The organization must establish a comprehensive framework to plan, implement, and control all processes within its AI Management System (AIMS). This ensures that the actions identified during the planning and risk assessment phase are effectively carried out.
This operational framework must include:
- Defining clear criteria for each process (e.g., for AI system development, usage, and monitoring) to ensure consistent execution.
- Implementing the specific controls identified in the organization's risk treatment plan. The controls listed in Annex A of the standard should be used as a reference.
- Continuously monitoring the performance of these controls to ensure they are effective and considering corrective actions if they are not achieving the desired outcomes.
- A formal process for managing planned changes and for reviewing and mitigating the adverse effects of any unplanned changes.
- A method for controlling any relevant externally provided processes, products, or services (e.g., third-party AI models, data providers, cloud services).
Throughout this entire process, the organization must maintain sufficient documented information (records) to provide evidence that its operational processes have been carried out as planned.