1. Inventory AI use cases and name accountable owners.

2. Document risk class, data flows and affected stakeholders.

3. Define acceptable use, human oversight and incident response.

4. Define audit trail, tests, approvals and monitoring before go-live.

5. Map to the EU AI Act, ISO 42001 and the existing ISMS.