top of page

IAPP AIGP, study guide domain ii

  • Writer: Ley Muller
    Ley Muller
  • Aug 21
  • 19 min read

Domain ii: Understanding Laws, Standards, Frameworks Apply to AI Systems


Domain II.a How existing data privacy laws apply to AI

 

Relevant privacy laws concerning the use of data.

  •  The Federal (US) Privacy Act of 1974 and the E-Government Act of 2002 require agencies to address the privacy implications of any system that collects identifiable information on the public

  •  The Health Insurance Portability and Accounting Act (HIPAA)= health

  •  Health Insurance Technology for Economic and Clinical Health Act of 2009 (HITECH), which increased penalties under HIPAA and provided greater access rights to individuals.

  •  The Family Educational Rights and Privacy Act (FERPA) = student education

  •  Protection of Pupil Rights Amendment of 1978 (PPRA) = student info

  •  State privacy laws

    •  CCPA/CPRA (CAlifornia!!),

      •  Any AI tool used in customer-facing apps or analytics must honor these rights, or businesses risk lawsuits and fine:.

        •  Informing users about what personal data is collected and why

        •  Allowing users to opt out of data sharing or sales

        •  Giving individuals the right to request data deletion

        •  Maintaining clear privacy notices

    •  Virginia Consumer Data Protection Act (VCDPA), CPA, CTDPA, Montana’s Consumer Data Privacy Act, Delaware Personal Data Privacy Act, Utah Consumer Privacy Act (UCPA), Oregon Consumer Privacy Act (OCPA), Iowa’s Consumer Data Protection Act (ICDPA), New Jersey Data Privacy Act (NJDPA), Indiana Consumer Data Protection Act, Tennessee Information Protection Act, Texas Data Privacy and Security Act (TDPSA)


Understanding key GDPR intersections

  • Data controller

    •  Has primary obligations to data subjects — they must uphold subjects’ rights, such as allow Data Subject Access Requests (DSAR)

    •  Must conduct Data Protection Impact Assessment (DPIA) / or Privacy Impact Assessment (PIA) if outside the GDPR

      •  DPIA = risk assessment of a data processing activity, for the individuals whose data it is

      •  PIA = slightly broader and more flexible. US, Canada, UK

    •  Must ensure data processor compliance.

    •  answer directly to supervisory authorities, and while audits extend to their processors, controllers face primary scrutiny.

    •  Must establish a lawful basis for processing personal data (e.g., consent, contractual necessity) and communicate this to data subjects.

  •  Data processor

    •  Person separate from the controller, who processes personal data on its behalf.

    •  must ensure that persons authorised to process the personal data have committed themselves to confidentiality (Article 28(3));

    •  must maintain a record of all categories of processing activities

    •  must implement appropriate technical and organisational measures

  • Understand automated decision making, DPIA, anonymization, and how they relate to AI systems

    •  AI systems processes data - often personal data

    •  “The data subject shall have the right NOT to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.” 

      •  One effective control is to  establish a human-in-the-loop procedure = to ensure human oversight and the ability to contest decisions.

      •  UNLESS they consent

    •  “the data controller shall implement suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision.”

    •  Creating a dataset to train an AI system may involve the use of PII, i.e. the proccessing of personal data.  This can lead to “high risks” to people’s rights and freedoms. A DPIA is mandatory in this scenario. This is different than an AI Conformity assessment.

      •  Anonymizing the training data can help to mitigate concerns by separating the information from the person.

  •  Purpose limitation

    •  =  requires that personal data be collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes.

  •  Data minization

    •   mandates that personal data collected should be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed

  •  GDPR data categories

    •  Personal data

      •  all information that can directly or indirectly identify an individual.

    •  Special categories of personal data = must take extra precautions.

      •  E.g. biometric data (facial images, voiceprints, iris scans, keystroke patterns) when used for the purpose of uniquely identifying individuals

      •  Political views

      •  Religion

      •  Race

      •  Sexual orientation

      •  Union membership

      •  Health  -but health data CAN be processed by healht insurers and health crae professionals, with consent

    •  Anonymous data

      •  GDPR doesn’t apply

    •  Pseudoanonymized data

      •  GDPR still applies

      •  People can be identified via a key

      •  This is different under US law! Psuedoanonymization is enough


Understand the intersection between requirements for AI Conformity Assessments and DPIAs.

  • BOTH involve risk assessment and mitigation plans

  •  “Before a high-risk AI system can be brought into the market, a Conformity Assessment (CA) should be made to ensure compliance with the AI Act

  •  Regarding personal data

    •  in the AI Act, the GDPR is explicitly mentioned when it comes to processing personal data], and when performing a DPIA is required.

    •  This means there will be an overlap between these two assessments as a high-risk AI system would almost automatically include high risk processing under the GDPR” 

    •  But a high-risk AI system doesn’t have to involve personal data - in which case a DPIA Wouldn’t be involved

  •  “A Conformity Assessment (CA) is focused on ensuring compliance with specific legal requirements, which are considered mitigation measures for high-risk systems.

    •  The main goal of CA is to guarantee adherence to the mitigation measures or requirements mandated by the law.

    •  An approved CA = required to enter the market.” 

  •  “A DPIA has a slightly different purpose. it serves as a tool for accountability by requiring controllers to assess and make decisions based on risks. It also mandates reporting on the decision-making process.

    •  The primary objective == hold controllers accountable for their actions and ensure more effective protection of individuals’ rights.

    •  The controller is ‘free’ to decide if and how it will mitigate risk.” 

  •  Whenever a high-risk AI system involves the processing of personal data, a DPIA will almost certainly be required.

    •  Both processes involve assessing risks related to specific systems and have distinct sets of requirements. To prevent redundant work or conflicting conclusions, it is probable that the CA can form the foundation for the DPIA of the controller.

 If the provider also operates as a controller under the GDPR, then both the DPIA and CA will be carried out by the same entity, reinforcing each other.”


 GDPR requirements for human supervision of algorithmic systems.

  • Users have the right to:

    •  Know about the automated decision;

    •  Understand the decision-making logic;

    •  Challenge the decision and share their perspective; and

    •  Request human intervention for decision review.

  • This is why data controllers must plan for human intervention, allowing individuals to review their situation, understand the decision, and contest it. 

  • Understand an individual’s right to meaningful information about the logic of AI systems.

    •  The existence of automated decision making, including profiling.

    •  “Meaningful information about the logic involved.”  Article 22 of the GDPR

      •  should be understood as information around the algorithmic method used rather than an explanation about the rationale of an automated decision.

      •  For example, if a loan application is refused, Article 22 may require the controller to provide information about the input data related to the individual and the general parameters set in the algorithm that enabled the automated decision.

      •  But Article 22 would not require an explanation around the source code, or how and why that specific decision was made.” 

    •  “The significance and the envisaged consequences of such processing” for the individual.

  •  "The privacy notice must be updated to explain the nature of automated processing, the logic involved, and the significance and consequences for the data subject.”


Domain II.b How other types of existing laws apply to AI 

Understand the existing laws that interact with AI use -

  •  IPR,

  •  non-discrimination,

  •  consumer protection,

  •  product liability

  • Know the consumer protection laws that address unfair and deceptive practices.

    •  In general: targeted advertising & recommendations are accepted, as long as they comply with transparency and consent requirements

    •  regulated under consumer protection laws:

      •  Deceptive claims

      •  Biased financial decisions

      •  Unauthorized data use

    •  Federal Trade Commission (FTC) Act (US) (Wheeler-Lea Act of 1938)

    •  EU Directive on unfair commercial practices from 2005 

    •  Children's Online Privacy Protection Act (COPPA) = governs the collection of information about minors

    •  Gramm Leach Bliley Act (GLBA) = banks and financial institutions

    •  Telemarketing Sales Rule (TSR), Telephone Consumer Protection Act of 1991, and the Do-Not-Call Registry

    •  Junk Fax Protection Act of 2005 (JFPA)

    •  Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003 (CAN-SPAM) and the Wireless Domain Registry

    •  Telecommunications Act of 1996 and Customer Proprietary Network Information (CPNI)

    •  Cable Communications Policy Act of 1984

    •  Video Privacy Protection Act of 1998 (VPPA) and Video Privacy Protection Act Amendments of 2012

    •  Driver's Privacy Protection Act (DPPA)

  • relevant non-discrimination laws (credit, employment, insurance, housing, etc.).

    •  The Fair Credit Reporting Act (FCRA), which regulates the collection and use of credit information.  regulates "consumer reporting agencies" and people who use the reports generated by consumer reporting agencies.

      •  Crucially, a generative AI service potentially could meet the definition of "consumer reporting agency" if the service regularly produces reports about individuals' "character, general reputation, personal characteristics, or mode of living" and these reports are used for employment purposes.”  

    •  Confidentiality of Substance Use Disorder Patient Records Rule Prohibits patient information helping criminal charges

    •  Fair and Accurate Credit Transactions Act of 2009 (FACTA)

      •  contains protections against identity theft, “red flags” rules

    •  Privacy Protection Act of 1980 (PPA)

      •  The PPA requires law enforcement to obtain a subpoena in order to obtain First Amendment- protected materials

    •  Title VII of the Civil Rights Act of 1964 prohibits employment discrimination on the basis of race, color, religion, sex, or national origin

    •  Title I of the Americans With Disabilities Act (“ADA”) prohibits employment discrimination against “qualified” individuals with disabilities

    •  Genetic Information Nondiscrimination Act of 2008

    •  Illinois Artificial Intelligence Video Interview Act – Requires that any employer relying on AI technology to analyze a screening interview must provide information to candidates and obtain consent; must also report demographic data to the state to analyze bias

    •  Maryland HB 1202 – Prohibits the use of facial recognition technology in the hiring process without consent of applicant

    •  NYC Regulation – A bias audit must be conducted on any use of automated employment decision tools requires; notice must be provided to applicants and alternative selection process must be provided

    •  The Wiretap Act

  • Know relevant product safety laws.

    •  Consumer Product Safety Act (CPSA) in 1972 for the purposes of protecting consumers against the risk of injury due to consumer products, enabling consumers to evaluate product safety, establishing consistent safety standards, and promoting research into the causes and prevention of injuries and deaths associated with unsafe products. 

    •  EU - The General Product Safety Regulation requires that all consumer products on the EU markets are safe and it establishes specific obligations for businesses to ensure it. It applies to non-food products and to all sales channels. 

  •   relevant IP law.

    •  Most important for copyright = originality

    •  “U.S. Patent and Trademark Office (USPTO), U.S. Copyright Office, and courts have yet to fully establish clear guidelines concerning AI-created content or inventions. However, they generally recognize rights only for human authors and inventors.

    •  European Patent Office (EPO) and European Union Intellectual Property Office (EUIPO) have similar stances, though discussions are ongoing about potential changes.” 

  • Understand the basic requirements of the EU Digital Services Act (transparency of recommender systems). 

    •  The DSA imposes obligations on all information society services that offer an intermediary service to recipients who are located or established in the EU, regardless of whether that intermediary service provider is incorporated or located within the EU.

    •  Transparency obligations: Advertising, user profiling, and recommender systems

      •  Article 26 DSA, providers of online platforms must supply users with information relating to any online advertisements on its platform so that the recipients of the services can clearly identify that such information constitutes an advertisement.

        •  Targeted ads based on profiling using special category data or personal data of minors = prohibited by providers of online platforms

      •  Article 27DSA  requires providers of online platforms that use recommendation systems to set out in their T&Cs the main parameters they use for such systems, including any available options for recipients to modify or influence them. Under Article 38, VLOPs and VLOSEs must provide atleast one option (not based on profiling) for users to modify the parameters used.

  •  Understanding liability reform

    •  = =  the process of changing the legal rules and principles that govern the responsibility and accountability of parties who cause or contribute to damage or harm through AI systems.

    • Awareness of the reform of EU product liability law.

      •  Needs to be updated because the current directive does not adequately cover digital services and connected products.

      •  Article 4 of the proposed Directive brings software into the scope of EU product liability laws. Operating systems, firmware, computer programs and applications and AI systems are all expressly included (by Recital 12).

      •  Article 7 extends liability to manufacturers of defective components, distributors, fulfilment service providers and online platforms.

      •  Articles 8 and 9 provide a disclosure regime and set of rebuttable presumptions designed to assist claimants.

    • Understand the basics of the AI Product Liability Directive.

      •  “Complements the Artificial Intelligence Act by introducing a new liability regime that ensures legal certainty, enhances consumer trust in AI, and assists consumers’ liability claims for damage caused by AI-enabled products and services.It applies to AI systems that are available on the EU market, or operating within the EU market.” 

  •  US federal level

    •  EO14091= Further Advancing Racial Equity and Support for Underserved Communities Through the Federal Government (from 2023… rescinded in 2025)

      •  required government institutions to assess the impact of AI-driven decisions on marginalized communities, ensuring these systems did not reinforce systemic bias.

      •  The term “algorithmic discrimination” refers to instances when automated systems contribute to unjustified different treatment or impacts disfavoring people based on their actual or perceived race, color, ethnicity, sex (including based on pregnancy, childbirth, and related conditions; gender identity; intersex status; and sexual orientation), religion, age, national origin, limited English proficiency, disability, veteran status, genetic information, or any other classification protected by law.

    •  Also revoked in 2025: Executive Order 14110: “The Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence - risk management and oversight


Domain II.c Existing and Emerging AI laws and standards

  

highest

Violations

Prohibited systems

35 million euro OR

  7% turnover

middle

Violations

high-risk

15 million euro OR

 3% turnover

lowest

Incorrect, incomplete, misleading info

7.5 mill euro OR

1% turnover

  •  All actors can get a penalty for non-compliance =  providers, deployers, importers, distributors, and notified bodies. 

  • Understand procedures for testing innovative AI and exemptions for research.

    •  An exception within the AI Act to process special categories of personal data to detect and correct bias within AI applies to providers of AI systems.

      •  “the AI Act's exception applies to developers and entities outsourcing the development of AI systems, for non-private use. The exception does not  seem to apply to organizations renting a fully developed AI system as a service, for example.”

  • Understand transparency requirements

    •  PROVIDERS must register High-risk AI systems  in an EU-wide public database

    •  obligation to warn people that they are interacting with an AI system.


 Understand other emerging global laws

  • Understand the key components of Canada’s AIDA, Artificial Intelligence and Data Act (C-27). 

    •  “AIDA provides a definition of “person” that includes trusts, partnerships, unincorporated associations and any other legal entity, and further clarifies when a such a “person” will be considered responsible for an AI system. A person becomes a “person responsible” for an AI system if they design, develop, make available for use, or manage the operation of an AI system in the course of international or interprovincial trade and commerce.”

      •  Responsibilities include:

        •  ensuring the anonymization of data

        •  conducting assessments to determine whether an AI system is “high-impact,”

        •  establishing measures related to risks

        •  monitoring and keeping records on risk mitigation

        •  requirements for organizations to publish a plain-language description of all high-impact AI systems on a public website.

      •  If adopted, will replace PIPEDA

    •  Minister of Innovation, Science and Industry must be notified about a high-impact AI system upon initial deployment


Understand the key components of U.S. state laws that govern the use of AI.

  •  California, Connecticut, Vermont, Hawaii, Illinois, New York, Oklahoma, Rhode Island (lost steam), and Washington (lost steam)

  •  “Provisions found in most of these bills require regular impact assessments of AI tools to ensure against discrimination; disclosure of such assessments to government agencies; internal policies, programs and safeguards to prevent foreseeable risks from AI; accommodating requests to opt-out of being subject to AI tools; disclosure of the AI's use to affected persons; and an explanation of how the AI tool uses personal information and how risks of discrimination are being minimized”

  •  Automated employment decision tools- "predictive data analytics" used by employers to make employment decisions about hiring, firing, promotion and compensation.

    •  Illinois, Massachusetts, New Jersey, New York, Vermont

    •  “require employers to provide advance notice to and obtain consent from job applicants and employees who are subject to AEDTs, explain the qualifications and characteristics that AI will assess to candidates, and conduct and disclose regular impact assessments or bias audits of AI tools. Most of these bills, however, include carveouts for the use of AI when promoting diversity or affirmative action initiatives.”

  •  AI Bill of Rights

    •  “provide state residents the rights to know when they are interacting with AI, to know when their data is being used to inform AI, not to be discriminated against by the use of AI, to have agency over their personal data; to understand the outcomes of an AI system impacting them and to opt out of an AI system”

    •  Oklahoma and New York

  •  Working Group Bills

    •  “creating government commissions, agencies or working groups to study the implementation of AI technologies and develop recommendations for future regulation”

    •  Utah, Florida, Hawaii, Massachusetts


Understand the Cyberspace Administration of China’s draft regulations on generative AI. 

  •  apply to services offered to the public and NOT the use of genAI services by enterprises.”

  •  During development, genAI providers must:

    •  not generate illegal content such as false or harmful information;

    •  prevent the generation of discriminatory content;

    •  not use advantages in algorithms, data, or platforms where this leads to monopoly and unfair competitive behaviors;

    •  not infringe on others’ portrait rights, reputation rights, honor rights, privacy rights and personal information rights; and

    •   

    •  take effective measures based on service types to increase the transparency of generative AI services and the accuracy and reliability of generative AI content.

  •  re:  training data, generative AI service providers must:

    •  use data and foundation models from legitimate sources;

    •  not infringe others’ legally owned intellectual property;

    •  obtain personal data with consent or under situations prescribed by the law or administrative measures; and

    •  take effective measures to increase the quality of training data, their truthfulness, accuracy, objectivity and diversity.

  •  When providing, generative AI service providers bear cybersecurity obligations as online information content producers and personal information protection obligations as personal information handlers and must:

    •  enter into service agreements with registered generative AI service users which specify the rights and obligations of both parties;

    •  guide users on the legal use of generative AI technology and take effective measures to prevent users from over-reliance on or “addiction to” the generated AI service;

    •  not collect non-essential personal information, not illegally retain input information and usage records which can be used to identify a user and not illegally provide users’ input information and usage records to others;

    •   receive and settle data subjects’ requests;

    •  tag generated content such as photos and video as pursuant to the Administrative Provisions on Deep Synthesis of Internet-based Information Services (Deep Synthesis Provisions);

    •  if illegal content is discovered, take measures to stop the generation and transmission of and delete illegal content, take rectification measures such as model improvement, and report to the relevant competent authorities;

    •  where users are found to use generative AI services to conduct illegal activities, take measures to warn the user, or restrict, suspend or terminate the service, retain the records, and report to the relevant competent authorities; and

    •  establish a mechanism for receiving and handling users’ complaints.

  •  In relation to other legal obligations and enforcement supervision, generative AI service providers shall:

    •  if the generative AI service comes with a public opinion attribute or social mobilization ability, carry out a safety assessment obligation and (within ten working days from the date of provision of services) go through record-filing formalities pursuant to the Administrative Provisions on Algorithm Recommendation for Internet Information Services (Algorithm Provisions); and

    •  when the relevant competent authorities (e.g., the CAC) commence supervisory checks on the generative AI service, cooperate with them, explain the source, size and types of the training data, tagging rules and the mechanisms and principles of the algorithm and provide necessary technology and data, etc., for support and assistance.

  

 

Domain II.d Industry standards and tools that apply to AI


Understand the similarities and differences among the major risk management frameworks and standards

  • ISO 31000 Risk Management – Guidelines.

    •  “A management system is the framework of policies, processes and procedures employed by an organization to ensure that it can fulfill the tasks required to achieve its purpose and objectives.” 

    •  Governance and culture; strategy and objective-setting; performance; information, communications and reporting; and the review and revision of practices to enhance the performance of the organization.

    •  Emphasis on leadership endorsement and engagement, emphasis on organizational governance, emphasis on iterative nature of risk management (regularly updating processes and policies in response to new industry developments)

  • United States National Institute of Standards and Technology, AI Risk Management Framework (NIST AI RMF).

    •  Voluntarily used to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems.

    •  The framework breaks down the AI risk management process into four core functions: "govern," "map," "measure," and "manage”.

      •  Govern = cross-fitting, enables the other three functions

        •  establish a culture of risk management,

        •  define roles and responsibilities,

        •  develop and implement policies

        •  Aim = comprehensive guidance on structures, systems, processes, teams

      •  Map

        •  Understand where AI is operating

        •  Recognize context

        •  = identify and understand AI risks within specific ocntexts & within AI lifecycle. This enables negative risk prevention.

        •  Aim = introduce visibility, allow AI actors to see all parts of the process

      •  Measure

        •  = assess, analyze, track identified risks from MAP, to inform MANAGE

        •  inclu de Testing, performance measurement, benchmarking,e tc

      •  Manage

        •   = prioritize risks and take action to mitigate them

        •  Strategies to maximize AI benefits

        •  Third party AI risks and benefits

    •  seven “characteristics of trustworthy AI,” which include:

      •   valid and reliable,

      •  safe,

      •  secure and resilient,

      •  accountable and transparent,

      •  explainable and interpretable,

      •  privacy-enhanced, and

      •  fair with harmful biases managed.

  •  NIST ARIA = Assessing Risks and Impacts of AI program. Expands on AI RMF.

    •  assess the societal risks and impacts of AI systems (i.e., what happens when people interact with AI regularly in realistic settings).

    •  Classified as a testing, evaluation, validation and verification (TEVV) program, specifically within societal contexts after deployment.

      •  Pilot test is focused on LLMs, and 3 levels of testing: model testing, red-teaming, and field testing.

  • European Union proposal for a regulation laying down harmonized rules on AI (EU AIA). 

    •  A proposed European law on artificial intelligence (AI) – the first comprehensive law on AI by a major regulator anywhere

    •  The majority of obligations fall on providers (developers) of high-risk AI systems.

    •   Users are natural or legal persons that deploy an AI system in a professional capacity, not affected end-users.

  • Council of Europe Human Rights, Democracy, and the Rule of Law Assurance Framework for AI Systems (HUDERIA).

    •  Focus on risk and impact from the perspective of human rights, democracy,and rule of law

    •  based on Council of Europe (CoE) standards

    •  Four parts

      •  Context-based risk analysis

      •  Stakeholder engagement

      •  Risk and impact assessment

      •  Mitigation plan

  • IEEE 7000-21 Standard Model Process for Addressing Ethical Concerns during System Design

    •  Braid in ethical values to systems engineering design/development

    •  Make ethical values traceable. Operationalize ethics in system design.

    •  Leadership + engineering + stakeholders

    •  Relevant for all sizes and types of organizations, using their own life cycle models

  •  ISO 22989

    •  a common vocabulary for AI , to ensure consistency across other standards.

    •  Not a certifiable standard.

    •  Terminology baseline used by:

      •  ISO/IEC 23894 — AI risk management

      •  ISO/IEC 23053 — Framework for AI systems using machine learning

      •  ISO/IEC 42001 — Artificial Intelligence Management System (AIMS)

      •  ISO/IEC 24028 — Overview of trustworthiness in AI

      •  ISO/IEC 5259 (series) — Data quality for analytics and ML

      •  ISO/IEC/IEEE 29119-11 — Testing of AI-based systems

    •  Does  NOT say anything about third party procurement


Attribute

How it is addressed or framed in ISO 22989

Terms for performance consistency and dependable behavior across lifecycle phases

Concepts relating to harm, hazard, and safe operation of AI systems

Terminology linking security properties (confidentiality, integrity, availability) to AI contexts

Definitions around robustness to perturbations, uncertainty, and dataset shift

Concepts for recovery and continued operation under adverse conditions

Shared language for making AI system capabilities and limitations visible

Definitions for explainability/interpretability to support understanding of outputs

Roles and responsibilities, human oversight, assurance concepts

Terms for bias, fairness, and mitigation approaches

Concepts for data protection in AI lifecycles

Dataset, labeling, quality characteristics across training/validation/testing

Usability / human factors

Human-in/on/over-the-loop, human oversight terminology

Lifecycle and change-related terms that support maintainable operation

Terminology for artifacts, provenance, and evidence across the lifecycle

  

  • ISO 42001 AI Management System

    •  Structured framework to orgs to develop or deloy AI system

    •  Key components of an AI Management System include governance structures, risk management strategies, compliance protocols, and training programs to build competence among personnel involved in AI projects.

  • ISO 9001  quality management

    •  ISO/IEC 42001 builds on this by providing a framework to manage the quality and consistency of AI systems.

  • Similarly, ISO 27001 information security

    • ISO/IEC 42001 these principles to the unique security risks and data protection challenges of AI.

  • ISO 13485 sets quality in medical devices

    • ISO/IEC 42001 supports this by ensuring AI components meet high standards of safety and effectiveness.

  • ISO/IEC Guide 51 Safety aspects – guidelines for their inclusion in standards.

    •  “reducing risk that can arise in the use of products or systems, including use by vulnerable consumers. This Guide aims to reduce the risk arising from the design, production, distribution, use (including maintenance) and destruction or disposal of products or systems.” 

  •  ISO 42005 AI Impact Assessment

  • Singapore Model AI Governance Framework.  

    •  provides detailed and readily-implementable guidance to private sector organizations to address key ethical and governance issues when deploying AI solutions

    •  Decisions made by AI should be: EXPLAINABLE, TRANSPARENT & FAIR

    •  AI systems should be HUMAN-CENTRIC

    •  recommends several measures to promote the  responsible use of AI, such as determining the level of human involvement in decision-making, adapting governance structures, and establishing communications and collaboration among stakeholders

    •  9 dimensionsof governance to foster a trusted AI ecosystem

      •  Accountability

      •  Data quality

      •  Trusted dev and deployment (transparency)

      •  Incident reporting

      •  Testing and assurance (ideally third-party, external validation)

      •  Security

      •  Content provenance (transparency around origins)

      •  Safety and alignment R&D

      •  AI for public good


 
 
 

Comments


bottom of page