FROM POLICY TO REVIEWABLE EVIDENCE

AI Governance
Readiness Map

Know which controls have a review record, which lack evidence and who owns the next step.

When governance has no traceable owner, Pharos Production connects it to development through system inventory, validation, monitoring and accountability. This worksheet turns those engineering practices into an editable evidence map.

Start the evidence map

One AI system · 12 controls · JSON / Markdown / CSV

THE REVIEW PATH

  1. 01
    Scope the systemPurpose, users, jurisdiction and role
  2. 02
    Attach the evidenceRACI, artifact reference and review record
  3. 03
    Assign the open workMissing fields stay visible in every export
A planning aid for a documented review. Entered evidence is not independently verified.

01 / WORKSHEET

Build an evidence record

Choose a system boundary. Then open a control and record the people and artifacts behind it. Suggested roles are examples; they are never assigned automatically.

System boundary

Display filter only. Every export contains all 12 controls.

01 / inventoryMAP

AI system inventory

Give the system a stable identity before assessing it. Include models, retrieval data, prompts, tools and the environments where people use them.

Evidence to prepare
Versioned register entry with intended purpose, model/provider identifiers, data sources, deployment location and review triggers.
EU review topic
Confirm system scope and the organization's role.
Framework context
NIST AI RMF Playbook: Map · European Commission: AI Act overview
Edit ownership and evidenceUnknown · owners not assigned
AI system inventory record
02 / scopeMAP

Jurisdiction and use-case review

Record who is affected, where outputs are used and which decisions the system can influence. Assign an explicit reviewer to the scope decision.

Evidence to prepare
Dated scoping memo with intended use, affected groups, deployment geography, legal questions and unresolved assumptions.
EU review topic
Check territorial scope, classification and applicable transition rules.
Framework context
NIST AI RMF Playbook: Map · European Commission: AI Act overview
Edit ownership and evidenceUnknown · owners not assigned
Jurisdiction and use-case review record
03 / riskMAP

Risk register and acceptance

Describe a plausible failure and its consequence for each affected group. Keep open risks visible with the acceptance authority and a review trigger.

Evidence to prepare
Risk register containing failure scenarios, impact analysis, mitigation owners, residual risk decisions and change triggers.
EU review topic
Review prohibited practices and any high-risk classification.
Framework context
NIST AI RMF Playbook: Map · European Commission: AI Act overview
Edit ownership and evidenceUnknown · owners not assigned
Risk register and acceptance record
04 / accountabilityGOVERN

Accountability and decision authority

Name the person who performs the control and the person who accepts its outcome. Record consulted specialists and the people who receive the decision.

Evidence to prepare
RACI record plus a release decision log that names risk acceptance authority, escalation route and unresolved objections.
EU review topic
Confirm provider/deployer responsibilities for the particular system.
Framework context
NIST AI RMF Playbook: Govern · European Commission: AI Act overview
Edit ownership and evidenceUnknown · owners not assigned
Accountability and decision authority record
05 / literacyGOVERN

Role-specific training

Make training fit the decisions each role actually makes. Operators should rehearse escalation and understand where the system can fail.

Evidence to prepare
Training record with role, relevant system limitations, completed exercises, attendance and a refresher trigger.
EU review topic
Review AI literacy obligations and operator competence.
Framework context
NIST AI RMF Playbook: Govern · European Commission: AI Act overview
Edit ownership and evidenceUnknown · owners not assigned
Role-specific training record
06 / supplierGOVERN

Supplier and model dependencies

Record which externally supplied components can change behavior. Include access, version changes and the evidence a provider makes available.

Evidence to prepare
Dependency register, supplier instructions, version policy, data-use terms, exit plan and a named owner for vendor changes.
EU review topic
Check upstream model information and downstream responsibilities.
Framework context
NIST AI RMF Playbook: Govern · European Commission: AI Act overview
Edit ownership and evidenceUnknown · owners not assigned
Supplier and model dependencies record
07 / dataMAP

Data provenance and access

Trace evaluation and retrieval data to a permitted source. Record sensitive fields, access rules and deletion or correction paths.

Evidence to prepare
Data lineage record with allowed uses, quality checks, retention decision, access test and affected population coverage.
EU review topic
Review data governance and separate privacy obligations.
Framework context
NIST AI RMF Playbook: Map · European Commission: AI Act overview
Edit ownership and evidenceUnknown · owners not assigned
Data provenance and access record
08 / validationMEASURE

Validation and failure testing

Test the intended use and credible misuse before release. Record subgroup limitations, security failures and the reason for each acceptance threshold.

Evidence to prepare
Versioned evaluation set, rubric, measured results, security tests, known limitations and an accepted release decision.
EU review topic
Review accuracy, robustness, cybersecurity and supporting documentation.
Framework context
NIST AI RMF Playbook: Measure · European Commission: AI Act overview
Edit ownership and evidenceUnknown · owners not assigned
Validation and failure testing record
09 / oversightMEASURE

Human oversight and user information

Test whether an operator can understand a warning, override an action and stop the workflow. Check what users are told about AI involvement.

Evidence to prepare
Observed override exercise, authority boundaries, user instructions, escalation path and accessible notices for the intended audience.
EU review topic
Review oversight measures and relevant transparency duties.
Framework context
NIST AI RMF Playbook: Measure · European Commission: AI Act overview
Edit ownership and evidenceUnknown · owners not assigned
Human oversight and user information record
10 / recordsGOVERN

Traceability and change records

Keep enough context to reconstruct a decision without indiscriminately retaining sensitive payloads. Tie approvals and changes to an identifiable release.

Evidence to prepare
Redacted trace sample, version/approval identifiers, retention/access rules and a tested path for retrieving a decision record.
EU review topic
Review logging and technical documentation requirements.
Framework context
NIST AI RMF Playbook: Govern · European Commission: AI Act overview
Edit ownership and evidenceUnknown · owners not assigned
Traceability and change records record
11 / monitoringMANAGE

Monitoring and response ownership

Connect a measured signal to a response owner. Review thresholds against an evaluation baseline and test the recovery path after a breach.

Evidence to prepare
Monitoring specification, baseline reference, alert routing, response exercise, rollback target and post-change review record.
EU review topic
Review post-market monitoring and deployer monitoring duties.
Framework context
NIST AI RMF Playbook: Manage · European Commission: AI Act overview
Edit ownership and evidenceUnknown · owners not assigned
Monitoring and response ownership record
12 / incidentMANAGE

Incident triage and notification

Rehearse how an issue becomes an incident, who contains it and who decides whether notification is required. Preserve the incident timeline.

Evidence to prepare
Incident playbook and exercise record with severity criteria, containment authority, notification review, recipients and applicable clocks.
EU review topic
Confirm reportability, recipient and deadline for the specific regime.
Framework context
NIST AI RMF Playbook: Manage · European Commission: AI Act overview
Edit ownership and evidenceUnknown · owners not assigned
Incident triage and notification record

02 / HOW TO READ THE MAP

A review record has conditions

A checkbox cannot establish that a control works. The rules below only determine whether the worksheet contains the fields needed to describe a review. They are editorial workflow rules for this tool, not requirements issued by NIST or a regulator.

How each selected state contributes to the result
Selected stateFields neededCounted as
Unknown / PlannedResponsible and accountable owners. Evidence and review work still follow.Needs attention, even when owners exist
Evidence recordedResponsible, accountable and an evidence referenceNeeds attention until review is recorded
Review recordedResponsible, accountable, evidence reference, reviewer and review dateReview recorded only if every required field exists
Not applicableAccountable, reviewer, review date and a rationale for this systemQualified exclusion only if every required field exists

Assign authority, not just a team name

RACI separates the person doing the work from the person accepting its outcome. Consulted specialists contribute to the decision; informed people receive it. Your organization determines whether the same person can hold several roles.

Reference a specific artifact revision and review scope. "Test report" is less useful than a document identifier with its revision, evaluation set and acceptance decision. The map accepts references as text and does not open or validate them.

Keep rejected and deferred work visible

A control marked "not applicable" without a reason remains open. Treat an overdue review, a changed model or a new user population as a reason to inspect the underlying record again. The tool checks date format and prevents a review date after the assessment date; it cannot decide how long evidence remains valid.

The selected function never changes the report denominator. Twelve controls equal recorded reviews plus qualified exclusions plus records needing attention. No percentage here represents legal readiness.

Pharos Production's four-pillar governance framework gives the engineering sequence behind this map: establish the inventory, test the system, monitor its behavior and retain accountable decisions. The new worksheet adds explicit evidence and review fields; it does not inherit the article's reviewer sign-off.

03 / WORKED EXAMPLE

A support copilot with unfinished evidence

This synthetic scenario helps you inspect the rules before entering real information. An internal support copilot suggests replies for staff. The example records completed inventory and accountability reviews, a reasoned exclusion for external model-supplier review, a validation report awaiting review and an incident playbook without assigned owners. The remaining controls are unknown.

Recorded reviews
2
Qualified exclusions
1
Needs attention
9

None of those counts certifies the copilot. Even the exclusion needs scrutiny: the fictional system uses an in-house model, but internal component provenance and data controls still apply. Change the intended use and revisit that decision.

Use "Load worked example" to inspect every field. The sample also ships as JSON, Markdown and CSV. These artifacts contain synthetic entries, not records from a client deployment.

04 / FRAMEWORK BOUNDARY

NIST organizes the work. Legal scope needs its own review.

The NIST AI RMF is voluntary. Its Playbook offers suggestions under Govern, Map, Measure and Manage and explicitly allows selective use. Our twelve-control selection is an editorial adaptation, not an official checklist or certification scheme. NIST states that AI RMF 1.0 is being revised; this release uses the published 1.0 structure.

EU applicability depends on the system, use and legal role. The European Commission's current overview distinguishes multiple application dates and transition periods. Use its current guidance with the applicable legal text before setting obligations or notification deadlines. The EU prompts in this map identify review topics; they are not an article-by-article legal crosswalk.

  1. Record the system's actual purpose, affected people and deployment locations.
  2. Have the relevant specialist document jurisdiction, role and applicable rules.
  3. Translate that conclusion into evidence requirements and approved incident procedures.
  4. Revisit the conclusion when the system, supplier or intended use changes.

Provider and deployer obligations can differ. Selecting "other jurisdictions" does not establish an exemption from EU rules, and NIST alignment does not establish compliance anywhere. Privacy, sector rules, product safety and contractual obligations need separate consideration.

05 / EVIDENCE & MAINTENANCE

What this release can support

Version
1.0.0
Sources checked
Prepared with
Codex, with automated tests and source review
Human approval
No independent human or legal sign-off is recorded for this tool

Control descriptions, suggested roles and evidence examples are original planning guidance. NIST links point to the relevant function for context. The Commission source supports EU review topics; it does not validate your selected status or an entered document.

The source article contributes its engineering structure. This release excludes its unsupported outcome statistics and blanket incident-reporting deadline. Resolve reportability and the actual notification clock for the relevant situation.

Inspect the complete control catalog, source registry and changelog. Report a correction with the control ID, source URL and proposed scope. A material source or rule change requires a new release and a fresh check of affected records.

Privacy, exports and reuse

The application makes no requests for your entered data. Hosting infrastructure may log ordinary page requests. Evidence references remain text; no documents are uploaded. Downloaded files contain what you entered, so store and share them according to your organization's rules. JSON retains exact values. Markdown escapes entered markup; CSV prefixes potentially executable spreadsheet values with an apostrophe. Consulted and informed fields are optional and stay in every export.

Original application code and control wording are available under the MIT license included with the package. External framework and regulatory materials retain their own terms. No affiliation with NIST or the European Commission is implied.