AI Use Case Submission Guide
A step-by-step walkthrough for business owners and technical leads submitting a new AI use case through their organization's RAIC public intake portal (/intake/your-org-slug). Mirrors the five sections of the on-screen form.
Before you start
RAIC's public intake portal lets anyone in your organization propose a new AI use case for governance review without needing a RAIC login. Submissions enter the staged approval workflow and receive a permanent ID (RC-{DEPT}-{###}).
- Your organization's intake URL — ask your OrgAdmin if you don't have it.
- A work email on one of your organization's allowed domains.
- Names and work emails for the Business Owner and Technical Lead.
- A short, plain-English description of what the AI will do and why.
Most submissions take 8–12 minutes. You cannot save and resume a public submission, so gather the information above before you start.
Section A. Your Information
Why this section exists
Identify yourself as the submitter so the governance team can follow up with questions. This is captured even when the form is filled by someone other than the use case owner.
What you'll be asked
- Your full name
- Your work email (must be on one of your organization's allowed email domains)
- Your role / title
Tips
- Use your corporate email — submissions from personal email domains are rejected by the portal.
- If you are submitting on behalf of someone else (e.g. an executive), capture the true business owner in Section C.
Section B. Use Case Identification
Why this section exists
Give the use case a clear name, description, and business context. This is what reviewers see first, and what the use case will be referred to by throughout its lifecycle (RC-{DEPT}-{###} ID).
What you'll be asked
- Use case name (short, human-readable)
- Plain-English description of what the AI will do and why
- Business unit / department
- Topic area (Finance, HR, Operations, Customer Service, Legal, IT, Healthcare, Public Services, Other)
- Whether the use case is public-facing
Tips
- Write the description for a reviewer who has never met you. Cover what the AI does, who uses it, and what decisions it informs.
- Avoid internal codenames as the use case name — use a name that will still make sense in twelve months.
- If the use case is public-facing (customers, citizens), say so explicitly — it materially changes the review path.
Section C. Ownership & Contacts
Why this section exists
Name the people who will be accountable for the use case once it is approved. The Business Owner is the operational owner; the Technical Lead is the implementation owner. Both receive notifications across the workflow.
What you'll be asked
- Business Owner name and email
- Technical Lead name and email
- Optional: additional process owners (data steward, model owner, etc.)
Tips
- Both Business Owner and Technical Lead must be real people with the named email — generic shared mailboxes fail downstream notifications.
- If the Business Owner has not yet been confirmed, name the most senior person you have agreement from. They can be reassigned later by an OrgAdmin.
Section D. AI Technology Details
Why this section exists
Tell reviewers what kind of AI is being used and how it is built. This drives ISO 42001 / EU AI Act / NIST AI RMF scoping and determines which controls and policies apply.
What you'll be asked
- AI technology type (Machine Learning, Deep Learning, Generative AI / LLM, NLP, Computer Vision, RPA-Hybrid, Reinforcement Learning, Rule-Based, Other)
- Foundation models or vendor models used (e.g. GPT-5, Gemini 2.5 Pro, Claude, an internal model)
- Whether the use case is COTS (commercial off-the-shelf) or built in-house
- Vendor name (if COTS or hybrid)
- Intended outputs (predictions, classifications, generated content, recommendations, decisions, etc.)
- Intended audience (internal staff, business unit, customers, regulators, the public)
Tips
- If you are using a major vendor (Microsoft Copilot, Google Workspace AI, OpenAI ChatGPT Enterprise, etc.), name them — your governance team probably already has approved policies for that vendor.
- If multiple AI components are involved (e.g. an LLM plus a classifier), submit them as one use case here; the underlying AI Systems are tracked separately.
Section E. Risk & Compliance
Why this section exists
Capture the inherent risk profile of the use case. This drives the assigned risk tier, the approval pathway, and which framework checklists (EU AI Act, ISO 42001, NIST, sector frameworks) apply.
What you'll be asked
- Whether the use case involves Personally Identifiable Information (PII)
- Whether it could affect people's rights (employment, credit, housing, healthcare, criminal justice, public services)
- Whether it could affect people's safety
- Demographic variables involved (race, gender, age, disability, etc., or none)
- Regulatory frameworks the use case must comply with (GDPR, CCPA, HIPAA, EU AI Act, NIST AI RMF, ISO 42001, FINRA, SOX, etc.)
- Brief description of key risks you can foresee
- Whether a human is in the loop (full human control / human-in-the-loop / human-on-the-loop / fully autonomous)
Tips
- If you are unsure whether the use case is rights- or safety-impacting, mark "Under Review" rather than "No". An OrgAdmin can adjust later.
- Listing a regulatory framework here does NOT mean you have to be compliant on day one — it means reviewers will route the use case through the right specialist.
- Be candid about foreseeable risks. Submissions that downplay risk are routinely sent back for re-scoping.
What happens after you submit
- You receive an on-screen confirmation with your use case's permanent ID.
- Business Owner, Technical Lead, and the org's intake notification address receive a branded email.
- The governance team triages and assigns a risk tier (Critical / High / Medium / Low).
- The use case enters the staged approval workflow; reviewers may follow up for clarification.
- Once approved, the use case is added to the Use Case Register and linked to systems, controls, risks, and policies.
Amending or withdrawing a submission
Public submissions cannot be edited from the public portal once submitted. To correct or add information, reply to the confirmation email or contact your governance team — an OrgAdmin or WorkflowAdmin can edit the submission inside RAIC. To withdraw a submission, ask your governance team to retire it; the audit trail is preserved.
Need help?
Your organization's RAIC intake notification address (set by your OrgAdmin) is the fastest route. The public Support Site at app.rhindoncyber.com/support has deeper module docs, and Rhindon Cyber support is reachable at [email protected].
