Review Triggers and Log
Two kinds of review. You need both.
The calendar catches drift. The trigger list catches everything that does not wait for the calendar.
Part 1 — Setting the Interval
Deployment: ________________________________
Review interval:
- Annual — standard
- Every six months — higher risk
- Quarterly — consequential decisions, sensitive data, limited human review
Reason for the interval chosen:
Record the reasoning. A deliberate, documented interval is a program decision. An undocumented one is indistinguishable from having missed something.
Next scheduled review: ________________
Part 2 — What to Check Each Time
| Check | Changed? | Notes |
|---|---|---|
| Has the use case changed | ||
| Has another team adopted the tool | ||
| Has the vendor changed anything material | ||
| Have new data sources been connected | ||
| Has the population expanded to a new location | ||
| Has the law changed anywhere in scope | ||
| Are the documented controls still in place | ||
| Is the named owner still in the role |
On the last row. Ownership decays quietly when people change jobs. It catches more problems than people expect.
Part 3 — Event Triggers
These prompt a review regardless of the calendar.
| Trigger | Why it matters | Occurred? |
|---|---|---|
| New location in scope | Different law may apply | |
| New use case for an existing tool | New deployment, new analysis | |
| Vendor contract renewal | Terms may have changed | |
| New data category added | May cross a threshold | |
| Vendor announces a material change | Model, hosting, sub-processor | |
| Regulatory change where you operate | Direct impact | |
| Effective date arriving | Known in advance — calendar it | |
| Incident or complaint involving the tool | Obvious | |
| Team expansion or reorganization | Ownership and access change | |
| Integration added or removed | Changes what the tool can reach |
A tool reviewed in January and expanded in February should not wait until the following January.
Part 4 — Attaching to Cycles You Already Run
Do not build a separate process. Add these questions to reviews that already happen.
| Existing cycle | What to add | Owner | Added? |
|---|---|---|---|
| Vendor risk review | The AI intake questions | ||
| Contract renewal | Check processing terms | ||
| Access review | Confirm oversight ownership | ||
| New vendor onboarding | Capture the intake at the start | ||
| Annual policy refresh | Check notice still covers this use |
The last row of value is the fourth one. A deployment captured properly at onboarding never needs reconstructing later.
Part 5 — Watching for Regulatory Change
You are watching the locations your deployments reach.
| Source | Set up? | Owner |
|---|---|---|
| Regulator updates for main locations | ||
| Law firm alerts covering your sectors | ||
| Known effective dates on the calendar | ||
| Counsel's watch list — ask them |
Known dates are the easiest win. December 2027 is already on the calendar. Put it there.
Locations currently in scope:
Part 6 — The Review Log
Record every review, including the ones that found nothing.
They are evidence you looked. A gap in the log reads as inattention, whether or not that is what happened.
| Date | Reviewed by | Trigger | Findings | Action taken |
|---|---|---|---|---|
Trigger column: scheduled, or name the event.
Findings column: "no change" is a valid and useful entry.
Part 7 — Version Control
When you update an assessment, keep the prior version.
The question is rarely what the document says now. It is what you knew, and when.
| Version | Date | What changed | Prior version retained? |
|---|---|---|---|
Part 8 — Prioritizing
You will not review everything at the same depth. No program does.
Higher attention where the deployment:
- Affects people in consequential domains — employment, lending, healthcare, insurance, housing
- Involves sensitive data categories
- Operates with limited human review
- Reaches multiple locations
- Serves vulnerable populations
Lower attention where the deployment:
- Produces internal outputs only
- Touches no personal data
- Has consistent human review before anything reaches a person
Prioritization reasoning:
Write the reasoning down. A deliberate, documented prioritization is defensible. An undocumented one is not distinguishable from an oversight.
One Constraint
Describing a monitoring practice you are not actually running is the one option that is not available.
If the volume outgrows what you can review, the answers are ordinary — narrow the scope deliberately and record why, move the intake earlier, use cycles already running, or bring in help.
The record has to match what you do.
Use and reuse
Free to use, share, and adapt within your organization. Attribution appreciated, not required. No warranty of any kind — this is practitioner guidance, not legal advice, and sufficiency is determined by your counsel.
LegisGate · Regulatory Intelligence for AI Deployments · legisgate.com
Written by compliance and audit practitioners who spent decades on the other side of the table.
Version 1.0 · Current as of August 2026 · Verify time-sensitive claims against current sources before relying on them.