AIG-02AI and Automated Decisions

AI risk assessed before deployment

AI systems are assessed for harm, bias, robustness and transparency before use, and the assessment is revisited on change.

Why it exists

The cost of a bad model is paid by people outside the room.

What usually proves it

Assessment records, bias testing, sign-off before deployment.

Smaller organizations

One assessment page per model, honestly completed.

Mapped to

  • Deliberately absentSOC 2 Trust Services Criteria — No AI-specific criteria.
  • Deliberately absentISO/IEC 27001 Annex A — Not addressed in Annex A.
  • Partially addressedNIST Cybersecurity Framework · ID.RA-01 — Through risk identification.
  • Deliberately absentPCI DSS — Out of scope.
  • Deliberately absentHIPAA Security Rule — Out of scope.
  • Partially addressedGDPR · Art. 35 — DPIA where processing is high risk.
  • Fully addressedEU AI Act · Art. 9, 27
  • Fully addressedNIST AI Risk Management Framework · MEASURE 2.1