FROM POLICY TO REVIEWABLE EVIDENCE
AI Governance
Readiness Map
Know which controls have a review record, which lack evidence and who owns the next step.
When governance has no traceable owner, Pharos Production connects it to development through system inventory, validation, monitoring and accountability. This worksheet turns those engineering practices into an editable evidence map.
Start the evidence mapOne AI system · 12 controls · JSON / Markdown / CSV
THE REVIEW PATH
- 01Scope the systemPurpose, users, jurisdiction and role
- 02Attach the evidenceRACI, artifact reference and review record
- 03Assign the open workMissing fields stay visible in every export
01 / WORKSHEET
Build an evidence record
Choose a system boundary. Then open a control and record the people and artifacts behind it. Suggested roles are examples; they are never assigned automatically.
Synthetic worked example loaded. All people, document references and review entries are illustrative. Use "Start blank" before recording a real system.
02 / HOW TO READ THE MAP
A review record has conditions
A checkbox cannot establish that a control works. The rules below only determine whether the worksheet contains the fields needed to describe a review. They are editorial workflow rules for this tool, not requirements issued by NIST or a regulator.
| Selected state | Fields needed | Counted as |
|---|---|---|
| Unknown / Planned | Responsible and accountable owners. Evidence and review work still follow. | Needs attention, even when owners exist |
| Evidence recorded | Responsible, accountable and an evidence reference | Needs attention until review is recorded |
| Review recorded | Responsible, accountable, evidence reference, reviewer and review date | Review recorded only if every required field exists |
| Not applicable | Accountable, reviewer, review date and a rationale for this system | Qualified exclusion only if every required field exists |
Assign authority, not just a team name
RACI separates the person doing the work from the person accepting its outcome. Consulted specialists contribute to the decision; informed people receive it. Your organization determines whether the same person can hold several roles.
Reference a specific artifact revision and review scope. "Test report" is less useful than a document identifier with its revision, evaluation set and acceptance decision. The map accepts references as text and does not open or validate them.
Keep rejected and deferred work visible
A control marked "not applicable" without a reason remains open. Treat an overdue review, a changed model or a new user population as a reason to inspect the underlying record again. The tool checks date format and prevents a review date after the assessment date; it cannot decide how long evidence remains valid.
The selected function never changes the report denominator. Twelve controls equal recorded reviews plus qualified exclusions plus records needing attention. No percentage here represents legal readiness.
Pharos Production's four-pillar governance framework gives the engineering sequence behind this map: establish the inventory, test the system, monitor its behavior and retain accountable decisions. The new worksheet adds explicit evidence and review fields; it does not inherit the article's reviewer sign-off.
03 / WORKED EXAMPLE
A support copilot with unfinished evidence
This synthetic scenario helps you inspect the rules before entering real information. An internal support copilot suggests replies for staff. The example records completed inventory and accountability reviews, a reasoned exclusion for external model-supplier review, a validation report awaiting review and an incident playbook without assigned owners. The remaining controls are unknown.
- Recorded reviews
- 2
- Qualified exclusions
- 1
- Needs attention
- 9
None of those counts certifies the copilot. Even the exclusion needs scrutiny: the fictional system uses an in-house model, but internal component provenance and data controls still apply. Change the intended use and revisit that decision.
Use "Load worked example" to inspect every field. The sample also ships as JSON, Markdown and CSV. These artifacts contain synthetic entries, not records from a client deployment.
04 / FRAMEWORK BOUNDARY
NIST organizes the work. Legal scope needs its own review.
The NIST AI RMF is voluntary. Its Playbook offers suggestions under Govern, Map, Measure and Manage and explicitly allows selective use. Our twelve-control selection is an editorial adaptation, not an official checklist or certification scheme. NIST states that AI RMF 1.0 is being revised; this release uses the published 1.0 structure.
EU applicability depends on the system, use and legal role. The European Commission's current overview distinguishes multiple application dates and transition periods. Use its current guidance with the applicable legal text before setting obligations or notification deadlines. The EU prompts in this map identify review topics; they are not an article-by-article legal crosswalk.
- Record the system's actual purpose, affected people and deployment locations.
- Have the relevant specialist document jurisdiction, role and applicable rules.
- Translate that conclusion into evidence requirements and approved incident procedures.
- Revisit the conclusion when the system, supplier or intended use changes.
Provider and deployer obligations can differ. Selecting "other jurisdictions" does not establish an exemption from EU rules, and NIST alignment does not establish compliance anywhere. Privacy, sector rules, product safety and contractual obligations need separate consideration.
05 / EVIDENCE & MAINTENANCE
What this release can support
- Version
- 1.0.0
- Sources checked
- Prepared with
- Codex, with automated tests and source review
- Human approval
- No independent human or legal sign-off is recorded for this tool
Control descriptions, suggested roles and evidence examples are original planning guidance. NIST links point to the relevant function for context. The Commission source supports EU review topics; it does not validate your selected status or an entered document.
The source article contributes its engineering structure. This release excludes its unsupported outcome statistics and blanket incident-reporting deadline. Resolve reportability and the actual notification clock for the relevant situation.
Inspect the complete control catalog, source registry and changelog. Report a correction with the control ID, source URL and proposed scope. A material source or rule change requires a new release and a fresh check of affected records.
Privacy, exports and reuse
The application makes no requests for your entered data. Hosting infrastructure may log ordinary page requests. Evidence references remain text; no documents are uploaded. Downloaded files contain what you entered, so store and share them according to your organization's rules. JSON retains exact values. Markdown escapes entered markup; CSV prefixes potentially executable spreadsheet values with an apostrophe. Consulted and informed fields are optional and stay in every export.
Original application code and control wording are available under the MIT license included with the package. External framework and regulatory materials retain their own terms. No affiliation with NIST or the European Commission is implied.