To satisfy its requirements and implement actions from Clause 6, the organization must maintain oversight of its operational processes. This includes implementing and monitoring all controls identified through risk treatment, especially those governing the AI system lifecycle, and taking corrective action when necessary. The organization must also systematically manage change, mitigating the consequences of both planned and unintended modifications. Furthermore, control must extend to all relevant externally provided services or products. Sufficient documentation is required to provide assurance that processes have been executed as intended.






The organization must establish a comprehensive framework to plan, implement, and control all processes within its AI Management System (AIMS). This ensures that the actions identified during the planning and risk assessment phase are effectively carried out.
This operational framework must include:
Throughout this entire process, the organization must maintain sufficient documented information (records) to provide evidence that its operational processes have been carried out as planned.
Digiturvamallissa kaikki vaatimuskehikkojen vaatimukset kohdistetaan universaaleihin tietoturvatehtäviin, jotta voitte muodostaa yksittäisen suunnitelman, joka täyttää ison kasan vaatimuksia.
.png)