Public Sector Governance
Public-Authority High-Risk AI Registration Check
What this control does
Confirm required registration before public-authority use and block unregistered systems.
How to implement
For public-sector deployers within the applicable registration requirements, identify the system, legal route and responsible registration owner. Verify the required system and deployer registration before authorizing use. If a required entry is missing, prevent use and inform the relevant provider or distributor. Retain registration evidence and revisit it when the system or use changes. Apply the specific database and confidentiality rules rather than assuming every registration is publicly visible.
Suggested timing and triggers
Before applicable public-sector use; on registration, system or use changes.
Evidence examples
Registration applicability decision System and deployer registration confirmations Pre-use verification and authorization records Missing-entry notifications and holds Updates following system or use changes
How to check this control
Sample a qualifying deployment and verify the relevant registration record and pre-use check. Confirm that a missing required entry would block use rather than only create a reminder.