Search the Atlas

Search risks, controls, and glossary terms

Non-AgenticPrivacy & Data Governance

Knowledge Authorization

Explanation

Knowledge authorization checks that a RAG system draws only on approved, sanctioned knowledge sources rather than unvetted or unauthorised content — ensuring a bank's assistant answers from the official, governed document set and not from rogue or out-of-scope material that could be inaccurate or contain data it should not surface. It matters because unauthorised sources undermine both accuracy and privacy controls, and the control carries the proposed RBI Safety/Resilience, NIST MANAGE 3.1 and ISO Clause 6.1.2 (privacy) mappings (no fixed priority is set). It is measured by Approved Knowledge Coverage; no calculation method is given in the control, so operationalise it as the share of the knowledge actually used or indexed that comes from the approved source registry. To implement, maintain an allow-list of authorised knowledge sources, instrument the RAG indexing and retrieval layers to validate every source against that registry, and log each indexed/retrieved item with its approval status and any unauthorised sources detected as evidence. The thresholds (proposed) are tiered: at least 0.90 coverage is the target, below 0.85 should be investigated, and below 0.80 must be remediated. Coverage below 0.85 triggers investigation into how unapproved content entered the corpus, and below 0.80 mandates remediation — purging unauthorised sources and tightening ingestion gating — before the system continues serving answers.

Risks mitigated

1