Global Software AI
1 min. lasīšana

ISO/IEC 42001 makes AI governance auditable

ISO/IEC 42001 does not prescribe seven named documents; it requires controlled evidence that AI risks, responsibilities, and decisions are managed.

Autors: Tim Crouch

Vairāk no AI Security

ISO/IEC 42001 does not mandate a universal bundle of exactly seven named documents. That claim is too neat. As an AI management-system standard, it instead requires organizations to maintain and retain documented information across governance, planning, operation, evaluation, and improvement.

The evidence includes the management system's scope, AI policy and objectives, risk-assessment and risk-treatment processes, a statement of applicability, impact-assessment processes and results, competence records, monitoring results, audits, management reviews, and corrective actions. Annex A controls also have to be considered, but they are not an automatic checklist applied identically to every organization. Selected controls, justified exclusions, and any additional controls belong in the statement of applicability.

CISSP Domain 1, Security and Risk Management, is therefore the primary lens. ISO/IEC 42001 connects policy, accountable roles, risk criteria, treatment decisions, impact assessment, assurance, and continual improvement. When someone asks why an AI system was approved, changed, restricted, or retired, the answer should be traceable to an authorized decision and its evidence.

Domain 2, Asset Security, makes that system concrete. AI systems, models, datasets, tools, infrastructure, and third-party components need identified owners and appropriate handling rules. An inventory, data-lineage records, system design specifications, and supplier documentation may all be sensible ways to satisfy those needs, but the standard does not define them as a fixed seven-document package.

Domain 5, Identity and Access Management, then governs who can use or alter those assets. Acceptable-use rules, authentication, privileged access, logging, and review should follow the system's risk and lifecycle context.

My takeaway is that ISO/IEC 42001 requires an evidence system, not paperwork by slogan. Keep documented information controlled, current, and connected to change management. Review it at planned intervals and after material changes; choose the cadence from risk and context rather than presenting a quarterly review as a universal requirement.