Leadership
Make senior leadership accountable for responsible AI, policy approval, role assignment, and integration with business processes.
How to implement it
- 01Approve an AI policy that defines acceptable use, prohibited use, escalation paths, and decision authority.
- 02Name an executive owner for the AI management system and assign operational owners for AI risk, data, security, legal, product, and model operations.
- 03Set up an AI governance forum with the authority to approve high-impact AI use cases and stop unsafe deployments.
- 04Define who can approve new AI systems, material model changes, training data changes, and exceptions to AI policy.
- 05Ensure AI objectives are not only technical goals, but include risk, transparency, human oversight, and stakeholder protection.
Evidence to keep
- - Approved AI policy
- - AI governance charter
- - Role descriptions or RACI
- - Steering committee minutes
- - Approval records for AI use cases
Common mistakes
- - Making AI governance an engineering-only responsibility
- - Approving policy without assigning authority
- - Letting product launch pressure override risk decisions
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.Acceptable use policyUse for ISO 27001 A.5.10, A.6.3, A.6.4, endpoint controls, remote work, and SOC 2 Security awareness.Change management policyUse for ISO 27001 A.8.32, A.8.9, SOC 2 change management criteria, and PCI DSS requirement 6 change controls.Information security roles and responsibilitiesUse for ISO 27001 A.5.2, A.5.3 and A.5.4, defining security roles, segregation of duties, management responsibilities, and SOC 2 organisational controls.
Open the control-to-policy map