AI System Inventory / Registry
System Name
Deployment Stage
EU Classification Required
NIST AI RMF
Human Oversight Required
Review Dates
Link to Model Card
Link to Risk Assessment
Regulatory Framework Required
AI Model Card
Model Name
Model Version
Architecture Required
Intended User
Out of Scopee.g., Do not use for non‑medical claims
Performance Metric
Fairness & Bias Matrix
Contract / Escalation Required
AI Risk Assessment
System Name / IDExample: Claim System
Owner
Case Description
EU Act Required
Impacted Population
Data Source Required
Risk Rating (Likelihood × Impact)
Known Limitationse.g., Model underperforms on rare disease codes <0.1% prevalence
Mitigation Controls 1) Human‑in‑the‑loop for all decisions
2) Output confidence threshold: <85% triggers manual review
3) Monthly bias testing on protected classes
4) Model versioning with rollback
Residual Risk Sign‑off
LLM Prompt Usage / Logs
Prompt LogsLogs of prompts (input & output)
GuardrailsInput & output guardrails enforced
System Prompt SecuritySecuring system prompts
AI Incident Report
Standard FollowedISO 27001
AI Vendor Assessment
AI Governance Framework
SOC 2 / ISO 27001 / ISO 42001 Certifications
Compliance with EU AI Act / NIST AI RMF
Defined AI Ownership & Accountability
Encryption & MFA Implemented
Vulnerability Management & Incident Response
Customer Data Ownership & Residency
No Unauthorized Use of Customer Data
Training Data Sources Documented
Model Cards & Intended Use Documented
Model Limitations & Explainability
Version Control & Change Management
Bias Testing & Fairness Assessments
Human Oversight & Escalation
Model Drift Monitoring
SLA, BCP & Disaster Recovery
Right‑to‑Audit Clause
Subprocessor Disclosure
IP Ownership & Liability Terms
Exit Strategy & Data Deletion
Vendor Risk Assessment Completed
Residual Risks Approved
Periodic Reassessment Scheduled
Bias & Fairness Audit
Fairness Objectives Defined
Protected Groups Identified
Representative Datasets Assessed
Fairness Metrics Tested
Pre‑Deployment Bias Assessment
Ongoing Monitoring
Human Oversight Documented
Mitigation Controls Implemented
Model Card Includes Limitations
Residual Risk Approved