- Apply risk maps, OWASP, evals, privacy, and supply chain on a real app.
- Create useful evidence to decide whether to publish, limit, or fix.
- Leave a repeatable template for future Aulafy projects.
Minimum report
# AI Audit System: Owner: Date: Users: Data processed: Connected tools: ## Main risks - Risk: Impact: Control: Status: ## Evals - Total cases: - Pass: - Fail: - Critical cases: ## Red teaming - Attacks tested: - Failures found: - Mitigations: ## Privacy - Sensitive data: - Logs: - Retention: - Access: ## Supply chain - Models: - Datasets: - Dependencies: - Licenses: ## Decision Outcome: publish | publish with limits | pilot | block Reason: Next review:
Launch traffic light
- Green: does not touch sensitive data, does not execute actions, basic evals pass.
- Yellow: touches internal data or tools; requires logs, limits, and human approval.
- Red: can affect money, health, employment, rights, customers, or personal data; requires serious review before production.