Operation
Run the processes that control AI systems across design, acquisition, development, deployment, use, monitoring, and retirement.
How to implement it
- 01Require intake and approval before new AI systems or material AI features are deployed.
- 02Apply lifecycle gates for data selection, model selection, testing, human oversight design, release approval, monitoring, and retirement.
- 03Define operating controls for AI outputs, including review thresholds, confidence rules, fallback processes, and user escalation.
- 04Manage AI suppliers by reviewing model provider terms, data use, security posture, transparency commitments, and change notifications.
- 05Keep logs for high-impact AI decisions, model changes, prompt changes, incidents, overrides, and human review actions.
Evidence to keep
- - AI intake tickets
- - Lifecycle gate records
- - Release approvals
- - Supplier due diligence
- - Monitoring logs and incident records
Common mistakes
- - Skipping governance for AI bought as SaaS
- - Launching pilots that become production without approval
- - Monitoring uptime but not output quality or harm
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.Change management policyUse for ISO 27001 A.8.32, A.8.9, SOC 2 change management criteria, and PCI DSS requirement 6 change controls.Secure development policyUse for ISO 27001 A.8.25 to A.8.32, source code controls, change management, and SOC 2 change controls.Cloud services and outsourcing policyUse for ISO 27001 A.5.19 to A.5.23, SOC 2 vendor management, and oversight of cloud and outsourced service providers.
Open the control-to-policy map