ISO/IEC 42001:2023 附属書 A.10.2
責任の割当て
Allocating responsibilities
管理策
第三者及び顧客との関係
規格の記載(原文と日本語訳)
Annex A.10.2
The organization shall ensure that responsibilities within their AI system life cycle are allocated between the organization, its partners, suppliers, customers and third parties.
日本語訳組織は、AIシステムのライフサイクルにおける責任が、組織、そのパートナー、供給者、顧客及び第三者の間で割り当てられることを確実にしなければならない。
Annex B.10.2(手引)
In an AI system life cycle, responsibilities can be split between parties providing data, parties providing algorithms and models, parties developing or using the AI system and being accountable with regard to some or all interested parties. The organization should document all parties intervening in the AI system life cycle and their roles and determine their responsibilities.
日本語訳AIシステムのライフサイクルにおいて、責任は、データを提供する者、アルゴリズム及びモデルを提供する者、AIシステムを開発又は利用し、一部又は全ての利害関係者に対して説明責任を負う者の間で分担されることがある。組織は、AIシステムのライフサイクルに関与する全ての当事者とその役割を文書化し、その責任を決定することが望ましい。
Annex B.10.2(手引)
When processed data includes PII, responsibilities are usually split between PII processors and controllers. ISO/IEC 29100 provides further information on PII controllers and PII processors. Where the privacy of PII is to be preserved, controls such as those described in ISO/IEC 27701 should be considered.
日本語訳処理されるデータが個人識別可能情報(PII)を含む場合、責任は通常、PII処理者とPII管理者との間で分担される。ISO/IEC 29100は、PII管理者及びPII処理者に関する更なる情報を提供している。PIIのプライバシーを保護する場合には、ISO/IEC 27701に記載されているような管理策を考慮することが望ましい。
原文は参考サイト(WatchDog Security GRC Wiki / Control Stack)に引用掲載されたものです。日本語訳は本サイトによる非公式訳です。
わかりやすく言うと
データ提供者、モデル提供者、開発者、利用者など、AIライフサイクルに関わる社内外の当事者の責任分担を明確にし、契約等で文書化します。
- 責任分担マトリクスを作成し、契約書に反映する
- 個人情報を扱う場合は管理者/処理者の区分を明確にする
- 責任の空白がないか
- 責任分担表
- 契約書・SLA