AAOAAO ABDULLAH AL OWASI

Interactive governance engine

Change the record.
Trace the decision.

One supplier-and-AI dataset powers specialist review perspectives. The complete domain register is available in the operating workspace.

Edit AI inventory, SaaS/LLM vendor, privacy and evidence metadata, then follow how the same source facts change risk priorities, drift/change signals, review queues, evidence coverage and decision outputs.

Browser-local demonstration. Metadata only: do not enter confidential evidence, raw prompts, credentials or personal data. No imported records are uploaded to a server; export JSON before leaving if you need to preserve the session.

Open all domain registers → · Read the client operating guide →

specialist review perspectives
1shared record model
5×5risk matrix
3export formats

What this demonstrates

AI, vendor & assurance
signals in one decision trail.

Use the same source record to inspect AI inventory and oversight gaps, SaaS/LLM vendor evidence, processor obligations, post-deployment drift/change review, risk treatment and assurance status. Material acceptance still requires a named human reviewer and rationale.

This is browser-local decision support, not a production GRC platform or automated regulatory determination.

Schema 1.0 · In memory

Read scenario & implementation plan ↗

Add a record or import CSV / JSON to calculate risk, evidence coverage and review actions.

Source record / changes propagate across modules

Acceptance requires a human reviewer and rationale. Record the authorized reviewer and link the approval evidence before accepting risk.

Scoring policy & evidence boundaries

Priority = min(25, max(1, likelihood × impact + signal points − evidence credit)). Unapproved AI adds 3; missing processor DPA adds 3; unresolved processor transfer outside EEA/UK adds 2. Unexpired current evidence with a recorded passing test subtracts 2. High ≥16, moderate ≥9, otherwise low. All thresholds are portfolio policy choices. Scores are ordinal priorities, not probabilities or regulatory determinations.

Evidence coverage = records marked current ÷ all records. Collection error is separate from failed evidence. A “current” flag is an assertion to verify, not proof of control effectiveness. Confirm legal transfer applicability and AI classification with the accountable reviewer.

AI review is triggered by an AI flag plus missing approval, tested disclosure, tested oversight or a nonempty evaluation set with no failures. The release gate additionally requires unexpired current evidence and a recorded passing control test. Supported answer drafts require unexpired current evidence, a passing control test and a named reviewer, and still require approval before external use.

Exact JSON schema ↗ · Public MITRE ATLAS reference subset ↗

Scenario assumptions / editable

Value you can interrogate.

Model one review cycle across all imported records. Set time and cost assumptions using your review process. Currency is USD for this planning scenario.

Modeled hours saved
Modeled net value (USD)
Modeled ROI

Take the decision trail with you.

Export the memo for reviewer context, JSON for exact round trips, or CSV for source-record analysis. The memo carries the scoring basis, model assumptions and human decision fields so the output remains reviewable outside the interface.

Need this pattern scoped to a real GRC / AI backlog? Start a decision brief ↗