Use of AI systems
Control how AI systems are used in practice so outputs are reviewed, limitations are understood, and misuse is detected.
How to implement it
- 01Define permitted users and permitted use cases
- 02Set output review rules for consequential decisions
- 03Train users on limitations and escalation
- 04Monitor use patterns, overrides, complaints, and unsafe outputs
Evidence to keep
- - User guidance
- - Access records
- - Human review logs
- - Usage monitoring reports
Metrics to watch
- - Users trained before access
- - Human override rate
- - Misuse or unsafe-output events
Put this area into the AI Statement of Applicability with a short rationale: included, excluded, or partially included. Tie that decision to the AI risk assessment, impact assessment, and system inventory.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.Incident response policyUse for ISO 27001 A.5.24 to A.5.28, SOC 2 incident response, PCI DSS 12.10, and security event handling.Access control policyUse for ISO 27001 A.5.15, A.5.16, A.5.17, A.5.18, A.8.2, SOC 2 Security, and PCI DSS requirements 7 and 8.Data retention and disposal policyUse for ISO 27001 A.5.33, A.5.34, A.8.10, SOC 2 Confidentiality and Privacy, and PCI DSS requirement 3.
Open the control-to-policy map