policy.
System
Northstar Support Cloud / Customer Support Copilot
Environment
Production pilot

# AI Control Gap Assessment

Sample Deliverable

Executive Summary

This assessment maps AI controls to their real state: missing, partial, implemented, or validated. It connects each control to an owner, evidence, remediation action, buyer impact, and release-blocker status.

The sample posture is not immature, but it is not yet enterprise-ready. Most controls exist in partial form. The biggest gaps are retrieval authorization proof, agent tool authority, approval context, trace retention, and provider boundary evidence.

Heads up

Public sample notice

This is a shortened, synthetic excerpt prepared as a public sample. A client version would include system-specific evidence, implementation references, architecture screenshots, control test results, owner sign-offs, and full supporting documentation. This sample uses Northstar Support Cloud / Customer Support Copilot as the synthetic reference system. This sample is not legal advice, not a compliance certification, not an audit opinion, not a warranty, and not proof that any unreviewed system is secure.
Decision · conditional

Control gap decision

Continue constrained pilot operation, but do not expand enterprise rollout until the seven release-blocking control gaps have remediation owners, evidence, and validation results.

Metrics

Control Gap Snapshot

Controls reviewed
14
Missing controls
1
Partial controls
10
Implemented controls
3
Validated controls
0
Release blockers
7
Note

Control maturity is evidence maturity

A control described in a policy is not mature. A mature control has an owner, implementation evidence, validation evidence, review cadence, and a buyer-safe explanation.

Control gap map

Control map

AI Control Gap Assessment

The control gap map connects controls, states, owners, evidence, remediation, release blockers, and buyer impact.

AI system inventory
planned
AI risk tiering
planned
Model provider boundary statement
planned
Gateway-only model routing
planned
Authorization-preserving retrieval
planned
Source trust labeling
planned
Agent tool inventory
planned
Agent tool permission matrix
planned

Control summary

Control state summary

ControlDomainStateOwnerRelease blocker
AI system inventorygovernanceimplementedProduct Securityno
AI risk tieringgovernancepartialProduct Securityno
Model provider boundary statementthird-party riskpartialVendor Management and Legalyes
Gateway-only model routingarchitectureimplementedAI Platform Engineeringno
Authorization-preserving retrievaldata accesspartialSearch Platformyes
Source trust labelingRAG securitypartialProduct Securityyes
Agent tool inventoryagentic controlspartialAI Platform Engineeringyes
Agent tool permission matrixagentic controlspartialAI Platform Engineeringyes
Approval context bundlesoversightpartialProduct Operationsyes
AI trace loggingobservabilityimplementedSecurity Engineeringno
AI trace retention and access controlprivacypartialSecurity Engineering and Privacyyes
AI release gateSDLCpartialProduct Securityno
AI incident response playbookoperationsmissingSecurity Operationsno
Enterprise AI questionnaire answer bankenterprise readinesspartialTrust and Securityno

Priority findings

Findings

Priority Control Gaps

Finding · high

No controls are yet validated

Evidence: ai-control-gap-assessment

Several controls are implemented or partially implemented, but none have enough validation evidence to be marked validated across the assessment scope.

Finding · critical

Seven control gaps block safe expansion

Evidence: ai-control-gap-assessment

Provider boundary, RAG authorization, source trust, tool inventory, permission matrix, approval bundles, and trace retention are release-blocking gaps.

Finding · medium

AI incident response is missing

Evidence: ai-incident-response-playbook

The AI incident response playbook is the only fully missing control in this sample, but it matters for trust-center readiness and operational maturity.

Finding · high

Buyer-facing gaps are concentrated in evidence

Evidence: enterprise-ai-security-evidence-pack

Many gaps are not purely technical. They affect what the company can safely claim to enterprise buyers.

Remediation waves

Control remediation waves

WaveThemeControls
0-30 daysBlock critical expansionRAG authorization, tool inventory, permission matrix, approval bundles
31-60 daysConvert posture into evidenceprovider boundary, trace retention, answer bank, source trust labeling
61-90 daysOperationalize repeatabilityrelease gate, incident response, risk tiering, trace logging
Decision · planned

Remediation sequence decision

Do not start with policy writing. Start with the release-blocking controls that protect retrieval, tools, approvals, traces, and provider claims.

Evidence expectations

Checklist

Evidence required to move from partial to validated

Architecture or design evidence.
Implementation owner.
Test or review evidence.
Runtime trace or configuration evidence where applicable.
Buyer-safe explanation.
Review cadence.
Exception process.
Retest criteria for failed or partial controls.

Related artifacts

Artifact

Related artifact: AI Risk Register

The risk register turns control gaps into owned risk decisions.

/deliverables/ai-risk-register
Artifact

Related artifact: AI Security Remediation Roadmap

The roadmap sequences remediation waves into owner-driven execution.

/deliverables/ai-security-remediation-roadmap
Artifact

Related artifact: AI Governance Evidence Matrix

The evidence matrix maps control gaps to governance and buyer proof.

/deliverables/ai-governance-evidence-matrix