Connected governance
One record.
Ten perspectives.
Change the facts. Follow the decision.
Supplier, AI, privacy and evidence records in one connected workspace. Session data stays in memory; export JSON before reloading or leaving this page.
Metadata only. Do not enter confidential evidence, raw prompts, credentials or personal data. No uploads are sent to a server. Use your controlled evidence repository for authorized approvals and retained records.
Add a record or import CSV / JSON to calculate risk, evidence coverage and review actions.
Inherent risk distribution
Likelihood 5 → 1 (top to bottom); impact 1 → 5 (left to right). Counts per cell. Select a cell to filter this table; select it again to clear. Signal adjustments appear separately in priority scores.
Evidence state distribution
No matching records in this view. Clear search, change modules, add a record or import records.
Source record / changes propagate across modules
Scoring policy & evidence boundaries
Priority = min(25, max(1, likelihood × impact + signal points − evidence credit)). Unapproved AI adds 3; missing processor DPA adds 3; unresolved processor transfer outside EEA/UK adds 2. Unexpired current evidence with a recorded passing test subtracts 2. High ≥16, moderate ≥9, otherwise low. All thresholds are portfolio policy choices. Scores are ordinal priorities, not probabilities or regulatory determinations.
Evidence coverage = records marked current ÷ all records. Collection error is separate from failed evidence. A “current” flag is an assertion to verify, not proof of control effectiveness. Confirm legal transfer applicability and AI classification with the accountable reviewer.
AI review is triggered by an AI flag plus missing approval, tested disclosure, tested oversight or a nonempty evaluation set with no failures. The release gate additionally requires unexpired current evidence and a recorded passing control test. Supported answer drafts require unexpired current evidence, a passing control test and a named reviewer, and still require approval before external use.
Exact JSON schema ↗ · Public MITRE ATLAS reference subset ↗Scenario assumptions / editable
Value you can interrogate.
Model one review cycle across all imported records. Set time and cost assumptions using your review process. Currency is USD for this planning scenario.
Take the decision with you.
JSON preserves editable state and assumptions. CSV exports source records with spreadsheet-formula protection; use JSON for exact round trips. The memo explains scores, model inputs and human decisions.

ABDULLAH AL OWASI