1. Build a decision-ready inventory
Record systems, models, vendors, data, users, purpose and affected processes. The inventory must reveal where AI influences people, rights, security, quality or continuity—not merely list tools.
2. Connect value, risk and accountability
Assess expected value, impact, likelihood, reversibility and applicable obligations together. Assign business and technical owners, data accountability, escalation, human oversight and the authority to suspend a system.
3. Make evidence part of operations
Policies matter when linked to registers, testing, decision logs, performance monitoring, incident handling, change control and review. ISO/IEC 42001 provides a management-system structure; the AI Act creates risk-based legal obligations. They are related, not interchangeable.
| Question | Minimum evidence |
|---|---|
| Which AI systems are used? | Inventory with purpose, owner, data and vendor |
| Which risks are accepted? | Documented assessment and acceptance criteria |
| How is degradation detected? | Metrics, thresholds, logs and review |