Each step has an accountable reviewer who signs off before you proceed.

1. Purpose and non-AI alternative

Reviewer: Programme or operations lead

Define the task, the non-AI alternative, and what AI adds. If the non-AI path is viable and sufficient, stop here.

2. People and partners

Reviewer: Protection or community-engagement focal point

Identify affected interests, safety risks, languages, local context, and partners who must be consulted.

3. Data

Reviewer: Data protection or IM focal point

Record data types, authority, minimization, and retention. Prohibited input triggers a Red outcome.

4. Tool and vendor

Reviewer: IT or procurement

Document tool, vendor, processing location, access, onward use, and fallback. Unapproved tools trigger Red.

5. Output verification

Reviewer: Subject-matter or MEAL focal point

Plan verification against trusted sources; test bias and exclusion with a human sample.

6. Human control

Reviewer: Line manager

Name who decides, records reasons, can override, and offers a remedy.

7. Monitoring and stop

Reviewer: Pilot or risk owner

Define pilot scope, failure threshold, incident route, review date, and withdrawal rule.

Use the browser scorer or export templates via ai-risk-screen export-templates.