01AI-System, Model and Provider Adoption
Examine an AI system, model or provider before adoption, procurement, integration or wider organisational use.
This may include reviewing evidence relating to performance, limitations, governance, security, infrastructure, reliability and responsible operation.
02AI Claims and Disclosure Verification
Assess whether material claims made by providers, vendors, issuers or internal teams are supported by relevant and current evidence.
Claims may relate to capability, performance, certification, assurance, governance, security, sovereignty or operational control.
03Agent Identity, Authority and Permissions
Understand what an AI agent is, whose authority it acts under, what it may access and which actions it can perform, trigger or delegate.
This may include permissions, tool access, workflow authority, delegated decision-making and accountability records.
04Evidence, Provenance and Assurance Records
Establish structured evidence connecting AI systems, claims, decisions, controls, data sources, providers and organisational reliance.
This can support traceability, evidence gaps, provenance and more defensible trust decisions.
05Runtime Monitoring and Re-Verification
Identify what should be monitored after adoption and which changes should trigger renewed verification.
Relevant changes may include model updates, new tools, permissions, data sources, providers, integrations, infrastructure or operating conditions.
06Sovereignty, Infrastructure and Dependency
Understand the jurisdictions, infrastructure, providers, data flows and technical or commercial dependencies supporting organisational use of AI.
This can support decisions relating to sovereignty, autonomy, privacy, resilience, continuity, organisational control and the ability to change or exit dependencies.