GV-1.4 The risk management process and its outcomes are established through transparent policies, procedures, and other controls based on organizational risk priorities
The risk management process and its outcomes are established through transparent policies, procedures, and other controls based on organizational risk priorities. The process and the decisions it produced are both docume
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Completed records for deployed systems showing the process was followed, not just defined · Document repository
governing documentDocuments that govern the control
- The documented AI risk management process, with the decision points it contains · Document repository
- Standardised documentation templates used across AI work products · Document repository
- Named accountable contacts recorded on work products so decisions are traceable to people · Document repository
First move
Common gaps auditors find
- Process defined centrally but the delivery records show a different practice
- Outcomes recorded without the reasoning, so the decision cannot be reviewed
- Documentation held in individual team tools with no organisational retention
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetGV-1.3 Processes and procedures are in place to determine the needed level of risk management activities based on the organization's risk tolerance · GV-1.5 Ongoing monitoring and periodic review of the risk management process and its outcomes are planned, organizational roles and responsibilities are clearly defined, including determining the frequency of periodic review