Free Checklist

AI Act / DORA Controlled Definitions Checklist

Nine operational steps to turn regulatory terms into a controlled glossary across policies, AI governance files, vendor reviews, Confluence pages, Jira tickets, and audit evidence — anchored to AI Act Article 3 and DORA Article 3.

Sources: AI Act — Regulation (EU) 2024/1689 · DORA — Regulation (EU) 2022/2554

What Is Inside

Operational checklist, not legal advice. Verify legal interpretation and current obligations with counsel before using it as audit evidence.

Get the Full Checklist

Enter your work email and the complete checklist unlocks on this page — no download, no signup.

Please enter a valid email address.

Used only for one optional follow-up about the checklist. No newsletter, no marketing list.

The Checklist

  1. Find the current source of truthWhere do approved definitions live today: Excel, Google Sheets, Confluence, SharePoint, CLM, risk register, AI inventory, vendor-management tool, policy template, or nowhere controlled?
  2. List shadow copiesNote every second copy that teams actually use: spreadsheet exports, contract playbooks, Jira tickets, onboarding docs, vendor questionnaires, board packs, and policy pages.
  3. Anchor each term to a sourceCapture term name, regulation or internal source, article/section, approved wording, source link, and any business explanation as a separate non-legal field.
  4. Do not collapse source-specific meaningsTerms like “provider”, “deployer”, “ICT service”, “critical function”, “incident”, or “subcontracting” may mean different things in different legal contexts.
  5. Assign ownershipRecord legal owner, operational owner, reviewer, approver, approval date, and next review date.
  6. Control changesUse draft → review → approved → deprecated. Keep old versions, require change reasons, and avoid self-approval for high-risk terms.
  7. Search active usageCheck approved terms, synonyms, and deprecated terms across AI governance policies, AI intake forms, model/system docs, DORA ICT contract templates, vendor questionnaires, incident playbooks, risk registers, Confluence, and Jira.
  8. Keep evidenceBe able to export current wording, source references, approval chain, change history, unresolved deprecated-term findings, justified exceptions, and last review date.
  9. Flag workflow riskTreat manual screenshots, anonymous spreadsheet edits, no owner, no review cadence, or inconsistent wording between legal/product/security as a control gap.

Minimum Term Watchlist

AI Act starter terms AI system, provider, deployer, importer, distributor, product manufacturer, authorised representative, high-risk AI system, general-purpose AI model, intended purpose, substantial modification, post-market monitoring.
DORA starter terms ICT service, ICT third-party service provider, critical or important function, ICT risk, ICT-related incident, major ICT-related incident, subcontracting, termination right, audit right, register of information.

Use the official legal source as the anchor. Add internal explanations only as separate commentary.

The 10-Minute Workflow Test

Pick one AI Act term and one DORA term. For each, ask:

  1. Where is the approved definition?
  2. Who approved it?
  3. What source does it cite?
  4. What changed since the previous version?
  5. Where is old wording still used?
  6. What would we export if an auditor, client, or board member asked tomorrow?
Reading the result: If the team cannot answer these in 10 minutes, the problem is not the definition list. It is the control workflow around the list.

Want the Workflow, Not Just the Checklist?

Compliance Glossary for Confluence runs steps 5–9 natively: owned terms, draft → review → approved lifecycle, deprecated-term scanning across pages, and one-click evidence export.

Evaluate in Confluence Read the Documentation

Related Resources

Compliance for Confluence — approved terms, page scanning, and audit evidence for regulated teams in Confluence

AI Act Terminology Governance — how Article 3 definitions become an operational glossary

DORA Terminology Guide — the ICT risk vocabulary behind DORA compliance

Compliance Documentation Checklist — what auditors check across SOC 2, ISO, FDA, and EU regulations

Terminology Management Guide — building a controlled vocabulary for compliance, QA, GRC, and legal teams