For the effective governance of an AI management system, the organization is required to conduct a thorough analysis of its internal and external context, including stakeholder expectations, to identify pertinent risks and opportunities. This analysis underpins the establishment of formal AI risk criteria, which must provide a clear basis for distinguishing between acceptable and unacceptable risk levels. A documented action plan is mandatory for addressing all identified risks and opportunities. This plan must detail the integration of these actions into system processes and include methods for evaluating their effectiveness, ensuring the system achieves its goals, prevents harm, and improves over time. All related activities must be retained as documented information.






The organization should establish and maintain a comprehensive process for identifying, assessing, and treating risks and opportunities related to its AI management system and the AI systems it develops or uses. This process should take into account the organization's context, the needs and expectations of relevant interested parties, and the specific domain, application environment, and intended use of AI systems.
The organization should define clear criteria for evaluating AI risks, including acceptable and unacceptable levels, and use these criteria to guide AI risk assessments and treatment decisions. Actions planned to address these identified risks and opportunities should be integrated into the organization's AI management system processes, and their effectiveness should be regularly assessed.
All measures undertaken to identify, assess, and manage AI-related risks and opportunities should be properly documented.
Digiturvamallissa kaikki vaatimuskehikkojen vaatimukset kohdistetaan universaaleihin tietoturvatehtäviin, jotta voitte muodostaa yksittäisen suunnitelman, joka täyttää ison kasan vaatimuksia.
.png)