# AI Governance Readiness Map

Version: 1.0.0

Status: DRAFT_REQUIRES_REVIEW

Draft evidence worksheet requiring human review. Counts describe recorded evidence and exclusions; they do not determine legal compliance.

## Scope
- systemName: SYNTHETIC EXAMPLE: internal support copilot
- intendedUse: Suggest replies for internal support staff; staff approve every response. Illustrative scenario only.
- assessedOn: 2026-09-11
- jurisdiction: eu-review
- euRole: unconfirmed

## Summary
- total: 12
- reviewed: 2
- excluded: 1
- needsAttention: 9

## Scope warnings
- Confirm the EU role for review.

## AI system inventory
- id: inventory
- title: AI system inventory
- function: MAP
- purpose: Give the system a stable identity before assessing it. Include models, retrieval data, prompts, tools and the environments where people use them.
- evidence: Versioned register entry with intended purpose, model/provider identifiers, data sources, deployment location and review triggers.
- suggestedResponsible: Product owner
- suggestedAccountable: System owner
- euReview: Confirm system scope and the organization's role.
- sourceReferences:
  - NIST AI RMF Playbook: Map: https://airc.nist.gov/airmf-resources/playbook/map/
  - European Commission: AI Act overview: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- status: review-recorded
- responsible: Example product lead
- accountable: Example system owner
- consulted: Example governance specialist
- informed: Example support team
- evidenceRef: SYNTHETIC inventory memo v1
- reviewer: Example reviewer
- reviewedOn: 2026-09-10
- rationale: Illustrative record, not an observed assessment.
- missing: &#91;&#93;
- nextAction: Documented review recorded; revisit when the system or evidence changes.

## Jurisdiction and use-case review
- id: scope
- title: Jurisdiction and use-case review
- function: MAP
- purpose: Record who is affected, where outputs are used and which decisions the system can influence. Assign an explicit reviewer to the scope decision.
- evidence: Dated scoping memo with intended use, affected groups, deployment geography, legal questions and unresolved assumptions.
- suggestedResponsible: Legal/compliance lead
- suggestedAccountable: Business owner
- euReview: Check territorial scope, classification and applicable transition rules.
- sourceReferences:
  - NIST AI RMF Playbook: Map: https://airc.nist.gov/airmf-resources/playbook/map/
  - European Commission: AI Act overview: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- status: unknown
- responsible: 
- accountable: 
- consulted: 
- informed: 
- evidenceRef: 
- reviewer: 
- reviewedOn: 
- rationale: 
- missing: &#91;"responsible","accountable"&#93;
- nextAction: Collect evidence or complete review: provide responsible, accountable.

## Risk register and acceptance
- id: risk
- title: Risk register and acceptance
- function: MAP
- purpose: Describe a plausible failure and its consequence for each affected group. Keep open risks visible with the acceptance authority and a review trigger.
- evidence: Risk register containing failure scenarios, impact analysis, mitigation owners, residual risk decisions and change triggers.
- suggestedResponsible: Risk analyst
- suggestedAccountable: Risk owner
- euReview: Review prohibited practices and any high-risk classification.
- sourceReferences:
  - NIST AI RMF Playbook: Map: https://airc.nist.gov/airmf-resources/playbook/map/
  - European Commission: AI Act overview: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- status: unknown
- responsible: 
- accountable: 
- consulted: 
- informed: 
- evidenceRef: 
- reviewer: 
- reviewedOn: 
- rationale: 
- missing: &#91;"responsible","accountable"&#93;
- nextAction: Collect evidence or complete review: provide responsible, accountable.

## Accountability and decision authority
- id: accountability
- title: Accountability and decision authority
- function: GOVERN
- purpose: Name the person who performs the control and the person who accepts its outcome. Record consulted specialists and the people who receive the decision.
- evidence: RACI record plus a release decision log that names risk acceptance authority, escalation route and unresolved objections.
- suggestedResponsible: Governance lead
- suggestedAccountable: Executive sponsor
- euReview: Confirm provider/deployer responsibilities for the particular system.
- sourceReferences:
  - NIST AI RMF Playbook: Govern: https://airc.nist.gov/airmf-resources/playbook/govern/
  - European Commission: AI Act overview: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- status: review-recorded
- responsible: Example product lead
- accountable: Example system owner
- consulted: Example governance specialist
- informed: Example support team
- evidenceRef: SYNTHETIC accountability memo v1
- reviewer: Example reviewer
- reviewedOn: 2026-09-10
- rationale: Illustrative record, not an observed assessment.
- missing: &#91;&#93;
- nextAction: Documented review recorded; revisit when the system or evidence changes.

## Role-specific training
- id: literacy
- title: Role-specific training
- function: GOVERN
- purpose: Make training fit the decisions each role actually makes. Operators should rehearse escalation and understand where the system can fail.
- evidence: Training record with role, relevant system limitations, completed exercises, attendance and a refresher trigger.
- suggestedResponsible: Training lead
- suggestedAccountable: System owner
- euReview: Review AI literacy obligations and operator competence.
- sourceReferences:
  - NIST AI RMF Playbook: Govern: https://airc.nist.gov/airmf-resources/playbook/govern/
  - European Commission: AI Act overview: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- status: unknown
- responsible: 
- accountable: 
- consulted: 
- informed: 
- evidenceRef: 
- reviewer: 
- reviewedOn: 
- rationale: 
- missing: &#91;"responsible","accountable"&#93;
- nextAction: Collect evidence or complete review: provide responsible, accountable.

## Supplier and model dependencies
- id: supplier
- title: Supplier and model dependencies
- function: GOVERN
- purpose: Record which externally supplied components can change behavior. Include access, version changes and the evidence a provider makes available.
- evidence: Dependency register, supplier instructions, version policy, data-use terms, exit plan and a named owner for vendor changes.
- suggestedResponsible: Vendor manager
- suggestedAccountable: System owner
- euReview: Check upstream model information and downstream responsibilities.
- sourceReferences:
  - NIST AI RMF Playbook: Govern: https://airc.nist.gov/airmf-resources/playbook/govern/
  - European Commission: AI Act overview: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- status: not-applicable
- responsible: 
- accountable: Example system owner
- consulted: 
- informed: 
- evidenceRef: 
- reviewer: Example reviewer
- reviewedOn: 2026-09-10
- rationale: SYNTHETIC SCOPE: model built and hosted entirely in-house, with no external model service. External supplier review excluded; internal dependency and provenance controls remain under inventory and data.
- missing: &#91;&#93;
- nextAction: Exclusion rationale recorded; revisit applicability when the scope changes.

## Data provenance and access
- id: data
- title: Data provenance and access
- function: MAP
- purpose: Trace evaluation and retrieval data to a permitted source. Record sensitive fields, access rules and deletion or correction paths.
- evidence: Data lineage record with allowed uses, quality checks, retention decision, access test and affected population coverage.
- suggestedResponsible: Data lead
- suggestedAccountable: Data owner
- euReview: Review data governance and separate privacy obligations.
- sourceReferences:
  - NIST AI RMF Playbook: Map: https://airc.nist.gov/airmf-resources/playbook/map/
  - European Commission: AI Act overview: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- status: unknown
- responsible: 
- accountable: 
- consulted: 
- informed: 
- evidenceRef: 
- reviewer: 
- reviewedOn: 
- rationale: 
- missing: &#91;"responsible","accountable"&#93;
- nextAction: Collect evidence or complete review: provide responsible, accountable.

## Validation and failure testing
- id: validation
- title: Validation and failure testing
- function: MEASURE
- purpose: Test the intended use and credible misuse before release. Record subgroup limitations, security failures and the reason for each acceptance threshold.
- evidence: Versioned evaluation set, rubric, measured results, security tests, known limitations and an accepted release decision.
- suggestedResponsible: Evaluation lead
- suggestedAccountable: Release owner
- euReview: Review accuracy, robustness, cybersecurity and supporting documentation.
- sourceReferences:
  - NIST AI RMF Playbook: Measure: https://airc.nist.gov/airmf-resources/playbook/measure/
  - European Commission: AI Act overview: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- status: evidence-recorded
- responsible: Example evaluation lead
- accountable: Example release owner
- consulted: 
- informed: 
- evidenceRef: SYNTHETIC evaluation memo v1; review pending.
- reviewer: 
- reviewedOn: 
- rationale: 
- missing: &#91;&#93;
- nextAction: Complete review.

## Human oversight and user information
- id: oversight
- title: Human oversight and user information
- function: MEASURE
- purpose: Test whether an operator can understand a warning, override an action and stop the workflow. Check what users are told about AI involvement.
- evidence: Observed override exercise, authority boundaries, user instructions, escalation path and accessible notices for the intended audience.
- suggestedResponsible: Product/security lead
- suggestedAccountable: System owner
- euReview: Review oversight measures and relevant transparency duties.
- sourceReferences:
  - NIST AI RMF Playbook: Measure: https://airc.nist.gov/airmf-resources/playbook/measure/
  - European Commission: AI Act overview: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- status: unknown
- responsible: 
- accountable: 
- consulted: 
- informed: 
- evidenceRef: 
- reviewer: 
- reviewedOn: 
- rationale: 
- missing: &#91;"responsible","accountable"&#93;
- nextAction: Collect evidence or complete review: provide responsible, accountable.

## Traceability and change records
- id: records
- title: Traceability and change records
- function: GOVERN
- purpose: Keep enough context to reconstruct a decision without indiscriminately retaining sensitive payloads. Tie approvals and changes to an identifiable release.
- evidence: Redacted trace sample, version/approval identifiers, retention/access rules and a tested path for retrieving a decision record.
- suggestedResponsible: Platform lead
- suggestedAccountable: System owner
- euReview: Review logging and technical documentation requirements.
- sourceReferences:
  - NIST AI RMF Playbook: Govern: https://airc.nist.gov/airmf-resources/playbook/govern/
  - European Commission: AI Act overview: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- status: unknown
- responsible: 
- accountable: 
- consulted: 
- informed: 
- evidenceRef: 
- reviewer: 
- reviewedOn: 
- rationale: 
- missing: &#91;"responsible","accountable"&#93;
- nextAction: Collect evidence or complete review: provide responsible, accountable.

## Monitoring and response ownership
- id: monitoring
- title: Monitoring and response ownership
- function: MANAGE
- purpose: Connect a measured signal to a response owner. Review thresholds against an evaluation baseline and test the recovery path after a breach.
- evidence: Monitoring specification, baseline reference, alert routing, response exercise, rollback target and post-change review record.
- suggestedResponsible: Operations lead
- suggestedAccountable: Service owner
- euReview: Review post-market monitoring and deployer monitoring duties.
- sourceReferences:
  - NIST AI RMF Playbook: Manage: https://airc.nist.gov/airmf-resources/playbook/manage/
  - European Commission: AI Act overview: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- status: unknown
- responsible: 
- accountable: 
- consulted: 
- informed: 
- evidenceRef: 
- reviewer: 
- reviewedOn: 
- rationale: 
- missing: &#91;"responsible","accountable"&#93;
- nextAction: Collect evidence or complete review: provide responsible, accountable.

## Incident triage and notification
- id: incident
- title: Incident triage and notification
- function: MANAGE
- purpose: Rehearse how an issue becomes an incident, who contains it and who decides whether notification is required. Preserve the incident timeline.
- evidence: Incident playbook and exercise record with severity criteria, containment authority, notification review, recipients and applicable clocks.
- suggestedResponsible: Incident commander
- suggestedAccountable: Accountable incident owner
- euReview: Confirm reportability, recipient and deadline for the specific regime.
- sourceReferences:
  - NIST AI RMF Playbook: Manage: https://airc.nist.gov/airmf-resources/playbook/manage/
  - European Commission: AI Act overview: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- status: planned
- responsible: 
- accountable: 
- consulted: 
- informed: 
- evidenceRef: SYNTHETIC draft incident playbook; owners unassigned.
- reviewer: 
- reviewedOn: 
- rationale: 
- missing: &#91;"responsible","accountable"&#93;
- nextAction: Collect evidence or complete review: provide responsible, accountable.
