MS-2.9 The AI model is explained, validated, and documented, and AI system output is interpreted within its context as identified in the MAP function and to inform responsible use and governance
The AI model is explained, validated, and documented, and AI system output is interpreted within its context – as identified in the MAP function – and to inform responsible use and governance. Explanations are validated
4
artefacts
1
held by a system
0
at each review
moderate
to go live
Source control / CI pipeline
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Guidance on interpreting output within the deployment context · Source control / CI pipeline
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- The explanation method used and validation of its fidelity to model behaviour · Document repository
- Model documentation covering how the model reaches its outputs · Document repository
- Identification of the audiences for explanation and what each needs · Document repository
First move
Start with the 1 of 4 artefacts that already live in a system (Source control / CI pipeline); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Explanation method adopted with no check that it reflects the model
- Feature attributions produced for developers and never translated for the people affected
- Limitations of the explanation method not stated
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetMS-2.8 Risks associated with transparency and accountability as identified in the MAP function are examined and documented · MS-2.10 Privacy risk of the AI system as identified in the MAP function is examined and documented