Lifecycle
Strategy & Planning
5 controls apply at this stage.
- directive
AI-CTRL-001
AI System Inventory and Classification
Maintain a complete, current, and classified inventory of all AI systems in development, deployment, and decommissioning to enable risk-based governance.
GovernanceISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +3v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-004
Third-Party AI Vendor Due Diligence
Ensure that third-party AI products and AI-enabled services are subject to risk-based due diligence covering data handling, model provenance, security testing, incident response, compliance posture, and contractual safeguards before procurement and on an ongoing basis.
Third-Party AIISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +4v1.0.0 Reviewed 2026-05-01 - directive
AI-CTRL-005
AI Risk Assessment and Impact Assessment
Ensure that each AI system is subject to a documented risk assessment and AI System Impact Assessment (AIIA) aligned with ISO/IEC 23894 and ISO/IEC 42005, completed prior to production deployment and refreshed on material change or annually.
AI Risk ManagementISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +3v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-006
Human-in-the-Loop Design for High-Risk Decisions
Ensure that AI systems producing decisions with legal or similarly significant effects on individuals incorporate meaningful human oversight in the decision flow, with documented design, training, and audit trails.
Human OversightISO 42001 NIST AI RMF EU AI Act OWASP Agentic Top 10 +2v1.0.0 Reviewed 2026-05-01 - directive
AI-CTRL-016
AI Acceptable Use Policy and User Training
Maintain a published, enforceable AI Acceptable Use Policy and deliver role-appropriate AI literacy training to employees, contractors, and other authorized users.
GovernanceISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +3v1.0.0 Reviewed 2026-05-01