Skip to content

Mapping to the FINOS AI Governance Framework

Generated by scripts/check_air_mapping.py from docs/air/catalogue.yaml and docs/air/mapping.yaml. Edit the YAML, not this file.

Every risk and every mitigation in the framework has exactly one entry, including the ones this project does not address. The script fails if an item is missing, if an entry names a knob or lint rule that does not exist in the code, or if the catalogue changes without the mapping.

Source

  • Framework: https://github.com/finos/ai-governance-framework at commit aabbffbe02a4 (2026-09-09), CC-BY-4.0. Titles, ids, types and the mitigates relation only. Text belongs to FINOS. The site labels this release v2.
  • This is one reviewer's reading. Have someone who owns the framework at your organisation check it before it is published.

How to read the statuses

Status Meaning
implemented This repo validates or computes it, with tests in this repo.
declared This repo carries the setting in the signed bundle. Enforcement is in mediatore, mediatore-guest or the gateway.
partial Some of the above, and the gap column says what is missing.
gap In scope for a sandbox policy layer, and nothing exists yet.
out_of_scope Not a sandbox policy concern, such as model quality, bias or training data.

Two limits apply to everything below. Nothing in this repo has run on a cluster yet. And "enforced elsewhere" names where enforcement belongs, it does not claim those components do it today.

Summary

implemented declared partial gap out_of_scope
Risks (23) 1 0 12 1 9
Mitigations (23) 1 2 12 2 6

Risks

ID Title Status In this repo Note Gap Enforced elsewhere
AIR-RC-001 Information Leaked To Hosted Model partial K4.1, K4.3, K4.4, K1.4
L007, L003
DataScope
Egress allowlist decides which model endpoints the sandbox can reach, volume caps and output export bound what leaves. Nothing classifies the data sent to a model. No data classification of prompt content. Audience classification is ROADMAP M4.
AIR-SEC-002 Information Leaked to Vector Store out_of_scope none No vector store is part of the sandbox.
AIR-OP-004 Hallucination and Inaccurate Outputs out_of_scope none Model output quality.
AIR-OP-005 Foundation Model Versioning gap K8.1 K8.1 pins the image, and with it the agent CLI. The model an agent may call is not in the spec. A model allowlist or pin could be a policy field rendered into managed settings.
AIR-OP-006 Non-Deterministic Behaviour out_of_scope none Model behaviour.
AIR-OP-007 Availability of Foundational Model partial K2.4, K4.3, K7.3
L009
Budgets, ceilings
Tool call, wall clock and egress byte budgets and lease ceilings cap consumption. No token or spend budget, so Denial of Wallet is only bounded by time and call count.
AIR-SEC-008 Tampering With the Foundational Model partial K8.1, K1.3
L008
Image source and tool pinning protect what runs in the sandbox. Hosted model weights and provider tampering are outside this project.
AIR-SEC-009 Data Poisoning out_of_scope none Training and fine-tuning data.
AIR-SEC-010 Prompt Injection partial K1.1, K1.2, K1.3, K3.3, K4.1, K1.4
L003
L003 refuses the combination of sensitive data, untrusted content and an outbound channel, so a successful injection has no path out. Injection itself is not prevented. Guard hook in mediatore-guest renders K3.3.
AIR-OP-014 Inadequate System Alignment out_of_scope none RAG response alignment.
AIR-OP-016 Bias and Discrimination out_of_scope none Model fairness.
AIR-OP-017 Lack of Explainability partial K8.3 K8.3 sets how much is logged. Reasoning capture is undefined. See AIR-DET-021 for the tiering that K8.3 steps should map to.
AIR-OP-018 Model Overreach / Expanded Use partial K7.2, K1.3
L011, L012, L013, L010
KnobGrant, SandboxProfile
Scope is a reviewed profile, widening it is a time-boxed, approved, one-step KnobGrant. This bounds how far a sandbox policy can drift, not how a business team uses the output. How the output is used in the business is outside the policy.
AIR-OP-019 Data Quality and Drift out_of_scope none Model data freshness.
AIR-OP-020 Reputational Risk out_of_scope none Consequence of other risks. Containment reduces it indirectly.
AIR-RC-022 Regulatory Compliance and Oversight partial K8.3, K8.2
L013
signed bundle, KnobGrant, gitops-only admission
Every policy version is signed, numbered and traceable to a grant with named approvers, K8.3 has a Compliance approver role. No retention period or records-class field, so the record-keeping obligations the framework names are not expressed.
AIR-RC-023 Intellectual Property (IP) and Copyright out_of_scope none Copyright in model output. Egress and export controls only help with trade secret leakage.
AIR-SEC-024 Agent Action Authorization Bypass implemented K5.1, K5.2, K5.3, K5.4, K5.5, K3.2, K2.1, K7.4
L005, L006, L007, L008, L009, L011, L012, L013
ceilings, status.maxExposure, KnobGrant
Policy side: deny by default, read-only tokens, no wildcard audiences, expiring relaxations, computed maximum exposure. Enforcement is in mediatore, guest and gateway. mediatore, mediatore-guest, gateway. Not verified here.
AIR-SEC-025 Tool Chain Manipulation and Injection partial K1.3, K3.3, K2.1
L008
Tools are pinned by digest and the guard strictness is carried in the bundle. Parameter and call-sequence rules are not modelled.
AIR-SEC-026 MCP Server Supply Chain Compromise partial K1.3
L008
MCP servers must be pinned by manifest digest. No vetting workflow or evidence of review is recorded.
AIR-SEC-027 Agent State Persistence Poisoning partial K6.1, K1.2 Tenancy tier and project instruction loading. One VM per lease that is destroyed afterwards is a banlieue and mediatore rule. Nothing in the spec says whether a workspace may persist between leases.
AIR-OP-028 Multi-Agent Trust Boundary Violations partial K6.1, K5.6 One identity and one VM per subject, carried as settings. banlieue, mediatore
AIR-SEC-029 Agent-Mediated Credential Discovery and Harvesting partial K3.1, K5.1, K5.2, K5.3, K5.4
L005, L006
Short, read-only, audience-bound tokens and credential delivery mode. No detection of credential discovery behaviour. mediatore-guest delivers credentials.

Which framework mitigations address each risk

The framework declares this relation. It is listed so a risk marked implemented or partial can be checked against the controls the framework expects for it.

Risk Framework mitigations
AIR-RC-001 AIR-DET-001, AIR-PREV-002, AIR-DET-004, AIR-PREV-006, AIR-PREV-007, AIR-PREV-012, AIR-DET-015, AIR-PREV-020
AIR-SEC-002 AIR-PREV-006, AIR-PREV-014, AIR-DET-016
AIR-OP-004 AIR-PREV-005, AIR-PREV-006, AIR-DET-013, AIR-DET-015
AIR-OP-005 AIR-DET-004, AIR-PREV-005, AIR-PREV-010, AIR-DET-011, AIR-DET-015
AIR-OP-006 AIR-DET-004, AIR-PREV-005, AIR-PREV-010, AIR-DET-011, AIR-DET-015
AIR-OP-007 AIR-PREV-003, AIR-DET-004, AIR-PREV-008, AIR-DET-009, AIR-PREV-017
AIR-SEC-008 AIR-PREV-007, AIR-PREV-012, AIR-PREV-020
AIR-SEC-009 AIR-PREV-002, AIR-PREV-006, AIR-PREV-012
AIR-SEC-010 AIR-PREV-003, AIR-PREV-017, AIR-PREV-019
AIR-OP-014 AIR-DET-004, AIR-PREV-005, AIR-DET-011, AIR-DET-015
AIR-OP-016 AIR-PREV-005, AIR-PREV-006, AIR-DET-011, AIR-DET-015
AIR-OP-017 AIR-DET-013
AIR-OP-018 AIR-PREV-003, AIR-DET-004, AIR-DET-011, AIR-PREV-017, AIR-PREV-018
AIR-OP-019 AIR-DET-004, AIR-PREV-006, AIR-DET-015
AIR-OP-020 AIR-PREV-003, AIR-PREV-007, AIR-DET-011, AIR-DET-013, AIR-PREV-017
AIR-RC-022 AIR-PREV-005, AIR-PREV-006, AIR-PREV-007, AIR-DET-013, AIR-PREV-014, AIR-DET-016, AIR-DET-021
AIR-RC-023 AIR-PREV-006, AIR-PREV-007
AIR-SEC-024 AIR-DET-004, AIR-PREV-018, AIR-PREV-019, AIR-DET-021, AIR-PREV-022, AIR-PREV-023
AIR-SEC-025 AIR-DET-004, AIR-PREV-019, AIR-DET-021
AIR-SEC-026 AIR-DET-004, AIR-PREV-020, AIR-PREV-023
AIR-SEC-027 AIR-DET-004, AIR-PREV-022
AIR-OP-028 AIR-DET-004, AIR-PREV-022
AIR-SEC-029 AIR-DET-004, AIR-PREV-023

Mitigations

ID Title Status In this repo Note Gap Enforced elsewhere
AIR-DET-001 AI Data Leakage Prevention and Detection partial K4.3, K4.4, K1.4
L009
Volume caps bound exfiltration. TLS inspection is the only content inspection hook, and its loosest step is R1. No data loss detection rules.
AIR-PREV-002 Data Filtering From External Knowledge Bases out_of_scope none Knowledge base ingestion.
AIR-PREV-003 User/App/Model Firewalling/Filtering declared K4.1, K4.2, K4.4
L007
Allowlist entries are validated here, filtering is done by the gateway. gateway
AIR-DET-004 AI System Observability partial status conditions, KnobGrant status Controller status shows version, digest, exposure and lint conditions. No metrics endpoint or events until ROADMAP M2. Decision audit is mediatore's.
AIR-PREV-005 System Acceptance Testing gap none Knob prerequisites are not proven by control tests. Grants record approvals, not test results.
AIR-PREV-006 Data Quality & Classification/Sensitivity partial DataScope Two data scopes, LabOnly and Internal. Audience classification is ROADMAP M4.
AIR-PREV-007 Legal and Contractual Frameworks for AI Systems out_of_scope none Contracts and legal review.
AIR-PREV-008 Quality of Service (QoS) and DDoS Prevention for AI Systems partial K7.3
L009
Lease concurrency and duration ceilings. Rate limiting at the gateway.
AIR-DET-009 AI System Alerting and Denial of Wallet (DoW) / Spend Monitoring partial L009
Budgets
Budgets cap use. No spend or token dimension, no alerting until ROADMAP M2.
AIR-PREV-010 AI Model Version Pinning gap none See AIR-OP-005. A model pin is not a policy field.
AIR-DET-011 Human Feedback Loop for AI Systems out_of_scope none K3.2 is approval of actions, not a feedback loop on output quality.
AIR-PREV-012 Role-Based Access Control for AI Data partial K7.2, K5.2, K5.3
L005, L006, L010
Subjects, eligibility and audience scoping. Scoping stops at the audience and token. Access control inside the downstream data store is that system's.
AIR-DET-013 Providing Citations and Source Traceability for AI-Generated Information out_of_scope none Output citation.
AIR-PREV-014 Encryption of AI Data at Rest out_of_scope none Disk encryption is a VM concern. banlieue installMode Deferred with vTPM and LUKS, see the banlieue design.
AIR-DET-015 Using Large Language Models for Automated Evaluation (LLM-as-a-Judge) out_of_scope none Model evaluation.
AIR-DET-016 Preserving Source Data Access Controls in AI Systems partial K5.6 Identity type is carried. Token delegation chain is mediatore's. mediatore
AIR-PREV-017 AI Firewall Implementation and Management declared K4.1, K4.4
L007
Same as AIR-PREV-003. gateway
AIR-PREV-018 Agent Authority Least Privilege Framework implemented K5.1, K5.2, K5.3, K5.5, K7.3, K7.4, K3.2
L005, L006, L009, L011, L012, L013
SandboxProfile, SandboxPolicy, KnobGrant, ceilings, status.maxExposure
Role and privilege definition is the profile and policy, dynamic privilege is the expiring grant with renewal re-evaluation, approval workflow is K3.2 and grant approvals, exposure is computed. Enforcement at the API and tool layer is downstream. Agent behaviour monitoring is not modelled. mediatore, mediatore-guest, gateway. Not verified here.
AIR-PREV-019 Tool Chain Validation and Sanitization partial K1.3, K3.3
L008
Tool selection is limited to pinned tools. Parameter validation and sequence validation rules are not in the spec.
AIR-PREV-020 MCP Server Security Governance partial K1.3, K4.1
L008
Pre-approved servers pinned by digest, with egress through the gateway. That resembles the framework's pre-approved tier, it has not been checked against that tier's requirements. No vetting, onboarding or incident response content.
AIR-DET-021 Agent Decision Audit and Explainability partial K8.3
signed bundle version
The policy version is stamped into tokens so decisions can be traced to a policy. K8.3 steps are not mapped to the framework's retention tiers, and reasoning capture is undefined. Audit events come from mediatore and the guest hook.
AIR-PREV-022 Multi-Agent Isolation and Segmentation partial K6.1, K5.6 Tenancy tier and identity type are carried. banlieue VM per identity, mediatore attestation.
AIR-PREV-023 Agentic System Credential Protection Framework partial K3.1, K5.1, K5.2, K5.3, K5.4
L005, L006
Just-in-time, short-lived, scoped credentials are policy. Delivery and environment isolation are downstream. No behavioural detection. mediatore-guest

Open gaps

  • AIR-RC-001 Information Leaked To Hosted Model: No data classification of prompt content. Audience classification is ROADMAP M4.
  • AIR-OP-005 Foundation Model Versioning: A model allowlist or pin could be a policy field rendered into managed settings.
  • AIR-OP-007 Availability of Foundational Model: No token or spend budget, so Denial of Wallet is only bounded by time and call count.
  • AIR-SEC-008 Tampering With the Foundational Model: Hosted model weights and provider tampering are outside this project.
  • AIR-OP-017 Lack of Explainability: Reasoning capture is undefined. See AIR-DET-021 for the tiering that K8.3 steps should map to.
  • AIR-OP-018 Model Overreach / Expanded Use: How the output is used in the business is outside the policy.
  • AIR-RC-022 Regulatory Compliance and Oversight: No retention period or records-class field, so the record-keeping obligations the framework names are not expressed.
  • AIR-SEC-025 Tool Chain Manipulation and Injection: Parameter and call-sequence rules are not modelled.
  • AIR-SEC-026 MCP Server Supply Chain Compromise: No vetting workflow or evidence of review is recorded.
  • AIR-SEC-027 Agent State Persistence Poisoning: Nothing in the spec says whether a workspace may persist between leases.
  • AIR-SEC-029 Agent-Mediated Credential Discovery and Harvesting: No detection of credential discovery behaviour.
  • AIR-DET-001 AI Data Leakage Prevention and Detection: No data loss detection rules.
  • AIR-DET-004 AI System Observability: No metrics endpoint or events until ROADMAP M2. Decision audit is mediatore's.
  • AIR-PREV-005 System Acceptance Testing: Knob prerequisites are not proven by control tests. Grants record approvals, not test results.
  • AIR-PREV-006 Data Quality & Classification/Sensitivity: Audience classification is ROADMAP M4.
  • AIR-DET-009 AI System Alerting and Denial of Wallet (DoW) / Spend Monitoring: No spend or token dimension, no alerting until ROADMAP M2.
  • AIR-PREV-010 AI Model Version Pinning: See AIR-OP-005. A model pin is not a policy field.
  • AIR-PREV-012 Role-Based Access Control for AI Data: Scoping stops at the audience and token. Access control inside the downstream data store is that system's.
  • AIR-PREV-018 Agent Authority Least Privilege Framework: Agent behaviour monitoring is not modelled.
  • AIR-PREV-019 Tool Chain Validation and Sanitization: Parameter validation and sequence validation rules are not in the spec.
  • AIR-PREV-020 MCP Server Security Governance: No vetting, onboarding or incident response content.
  • AIR-DET-021 Agent Decision Audit and Explainability: K8.3 steps are not mapped to the framework's retention tiers, and reasoning capture is undefined.
  • AIR-PREV-023 Agentic System Credential Protection Framework: No behavioural detection.