The organization is responsible for carrying out the AI risk mitigation strategy detailed in section 6.1.3 and must subsequently validate the effectiveness of all implemented controls. Risk treatment is required to be an ongoing, adaptive process. In instances where new threats emerge or existing countermeasures are determined to be inadequate, the organization must formally re-engage the risk treatment methodology to re-evaluate and update its mitigation plan. A complete record of all actions and outcomes related to AI risk treatment activities must be maintained as documented information.






The organization must implement the controls and actions outlined in its AI risk treatment plan (as defined in ISO 42001 Clause 6.1.3).
This process must be a continuous cycle that includes:
The organization must maintain documented information (records) of the results of all risk treatment activities, including which controls were implemented and evidence of their effectiveness.
Digiturvamallissa kaikki vaatimuskehikkojen vaatimukset kohdistetaan universaaleihin tietoturvatehtäviin, jotta voitte muodostaa yksittäisen suunnitelman, joka täyttää ison kasan vaatimuksia.
.png)