AI governance planning tool

Map AI governance obligations to evidence, owners, and practical actions

Describe an AI system’s operational context to produce a deterministic, non-legal obligation map covering policy, privacy, security, model risk, oversight, transparency, monitoring, incidents, assurance, and third-party controls.

No external APIs or fabricated live data. Results depend on the information supplied and should be reviewed by qualified governance, legal, risk, privacy, security, and sector specialists.
AI governance obligation mapping illustrationA central AI system connected to policy, privacy, security, oversight, monitoring, and assurance controls.PolicySecurityOversightAssurance

How it works

The mapper applies fixed rules to the system context you provide. It does not determine legal status; it helps teams organise questions, evidence, ownership, and implementation work.

1. Describe the context

Enter the jurisdiction, sector, purpose, users, affected groups, deployment, data, automation, consequence, model, vendors, and existing controls.

2. Apply transparent rules

Deterministic weights identify baseline and elevated obligation categories. Existing controls reduce urgency slightly but do not remove the need for evidence.

3. Prioritise delivery

Review rationale, evidence, accountable roles, due actions, unresolved questions, score details, and exportable results.

AI system context

Fields marked required must be completed. Select the most conservative accurate answer when the final design is not yet fixed.

System and organisational context

Example: Customer support response assistant.

Describe the business process, integrations, planned launch, decision flow, and any known exclusions.

Users

Select everyone who directly uses the system or its outputs.

Affected groups

Select people or organisations that may experience a material effect.

Deployment locations

Include user, processing, hosting, support, and operational locations where known.

Data types

Select all data used for training, retrieval, prompts, operation, monitoring, or output.

Automation, consequence, model, and vendors
Existing controls

Select controls that are implemented and can be evidenced. Reported controls reduce priority by one point only; effectiveness is not assumed.

Methodology, limitations, and responsible use

Methodology

The mapper uses a fixed rule set. Context factors add priority points to relevant categories. Each category is capped at 10. A reported existing control subtracts one point from its matching category to reflect reduced implementation urgency, not proven effectiveness.

Scale and thresholds

Category scores: 7–10 high priority, 4–6 applicable, 2–3 baseline, 0–1 monitor. Overall index: 70–100 extensive, 45–69 material, 25–44 moderate, and 0–24 baseline obligation profile.

Limitations

The tool cannot confirm legal applicability, regulatory classification, control design quality, evidence authenticity, vendor behaviour, technical performance, or implementation effectiveness. Requirements may change and differ by jurisdiction or sector.

Use the result

Assign owners, validate the rationales, close unresolved questions, collect evidence, translate actions into dated work items, and record decisions. Re-run the mapper after material design, vendor, data, location, or use changes.

Assumptions

Selections are treated as accurate and current. Higher-consequence, higher-automation, sensitive-data, regulated-sector, cross-border, and externally supplied systems require stronger evidence and assurance.

Governance decision

The score should inform—not replace—risk acceptance, legal analysis, privacy review, security assessment, model validation, procurement due diligence, user research, and operational approval.

Frequently asked questions

Is this legal advice?

No. It is a structured, non-legal planning aid. Qualified legal and regulatory specialists should confirm applicable duties and interpretations.

How is the score calculated?

Fixed context rules add points to 12 governance categories, each capped at 10. Reported existing controls reduce their matching category by one point. The overall index is the rounded percentage of total category points out of 120.

Does a low score mean the system is compliant?

No. A low score only indicates fewer elevated triggers in the selected context. Baseline governance, evidence, security, privacy, monitoring, incident response, and organisational requirements may still apply.

Why are existing controls only given a small reduction?

The tool records that a control is reported but cannot verify design, implementation, testing, coverage, or effectiveness. Evidence and independent review remain necessary.

What should count as an affected group?

Include people or organisations whose access, opportunities, treatment, safety, rights, workload, finances, services, or decisions may be materially influenced by the AI system.

How should global deployments be entered?

Select global or cross-region deployment and document countries for users, hosting, data processing, support, vendors, and model providers. Cross-border details should then be reviewed separately.

Can this tool classify a system under the EU AI Act?

No. It can flag areas that deserve classification and evidence review, but formal classification depends on definitions, intended purpose, deployment context, prohibited practices, exceptions, and current legal interpretation.

What evidence should be collected first?

Begin with the system description, owner, purpose, users, affected groups, architecture, model and vendor details, data map, risk assessment, approvals, operating procedures, monitoring thresholds, and incident process.

Who should own the obligation map?

A named business or system owner should coordinate it, with accountable contributions from AI governance, legal, privacy, security, risk, compliance, procurement, engineering, operations, and internal audit as relevant.

When should the map be updated?

Update it before launch and after material changes to purpose, data, model, automation, users, vendors, jurisdictions, integrations, performance, incidents, or regulatory expectations.

Are exports transmitted externally?

No. CSV and JSON downloads are created locally in the browser. The normal form submission is processed by the hosting server so the PHP page can calculate a result without JavaScript.

Can the output be used as an audit record?

It can support an audit trail when retained with dated inputs, reviewers, evidence, decisions, approvals, and remediation records. By itself, the generated map is not proof that controls are effective or obligations are satisfied.