Agents / Model Risk Management

Assurance Agent

ConfidentialAgent runLimited riskGovernance · BU Restricted · 61 runs / 30d

Runs the automated check battery on every submitted model and composed workflow: performance against the declared benchmarks, fairness tests across customer segments, explainability outputs, security and supply-chain scan of the artefact, PII leakage in prompts for GenAI assets, and licence scan of third-party components. Assembles the check report for Model Risk.

Governs the Alliance AI platform

Agent runAll governance agents →

An agent executes the process end to end and logs what it did. No human is in the path, because there is no discretion to exercise and no consequence to carry.

Acts for
Model Risk & Governance
Action class
read-only
Decisions / 30d
61
Safe-state returns / 30d
1

Processes covered

  • Automated assurance: performance, fairness, explainability, security, PII in prompts, licences
  • Conformance testing of composed workflows
  • Data residency and GenAI screening checks

Stages:Build & validateDeploy & integrateOperate & charge back

Memory

Retains check reports for the life of the asset version; purged on retirement.

Safe state

Marks the check as 'not run' and blocks routing to validation when any scanner is unavailable or the PII-in-prompt screen fails, rather than passing the stage.

Reviewer time per case: 0 min with this agent, 75 without.

Ownership and sensitivity

Owned by

Group Risk ManagementModel Risk Management

Accountable owner: Dr. Kavitha Subramaniam

Who approves access

  1. Owner, Model Risk Management, Dr. Kavitha Subramaniam
Confidential

Business-sensitive. Models and data products scoped to named business units.

Entitlement per business unit, approved by the owner; conditions attach.

Tools

  • Artefact and container scanner
  • SBOM, signature and licence scanner
  • Benchmark harness
  • Fairness and explainability suite
  • PII-in-prompt screen
  • Check-report writer

Data access scope

  • Read-only: artefacts, SBOMs, evaluation datasets referenced in the manifest
  • Read-only: check reports of comparable validated models
  • Write: check report attached to the case only

Guardrails

  • A failed security, licence or PII check blocks routing to validation automatically
  • Never modifies an artefact; findings are reported, not fixed
  • Anomaly flags always show the comparable set they were judged against

Human-in-the-loop

  • The Model Risk validator reads the check report before any validation opinion

Orchestration

Trigger / IntakeLLM Orchestratorpolicy-rag-copilotArtefact and container scan…SBOM, signature and licence…Benchmark harnessFairness and explainability…Humansign-off

Every tool call is scoped by the declared data access above; the orchestrator cannot reach systems outside it. Owning business unit: Group Data & AI.

Live demo run

Watch the agent execute a real scenario step by step, every tool call, validation, and human checkpoint is traced and auditable. Typical run: ~6.9s.

Used in workflows

Retiring this asset would require these chains to be re-pointed first.

Audit

Updated 2026-07-30. Run traces retained 24 months for audit under the platform governance policy.

Community · 0 threads

Questions, findings and requests from the business units that use this asset. Owners reply here; threads with upvotes surface to the owning team's inbox.

No threads yet. Be the first to ask, or to share what you found.