ISO/IEC 42001:2023 箇条 8.3
AIリスク対応
AI risk treatment
要求事項
運用
規格の記載(原文と日本語訳)
Clause 8.3
The organization shall implement the AI risk treatment plan according to 6.1.3 and verify its effectiveness. When risk assessments identify new risks that require treatment, a risk treatment process in accordance with 6.1.3 shall be performed for these risks. When risk treatment options as defined by the risk treatment plan are not effective, these treatment options shall be reviewed and revalidated following the risk treatment process according to 6.1.3 and the risk treatment plan shall be updated. The organization shall retain documented information of the results of all AI risk treatments.
日本語訳組織は、6.1.3に従ってAIリスク対応計画を実施し、その有効性を検証しなければならない。リスクアセスメントによって対応が必要な新たなリスクが特定された場合には、それらのリスクに対して6.1.3に従ったリスク対応のプロセスを実施しなければならない。リスク対応計画で定めたリスク対応の選択肢が有効でない場合には、6.1.3に従ったリスク対応のプロセスに沿ってそれらの選択肢をレビューし、再度妥当性を確認し、リスク対応計画を更新しなければならない。組織は、全てのAIリスク対応の結果の文書化した情報を保持しなければならない。
原文は参考サイト(WatchDog Security GRC Wiki / Control Stack)に引用掲載されたものです。日本語訳は本サイトによる非公式訳です。
わかりやすく言うと
リスク対応計画を実行し、本当に効いているかを検証します。効いていなければ見直します。
- 対応策ごとに有効性指標と確認時期を設定する
- 有効性の検証が行われているか
- リスク対応の実施・有効性確認記録