ISO/IEC 42001:2023 箇条 6.1.3

AIリスク対応

AI risk treatment

要求事項 計画

規格の記載(原文と日本語訳)

Clause 6.1.3

Taking the AI risk assessment results into account, the organization shall define an AI risk treatment process to: a) select appropriate AI risk treatment options; b) determine all controls that are necessary to implement the AI risk treatment options chosen and compare the controls with those in Annex A to verify that no necessary controls have been omitted; c) consider the controls from Annex A that are relevant for the implementation of the AI risk treatment options; d) identify if additional controls are necessary beyond those in Annex A in order to implement all risk treatment options; e) consider the guidance in Annex B for the implementation of controls determined in b) and c); f) produce a statement of applicability that contains the necessary controls [see b), c) and d)] and provide justification for inclusion and exclusion of controls. Justification for exclusion can include where the controls are not deemed necessary by the risk assessment and where they are not required by (or are subject to exceptions under) applicable external requirements; g) formulate an AI risk treatment plan.
日本語訳AIリスクアセスメントの結果を考慮して、組織は、次の事項を行うためのAIリスク対応のプロセスを定めなければならない。a) 適切なAIリスク対応の選択肢を選定する。b) 選定したAIリスク対応の選択肢の実施に必要な全ての管理策を決定し、それらを附属書Aの管理策と比較して、必要な管理策が見落とされていないことを検証する。c) AIリスク対応の選択肢の実施に関連する附属書Aの管理策を考慮する。d) 全てのリスク対応の選択肢を実施するために、附属書Aの管理策以外の追加の管理策が必要かどうかを特定する。e) b)及びc)で決定した管理策の実施にあたって、附属書Bの手引を考慮する。f) 必要な管理策[b)、c)及びd)参照]を含む適用宣言書を作成し、管理策を含めた理由及び除外した理由を示す。除外の正当な理由には、リスクアセスメントによって管理策が必要と判断されない場合や、適用される外部要求事項によって要求されない(又は例外の対象となる)場合が含まれ得る。g) AIリスク対応計画を策定する。

Clause 6.1.3

The organization shall obtain approval from the designated management for the AI risk treatment plan and for acceptance of the residual AI risks. The necessary controls shall be: aligned to the objectives in 6.2; available as documented information; communicated within the organization; available to interested parties, as appropriate. The organization shall retain documented information about the AI risk treatment process.
日本語訳組織は、AIリスク対応計画及び残留AIリスクの受容について、指名された管理層の承認を得なければならない。必要な管理策は、6.2の目的と整合し、文書化した情報として利用可能であり、組織内に伝達され、必要に応じて利害関係者が入手可能でなければならない。組織は、AIリスク対応のプロセスについての文書化した情報を保持しなければならない。

原文は参考サイト(WatchDog Security GRC Wiki / Control Stack)に引用掲載されたものです。日本語訳は本サイトによる非公式訳です。

わかりやすく言うと

リスクへの対応策(低減・回避・移転・受容)を選び、附属書Aと突き合わせて必要な管理策を決め、適用宣言書(SoA)にまとめます。ISO 27001と同じ構造です。

  • 附属書A全38管理策について採否と理由をSoAに記載する
  • 残留リスクの受容をリスクオーナーが承認する

対応する附属書Aの管理策 対応表で見る ›

この箇条は附属書A全体と照合します(適用宣言書の作成)。

関連する項目

関連する用語 用語集 ›