ADORSYS-GIS / ADORSYS-GIS/lightbridge-governance

[Story]: AI management system documentation (policy, risk register, impact assessments)

未关闭
#112 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
user-story
主要语言
Rust
星标
1
派生
2
平均合并
13 小时 13 分钟
30 天内合并 PR
110

描述

## Summary
Produce the AI management system documentation required by ISO/IEC 42001: AI policy, AI risk register, and AI system impact assessments.

## Intent / Source of truth
The standard requires documented policies and risk management processes specific to AI systems, distinct from general information-security documentation. Part of [Epic] ISO/IEC 42001 certification path.

## Scope
- [ ] AI policy document (scope, principles, roles)
- [ ] AI risk register covering lightbridge's actual model fleet and data flows
- [ ] Impact assessment template applied to at least the highest-risk AI use cases

## Out of scope
- A generic risk-management framework unrelated to AI-specific clauses

## Verification
Documentation reviewed against the g2s1 gap analysis, closing the documentation-related gaps identified there.

## Risk assessment
Documentation that doesn't reflect actual operational practice is worse than none at audit time; the risk register must be grounded in the real model catalog (ai-helm-values models.yaml/inference.yaml), not generic AI risks.

## AI Usage Declaration
Drafted with AI assistance during the 2026-08-13 cross-repo backlog consolidation and enterprise-readiness research. A human owns intent, verification and consequences.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。