EvidenceSheet

GV-3.2 Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems

Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems. The policy distinguishes the human roles around a system, operator, rev

4
artefacts
1
held by a system
0
at each review
moderate
to go live
Cloud console / configuration management
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Per-system documentation of the configuration chosen and why · Cloud console / configuration management

periodic reviewEvidence produced at each review

none for this control

governing documentDocuments that govern the control

  • Policy defining each human role in the human-AI configuration and its authority · Policy repository / GRC workspace
  • Oversight procedures stating when a human may override or must intervene · Policy repository / GRC workspace
  • Competency requirements attached to each oversight role · Policy repository / GRC workspace

First move

Start with the 1 of 4 artefacts that already live in a system (Cloud console / configuration management); keep the periodic reviews but log each one as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

GV-3.1 Decision-making related to mapping, measuring, and managing AI risks throughout the lifecycle is informed by a diverse team · GV-4.1 Organizational policies and practices are in place to foster a critical thinking and safety-first mindset in the design, development, deployment, and uses of AI systems to minimize negative impacts