TheSuperIntelligence.SI

The Agent Assurance Passport Methodology

A context-specific framework for recording what an agent may do, what evidence supports claims about it, what controls exist and who accepts the residual risk.

01

Purpose

What the agent is authorised to achieve.

02

Agency

The decisions and actions it can take.

03

Access

Its systems, data, credentials and tools.

04

Impact

The consequences of incorrect or malicious behaviour.

05

Evidence

What has actually been demonstrated or verified.

06

Controls

The restrictions, oversight and recovery mechanisms.

07

Residual Risk

The risk remaining after controls.

08

Change

Events that invalidate the previous assessment.

Published scoring logic

Domain Risk = Likelihood × Impact. The combined score is normalised to 0–100 and adjusted by operating-context weighting. Residual risk applies recorded control effectiveness and evidence uncertainty. Critical conditions override a lower numerical result.

0–24 Suitable to approve25–49 Approve with controls50–74 Further testing required75–100 Do not deploy

Evidence classification

Verified independently checked or technically confirmed · Demonstrated observed in a controlled demonstration · Documented supported by supplied documentation · Declared stated by the provider but not independently verified · Missing no adequate evidence supplied.

Framework mapping

This guidance mapping connects the method to relevant principles in NCSC agentic-AI cyber-risk guidance, the NIST AI Risk Management Framework, ISO/IEC 42001 concepts, OWASP AI and agentic-risk guidance, and UK GDPR security and accountability principles. States are Addressed, Partially addressed, Evidence required or Not applicable. It does not claim formal compliance, certification, endorsement or legal assurance.

Safe adoption and future research

This demonstrator has been developed in response to the growing need for evidence-based, operational approaches to AI-agent assurance. Available now: structured assessment, transparent scoring, evidence classification, control recommendations, scenario-test recording, human decisions, printable Passports and reassessment logic.

Proposed R&D—not current functionality: open-source connectors, automated evidence collection and adversarial testing, behavioural telemetry, continuous monitoring, machine-readable policies, cryptographically verifiable Passports and organisational security integrations.

Methodology change log

AAP Methodology v1.0

Published September 2026. Initial operational-demonstrator methodology covering purpose, agency, access, impact, evidence, controls, residual risk and change. Twelve risk domains, four decision bands and the initial critical-override set were introduced. No earlier versions exist.

An Agent Assurance Passport supports—not replaces—professional cybersecurity, legal, regulatory or operational assessment. No government, NCSC or Sovereign AI approval or endorsement is implied.