Governance Contracts
All 16 Components
Browsable reference for every CSM 2.0 governance contract. Filter by domain or execution function.
Showing 16 of 16 contracts
Policy Framework
EnterpriseCore Question
Are there organizational AI policies that apply to this system, and do they account for adaptive or probabilistic behavior?
Key Inputs (3)
Objective Rules (3)
ENT-POLICY-R1: AI policy must be documented.[BLOCKING]
ENT-POLICY-R2: Policy must address adaptive/probabilistic behavior.
ENT-POLICY-R3: Accountable owner must be assigned.[BLOCKING]
Human Judgment Points (2)
ENT-POLICY-HJ1: Is the use ethically acceptable within organizational values?
ENT-POLICY-HJ2: Does a specific legal obligation apply to this use?
Required Decisions (2)
ENT-POLICY-D1: Is the use ethically acceptable?(human_approval)[BLOCKING]
ENT-POLICY-D2: Does a specific legal obligation apply?(legal_review)[BLOCKING]
Required Evidence (2)
ENT-POLICY-E1: AI policy document
ENT-POLICY-E2: Accountable owner assignment
Outputs (4)
Handoff Targets
PRJ/PRJ-BUSINESS: policyBoundaries, accountableOwner
Reassessment Triggers (4)
Execution Functions
Responsible
AI Governance Lead, Policy Owner
Accountable
AI Governance Lead
Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.
Risk Assessment
EnterpriseCore Question
Has a risk assessment been performed that accounts for adaptive AI behavior and temporal change?
Key Inputs (3)
Objective Rules (2)
ENT-RISK-R1: Risk assessment must be completed.
ENT-RISK-R2: Assessment must address drift/temporal change.
Human Judgment Points (1)
ENT-RISK-HJ1: Is the residual risk acceptable?
Required Decisions (1)
ENT-RISK-D1: Is residual risk acceptable?(risk_acceptance)[BLOCKING]
Required Evidence (1)
ENT-RISK-E1: Risk assessment document(expires: 365d)
Outputs (3)
Handoff Targets
PRJ/PRJ-TESTING: riskContext, identifiedRisks
Reassessment Triggers (5)
Execution Functions
Responsible
Risk Manager, AI Governance Lead
Accountable
AI Governance Lead
Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.
Data Stewardship
EnterpriseCore Question
Are data sources that influence AI behavior identified, owned and governed?
Key Inputs (3)
Objective Rules (3)
ENT-DATA-R1: Data sources must be identified.
ENT-DATA-R2: Each data source must have an assigned owner.
ENT-DATA-R3: Data sensitivity must be classified.
Required Evidence (1)
ENT-DATA-E1: Data source inventory
Outputs (3)
Handoff Targets
PRJ: dataOwnership, dataSensitivityClassifications
Reassessment Triggers (3)
Execution Functions
Responsible
Data Steward, Data Governance Lead
Accountable
Data Governance Lead
Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.
Strategic Mandate
EnterpriseCore Question
Is there a documented strategic mandate with a named accountable owner and defined boundaries?
Key Inputs (3)
Objective Rules (3)
ENT-MANDATE-R1: Strategic mandate must be documented.[BLOCKING]
ENT-MANDATE-R2: Accountable owner must be assigned.[BLOCKING]
ENT-MANDATE-R3: Mandate boundaries must be defined.
Required Evidence (1)
ENT-MANDATE-E1: Strategic mandate document
Outputs (3)
Handoff Targets
PRJ/PRJ-BUSINESS: intendedPurpose, accountableOwner, strategicMandate
Reassessment Triggers (3)
Execution Functions
Responsible
Executive Sponsor, AI Governance Lead
Accountable
Executive Sponsor
Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.
Business Case Definition
ProjectCore Question
Is there a documented business case with success criteria and risk-benefit evaluation?
Key Inputs (3)
Objective Rules (2)
PRJ-BUSINESS-R1: Business case must be documented.
PRJ-BUSINESS-R2: Success criteria must be defined.
Human Judgment Points (1)
PRJ-BUSINESS-HJ1: Does the business benefit justify the risk?
Required Decisions (1)
PRJ-BUSINESS-D1: Does the business benefit justify the risk?(risk_acceptance)[BLOCKING]
Required Evidence (1)
PRJ-BUSINESS-E1: Business case document
Outputs (3)
Handoff Targets
CODE/CODE-STANDARDS: approvedUseCase, businessSuccessCriteria, applicableConstraints
Reassessment Triggers (2)
Execution Functions
Responsible
Product Manager, Project Lead
Accountable
Product Manager
Dependencies
Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.
Controlled Testing
ProjectCore Question
Is there a controlled testing plan that addresses identified risks and success criteria?
Key Inputs (3)
Objective Rules (3)
PRJ-TESTING-R1: Testing plan must be documented.
PRJ-TESTING-R2: Testing must address identified risks.
PRJ-TESTING-R3: Testing results must be recorded.
Required Evidence (2)
PRJ-TESTING-E1: Testing plan
PRJ-TESTING-E2: Testing results(expires: 365d)
Outputs (3)
Handoff Targets
PRJ/PRJ-SCALE: evaluationCriteria, testingResults
Reassessment Triggers (5)
Execution Functions
Responsible
QA Lead, Project Lead
Accountable
Project Lead
Dependencies
Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.
Scale Decision Framework
ProjectCore Question
Is there a documented scale decision with explicit criteria and evidence?
Key Inputs (3)
Objective Rules (2)
PRJ-SCALE-R1: Scale criteria must be documented.
PRJ-SCALE-R2: Scale decision must be made with evidence.
Human Judgment Points (1)
PRJ-SCALE-HJ1: Should the system proceed to scale?
Required Decisions (1)
PRJ-SCALE-D1: Should the system proceed to scale?(human_approval)[BLOCKING]
Required Evidence (1)
PRJ-SCALE-E1: Scale decision document
Outputs (3)
Handoff Targets
PRJ/PRJ-PLAYBOOK: scaleDecision, releaseExpectations
Reassessment Triggers (3)
Execution Functions
Responsible
Project Lead, Executive Sponsor
Accountable
Executive Sponsor
Dependencies
Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.
Playbook Documentation
ProjectCore Question
Is there a playbook that transfers pilot decisions, learning and operational requirements to ongoing owners?
Key Inputs (3)
Objective Rules (3)
PRJ-PLAYBOOK-R1: Playbook must be documented.
PRJ-PLAYBOOK-R2: Playbook must include key decisions.
PRJ-PLAYBOOK-R3: Operational owners must be identified.
Required Evidence (1)
PRJ-PLAYBOOK-E1: Playbook document
Outputs (3)
Handoff Targets
ENT: lessonsRequiringEnterpriseChange, discoveredDependencies
Reassessment Triggers (2)
Execution Functions
Responsible
Project Lead, Operations Lead
Accountable
Project Lead
Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.
Development Standards
CodeCore Question
Are there development standards that address AI-assisted code generation, review and quality?
Key Inputs (2)
Objective Rules (2)
CODE-STANDARDS-R1: AI-assisted development standards must be documented.
CODE-STANDARDS-R2: Review requirements for AI-generated code must be defined.
Required Evidence (1)
CODE-STANDARDS-E1: Development standards document
Outputs (3)
Handoff Targets
CODE/CODE-HUMAN: reviewRequirements
Reassessment Triggers (2)
Execution Functions
Responsible
Engineering Lead, Tech Lead
Accountable
Engineering Lead
Dependencies
Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.
Security Protocols
CodeCore Question
Are security protocols in place that address AI-generated code vulnerabilities and dependencies?
Key Inputs (3)
Objective Rules (3)
CODE-SECURITY-R1: Security scanning must be active.[BLOCKING]
CODE-SECURITY-R2: Dependency verification must be performed.
CODE-SECURITY-R3: Security review artifact must exist.[BLOCKING]
Required Evidence (2)
CODE-SECURITY-E1: Security scan results(expires: 90d)
CODE-SECURITY-E2: Security review document(expires: 180d)
Outputs (3)
Handoff Targets
UX: securityTestResults, knownLimitations
Reassessment Triggers (4)
Execution Functions
Responsible
Security Engineer, Engineering Lead
Accountable
Engineering Lead
Dependencies
Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.
Human Oversight
CodeCore Question
Is there a defined human review process for AI-assisted contributions proportionate to risk?
Key Inputs (2)
Objective Rules (2)
CODE-HUMAN-R1: Human review process must be defined.
CODE-HUMAN-R2: Review must be proportionate to risk.
Human Judgment Points (1)
CODE-HUMAN-HJ1: Is the human oversight proportionate for this system risk profile?
Required Decisions (1)
CODE-HUMAN-D1: Is human oversight proportionate?(human_approval)
Required Evidence (1)
CODE-HUMAN-E1: Review process document
Outputs (2)
Reassessment Triggers (2)
Execution Functions
Responsible
Engineering Lead, Senior Developer
Accountable
Engineering Lead
Dependencies
Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.
Traceability Logging
CodeCore Question
Is there traceability logging that records AI-assisted changes with appropriate provenance?
Key Inputs (2)
Objective Rules (2)
CODE-TRACE-R1: Traceability logging must be active.
CODE-TRACE-R2: AI-assisted changes must be tracked.
Required Evidence (1)
CODE-TRACE-E1: Traceability log configuration
Outputs (2)
Reassessment Triggers (2)
Execution Functions
Responsible
Engineering Lead, DevOps Lead
Accountable
Engineering Lead
Dependencies
Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.
Impact Analysis
UXCore Question
Has an impact analysis been performed for affected individuals and groups?
Key Inputs (2)
Objective Rules (2)
UX-IMPACT-R1: Impact analysis must be completed.
UX-IMPACT-R2: Affected stakeholders must be identified.
Required Evidence (1)
UX-IMPACT-E1: Impact analysis document(expires: 365d)
Outputs (3)
Handoff Targets
UX/UX-EXPLAIN: impactFindings, stakeholderNeeds
Reassessment Triggers (4)
Execution Functions
Responsible
UX Researcher, Product Manager
Accountable
Product Manager
Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.
Explainability Design
UXCore Question
Does the system provide explanations appropriate for user understanding and appropriate reliance?
Key Inputs (2)
Objective Rules (2)
UX-EXPLAIN-R1: Explainability must be designed.
UX-EXPLAIN-R2: Limitations must be communicated.
Human Judgment Points (1)
UX-EXPLAIN-HJ1: Is the explanation adequate for affected users?
Required Decisions (1)
UX-EXPLAIN-D1: Is the explanation adequate?(human_approval)
Required Evidence (1)
UX-EXPLAIN-E1: Explainability design document
Outputs (3)
Handoff Targets
UX/UX-CAPABILITY: explanationDesign, userUnderstandingRequirements
Reassessment Triggers (3)
Execution Functions
Responsible
UX Designer, Product Manager
Accountable
Product Manager
Dependencies
Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.
Capability Development
UXCore Question
Is there a capability development plan that prepares users to supervise and interact with the AI system?
Key Inputs (2)
Objective Rules (2)
UX-CAPABILITY-R1: Capability plan must be documented.
UX-CAPABILITY-R2: Training must be provided.
Human Judgment Points (1)
UX-CAPABILITY-HJ1: Is the training adequate for the system risk profile?
Required Decisions (1)
UX-CAPABILITY-D1: Is training adequate?(human_approval)
Required Evidence (2)
UX-CAPABILITY-E1: Capability plan
UX-CAPABILITY-E2: Training materials(expires: 365d)
Outputs (3)
Reassessment Triggers (2)
Execution Functions
Responsible
Training Lead, Product Manager
Accountable
Product Manager
Dependencies
Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.
Adoption Measurement
UXCore Question
Is adoption being measured with feedback and complaint channels in place?
Key Inputs (3)
Objective Rules (3)
UX-ADOPTION-R1: Adoption metrics must be defined.
UX-ADOPTION-R2: Feedback channel must exist.
UX-ADOPTION-R3: Complaint channel must exist.
Required Evidence (1)
UX-ADOPTION-E1: Adoption metrics definition
Outputs (4)
Handoff Targets
PRJ/PRJ-BUSINESS: userFeedback, usageFindings, escalationData
Reassessment Triggers (2)
Execution Functions
Responsible
UX Researcher, Product Manager
Accountable
Product Manager
Dependencies
Original CSM publication, August 29, 2025. V2 contract formalized 2026-08-10.