For your role

Policy and compliance

Map technical requirements directly onto the EU AI Act, NIST AI RMF, and ISO 42001, in terms a control can be tested against.

Where to start

Three moves, in order

Each ends somewhere you can act rather than somewhere you can read.

  1. Review the regulatory crosswalks

    Line-by-line mappings between international AI legislation and controls a system can be tested against.

    View crosswalk matrix

  2. Set service-level indicators of justice

    Define measurable commitments for appeal passage rates and non-retaliation, rather than intentions.

    Explore SLJ metrics

  3. Export contract clauses

    Generate vendor agreement terms for third-party AI procurement that a counterparty can be held to.

    Generate SLA clauses

Tools and standards

What to run and what to satisfy

The diagnostics that surface risk for this role, and the standards that bear on its work.

What to attend to

The parts of the method that bear on your work

Not everything here is yours. These are the parts that are.

  • Define the governing standard and the rights it protects.
  • Map enforcement pathways and escalation lanes.
  • Prepare public-facing summaries grounded in glossary anchors.

First moves

  1. Select the standard your policy should reference and cite its glossary anchors.
  2. Run a validator to gather baseline risk and burden scores.
  3. Publish policy updates with the same glossary language used in the standards.

Adoption checklist

What to have in place

For a team that has decided to adopt. Each line is a thing that either exists or does not; none of them is a posture.

  • Bind contestability rights to explicit owner roles and response clocks.
  • Define restitution pathways for harms that cannot be fully reversed.
  • Set incident disclosure expectations for high-impact failures.
  • Require sign-off authority for resume decisions after a halt.

Other roles

If that was not you

Seven audiences, one page each. Picking the wrong one costs a click, not a detour.

  • Engineering — You build or operate the system that makes the decision.
  • Audit and assurance — You verify someone else's claims from the evidence their system emits.
  • Operations — You run the appeals, the incident response, or the queues where the system's errors land.
  • Design — You shape the interface where a person meets the decision.
  • Research — You study these systems and publish about them.
  • Executive — You decide whether to deploy, and you carry the liability when it goes wrong.

Or go back to Start, which asks the same question with all seven answers on one screen.