Information for interested parties
Provide appropriate transparency to users, customers, staff, regulators, auditors, and affected people.
How to implement it
- 01Define what information each stakeholder group needs
- 02Prepare user notices, model cards, customer FAQs, and audit packs where appropriate
- 03Explain AI limitations, human oversight, appeal paths, and data use in plain language
- 04Keep disclosures current when systems change
Evidence to keep
- - Stakeholder communication plan
- - AI notices
- - Model or system cards
- - Customer assurance pack
Metrics to watch
- - Disclosure coverage
- - Stakeholder questions unresolved
- - Expired assurance documents
Put this area into the AI Statement of Applicability with a short rationale: included, excluded, or partially included. Tie that decision to the AI risk assessment, impact assessment, and system inventory.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.Change management policyUse for ISO 27001 A.8.32, A.8.9, SOC 2 change management criteria, and PCI DSS requirement 6 change controls.Data breach response policyUse for ISO 27001 A.5.24 to A.5.28, SOC 2 incident handling, privacy notification, and PCI DSS requirement 12.10.Logging and monitoring policyUse for ISO 27001 A.8.15, A.8.16, A.8.17, SOC 2 Security, and PCI DSS requirements 10 and 11.
Open the control-to-policy map