Based on the use case:

  • Self-Assessment: For most internal high-risk systems

  • Third-Party Assessment: Needed for sensitive cases (e.g., biometric ID, public security)

🔍 Confirm whether your case requires external review.