1. Describe the context
Enter the jurisdiction, sector, purpose, users, affected groups, deployment, data, automation, consequence, model, vendors, and existing controls.
AI governance planning tool
Describe an AI system’s operational context to produce a deterministic, non-legal obligation map covering policy, privacy, security, model risk, oversight, transparency, monitoring, incidents, assurance, and third-party controls.
The mapper applies fixed rules to the system context you provide. It does not determine legal status; it helps teams organise questions, evidence, ownership, and implementation work.
Enter the jurisdiction, sector, purpose, users, affected groups, deployment, data, automation, consequence, model, vendors, and existing controls.
Deterministic weights identify baseline and elevated obligation categories. Existing controls reduce urgency slightly but do not remove the need for evidence.
Review rationale, evidence, accountable roles, due actions, unresolved questions, score details, and exportable results.
Fields marked required must be completed. Select the most conservative accurate answer when the final design is not yet fixed.
The mapper uses a fixed rule set. Context factors add priority points to relevant categories. Each category is capped at 10. A reported existing control subtracts one point from its matching category to reflect reduced implementation urgency, not proven effectiveness.
Category scores: 7–10 high priority, 4–6 applicable, 2–3 baseline, 0–1 monitor. Overall index: 70–100 extensive, 45–69 material, 25–44 moderate, and 0–24 baseline obligation profile.
The tool cannot confirm legal applicability, regulatory classification, control design quality, evidence authenticity, vendor behaviour, technical performance, or implementation effectiveness. Requirements may change and differ by jurisdiction or sector.
Assign owners, validate the rationales, close unresolved questions, collect evidence, translate actions into dated work items, and record decisions. Re-run the mapper after material design, vendor, data, location, or use changes.
Selections are treated as accurate and current. Higher-consequence, higher-automation, sensitive-data, regulated-sector, cross-border, and externally supplied systems require stronger evidence and assurance.
The score should inform—not replace—risk acceptance, legal analysis, privacy review, security assessment, model validation, procurement due diligence, user research, and operational approval.
No. It is a structured, non-legal planning aid. Qualified legal and regulatory specialists should confirm applicable duties and interpretations.
Fixed context rules add points to 12 governance categories, each capped at 10. Reported existing controls reduce their matching category by one point. The overall index is the rounded percentage of total category points out of 120.
No. A low score only indicates fewer elevated triggers in the selected context. Baseline governance, evidence, security, privacy, monitoring, incident response, and organisational requirements may still apply.
The tool records that a control is reported but cannot verify design, implementation, testing, coverage, or effectiveness. Evidence and independent review remain necessary.
Include people or organisations whose access, opportunities, treatment, safety, rights, workload, finances, services, or decisions may be materially influenced by the AI system.
Select global or cross-region deployment and document countries for users, hosting, data processing, support, vendors, and model providers. Cross-border details should then be reviewed separately.
No. It can flag areas that deserve classification and evidence review, but formal classification depends on definitions, intended purpose, deployment context, prohibited practices, exceptions, and current legal interpretation.
Begin with the system description, owner, purpose, users, affected groups, architecture, model and vendor details, data map, risk assessment, approvals, operating procedures, monitoring thresholds, and incident process.
A named business or system owner should coordinate it, with accountable contributions from AI governance, legal, privacy, security, risk, compliance, procurement, engineering, operations, and internal audit as relevant.
Update it before launch and after material changes to purpose, data, model, automation, users, vendors, jurisdictions, integrations, performance, incidents, or regulatory expectations.
No. CSV and JSON downloads are created locally in the browser. The normal form submission is processed by the hosting server so the PHP page can calculate a result without JavaScript.
It can support an audit trail when retained with dated inputs, reviewers, evidence, decisions, approvals, and remediation records. By itself, the generated map is not proof that controls are effective or obligations are satisfied.