Skip to content

Industry playbook assessment method

Industry playbooks provide sector context, not a shortcut to applicability. Two systems in the same sector can require very different controls because their purpose, data, autonomy, users, affected people and operating environment differ.

Record product and model versions, owner, purpose, users, affected people, supplier, deployment, integrations, data sources, decisions and actions. Separate materially different use cases rather than averaging their exposure into one assessment.

Identify regulated entities and activities, contractual commitments, professional duties, geographies, vulnerable groups and sector safety obligations. Have an appropriate legal or compliance owner confirm jurisdiction-specific conclusions.

Complete intake, ACRS and authoritative routing. Use the industry page to recognise likely triggers, then confirm each one from the actual record. The Governance Weighting Profile may increase review, cadence and escalation; it does not alter factual applicability.

For each material claim, identify owner, artifact, period, system version and test. Typical evidence includes requirements, impact assessments, data lineage, validation, human-oversight procedures, security tests, monitoring, incident records, supplier assurance and decision logs.

Use representative populations, environments and edge cases. Test human escalation, appeal, fallback, access denial, misuse and monitoring, not only expected model accuracy. Agentic systems also require request-level allow, deny, approval, failure and containment tests.

Separate factual scope, assessment score, assurance depth, residual risk and approval. State limitations, conditions, owner, review date and reassessment triggers. Do not describe readiness or mapped support as legal compliance.

Reassess after material changes to purpose, model, data, supplier, affected people, market, autonomy, access, incident history, law or professional guidance. Periodic review does not replace event-driven reassessment.

QualityInterpretation
AssertionA claim with no corroborating artifact.
DocumentedApproved design or procedure exists.
ImplementedOperating records show the design is in use.
AssuredIndependent or appropriately separated testing supports effective operation.