Visual Maps 5–7
Map 5 — Principle → Risk → Practice → Control
Principle
what should be protected?
↓
Risk
what harm could occur?
↓
Practice
what should people do?
↓
Control
how will we enforce/test it?
Source-style example
Protect health-information privacy
↓
Unauthorized disclosure risk
↓
Only care-related users with a need may access
↓
Periodic access review removes inappropriate users
Recognition cue: a value statement is not a control. The control is an enforceable/testable mechanism.
Map 6 — Ethical-risk checkpoints for personal-data analytics
Population
Who is included / excluded?
↓
Capture
What is collected, and why?
↓
Analysis
How are people interpreted, combined, modeled or scored?
↓
Results / Use
Who receives or acts on the result, and what consequences follow?
Key lesson: do not wait until the final result. Ethical risk can enter at selection, capture, analysis and use.
For a consequential project, add Governance/legal review, documented decisions and harm mitigation across the flow.
Map 7 — Ethical culture & Governance operating loop
Current-state review
↓
Define principles + risks
↓
Set practices + controls
↓
Strategy / roadmap + training / communications
↓
Monitor / escalate / remediate
↺ improve again
Governance: standards, policies, decision practices and oversight.
Legal counsel: law and legal-risk interpretation.
Practitioners: recognize and raise day-to-day ethical risk.
Rebuild: recreate the five-step loop; put Governance on the left, Legal on the right, and write the practitioner duty underneath.
Final blank-page challenge
Recreate Chapter 2 from only these anchors:
- 3 ethical concerns.
- 4 ethical principles.
- 8 recurring privacy-management themes.
- 6 unethical-practice risk patterns.
- Principle → Risk → Practice → Control.
- 4 ethical-risk checkpoints.
- Ethical culture loop + Governance/legal oversight.
If you can redraw these roughly and explain each relationship in ordinary language, the atlas has done its job.
Source anchors: Chapter 2 pp. 63–67.