re-ai-gov Join the waiting list

Responsible AI Governance

What you do with the outcome of the scan, and which route fits

The scan delivers a dossier: a register of AI applications, a classification of role and risk level, a gap and obligations report, and a set of governance templates with board reporting. What happens after that is not up to the tool. That is up to you, and there are three ways to do it.

The order below is deliberate. Doing it yourself comes first, not because it is always the best choice, but because it is the starting position. Everything you hand over to a partner, you hand over to a partner after the dossier is in place, not instead of the dossier.

Route 1: do it yourself

What you get: the complete dossier from the scan, plus the templates to fill in yourself. The register, the classification and the timeline with what needs to happen now and what can wait are there. The governance templates connect to the existing risk structure, so that no second process arises alongside the first. For the underlying AI Act knowledge, register and literacy, there is aiacta.eu, where that framework already stands.

When this fits: if there is already a risk or compliance function that can translate classifications, obligations and timelines into policy and the assignment of responsibility. If the organisation is small or manageable enough to carry the number of applications and the associated agreements itself.

What you need to be able to do yourself: fill in templates without someone interpreting them for you. Actually assign accountability to a name, not to a team. Set up and monitor human oversight, even when there is no direct pressure from a supervisory authority behind it. Whoever does not have that in house risks the dossier staying on the shelf while the scan had just set it in motion.

Where this does not fit: if there is no capacity whatsoever to translate the gap report into internal agreements, or if the number of applications and the departments involved is too large to keep an overview of by yourself.

Route 2: partly guided

What you get: the same dossier, supplemented by a partner who develops the oversight design with you and embeds it in the existing risk structure. The partner works after the report, outside the tool. The scan remains the dossier on which that guidance is based; no separate, parallel process is created alongside it.

When this fits: if the classification and the obligations are clear, but the design of who is responsible for what, and how monitoring runs, requires more thinking than is internally available. Also fitting if a risk structure does exist, but it is unclear how AI-specific oversight fits into it without duplication of work.

What you need to be able to do yourself: supply and explain the results of the gap report to the partner, and decide on the content of the policy yourself. The partner helps design, but the organisation remains the owner of the choices about role, risk and responsibility.

Where this does not fit: if there is a need for someone to take over the entire process from start to finish, including execution and monitoring. That is route 3, not this one.

Route 3: fully outsourced

What you get: the complete governance process with a partner, with the scan as the fixed dossier. The partner carries out what the gap report indicates, sets up oversight, and follows the horizon scanner for changes. The tool remains the starting point and the record; the execution lies elsewhere.

When this fits: if there is no internal capacity to translate classification, oversight and monitoring into ongoing policy, or if the scale and speed of AI use in the organisation moves faster than can be kept up with internally.

What you need to be able to do yourself: sharpen the scope and the assignment to the partner based on the dossier, and keep following the progress. Outsourcing execution is not outsourcing ownership: the organisation remains responsible for what happens with AI applications, even when a partner runs the process.

Where this does not fit: if the idea is that a partner also takes over the decision on risk acceptance. That decision lies with the organisation itself, however the process is organised.

What the three routes have in common

In none of the three routes is a party from this scan itself involved in the execution. The tool delivers the dossier; what happens after that is a choice made after the report, not built into it. How that intake, classification and template structure exactly come about is described on how it works, and whoever is looking for more background on role, risk and obligations will find it in the knowledge base.

Whichever route fits, none of the three says anything about how much time it takes or which roles it affects. That only becomes concrete once governance is translated into tasks, hours and systems, and for that the work scan from FTE TO AI (ftetoai.com) is the next step. That is a different instrument for a different question, after this one.

Andrewde assistent van de Responsible AI Scan

Vraag maar. Governance begint bij weten wat er draait — ook wat niemand heeft goedgekeurd.

Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.