Context of the organization
Define why AI matters to the organisation, who is affected by it, and what parts of the business sit inside the AI management system.
How to implement it
- 01List internal and external issues that affect AI governance, including regulation, customer expectations, product strategy, data access, model suppliers, and risk appetite.
- 02Identify interested parties such as customers, users, employees, regulators, partners, model providers, and people affected by AI outputs.
- 03Set the AIMS scope by business unit, product, geography, AI system type, and third-party dependency.
- 04Create an AI system inventory so the scope is tied to real systems rather than abstract policy language.
- 05Map each AI system to owner, intended use, user group, data sources, model provider, risk tier, and monitoring needs.
Evidence to keep
- - AIMS scope statement
- - AI system inventory
- - Interested-party register
- - AI context and obligations register
- - Boundary diagram for in-scope AI systems
Common mistakes
- - Leaving employee AI tools out of scope
- - Treating vendor AI as out of scope because it is not built internally
- - Writing a scope that auditors cannot trace to real systems
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.Supplier security policyUse for ISO 27001 A.5.19 to A.5.23, SOC 2 vendor management, cloud services, and AI supplier reviews.Logging and monitoring policyUse for ISO 27001 A.8.15, A.8.16, A.8.17, SOC 2 Security, and PCI DSS requirements 10 and 11.Access control policyUse for ISO 27001 A.5.15, A.5.16, A.5.17, A.5.18, A.8.2, SOC 2 Security, and PCI DSS requirements 7 and 8.
Open the control-to-policy map