For each AI use case: (a) define and document data quality, data and model provenance and data preparation requirements; (b) understand and document the data sources and collection processes the model or system relies on, including personal and sensitive data, and manage and document training, test and inference data; (c) for developers, define and document how models and systems are protected against emerging cybersecurity and privacy risks; (d) where appropriate, report data, model and system provenance to stakeholders; (e) document how the Australian Privacy Principles were applied, including in third-party models and systems; (f) document data usage rights including intellectual property and copyright, Indigenous data sovereignty, privacy, confidentiality and contract; and (g) monitor for and detect leakage of personal and sensitive information from models and systems.
This control maps to 3 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.