| AI inventory and classification | Use cases, owners, models, vendors, data, users, jurisdictions, status, and risk tier | Register and taxonomy | Assessment | Product and architecture evidence | AI governance owner |
| Responsible-AI gap assessment | Current controls, evidence, gaps, risks, dependencies, and priorities | Report and action plan | Assessment | Policies, records, interviews | Risk or programme sponsor |
| Governance and operating model | Decision rights, RACI, committees, escalation, exceptions, and reporting | Framework and role pack | Design | Organisation and risk appetite | Executive sponsor |
| Lifecycle control library | Requirements for design, data, vendors, testing, release, monitoring, incidents, and retirement | Control matrix and procedures | Design | Delivery lifecycle and tooling | Product and engineering |
| AI evaluation plan | Risk-based test cases, data sets, metrics, thresholds, human review, regression, and evidence | Evaluation specification | Implementation | Use-case objectives and samples | Product and ML owners |
| Transparency and assurance pack | System description, intended use, limitations, oversight, data and vendor summary, and evidence index | Customer-ready documentation | Assurance | Approved facts and legal review | Product, legal, and trust teams |
| Monitoring and incident framework | Metrics, alerts, review cadence, complaints, escalation, containment, notification, and lessons learned | Playbook and dashboard design | Operations | Telemetry and support processes | Operations and incident owner |
| Training and knowledge transfer | Role-based awareness, reviewer guidance, templates, scenarios, and handover | Workshops and materials | Transition | Audience and internal policy | Governance and learning leads |