Three Lines Model

Ownership, oversight and independent assurance, and where architecture sits in it.

5Questions
13Flashcards
3Terms
Assurance, Audit & Model Risk

Neighbouring topics

Assurance, Audit & Model Risk

General material on assurance, architectural governance and risk oversight.

4 quiz 9 cards 2 terms

Control Design vs Operation

A control that is well designed and never runs fails exactly like one that is absent.

3 quiz 8 cards 4 terms

Audit Evidence

Producing durable, tamper-evident proof as a by-product rather than as a project.

4 quiz 9 cards 4 terms

Certification Impact on Architecture

What SOC 2 and ISO 27001 actually require of a design, and what they do not.

5 quiz 9 cards 3 terms

Continuous Controls Monitoring

Testing controls continuously instead of sampling them once a year.

6 quiz 8 cards 5 terms

Segregation of Duties

Splitting authority so no single actor can both make and approve a change.

5 quiz 9 cards 5 terms

Change Advisory vs Automated Gates

Replacing a weekly board with evidence a machine produces on every change.

6 quiz 12 cards 3 terms

Risk Appetite

The stated tolerance that tells you which risks you are allowed to accept.

5 quiz 11 cards 3 terms

Risk Assessment Methods

Qualitative matrices, FAIR and scenario analysis, and the illusion of a precise score.

4 quiz 10 cards 3 terms

Security Design Review

Reviewing an architecture for security while changing it is still cheap.

5 quiz 7 cards 3 terms

Architecture Compliance Checks

Automating conformance to standards so review effort goes to the genuinely novel.

5 quiz 11 cards 5 terms

Exception & Waiver Management

Time-boxed, owned deviations with a remediation date, rather than permanent silence.

6 quiz 12 cards 5 terms

Design Authority

How an ARB should decide, what it should not review, and how it avoids becoming a queue.

5 quiz 10 cards 2 terms

Model Risk Management

Inventory, validation, monitoring and challenge for models that make consequential decisions.

5 quiz 7 cards 5 terms

AI Risk Tiering

Classifying a use case by potential harm, and the obligations each tier triggers.

5 quiz 11 cards 3 terms

Model Documentation

Model cards, intended use, limitations, and the record a regulator will ask for.

5 quiz 10 cards 2 terms

Model Evaluation & Red-Teaming

Adversarial testing of a probabilistic system with no fixed expected output.

4 quiz 10 cards 3 terms

Bias & Fairness Controls

Measuring disparate outcomes, choosing a fairness definition, and living with the trade-off.

6 quiz 10 cards 3 terms

Human-in-the-Loop Design

Meaningful review rather than a rubber stamp, and designing against automation bias.

5 quiz 11 cards 3 terms