Responsible use
Make responsible AI principles operational, including fairness, accountability, transparency, privacy, security, safety, and human agency.
How to implement it
- 01Define responsible AI principles and turn them into controls
- 02Set human oversight levels based on impact
- 03Document fairness, explainability, safety, and misuse tests where relevant
- 04Create channels for feedback, appeal, and incident reporting
Evidence to keep
- - Responsible AI principles
- - Oversight design
- - Fairness or safety test records
- - Feedback and appeal records
Metrics to watch
- - High-impact systems with oversight defined
- - Appeals or complaints
- - Responsible AI test completion
Put this area into the AI Statement of Applicability with a short rationale: included, excluded, or partially included. Tie that decision to the AI risk assessment, impact assessment, and system inventory.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.Data breach response policyUse for ISO 27001 A.5.24 to A.5.28, SOC 2 incident handling, privacy notification, and PCI DSS requirement 12.10.Data retention and disposal policyUse for ISO 27001 A.5.33, A.5.34, A.8.10, SOC 2 Confidentiality and Privacy, and PCI DSS requirement 3.Incident response policyUse for ISO 27001 A.5.24 to A.5.28, SOC 2 incident response, PCI DSS 12.10, and security event handling.
Open the control-to-policy map