Step 1 of 4 — Scope
Step 1 — Scope & Context
Start with where you operate and which sector you serve. This narrows which regulations may apply before we ask about your specific system.
If you are certain the EU AI Act doesn't apply to your organisation or this system, tick above to skip EU AI Act questions. You will still answer whether EU residents' data is processed for GDPR screening.
Step 2 — System Description
Describe the AI system itself: what it is, what it does, and how it operates.
Step 3 — Impact & Risk
Describe how the system affects people, what data it uses, and your initial risk assessment.
Step 4 — Results
Your inputs
Go back to any previous step to change answers, then re-run discovery.
Applicable regulations
Top controls by SRF layer
Priority controls derived from the regulations above, grouped by the CoSAI AI SRF layer that holds primary accountability.