MP-3.5 Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function
Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from GOVERN function. Oversight is designed for the specific configuration, assessed for whether it is exerci
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Assessment of whether oversight is exercisable at the pace and volume of operation · Document repository
governing documentDocuments that govern the control
- The documented human oversight process for the system · Document repository
- The link to the governing organisational policy on oversight · Policy repository / GRC workspace
- The authority the overseer holds, including whether they can stop the system · Document repository
First move
Common gaps auditors find
- Oversight designed at a volume the reviewer cannot sustain
- Overseer able to observe but not to intervene
- Process differs from the governing policy with no recorded deviation
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetMP-3.4 Processes for operator and practitioner proficiency with AI system performance and trustworthiness, and relevant technical standards and certifications, are defined, assessed and documented · MP-4.1 Approaches for mapping AI technology and legal risks of its components, including the use of third-party data or software, are in place, followed, and documented, as are risks of infringement of a third party's intellectual property or other rights