Legal & Regulatory Mapping Checklist for AI Use Cases

An actionable, saver-friendly interactive playbook to map AI use cases to likely legal, regulatory, and contractual obligations, capture required artifacts, assign reviewer notes, and record mitigation actions and status.

Interactive Tool

Legal & Regulatory Mapping Checklist for AI Use Cases

Use this interactive checklist to record each AI use case, identify likely legal and regulatory checkpoints across jurisdictions, capture required evidence for audits, and assign reviewer notes and mitigation actions. The form guides you through high-risk categories, typical required artifacts, and an operational checklist to reduce the chance that undiscovered obligations will halt deployment.

How to use this form

  1. Create an entry for each discrete use case or deployment context (where data, users, risk profile, or jurisdiction differ).
  2. Select high-risk categories that apply. If you select Personal Data, Healthcare, Credit/Insurance, Public Sector, or similar, plan for a formal legal review and any mandatory impact assessments.
  3. Attach or link required artifacts (data inventories, DPIAs, vendor contracts, model cards, logs). Record mitigation actions and responsible owners.
  4. Use the Risk Rating and Status to prioritize review and gating decisions.

If you are unsure about legal obligations, capture what you know and mark the entry In Review so a legal or compliance reviewer can follow up.

A short, unique name for this use case or deployment (e.g., 'Loan-Eligibility Recommendation v1 — US Pilot').
Describe the goal, main actors, data sources, and primary outputs or decisions the model supports. Keep it brief (2–4 sentences).
List countries, states, provinces, or international regions (e.g., 'United States (CA, NY), EU, UK').
Select any categories that describe this use case. Selection helps prioritize legal checks and required artifacts.
If 'Yes', record data inventory and consent/legal basis evidence below and plan for privacy review.
Select artifacts you have or need to collect. Linking or attaching documents in your records system is recommended.
List specific statutes, regulations, standards, or guidance that may apply (e.g., 'GDPR Art. 35 — DPIA; EU AI Act — high-risk systems', 'CFPB guidance on credit scoring'). If unknown, note 'Legal review required'.
Record any contractual clauses, SLAs, data residency or deletion requirements, or customer-specific constraints.
Describe privacy, fairness, security, or governance mitigations (e.g., minimize data fields, differential privacy, additional testing, human-in-loop gating). Assign owners in action items below.
Use this to gate deployment. High and Critical should require formal legal & compliance approval.
A quick status of artifact collection to triage follow-ups.
List concrete next steps, owners, and due dates (e.g., 'Legal to complete DPIA — Alice — 2026-09-01; Engineering to remove free-text PII field — Bob — 2026-08-15').
Name of the legal/compliance/technical reviewer completing this record.
Date of this review (YYYY-MM-DD).
Operational status used to gate deployment and trigger follow-ups.
Optional next review or action due date (YYYY-MM-DD).
Helps determine access controls for stored artifacts and reviewer notes.
You can explore this tool now. Sign in or create an account to save your responses and return to them later.
Make this tool part of your work

Save a personal copy, bring it to your team, or tailor the questions and workflow to fit what you are hungry to improve.

Member customization and team collaboration are coming soon.

Discussion

Comments and conversation will live here.