Control
Status
Description
AI system impact assessment
Operational
The organization shall perform AI system impact assessments according to 6.1.4 at planned intervals or when significant changes are proposed to occur. The organization shall retain documented information of the results of all AI system impact assessments.
Determining the scope of the AI management system
Operational
The organization shall determine the boundaries and applicability of the AI management system to establish its scope. When determining this scope, the organization shall consider: the external and internal issues referred to in 4.1; the requirements referred to in 4.2. The scope shall be available as documented information. The scope of the AI management system shall determine the organization’s activities with respect to this document’s requirements on the AI management system, leadership, planning, support, operation, performance, evaluation, improvement, controls and objectives.
AI objectives and planning
Operational
The organization shall establish AI objectives at relevant functions and levels. The AI objectives shall be consistent with the AI policy, be measurable, take into account applicable requirements, be monitored, be communicated, be updated as appropriate, and be available as documented information. Planning includes defining work, resources, responsibilities, deadlines, and evaluation methods.
Monitoring, measurement, analysis
Operational
The organization shall determine what needs to be monitored and measured, the methods, timing, and evaluation of results. Documented information shall evidence performance and effectiveness of the AI management system.
General (internal audit)
Operational
The organization shall conduct internal audits at planned intervals to provide information on whether the AI management system conforms to requirements and is effectively implemented and maintained.
Continual improvement
Operational
The organization shall continually improve the suitability, adequacy and effectiveness of the AI management system.
Nonconformity and corrective action
Operational
When a nonconformity occurs, the organization reacts, evaluates causes, implements action, reviews effectiveness, and keeps evidence of nonconformities and corrective actions.
AI policy (documented)
Operational
The organization should document a policy for the development or use of AI systems.
External reporting
Operational
The organization should provide capabilities for interested parties to report adverse impacts of the system.
Communication of incidents
Operational
The organization should determine and document a plan for communicating incidents to users of the system.
Information for interested parties
Operational
The organization should determine and document its obligations to reporting information about the AI system to interested parties.
Processes for responsible use of AI
Operational
The organization should define and document the processes for the responsible use of AI systems.
Objectives for responsible use of AI
Operational
The organization should identify and document objectives to guide the responsible use of AI systems.
Intended use of the AI system
Operational
The organization should ensure that the AI system is used according to the intended uses of the AI system and its accompanying documentation.
Understanding the organization and its context
Operational
The organization shall determine external and internal issues that are relevant to its purpose and that affect its ability to achieve the intended result(s) of its AI management system. The organization shall determine whether climate change is a relevant issue and consider the intended purpose of AI systems.
Understanding the needs and expectations of interested parties
Operational
The organization shall determine the interested parties that are relevant to the AI management system, their requirements, and which requirements will be addressed.
AI management system
Operational
The organization shall establish, implement, maintain, continually improve and document an AI management system, including the processes needed and their interactions.
Leadership and commitment
Operational
Top management shall demonstrate leadership and commitment with respect to the AI management system, ensuring resources, integration, communications, and continual improvement.
AI policy (top management)
Operational
Top management shall establish an AI policy that is appropriate, provides a framework for objectives, meets requirements, and is communicated and made available.
Roles, responsibilities and authorities
Operational
Top management assigns responsibility and authority for ensuring conformity and reporting on AI management system performance.
Awareness
Operational
Persons doing work under the organization’s control are aware of the AI policy, their contributions, and implications of not conforming.
Communication
Operational
The organization determines internal and external communications relevant to the AI management system.
Documented information (general)
Operational
The organization’s AI management system includes documented information required by the standard and what the organization deems necessary.
Creating and updating documented information
Operational
When creating and updating documentation, the organization ensures appropriate identification, format, media, and review/approval.
AI risk treatment (plan execution)
Operational
The organization implements the AI risk treatment plan, verifies effectiveness, and updates the plan when needed.
Internal audit programme
Operational
The organization plans, establishes, implements, and maintains audit programmes covering objectives, scope, methods, and reporting.
General management review
Operational
Top management reviews the AI management system to ensure suitability, adequacy, and effectiveness.
Management review inputs
Operational
Management review covers prior actions, changes in context, needs of interested parties, performance data, and improvement opportunities.
Management review results
Operational
Results include decisions on continual improvement and needed changes, retained as documented information.
Reporting of concerns
Operational
The organization defines and implements a process to report concerns about its role with respect to an AI system throughout its life cycle.
Control of documented information
Operational
Documented information required by the AI management system is controlled to ensure availability, suitability, and protection.
Planning for the AI management system
Operational
The organization considers issues, requirements, risks, and opportunities to assure the AI management system achieves intended results and supports continual improvement.
AI risk assessment (process definition)
Operational
The organization defines and establishes an AI risk assessment process aligned with policy and objectives.
AI risk treatment (process definition)
Operational
Taking risk assessment results into account, the organization defines a treatment process including selecting options and verifying controls.
AI risk assessment (execution)
Operational
AI risk assessments are performed at planned intervals or upon significant change, with documented results.
AI system deployment
Operational
The organization documents deployment plans and ensures requirements are met before deployment.
AI system recording of event logs
Operational
The organization determines life-cycle phases requiring event logs, ensuring logging at minimum when AI systems are in use.
Quality of data for AI systems
Operational
Data quality requirements are defined and enforced for datasets used to develop and operate AI systems.
System documentation and information
Operational
Necessary system information is provided to users.