# AI Risk & Governance Management Platforms: evaluation worksheet

Source: https://dutygraph.com/directory/ai-governance/categories/ai-risk/
Editorial date: 2026-09-07

## Scope

- Organization / team:
- Task and expected output:
- Human owner:
- Product and version:
- Evaluation date / environment:
- Reviewer:

## Questions

### 1. Are assessments attached to a specific use case, owner and version?

- Observation (demonstrated / described / unknown):
- Evidence reference:
- Limitation or follow-up:

### 2. Can a scope change reopen the relevant review without erasing the earlier decision?

- Observation (demonstrated / described / unknown):
- Evidence reference:
- Limitation or follow-up:

### 3. Does the evidence distinguish a declared control from an observed test result?

- Observation (demonstrated / described / unknown):
- Evidence reference:
- Limitation or follow-up:

### 4. Can reviewers export the decision, exceptions, evidence and unresolved follow-up together?

- Observation (demonstrated / described / unknown):
- Evidence reference:
- Limitation or follow-up:

## Evidence checklist

- [ ] A versioned use-case assessment
- [ ] An exception with a named owner and review date
- [ ] A change-triggered reassessment and evidence export

## Boundary to check

A governance platform can organize a program; it does not itself provide a legal conclusion or certify compliance. Applicable obligations and assurance needs depend on the organization and use case and require the appropriate specialists.

## Decision

- Fit for the scoped task:
- Unresolved gaps:
- Next action, owner and date:

This is a planning worksheet, not an endorsement, access approval or compliance certification. Keep confidential evaluation notes in your organization's approved storage.
