The organisational control model for AI governance
PSF defines safe AI deployment at the system level. PAI-8 defines the governance, audit, incident, and vendor controls an organisation must operate around those systems. Eight controls, four maturity levels, public evidence.
PAI-8 and PSF are parallel standards, not replacements. PSF (D1-D8) governs technical deployment safety. PAI-8 (C1-C8) governs organisational governance maturity. Mature programmes need both layers.
✓Immutable audit trail: logs cannot be altered post-hoc
C8
Vendor & Supply Chain
Inventory of all third-party AI dependencies, vendor risk assessment, contractual AI continuity protections, and tested fallback capability.
✓Inventory of all third-party AI components maintained
✓Vendor risk assessment for all AI service providers
✓AI safety and continuity requirements in vendor contracts
✓Continuity plan for critical AI dependencies tested annually
Maturity Levels
Each of the 8 controls is scored L0–L3. A PAI-8 assessment produces a per-control maturity score and an overall governance posture rating.
L0
Unprepared
No formal AI safety controls. AI is deployed without governance, assessment, or documentation. Material risk of regulatory, reputational, or operational harm.
L1
Basic
Controls are documented but inconsistently operational. Policies exist on paper but are not embedded in decisions. Evidence is sparse or absent.
L2
Managed
Controls are operational with documented process, regular cadence, and evidenced application to real decisions. Suitable for most regulated environments.
L3
Optimised
Controls are continuously improved with metrics, benchmarking against sector peers, and board-level governance review. Industry-leading posture.