What the 230 control objectives already answer.
The CRI Financial Services AI Risk Management Framework contains 230 control objectives — the most operationally specific AI governance artefact the financial sector has produced. We mapped every one of them against the eight MARQUE questions. The distribution is the finding: documentation and oversight are heavily covered, and the questions specific to autonomous action are not.
Coverage by question.
| Question | What it asks | Objectives | Share | Assessment |
|---|---|---|---|---|
| Authority | What is the agent permitted to commit, and who granted that? | 39 | 17% | Partial |
| Oversight | Who is accountable in the interval between decision and review? | 110 | 48% | Well covered |
| Drift | How is behavioural change detected before it becomes loss? | 11 | 5% | Thin |
| Auditability | Can a decision be reconstructed months later, exactly? | 131 | 57% | Well covered |
| Accountability | When it goes wrong, who answers? | 55 | 24% | Well covered |
| Identity | What is the agent, legally, and to whom does its output belong? | 32 | 14% | Partial |
| Systemic behaviour | What happens when many agents converge on the same trade? | 16 | 7% | Thin |
| Standards & interoperability | What does conformance actually mean here? | 62 | 27% | Well covered |
A control objective may serve more than one question, so the column sums above 230. 18 of the 230 map to no MARQUE question — largely fairness, privacy and human-subject controls that matter but sit outside the authority-to-act problem.
The finding.
Auditability and oversight dominate. That is what a framework built by risk and compliance functions produces, and it is not a criticism — those controls are real and they are the ones examiners will test first.
But the thin columns are drift (11), systemic behaviour (16), identity (32), and they are thin in a specific way. The framework governs an AI system that an institution operates. It does not govern an agent that acts — because at v1.0 it was not written to, and because the vocabulary for delegated authority did not exist in the sector's own lexicon.
An institution that implements all 230 control objectives has built a genuinely strong AI risk programme and has still not answered what its agent is permitted to commit, who granted that, and what happens when many agents do the same thing at once.
Those are not exotic questions. They are the first questions an examiner will ask once agentic deployment is visible, and the existing control set does not reach them.
Method, stated plainly.
This mapping is editorial. Each of the 230 control objectives was assessed against the eight questions using its objective text and its named risk statement. A first pass used terminology matching; the assignment is judgement, and judgement can be wrong.
Two things follow from that. First, the underlying data is published as JSON so you can re-derive it, disagree with specific assignments, and show your working. Second, if you think a mapping is wrong we would rather hear it than not — corrections are published with attribution.
What is not editorial: the 230 count, the function breakdown, and the objective text. Those come directly from the published Risk and Control Matrix v1.0 and can be checked against it.