Interactive governance engine
Change the record.
Trace the decision.
One supplier-and-AI dataset powers specialist review perspectives. The complete domain register is available in the operating workspace.
Edit AI inventory, SaaS/LLM vendor, privacy and evidence metadata, then follow how the same source facts change risk priorities, drift/change signals, review queues, evidence coverage and decision outputs.
Browser-local demonstration. Metadata only: do not enter confidential evidence, raw prompts, credentials or personal data. No imported records are uploaded to a server; export JSON before leaving if you need to preserve the session.
Open all domain registers → · Read the client operating guide →
What this demonstrates
AI, vendor & assurance
signals in one decision trail.
Use the same source record to inspect AI inventory and oversight gaps, SaaS/LLM vendor evidence, processor obligations, post-deployment drift/change review, risk treatment and assurance status. Material acceptance still requires a named human reviewer and rationale.
This is browser-local decision support, not a production GRC platform or automated regulatory determination.
Add a record or import CSV / JSON to calculate risk, evidence coverage and review actions.
Inherent risk distribution
Likelihood 5 → 1 (top to bottom); impact 1 → 5 (left to right). Counts per cell. Select a cell to filter this table; select it again to clear. Signal adjustments appear separately in priority scores.
Evidence state distribution
No matching records in this view. Clear search, change modules, add a record or import records.
Source record / changes propagate across modules
Scoring policy & evidence boundaries
Priority = min(25, max(1, likelihood × impact + signal points − evidence credit)). Unapproved AI adds 3; missing processor DPA adds 3; unresolved processor transfer outside EEA/UK adds 2. Unexpired current evidence with a recorded passing test subtracts 2. High ≥16, moderate ≥9, otherwise low. All thresholds are portfolio policy choices. Scores are ordinal priorities, not probabilities or regulatory determinations.
Evidence coverage = records marked current ÷ all records. Collection error is separate from failed evidence. A “current” flag is an assertion to verify, not proof of control effectiveness. Confirm legal transfer applicability and AI classification with the accountable reviewer.
AI review is triggered by an AI flag plus missing approval, tested disclosure, tested oversight or a nonempty evaluation set with no failures. The release gate additionally requires unexpired current evidence and a recorded passing control test. Supported answer drafts require unexpired current evidence, a passing control test and a named reviewer, and still require approval before external use.
Exact JSON schema ↗ · Public MITRE ATLAS reference subset ↗Scenario assumptions / editable
Value you can interrogate.
Model one review cycle across all imported records. Set time and cost assumptions using your review process. Currency is USD for this planning scenario.
Take the decision trail with you.
Export the memo for reviewer context, JSON for exact round trips, or CSV for source-record analysis. The memo carries the scoring basis, model assumptions and human decision fields so the output remains reviewable outside the interface.
Need this pattern scoped to a real GRC / AI backlog? Start a decision brief ↗

ABDULLAH AL OWASI