GV-3.2 Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems
Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems. The policy distinguishes the human roles around a system, operator, rev
system holds itEvidence a system already holds
- Per-system documentation of the configuration chosen and why · Cloud console / configuration management
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- Policy defining each human role in the human-AI configuration and its authority · Policy repository / GRC workspace
- Oversight procedures stating when a human may override or must intervene · Policy repository / GRC workspace
- Competency requirements attached to each oversight role · Policy repository / GRC workspace
First move
Common gaps auditors find
- Human in the loop asserted without stating what the human is empowered to change
- Oversight assigned to a role with no authority to stop the system
- Configuration documented at design and not updated after automation increased
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetGV-3.1 Decision-making related to mapping, measuring, and managing AI risks throughout the lifecycle is informed by a diverse team · GV-4.1 Organizational policies and practices are in place to foster a critical thinking and safety-first mindset in the design, development, deployment, and uses of AI systems to minimize negative impacts