Scope obligations and assign owners
After classification, confirm which derived obligations genuinely apply, mark the rest not applicable, put a named owner on each, and settle the Art. 4 literacy duty.
Once a system is classified, the engine derives its obligation set and the journey moves into the Scope phase (the second of six). Scoping is a short but important pass: you confirm which derived obligations genuinely apply, put a named owner on each, and settle your Art. 4 AI-literacy duty before the heavy implementation work begins.
Where the applicable obligations show up
The obligations the engine generated appear in two places, both live views of the same records:
- On the system — the Obligations tab of the system record lists every one, with phase chips to narrow the view. A locked phase says what has to finish first.
- Across the portfolio — Obligations (under Position) is the one register for every obligation on every system, plus the organisation-scope steps of any programme you run. Filter it by domain, framework, system or scope.
Open any obligation to see its drawer: the article reference, its plain-language reading, the form or checklist, evidence, and the history of every change.
Confirm what applies
- Open the system's Obligations tab and read down the list — this is the full set the engine derived from your classification, flags and GDPR answers.
- Open each obligation. Read the article reference and description to confirm it fits how you actually use the system.
- If an obligation genuinely does not apply, set its status to Not applicable in the drawer. This is a scoping call, not a completion claim — the completion figures simply exclude it, and no approval gate applies. Leave a note so the de-scoping decision is auditable.
- Leave everything that does apply at To do for now — the Implement phase is where it is worked.
Do not mark obligations Complete during scoping to "clear" the phase. The gate wants genuine completion. De-scope only what truly does not apply.
Assign owners
Accountability is per obligation. In the drawer, the Assigned to control in the header picks a team member (choose Unassigned to clear it), and an optional Due date puts the item on the Timeline and in the dashboard's action queue as it approaches. Both save the moment you pick them. You can also set an Owner for the whole system, and start many obligations at once from the register's bulk bar.
Owners receive the reminders the platform sends, so an unassigned obligation is one nobody is watching. The Dashboard treats it as a gate: while any duty is unowned, its Work · this week panel puts assign owners first and shows the items beneath it as locked, with no dates — because a date on a duty nobody owns is fiction.
Art. 4 AI literacy sits in this phase
The Scope phase also carries your Art. 4 duty, in force since 2 February 2025, to ensure the people who deal with your AI systems have a sufficient level of AI literacy. It is an organisation obligation — you satisfy it once for the workspace, not once per system — and the record behind it is built in the Academy. See The Academy: your AI literacy record, and when it lapses.
Gate-locking
A phase is complete when every applicable obligation in it is complete, or when it has no applicable obligations (then it is complete by definition). A later phase is locked while any earlier, non-empty phase is below 100%. The journey bar in the system header shows it — complete phases filled, the current phase highlighted, a locked phase greyed with a note naming what is blocking it. See The six-phase compliance journey.