Each step has an accountable reviewer who signs off before you proceed.
1. Purpose and non-AI alternative
Reviewer: Programme or operations lead
Define the task, the non-AI alternative, and what AI adds. If the non-AI path is viable and sufficient, stop here.
2. People and partners
Reviewer: Protection or community-engagement focal point
Identify affected interests, safety risks, languages, local context, and partners who must be consulted.
3. Data
Reviewer: Data protection or IM focal point
Record data types, authority, minimization, and retention. Prohibited input triggers a Red outcome.
4. Tool and vendor
Reviewer: IT or procurement
Document tool, vendor, processing location, access, onward use, and fallback. Unapproved tools trigger Red.
5. Output verification
Reviewer: Subject-matter or MEAL focal point
Plan verification against trusted sources; test bias and exclusion with a human sample.
6. Human control
Reviewer: Line manager
Name who decides, records reasons, can override, and offers a remedy.
7. Monitoring and stop
Reviewer: Pilot or risk owner
Define pilot scope, failure threshold, incident route, review date, and withdrawal rule.
Use the browser scorer or export templates via ai-risk-screen export-templates.
