Assess the risks and controls associated with generative AI and agentic systems, including retrieval-augmented generation, LLM-based applications, agentic workflows, orchestration tooling, APIs, data pipelines, cloud and platform infrastructure, identity and access management, security, resilience, third-party dependencies, monitoring and human oversight.