The control library keeps trust work tied to the exact binder that will succeed or stall under external review.
| Control family | Owner | Audience | Action | Requested assertion | Coverage |
|---|---|---|---|---|---|
| AI governance readiness binder | Chief AI Officer | Board risk committee | REFRESH | Agent governance, rollout, and exception control evidence is review-ready. | 70 |
| Identity assurance binder | Chief Information Security Officer | Audit committee | CLOSE | Identity reviews, guest access, and mobile protection controls are audit-ready. | 84 |
| Platform security binder | VP Platform Engineering | Board technology committee | ESCALATE | Hosting, release safety, backup, and runtime hardening controls are connected enough for diligence. | 63 |
| Procurement trust binder | Chief Commercial Officer | Board growth committee | CLOSE | Security questionnaire, trust-center, and proof reuse are buyer-ready. | 88 |
| Revenue control binder | Chief Revenue Officer | Board finance committee | DEFER | Reporting, attribution, and release controls already form one diligence-grade control plane. | 58 |
| Regulated systems binder | Quality systems lead | Board compliance committee | REFRESH | GxP, specimen, CAPA, safety, and narrative review already form a reusable regulated binder. | 67 |