Understand the enterprise's role in the AI lifecycle and keep an up-to-date registry of linked AI systems; understand potential adverse impacts from internal sources (incident monitoring, oversight bodies) and external sources (human rights institutions, AI observatories, regulators, civil society, workers and unions, incident databases, court cases, grievances, affected communities), using the OECD classification framework; consider risk arising from system interaction, the nature of the use case, the user and its objectives, data, software and human-in-the-loop inputs (including labour risks in annotation and moderation and sourcing of private data or IP), geographic and political context, competency and scientific validity, and intended use and foreseeable misuse; use an escalation questionnaire where not every system can be assessed in depth; review the scoping regularly and on significant change; and draw on consumer protection and sector rules to define high-risk uses (Box 2.1).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.