What the ICO Code asks. Every AI processing activity must have an identified UK GDPR Article 6 lawful basis. Where special-category data is involved (health, biometric, ethnic origin), an additional Article 9 condition is required. A DPO (or equivalent accountable person) oversees AI systems. The Article 30 ROPA includes AI systems and automated decisions — purpose, lawful basis, data categories, retention, recipients, ADM logic + significance.
What counts as compliant. A lawful-basis register with one entry per AI system; an Article 9 condition register where special-category data flows; named DPO oversight with sign-off cadence; ROPA updated to capture AI processing including the ADM logic disclosure.
What Secruna ships for Theme 1. Four rules covering lawful-basis identification, the Article 9 condition register, DPO oversight and ROPA updates. The AI inventory feeds the ROPA refresh; verdict rows cite the AI-system entry that drove them.
See this in your dashboard at: /inventory?framework=ico_ai_adm_code&theme=LB with the lawful-basis register state per tenant.