Best use: copy the table into a spreadsheet or workspace before a security questionnaire, trust-centre update, AI governance review or procurement meeting. Keep facts, evidence links and adviser questions separate so teams do not overclaim compliance.
| Evidence field | What to capture | Owner | Proof link or status | Do not claim unless verified |
|---|---|---|---|---|
| AI use case | Feature, workflow, assistant, model-enabled process or vendor capability being reviewed. | Product or operations owner | Inventory row, architecture note, release note or intake ticket. | Complete AI inventory. |
| Data boundary | Whether personal, customer, confidential, support, telemetry or synthetic data is used. | Security/privacy owner | Data-flow diagram, vendor setting, DPIA/question log, policy reference. | GDPR, EU AI Act or DPA compliance. |
| Human review | Where people approve, monitor, override or sample AI output before customer impact. | Support, product or risk owner | SOP, queue screenshot, QA sample, escalation policy. | Zero-risk automation or guaranteed accuracy. |
| Vendor and model dependency | Provider, region, contractual status, retention setting, fallback and subprocessors if known. | Engineering/procurement owner | Vendor page, contract note, risk review ticket, configuration evidence. | Official vendor approval or partnership. |
| Security control mapping | Access control, logging, monitoring, incident handoff, secrets and change-management evidence. | Security/engineering owner | Control ID, policy, runbook, screenshot or ticket. | SOC 2 or ISO 27001 certification outcome. |
| Cloud and AI cost ownership | Team, service, budget owner, usage metric, cost review cadence and unresolved allocation gaps. | Finance/engineering owner | Dashboard, tag policy, billing export, FinOps ticket. | Savings, ROI or unit economics that have not been measured. |
| Adviser question | Legal, DPO, audit, certification, customer-contract or regulator interpretation that AICS should not decide. | Qualified adviser or accountable executive | Open question, meeting note, decision log or external advice reference. | Legal, privacy, regulatory or audit conclusions. |
Simple owner dashboard fields
Status labels
Use “verified”, “needs owner”, “needs evidence”, “needs adviser”, or “out of scope”. Avoid “compliant” unless a qualified owner has approved that exact wording.
Monthly review questions
What changed in AI usage, data, vendors, access, incidents, cost, human review, customer questions and unresolved adviser items?
Need this packaged for a buyer review?
AICS can turn this table into a bounded evidence-room diagnostic with owner gaps, source links, questionnaire handoff notes and claim boundaries.
View the diagnostic packageClaim boundaries
This template does not claim real client outcomes, enterprise procurement approval, GDPR compliance, EU AI Act compliance, DORA/NIS2/SOC 2/ISO 27001 readiness, legal advice, DPO advice, certification, audit attestation, savings, revenue impact, security-questionnaire approval or superiority over any governance, GRC, privacy, security, trust-centre or FinOps platform.
Compare AICS with governance and GRC tools · Read the evidence-room FAQ · More resources