What’s inside the PDF:
- The processing, specifically: tool, tier, data fields, whose data, purpose, lawful basis
- The four AI-specific risks: training, accuracy, automated decisions, transfers and retention
- Measures and sign-off, with a named risk owner and a review trigger
The most common failure this starter prevents is the generic DPIA: “we use AI tools on client data, risks are mitigated by policies”. The ICO’s recurring criticism is exactly that vagueness, and it evaporates the moment the form demands the tool’s name, the actual fields, and what happens when output is wrong about a person. Specific is not harder; it is just less comfortable, once.
This is deliberately a starter, not legal advice: it gets the AI-specific thinking onto paper so the conversation with your DPO or adviser is short and concrete. The regulatory context per jurisdiction lives in the governance cluster; the per-provider data terms live in the providers cluster.
This page and the template are for informational purposes only and do not constitute regulated financial advice, legal advice, or a compliance opinion. Adapt with a qualified professional where regulation applies.