AI objectives and metrics
Define measurable objectives for AI performance and governance so the AIMS can be evaluated and improved.
How to implement it
- 01Set measurable AI objectives tied to business value, risk, quality, and stakeholder protection
- 02Define metrics for model performance and governance performance
- 03Review metrics in management review and risk forums
- 04Use metric trends to trigger corrective action or reassessment
Evidence to keep
- - AIMS objectives
- - Metric definitions
- - Performance dashboards
- - Management review actions
Metrics to watch
- - Objective completion
- - Model drift alerts
- - Corrective actions from metric reviews
Put this area into the AI Statement of Applicability with a short rationale: included, excluded, or partially included. Tie that decision to the AI risk assessment, impact assessment, and system inventory.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.Information risk management procedureThe clause 6.1.2/6.1.3 and 8.2/8.3 engine: risk identification, analysis scales, evaluation, treatment, acceptance and review.Information security roles and responsibilitiesUse for ISO 27001 A.5.2, A.5.3 and A.5.4, defining security roles, segregation of duties, management responsibilities, and SOC 2 organisational controls.ISMS internal audit procedureHow to plan and run internal ISMS audits under ISO 27001 clause 9.2, from programme to follow-up.
Open the control-to-policy map