Industry playbook assessment method
Industry playbooks provide sector context, not a shortcut to applicability. Two systems in the same sector can require very different controls because their purpose, data, autonomy, users, affected people and operating environment differ.
1. Establish the system boundary
Section titled “1. Establish the system boundary”Record product and model versions, owner, purpose, users, affected people, supplier, deployment, integrations, data sources, decisions and actions. Separate materially different use cases rather than averaging their exposure into one assessment.
2. Confirm sector and legal facts
Section titled “2. Confirm sector and legal facts”Identify regulated entities and activities, contractual commitments, professional duties, geographies, vulnerable groups and sector safety obligations. Have an appropriate legal or compliance owner confirm jurisdiction-specific conclusions.
3. Route from facts
Section titled “3. Route from facts”Complete intake, ACRS and authoritative routing. Use the industry page to recognise likely triggers, then confirm each one from the actual record. The Governance Weighting Profile may increase review, cadence and escalation; it does not alter factual applicability.
4. Build the evidence plan
Section titled “4. Build the evidence plan”For each material claim, identify owner, artifact, period, system version and test. Typical evidence includes requirements, impact assessments, data lineage, validation, human-oversight procedures, security tests, monitoring, incident records, supplier assurance and decision logs.
5. Test realistic failure
Section titled “5. Test realistic failure”Use representative populations, environments and edge cases. Test human escalation, appeal, fallback, access denial, misuse and monitoring, not only expected model accuracy. Agentic systems also require request-level allow, deny, approval, failure and containment tests.
6. Record the decision
Section titled “6. Record the decision”Separate factual scope, assessment score, assurance depth, residual risk and approval. State limitations, conditions, owner, review date and reassessment triggers. Do not describe readiness or mapped support as legal compliance.
7. Monitor sector-specific change
Section titled “7. Monitor sector-specific change”Reassess after material changes to purpose, model, data, supplier, affected people, market, autonomy, access, incident history, law or professional guidance. Periodic review does not replace event-driven reassessment.
Evidence quality scale
Section titled “Evidence quality scale”| Quality | Interpretation |
|---|---|
| Assertion | A claim with no corroborating artifact. |
| Documented | Approved design or procedure exists. |
| Implemented | Operating records show the design is in use. |
| Assured | Independent or appropriately separated testing supports effective operation. |