ADORSYS-GIS / ADORSYS-GIS/lightbridge-governance
[Story]: AI management system documentation (policy, risk register, impact assessments)
- 主要语言
- Rust
- 星标
- 1
- 派生
- 2
- 平均合并
- 13 小时 13 分钟
- 30 天内合并 PR
- 110
描述
## Summary
Produce the AI management system documentation required by ISO/IEC 42001: AI policy, AI risk register, and AI system impact assessments.
## Intent / Source of truth
The standard requires documented policies and risk management processes specific to AI systems, distinct from general information-security documentation. Part of [Epic] ISO/IEC 42001 certification path.
## Scope
- [ ] AI policy document (scope, principles, roles)
- [ ] AI risk register covering lightbridge's actual model fleet and data flows
- [ ] Impact assessment template applied to at least the highest-risk AI use cases
## Out of scope
- A generic risk-management framework unrelated to AI-specific clauses
## Verification
Documentation reviewed against the g2s1 gap analysis, closing the documentation-related gaps identified there.
## Risk assessment
Documentation that doesn't reflect actual operational practice is worse than none at audit time; the risk register must be grounded in the real model catalog (ai-helm-values models.yaml/inference.yaml), not generic AI risks.
## AI Usage Declaration
Drafted with AI assistance during the 2026-08-13 cross-repo backlog consolidation and enterprise-readiness research. A human owns intent, verification and consequences.
贡献指南
评估
这个 Issue 还没有评估数据。