Policy Register

AI governance policy

The organisation's policy for developing, buying and using AI systems: principles, roles, risk, alignment with the other policies and review.

How the register reads it

Also calledAI policy, responsible AI policy, AI principles
FamilyAI and automated decisions
Document typePolicy. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Expected ownerThe AI governance lead (CTO, CDO or head of data science).
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whenISO 42001 is ticked and no line resolves to it.
TemplateAi governance policy.

Which standards require it, and what each expects it to contain

5 requiring clauses, 1 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 42001:2023

ISO 42001 A.2.2 AI policy

The organization shall document a policy for the development, deployment, or use of AI systems that aligns with the organization's strategic direction.

Evidence an auditor accepts: AI policy; approval records; aI-specific policy (distinct from general IT policy)
Common gap: Does the AI policy address AI-specific concerns beyond restating IT policy?
Source: ISO/IEC 42001:2023
ISO 42001 A.2.3 Alignment with other organizational policies

The AI policy shall be aligned with other organizational policies (privacy, security, quality, ethics, HR).

Evidence an auditor accepts: Policy cross-reference matrix; mapping AI policy to ISMS, PIMS, QMS, HR policies; conflict resolution evidence
Common gap: Are policy conflicts identified and resolved?
Source: ISO/IEC 42001:2023
ISO 42001 A.2.4 Review of the AI policy

The AI policy shall be reviewed at planned intervals or if significant changes occur to ensure continuing suitability, adequacy, and effectiveness.

Evidence an auditor accepts: Policy review schedule; review records; annual review evidence
Common gap: Has the policy been reviewed since publication or is it stale?
Source: ISO/IEC 42001:2023
ISO 42001 A.3.2 AI roles and responsibilities

Roles and responsibilities for AI shall be defined and allocated according to the organization's needs.

Evidence an auditor accepts: Role descriptions; rACI matrix; org chart
Common gap: Are AI-specific roles defined or rolled into existing IT roles?
Source: ISO/IEC 42001:2023
ISO 42001 A.3.3 Reporting of concerns

A process shall be established to enable reporting of concerns about AI systems' development, deployment, or use.

Evidence an auditor accepts: Concern reporting procedure; whistleblower channel evidence; concern register
Common gap: Is the reporting channel actually used and concerns addressed?
Source: ISO/IEC 42001:2023

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Record of processing activities · AI system development and operation standard