Playbook 6 — Documentation Register
The artifact that actually satisfies an auditor, a client, or your own future self
Why Documentation Is the Whole Game
Every other playbook in this series produces a decision — a risk tier, a vendor approval, a bias check result, a go-live sign-off. None of that protects you unless it’s written down somewhere you can find it again. An AI system without documentation has no memory, no defense, and nothing to show a client, a regulator, or your own team six months from now when someone asks “why did we build it this way?”
AI System Inventory — Master Template
One row per AI system or tool in active use. This is the single most useful document in the whole series — start here if you start anywhere.
| System name | Owner | Risk tier (PB1) | Built or bought (PB2) | Data type (PB3) | Gate / status (PB4) | Last reviewed |
|---|---|---|---|---|---|---|
| e.g. Support chatbot | e.g. COO | Limited | Bought | No personal data | Production | e.g. 2026-09-01 |
One-Page AI Project Sheet — Per System
One per system, and only for the ones that need it — generally anything High tier:
- System name
- Owner
- Risk tier
- Purpose / business case
- Data used
- Vendor, if any
- Key risks and their mitigations
- Review cadence
- Current gate / status
- Last reviewed date
- Linked decision-log entries
Use-Case Fit Note — Seven Things to Write Down
Once a use case clears the triage in Playbook 1, write these down once. It’s more granular than the Value, Cost & Risk Canvas in Measure Value, Risk, Costs & KPIs, and it screens for something different: that canvas asks whether the business case holds up, this one asks what governance exposure the use case carries. They’re complementary, not redundant.
- Intended use — and foreseeable misuse.
- Positive and negative impacts identified.
- Predictable failure modes and how they’re mitigated.
- Which groups of people the system applies to.
- How complex the system is — a rule-based filter, or a model that keeps changing.
- Where a human sits in the loop.
- Any effect on employment or the skills your team needs.
Decision Log Template
Not every decision needs a full project sheet — but every consequential one needs a line here.
| Date | Decision | Who decided | Objection recorded? | Outcome |
|---|---|---|---|---|
| e.g. 2026-09-10 | Proceed to pilot | AI Officer | Legal flagged DPA gap — resolved before sign-off | Pilot approved |
Minimum Documentation Set — Checklist
- AI system inventory exists and is reviewed quarterly (Playbook 5).
- Every High-tier system has a completed AI Project Sheet.
- Every vendor-supplied High-tier system has a saved due-diligence record (Playbook 2).
- Decision log is updated whenever a governance disagreement is resolved (Playbook 5).
- Documentation is stored somewhere the whole governance committee can access it — not in one person’s inbox.
Borrow One Term: Statement of Applicability
ISO/IEC 42001 uses a Statement of Applicability: a document that lists every Annex A control and, for each, whether it applies, why or why not, and its implementation status. Playbook 1’s triage is already doing this informally. Naming it “our Statement of Applicability” in this register costs nothing and reads as the vocabulary a COO running vendor diligence recognizes.
Next Steps
If you’re only going to implement one thing from this entire series, implement the AI system inventory. Everything else in the series feeds into it, and it’s the one document that turns “we think we’re being careful” into something you can actually show someone.