01Use case and accountability
- What business outcome is proposed?
- Who will use the system and who may be affected?
- Who owns the decision and ongoing operation?
- Which uses are explicitly out of scope?
02Data and privacy
- What data enters, leaves, or is generated by the service?
- Is sensitive, confidential, regulated, or personal data involved?
- Where is data processed and who can access it?
- What deletion, retention, and reuse controls apply?
03Model and output behavior
- What models or components support the service?
- How are limitations and failure modes communicated?
- Can outputs influence consequential decisions?
- What evaluation is relevant to the intended use?
04Security and resilience
- How is access controlled and logged?
- How are vulnerabilities and incidents handled?
- What dependencies and subprocessors are material?
- What continuity, backup, and exit options exist?
05Legal and commercial terms
- Do usage rights fit the proposed workflow?
- How are customer inputs and generated outputs treated?
- What commitments, exclusions, and change rights matter?
- Can the organization meet its own obligations?
06Oversight and lifecycle
- Where is human review required?
- How can users report harmful or incorrect behavior?
- What conditions must be monitored?
- What changes require reassessment?
How to use this checklist
For each relevant question, record an owner, response, evidence reference, reviewer finding, open gap, and next action. A completed checkbox is not evidence and does not by itself support approval.