White House Accord on Super Intelligence: Mapping the Four Layers to Vendor Due Diligence
On September 29, 2026, major frontier model developers signed the White House Accord on Super Intelligence (Joint Commitment on Frontier Responsibilities). The Accord is voluntary and contains no enforcement mechanism, penalties, or mandatory public disclosure requirements. It is not law.
Despite its lack of legal force, the four layers of controls and audits described in the Accord are already beginning to function as a practical baseline for enterprise security questionnaires, vendor risk assessments, and procurement processes. CISOs, CDOs, and third-party risk teams should treat these layers as the emerging reference standard when evaluating AI and frontier-model vendors.
The Four Layers Defined
The Accord states that each company training and deploying frontier models should implement the following four layers:
1. Internal controls
Robust internal controls to monitor the capabilities and alignment of models during training and deployment, covering areas such as cybersecurity, biosecurity, and chemical threats, and to ensure models do not hack or access technical systems in unintended ways.
2. Internal oversight team
An empowered internal team responsible for ensuring that the controls, monitoring, and detection are operating as intended and that any issues are remediated.
3. External audits
Partnership with an independent external auditor or evaluator to carry out independent assessments of whether the controls, monitoring, and detection are operating as intended.
4. Independent board oversight
An independent committee of the board of directors that oversees and receives reports from the teams operating the controls and from the internal and external auditors/evaluators, and that ensures identified issues are remediated.
These layers form a nested structure: operational controls → internal assurance → external assurance → board-level governance.
Why Voluntary Commitments Become De Facto Standards
Enterprise security and procurement teams routinely convert high-profile voluntary frameworks into questionnaire requirements. Once a critical mass of large vendors publicly commits to a structure, the absence of that structure becomes a risk flag.
Security questionnaires, SOC 2 questionnaires, AI-specific risk assessments, and RFP due-diligence packages are already beginning to reference the Accord’s four-layer model. Vendors that cannot map their practices to these layers face longer review cycles or conditional approvals. For CISOs and CDOs, the practical question is not whether the Accord is binding, but how quickly their own due-diligence processes will treat it as the expected baseline.
Mapping the Four Layers to Existing Vendor Due Diligence
Layer 1: Internal Controls → Technical and Operational Controls Review
What to ask vendors
- What specific controls exist to monitor model capabilities and alignment during training and deployment?
- How are cybersecurity, biosecurity, chemical-threat, and unintended system-access risks monitored?
- What logging, detection, and containment mechanisms are in place for anomalous model behavior?
- How frequently are these controls tested or validated internally?
Map to existing processes
- Align with existing control frameworks already used in vendor assessments (e.g., SOC 2 Trust Services Criteria, ISO 27001 control domains, NIST AI RMF Map/Measure functions, or internal AI risk taxonomies).
- Request evidence of control design and operating effectiveness, similar to how you request evidence for access controls or change management.
- Treat the absence of documented monitoring for the specific risk areas named in the Accord as a gap requiring compensating controls or contractual language.
Layer 2: Internal Oversight Team → Organizational Accountability and Remediation
What to ask vendors
- Is there a designated internal team (or function) responsible for verifying that the Layer 1 controls are operating as intended?
- What is the team’s authority, reporting line, and remediation mandate?
- How are issues escalated and tracked to closure?
- What is the cadence of internal reviews or attestations?
Map to existing processes
- Parallel existing questions about security operations, compliance, or risk functions that own control monitoring.
- Look for clear ownership (named team or role) rather than diffuse responsibility.
- Require evidence of issue tracking and remediation timelines, similar to vulnerability management or audit-finding closure processes.
- Note whether the team has sufficient independence from the model-development organization.
Layer 3: External Audits → Independent Assurance
What to ask vendors
- Has the vendor engaged an independent external auditor or evaluator to assess the effectiveness of its controls and monitoring?
- What is the scope of the external assessment?
- How frequently is the assessment performed?
- Will the vendor share a summary of findings or an attestation letter (under NDA if necessary)?
Map to existing processes
- Treat this as analogous to SOC 2 Type II reports, ISO certifications, or independent penetration-test results.
- Prefer assessments performed by recognized independent firms with relevant expertise.
- Where full reports are not available, accept scoped attestations or executive summaries that address the specific control areas in the Accord.
- Flag vendors that rely solely on internal assessments with no external component.
Layer 4: Independent Board Oversight → Governance and Accountability
What to ask vendors
- Does an independent committee of the board of directors receive reports from the internal oversight team and external auditors?
- What is the committee’s mandate regarding remediation of identified issues?
- How frequently does the committee review AI/frontier-model risk matters?
- Is there board-level visibility into residual risk and remediation status?
Map to existing processes
- Align with existing board-governance and risk-oversight questions already asked of critical vendors (especially those providing material services or high-risk technology).
- Look for evidence of formal board or board-committee oversight rather than informal executive briefings.
- For privately held or smaller vendors, accept equivalent governance structures (e.g., independent risk committee or external advisory board with comparable authority) while noting the difference.
Practical Implementation Guidance for CISOs and CDOs
1. Update questionnaires now
Add a short section that explicitly references the four layers. Even if you do not require full compliance, asking the questions surfaces gaps early.
2. Prioritize by risk tier
Apply the full four-layer mapping first to vendors providing frontier or high-capability models, systems that can take autonomous actions, or services that process sensitive data or operate in regulated environments.
3. Accept evidence in familiar formats
SOC 2 reports, independent audit letters, board committee charters, and internal control narratives can all map to the layers. Do not require a new proprietary format.
4. Document residual risk
Where a vendor cannot fully map to one or more layers, record the gap, any compensating controls, and the business justification for continued use.
5. Track evolution
The Accord states that signatories will meet regularly to establish standards and best practices. Revisit vendor responses periodically as industry practice solidifies.
Frequently Asked Questions
Is the White House Accord on Super Intelligence legally binding?
No. The Accord is a voluntary commitment. It contains no enforcement mechanism, penalties, or mandatory reporting requirements to any government body.
Do vendors have to implement all four layers?
The Accord states that companies “should” implement the four layers. There is no legal requirement. However, enterprise security and procurement teams are increasingly treating the layers as a practical baseline in vendor assessments.
How should we handle vendors that cannot fully map to the four layers?
Document the specific gaps, identify any compensating controls the vendor has in place, and record the residual risk and business justification for continued use. Prioritize remediation or contractual requirements according to the risk tier of the vendor.
Can existing SOC 2 or ISO reports satisfy the external-audit layer?
In many cases, yes—if the scope of the existing report adequately covers the relevant controls for model monitoring, alignment, and the risk areas named in the Accord. Request clarification from the vendor when the scope is unclear.
Does the Accord apply only to the companies that signed it?
The text focuses on companies that train and deploy frontier models. Enterprise due-diligence teams are free to apply the same four-layer questions to any AI or model-related vendor they assess.
Where can I find the official text of the Accord?
The full text of the White House Accord on Super Intelligence (Joint Commitment on Frontier Responsibilities) was released by the White House on September 29, 2026.
Resources from The AI Table
The AI Table provides research, policy briefs, and membership programs focused on responsible AI adoption, governance, and AI strategy. These resources help CISOs, CDOs, and risk teams translate high-level commitments such as the White House Accord into practical vendor-assessment and internal-control frameworks.