ctl-009
AI-generated content requires human review before customer or record use.
- Type
- PREVENTIVE
- Automation
- MANUAL
- Frequency
- CONTINUOUS
- Owner
- Digital Strategy
Control Design Assessment (CDA)
Procedures evaluating whether the control is designed adequately.
- 1.Obtain and read the human-review-gate procedure; confirm it defines which AI-generated outputs require review before customer or record use.
- 2.Confirm the gate applies before customer-facing or record use, not after.
- 3.Confirm bypass events are captured in an audit log as part of the control design, so a bypass does not defeat the compensating review.
Control Operating Effectiveness (COE)
Procedures evaluating whether the control operated over the testing period.
- 1.Select 25 AI-generated outputs used with customers or in records and confirm each carries evidence of human review prior to use.
- 2.Confirm the reviewer identity captured on each sampled item differs from the process that generated the content.
- 3.Confirm instances where the review gate was bypassed were logged and escalated.
Linked risks
- Ungoverned generative AI outputmitigation 3
Framework mappings & latest test
GRC-15LOG-15
Latest test:FAIL2026-04-30