Purpose
What the agent is authorised to achieve.
A context-specific framework for recording what an agent may do, what evidence supports claims about it, what controls exist and who accepts the residual risk.
What the agent is authorised to achieve.
The decisions and actions it can take.
Its systems, data, credentials and tools.
The consequences of incorrect or malicious behaviour.
What has actually been demonstrated or verified.
The restrictions, oversight and recovery mechanisms.
The risk remaining after controls.
Events that invalidate the previous assessment.
Domain Risk = Likelihood × Impact. The combined score is normalised to 0–100 and adjusted by operating-context weighting. Residual risk applies recorded control effectiveness and evidence uncertainty. Critical conditions override a lower numerical result.
Verified independently checked or technically confirmed · Demonstrated observed in a controlled demonstration · Documented supported by supplied documentation · Declared stated by the provider but not independently verified · Missing no adequate evidence supplied.
This guidance mapping connects the method to relevant principles in NCSC agentic-AI cyber-risk guidance, the NIST AI Risk Management Framework, ISO/IEC 42001 concepts, OWASP AI and agentic-risk guidance, and UK GDPR security and accountability principles. States are Addressed, Partially addressed, Evidence required or Not applicable. It does not claim formal compliance, certification, endorsement or legal assurance.
This demonstrator has been developed in response to the growing need for evidence-based, operational approaches to AI-agent assurance. Available now: structured assessment, transparent scoring, evidence classification, control recommendations, scenario-test recording, human decisions, printable Passports and reassessment logic.
Proposed R&D—not current functionality: open-source connectors, automated evidence collection and adversarial testing, behavioural telemetry, continuous monitoring, machine-readable policies, cryptographically verifiable Passports and organisational security integrations.
Published September 2026. Initial operational-demonstrator methodology covering purpose, agency, access, impact, evidence, controls, residual risk and change. Twelve risk domains, four decision bands and the initial critical-override set were introduced. No earlier versions exist.
An Agent Assurance Passport supports—not replaces—professional cybersecurity, legal, regulatory or operational assessment. No government, NCSC or Sovereign AI approval or endorsement is implied.