What to send
- selected service: Security Review, AI Governance, EU AI Act, or NIS2
- company type, employee band, and the responsible owner
- product/system scope and what is in/out
- current pressure: customer review, questionnaire, regulatory, or procurement
- deadline, reviewer window, or internal timing constraint
- evidence transfer method and sensitive-data flag
- external LLM processing permission; default is no
Why email
- it supports direct artifact and file links without reformatting
- it keeps scope, questions, and decisions in an attributable written thread
- it fits the async operating model; there is no form and no routine call scheduling