1. Transparency & inventory (LAND)
- Central AI register in place?Is there a list of all AI systems used in the company – including shadow AI and browser extensions?
- Vendor transparency?Are vendors, their countries of origin and the type of data processing documented?
2. Risk classification (TRIAGE)
- EU AI Act classification?Do we know which use cases could be classified as “high risk” or “prohibited”?
- Standardised risk triage?Is there a process to review new AI ideas for compliance and security before implementation?
3. Roles & responsibilities (EXPAND)
- Defined AI system owners?Is it clear for every system who holds business responsibility and monitors policy compliance?
- Governance gates established?Are there defined approval points (e.g. by IT security, legal, data protection) before go-live?
4. Evidence & operations (SCALE)
- Evidence routine in place?In case of an audit, can we immediately present documentation on training data, tests and risk assessments?
- Continuous monitoring?Are performance, bias and compliance of AI systems monitored during operation?
Evaluation
Ticked “no” more than three times? Then it is worth putting your AI governance on a solid foundation. Book a free 30-minute risk triage.
How AI governance works with FutureProfAI