Control framework / / By SpendAssureFounder on LinkedIn

What actually stops AI spending? Four classes. Different evidence.

Separate contractual limits, provider caps, rate controls and uncovered spending. Use four control classes to explain AI budget coverage to finance.

The four AI spending control classes.

This is SpendAssure’s reporting framework, not an industry certification. Classify the exact resource and scope supported by the evidence. An organisation can have resources in several classes at the same time.

Control classes and the information finance should receive
ClassMeaningFinance record
Contractually boundedApplicable terms explicitly fix the maximum for the stated scope and period, such as a fixed licence without variable charges. Prepayment qualifies only if the terms exclude overage or negative-balance liability.Contractual maximum for the covered scope, with currency and period.
Provider-cappedThe provider enforces a spend cap, but no numerical overshoot bound is established in its documentation.Configured cap, labelled "provider-enforced; overshoot bound unspecified".
Velocity-boundedEvery material billable dimension of the resource has an enforceable upper rate, with burst allowances and pricing accounted for. A rate limit bounds how fast liability grows, not its total.Spend rate per hour and per day, labelled "speed limit, not a ceiling".
UnboundedNeither a contractual or provider cap nor a complete enforceable rate envelope covers the resource's material billable dimensions.UNBOUNDED, with the uncovered dimension named.

Why is an approved budget not enough?

Consider a team with an approved €10,000 monthly amount. The approval authorises a plan. An email alert at €8,000 prompts a decision. Neither fact by itself establishes what stops requests, which charges are included or who can raise the control.

Document the mechanism separately. Current provider examples are explained in our OpenAI spend-limit guide and Anthropic workspace guide, each with dated primary references. The capability comparison separates settings from API access.

What makes a scope Contractually bounded?

Use this class only when the applicable terms fix the maximum liability for the stated scope and period. A fixed subscription that also permits variable usage needs those components separated. An upfront payment is not sufficient evidence if the agreement allows overage or a negative balance.

The operational record should identify the agreement, covered resource, currency, period and exclusions. Someone authorised to interpret the agreement must confirm the scope. This guide supplies a reporting vocabulary; it does not determine the effect of a particular contract.

What does Provider-capped tell a reviewer?

It identifies a provider-enforced spending setting while keeping enforcement limitations visible. A saved amount and a contractual maximum are different forms of evidence. Accounting delay, scope and the provider’s treatment of in-flight work still matter.

For example, a report can retain the configured amount and an explicit note that its overshoot bound is unspecified. Avoid converting a favourable observation from one test into a promise about every workload. Revisit the record when the provider changes its documented behaviour.

Why is a rate a speed limit, not a ceiling?

An illustrative €200 per hour corresponds to €4,800 per day at that rate. It does not bound total spending across an unlimited period. A complete rate assessment also needs all material billable dimensions, pricing and burst allowances.

A token-rate limit may leave other charges outside the calculation. If a team cannot establish coverage for a material dimension, keep that gap visible. Do not classify the entire resource from a convenient partial calculation.

A review separates approved budget, control mechanism, evidence and owner.
An original control-review model. Each field answers a different finance question.

What should an Unbounded record trigger?

Unbounded is a statement about missing coverage under this framework, not a prediction that a resource will overspend. The next useful action is to name the uncovered dimension, responsible owner and review decision.

A low-volume prototype can be deliberately accepted with an uncovered control gap. That decision should be visible and time-bound rather than concealed behind a small current bill. Actual spend and control coverage answer different questions.

Keep evidence freshness separate from the class.

An API-read setting and a manually attested setting need separate labels. An attestation records who checked what and when. SpendAssure’s proposed default expires manual attestations after 30 days; conflicting evidence triggers earlier review.

The label does not create enforcement. When evidence expires, flag the record for review rather than presenting it as newly verified. Retain the previous observation so the owner can investigate what changed.

Apply the classes to a finance review.

Start with a resource inventory and avoid adding parent controls to child controls as if they covered independent spend. Keep currency, period, source, owner and exceptions with each row. An internal allocation may overlap a provider control; explain that relationship explicitly.

The AI spend management guide connects this classification to the wider review process. Use the policy template to decide who may approve changes. SpendAssure’s production workflow is in development; this framework can already be used in a spreadsheet.