TwinEthosRequest access

Control

Organization using AI without a documented AI management system

An organization that develops, provides, or uses AI systems should operate a documented, auditable AI management system (policy, roles, risk process, lifecycle controls, audit, improvement).

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: AI is deployed without a documented risk-management process or impact assessment · control id cond.ai-org-no-management-system

Reach

1items this one guard addresses
0jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
1standards and frameworks on the same control

The guard to add

Maintain a documented AI management system: an approved AI policy, named roles, an AI risk process, lifecycle controls, and internal audit and review records.

An organizational artifact set owned by an accountable executive: an AI policy approved by top management; the scope of the management system and an inventory of AI systems; roles and authorities (who approves releases, who owns each system's risk); an AI risk assessment and treatment process with a register; lifecycle controls for data, development, validation, deployment, monitoring, and retirement; internal audit and management-review records; and tracked improvement actions. It is reviewed on a planned cycle and when AI systems are added or materially changed. In the repository, keep the AI-system inventory with links to those records and a CI check that every listed system has an owner and a risk-register entry.

Where it goes: 12 repository artifacts, 11 CI/CD pipeline.

What reviewers look for: a current AI policy, scope or Statement of Applicability, AI risk register, and dated internal audit and management-review records; an inventory that covers the AI systems actually in the codebase, each with an owner; any certification claim backed by a certificate, not just a policy page.

Organizational control: the evidence is a kept record, its owner and its upkeep, not code.

Example (AI system inventory (repo record)), before:

# ai-systems.yaml
- name: support-chatbot
  model: gpt-4o

After:

# ai-systems.yaml, reviewed at each management review
policy: docs/aims/ai-policy.md            # approved by CEO, 2026-03-01
statement_of_applicability: docs/aims/soa.md
systems:
  - name: support-chatbot
    model: gpt-4o
    owner: head-of-support
    risk_register: docs/aims/risk-register.md#support-chatbot
    lifecycle_stage: production
    last_internal_audit: 2026-06-12

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Standard / soft law (1)