Impact scenarios
Describe credible harm or operational failure in the actual workflow context.
Scenario register with severity rationaleEnterprise AI · Governance and evaluation
Governance should help teams make and revisit release decisions. We connect workflow risks to controls, representative evaluations, documented exceptions, and operational evidence instead of treating review as a late compliance form.
01 · Risk frame
We identify affected people, decisions, data, actions, reversibility, material error modes, and oversight duties. This defines proportionate controls and evidence expectations.
Describe credible harm or operational failure in the actual workflow context.
Scenario register with severity rationaleConnect each material scenario to prevention, detection, response, and accountable ownership.
Risk-to-control matrixRecord what remains after controls and who can accept or reject that exposure.
Time-bound exception or release decision02 · Measurement
Case sets cover ordinary work, edge conditions, denied access, missing evidence, and failure behavior. Rubrics separate task quality, evidence support, control behavior, and user impact.
Define case population, rubric, thresholds, reviewers, and disagreement handling before results.
Evaluation protocolCapture configuration, source version, output, intermediate evidence, score, and reviewer notes.
Reproducible result bundleCompare results with thresholds and document exceptions, mitigations, or stop conditions.
Signed readiness record03 · Control evidence
Control assurance covers identity propagation, source permissions, data handling, tool authority, approval enforcement, event completeness, safe fallback, and suspension.
Verify prohibited data and actions remain inaccessible across representative identities and states.
Boundary test recordVerify material events and control failures produce timely, attributable signals.
Telemetry completeness reportExercise investigation, containment, user communication, and restoration paths.
Scenario exercise findings04 · Decision record
The release record links intended use, evaluation results, control evidence, known limits, change scope, approvers, and the next review trigger.

Each readiness claim points to a current result or control artifact.
Accepted limitations include scope, mitigation, owner, and expiry.
Material changes identify which evidence must be rerun or reviewed.
05 · Operating model
Teams receive risk and evaluation templates, decision rights, evidence retention rules, review triggers, exception handling, and a cadence that aligns with product and operational change.
Workflow, security, data, engineering, and service owners know which decisions they hold.
Cases, results, and approvals are versioned and retained according to policy.
Material source, policy, workflow, integration, or component change reopens defined evidence.
The next step is a bounded working session: one workflow, its evidence sources, the decision owner, and the conditions under which the system must stop or hand over.
Design an evaluation plan