AI and automated decisions
The documents an organisation that uses or builds AI systems now needs: the AI policy, the acceptable-use rules, the impact assessment, the logging of automated decisions.
Policy types in this family
5- AI governance policy policy
The organisation's policy for developing, buying and using AI systems: principles, roles, risk, alignment with the other policies and review. Required by ISO 42001; owner the AI governance lead (CTO, CDO or head of data science). - AI system development and operation standard standard
The rules for designing, building, verifying, deploying, monitoring and logging AI systems, and the documentation each stage leaves. Required by ISO 42001; owner the AI governance lead (CTO, CDO or head of data science). - AI system impact assessment procedure procedure
When and how the effect of an AI system on individuals, groups and society is assessed, documented and acted on before and after deployment. Required by ISO 42001, GDPR; owner the AI governance lead (CTO, CDO or head of data science). - AI use policy (acceptable AI use) policy
Which AI tools people may use, for what, with which data, what must be checked by a person, and what must never be entered or relied on. Required by ISO 27001, ISO 42001; owner the AI governance lead (CTO, CDO or head of data science). - Automated decision-making procedure procedure
Which decisions are made or assisted by a system, how a person can be involved, what the data subject is told, and how a decision is contested. Required by ISO 27701, ISO 42001, GDPR; owner the AI governance lead (CTO, CDO or head of data science).
What reaches this family
| ISO 27001 | Expects: no document of this family on its gap list. Requires, by clause: ISO 27001 5.10. |
|---|---|
| ISO 27701 | Expects: no document of this family on its gap list. Requires, by clause: ISO 27701 A.1.3.11. |
| ISO 42001 | Expects: ai governance policy, ai system impact assessment procedure, ai use policy (acceptable ai use). Requires, by clause: ISO 42001 A.2.2, ISO 42001 A.2.3, ISO 42001 A.2.4, ISO 42001 A.3.2, ISO 42001 A.3.3, ISO 42001 A.6.1.3, ISO 42001 A.6.2.4, ISO 42001 A.6.2.6, ISO 42001 A.6.2.8, ISO 42001 A.5.2, ISO 42001 A.5.3, ISO 42001 A.5.4, ISO 42001 A.9.2, ISO 42001 A.9.4. |
| GDPR | Expects: automated decision-making procedure. Requires, by clause: GDPR Art. 35, GDPR Art. 22. |
Register the documents in this family
Paste the list; every document in this family is placed in its type, given its owner and cadence against the clauses, and the ones the regimes expect and the list does not carry are named. Eight documents free, no account.
Build a register