Getting started

Core concepts

Use these terms consistently to understand what each record does and how it connects to the lifecycle.

Context and governed object

  • Company: the durable company or client context.
  • Project: the governance workspace, engagement, or programme. It may contain multiple AI Systems.
  • AI System: the governed business use of AI to which meaningful governance work ultimately traces.
  • Governance Plan: the system-specific explanation of what governance work applies and why.

Obligations and assurance

  • Framework or regulation: the authoritative source of expectations.
  • Requirement or obligation: what must be satisfied; a Task is work assigned to a person.
  • Control: a practical recurring measure used to meet an obligation or reduce risk.
  • Assessment: a structured, broader review. A Control Test checks one control. A Technical Evaluation measures system behavior.
  • Evidence: reviewed proof supporting a claim, control, assessment, or decision—not merely an uploaded file.

Issues, authority, and continuity

  • Finding: an observed deficiency. Risk: an uncertain harmful outcome or exposure.
  • Remediation: the corrective plan for a deficiency; completion still requires verification or re-test.
  • Approval Policy: rules for how approval must occur. Approval Request: a particular request for authority. Decision: the permanent accountable outcome.
  • Monitoring: ongoing checks of whether the prior governance state remains valid. Playbook: a reusable process for executing a known scenario.
Next stepSee how everything connects