Published 2 October 2026 · Online guide
Define the use case and responsibility
Begin with the business task, affected users and decisions the system will support. Record prohibited uses, data restrictions and where human authorization remains necessary. Assign a business owner and an operational owner. A governance document should explain who can accept a risk and who must act when a system fails.
Establish evaluation and change controls
Select evaluation criteria that reflect the actual workflow. Test representative and difficult inputs, not just demonstration examples. For generated content, assess unsupported statements, relevance and information exposure separately. Record the dataset, configuration and limitations so later comparisons are meaningful. Control changes to models, prompts and retrieval sources through a documented release process.
Plan operation and escalation
Define monitoring, incident handling, human override and rollback before deployment. Keep a record of exceptions and revisit the assessment when data, users or intended use changes. Check applicable obligations with appropriate specialists rather than treating a framework as regulatory approval.
Working checklist
Document the intended use; identify data owners; define evaluation criteria; test failure cases; assign risk acceptance; agree release gates; establish monitoring; test rollback; record reassessment triggers. Useful outputs include a use-case register, evaluation plan, decision log and operating runbook. These support a scoped programme; they do not guarantee model accuracy or business returns.
General planning guidance. Adapt the framework to your systems, business requirements and applicable obligations.
Explore related technology insights