G.1 Obligation scope worksheet
| Field | Question to resolve | Decision evidence |
|---|---|---|
| Entity and role | Which legal entity acts as developer, deployer, provider, controller, processor, or covered business? | Named legal entity and role rationale. |
| Geography | Which locations, customers, processing, and services trigger territorial scope? | Jurisdiction facts and responsible legal review. |
| Decision and influence | Does the agent make, substantially influence, or prepare a covered decision? | Complete decision-stage map and use description. |
| Data and people | Which personal data, sensitive categories, groups, and rights are implicated? | Data inventory and affected-population scope. |
| Instrument and status | Is the source governing text, enacted law, final regulation, guidance, official announcement, or draft? | Version, exact provision, status, and retrieval date. |
| Obligation and clock | What duty applies, to whom, from when, and under which incident or notice trigger? | Obligation-specific calendar and legal determination. |
| Exception or exemption | Which exact exemption is asserted, and does it cover this processing rather than the institution generally? | Written scope rationale and review trigger. |
| Control and proof | Which operating mechanism discharges the duty, and how is it demonstrated? | Control owner, test, records, notice or remedy evidence. |
| Change trigger | Which change to law, use, data, role, customer, or geography reopens the decision? | Named owner and monitoring/update process. |
The regulatory table in chapter 16 is a researched scope aid for the listed US and EU instruments. It is not an exhaustive jurisdictional inventory. Do not treat a voluntary framework, protocol requirement, or proposed test as a statutory duty.
G.2 Supplier evidence worksheet
| Topic | Ask the supplier | Validate locally |
|---|---|---|
| Version and change | What is pinned, resolved, opaque, deprecated, or silently changed? | Manifest joins, change triggers, and limitation record. |
| Evaluation | Which configuration, task population, attack budget, denominator, oracle, and exclusions support the claim? | Relevant institution-specific holdouts and raw failure outcomes. |
| Authority and adapters | Which tools, tokens, protocol versions, hook routes, subprocesses, and background effects are covered? | Resource authorization, audience/issuer negatives, and bypass inventory. |
| Data handling | Which inputs, artifacts, logs, and memory cross each boundary, with what processing and retention? | Approved source/data flow, egress, deletion and restoration tests. |
| Monitor evidence | Which signals are available, and are they traces, summaries, scores, or effect observations? | Operating-threshold errors, unfamiliar conditions, timing, and effective intervention. |
| Incidents and recovery | Who notifies, contains, preserves evidence, and supports remedy? | Exercise withdrawal, reconciliation, and descendant containment. |
| Exit and rights | Can work, evidence, permitted content, and business obligations be transferred? | Fallback-specific authority and continuity drill. |
G.3 Local responsibility worksheet
Assign a named local role for each mandate, resource boundary, oracle, reviewer pool, monitor, evidence store, legal determination, exception, halt, restart, supplier relationship, and retirement. Record consulted roles and escalation substitutes. The first line operates controls, the second line challenges risk, and internal audit preserves its independence.