Firms using or planning to use AI in service delivery must develop and implement responsible-use policies informed by the risk register, covering internally developed and third-party systems, which at minimum set out the roles, responsibilities and liabilities of everyone procuring or using AI, at least annual training expectations, how human control and judgement interact with AI (for example monitoring or dip-sampling outputs), and guidance on identifying and mitigating AI risks.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.