System boundary
Identify the model, product surface, operators, vendors, interfaces and change points that can affect the assurance question.
Editorial reference: Engagement scoping brief
Maison Sasson / methodology & evidence
/A practical method for regulated organisations that need to understand how an AI system is governed, tested and evidenced across jurisdictions.
This page separates what is verified, what is declared as a capability, and what remains to be documented for a specific engagement.
Evidence register
Label each conclusion by the artefacts and interviews that support it, and record gaps instead of filling them with assumptions.
01 / Perimeter
The examination begins with the system, decision, data flows and jurisdictions actually in scope—not with a generic compliance label.
Identify the model, product surface, operators, vendors, interfaces and change points that can affect the assurance question.
Editorial reference: Engagement scoping brief
Map intended use, affected people, decisions, human oversight and the operational context in which harm could occur.
Editorial reference: Risk and control interview record
Label each conclusion by the artefacts and interviews that support it, and record gaps instead of filling them with assumptions.
Editorial reference: Public evidence policy / this page
02 / Method
Each phase produces an inspectable hand-off. The exact tests and sampling depth are agreed once the system perimeter is known.
Turn the business question into a bounded assurance brief with owners, uses, dependencies and decision criteria.
Editorial reference: Proposed engagement method
Follow data, model, human and vendor pathways to test whether the control story matches the operating reality.
Editorial reference: Proposed engagement method
Review selected documentation, records, controls and samples; record observations with their source and confidence.
Editorial reference: Proposed engagement method
Translate observations into prioritised actions, accountable owners and a plan for evidence that is still missing.
Editorial reference: Proposed engagement method
03 / Evidence
A conclusion is only as strong as its source, recency, ownership and connection to the control being examined.
Evidence has a source, an owner and a date.
A gap is a useful finding when it is named clearly and assigned a next action.
Policies, system descriptions, model cards, risk assessments, contracts, approvals and change records.
Editorial reference: Evidence request list
Logs, tickets, monitoring views, test results, incident records and samples showing how controls operate in practice.
Editorial reference: Evidence register
Interviews and walkthroughs with accountable owners, operators, risk, security, legal and procurement teams.
Editorial reference: Interview record
Every observation points back to an artefact, interview or sample; unresolved material gaps remain visible.
Editorial reference: Public evidence policy / this page
04 / Outputs
The deliverable is designed to help a regulated team decide what to accept, fix, test again or document next.
A concise record of scope, assumptions, owners, systems, uses and evidence thresholds.
Source-linked observations, control status, residual uncertainty and material limitations.
Priorities, owners and next evidence actions, mapped to the organisation’s operating rhythm.
05 / Boundaries
Assurance is bounded work. A report is not a universal certification, legal opinion or substitute for management accountability.
Maison Sasson does not present this methodology as a certification, accreditation or regulator approval.
A reviewed sample, period or deployment cannot by itself prove every control works everywhere or forever.
The crosswalk supports structured questions; it does not replace jurisdiction-specific legal advice or regulatory interpretation.
Where source material, system access or jurisdictional analysis is missing, the appropriate result is a documented gap and a next step.
06 / Crosswalk
This crosswalk organises questions and possible evidence across governance, risk, management systems and resilience. It is a working correspondence, not a compliance result.
The four frameworks are not equivalent or interchangeable. This matrix does not establish compliance, certification, accreditation, regulatory approval or universal coverage; legal and entity-specific analysis remains necessary.
Theme
Perimeter
Clarify the system, intended use, actors, decision rights and affected people before mapping any obligation or control.
Working correspondence
Identify the potentially relevant provider, deployer and system context; applicability and obligations depend on the use, role and facts of the case.
Use Govern and Map questions to record accountability, intended purpose, context, impacts and risk assumptions.
Look for organisational context, leadership, policy and assigned responsibilities in the AI management system evidence.
Test whether the entity, sector and services fall within the directive’s national scope and how management responsibility is evidenced.
Sources and review date
Limits and open questions
Theme
Perimeter
Connect design, testing, human oversight, monitoring, incidents and records to the operating reality of one bounded system.
Working correspondence
Ask which risk controls, technical records, logging, human oversight, monitoring and incident records may apply to the system in scope.
Use Measure and Manage questions to relate testing, monitoring, residual risk, responses and continuous learning to named owners.
Trace operational planning, performance evaluation and continual-improvement evidence without reproducing protected standard text.
Map AI dependencies into cybersecurity risk management, incident handling, continuity and supply-chain evidence where the entity is in scope.
Sources and review date
Limits and open questions
Theme
Perimeter
Separate territorial reach, entity scope, sector duties, supplier dependencies and the jurisdictional assumptions behind each conclusion.
Working correspondence
Check territorial reach, supply-chain roles and the system facts that can change which provisions are relevant across markets.
Use the framework as a flexible risk vocabulary, recording where local law, sector practice or organisational priorities add requirements.
Consider the organisation’s context, boundaries, interested parties and management-system interfaces across locations and suppliers.
Check national transposition, entity designation, sector, supply chain, reporting route and resilience obligations with the relevant authority.
Sources and review date
Limits and open questions
The public matrix links the current source set, consultation dates and open gaps. Rows marked declared or to document are not verified evidence of coverage; no legal advice, certification or regulatory approval is implied.
/jurisdictions07 / Engagement
The public methodology is a starting point; the pre-assessment turns it into a scoped discussion.
A short multilingual intake to identify which governance questions deserve attention first.
A scoped examination of a system, control set or cross-border operating question.
A prioritised path from open questions to owned evidence and repeatable review.
A synthetic, public example of the Ledger structure: useful for orientation, never a real audit or certification.
Next step / scoped audit request
Share the context, jurisdictions and evidence questions that matter. The first conversation is about scope, not a pre-written conclusion.