Skip to content

Latest commit

 

History

History
170 lines (125 loc) · 6.71 KB

File metadata and controls

170 lines (125 loc) · 6.71 KB

ISO 42001 Reference Card: Clause 8 — Operation


Purpose

Clause 8 is where the AIMS moves from planning into controlled operation. It requires the organisation to operate the processes needed to meet AIMS requirements, manage AI risk, perform AI system impact assessment and control operational change.

This clause is the practical delivery layer of ISO 42001. It is where AI governance is applied to real AI systems, real users, real data and real organisational decisions.


Sub-clauses

8.1 Operational planning and control

The organisation must plan, implement and control the processes needed to meet AIMS requirements and implement the actions identified in Clause 6.

Operational control means the organisation has defined how AI governance activities are performed, who performs them, what evidence is retained and how deviations are handled.

Operational controls may include:

  • AI system inventory management
  • AI risk assessment before development, deployment or significant change
  • Approval gates for AI systems
  • Data quality and data governance checks
  • Testing, validation and evaluation processes
  • Human oversight arrangements
  • Supplier and third-party AI due diligence
  • User information and transparency processes
  • Monitoring of deployed AI systems
  • Incident, issue and escalation processes
  • Retirement or decommissioning controls

Operational planning should define:

Planning area Example evidence
Process criteria Standards, procedures, approval rules
Control implementation Workflows, checklists, system records
Documented information Risk assessments, approvals, test results
Change control Change records, impact reviews, approvals
Outsourced processes Supplier assessments, contracts, monitoring

Operational control should apply across the AI lifecycle, not only at the point of deployment. Many AI risks are created during design, data selection, development, procurement or configuration.


8.2 AI risk assessment

The organisation must perform AI risk assessments at planned intervals and when significant changes occur.

AI risk assessment identifies, analyses and evaluates risks associated with AI systems and the AIMS. It should consider the intended use of AI systems, reasonably foreseeable misuse, affected parties and potential consequences.

AI risk assessment should consider:

  • The purpose and context of the AI system
  • Who may be affected by the system
  • Potential harms to individuals, groups, society or the organisation
  • Data quality, representativeness and suitability
  • Bias, fairness and discrimination risks
  • Accuracy, robustness and reliability
  • Human oversight and decision authority
  • Security and misuse risks
  • Transparency and explainability needs
  • Legal, regulatory and contractual obligations
  • Third-party dependencies

Risk assessment outputs should include:

  • Identified risks
  • Risk owners
  • Assessment of likelihood and impact
  • Treatment decisions
  • Required controls
  • Residual risk evaluation
  • Approval or escalation decisions
  • Records retained as documented information

The assessment method should be repeatable and proportionate. Higher-risk AI systems need deeper analysis, stronger controls and more senior approval.


8.3 AI risk treatment

The organisation must implement risk treatment actions based on the AI risk assessment.

Risk treatment is the step where assessment becomes action. It determines which controls will be used to reduce, avoid, transfer or accept AI-related risks.

Risk treatment options may include:

  • Avoiding a high-risk AI use case
  • Changing system design or intended use
  • Adding human oversight or approval steps
  • Improving data quality or data controls
  • Applying testing, validation or monitoring controls
  • Restricting access or use
  • Adding transparency or user information
  • Strengthening supplier contractual requirements
  • Escalating residual risk for senior acceptance

Good risk treatment evidence shows:

  • The link between risk and treatment action
  • The control owner
  • Implementation status
  • Evidence of implementation
  • How residual risk is evaluated
  • Who accepted any remaining risk

A treatment plan is not enough on its own. Auditors will look for evidence that controls are implemented and operating.


8.4 AI system impact assessment

The organisation must assess the potential consequences of AI systems for individuals, groups and society where relevant.

AI system impact assessment is broader than organisational risk. It asks who may be affected, how they may be affected and whether the AI system could create or amplify harm.

Impact assessment should consider:

  • The intended purpose of the AI system
  • The deployment context
  • Affected individuals or groups
  • Potential benefits and adverse impacts
  • Fairness, accessibility and inclusion concerns
  • Privacy and data protection impacts
  • Human rights and societal impacts where relevant
  • Transparency and contestability needs
  • Dependence on automated outputs
  • The effectiveness of mitigation measures

Examples of impact questions:

  • Could the AI system affect access to important services or opportunities?
  • Could errors create material harm?
  • Could some groups be affected differently from others?
  • Can affected people understand, challenge or seek review of outcomes?
  • Is there meaningful human oversight?
  • Are benefits and risks proportionate to the intended use?

Impact assessment should be revisited when the system, context, data, users or intended use changes.


Common audit questions

  • What operational processes control AI system development, deployment and use?
  • How does the organisation maintain an inventory of in-scope AI systems?
  • When are AI risk assessments required, and who approves them?
  • How are risk treatment actions selected, implemented and tracked?
  • How are AI system impact assessments performed and reviewed?
  • How are outsourced or third-party AI processes controlled?
  • What evidence shows that operational controls are followed in practice?

Connections to other clauses

Clause 8 output Used by
Operational processes Clause 9 (monitoring, audit), Clause 10 (improvement)
AI risk assessments Annex A control selection, Statement of Applicability
Risk treatment plans Clause 6 objectives, Clause 9 performance evaluation
AI system impact assessments Interested party management, transparency and oversight controls
Operational records Certification audit evidence

Key message

Clause 8 is where AI governance is operated. It turns risks, objectives and controls into day-to-day processes for real AI systems.


Reference catalogue entry — use this as source material for matching funny and professional infographic cards.