| AI-system inventory | Use case, purpose, owner, users, affected persons, model or vendor, data, integrations, lifecycle stage, geography, and business criticality. | Creates the controlled population for classification, governance, and remediation. |
| Operator-role matrix | Preliminary mapping of provider, deployer, importer, distributor, product-manufacturer, and value-chain responsibilities. | Clarifies which teams and third parties need to supply evidence or take action. |
| Risk and obligation map | Screening for prohibited practices, high-risk categories, transparency duties, GPAI dependencies, and other relevant obligations. | Focuses detailed review on systems with the greatest legal, operational, and reputational exposure. |
| Control and evidence assessment | Current controls, documented evidence, design gaps, operating gaps, ownership gaps, and confidence level. | Separates missing documentation from missing control design and ineffective operation. |
| Prioritised gap register | Finding, affected system, rationale, severity, dependency, accountable owner, target action, and verification method. | Turns findings into a governed remediation backlog. |
| Readiness roadmap | Immediate containment, near-term remediation, operating-model improvements, technology enablement, training, and assurance activities. | Supports investment, sequencing, resource planning, and executive oversight. |
| Executive briefing | Portfolio exposure, key uncertainties, decision points, major dependencies, residual risks, and recommended next actions. | Enables board, executive, risk, compliance, and programme decisions. |