Performance evaluation
Measure whether the AIMS is working, audit it, and have leadership review performance and needed changes.
How to implement it
- 01Define monitoring for both management-system performance and AI system performance.
- 02Track indicators such as incidents, exceptions, overdue risk treatments, model drift, complaint trends, assessment coverage, and review completion.
- 03Run internal audits that sample AI systems, policies, evidence, suppliers, risk decisions, and corrective actions.
- 04Hold management reviews that cover AIMS performance, changes in context, audit findings, stakeholder feedback, incidents, and improvement needs.
- 05Use evidence from monitoring and audits to adjust AI objectives, controls, and risk appetite.
Evidence to keep
- - AIMS KPI dashboard
- - Internal audit plan and reports
- - Management review minutes
- - Corrective action tracker
- - Monitoring reports
Common mistakes
- - Measuring model accuracy while ignoring governance performance
- - Running audits with no sampling method
- - Treating management review as a status update only
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.Incident response policyUse for ISO 27001 A.5.24 to A.5.28, SOC 2 incident response, PCI DSS 12.10, and security event handling.Logging and monitoring policyUse for ISO 27001 A.8.15, A.8.16, A.8.17, SOC 2 Security, and PCI DSS requirements 10 and 11.Supplier security policyUse for ISO 27001 A.5.19 to A.5.23, SOC 2 vendor management, cloud services, and AI supplier reviews.
Open the control-to-policy map