AI System Inventory
Step 1: Create a comprehensive inventory of all AI systems in use. For each system document: purpose, provider, risk category, data processed, users, and deployment date. Template provided.
Risk Classification
Step 2: Classify each AI system by EU AI Act risk level: Unacceptable (prohibited), High Risk (Articles 6-7 requirements), Limited Risk (transparency obligations), and Minimal Risk (no specific requirements).
Gap Analysis
Step 3: For high-risk systems, assess compliance with: risk management system (Article 9), data governance (Article 10), technical documentation (Article 11), record-keeping (Article 12), transparency (Article 13), human oversight (Article 14), and accuracy (Article 15).
Remediation Plan
Step 4: Create a prioritized remediation plan for identified gaps. Template includes: gap description, severity, responsible party, remediation action, timeline, cost estimate, and verification method.
.png)