AAISM · Topic 4
AI Governance Frameworks
Domain: AI Governance and Program Management, about 31% of the exam
ISO/IEC 42001 management system
- 4 Context
- 5 Leadership
- 6 Planning
- 7 Support
- 8 Operation
- 9 Evaluation
- 10 Improvement
- Scope
- any organization developing, providing, using AI
- Clause 6
- risk assessment, impact assessment, objectives
- Clause 8
- operational controls, impact assessment performed
- Clause 9
- monitoring, internal audit, management review
- Annex A
- reference controls, justified in statement
- Annex B
- implementation guidance for controls
- Certifiable
- yes, unlike NIST AI RMF
Statement of applicability lists every Annex A control and says why it is included or excluded
ISO 42001 Annex A themes
- AI policy and internal organization
- Resources: data, tools, compute, people
- Impact assessment on individuals and society
- AI system lifecycle and documentation
- Data for AI systems and quality
- Information for interested parties
- Use of AI systems, responsible use
- Third-party and customer relationships
Companion standards
- ISO/IEC 23894
- AI risk management guidance, not certifiable
- ISO 31000
- parent risk management principles
- ISO/IEC 22989
- AI concepts and terminology
- ISO/IEC 38507
- governance implications for boards
- ISO/IEC 27001
- information security, integrate with 42001
- ISO/IEC 5338
- AI system lifecycle processes
NIST AI RMF
- Govern
- culture, roles, policies, accountability
- Map
- context, purpose, impacts, stakeholders
- Measure
- test, benchmark, track trustworthiness
- Manage
- prioritize, respond, monitor, accept
- Voluntary
- guidance, no certification
- Trustworthy AI
- seven characteristics, valid and reliable first
- Playbook and profiles
- GenAI profile is AI 600-1
Govern is cross-cutting; after it, start with Map to fix context before measuring anything
EU AI Act essentials
- Four tiers: unacceptable, high, limited, minimal
- High-risk: Annex I products, Annex III uses
- Employment screening is high-risk
- Human oversight able to intervene or override
- Training data relevant, representative, error-checked
- Right to explanation and complaint
- Real-time biometric ID: narrow law enforcement exceptions
- In force August 2024, phased duties
Policy hierarchy
- Principles
- Policy
- Standard
- Objective
- KPI
- Target
- Procedure
What each does
- Policy
- mandatory intent approved by leadership
- Objective
- measurable outcome the policy seeks
- KPI
- metric showing progress toward objective
- Target
- the KPI value to reach
Worked example
- Policy
- all high-risk models are reviewed
- Objective
- no unreviewed model in production
- KPI
- percent of models with review
- Target
- 100 percent by year end
Roles and structures
- Board
- risk appetite, ultimate accountability
- AI governance committee
- approves high-risk deployments
- Chief AI officer
- program owner and executive sponsor
- AI risk manager
- register, assessments, reporting
- Ethics lead
- fairness, transparency review
- Data governance
- quality, provenance, consent
- Security
- threat modeling, controls, incidents
- Three lines
- operate, oversee, independently assure
Transparency artifacts
- Model card
- purpose, limits, performance by group
- Datasheet
- dataset motivation, composition, collection
- System card
- whole application, safety mitigations
- AI-BOM
- models, data, dependencies inventory
- Impact assessment
- consequences to people and society
- Conformity declaration
- provider attests high-risk compliance
- Register entry
- EU database before market
Wider landscape
- OECD principles: inclusive growth, human-centered, transparent, robust, accountable
- UNESCO recommendation is non-binding
- Council of Europe convention binds signatories
- NYC Local Law 144: annual bias audits
- Colorado: reasonable care for high-risk AI
- SR 11-7: model risk, independent validation
- Sector law applies regardless of AI
Building the program
- Inventory AI
- Classify risk
- Set policy
- Assign owners
- Assess
- Control
- Audit
- Improve
- Inventory first, nothing governs unknown systems
- Maturity: ad hoc to optimized
- Management review feeds continual improvement
Management review inputs
- Status of previous actions
- Changes in internal and external context
- AI performance and control effectiveness
- Audit results and nonconformities
- Incident trends and complaints
- Interested party feedback
- Opportunities for improvement
Key numbers
- Seven
- ISO 42001 requirement clauses, 4 to 10
- Four
- NIST AI RMF functions
- Seven
- NIST trustworthiness characteristics
- Four
- EU AI Act risk tiers
- Five
- OECD AI principles
- Three
- lines of defense
- August 2024
- AI Act in force
Reference strip: 42001, NIST, AI Act, hierarchy, artifacts
ISO/IEC 42001
- Certifiable AI management system
- Clauses 4 to 10, Annex A controls
- Statement of applicability required
- 23894 guides the risk part
NIST AI RMF
- Govern, map, measure, manage
- Voluntary, profiles, playbook
- Valid and reliable comes first
- Map before measure
EU AI Act
- Unacceptable, high, limited, minimal
- Human oversight, data governance, logging
- Provider proves, deployer oversees
- Explanation and complaint rights
Policy hierarchy
- Policy states intent
- Objective states outcome
- KPI measures progress
- Target sets the value
Artifacts
- Model card, datasheet, system card
- AI-BOM inventories components
- Impact assessment for people
- Conformity declaration for market
Quick exam traps
- Trap: NIST AI RMF certification demonstrates compliance to regulators
- Trap: ISO/IEC 23894 is the certifiable AI standard
- Trap: A KPI and a target are the same thing
- Trap: Minimal-risk systems under the AI Act have no obligations at all
- Trap: Human oversight is satisfied by a human reading the output log afterwards
- Trap: The AI governance committee owns day-to-day model risk
- Trap: A model card replaces an impact assessment
- Trap: Measure comes before Map when adopting the NIST AI RMF
cybercertprep.com · original revision sheet written from the public body of knowledge