GV-2.3 Executive leadership of the organization takes responsibility for decisions about risks associated with AI system development and deployment
Executive leadership of the organization takes responsibility for decisions about risks associated with AI system development and deployment. Named executives hold and exercise the decision right over AI risk acceptance,
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Minutes recording executive decisions to accept, mitigate or reject AI risks · Policy repository / GRC workspace
- Evidence of the authority and budget granted to the accountable officer · Document repository
governing documentDocuments that govern the control
- The charter or terms of reference assigning AI risk decisions to named executives · Policy repository / GRC workspace
- The stated organisational appetite for AI risk, approved at executive level · Document repository
First move
Common gaps auditors find
- Executive sponsorship claimed with no minuted decision to point to
- Risk acceptance signed by the project owner who benefits from proceeding
- Appetite endorsed once at programme start and never revisited as systems changed
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetGV-2.2 The organization's personnel and partners receive AI risk management training to enable them to perform their duties and responsibilities consistent with related policies, procedures, and agreements · GV-3.1 Decision-making related to mapping, measuring, and managing AI risks throughout the lifecycle is informed by a diverse team