Policy Register

AI and automated decisions

The documents an organisation that uses or builds AI systems now needs: the AI policy, the acceptable-use rules, the impact assessment, the logging of automated decisions.

Policy types in this family

5

What reaches this family

ISO 27001Expects: no document of this family on its gap list. Requires, by clause: ISO 27001 5.10.
ISO 27701Expects: no document of this family on its gap list. Requires, by clause: ISO 27701 A.1.3.11.
ISO 42001Expects: ai governance policy, ai system impact assessment procedure, ai use policy (acceptable ai use). Requires, by clause: ISO 42001 A.2.2, ISO 42001 A.2.3, ISO 42001 A.2.4, ISO 42001 A.3.2, ISO 42001 A.3.3, ISO 42001 A.6.1.3, ISO 42001 A.6.2.4, ISO 42001 A.6.2.6, ISO 42001 A.6.2.8, ISO 42001 A.5.2, ISO 42001 A.5.3, ISO 42001 A.5.4, ISO 42001 A.9.2, ISO 42001 A.9.4.
GDPRExpects: automated decision-making procedure. Requires, by clause: GDPR Art. 35, GDPR Art. 22.

Register the documents in this family

Paste the list; every document in this family is placed in its type, given its owner and cadence against the clauses, and the ones the regimes expect and the list does not carry are named. Eight documents free, no account.

Build a register