Skip to content

Latest commit

 

History

History
249 lines (206 loc) · 21.9 KB

File metadata and controls

249 lines (206 loc) · 21.9 KB

FSI Agent Governance Framework - Control Index

Complete Control Reference (78 Controls)

This directory contains comprehensive control documentation for the FSI Agent Governance Framework across four pillars. See the Solutions Index for the live catalog of 33 companion solutions aligned to the companion repository inventory.


Pillar 1: Security Controls (29 Controls)

Control ID Control Name Implementation
1.1 Restrict Agent Publishing by Authorization Portal / PowerShell, Hardening Baseline, UASD
1.2 Agent Registry and Integrated Apps Management Portal / PowerShell
1.3 SharePoint Content Governance and Permissions Portal / PowerShell
1.4 Advanced Connector Policies (ACP) Portal / PowerShell, FUS, SDM
1.5 Data Loss Prevention (DLP) and Sensitivity Labels Portal / PowerShell, Deny Event Correlation, SDM, MTR
1.6 Microsoft Purview: DSPM for AI Portal
1.7 Comprehensive Audit Logging and Compliance Portal / PowerShell, Deny Event Correlation, Hardening Baseline, ACM, FSW, CSI
1.8 Runtime Protection and External Threat Detection Portal, Hardening Baseline, CMM, FUS, CSI
1.9 Data Retention and Deletion Policies Portal / PowerShell
1.10 Communication Compliance Monitoring Portal, FSW, MTR
1.11 Conditional Access and Phishing-Resistant MFA Portal / PowerShell, SSC, CAA, CSI, MTR
1.12 Insider Risk Detection and Response Portal
1.13 Sensitive Information Types (SITs) and Pattern Recognition Portal / PowerShell, MTR
1.14 Data Minimization and Agent Scope Control Portal, CMM, FUS, SDM, CSI, MTR
1.15 Encryption: Data in Transit and at Rest Portal
1.16 Information Rights Management (IRM) for Documents Portal / PowerShell
1.17 Endpoint Data Loss Prevention (Endpoint DLP) Portal
1.18 Application-Level Authorization and Role-Based Access Control (RBAC) Portal / PowerShell, Hardening Baseline, ASARD, CAA
1.19 eDiscovery for Agent Interactions Portal / PowerShell
1.20 Network Isolation and Private Connectivity Portal
1.21 Adversarial Input Logging Portal
1.22 Information Barriers for AI Agents Portal / PowerShell
1.23 Step-Up Authentication for AI Agent Operations Portal, ACA, SSC, CAA, ITE, CSI
1.24 Defender AI Security Posture Management (AI-SPM) Portal
1.25 MIME Type Restrictions for File Uploads PowerShell + Portal, MTR
1.26 Agent File Upload and File Analysis Restrictions Portal / PowerShell
1.27 AI Agent Content Moderation Enforcement Portal / PowerShell, CMM
1.28 Policy-Based Agent Publishing Restrictions Portal / PowerShell
1.29 Global Secure Access: Network Controls for Copilot Studio Agents Portal / PowerShell

Pillar 2: Management Controls (26 Controls)

Control ID Control Name Implementation
2.1 Managed Environments Portal / PowerShell, ELM, Hardening Baseline, SoDD
2.2 Environment Groups and Tier Classification Portal / PowerShell, ELM
2.3 Change Management and Release Planning Portal / PowerShell, Message Center Monitor, Pipeline Cleanup, SoDD
2.4 Business Continuity and Disaster Recovery Portal / PowerShell
2.5 Testing, Validation, and Quality Assurance Portal / PowerShell
2.6 Model Risk Management (Alignment with OCC 2011-12/SR 26-2 (formerly SR 11-7)) Portal, MRM
2.7 Vendor and Third-Party Risk Management Portal
2.8 Access Control and Segregation of Duties Portal / PowerShell, ASARD, SoDD
2.9 Agent Performance Monitoring and Optimization Portal, AOF, CSA, HT, MRM
2.10 Patch Management and System Updates Portal, Message Center Monitor
2.11 Bias Testing and Fairness Assessment Portal
2.12 Supervision and Oversight (FINRA Rule 3110) Portal, FSW
2.13 Documentation and Record Keeping Portal
2.14 Training and Awareness Program Portal
2.15 Environment Routing and Auto-Provisioning Portal / PowerShell, ELM
2.16 RAG Source Integrity Validation Portal, RSV
2.17 Multi-Agent Orchestration Limits Portal, ACRD
2.18 Automated Conflict of Interest Testing Portal, COI
2.19 Customer AI Disclosure and Transparency Portal
2.20 Adversarial Testing and Red Team Framework Portal
2.21 AI Marketing Claims and Substantiation Portal
2.22 Inactivity Timeout Enforcement PowerShell + Portal, ITE
2.23 User Consent and AI Disclosure Enforcement Portal / PowerShell
2.24 Agent Feature Enablement and Restriction Governance Portal / PowerShell, GAICA
2.25 Microsoft Agent 365 — Admin Center Governance Console Portal / PowerShell
2.26 Entra Agent ID — Identity Governance for Agents Portal / PowerShell

Pillar 3: Agent Reporting (14 Controls)

Control ID Control Name Implementation
3.1 Agent Inventory and Metadata Management Portal / PowerShell, CD
3.2 Usage Analytics and Activity Monitoring Portal, CD, CSA
3.3 Compliance and Regulatory Reporting Portal, CD, MTR
3.4 Incident Reporting and Root Cause Analysis Portal, Deny Event Correlation
3.5 Cost Allocation and Budget Tracking Portal
3.6 Orphaned Agent Detection and Remediation Portal / PowerShell
3.7 PPAC Security Posture Assessment Portal, Hardening Baseline, ITE, MTR
3.8 Copilot Hub Portal, Hardening Baseline, UASD, AAM, ITE, CSI
3.9 Microsoft Sentinel Integration Portal / PowerShell, AOF
3.10 Hallucination Feedback Loop Portal, HT
3.11 Centralized Agent Inventory Enforcement Portal / PowerShell
3.12 Agent Governance Exception and Override Management Portal / PowerShell
3.13 Agent 365 Admin Center Analytics and Reporting Portal / PowerShell
3.14 Agent 365 Observability SDK and Custom Agent Telemetry Portal / PowerShell

Pillar 4: SharePoint Advanced Management (9 Controls)

Control ID Control Name Implementation
4.1 SharePoint Information Access Governance (IAG) / Restricted Content Discovery Portal / PowerShell
4.2 Site Access Reviews and Certification Portal
4.3 Site and Document Retention Management Portal / PowerShell, AKSS, MTR
4.4 Guest and External User Access Controls Portal / PowerShell
4.5 SharePoint Security and Compliance Monitoring Portal
4.6 Grounding Scope Governance Portal
4.7 Microsoft 365 Copilot Data Governance Portal
4.8 Item-Level Permission Scanning for Agent Knowledge Sources PowerShell, AKSS
4.9 Embedded File Content Governance Portal / PowerShell

Implementation Reference Legend

The Implementation column indicates how each control is implemented:

Reference Meaning
Portal Configured through Microsoft admin portals (PPAC, Purview, Entra, etc.)
PowerShell Automated via PowerShell cmdlets
Solution Link Deployable automation from FSI-AgentGov-Solutions

Companion solutions provide deployment documentation, governance scripts, KQL queries, and templates that help operationalize controls at scale. See Solutions Index for the live catalog of 33 companion solutions.


How to Use This Framework

  1. Review the Overview - Start with the framework overview to understand the 3 zones and 4 pillars
  2. Assess Current State - For each control, review your current implementation level (Baseline, Recommended, or Regulated)
  3. Implement Controls - Follow the implementation guidance in each control file
  4. Verify & Document - Use the verification steps to confirm implementation and document evidence
  5. Establish Recurring Reviews - Schedule quarterly reviews to ensure controls remain effective

Governance Levels

Each control is documented with three governance levels:

  • Baseline: Minimum required implementation
  • Recommended: Best practice implementation for Zone 2+ agents
  • Regulated/High-Risk: Comprehensive implementation for Zone 3 agents and regulated environments

Pillar Descriptions

Pillar 1: Security Controls (29 Controls)

Focus: Protect data and systems from unauthorized access, misuse, and exploitation.

  • Authentication and Authorization
  • Data Loss Prevention
  • Audit Logging
  • Encryption
  • Threat Detection
  • eDiscovery
  • Network Isolation
  • Adversarial Input Protection
  • Information Barriers
  • Step-Up Authentication
  • File Upload Governance
  • Content Moderation
  • Publishing Restrictions
  • AI Security Posture Management
  • Global Secure Access

Pillar 2: Management Controls (26 Controls)

Focus: Govern the agent lifecycle, access control, change management, and model risk.

  • Managed Environments
  • Change Management
  • Business Continuity
  • Testing & Validation
  • Model Risk Management
  • Vendor Management
  • Training & Supervision
  • RAG Source Validation
  • Multi-Agent Orchestration
  • Conflict of Interest Testing
  • Customer AI Disclosure
  • Adversarial Testing & Red Teaming
  • AI Marketing Claims & Substantiation
  • Inactivity Timeout Enforcement
  • User Consent & AI Disclosure
  • Feature Enablement Governance
  • Agent 365 Governance Console
  • Entra Agent ID Governance

Pillar 3: Agent Reporting (14 Controls)

Focus: Visibility and monitoring of agent activities, performance, and compliance.

  • Agent Inventory
  • Usage Analytics
  • Compliance Reporting
  • Incident Management
  • Cost Tracking
  • Orphaned Agent Detection
  • PPAC Security Posture
  • Copilot Hub
  • Sentinel Integration
  • Hallucination Feedback
  • Centralized Inventory Enforcement
  • Exception & Override Management
  • Agent 365 Admin Center Analytics
  • Custom Agent Telemetry

Pillar 4: SharePoint Advanced Management (9 Controls)

Focus: Govern SharePoint content accessed by agents with specific access, retention, and security controls.

  • Information Access Governance
  • Access Reviews
  • Retention Management
  • Guest Access Controls
  • Security Monitoring
  • Grounding Scope Governance
  • M365 Copilot Data Governance
  • Item-Level Permission Scanning for Agent Knowledge Sources
  • Embedded File Content Governance

Regulatory Alignment

The framework covers compliance requirements for:

  • FINRA: Rules 3110, 4511, 4512, 2111 (Suitability)
  • SEC: Rules 17a-3/4, 10b-5, Reg BI, Reg S-P
  • SOX: Sections 302, 404 (internal controls and reporting)
  • GLBA: Sections 501, 504, 505 (safeguards and privacy)
  • OCC: Bulletin 2011-12 and SR 26-2 (formerly SR 11-7) (model risk management)
  • Federal Reserve: SR 26-2 (formerly SR 11-7) (model risk, fair lending)

Governance Zones

Controls are documented for implementation in three governance zones:

  • Zone 1: Personal Productivity - Individual development, low risk
  • Zone 2: Team Collaboration - Departmental agents, medium risk
  • Zone 3: Enterprise Managed - Organization-wide, high risk, customer-facing

Questions & Support

For questions about specific controls or implementation guidance:

  • Review the control file for detailed verification steps
  • Contact your AI Governance Lead
  • Escalate to Compliance Officer for regulatory questions
  • Contact your technical implementation team for platform-specific guidance

FSI Agent Governance Framework v1.4.0 - April 2026