IN BRIEF

A practical, non-certifying checklist for inventory, role mapping, risk review, evidence and monitoring.

01 / ORGANISE

Discover

Build an inventory with owners, suppliers, intended purposes, deployment regions and affected groups.

  • Identify systems and model dependencies
  • Map provider and deployer roles
  • Record intended and actual uses
02 / ORGANISE

Assess

Screen for prohibited practices, high-risk criteria, transparency duties and GPAI model responsibilities. Document open questions and the legal basis for decisions.

  • Check Article 5 and Article 6
  • Review relevant Annexes
  • Set review dates as guidance evolves
03 / ORGANISE

Operate

Assign control owners for documentation, oversight, testing, incident handling, training and change management according to applicable duties.

  • Retain review evidence
  • Track system changes
  • Reassess when intended purpose changes
Verify the source

This guide is an orientation, not a legal determination. Check the current legal text and official implementation guidance for your system.

Read the AI Act ↗European Commission overview ↗