What it is for

It turns a general discussion about AI into a concrete list of decisions, owners and evidence. In an organisation where AI is already used without a policy, it establishes what to resolve first and what demonstrates that it has been resolved.

A catalogue of 325 controls

The catalogue was built on ISO/IEC 42001, the EU AI Act and NIST AI RMF, and organises controls by category with risk weighting. Its size does not imply that all of them apply to every organisation: selection is proportional to context, data types and the possible consequences of an error.

325 controls in the catalogue. Each square is one. The highlighted ones illustrate that an organisation applies a selection proportional to its context: the figure shows that proportion, not a count by category.
Control
A verifiable practice, with an owner and associated evidence.
Evidence
The document or record showing the control operates, not merely that it was drafted.
Owner
The person or area accountable for the control, identified in a matrix.
Sector modules
Thematic adaptations of the catalogue to specific contexts.

Four maturity levels

The G0–G3 path describes capabilities, not a grade. Placing an organisation at a level is a starting point for decisions, not a result to publish.

  1. Informal

    AI is used in a fragmented way, without policy or oversight. The main risk is exposing information in uncontrolled tools.

    Typical evidenceNo systematic evidence: the first step is a base policy and an inventory.

  2. Defined

    An approved leadership policy exists and a decision body has been constituted. Use cases are inventoried and classified by risk.

    Typical evidenceConstitution record of the decision body and a register of use cases.

  3. Managed

    Privacy and security controls are integrated into the development and procurement cycle. Impact assessments are carried out systematically.

    Typical evidenceImpact assessments and technical documentation per critical system.

  4. Optimised

    Governance is part of how the organisation works, with recurring external review and continuous improvement.

    Typical evidenceTransparency reports and results of external reviews.

What counts as evidence

A self-assessment is not an audit or a certification. The framework organises the preparation; independent verification, where it applies, is carried out by a qualified third party.

  • A register of AI systems in use, with owner and risk classification.
  • An approved policy, with date, scope and the body that approved it.
  • An impact assessment for a system, with identified risks and their treatment.
  • A record of vendor reviews and of the results delivered.

The platform's role

AGORA has a platform that organises follow-up of the work: control status, associated evidence and pending reviews. It is a tool supporting the consulting work.

  • It does not replace professional work or issue automatic conclusions.
  • It is not offered as a self-service product with public sign-up.
  • Its use within an engagement is defined by scope, not by default.

The framework's master document is internal and is not published. What this page describes is its structure and function, not its full content.

Free exploratory assessment

Twelve questions about AI and data use in your organisation. An AGORA professional reviews them and sends you a written response by email.