unified
UC-AI-01 — Maintain and periodically review the AI policy
Establish a management-approved AI policy that sets principles and requirements for developing and using AI systems, and keep it demonstrably consistent with related organizational policies such as security, privacy, and ethics. Review the policy at planned intervals and upon significant regulatory or technology change, recording review outcomes and revisions. Publish the current version to all relevant personnel and retain prior versions as evidence.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- AI Governance
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-AI-01
- title
- Maintain and periodically review the AI policy
- statement
- Establish a management-approved AI policy that sets principles and requirements for developing and using AI systems, and keep it demonstrably consistent with related organizational policies such as security, privacy, and ethics. Review the policy at planned intervals and upon significant regulatory or technology change, recording review outcomes and revisions. Publish the current version to all relevant personnel and retain prior versions as evidence.
- domain
- AI Governance
- control_type
- preventive
- control_category
- administrative
- members
- framework
- iso-42001
- control_id
- A.2.2
- coverage
- full
- relationship
- superset_of
- framework
- iso-42001
- control_id
- A.2.3
- coverage
- full
- relationship
- superset_of
- framework
- iso-42001
- control_id
- A.2.4
- coverage
- full
- relationship
- superset_of
- framework
- aiuc-1
- control_id
- E008
- coverage
- partial
- delta
- periodic internal review of the AI control set and operating processes for continued effectiveness, beyond review of the policy text
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-AI-01 — Maintain and periodically review the AI policy maps_to E008 — Review internal processes
- framework
- aiuc-1
- control_id
- E008
- coverage
- partial
- delta
- periodic internal review of the AI control set and operating processes for continued effectiveness, beyond review of the policy text
- relationship
- intersects_with
- source_version
- July 15, 2026 release (quarterly update cadence)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- AI Governance Framework, Roles & Obligations Review operates UC-AI-01 — Maintain and periodically review the AI policy
- UC-AI-01 — Maintain and periodically review the AI policy mitigates Innovation shortfall and emerging-technology adoption risk
- strength
- related
- rationale
- The AI policy imposes ethics/responsible-use diligence on AI adoption (one named facet), but does not operate against innovation shortfall, competitiveness loss, or failed technology bets; a governance hook, not the operative defense.
- UC-AI-01 — Maintain and periodically review the AI policy maps_to A.2.4 — Review of the AI policy
- framework
- iso-42001
- control_id
- A.2.4
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2023
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AI-01 — Maintain and periodically review the AI policy maps_to A.2.2 — AI policy
- framework
- iso-42001
- control_id
- A.2.2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2023
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AI-01 — Maintain and periodically review the AI policy maps_to A.2.3 — Alignment with other organizational policies
- framework
- iso-42001
- control_id
- A.2.3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2023
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO/IEC 42001 AI Management System Internal Audit tests UC-AI-01 — Maintain and periodically review the AI policy
- UC-AI-01 — Maintain and periodically review the AI policy mitigates AI accountability gaps and organizational liability
- strength
- related
- rationale
- A management-approved AI policy sets governance expectations and evidences due diligence, but the operative accountability defense is role/owner assignment (UC-02/UC-13); the policy contributes rather than closing the responsibility gap.
- UC-AI-01 — Maintain and periodically review the AI policy mitigates Deployment of prohibited AI practices (EU AI Act Art.5)
- strength
- related
- rationale
- Policy principles mandate lawful/responsible use, framing the prohibition-screening actually operated by UC-12.
- AI Governance & Risk/Impact Assessment oversees UC-AI-01 — Maintain and periodically review the AI policy