Control
Organization using AI without a documented AI management system
An organization that develops, provides, or uses AI systems should operate a documented, auditable AI management system (policy, roles, risk process, lifecycle controls, audit, improvement).
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Reach
The guard to add
Maintain a documented AI management system: an approved AI policy, named roles, an AI risk process, lifecycle controls, and internal audit and review records.
An organizational artifact set owned by an accountable executive: an AI policy approved by top management; the scope of the management system and an inventory of AI systems; roles and authorities (who approves releases, who owns each system's risk); an AI risk assessment and treatment process with a register; lifecycle controls for data, development, validation, deployment, monitoring, and retirement; internal audit and management-review records; and tracked improvement actions. It is reviewed on a planned cycle and when AI systems are added or materially changed. In the repository, keep the AI-system inventory with links to those records and a CI check that every listed system has an owner and a risk-register entry.
Where it goes: 12 repository artifacts, 11 CI/CD pipeline.
What reviewers look for: a current AI policy, scope or Statement of Applicability, AI risk register, and dated internal audit and management-review records; an inventory that covers the AI systems actually in the codebase, each with an owner; any certification claim backed by a certificate, not just a policy page.
Organizational control: the evidence is a kept record, its owner and its upkeep, not code.
Example (AI system inventory (repo record)), before:
# ai-systems.yaml
- name: support-chatbot
model: gpt-4oAfter:
# ai-systems.yaml, reviewed at each management review
policy: docs/aims/ai-policy.md # approved by CEO, 2026-03-01
statement_of_applicability: docs/aims/soa.md
systems:
- name: support-chatbot
model: gpt-4o
owner: head-of-support
risk_register: docs/aims/risk-register.md#support-chatbot
lifecycle_stage: production
last_internal_audit: 2026-06-12Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Every rule this guard addresses
Standard / soft law (1)
- International (INTL)
- Organizations developing, providing, or using AI should operate a certifiable AI management system (ISO/IEC 42001) ISO/IEC 42001:2023, Clauses 4-10 (AIMS requirements)