What to include in your assessment scope
Write a defensible scope statement: which AI systems, teams, jurisdictions and data flows are in — and what is deliberately out.
What a good scope statement contains
- Systems list — every AI system in scope with a stable system ID, business owner, purpose, lifecycle stage (pilot / prod / retired) and EU AI Act risk classification (prohibited / high-risk / limited / minimal).
- Embedded AI — M365 Copilot, Gemini for Workspace, Glean, GitHub Copilot, Notion AI, Salesforce Einstein, Zoom AI Companion. List the tenant/workspace IDs.
- Third-party APIs — OpenAI, Anthropic, Google AI, Azure OpenAI, AWS Bedrock with region, model family and data-processing addendum reference.
- Jurisdictions — where data subjects live (drives GDPR, UK GDPR, EU AI Act) and where models are hosted (drives data residency).
- Out of scope, with reason — e.g. "spam filter — minimal risk, not customer-facing".
Do this Monday
- Pull a list of approved SaaS from Okta / Entra ID and flag every product whose vendor announced an AI feature in the last 12 months.
- Cross-check against a shadow-AI scan (Netskope, Zscaler, Microsoft Defender for Cloud Apps).
- Publish v1.0 of the scope statement, dated and signed.
Reviewer hot-buttons
- Is shadow AI accounted for, or only the things IT approved?
- Are embedded AI features (Copilot, Einstein) listed separately from the host SaaS?
- Does the scope name a review cadence (quarterly is the norm)?