Policy Register

AI system development and operation standard

The rules for designing, building, verifying, deploying, monitoring and logging AI systems, and the documentation each stage leaves.

How the register reads it

Also calledMLOps standard, model risk management
FamilyAI and automated decisions
Document typeStandard. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Folds intoThe regimes accept it folded into the ai governance policy; when neither is listed, the gap is counted once, under the parent.
Expected ownerThe AI governance lead (CTO, CDO or head of data science).
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whennever on its own: the register recognises it and names the clauses, but no ticked regime lists it as a separate document (its parent, ai governance policy, is).
TemplateNo template yet. The clauses below say what the document is expected to contain.

Which standards require it, and what each expects it to contain

4 requiring clauses, 1 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 42001:2023

ISO 42001 A.6.1.3 Processes for responsible design and development of AI systems

The organization shall define and document specific processes for the responsible design and development of AI systems.

Evidence an auditor accepts: AI development lifecycle (AI SDLC) procedure; design review records; stage gates and reviews
Common gap: Are responsible AI checkpoints embedded in SDLC or bolted on?
Source: ISO/IEC 42001:2023
ISO 42001 A.6.2.4 AI system verification and validation

AI systems shall be verified and validated, and the results documented. Verification confirms requirements are met; validation confirms intended use is achieved.

Evidence an auditor accepts: V&V plans; test results; acceptance reports
Common gap: Are V&V results signed off independently from developers?
Source: ISO/IEC 42001:2023
ISO 42001 A.6.2.6 AI system operation and monitoring

AI systems shall be operated and monitored according to organizational and operational requirements throughout their lifetime. Operational guidance shall be available to operators.

Evidence an auditor accepts: Operations runbooks; monitoring dashboards; incident logs
Common gap: Is monitoring active and alerts acted upon?
Source: ISO/IEC 42001:2023
ISO 42001 A.6.2.8 AI system event logging

Event logs shall be generated and recorded during AI system operations to enable monitoring, accountability, and incident investigation.

Evidence an auditor accepts: Logging standards; log samples; log retention policy
Common gap: Are logs sufficient to reconstruct an incident or audit a decision?
Source: ISO/IEC 42001:2023

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

AI governance policy · AI system impact assessment procedure