complylock.ai / aiuc-1-checklist

AIUC-1 checklist: the tool-call controls

Before an accredited auditor assesses your agent, five things should already exist for the tool-call controls. An inventory of every tool the agent can call, with the declared permissions, roles and data boundary for each (D003, B007). An enforcement point at the action boundary that refuses out-of-scope calls and writes a log, rather than a system prompt asking the model to behave (D003, B006). A third-party adversarial evaluation of that surface, with findings mapped control by control (D004). Evidence that data reaching a tool stays inside its declared classification (A003). And a re-test cadence, quarterly, so the evidence in the package is not a snapshot from last year. ComplyLock builds that set for one agent workflow and hands it over organized the way the auditor reads it.

Book a call