Paul Miles — AI and Data Assurance Pathway + Contract Toolkit
Tag: S-2026-05-06-paul-ai-data-pathway
Type: own-writing
Author(s): Paul Miles (Red Strata)
Date of source: 2026-05-06
Date ingested: 2026-05-17
Authority weight: own-writing.
Raw file: Open Brain corpus snapshot at /_raw_sources/open-brain-2026-05-17-corpus.md. Documents on disk: C:\Users\pgmil\OneDrive\Documents\_ClaudeWorkspace\04 Ai and Data services\AI_Data_Assurance_Pathway.docx and .md.
What it claims
A senior-practitioner Learning & Development pathway for an AI and Data assurance capability targeted at EU banking and capital markets. Output mix: practitioner artefacts, structured reading, hands-on labs (explicitly not formal certifications). Regulatory scope: EU only (EU AI Act, EBA, ESMA). FS sub-sector: banking / capital markets. Starting level: senior on both audit/risk and AI/data — refresh + edge.
Practitioner artefacts to build out (~30 named):
- AI System Inventory template
- Regulatory Crosswalk
- AIMS Statement of Applicability (ISO 42001)
- AI Use-Case Intake Form
- AI Ethics Board pack template
- AI Literacy curriculum spec
- Data Lineage Evidence Pack
- AI Dataset Datasheet (extending Gebru et al.) tailored to AI Act Art 10
- DPIA template for AI
- RAG Corpus Control Checklist
- Model Validation Report (mappable to AI Act Annex IV)
- LLM Evaluation Plan
- Fairness Testing Workpaper
- Agent Control Surface Diagram
- Agent Threat Model (OWASP Agentic + MITRE ATLAS)
- Eval Plan for GenAI / Agentic
- Human-in-the-Loop Decision Matrix
- Tool Registry & Approval Workflow
- Prompt Change Control SOP
- AI Logging & Evidence Specification (Art 12)
- Drift Monitoring Plan
- AI Change Control SOP
- AI Incident Response Playbook
- AI Vendor DDQ
- AI Contract Clause Library (DORA Art 30 + AI Act Arts 25, 53)
- AI Supply-Chain Concentration Heatmap
- Foundation-Model Exit Plan
- AI Threat Model (ATLAS-aligned)
- AI Red-Team Test Case Library
- AI 3LoD RACI
- Annual AI Assurance Plan
- AI Control-Evidence Calendar
- AI Risk Board Pack
- Internal Audit AI Engagement Plan
Areas requiring further research (Paul’s own flag, 6 May 2026):
- AI Act harmonised standards from CEN-CENELEC JTC 21 not yet fully published; Digital Omnibus may delay the 2 Aug 2026 high-risk obligations.
- EBA / ESMA implementing guidance on AI Act for FS — EBA stated no immediate new guidelines but a 2026–2027 supervisory convergence programme; concrete control expectations beyond the November 2025 factsheet still pending.
- Agent assurance best practice — OWASP Agentic Top 10 (Dec 2025) and MITRE ATLAS agentic techniques (Oct 2025 – Feb 2026) are recent and no FS-supervisor formal expectations yet.
- GPAI systemic-risk evaluation methodology from the AI Office still being published.
- CSSF and other national-competent-authority specifics will need local supplementation when client jurisdiction is known.
Notable quotes
None — own-writing.
What’s speculative vs. asserted
- Asserted: the pathway design, target scope, deliverable list.
- Forward-looking: the artefacts are a build-out list; specific templates have not all been authored at point of capture. Paul flags Areas 1–5 above as known gaps requiring further work.
Topics this feeds
- AI and Data Assurance Pathway
- Service Line — Regulatory Readiness and Evidence
- Model Risk Management and Agentic AI
Open questions raised
All five “Areas requiring further research” items above; rolled into open-questions.
Ingestion note
Two Open Brain task-type thoughts dated 6 May 2026.