The organisation shall define and document the processes for the responsible use of AI systems. This control is essential for maintaining governance and ensuring that AI systems are managed responsibly. It should be applied consistently across all relevant organisational processes and reviewed periodically to remain effective.
Business Requirement The purpose of this control is to safeguard organisational integrity, compliance with legal and regulatory requirements, and to promote trustworthiness in AI systems. It ensures that risks are mitigated and that the organisation’s objectives for responsible AI use are achieved.
Depending on its context, the organisation can have many considerations for determining whether to use a particular AI system. Whether the AI system is developed by the organisation itself or sourced from a third party, the organisation should be clear on what these considerations are and develop policies to address them. Some examples are: — required approvals; — cost (including for ongoing monitoring and maintenance); — approved sourcing requirements; — legal requirements applicable to the organisation. Where the organisation has accepted policies for the use of other systems, assets, etc., these policies can be incorporated if desired. Organisations should implement this control by establishing clear procedures, assigning responsibilities, and maintaining accurate documentation. Practical steps include integrating this control into existing governance frameworks, training relevant personnel, and monitoring compliance through regular audits.
AvISO will be updating and reviewing all the information regularly, so keep us bookmarked and keep checking!
Got a question or need help? Don't hesitate to reach out to our team.
If you would like to know more about ISO Standards, Certification and the value of a good management system you can add to your business we would love to hear from you: Kent: 01892 800476 | London: 02037 458 476 | info@avisoconsultancy.co.uk