Planning
Plan how the organisation will assess AI risks and opportunities, set measurable objectives, and manage changes to the AIMS.
How to implement it
- 01Define an AI risk assessment method that covers harm, bias, privacy, safety, security, reliability, explainability, misuse, and legal impact.
- 02Run an AI impact assessment for systems that affect people, customers, regulated decisions, safety, or material business outcomes.
- 03Maintain a risk treatment plan that links each risk to controls, accountable owners, due dates, and residual risk approval.
- 04Set AIMS objectives such as inventory coverage, assessment completion, incident response time, model monitoring coverage, and training completion.
- 05Define how changes to models, prompts, datasets, providers, or intended use trigger reassessment.
Evidence to keep
- - AI risk methodology
- - AI risk register
- - AI impact assessments
- - Risk treatment plan
- - AIMS objectives and progress reports
Common mistakes
- - Assessing only cybersecurity risk
- - Ignoring foreseeable misuse
- - Failing to reassess when a model is repurposed
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.Change management policyUse for ISO 27001 A.8.32, A.8.9, SOC 2 change management criteria, and PCI DSS requirement 6 change controls.Data breach response policyUse for ISO 27001 A.5.24 to A.5.28, SOC 2 incident handling, privacy notification, and PCI DSS requirement 12.10.Incident response policyUse for ISO 27001 A.5.24 to A.5.28, SOC 2 incident response, PCI DSS 12.10, and security event handling.
Open the control-to-policy map