Data for AI systems
Govern data used for AI so it is lawful, suitable, representative enough for the purpose, protected, and traceable.
How to implement it
- 01Document data sources, rights, lineage, and quality checks
- 02Assess training, validation, test, prompt, and operational data separately
- 03Apply privacy, classification, retention, and access controls
- 04Track data changes that could affect model behaviour
Evidence to keep
- - Data inventory
- - Data lineage records
- - Data quality checks
- - Privacy and security reviews
Metrics to watch
- - Datasets with lineage recorded
- - Data quality exceptions
- - Open privacy or retention issues
Put this area into the AI Statement of Applicability with a short rationale: included, excluded, or partially included. Tie that decision to the AI risk assessment, impact assessment, and system inventory.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.Data retention and disposal policyUse for ISO 27001 A.5.33, A.5.34, A.8.10, SOC 2 Confidentiality and Privacy, and PCI DSS requirement 3.Information classification and handling policyUse for ISO 27001 A.5.12, A.5.13, A.5.14, privacy, SOC 2 Confidentiality, and data handling controls.Acceptable use policyUse for ISO 27001 A.5.10, A.6.3, A.6.4, endpoint controls, remote work, and SOC 2 Security awareness.
Open the control-to-policy map