CSM 2.0 Reference

Governance Contracts
All 16 Components

Browsable reference for every CSM 2.0 governance contract. Filter by domain or execution function.

Domain:
Execution Function:

Showing 16 of 16 contracts

ENT-POLICY

Policy Framework

Enterprise
Ensure AI ethics standards and organizational policies account for system behavior that may differ from conventional software.

Core Question

Are there organizational AI policies that apply to this system, and do they account for adaptive or probabilistic behavior?

Key Inputs (3)

aiPolicyDocumentedpolicyAddressesAdaptiveBehavioraccountableOwner

Objective Rules (3)

ENT-POLICY-R1: AI policy must be documented.[BLOCKING]

ENT-POLICY-R2: Policy must address adaptive/probabilistic behavior.

ENT-POLICY-R3: Accountable owner must be assigned.[BLOCKING]

Human Judgment Points (2)

ENT-POLICY-HJ1: Is the use ethically acceptable within organizational values?

ENT-POLICY-HJ2: Does a specific legal obligation apply to this use?

Required Decisions (2)

ENT-POLICY-D1: Is the use ethically acceptable?(human_approval)[BLOCKING]

ENT-POLICY-D2: Does a specific legal obligation apply?(legal_review)[BLOCKING]

Required Evidence (2)

ENT-POLICY-E1: AI policy document

ENT-POLICY-E2: Accountable owner assignment

Outputs (4)

Policy applicability determinationAccountable owner assignmentEthical acceptability decisionLegal applicability determination

Handoff Targets

PRJ/PRJ-BUSINESS: policyBoundaries, accountableOwner

Reassessment Triggers (4)

TRIGGER-USE-CHANGETRIGGER-JURISDICTION-CHANGETRIGGER-POLICY-CHANGETRIGGER-OWNER-CHANGE

Execution Functions

EF1-PURPOSEEF6-COMPLIANCE

Responsible

AI Governance Lead, Policy Owner

Accountable

AI Governance Lead

Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.

ENT-RISK

Risk Assessment

Enterprise
Evaluate risks that account for AI system behavior which may change over time, including model updates, provider changes, or data drift.

Core Question

Has a risk assessment been performed that accounts for adaptive AI behavior and temporal change?

Key Inputs (3)

riskAssessmentCompletedriskAssessmentAddressesDriftriskAssessmentDate

Objective Rules (2)

ENT-RISK-R1: Risk assessment must be completed.

ENT-RISK-R2: Assessment must address drift/temporal change.

Human Judgment Points (1)

ENT-RISK-HJ1: Is the residual risk acceptable?

Required Decisions (1)

ENT-RISK-D1: Is residual risk acceptable?(risk_acceptance)[BLOCKING]

Required Evidence (1)

ENT-RISK-E1: Risk assessment document(expires: 365d)

Outputs (3)

Risk assessmentResidual risk acceptance decisionRisk register entry

Handoff Targets

PRJ/PRJ-TESTING: riskContext, identifiedRisks

Reassessment Triggers (5)

TRIGGER-USE-CHANGETRIGGER-SECURITY-INCIDENTTRIGGER-DRIFTTRIGGER-USER-HARMTRIGGER-POLICY-CHANGE

Execution Functions

EF3-RISKEF1-PURPOSE

Responsible

Risk Manager, AI Governance Lead

Accountable

AI Governance Lead

Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.

ENT-DATA

Data Stewardship

Enterprise
Govern datasets that influence ongoing AI behavior, including training data, retrieval sources and operational data.

Core Question

Are data sources that influence AI behavior identified, owned and governed?

Key Inputs (3)

dataSourcesIdentifieddataOwnersAssigneddataSensitivityClassified

Objective Rules (3)

ENT-DATA-R1: Data sources must be identified.

ENT-DATA-R2: Each data source must have an assigned owner.

ENT-DATA-R3: Data sensitivity must be classified.

Required Evidence (1)

ENT-DATA-E1: Data source inventory

Outputs (3)

Data source inventoryData ownership assignmentsData sensitivity classifications

Handoff Targets

PRJ: dataOwnership, dataSensitivityClassifications

Reassessment Triggers (3)

TRIGGER-DATA-CHANGETRIGGER-PROVIDER-CHANGETRIGGER-POLICY-CHANGE

Execution Functions

EF2-MAPPINGEF6-COMPLIANCE

Responsible

Data Steward, Data Governance Lead

Accountable

Data Governance Lead

Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.

ENT-MANDATE

Strategic Mandate

Enterprise
Define organizational authority and strategic alignment that establishes why AI systems are deployed and what boundaries apply.

Core Question

Is there a documented strategic mandate with a named accountable owner and defined boundaries?

Key Inputs (3)

strategicMandateDocumentedaccountableOwnermandateBoundaries

Objective Rules (3)

ENT-MANDATE-R1: Strategic mandate must be documented.[BLOCKING]

ENT-MANDATE-R2: Accountable owner must be assigned.[BLOCKING]

ENT-MANDATE-R3: Mandate boundaries must be defined.

Required Evidence (1)

ENT-MANDATE-E1: Strategic mandate document

Outputs (3)

Strategic mandateAccountable owner assignmentBoundary definitions

Handoff Targets

PRJ/PRJ-BUSINESS: intendedPurpose, accountableOwner, strategicMandate

Reassessment Triggers (3)

TRIGGER-OWNER-CHANGETRIGGER-USE-CHANGETRIGGER-POLICY-CHANGE

Execution Functions

EF1-PURPOSE

Responsible

Executive Sponsor, AI Governance Lead

Accountable

Executive Sponsor

Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.

PRJ-BUSINESS

Business Case Definition

Project
Define what problem or value is being tested. The business case defines the hypothesis an AI initiative is evaluating.

Core Question

Is there a documented business case with success criteria and risk-benefit evaluation?

Key Inputs (3)

businessCaseDocumentedsuccessCriteriaDefinedriskBenefitEvaluated

Objective Rules (2)

PRJ-BUSINESS-R1: Business case must be documented.

PRJ-BUSINESS-R2: Success criteria must be defined.

Human Judgment Points (1)

PRJ-BUSINESS-HJ1: Does the business benefit justify the risk?

Required Decisions (1)

PRJ-BUSINESS-D1: Does the business benefit justify the risk?(risk_acceptance)[BLOCKING]

Required Evidence (1)

PRJ-BUSINESS-E1: Business case document

Outputs (3)

Business caseSuccess criteriaRisk-benefit decision

Handoff Targets

CODE/CODE-STANDARDS: approvedUseCase, businessSuccessCriteria, applicableConstraints

Reassessment Triggers (2)

TRIGGER-USE-CHANGETRIGGER-SCOPE-EXPANSION

Execution Functions

EF1-PURPOSEEF3-RISK

Responsible

Product Manager, Project Lead

Accountable

Product Manager

Dependencies

ENT-MANDATEENT-POLICY

Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.

PRJ-TESTING

Controlled Testing

Project
Define what must be learned before scale. Testing designed to answer specific governance and performance questions.

Core Question

Is there a controlled testing plan that addresses identified risks and success criteria?

Key Inputs (3)

testingPlanDocumentedtestingAddressesRiskstestingResultsRecorded

Objective Rules (3)

PRJ-TESTING-R1: Testing plan must be documented.

PRJ-TESTING-R2: Testing must address identified risks.

PRJ-TESTING-R3: Testing results must be recorded.

Required Evidence (2)

PRJ-TESTING-E1: Testing plan

PRJ-TESTING-E2: Testing results(expires: 365d)

Outputs (3)

Testing planTesting resultsRisk coverage analysis

Handoff Targets

PRJ/PRJ-SCALE: evaluationCriteria, testingResults

Reassessment Triggers (5)

TRIGGER-MODEL-CHANGETRIGGER-CONFIG-CHANGETRIGGER-DATA-CHANGETRIGGER-EVAL-FAILURETRIGGER-DRIFT

Execution Functions

EF3-RISKEF4-DELIVERY

Responsible

QA Lead, Project Lead

Accountable

Project Lead

Dependencies

ENT-RISK

Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.

PRJ-SCALE

Scale Decision Framework

Project
Define what evidence justifies broader commitment. Defined criteria for deciding whether to proceed, change or stop.

Core Question

Is there a documented scale decision with explicit criteria and evidence?

Key Inputs (3)

scaleCriteriaDocumentedscaleDecisionMadescaleDecisionEvidence

Objective Rules (2)

PRJ-SCALE-R1: Scale criteria must be documented.

PRJ-SCALE-R2: Scale decision must be made with evidence.

Human Judgment Points (1)

PRJ-SCALE-HJ1: Should the system proceed to scale?

Required Decisions (1)

PRJ-SCALE-D1: Should the system proceed to scale?(human_approval)[BLOCKING]

Required Evidence (1)

PRJ-SCALE-E1: Scale decision document

Outputs (3)

Scale decisionScale criteriaDecision rationale

Handoff Targets

PRJ/PRJ-PLAYBOOK: scaleDecision, releaseExpectations

Reassessment Triggers (3)

TRIGGER-SCOPE-EXPANSIONTRIGGER-EVAL-FAILURETRIGGER-DRIFT

Execution Functions

EF4-DELIVERY

Responsible

Project Lead, Executive Sponsor

Accountable

Executive Sponsor

Dependencies

PRJ-TESTINGPRJ-BUSINESS

Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.

PRJ-PLAYBOOK

Playbook Documentation

Project
Define what decisions and learning need to survive beyond the pilot team. Documentation that transfers knowledge to operational owners.

Core Question

Is there a playbook that transfers pilot decisions, learning and operational requirements to ongoing owners?

Key Inputs (3)

playbookDocumentedplaybookIncludesDecisionsoperationalOwnersIdentified

Objective Rules (3)

PRJ-PLAYBOOK-R1: Playbook must be documented.

PRJ-PLAYBOOK-R2: Playbook must include key decisions.

PRJ-PLAYBOOK-R3: Operational owners must be identified.

Required Evidence (1)

PRJ-PLAYBOOK-E1: Playbook document

Outputs (3)

PlaybookOperational owner assignmentsDecision log

Handoff Targets

ENT: lessonsRequiringEnterpriseChange, discoveredDependencies

Reassessment Triggers (2)

TRIGGER-DECOMMISSIONTRIGGER-POLICY-CHANGE

Execution Functions

EF5-OVERSIGHTEF6-COMPLIANCE

Responsible

Project Lead, Operations Lead

Accountable

Project Lead

Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.

CODE-STANDARDS

Development Standards

Code
Engineering standards that account for AI-assisted development, including review requirements and quality expectations.

Core Question

Are there development standards that address AI-assisted code generation, review and quality?

Key Inputs (2)

aiAssistedDevStandardsDocumentedreviewRequirementsDefined

Objective Rules (2)

CODE-STANDARDS-R1: AI-assisted development standards must be documented.

CODE-STANDARDS-R2: Review requirements for AI-generated code must be defined.

Required Evidence (1)

CODE-STANDARDS-E1: Development standards document

Outputs (3)

Development standardsReview requirementsAllowed tools list

Handoff Targets

CODE/CODE-HUMAN: reviewRequirements

Reassessment Triggers (2)

TRIGGER-TOOL-AUTHORITY-CHANGETRIGGER-POLICY-CHANGE

Execution Functions

EF4-DELIVERY

Responsible

Engineering Lead, Tech Lead

Accountable

Engineering Lead

Dependencies

PRJ-BUSINESS

Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.

CODE-SECURITY

Security Protocols

Code
Security practices that address AI-generated code, including vulnerability scanning and dependency verification.

Core Question

Are security protocols in place that address AI-generated code vulnerabilities and dependencies?

Key Inputs (3)

securityScanningActivedependencyVerificationProcesssecurityReviewArtifact

Objective Rules (3)

CODE-SECURITY-R1: Security scanning must be active.[BLOCKING]

CODE-SECURITY-R2: Dependency verification must be performed.

CODE-SECURITY-R3: Security review artifact must exist.[BLOCKING]

Required Evidence (2)

CODE-SECURITY-E1: Security scan results(expires: 90d)

CODE-SECURITY-E2: Security review document(expires: 180d)

Outputs (3)

Security scan resultsSecurity reviewDependency verification results

Handoff Targets

UX: securityTestResults, knownLimitations

Reassessment Triggers (4)

TRIGGER-SECURITY-INCIDENTTRIGGER-NEW-INTEGRATIONTRIGGER-DEPENDENCY-CHANGETRIGGER-MODEL-CHANGE

Execution Functions

EF3-RISKEF4-DELIVERY

Responsible

Security Engineer, Engineering Lead

Accountable

Engineering Lead

Dependencies

CODE-STANDARDS

Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.

CODE-HUMAN

Human Oversight

Code
Human review of AI-assisted contributions proportionate to risk and consequence.

Core Question

Is there a defined human review process for AI-assisted contributions proportionate to risk?

Key Inputs (2)

humanReviewProcessDefinedreviewProportionateToRisk

Objective Rules (2)

CODE-HUMAN-R1: Human review process must be defined.

CODE-HUMAN-R2: Review must be proportionate to risk.

Human Judgment Points (1)

CODE-HUMAN-HJ1: Is the human oversight proportionate for this system risk profile?

Required Decisions (1)

CODE-HUMAN-D1: Is human oversight proportionate?(human_approval)

Required Evidence (1)

CODE-HUMAN-E1: Review process document

Outputs (2)

Human review processReview proportionality assessment

Reassessment Triggers (2)

TRIGGER-TOOL-AUTHORITY-CHANGETRIGGER-SCOPE-EXPANSION

Execution Functions

EF5-OVERSIGHT

Responsible

Engineering Lead, Senior Developer

Accountable

Engineering Lead

Dependencies

CODE-STANDARDS

Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.

CODE-TRACE

Traceability Logging

Code
Records that provide appropriate provenance for AI-assisted changes where risk warrants it.

Core Question

Is there traceability logging that records AI-assisted changes with appropriate provenance?

Key Inputs (2)

traceabilityLoggingActiveaiAssistedChangesTracked

Objective Rules (2)

CODE-TRACE-R1: Traceability logging must be active.

CODE-TRACE-R2: AI-assisted changes must be tracked.

Required Evidence (1)

CODE-TRACE-E1: Traceability log configuration

Outputs (2)

Traceability logsAI-assisted change records

Reassessment Triggers (2)

TRIGGER-TOOL-AUTHORITY-CHANGETRIGGER-POLICY-CHANGE

Execution Functions

EF6-COMPLIANCEEF2-MAPPING

Responsible

Engineering Lead, DevOps Lead

Accountable

Engineering Lead

Dependencies

CODE-STANDARDS

Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.

UX-IMPACT

Impact Analysis

UX
Assessment of how AI-supported outcomes affect individuals, groups and workflows.

Core Question

Has an impact analysis been performed for affected individuals and groups?

Key Inputs (2)

impactAnalysisCompletedaffectedStakeholdersIdentified

Objective Rules (2)

UX-IMPACT-R1: Impact analysis must be completed.

UX-IMPACT-R2: Affected stakeholders must be identified.

Required Evidence (1)

UX-IMPACT-E1: Impact analysis document(expires: 365d)

Outputs (3)

Impact analysisStakeholder mapImpact severity assessment

Handoff Targets

UX/UX-EXPLAIN: impactFindings, stakeholderNeeds

Reassessment Triggers (4)

TRIGGER-USE-CHANGETRIGGER-SCOPE-EXPANSIONTRIGGER-USER-HARMTRIGGER-POLICY-CHANGE

Execution Functions

EF3-RISK

Responsible

UX Researcher, Product Manager

Accountable

Product Manager

Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.

UX-EXPLAIN

Explainability Design

UX
Design choices that help users understand system behavior, limitations and appropriate reliance.

Core Question

Does the system provide explanations appropriate for user understanding and appropriate reliance?

Key Inputs (2)

explainabilityDesignedlimitationsCommunicated

Objective Rules (2)

UX-EXPLAIN-R1: Explainability must be designed.

UX-EXPLAIN-R2: Limitations must be communicated.

Human Judgment Points (1)

UX-EXPLAIN-HJ1: Is the explanation adequate for affected users?

Required Decisions (1)

UX-EXPLAIN-D1: Is the explanation adequate?(human_approval)

Required Evidence (1)

UX-EXPLAIN-E1: Explainability design document

Outputs (3)

Explainability designLimitation disclosuresExplanation adequacy decision

Handoff Targets

UX/UX-CAPABILITY: explanationDesign, userUnderstandingRequirements

Reassessment Triggers (3)

TRIGGER-USE-CHANGETRIGGER-MODEL-CHANGETRIGGER-DRIFT

Execution Functions

EF5-OVERSIGHT

Responsible

UX Designer, Product Manager

Accountable

Product Manager

Dependencies

UX-IMPACT

Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.

UX-CAPABILITY

Capability Development

UX
Training and skill development that enables users to effectively supervise and interact with AI systems.

Core Question

Is there a capability development plan that prepares users to supervise and interact with the AI system?

Key Inputs (2)

capabilityPlanDocumentedtrainingProvided

Objective Rules (2)

UX-CAPABILITY-R1: Capability plan must be documented.

UX-CAPABILITY-R2: Training must be provided.

Human Judgment Points (1)

UX-CAPABILITY-HJ1: Is the training adequate for the system risk profile?

Required Decisions (1)

UX-CAPABILITY-D1: Is training adequate?(human_approval)

Required Evidence (2)

UX-CAPABILITY-E1: Capability plan

UX-CAPABILITY-E2: Training materials(expires: 365d)

Outputs (3)

Capability planTraining materialsTraining adequacy decision

Reassessment Triggers (2)

TRIGGER-USE-CHANGETRIGGER-MODEL-CHANGE

Execution Functions

EF5-OVERSIGHT

Responsible

Training Lead, Product Manager

Accountable

Product Manager

Dependencies

UX-EXPLAIN

Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.

UX-ADOPTION

Adoption Measurement

UX
Monitoring of how AI systems are actually used, including feedback and complaints.

Core Question

Is adoption being measured with feedback and complaint channels in place?

Key Inputs (3)

adoptionMetricsDefinedfeedbackChannelExistscomplaintChannelExists

Objective Rules (3)

UX-ADOPTION-R1: Adoption metrics must be defined.

UX-ADOPTION-R2: Feedback channel must exist.

UX-ADOPTION-R3: Complaint channel must exist.

Required Evidence (1)

UX-ADOPTION-E1: Adoption metrics definition

Outputs (4)

Adoption metricsFeedback channelComplaint channelAdoption data

Handoff Targets

PRJ/PRJ-BUSINESS: userFeedback, usageFindings, escalationData

Reassessment Triggers (2)

TRIGGER-DRIFTTRIGGER-USER-HARM

Execution Functions

EF3-RISKEF5-OVERSIGHT

Responsible

UX Researcher, Product Manager

Accountable

Product Manager

Dependencies

UX-IMPACT

Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.

Discuss AI →