[
  {
    "id": "inventory",
    "title": "AI system inventory",
    "function": "MAP",
    "purpose": "Give the system a stable identity before assessing it. Include models, retrieval data, prompts, tools and the environments where people use them.",
    "evidence": "Versioned register entry with intended purpose, model/provider identifiers, data sources, deployment location and review triggers.",
    "suggestedResponsible": "Product owner",
    "suggestedAccountable": "System owner",
    "euReview": "Confirm system scope and the organization's role.",
    "sourceReferences": [
      {
        "label": "NIST AI RMF Playbook: Map",
        "url": "https://airc.nist.gov/airmf-resources/playbook/map/"
      },
      {
        "label": "European Commission: AI Act overview",
        "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
      }
    ]
  },
  {
    "id": "scope",
    "title": "Jurisdiction and use-case review",
    "function": "MAP",
    "purpose": "Record who is affected, where outputs are used and which decisions the system can influence. Assign an explicit reviewer to the scope decision.",
    "evidence": "Dated scoping memo with intended use, affected groups, deployment geography, legal questions and unresolved assumptions.",
    "suggestedResponsible": "Legal/compliance lead",
    "suggestedAccountable": "Business owner",
    "euReview": "Check territorial scope, classification and applicable transition rules.",
    "sourceReferences": [
      {
        "label": "NIST AI RMF Playbook: Map",
        "url": "https://airc.nist.gov/airmf-resources/playbook/map/"
      },
      {
        "label": "European Commission: AI Act overview",
        "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
      }
    ]
  },
  {
    "id": "risk",
    "title": "Risk register and acceptance",
    "function": "MAP",
    "purpose": "Describe a plausible failure and its consequence for each affected group. Keep open risks visible with the acceptance authority and a review trigger.",
    "evidence": "Risk register containing failure scenarios, impact analysis, mitigation owners, residual risk decisions and change triggers.",
    "suggestedResponsible": "Risk analyst",
    "suggestedAccountable": "Risk owner",
    "euReview": "Review prohibited practices and any high-risk classification.",
    "sourceReferences": [
      {
        "label": "NIST AI RMF Playbook: Map",
        "url": "https://airc.nist.gov/airmf-resources/playbook/map/"
      },
      {
        "label": "European Commission: AI Act overview",
        "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
      }
    ]
  },
  {
    "id": "accountability",
    "title": "Accountability and decision authority",
    "function": "GOVERN",
    "purpose": "Name the person who performs the control and the person who accepts its outcome. Record consulted specialists and the people who receive the decision.",
    "evidence": "RACI record plus a release decision log that names risk acceptance authority, escalation route and unresolved objections.",
    "suggestedResponsible": "Governance lead",
    "suggestedAccountable": "Executive sponsor",
    "euReview": "Confirm provider/deployer responsibilities for the particular system.",
    "sourceReferences": [
      {
        "label": "NIST AI RMF Playbook: Govern",
        "url": "https://airc.nist.gov/airmf-resources/playbook/govern/"
      },
      {
        "label": "European Commission: AI Act overview",
        "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
      }
    ]
  },
  {
    "id": "literacy",
    "title": "Role-specific training",
    "function": "GOVERN",
    "purpose": "Make training fit the decisions each role actually makes. Operators should rehearse escalation and understand where the system can fail.",
    "evidence": "Training record with role, relevant system limitations, completed exercises, attendance and a refresher trigger.",
    "suggestedResponsible": "Training lead",
    "suggestedAccountable": "System owner",
    "euReview": "Review AI literacy obligations and operator competence.",
    "sourceReferences": [
      {
        "label": "NIST AI RMF Playbook: Govern",
        "url": "https://airc.nist.gov/airmf-resources/playbook/govern/"
      },
      {
        "label": "European Commission: AI Act overview",
        "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
      }
    ]
  },
  {
    "id": "supplier",
    "title": "Supplier and model dependencies",
    "function": "GOVERN",
    "purpose": "Record which externally supplied components can change behavior. Include access, version changes and the evidence a provider makes available.",
    "evidence": "Dependency register, supplier instructions, version policy, data-use terms, exit plan and a named owner for vendor changes.",
    "suggestedResponsible": "Vendor manager",
    "suggestedAccountable": "System owner",
    "euReview": "Check upstream model information and downstream responsibilities.",
    "sourceReferences": [
      {
        "label": "NIST AI RMF Playbook: Govern",
        "url": "https://airc.nist.gov/airmf-resources/playbook/govern/"
      },
      {
        "label": "European Commission: AI Act overview",
        "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
      }
    ]
  },
  {
    "id": "data",
    "title": "Data provenance and access",
    "function": "MAP",
    "purpose": "Trace evaluation and retrieval data to a permitted source. Record sensitive fields, access rules and deletion or correction paths.",
    "evidence": "Data lineage record with allowed uses, quality checks, retention decision, access test and affected population coverage.",
    "suggestedResponsible": "Data lead",
    "suggestedAccountable": "Data owner",
    "euReview": "Review data governance and separate privacy obligations.",
    "sourceReferences": [
      {
        "label": "NIST AI RMF Playbook: Map",
        "url": "https://airc.nist.gov/airmf-resources/playbook/map/"
      },
      {
        "label": "European Commission: AI Act overview",
        "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
      }
    ]
  },
  {
    "id": "validation",
    "title": "Validation and failure testing",
    "function": "MEASURE",
    "purpose": "Test the intended use and credible misuse before release. Record subgroup limitations, security failures and the reason for each acceptance threshold.",
    "evidence": "Versioned evaluation set, rubric, measured results, security tests, known limitations and an accepted release decision.",
    "suggestedResponsible": "Evaluation lead",
    "suggestedAccountable": "Release owner",
    "euReview": "Review accuracy, robustness, cybersecurity and supporting documentation.",
    "sourceReferences": [
      {
        "label": "NIST AI RMF Playbook: Measure",
        "url": "https://airc.nist.gov/airmf-resources/playbook/measure/"
      },
      {
        "label": "European Commission: AI Act overview",
        "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
      }
    ]
  },
  {
    "id": "oversight",
    "title": "Human oversight and user information",
    "function": "MEASURE",
    "purpose": "Test whether an operator can understand a warning, override an action and stop the workflow. Check what users are told about AI involvement.",
    "evidence": "Observed override exercise, authority boundaries, user instructions, escalation path and accessible notices for the intended audience.",
    "suggestedResponsible": "Product/security lead",
    "suggestedAccountable": "System owner",
    "euReview": "Review oversight measures and relevant transparency duties.",
    "sourceReferences": [
      {
        "label": "NIST AI RMF Playbook: Measure",
        "url": "https://airc.nist.gov/airmf-resources/playbook/measure/"
      },
      {
        "label": "European Commission: AI Act overview",
        "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
      }
    ]
  },
  {
    "id": "records",
    "title": "Traceability and change records",
    "function": "GOVERN",
    "purpose": "Keep enough context to reconstruct a decision without indiscriminately retaining sensitive payloads. Tie approvals and changes to an identifiable release.",
    "evidence": "Redacted trace sample, version/approval identifiers, retention/access rules and a tested path for retrieving a decision record.",
    "suggestedResponsible": "Platform lead",
    "suggestedAccountable": "System owner",
    "euReview": "Review logging and technical documentation requirements.",
    "sourceReferences": [
      {
        "label": "NIST AI RMF Playbook: Govern",
        "url": "https://airc.nist.gov/airmf-resources/playbook/govern/"
      },
      {
        "label": "European Commission: AI Act overview",
        "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
      }
    ]
  },
  {
    "id": "monitoring",
    "title": "Monitoring and response ownership",
    "function": "MANAGE",
    "purpose": "Connect a measured signal to a response owner. Review thresholds against an evaluation baseline and test the recovery path after a breach.",
    "evidence": "Monitoring specification, baseline reference, alert routing, response exercise, rollback target and post-change review record.",
    "suggestedResponsible": "Operations lead",
    "suggestedAccountable": "Service owner",
    "euReview": "Review post-market monitoring and deployer monitoring duties.",
    "sourceReferences": [
      {
        "label": "NIST AI RMF Playbook: Manage",
        "url": "https://airc.nist.gov/airmf-resources/playbook/manage/"
      },
      {
        "label": "European Commission: AI Act overview",
        "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
      }
    ]
  },
  {
    "id": "incident",
    "title": "Incident triage and notification",
    "function": "MANAGE",
    "purpose": "Rehearse how an issue becomes an incident, who contains it and who decides whether notification is required. Preserve the incident timeline.",
    "evidence": "Incident playbook and exercise record with severity criteria, containment authority, notification review, recipients and applicable clocks.",
    "suggestedResponsible": "Incident commander",
    "suggestedAccountable": "Accountable incident owner",
    "euReview": "Confirm reportability, recipient and deadline for the specific regime.",
    "sourceReferences": [
      {
        "label": "NIST AI RMF Playbook: Manage",
        "url": "https://airc.nist.gov/airmf-resources/playbook/manage/"
      },
      {
        "label": "European Commission: AI Act overview",
        "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
      }
    ]
  }
]
