- AI Governance & Risk/Impact Assessment — AI Governance · 10 steps
Assess AI system context, impacts and risks; authorize treatment and monitored deployment, route residual risks to the proper authority and approve the evidenced assessment package.
- AI Governance Framework, Roles & Obligations Review — AI Governance; with Executive · 7 steps
Review AI policy, role competence, resource dependencies and provider or deployer obligations; approve necessary changes, resolve gaps and retain the published policy and cycle evidence.
- AI Guardrail Configuration & Agent Permission Review — AI Governance; with IT · 5 steps
Operate the monthly and per-release first-line review of the guardrail stack around every deployed AI agent: confirm the layered input defenses and endpoint limits that screen adversarial input, injection, and jailbreak attempts and prevent scraping and model extraction; diff each agent's tool allow-list, permissions, approval gates, sandboxing, and configuration artifacts against its authorized scope; and check output filters and grounding, secrets redaction, misuse refusals, and secure-code-generation defaults against baseline. Two decisions route over-permissioned agents and guardrail drift through remediation and retest. The cycle closes with a signed guardrail attestation, cycle metrics, and owned remediation actions linked to the anchor Control.
- AI Operations Monitoring & Incident Response — AI Governance; with IT · 5 steps
Operate the monthly review of the deployed AI estate: confirm automatic event logging and retention and work performance, anomaly, and drift alerts to closure; verify human-oversight staffing and intervention records; and screen AI uses against intended use and legal prohibitions. Triage reports from the AI concern channels, execute any required incident communications and regulator reporting within mandated timeframes, and retain all resolution records.
- AI Service Data Policy & Quality Management Cycle — AI Governance; with Privacy · 5 steps
Review AI service input and output data policies, collect required customer acknowledgments, assess quality management and obligations, and track corrective actions with a retained cycle record.
- AI System Development, Data & Deployment Gate — AI Governance; with IT · 7 steps
Run the release board gate that every new AI system and substantial modification must clear before deployment. The gate approves responsible-AI objectives and per-system requirements before build, governs training, validation, and test data with bias mitigation, executes the pre-deployment impact assessment and EU AI Act risk classification, confirms Annex IV-grade technical documentation, and records verification, validation, and deployment sign-off, with retraining and other changes re-entering the same gate.
- AI Transparency & Value-Chain Communications — AI Governance; with Compliance & Legal · 6 steps
Run the recurring AI-transparency cycle: keep each AI system's user and deployer documentation, AI-interaction disclosures, and AI-generated-content marking (including deepfakes) current with system changes, and retain distribution evidence. Evaluate AI suppliers against the organization's responsible-AI requirements and review customer needs and communications so customers have what they need to use the systems responsibly.
- EU AI Act Obligation Impact Analysis — AI Governance; with Compliance & Legal · 10 steps
Parse EU AI Act obligations, map affected AI use cases, crosswalk controls, flag conformity gaps, and hand high-risk items to AIMS.
- GPAI Model Provider Compliance Cycle — AI Governance; with Compliance & Legal · 8 steps
Run the recurring compliance cycle owned by providers of general-purpose AI models: maintain model technical documentation and the downstream-provider information pack, operate the EU copyright reservation-of-rights policy, and publish the training-content summary on every model release and quarterly refresh. For models designated as posing systemic risk, the cycle additionally runs state-of-the-art model evaluations with adversarial testing, assesses and mitigates systemic risks, tracks and reports serious incidents to the AI Office, and verifies cybersecurity protection of the model and its infrastructure.
- ISO/IEC 42001 AI Management System Internal Audit — Internal Audit; with AI Governance · 2 steps
Plan and perform an independent internal audit of an AI management system against ISO/IEC 42001, using AIUC-1 crosswalk evidence where it helps test AI-specific safeguards; document findings, management actions, and an independent conclusion without presenting the work as certification.
- Quarterly Third-Party AI Evaluation Cycle — AI Governance; with Procurement · 7 steps
Operate the quarterly cycle in which the AI product team commissions an independent third-party evaluator to test every in-scope AI system for adversarial robustness and jailbreak resistance, harmful and out-of-scope outputs, agent-specific high-risk outputs, hallucination rates, and unsafe or unauthorized tool calls. The test scope, categories, and pass thresholds are fixed in advance, then every finding is triaged against those pre-agreed thresholds by category and severity. Failed categories are driven through remediation and evaluator retest, and the evaluator report is formally accepted or returned for rework. The cycle closes by publishing the accepted evaluation evidence — trust-portal summary, customer-facing attestation, and evidence register — and tuning the guardrails from what the evaluation found.