AI governance policy
The organisation's policy for developing, buying and using AI systems: principles, roles, risk, alignment with the other policies and review.
How the register reads it
| Also called | AI policy, responsible AI policy, AI principles |
|---|---|
| Family | AI and automated decisions |
| Document type | Policy. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Expected owner | The AI governance lead (CTO, CDO or head of data science). |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | ISO 42001 is ticked and no line resolves to it. |
| Template | Ai governance policy. |
Which standards require it, and what each expects it to contain
5 requiring clauses, 1 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
ISO/IEC 42001:2023
ISO 42001 A.2.2 AI policyThe organization shall document a policy for the development, deployment, or use of AI systems that aligns with the organization's strategic direction.
Common gap: Does the AI policy address AI-specific concerns beyond restating IT policy?
Source: ISO/IEC 42001:2023
ISO 42001 A.2.3 Alignment with other organizational policiesThe AI policy shall be aligned with other organizational policies (privacy, security, quality, ethics, HR).
Common gap: Are policy conflicts identified and resolved?
Source: ISO/IEC 42001:2023
ISO 42001 A.2.4 Review of the AI policyThe AI policy shall be reviewed at planned intervals or if significant changes occur to ensure continuing suitability, adequacy, and effectiveness.
Common gap: Has the policy been reviewed since publication or is it stale?
Source: ISO/IEC 42001:2023
ISO 42001 A.3.2 AI roles and responsibilitiesRoles and responsibilities for AI shall be defined and allocated according to the organization's needs.
Common gap: Are AI-specific roles defined or rolled into existing IT roles?
Source: ISO/IEC 42001:2023
ISO 42001 A.3.3 Reporting of concernsA process shall be established to enable reporting of concerns about AI systems' development, deployment, or use.
Common gap: Is the reporting channel actually used and concerns addressed?
Source: ISO/IEC 42001:2023
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a registerRecord of processing activities · AI system development and operation standard