> ## Documentation Index
> Fetch the complete documentation index at: https://evalgate.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Risks & controls

> Collaborative RACM for AI risks, controls, safeguards, evidence requests, review authority, and reviewed-scope export.

# Risks & controls

**Status:** Available (Shipped) · **Owner:** Proof / Trust & Review · maturity: [Feature status](/docs/platform/feature-status)

Open `/proof/risks-and-controls` in the product. The workspace answers: what
could go wrong, what addresses it, which safeguards are mapped, and what
remains unestablished.

This is a collaborative RACM over risks, controls, safeguard bindings,
walkthrough notes, assignments, evidence requests/submissions, conclusions,
findings, risk acceptance, and reviewed-scope export. It is separate from the
control-assurance implementation surface at `/proof/controls`, which owns
receipt-backed prevention claims for tool/schema controls.

## What the matrix shows

| Column | Meaning |
| - | - |
| Risk | Named AI risk with owner |
| Control | Requirement that addresses the risk, with designated reviewer |
| Safeguard | Mapped implementation/profile binding (not manufactured activation) |
| Evidence | Requests and submissions scoped to the control |
| Next | Honest next action (link control, request evidence, review, conclude) |

## Authority boundaries

* Review, conclude, and close paths require the control’s designated reviewer
  (or an explicit combined-role setting). Submitters cannot self-approve by
  default.
* Risk acceptance requires the recorded risk owner.
* Staging≠production mismatches come from artifact provenance, not free-text
  claim scope.
* Superseded submissions stay readable but are not current acceptance material.

## Evidence and export

1. Request evidence for a control criterion.
2. Submit artifacts against that request (request-scoped replace).
3. Review with loaded artifacts and provenance.
4. Record design/implementation/operation conclusions bound to configuration
   revisions.
5. Export a reviewed-scope snapshot (JSON and XLSX) that freezes limitations and
   evidence IDs.

Guest portals and optional connector collectors remain optional product paths;
do not treat an empty guest invite as a closed control.

## Related reading

* [Connect controls to actual evidence](/docs/guides/connect-controls-to-evidence)
* [Platform map](/docs/platform/platform-map)
* [Feature status](/docs/platform/feature-status)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.