{
  "version": "1.0.0",
  "status": "DRAFT_REQUIRES_REVIEW",
  "scope": {
    "systemName": "SYNTHETIC EXAMPLE: internal support copilot",
    "intendedUse": "Suggest replies for internal support staff; staff approve every response. Illustrative scenario only.",
    "assessedOn": "2026-09-11",
    "jurisdiction": "eu-review",
    "euRole": "unconfirmed"
  },
  "summary": {
    "total": 12,
    "reviewed": 2,
    "excluded": 1,
    "needsAttention": 9
  },
  "scopeWarnings": [
    "Confirm the EU role for review."
  ],
  "controls": [
    {
      "id": "inventory",
      "title": "AI system inventory",
      "function": "MAP",
      "purpose": "Give the system a stable identity before assessing it. Include models, retrieval data, prompts, tools and the environments where people use them.",
      "evidence": "Versioned register entry with intended purpose, model/provider identifiers, data sources, deployment location and review triggers.",
      "suggestedResponsible": "Product owner",
      "suggestedAccountable": "System owner",
      "euReview": "Confirm system scope and the organization's role.",
      "sourceReferences": [
        {
          "label": "NIST AI RMF Playbook: Map",
          "url": "https://airc.nist.gov/airmf-resources/playbook/map/"
        },
        {
          "label": "European Commission: AI Act overview",
          "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
        }
      ],
      "status": "review-recorded",
      "responsible": "Example product lead",
      "accountable": "Example system owner",
      "consulted": "Example governance specialist",
      "informed": "Example support team",
      "evidenceRef": "SYNTHETIC inventory memo v1",
      "reviewer": "Example reviewer",
      "reviewedOn": "2026-09-10",
      "rationale": "Illustrative record, not an observed assessment.",
      "missing": [],
      "nextAction": "Documented review recorded; revisit when the system or evidence changes."
    },
    {
      "id": "scope",
      "title": "Jurisdiction and use-case review",
      "function": "MAP",
      "purpose": "Record who is affected, where outputs are used and which decisions the system can influence. Assign an explicit reviewer to the scope decision.",
      "evidence": "Dated scoping memo with intended use, affected groups, deployment geography, legal questions and unresolved assumptions.",
      "suggestedResponsible": "Legal/compliance lead",
      "suggestedAccountable": "Business owner",
      "euReview": "Check territorial scope, classification and applicable transition rules.",
      "sourceReferences": [
        {
          "label": "NIST AI RMF Playbook: Map",
          "url": "https://airc.nist.gov/airmf-resources/playbook/map/"
        },
        {
          "label": "European Commission: AI Act overview",
          "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
        }
      ],
      "status": "unknown",
      "responsible": "",
      "accountable": "",
      "consulted": "",
      "informed": "",
      "evidenceRef": "",
      "reviewer": "",
      "reviewedOn": "",
      "rationale": "",
      "missing": [
        "responsible",
        "accountable"
      ],
      "nextAction": "Collect evidence or complete review: provide responsible, accountable."
    },
    {
      "id": "risk",
      "title": "Risk register and acceptance",
      "function": "MAP",
      "purpose": "Describe a plausible failure and its consequence for each affected group. Keep open risks visible with the acceptance authority and a review trigger.",
      "evidence": "Risk register containing failure scenarios, impact analysis, mitigation owners, residual risk decisions and change triggers.",
      "suggestedResponsible": "Risk analyst",
      "suggestedAccountable": "Risk owner",
      "euReview": "Review prohibited practices and any high-risk classification.",
      "sourceReferences": [
        {
          "label": "NIST AI RMF Playbook: Map",
          "url": "https://airc.nist.gov/airmf-resources/playbook/map/"
        },
        {
          "label": "European Commission: AI Act overview",
          "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
        }
      ],
      "status": "unknown",
      "responsible": "",
      "accountable": "",
      "consulted": "",
      "informed": "",
      "evidenceRef": "",
      "reviewer": "",
      "reviewedOn": "",
      "rationale": "",
      "missing": [
        "responsible",
        "accountable"
      ],
      "nextAction": "Collect evidence or complete review: provide responsible, accountable."
    },
    {
      "id": "accountability",
      "title": "Accountability and decision authority",
      "function": "GOVERN",
      "purpose": "Name the person who performs the control and the person who accepts its outcome. Record consulted specialists and the people who receive the decision.",
      "evidence": "RACI record plus a release decision log that names risk acceptance authority, escalation route and unresolved objections.",
      "suggestedResponsible": "Governance lead",
      "suggestedAccountable": "Executive sponsor",
      "euReview": "Confirm provider/deployer responsibilities for the particular system.",
      "sourceReferences": [
        {
          "label": "NIST AI RMF Playbook: Govern",
          "url": "https://airc.nist.gov/airmf-resources/playbook/govern/"
        },
        {
          "label": "European Commission: AI Act overview",
          "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
        }
      ],
      "status": "review-recorded",
      "responsible": "Example product lead",
      "accountable": "Example system owner",
      "consulted": "Example governance specialist",
      "informed": "Example support team",
      "evidenceRef": "SYNTHETIC accountability memo v1",
      "reviewer": "Example reviewer",
      "reviewedOn": "2026-09-10",
      "rationale": "Illustrative record, not an observed assessment.",
      "missing": [],
      "nextAction": "Documented review recorded; revisit when the system or evidence changes."
    },
    {
      "id": "literacy",
      "title": "Role-specific training",
      "function": "GOVERN",
      "purpose": "Make training fit the decisions each role actually makes. Operators should rehearse escalation and understand where the system can fail.",
      "evidence": "Training record with role, relevant system limitations, completed exercises, attendance and a refresher trigger.",
      "suggestedResponsible": "Training lead",
      "suggestedAccountable": "System owner",
      "euReview": "Review AI literacy obligations and operator competence.",
      "sourceReferences": [
        {
          "label": "NIST AI RMF Playbook: Govern",
          "url": "https://airc.nist.gov/airmf-resources/playbook/govern/"
        },
        {
          "label": "European Commission: AI Act overview",
          "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
        }
      ],
      "status": "unknown",
      "responsible": "",
      "accountable": "",
      "consulted": "",
      "informed": "",
      "evidenceRef": "",
      "reviewer": "",
      "reviewedOn": "",
      "rationale": "",
      "missing": [
        "responsible",
        "accountable"
      ],
      "nextAction": "Collect evidence or complete review: provide responsible, accountable."
    },
    {
      "id": "supplier",
      "title": "Supplier and model dependencies",
      "function": "GOVERN",
      "purpose": "Record which externally supplied components can change behavior. Include access, version changes and the evidence a provider makes available.",
      "evidence": "Dependency register, supplier instructions, version policy, data-use terms, exit plan and a named owner for vendor changes.",
      "suggestedResponsible": "Vendor manager",
      "suggestedAccountable": "System owner",
      "euReview": "Check upstream model information and downstream responsibilities.",
      "sourceReferences": [
        {
          "label": "NIST AI RMF Playbook: Govern",
          "url": "https://airc.nist.gov/airmf-resources/playbook/govern/"
        },
        {
          "label": "European Commission: AI Act overview",
          "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
        }
      ],
      "status": "not-applicable",
      "responsible": "",
      "accountable": "Example system owner",
      "consulted": "",
      "informed": "",
      "evidenceRef": "",
      "reviewer": "Example reviewer",
      "reviewedOn": "2026-09-10",
      "rationale": "SYNTHETIC SCOPE: model built and hosted entirely in-house, with no external model service. External supplier review excluded; internal dependency and provenance controls remain under inventory and data.",
      "missing": [],
      "nextAction": "Exclusion rationale recorded; revisit applicability when the scope changes."
    },
    {
      "id": "data",
      "title": "Data provenance and access",
      "function": "MAP",
      "purpose": "Trace evaluation and retrieval data to a permitted source. Record sensitive fields, access rules and deletion or correction paths.",
      "evidence": "Data lineage record with allowed uses, quality checks, retention decision, access test and affected population coverage.",
      "suggestedResponsible": "Data lead",
      "suggestedAccountable": "Data owner",
      "euReview": "Review data governance and separate privacy obligations.",
      "sourceReferences": [
        {
          "label": "NIST AI RMF Playbook: Map",
          "url": "https://airc.nist.gov/airmf-resources/playbook/map/"
        },
        {
          "label": "European Commission: AI Act overview",
          "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
        }
      ],
      "status": "unknown",
      "responsible": "",
      "accountable": "",
      "consulted": "",
      "informed": "",
      "evidenceRef": "",
      "reviewer": "",
      "reviewedOn": "",
      "rationale": "",
      "missing": [
        "responsible",
        "accountable"
      ],
      "nextAction": "Collect evidence or complete review: provide responsible, accountable."
    },
    {
      "id": "validation",
      "title": "Validation and failure testing",
      "function": "MEASURE",
      "purpose": "Test the intended use and credible misuse before release. Record subgroup limitations, security failures and the reason for each acceptance threshold.",
      "evidence": "Versioned evaluation set, rubric, measured results, security tests, known limitations and an accepted release decision.",
      "suggestedResponsible": "Evaluation lead",
      "suggestedAccountable": "Release owner",
      "euReview": "Review accuracy, robustness, cybersecurity and supporting documentation.",
      "sourceReferences": [
        {
          "label": "NIST AI RMF Playbook: Measure",
          "url": "https://airc.nist.gov/airmf-resources/playbook/measure/"
        },
        {
          "label": "European Commission: AI Act overview",
          "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
        }
      ],
      "status": "evidence-recorded",
      "responsible": "Example evaluation lead",
      "accountable": "Example release owner",
      "consulted": "",
      "informed": "",
      "evidenceRef": "SYNTHETIC evaluation memo v1; review pending.",
      "reviewer": "",
      "reviewedOn": "",
      "rationale": "",
      "missing": [],
      "nextAction": "Complete review."
    },
    {
      "id": "oversight",
      "title": "Human oversight and user information",
      "function": "MEASURE",
      "purpose": "Test whether an operator can understand a warning, override an action and stop the workflow. Check what users are told about AI involvement.",
      "evidence": "Observed override exercise, authority boundaries, user instructions, escalation path and accessible notices for the intended audience.",
      "suggestedResponsible": "Product/security lead",
      "suggestedAccountable": "System owner",
      "euReview": "Review oversight measures and relevant transparency duties.",
      "sourceReferences": [
        {
          "label": "NIST AI RMF Playbook: Measure",
          "url": "https://airc.nist.gov/airmf-resources/playbook/measure/"
        },
        {
          "label": "European Commission: AI Act overview",
          "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
        }
      ],
      "status": "unknown",
      "responsible": "",
      "accountable": "",
      "consulted": "",
      "informed": "",
      "evidenceRef": "",
      "reviewer": "",
      "reviewedOn": "",
      "rationale": "",
      "missing": [
        "responsible",
        "accountable"
      ],
      "nextAction": "Collect evidence or complete review: provide responsible, accountable."
    },
    {
      "id": "records",
      "title": "Traceability and change records",
      "function": "GOVERN",
      "purpose": "Keep enough context to reconstruct a decision without indiscriminately retaining sensitive payloads. Tie approvals and changes to an identifiable release.",
      "evidence": "Redacted trace sample, version/approval identifiers, retention/access rules and a tested path for retrieving a decision record.",
      "suggestedResponsible": "Platform lead",
      "suggestedAccountable": "System owner",
      "euReview": "Review logging and technical documentation requirements.",
      "sourceReferences": [
        {
          "label": "NIST AI RMF Playbook: Govern",
          "url": "https://airc.nist.gov/airmf-resources/playbook/govern/"
        },
        {
          "label": "European Commission: AI Act overview",
          "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
        }
      ],
      "status": "unknown",
      "responsible": "",
      "accountable": "",
      "consulted": "",
      "informed": "",
      "evidenceRef": "",
      "reviewer": "",
      "reviewedOn": "",
      "rationale": "",
      "missing": [
        "responsible",
        "accountable"
      ],
      "nextAction": "Collect evidence or complete review: provide responsible, accountable."
    },
    {
      "id": "monitoring",
      "title": "Monitoring and response ownership",
      "function": "MANAGE",
      "purpose": "Connect a measured signal to a response owner. Review thresholds against an evaluation baseline and test the recovery path after a breach.",
      "evidence": "Monitoring specification, baseline reference, alert routing, response exercise, rollback target and post-change review record.",
      "suggestedResponsible": "Operations lead",
      "suggestedAccountable": "Service owner",
      "euReview": "Review post-market monitoring and deployer monitoring duties.",
      "sourceReferences": [
        {
          "label": "NIST AI RMF Playbook: Manage",
          "url": "https://airc.nist.gov/airmf-resources/playbook/manage/"
        },
        {
          "label": "European Commission: AI Act overview",
          "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
        }
      ],
      "status": "unknown",
      "responsible": "",
      "accountable": "",
      "consulted": "",
      "informed": "",
      "evidenceRef": "",
      "reviewer": "",
      "reviewedOn": "",
      "rationale": "",
      "missing": [
        "responsible",
        "accountable"
      ],
      "nextAction": "Collect evidence or complete review: provide responsible, accountable."
    },
    {
      "id": "incident",
      "title": "Incident triage and notification",
      "function": "MANAGE",
      "purpose": "Rehearse how an issue becomes an incident, who contains it and who decides whether notification is required. Preserve the incident timeline.",
      "evidence": "Incident playbook and exercise record with severity criteria, containment authority, notification review, recipients and applicable clocks.",
      "suggestedResponsible": "Incident commander",
      "suggestedAccountable": "Accountable incident owner",
      "euReview": "Confirm reportability, recipient and deadline for the specific regime.",
      "sourceReferences": [
        {
          "label": "NIST AI RMF Playbook: Manage",
          "url": "https://airc.nist.gov/airmf-resources/playbook/manage/"
        },
        {
          "label": "European Commission: AI Act overview",
          "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
        }
      ],
      "status": "planned",
      "responsible": "",
      "accountable": "",
      "consulted": "",
      "informed": "",
      "evidenceRef": "SYNTHETIC draft incident playbook; owners unassigned.",
      "reviewer": "",
      "reviewedOn": "",
      "rationale": "",
      "missing": [
        "responsible",
        "accountable"
      ],
      "nextAction": "Collect evidence or complete review: provide responsible, accountable."
    }
  ]
}
