{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"AI Governance","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AI-01","description":"Establish a management-approved AI policy that sets principles and requirements for developing and using AI systems, and keep it demonstrably consistent with related organizational policies such as security, privacy, and ethics. Review the policy at planned intervals and upon significant regulatory or technology change, recording review outcomes and revisions. Publish the current version to all relevant personnel and retain prior versions as evidence.","details":{"control_category":"administrative","control_type":"preventive","domain":"AI Governance","guidance":[],"members":[{"control_id":"A.2.2","coverage":"full","framework":"iso-42001","relationship":"superset_of"},{"control_id":"A.2.3","coverage":"full","framework":"iso-42001","relationship":"superset_of"},{"control_id":"A.2.4","coverage":"full","framework":"iso-42001","relationship":"superset_of"},{"control_id":"E008","coverage":"partial","delta":"periodic internal review of the AI control set and operating processes for continued effectiveness, beyond review of the policy text","framework":"aiuc-1","relationship":"intersects_with"}],"statement":"Establish a management-approved AI policy that sets principles and requirements for developing and using AI systems, and keep it demonstrably consistent with related organizational policies such as security, privacy, and ethics. Review the policy at planned intervals and upon significant regulatory or technology change, recording review outcomes and revisions. Publish the current version to all relevant personnel and retain prior versions as evidence.","title":"Maintain and periodically review the AI policy","unified_id":"UC-AI-01"},"id":"uc:UC-AI-01","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AI-01","sourceIds":["aiuc-1","iso-42001"],"sourceUrl":null,"title":"UC-AI-01 — Maintain and periodically review the AI policy","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:044870bb9f8c8f4641da1e572d13f41f15f0c7f82e9eaadb79fe7885da37e658","properties":{"control_id":"E008","coverage":"partial","delta":"periodic internal review of the AI control set and operating processes for continued effectiveness, beyond review of the policy text","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-01-156cdd4f.json","sourceId":"uc:UC-AI-01","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-e008-c8f7f0e4.json","targetId":"ctrl:aiuc-1:E008","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:07dc1fe53b324044692765d5bf12dc89ca7588ba81609242e46b5ab607f3d645","properties":{},"sourceDetailPath":"/data/v1/records/wf-g31-74d18d48.json","sourceId":"wf:G31","targetDetailPath":"/data/v1/records/uc-uc-ai-01-156cdd4f.json","targetId":"uc:UC-AI-01","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0cf61310a09241029e53a163563d2ad6af0b5363f22cc6c29a5cc0c3d65cf1fa","properties":{"rationale":"The AI policy imposes ethics/responsible-use diligence on AI adoption (one named facet), but does not operate against innovation shortfall, competitiveness loss, or failed technology bets; a governance hook, not the operative defense.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-01-156cdd4f.json","sourceId":"uc:UC-AI-01","targetDetailPath":"/data/v1/records/risk-strategic-innovation-emerging-tech-025a931b.json","targetId":"risk:strategic-innovation-emerging-tech","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:17cd20e62434962680b0e52ea6fa41185fa884b512aa180abac52f6b35dd387b","properties":{"control_id":"A.2.4","coverage":"full","delta":null,"framework":"iso-42001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2023"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-01-156cdd4f.json","sourceId":"uc:UC-AI-01","targetDetailPath":"/data/v1/records/ctrl-iso-42001-a-2-4-59052a56.json","targetId":"ctrl:iso-42001:A.2.4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:212cd97aefe22e3c0ab6a542aea9267aa78a27146298405a75976ad618036db8","properties":{"control_id":"A.2.2","coverage":"full","delta":null,"framework":"iso-42001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2023"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-01-156cdd4f.json","sourceId":"uc:UC-AI-01","targetDetailPath":"/data/v1/records/ctrl-iso-42001-a-2-2-dbf7432d.json","targetId":"ctrl:iso-42001:A.2.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:27b5f98176d788667c086a4ea8478dd90051bd23ebebca44725bc9f086f28e74","properties":{"control_id":"A.2.3","coverage":"full","delta":null,"framework":"iso-42001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2023"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-01-156cdd4f.json","sourceId":"uc:UC-AI-01","targetDetailPath":"/data/v1/records/ctrl-iso-42001-a-2-3-b0138cc0.json","targetId":"ctrl:iso-42001:A.2.3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:36c11737e5cecea0df0af2a97a7f9bc06f14145b57d641d7588a86c1b957afcb","properties":{},"sourceDetailPath":"/data/v1/records/wf-d59-b3ddf606.json","sourceId":"wf:D59","targetDetailPath":"/data/v1/records/uc-uc-ai-01-156cdd4f.json","targetId":"uc:UC-AI-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5267162df2e31d7b15e365101807288dd2bb43c43c3839f4d1e0d4d549206f9e","properties":{"rationale":"A management-approved AI policy sets governance expectations and evidences due diligence, but the operative accountability defense is role/owner assignment (UC-02/UC-13); the policy contributes rather than closing the responsibility gap.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-01-156cdd4f.json","sourceId":"uc:UC-AI-01","targetDetailPath":"/data/v1/records/risk-ai-accountability-liability-193b3f72.json","targetId":"risk:ai-accountability-liability","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:74d1fb5491627884c4399a634058ee706707c76277b8a705024a7c42c3540f59","properties":{"rationale":"Policy principles mandate lawful/responsible use, framing the prohibition-screening actually operated by UC-12.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-01-156cdd4f.json","sourceId":"uc:UC-AI-01","targetDetailPath":"/data/v1/records/risk-ai-prohibited-practices-daf993e5.json","targetId":"risk:ai-prohibited-practices","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d278bbab6cf68439fbbd4eca4dd021ddd91f6a91a354d60b97cdb258726e86b4","properties":{},"sourceDetailPath":"/data/v1/records/wf-g1-14bc355c.json","sourceId":"wf:G1","targetDetailPath":"/data/v1/records/uc-uc-ai-01-156cdd4f.json","targetId":"uc:UC-AI-01","type":"oversees"}],"schemaVersion":1}
