GV-4.1 Organizational policies and practices are in place to foster a critical thinking and safety-first mindset in the design, development, deployment, and uses of AI systems to minimize negative impacts
Organizational policies, and practices are in place to foster a critical thinking and safety-first mindset in the design, development, deployment, and uses of AI systems to minimize negative impacts. Practices exist that
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Records of concerns raised and how each was resolved · Document repository
- Evidence a concern changed a design or delayed a deployment · Source control / CI pipeline
governing documentDocuments that govern the control
- Policy establishing separated accountability for development, risk and assurance · Policy repository / GRC workspace
- The internal route for raising an AI safety concern and the protection attached to it · Document repository
First move
Common gaps auditors find
- A stated speak-up culture with no record of anything ever being raised
- Assurance and development reporting to the same accountable owner
- Concerns logged and closed without a recorded resolution
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetGV-3.2 Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems · GV-4.2 Organizational teams document the risks and potential impacts of the AI technology they design, develop, deploy, evaluate and use, and communicate about the impacts more broadly