| Executive risk summary | Purpose, overall risk position, material findings, evidence gaps, limitations, and recommended decision | Approval, restriction, remediation, or escalation | Executive sponsor or AI governance committee |
| Model risk assessment report | Scope, methodology, evidence reviewed, tests performed, findings, severity, rationale, and limitations | Independent challenge and assurance record | Model risk, internal audit, compliance, or technology risk |
| Control and evidence matrix | Required controls, available evidence, design assessment, operating evidence, gaps, and owners | Control remediation and audit readiness | Model owner and control owners |
| Test-results pack | Performance, subgroup, calibration, robustness, explainability, data-quality, or security-related test outputs | Technical validation and acceptance criteria | Data science, validation, engineering, and risk teams |
| Risk and remediation register | Finding, impact, likelihood, severity, action, owner, dependency, target state, and closure evidence | Prioritised remediation management | Programme or model owner |
| Monitoring and review plan | Metrics, thresholds, alerts, review cadence, escalation, retraining triggers, and retirement criteria | Ongoing operational control | Model operations and business owner |
| Supplier due-diligence appendix | Vendor evidence, contractual gaps, model transparency, data handling, service controls, and exit risks | Procurement and third-party risk decisions | Procurement, legal, security, and risk |