MP-3.3 Targeted application scope is specified and documented based on the system's capability, established context, and AI system categorization
Targeted application scope is specified and documented based on the system’s capability, established context, and AI system categorization. Scope is bounded in writing and justified by capability and context, which is wh
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Records of any scope extension and the re-assessment that accompanied it · Policy repository / GRC workspace
governing documentDocuments that govern the control
- The documented targeted application scope and its boundaries · Policy repository / GRC workspace
- The capability and context basis for the scope chosen · Policy repository / GRC workspace
- Controls that keep use inside the stated scope · Policy repository / GRC workspace
First move
Common gaps auditors find
- Scope broad enough that no use is outside it
- Boundary documented with nothing enforcing it
- Scope extended in practice without re-assessment
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetMP-3.2 Potential costs, including non-monetary costs, which result from expected or realized AI errors or system functionality and trustworthiness are examined and documented, as connected to organizational risk tolerance · MP-3.4 Processes for operator and practitioner proficiency with AI system performance and trustworthiness, and relevant technical standards and certifications, are defined, assessed and documented