In the event of a nonconformity, the organization is required to initiate a formal response. This includes immediate measures to contain and rectify the issue while mitigating its consequences. A systematic review must be conducted to identify the root cause(s) and prevent recurrence by assessing whether similar vulnerabilities exist. Following this analysis, the organization must implement corrective actions that are proportionate to the nonconformity's effects. The effectiveness of these remedial measures must be validated, and the AI management system updated if necessary. Documented evidence of the nonconformity, the actions taken, and their outcomes is mandatory.






The organization must establish and maintain a formal process for identifying, managing, and correcting any nonconformities within its AI Management System (AIMS).
When a nonconformity is identified, this process must ensure the organization takes the following steps:
The organization must maintain documented information (records) for every nonconformity, detailing what happened, the actions taken in response, and the results of the corrective actions.
Digiturvamallissa kaikki vaatimuskehikkojen vaatimukset kohdistetaan universaaleihin tietoturvatehtäviin, jotta voitte muodostaa yksittäisen suunnitelman, joka täyttää ison kasan vaatimuksia.
.png)