Define the review boundary
Record the entity, purpose, workflow, system version, affected people and included information. Name the business owner and specialist reviewers.
List exclusions and unknowns. Without a defined population, “review complete” has no clear meaning.
Working checklist
| Area | Question to resolve | Evidence to consider |
|---|---|---|
| Applicability | Which legal, contractual and internal requirements apply? | Scoped specialist assessment and basis |
| Purpose | Why is the use needed and what may it do? | Use-case boundary and approved purpose |
| Information | What is collected, used, generated, shared and retained? | Information-flow map and product-specific terms |
| Affected decisions | How does the program influence outcomes about people? | Workflow, inputs, outputs and actual human role |
| Fairness and quality | What material errors or unequal outcomes need assessment? | Representative evaluation and specialist analysis |
| Security | What can the system access or change? | Implemented permissions, testing and response arrangements |
| Claims and communications | What is said to users and customers? | Reviewed wording and substantiation |
| Intellectual property | What rights support inputs and intended outputs? | Licences, permissions and relevant legal review |
| Vendors | Which dependencies and processing arrangements matter? | Contracts, service boundaries and exit evidence |
| Operation | Who monitors, changes, interrupts and retires the use? | Named owners and tested operating procedures |
Not every row establishes a mandatory legal obligation for every use. The reviewer must distinguish law, guidance, contract and internal practice.
Add an evidence status
Use supported within scope, action required, not assessed, or not applicable with reason. Record who made the judgement and on what basis.
Do not convert “not assessed” into “compliant”. Do not call an uncertainty a breach without assessment.
Assign the next action
For each unresolved question, name the evidence needed, owner and review date. Identify decisions that cannot proceed until a material issue is resolved.
Changes in purpose, information, model, tools or permissions can require a new assessment. Completion is not permanent approval for every future configuration.
Download the checklist, assign an owner for each section, and set your deadlines. If you need help completing it, the ADM Transparency Sprint (6 weeks) covers Sections 1 through 3 with guaranteed compliance by 10 December 2026.
Discuss your AI problemRelated Topics
Explore This Pillar
Go deeper with the matching master pillar and the most relevant supporting topics for this page.