AIG-01AI and Automated Decisions

AI system inventory

AI and automated decision systems in use are inventoried with purpose, owner, data and risk classification.

Why it exists

You cannot govern models you have not listed, including the ones staff adopted quietly.

What usually proves it

AI inventory, classification records, owner assignment.

Smaller organizations

One list including the tools people already use.

Mapped to

  • Deliberately absentSOC 2 Trust Services Criteria — No AI-specific criteria; AI systems are treated as any other system.
  • Deliberately absentISO/IEC 27001 Annex A — Annex A is technology-neutral; ISO/IEC 42001 addresses AI management systems instead.
  • Partially addressedNIST Cybersecurity Framework · ID.AM-01 — Through asset inventory.
  • Deliberately absentPCI DSS — Out of scope.
  • Deliberately absentHIPAA Security Rule — Out of scope.
  • Partially addressedGDPR · Art. 22, 30 — Automated decision-making records where applicable.
  • Fully addressedEU AI Act · Art. 6, 49
  • Fully addressedNIST AI Risk Management Framework · MAP 1.1