The deployer must complete an impact assessment for each high-risk AI system annually and within 90 days after any intentional and substantial modification; the assessment must cover purpose, intended use, benefits, discrimination risks and mitigation, data categories processed, outputs, monitoring and transparency measures; retained for at least three years.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.