Firms whose AI use has a material impact must set up and run a register of risks covering at least bias in the system and outputs, erroneous outputs, limits on information about the system and its training data, and retention or use of data the firm inputs; each entry must describe the risk, its likelihood and impact, the mitigation plan, the firm's risk appetite, status updates and a RAG or similar rating, and those responsible for AI decisions must review and update it at least quarterly.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.