Automated decision-making procedure
Which decisions are made or assisted by a system, how a person can be involved, what the data subject is told, and how a decision is contested.
How the register reads it
| Also called | profiling procedure, human oversight procedure |
|---|---|
| Family | AI and automated decisions |
| Document type | Procedure. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Folds into | The regimes accept it folded into the ai use policy (acceptable ai use); when neither is listed, the gap is counted once, under the parent. |
| Expected owner | The AI governance lead (CTO, CDO or head of data science). |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | GDPR is ticked and no line resolves to it or to its parent (ISO 27701, ISO 42001 require it too, inside a parent document, so they do not list it separately). |
| Template | No template yet. The clauses below say what the document is expected to contain. |
Which standards require it, and what each expects it to contain
3 requiring clauses, 3 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
ISO/IEC 27701:2025
ISO 27701 A.1.3.11 Automated decision makingThe organization must identify and address the obligations, including legal obligations, that it owes to individuals arising from decisions it makes about them based solely on automated processing of their personal data, taking account of jurisdictions that impose specific obligations where such decisions significantly affect the individual, such as notifying that automated decision making exists, allowing objection to it, or providing human intervention, and of jurisdictions where some processing may not be fully automated at all.
Common gap: Automated decisions unrecognised as such because a person nominally approves an output they never question, which is not meaningful human involvement
Source: ISO/IEC 27701:2025
ISO/IEC 42001:2023
ISO 42001 A.9.4 Intended use of the AI systemThe organization shall ensure that the AI system is used according to the intended uses of the AI system and its accompanying documentation.
Common gap: Is off-label use detected and addressed?
Source: ISO/IEC 42001:2023
GDPR (Regulation (EU) 2016/679)
GDPR Art. 22 Automated individual decision-making, including profilingDo not subject a data subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, unless the decision is necessary for entering into or performing a contract between the data subject and the controller, is authorised by Union or Member State law that lays down suitable safeguards, or is based on the data subject's explicit consent. Where the contract or explicit consent route is used, implement suitable measures to safeguard the data subject's rights, freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express a point of view and to contest the decision. Such decisions must not be based on special categories of personal data unless explicit consent or substantial public interest applies and suitable safeguards are in place.
Common gap: A rubber stamp reviewer treated as human involvement, which leaves the decision solely automated in substance
Source: GDPR (Regulation (EU) 2016/679)
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a registerAI use policy (acceptable AI use) · Anti-bribery and corruption policy