ISO/IEC 23894:2023
Framework – ISO/IEC 23894:2023

ISO/IEC 23894:2023 5.5: Implementation

The framework should be implemented through a plan with time and resources attached, by identifying where, when, how and by whom decisions are made, by adjusting decision-making processes where necessary and by making sure the arrangements for managing risk are understood and practised (ISO 31000:2018, 5.5); for AI the plan should cover the decision points across the AI system life cycle where risk is assessed and treated, from inception through design, development, verification, deployment, operation and retirement.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 35 controls across 13 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 38500:2024 · 20 controls

  • 4.1 Outcomes of good governance of IT
  • 4.1.2 Effective performance
  • 4.1.3 Responsible stewardship
  • 4.1.4 Ethical behaviour
  • 4.2 Principles, model and framework
  • 5.10 Risk governance
  • 5.11 Social responsibility
  • 5.3 Value generation
  • 5.5 Oversight
  • 5.6 Accountability
  • 5.7 Stakeholder engagement
  • 5.9 Data and decisions
  • 6.1 Introduction to the model
  • 6.2 Governance of IT practice
  • 6.2.1 Engage stakeholders
  • 6.4 Framework for the governance of IT
  • 7.2 Elements of the framework
  • 7.2.3 Capability
  • 7.2.5 Delegation
  • 7.2.7 Accountability

ISO 19011:2018 · 4 controls

  • 5.5 Implementing audit programme
  • 5.5.4 Selecting audit team members
  • 7.2 Determining auditor competence
  • 7.2.4 Achieving auditor competence

APRA CPS 234 · 1 control

  • CPS234-21 Implementation of Information Security Controls
  • BR-OF-A1 Implementation and scope of Open Finance

ISO 10005:2005 · 1 control

  • 6.2 Implementation of the quality plan

ISO 14004:2016 · 1 control

  • 10.3.2 Implementation of continual improvement

ISO 22301:2019 · 1 control

  • 8.3.5 Implementation of solutions
  • 27557-5.4 Implementation and evaluation

NIST SP 800-128 · 1 control

NIST SP 800-160 · 1 control

  • VPSHR-3 Implementation Guidance and Reporting

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Framework – ISO/IEC 23894:2023

Query this from an agent

The graph holds this control, the 35 it maps to, and the evidence behind each claim, over MCP and REST.