Assessment workflow
1. Select the system
Section titled “1. Select the system”Confirm the selected system, version and use context. Switching systems changes the assessment and AI-analysis scope.
2. Establish the assessment boundary
Section titled “2. Establish the assessment boundary”Record intended use, foreseeable misuse, organisational role, lifecycle stage, dependencies, deployment environment, users and affected parties.
3. Confirm triggers and responsibilities
Section titled “3. Confirm triggers and responsibilities”Identify why the assessment is being performed, who leads it, which disciplines participate, who approves it and which thresholds require escalation.
4. Gather system information
Section titled “4. Gather system information”Collect data, model, algorithm, capability, limitation, deployment and monitoring information. State unknowns explicitly.
5. Engage relevant parties
Section titled “5. Engage relevant parties”Determine who needs to be consulted, how participation will be accessible and safe, and how input will affect decisions. Explain any limits on engagement.
6. Assess all 119 items
Section titled “6. Assess all 119 items”For each item:
- Read the clause-aligned objective and advisory.
- Select maturity from 1 to 5.
- Record assurance depth separately.
- Write system-specific rationale.
- Link evidence and tests.
- Record any approved N/A basis.
- Raise findings for gaps or adverse evidence.
7. Analyse impacts
Section titled “7. Analyse impacts”Consider benefits and harms across people, groups and society, including fairness, privacy, safety, security, accessibility, explainability, accountability, environment, labour, culture and foreseeable misuse where relevant.
8. Select measures
Section titled “8. Select measures”For each material impact, document:
- Prevention, reduction or enhancement measure.
- Owner and deadline.
- Expected effect and success measure.
- Residual impact and uncertainty.
- Monitoring and escalation.
- Decision if adequate treatment is not possible.
9. Review contradictions
Section titled “9. Review contradictions”Check whether:
- A high maturity claim lacks operating evidence.
- A favourable conclusion conflicts with a failed test or open finding.
- Affected parties were identified but not engaged.
- An N/A decision removes a material impact without approval.
- Monitoring cannot detect the impact it is meant to manage.
10. Write and approve the conclusion
Section titled “10. Write and approve the conclusion”State system scope, method, participants, material benefits and harms, measures, residual impacts, limitations, publication decision, owner and reassessment triggers.
11. Monitor and reassess
Section titled “11. Monitor and reassess”Review the assessment after change, incident, complaint, performance drift, new affected population, new evidence or changed external conditions.
Completion checklist
Section titled “Completion checklist”- Correct system and version selected.
- Intended use and foreseeable misuse documented.
- Affected parties identified.
- Responsibilities and thresholds approved.
- All 119 items considered.
- Maturity and assurance are separate.
- N/A decisions are structured and approved.
- Engagement evidence and limitations are recorded.
- Material impacts have measures and owners.
- Adverse evidence is reflected.
- Human conclusion and reassessment triggers are complete.