For the duration of an artificial intelligence system's existence, from its initial conception to its eventual decommissioning, the organization holds a continuous obligation. It must systematically evaluate and formally record the foreseeable consequences the system could have. This documented analysis must address the potential effects on both individual persons and identifiable population subgroups, ensuring a comprehensive impact assessment is maintained throughout the AI system's lifecycle.






The organization should establish and maintain a process for documenting the results of AI system impact assessments. This documentation should include the assessment methodology, identified impacts, risk treatment plans, and the reasoning for decisions made. Additionally, the organization should define and adhere to a retention period for these records.






The organization should systematically assess and document the potential impacts of its AI systems on individuals and groups of individuals throughout the entire AI system lifecycle, from design and development to deployment and monitoring. This assessment should consider various types of impacts, transparency and explainability, security and privacy, fairness, accessibility, accountability, safety and health and human rights, to ensure responsible and human-centric AI development and use.
Digiturvamallissa kaikki vaatimuskehikkojen vaatimukset kohdistetaan universaaleihin tietoturvatehtäviin, jotta voitte muodostaa yksittäisen suunnitelman, joka täyttää ison kasan vaatimuksia.
.png)