QIS-T-700 QISTRUST.COM THE GOVERNANCE LAYER REV 2026-08-02 · BUILD 13.0
The Governance Layer · Crosswalk

What the 230 control objectives already answer.

The CRI Financial Services AI Risk Management Framework contains 230 control objectives — the most operationally specific AI governance artefact the financial sector has produced. We mapped every one of them against the eight MARQUE questions. The distribution is the finding: documentation and oversight are heavily covered, and the questions specific to autonomous action are not.

QIS-T-700·230 control objectives·FS AI RMF v1.0, 9 February 2026·Verified 2026-08-02

Coverage by question.

MARQUE question → control objectives addressing it (n = 230)
QuestionWhat it asksObjectivesShareAssessment
AuthorityWhat is the agent permitted to commit, and who granted that?3917%Partial
OversightWho is accountable in the interval between decision and review?11048%Well covered
DriftHow is behavioural change detected before it becomes loss?115%Thin
AuditabilityCan a decision be reconstructed months later, exactly?13157%Well covered
AccountabilityWhen it goes wrong, who answers?5524%Well covered
IdentityWhat is the agent, legally, and to whom does its output belong?3214%Partial
Systemic behaviourWhat happens when many agents converge on the same trade?167%Thin
Standards & interoperabilityWhat does conformance actually mean here?6227%Well covered

A control objective may serve more than one question, so the column sums above 230. 18 of the 230 map to no MARQUE question — largely fairness, privacy and human-subject controls that matter but sit outside the authority-to-act problem.

The finding.

Auditability and oversight dominate. That is what a framework built by risk and compliance functions produces, and it is not a criticism — those controls are real and they are the ones examiners will test first.

But the thin columns are drift (11), systemic behaviour (16), identity (32), and they are thin in a specific way. The framework governs an AI system that an institution operates. It does not govern an agent that acts — because at v1.0 it was not written to, and because the vocabulary for delegated authority did not exist in the sector's own lexicon.

What this means practically

An institution that implements all 230 control objectives has built a genuinely strong AI risk programme and has still not answered what its agent is permitted to commit, who granted that, and what happens when many agents do the same thing at once.

Those are not exotic questions. They are the first questions an examiner will ask once agentic deployment is visible, and the existing control set does not reach them.

Method, stated plainly.

This mapping is editorial. Each of the 230 control objectives was assessed against the eight questions using its objective text and its named risk statement. A first pass used terminology matching; the assignment is judgement, and judgement can be wrong.

Two things follow from that. First, the underlying data is published as JSON so you can re-derive it, disagree with specific assignments, and show your working. Second, if you think a mapping is wrong we would rather hear it than not — corrections are published with attribution.

What is not editorial: the 230 count, the function breakdown, and the objective text. Those come directly from the published Risk and Control Matrix v1.0 and can be checked against it.