Purpose and use
AI use cases, agents, models, vendors, and embedded features can enter review without one current record of ownership, intended use, dependencies, human authority, risk, evidence, release conditions, and retirement.
Who should use it
Business owners, technical owners, risk, security, privacy, legal, accessibility, procurement, operations, and delivery stakeholders who need one shared record of the reviewed system state.
Decision supported
What exactly is this AI system, who owns its consequences, what evidence supports the current state, and under what conditions may it proceed, pause, roll back, or retire?
Identity and ownership
Record the current answer, owner, supporting evidence, unknowns, and next review trigger. Use the organization's own risk language rather than treating this worksheet as a universal scoring model.
- System, use-case, agent, model, vendor, and business-process name
- Business owner, technical owner, risk or policy owner, and release authority
- Lifecycle state, review date, next review trigger, and retained record location
- Intended users, affected people, environments, and organizational boundary
Intended use and prohibited use
Record the current answer, owner, supporting evidence, unknowns, and next review trigger. Use the organization's own risk language rather than treating this worksheet as a universal scoring model.
- Business problem, expected benefit, and decision the system supports
- Approved context, user population, geography, and operating conditions
- Explicit prohibited uses, unsupported decisions, and out-of-scope populations
- Known assumptions, unknowns, and conditions that invalidate the current approval
System, data, and dependency boundary
Record the current answer, owner, supporting evidence, unknowns, and next review trigger. Use the organization's own risk language rather than treating this worksheet as a universal scoring model.
- Models, prompts, retrieval, agents, tools, APIs, vendors, and downstream actions
- Data sources, classifications, trust states, access controls, retention, and deletion
- External dependencies, failure modes, fallback paths, and concentration risk
- Versioned configuration and change sources needed to reproduce the reviewed state
Consequence and human authority
Record the current answer, owner, supporting evidence, unknowns, and next review trigger. Use the organization's own risk language rather than treating this worksheet as a universal scoring model.
- Consequential outputs or actions and who may be affected
- Proposal, review, approval, execution, appeal, override, and escalation roles
- Actions the system may never take automatically
- Evidence and interface cues reviewers need to make an informed decision
Risk and concern inventory
Record the current answer, owner, supporting evidence, unknowns, and next review trigger. Use the organization's own risk language rather than treating this worksheet as a universal scoring model.
- Organization-defined risk tier and the rationale for that tier
- Safety, security, privacy, fairness, accessibility, reliability, legal, operational, and vendor concerns
- Impact, likelihood, uncertainty, affected parties, mitigations, owners, and residual risk
- Issues that require deeper review, independent expertise, or a stop decision
Evidence and evaluation
Record the current answer, owner, supporting evidence, unknowns, and next review trigger. Use the organization's own risk language rather than treating this worksheet as a universal scoring model.
- Golden, edge, ambiguous, adversarial, refusal, access-control, and failure cases
- Evaluation environment, fixtures, measures, thresholds, reviewers, and observed results
- Known limitations, disagreement, exceptions, missing evidence, and unresolved questions
- Links to versioned system cards, test results, data or model documentation, and decision records
Release decision and conditions
Record the current answer, owner, supporting evidence, unknowns, and next review trigger. Use the organization's own risk language rather than treating this worksheet as a universal scoring model.
- Decision: proposed, discovery, pilot, conditional approval, approved for bounded use, paused, or retired
- Approved scope, release conditions, exceptions, expiry, and required approvers
- Rollback, blocked-action, incident, notification, and recovery criteria
- Monitoring, change review, retraining or vendor-update triggers, and evidence-retention expectations
Retirement and handoff
Record the current answer, owner, supporting evidence, unknowns, and next review trigger. Use the organization's own risk language rather than treating this worksheet as a universal scoring model.
- Decommissioning trigger, owner, user communication, and continuity path
- Data, record, model, prompt, integration, and credential disposition
- Client-owned artifacts, export formats, retained knowledge, and successor-system dependencies
- Final review outcome, remaining obligations, and archive location