Skip to content

AI governance, security and risk

Use this collection to organise questions about an AI system and assign responsibility for the answers. Assessment tools support review planning; their scores do not certify a supplier or determine legal compliance.

Step 1

Identify data and workflow exposure

Document the information entering the system, who can access it, and where outputs are used. The relevant review depends on the actual workflow and the consequences of an incorrect result.

Start a data privacy assessment

Step 2

Review evidence for controls

Collect supplier documentation and your own operating requirements. Check access, retention, auditability, and incident processes, and have the appropriate security or legal owner resolve unanswered questions.

Review the security checklist

Step 3

Assign ongoing ownership

Define who maintains controls, reviews changes, and records incidents after deployment. Treat assessment results as a starting point for action rather than a permanent pass or fail.

Plan governance responsibilities

See how sources, assumptions, and editorial judgements are distinguished in our evaluation methodology.