Describe your use case, get its risk register
Tick the elements your solution contains — components, design choices and capabilities, following the ARC framework's element lens. The tool derives the activated risks from the 44-risk enterprise taxonomy, the relevant control categories, and one-line control statements with Cardinal / Standard / Best-practice levels — then lets you download the complete register and its mapping tables, with stable IDs on every element, risk, category and statement. Cardinal control statements are readiness-aware: declare your enterprise infra and statements whose prerequisites are missing are flagged as gated, not day-one mandates. Specific guardrail implementations are designed downstream by system teams; this tool stays at the control-statement level.
Elements you can declare (19)
Components: EL-01 LLM / foundation model · EL-02 Tools / function calling · EL-03 Instructions / system prompt · EL-04 Memory / knowledge store
Design: EL-05 Agentic architecture (multi-agent)
Capabilities: EL-06 Planning & goal management · EL-07 Agent delegation · EL-08 Tool selection & use · EL-09 Natural language communication · EL-10 Multimodal understanding & generation · EL-11 Official communication · EL-12 Business transactions · EL-13 Internet & search access · EL-14 Computer use · EL-15 Other programmatic interfaces · EL-16 Code execution · EL-17 File & data management · EL-18 System management · EL-19 Privileged system access
Retained control categories (13)
Each links into the full Control Library. “Human Oversight” and “Monitoring & Review” are display names for the library's “Human-in-the-Loop (HITL) Moderation” and “Monitoring & Validation”.
Worked example: a RAG chat assistant with web search
Declaring 5 elements (LLM, instructions, memory, natural-language chat, internet & search access) activates 36 of the 44 enterprise risks and recommends 107 control statements across 12 control categories: