Paul Miles — AI and Data Assurance Pathway + Contract Toolkit

Tag: S-2026-05-06-paul-ai-data-pathway Type: own-writing Author(s): Paul Miles (Red Strata) Date of source: 2026-05-06 Date ingested: 2026-05-17 Authority weight: own-writing. Raw file: Open Brain corpus snapshot at /_raw_sources/open-brain-2026-05-17-corpus.md. Documents on disk: C:\Users\pgmil\OneDrive\Documents\_ClaudeWorkspace\04 Ai and Data services\AI_Data_Assurance_Pathway.docx and .md.

What it claims

A senior-practitioner Learning & Development pathway for an AI and Data assurance capability targeted at EU banking and capital markets. Output mix: practitioner artefacts, structured reading, hands-on labs (explicitly not formal certifications). Regulatory scope: EU only (EU AI Act, EBA, ESMA). FS sub-sector: banking / capital markets. Starting level: senior on both audit/risk and AI/data — refresh + edge.

Practitioner artefacts to build out (~30 named):

  • AI System Inventory template
  • Regulatory Crosswalk
  • AIMS Statement of Applicability (ISO 42001)
  • AI Use-Case Intake Form
  • AI Ethics Board pack template
  • AI Literacy curriculum spec
  • Data Lineage Evidence Pack
  • AI Dataset Datasheet (extending Gebru et al.) tailored to AI Act Art 10
  • DPIA template for AI
  • RAG Corpus Control Checklist
  • Model Validation Report (mappable to AI Act Annex IV)
  • LLM Evaluation Plan
  • Fairness Testing Workpaper
  • Agent Control Surface Diagram
  • Agent Threat Model (OWASP Agentic + MITRE ATLAS)
  • Eval Plan for GenAI / Agentic
  • Human-in-the-Loop Decision Matrix
  • Tool Registry & Approval Workflow
  • Prompt Change Control SOP
  • AI Logging & Evidence Specification (Art 12)
  • Drift Monitoring Plan
  • AI Change Control SOP
  • AI Incident Response Playbook
  • AI Vendor DDQ
  • AI Contract Clause Library (DORA Art 30 + AI Act Arts 25, 53)
  • AI Supply-Chain Concentration Heatmap
  • Foundation-Model Exit Plan
  • AI Threat Model (ATLAS-aligned)
  • AI Red-Team Test Case Library
  • AI 3LoD RACI
  • Annual AI Assurance Plan
  • AI Control-Evidence Calendar
  • AI Risk Board Pack
  • Internal Audit AI Engagement Plan

Areas requiring further research (Paul’s own flag, 6 May 2026):

  1. AI Act harmonised standards from CEN-CENELEC JTC 21 not yet fully published; Digital Omnibus may delay the 2 Aug 2026 high-risk obligations.
  2. EBA / ESMA implementing guidance on AI Act for FS — EBA stated no immediate new guidelines but a 2026–2027 supervisory convergence programme; concrete control expectations beyond the November 2025 factsheet still pending.
  3. Agent assurance best practice — OWASP Agentic Top 10 (Dec 2025) and MITRE ATLAS agentic techniques (Oct 2025 – Feb 2026) are recent and no FS-supervisor formal expectations yet.
  4. GPAI systemic-risk evaluation methodology from the AI Office still being published.
  5. CSSF and other national-competent-authority specifics will need local supplementation when client jurisdiction is known.

Notable quotes

None — own-writing.

What’s speculative vs. asserted

  • Asserted: the pathway design, target scope, deliverable list.
  • Forward-looking: the artefacts are a build-out list; specific templates have not all been authored at point of capture. Paul flags Areas 1–5 above as known gaps requiring further work.

Topics this feeds

Open questions raised

All five “Areas requiring further research” items above; rolled into open-questions.

Ingestion note

Two Open Brain task-type thoughts dated 6 May 2026.