Question bank

Reviewer question bank

The questions examiners and internal audit actually ask about agents, per regime, and the artifact that closes each one.

Why it exists

Most preparation optimises for the question teams expect — 'is the model accurate?' — and reviewers ask something adjacent that the programme has no artifact for. The questions below are phrased the way they arrive: narrow, evidential, and usually about one specific past action rather than about the system in general. Each is paired with what the reviewer is really testing, because answering the surface question while missing the test is the most common way a well-run programme still fails an examination.

What it contains

01

Questions grouped by regime, phrased as they are actually asked

02

What each question is really testing, which is rarely what it appears to ask

03

The artifact that closes it — and the answer that looks like evidence but is not

04

Cross-regime questions that arrive regardless of sector

05

A note on which citations move, and how to check them

No email required, and nothing is recorded when you download. Use it, adapt it, argue with it — attribution is welcome, not a condition.

Question bank · v1.0 · 24 July 2026

Asked regardless of sector

The questionWhat it is testingWhat closes itWhat does not
Show me one action this agent took last quarter and why it was allowed.Whether evidence is reconstructible on the reviewer's timeline rather than reproducible on yours.A completed reconstruction: authority, policy version, inputs, model and prompt versions, outcome.A walkthrough of how the system is designed to work.
Who authorised it to do that?Whether authority is granted and recorded, or merely inherited from a service account.A scoped, time-boxed grant traceable to a named human.A named product owner with no recorded grant.
What would have stopped it?Whether enforcement sits at the point of action or is monitoring wearing a control's name.A captured denial of the same action class.An alert that fired after the record changed.
Which model version was in effect?Whether you are pinned or riding a provider alias.An immutable version identifier on the action record.A provider name, or an alias such as 'latest'.
What did the human approver see?Whether human-in-the-loop is a control or a formality.The presented context, the decision, the identity and the dwell time.A workflow status reading 'approved'.
How long do you keep that evidence?Whether retention is mapped per regime or inherited from a log default.A retention schedule per evidence class, with legal-hold handling.The platform's default log retention.

By regime

Regulatory instruments move. Dates are given so they can be checked, and every one of these should be verified against the primary source on the day it is used — particularly the Gulf and EU entries, where secondary summaries are unusually unreliable.

RegimeThe questionWhat closes it
Federal Reserve SR 11-7 / OCC 2011-12 (2011)Is this agent in the model inventory, and as what?An inventory row representing action classes, tools and delegated authority — not a single row named after the assistant.
SR 11-7 — effective challengeWho challenged this, and could they reconstruct the decision?An independent review covering authority and containment, with its limitations stated.
SR 11-7 — ongoing monitoringWhat tells you the agent's behaviour has changed?Thresholds tied to action risk, plus a trigger that fires on provider-side version changes.
OCC 2023-17 (third-party risk)How is this provider overseen, and what is your exit?Executed audit-rights and version-notice clauses, plus a tested replacement or cease-use path. Note the guidance sets no dollar thresholds.
NYDFS Part 500.11What access does the third party have?Access-scoped evidence — the obligation follows access, not contract value.
NAIC model bulletin on AI (adopted in 25 jurisdictions, plus 4 with their own AI regulation, as of 1 April 2026)If an agent contributed to a declination, can you explain it in the terms the regulator expects?An adverse-action reconstruction from evidence, not a post-hoc rationalisation.
State DOI — unfair discriminationHow do you test for proxy discrimination through agent-selected features?Testing at the decision the customer experienced, repeated after model changes — not a one-off fairness dashboard on a model score.
HIPAA Security Rule §164.312Minimum necessary — how does that hold when the agent retrieves broadly?Entitlement scoping at query time plus access evidence sized for agent volumes.
HIPAA — business associatesDoes your agent platform process ePHI, and is its audit trail visible to you?An executed BAA and demonstrated visibility into the platform's own trail.
21 CFR Part 11Is the agent-written record attributable, and is the audit trail intact?Immutable action events with attribution to the agent and the authority behind it.
India DPDP Act (rules notified 13 November 2025; obligations commence 13 May 2027)What purpose was this processing bound to, and did the agent stay inside it?Purpose binding enforced architecturally, with sectoral overrides from RBI, SEBI or IRDAI applied where stricter.
CBUAE AI/ML Guidance Note (issued 11 February 2026, applies to licensed financial institutions including insurers)Where is the AI model inventory, and does it extend to third-party models?An inventory per §2f with name, purpose and risk rating, extended to third-party models per §9c. Note the Note is drafted in 'should' language — a supervisory expectation, not a penalty regime — but §2f ties to the CBUAE Model Management Standards (21 December 2022), which are mandatory for banks.
CBUAE §3cWhen did you last test for bias, and what triggered it?Testing at least annually and on every material change, connected to the customer-impacting decision.
CBUAE §9a / §6fWhat are your audit rights over the provider, and can you cease use immediately?Executed rights plus a tested cease-use path — a contractual promise until the exit has actually been run.
EU AI Act — Article 50 transparency (applies from 2 August 2026)Do people know they are dealing with an AI system?Disclosure at the point of interaction, evidenced in the outbound record.
EU AI Act — Annex III high-risk (postponed to 2 December 2027 by the Digital Omnibus)Which of your uses fall in Annex III, and what is the plan?A scoping assessment with dates. The delay moves the deadline, not the design work.
DORAIs this an ICT service supporting a critical function?An early designation position — there is no advisory carve-out in the ESAs' January 2025 Q&A, so the classification should be asserted rather than assumed.

How to use it

  1. Run it as a mock examination, not a questionnaire. Have someone outside the delivery team ask, and refuse design explanations as answers.
  2. Score each question as closed, partial or open on evidence alone.
  3. Anything answered with a description rather than a link is open.
  4. Give every open question an owner and a date before the next review cycle.
  5. Re-check each cited instrument against its primary source before relying on it — several of these changed inside the last year.

Built from public standards and general practice. Regulatory instruments move — check anything cited here against its primary source on the day you rely on it. Related: the other artifacts · the diagnostic.

Next step

Want this applied to your architecture?

The artifacts are general by design. Applying one to a specific estate is what the governance review does.