AI 扩展计划 / Playbooks
ABPA 模板 05:AI Control Pack
52 行abpa/templates/05-ai-control-pack.md
AI Control Pack
Use this to turn AI risk into architecture, process, and monitoring controls.
1. Control Register
| Control ID | Risk | Scenario | Preventive control | Detective control | Corrective control | Evidence | Owner |
|---|---|---|---|---|---|---|---|
| C-001 | Hallucination |
2. Risk Coverage
| Risk class | Required? | Control IDs | Residual risk |
|---|---|---|---|
| Hallucination / unsupported claim | yes / no | ||
| Prompt injection | yes / no | ||
| Privacy leakage | yes / no | ||
| Bias / unfair outcome | yes / no | ||
| Over-reliance | yes / no | ||
| Unsafe automation | yes / no | ||
| Stale knowledge | yes / no | ||
| Tool / model outage | yes / no | ||
| Audit failure | yes / no | ||
| Cost runaway | yes / no |
3. Human Oversight
| Decision / output | Human role | Required evidence | Override rule | Audit field |
|---|---|---|---|---|
| review / approve / reject / escalate |
4. Monitoring Signals
| Signal | Source | Threshold | Response |
|---|---|---|---|
| Invalid citation rate | |||
| Manual override rate | |||
| Escalation rate | |||
| Prompt injection block rate | |||
| Model error / timeout rate | |||
| Cost per case |
5. Governance Cadence
| Activity | Frequency | Owner | Evidence |
|---|---|---|---|
| Control review | |||
| Eval refresh | |||
| Prompt/tool change review | |||
| Model/provider review | |||
| Incident drill |