An AI system is any system, product or service that uses AI, whether implemented in software or largely in hardware such as robots; trustworthiness means being able to satisfy what stakeholders expect in a way that can be verified, applicable across AI systems, technologies and domains. Like security, trustworthiness is handled as a non-functional requirement that describes emergent properties, seen from the angle of quality in use (ISO/IEC 25010), and an organization can raise it through a process that has measurable outcomes and KPIs, so it is both an ongoing process and a requirement. The precautionary principle (threats of serious or irreversible harm justify preventive measures despite scientific uncertainty) applies as a risk mitigation technique when capturing stakeholder value requirements, context of use and risks of harm. Where an AI system is an existing system enhanced with AI, every trustworthiness approach that applied before (quality metrics and measurement, safety and risk of harm, security and privacy risk frameworks) continues to apply.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.