ADORSYS-GIS / ADORSYS-GIS/lightbridge-governance

[Story]: AI management system documentation (policy, risk register, impact assessments)

Offen
#112 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
user-story
Vorherrschende Sprache
Rust
Sterne
1
Forks
2
Ø Merge
14 Std. 36 Min.
Gemergte PRs (30 T.)
107

Beschreibung

## Summary
Produce the AI management system documentation required by ISO/IEC 42001: AI policy, AI risk register, and AI system impact assessments.

## Intent / Source of truth
The standard requires documented policies and risk management processes specific to AI systems, distinct from general information-security documentation. Part of [Epic] ISO/IEC 42001 certification path.

## Scope
- [ ] AI policy document (scope, principles, roles)
- [ ] AI risk register covering lightbridge's actual model fleet and data flows
- [ ] Impact assessment template applied to at least the highest-risk AI use cases

## Out of scope
- A generic risk-management framework unrelated to AI-specific clauses

## Verification
Documentation reviewed against the g2s1 gap analysis, closing the documentation-related gaps identified there.

## Risk assessment
Documentation that doesn't reflect actual operational practice is worse than none at audit time; the risk register must be grounded in the real model catalog (ai-helm-values models.yaml/inference.yaml), not generic AI risks.

## AI Usage Declaration
Drafted with AI assistance during the 2026-08-13 cross-repo backlog consolidation and enterprise-readiness research. A human owns intent, verification and consequences.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start with the g2s1 gap analysis and the actual model catalog in ai-helm-values/models.yaml and inference.yaml. Produce the scoped AI policy, risk register, and impact-assessment template applied to the highest-risk use cases, then verify that the documentation reflects operational practice and closes the identified gaps.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Bereich
documentation
Issue-Typ
Dokumentation
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Ruhig
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
55/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.