Control #

B

1

.

3

Require human approval for high-risk AI tool calls

Block AI-initiated access to high-risk tools (e.g., financial transfers, deletion actions) unless explicitly approved by a human. Approvals must be documented and specific to the task or time window.

Evidence

Policy document defining high-risk AI actions and human approval policy

Approval logs showing human validation history for high-risk AI actions

Recommended actions

We'll recommend specific practices and actions for complying with this control.

Provide feedback on this control