Control #
B
1
.
3
Require human approval for high-risk AI tool calls
Block AI-initiated access to high-risk tools (e.g., financial transfers, deletion actions) unless explicitly approved by a human. Approvals must be documented and specific to the task or time window.
Evidence
Policy document defining high-risk AI actions and human approval policy
Approval logs showing human validation history for high-risk AI actions
Recommended actions
We'll recommend specific practices and actions for complying with this control.