Resources for AI systems
Ensure the organisation has the people, tools, data, infrastructure, and budget needed to govern AI systems properly.
How to implement it
- 01Identify resource needs for each AI lifecycle stage
- 02Set competence requirements for AI roles
- 03Provide tooling for evaluation, monitoring, and evidence collection
- 04Plan capacity for human oversight and incident response
Evidence to keep
- - Resource plan
- - Competence matrix
- - Tooling inventory
- - Training completion records
Metrics to watch
- - Training completion
- - Coverage of monitoring tooling
- - Human review backlog
Put this area into the AI Statement of Applicability with a short rationale: included, excluded, or partially included. Tie that decision to the AI risk assessment, impact assessment, and system inventory.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.Incident response policyUse for ISO 27001 A.5.24 to A.5.28, SOC 2 incident response, PCI DSS 12.10, and security event handling.Acceptable use policyUse for ISO 27001 A.5.10, A.6.3, A.6.4, endpoint controls, remote work, and SOC 2 Security awareness.Access control policyUse for ISO 27001 A.5.15, A.5.16, A.5.17, A.5.18, A.8.2, SOC 2 Security, and PCI DSS requirements 7 and 8.
Open the control-to-policy map