Bachelorthesis "Operationalizing Agentic AI Governance"
AI agents that act on their own create governance risks that traditional AI does not. Swiss Post has principles and controls for them, but no way to measure whether those controls actually work in operation. This thesis builds the missing measurement layer.
Rajah, Shelina Robert, 2026
Type of Thesis Bachelor Thesis
Client Schweizerische Post
Supervisor Westpfahl, swantje
Views: 1
Agentic AI has entered enterprises faster than the structures meant to govern it. Once an agent plans, decides, and acts across systems, evaluating the underlying model is no longer enough. Swiss Post has established its first governance artefacts, including a reference architecture, a secure model, and defined controls. What is missing is a way to tell, during live operation, whether those controls are effective. A control can be defined, documented, and still fail unnoticed. The organisation can state what governance should exist, but not whether it works.
The thesis derives an agentic-AI control register from Swiss Post's own documentation, established industry frameworks and standards, and academic literature, under a strict source-integrity rule where every entry traces to a primary source or is marked as author-derived. Each control is linked to a documented risk, made measurable through a key performance indicator, and connected to a graded response when a threshold is breached. A maturity model and a per-agent readiness check complete the instrument, all designed to run on Swiss Post's existing technology stack.
The central result is an end-to-end control register that links risks, controls, and key performance indicators into a ready-to-use steering instrument. It comprises 48 risks, 66 controls across 15 governance domains, and 70 indicators, each control traceable to a risk and each indicator to a control. A prioritisation model orders the controls so that the legally and safety-critical measures come first. A three-tier escalation logic binds every breach to a defined response, and a maturity model lets Swiss Post assess and improve how well each domain is governed over time.The contribution is an operationalisation, not another framework. It supplies the missing measurement layer for the governance model Swiss Post already has, in a form the organisation can activate with its first productive agent. The derivation also revealed where the inherited risk landscape stops: strong on model- and data-level risk, but exposed on inter-agent, protocol, and oversight-timing risks. Because the structure is general while its content is specific to Swiss Post, it transfers to other regulated organisations, whereas the concrete mappings and thresholds must be re-derived for each context.
Studyprogram: Wirtschaftsinformatik (Bachelor)
Keywords Agentic AI, Operationalizing, KPIs and Metrics
Confidentiality: öffentlich