Use-case intake
Document purpose, users, decisions, data, model or service, integrations, owners, and expected value.
Exact scope, evidence, access, stakeholders, and acceptance criteria are agreed before delivery.
Document purpose, users, decisions, data, model or service, integrations, owners, and expected value.
Assess security, privacy, legal, bias, reliability, transparency, human oversight, vendor, and operational risk.
Specify evidence, guardrails, testing, access, monitoring, documentation, human review, and incident requirements.
Record risk tier, conditions of use, residual risk, approval, exceptions, and review triggers.
Confirm the business driver, environment, stakeholders, boundaries, assumptions, and evidence needs.
Review the current state, evidence, architecture, risks, dependencies, and material gaps.
Develop the agreed controls, artifacts, recommendations, implementation, or operating routines.
Confirm completion, residual risk, ownership, reporting, and the next improvement priorities.