You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
"Management direction and support for AI via policies.",
19
20
guidance:
20
21
"Management should define and endorse a set of policies to provide clear direction and support for AI development and use within the organization, aligned with business objectives and relevant regulations/ethics.",
"Establishment of a governance structure for AI oversight.",
29
31
guidance:
30
32
"An AI governance framework, including roles, responsibilities, processes, and oversight mechanisms, should be established and maintained to direct and control the organization's AI-related activities.",
shortDescription: "Assigning accountability for AI systems.",
56
61
guidance:
57
62
"Accountability should be assigned for the establishment, implementation, maintenance, monitoring, evaluation and improvement of the AIMS and for AI systems throughout their lifecycle.",
shortDescription: "Separating conflicting duties related to AI.",
109
119
guidance:
110
120
"Conflicting duties and areas of responsibility should be segregated to reduce opportunities for unauthorized or unintentional modification or misuse of AI systems or related assets.",
shortDescription: "Identifying resources needed for AI.",
125
136
guidance:
126
137
"Resources necessary for the development, operation, and maintenance of AI systems, including data, knowledge, processes, systems, computing power, and human expertise, should be identified and managed.",
"Establishing and managing a defined AI lifecycle process.",
178
194
guidance:
179
195
"A defined lifecycle process should be established and managed for AI systems, covering stages from conception through retirement, incorporating AI-specific considerations.",
"Processes to ensure data quality characteristics.",
269
294
guidance:
270
295
"Processes should be implemented to ensure that data used for developing and operating AI systems meets defined quality criteria relevant to its intended use (e.g., accuracy, completeness, timeliness, relevance, representativeness).",
"Securely handling data throughout its lifecycle.",
315
345
guidance:
316
346
"Data should be handled securely, including storage, access control, transmission, and disposal, according to its classification and applicable requirements.",
"Application of information security controls to AI systems.",
332
363
guidance:
333
364
"Information security requirements and controls (potentially leveraging standards like ISO/IEC 27001) should be applied throughout the AI system lifecycle to protect confidentiality, integrity, and availability.",
"Managing risks when using third-party AI systems, components, or data.",
377
412
guidance:
378
413
"Risks associated with third-party provision or use of AI systems, components, services, or data should be identified, assessed, and managed through appropriate agreements and monitoring.",
"Including AI-specific requirements in supplier agreements.",
387
423
guidance:
388
424
"Agreements with third parties supplying AI systems, components, services, or data should include relevant AI-specific requirements (e.g., security, privacy, ethics, performance).",
0 commit comments