| AI System Inventory / Registry |
| System Name | |
| Deployment Stage | |
| EU Classification Required | |
| NIST AI RMF | |
| Human Oversight Required | |
| Review Dates | |
| Link to Model Card | |
| Link to Risk Assessment | |
| Regulatory Framework Required | |
| AI Model Card |
| Model Name | |
| Model Version | |
| Architecture Required | |
| Intended User | |
| Out of Scope | e.g., Do not use for non‑medical claims |
| Performance Metric | |
| Fairness & Bias Matrix | |
| Contract / Escalation Required | |
| AI Risk Assessment |
| System Name / ID | Example: Claim System |
| Owner | |
| Case Description | |
| EU Act Required | |
| Impacted Population | |
| Data Source Required | |
| Risk Rating (Likelihood × Impact) | |
| Known Limitations | e.g., Model underperforms on rare disease codes <0.1% prevalence |
| Mitigation Controls |
1) Human‑in‑the‑loop for all decisions
2) Output confidence threshold: <85% triggers manual review
3) Monthly bias testing on protected classes
4) Model versioning with rollback
|
| Residual Risk Sign‑off | |
| LLM Prompt Usage / Logs |
| Prompt Logs | Logs of prompts (input & output) |
| Guardrails | Input & output guardrails enforced |
| System Prompt Security | Securing system prompts |
| AI Incident Report |
| Standard Followed | ISO 27001 |
| AI Vendor Assessment |
| AI Governance Framework | |
| SOC 2 / ISO 27001 / ISO 42001 Certifications | |
| Compliance with EU AI Act / NIST AI RMF | |
| Defined AI Ownership & Accountability | |
| Encryption & MFA Implemented | |
| Vulnerability Management & Incident Response | |
| Customer Data Ownership & Residency | |
| No Unauthorized Use of Customer Data | |
| Training Data Sources Documented | |
| Model Cards & Intended Use Documented | |
| Model Limitations & Explainability | |
| Version Control & Change Management | |
| Bias Testing & Fairness Assessments | |
| Human Oversight & Escalation | |
| Model Drift Monitoring | |
| SLA, BCP & Disaster Recovery | |
| Right‑to‑Audit Clause | |
| Subprocessor Disclosure | |
| IP Ownership & Liability Terms | |
| Exit Strategy & Data Deletion | |
| Vendor Risk Assessment Completed | |
| Residual Risks Approved | |
| Periodic Reassessment Scheduled | |
| Bias & Fairness Audit |
| Fairness Objectives Defined | ☐ |
| Protected Groups Identified | ☐ |
| Representative Datasets Assessed | ☐ |
| Fairness Metrics Tested | ☐ |
| Pre‑Deployment Bias Assessment | ☐ |
| Ongoing Monitoring | ☐ |
| Human Oversight Documented | ☐ |
| Mitigation Controls Implemented | ☐ |
| Model Card Includes Limitations | ☐ |
| Residual Risk Approved | ☐ |