Support
Provide the people, skills, communication, documentation, and records needed for the AI management system to operate.
How to implement it
- 01Define competence requirements for teams that build, buy, approve, monitor, or use AI systems.
- 02Train staff on acceptable AI use, data handling, prompt safety, human review, incident reporting, and limits of AI-generated outputs.
- 03Create communication rules for AI disclosures, customer questions, regulatory requests, and internal escalation.
- 04Control documented information such as policies, model cards, impact assessments, testing records, and monitoring reports.
- 05Keep evidence in a system that preserves ownership, version history, review status, and retention requirements.
Evidence to keep
- - AI training records
- - Competence matrix
- - Communication plan
- - Document control register
- - Versioned model and system documentation
Common mistakes
- - Training only developers
- - Letting model documentation live in scattered notebooks
- - Not controlling prompt libraries or system instructions
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.Incident response policyUse for ISO 27001 A.5.24 to A.5.28, SOC 2 incident response, PCI DSS 12.10, and security event handling.Acceptable use policyUse for ISO 27001 A.5.10, A.6.3, A.6.4, endpoint controls, remote work, and SOC 2 Security awareness.Data breach response policyUse for ISO 27001 A.5.24 to A.5.28, SOC 2 incident handling, privacy notification, and PCI DSS requirement 12.10.
Open the control-to-policy map