WORKING PROTOTYPE — not yet live, not yet on a domain. For Bridget's review only. Not legal advice.
Aztec AI Assessment
Second line of defence · Independent AI risk review Rate a use case's inherent risk, assess all 21 controls with evidence, and produce a residual risk view with findings and a recommendation.
Step 1
Intake — inherent risk rating
Rate the use case before considering any controls. This sets the baseline the control review is measured against.
Step 2
Control adequacy assessment
For each control: ask the question, obtain the evidence, then rate. Effective requires evidence of operating effectiveness, not verbal assurance. A rating other than N/A requires a written evidence note.
Step 3
Residual risk & findings
Inherent Risk
—
Control Effectiveness
—
Residual Risk
—
Findings register (auto-generated from ratings)
#
Severity
Control
Rating
Evidence note
No findings yet — complete the Controls tab first.