| AI risk-classification framework | Define how systems are assigned to tiers. | Criteria, thresholds, examples, overrides, evidence rules and reassessment triggers. | AI governance, risk, legal, product and technology teams. |
| Classification questionnaire | Collect consistent evidence from system owners. | Purpose, affected groups, data, autonomy, impact, oversight, vendor and monitoring questions. | Use-case owners, procurement and reviewers. |
| AI system classification register | Maintain the portfolio decision record. | Tier, rationale, evidence status, owner, reviewers, approvals, conditions and review date. | Governance forums, audit and programme teams. |
| Tier-to-control matrix | Apply proportionate governance. | Required assessments, tests, approvals, documentation, monitoring and incident routes. | Delivery, assurance, risk and compliance teams. |
| Decision and exception procedure | Handle ambiguous, urgent or disputed cases. | Escalation thresholds, decision rights, conflict handling and exception expiry. | Accountable executives and governance committees. |
| Training and handover pack | Enable repeatable internal use. | Guidance, worked examples, facilitator notes, reviewer checklist and maintenance plan. | Internal governance and operational teams. |