OECD AI Principles
Data Governance and Bias

OECD AI Principles OECDAI-5: Data Governance, Training Data Quality, Privacy, and Bias Mitigation

Operate data governance underpinning trustworthy AI per OECD Principles. Data governance must address (a) training data quality and governance with documented sourcing + provenance + consent + licensing + curation + quality controls + (b) data bias assessment and mitigation across training + validation + testing + production data, (c) data provenance and lineage tracking with metadata management + chain of custody + reproducibility support, (d) privacy protection in AI training data per applicable privacy regimes (GDPR + state privacy laws + sector-specific) + including data minimisation + purpose limitation + lawful basis + data subject rights handling for training data + model output containing training data + (e) data retention for AI models including training data + model snapshots + audit trails + inference logs per regulatory + investigative + governance need, (f) bias detection and mitigation including evaluation against fairness metrics appropriate to use case + intervention at data + model + output stages + ongoing monitoring for emergent bias + (g) cross-border data flow for AI training and inference per applicable regulation + (h) special handling for sensitive categories (health + biometric + children + protected class).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 298 controls across 94 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 8 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.25 Data protection by design and by default
  • GDPR-Art.35 Data protection impact assessment
  • GDPR-Art.38 Position of the data protection officer
  • GDPR-Art.9 Processing of special categories of personal data
  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

Bahrain PDPL · 6 controls

ISO/IEC 23894:2023 · 6 controls

  • ISO23894-5.1 Leadership and Commitment
  • ISO23894-5.2 AI Risk Management Integration
  • ISO23894-5.5 Framework Evaluation
  • ISO23894-6.3.1 AI Risk Identification
  • ISO23894-A.1 Data Quality and Representativeness
  • ISO23894-A.5 Privacy and Data Protection in AI
  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-4.3 Individual impact consideration
  • 27557-6.4 Privacy risk treatment
  • 27557-6.6 Recording and reporting
  • 27557-7.3 Risk-based privacy program implementation
  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer
  • BB-DPA-4 Section 4 - Principles Relating to Processing
  • NISTPF-2 Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring
  • NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing
  • NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • AZ-DPA-14 Article 16 - Liability for violations
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • UAE-PDPL-FreeZones Coordination with DIFC, ADGM and sectoral data protection regimes

ISO/IEC 27400:2022 · 4 controls

  • 27400-5.4 Data and privacy risks
  • 27400-7.1 Network Security for IoT
  • 27400-7.3 Data minimization and purpose limitation
  • 27400-7.4 Data retention and deletion
  • NORWAY-4 DPIA, Privacy by Design, Records of Processing
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control
  • NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training
  • NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement

Privacy Act 2020 · 4 controls

  • NZPRV-2 IPP 5 Storage and Security of Personal Information
  • NZPRV-5 IPP 11-12 Disclosure, Cross-Border Disclosure (Schedule 8)
  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design
  • NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training
  • AIGF-1.1 Risk Management and Internal Controls
  • AIGF-1.2 AI Ethics Governance Body
  • AIGF-1.3 Data Management
  • AIGF-3.2 Explainability

South Korea ISMS-P · 4 controls

  • ISMSP-MS-02 Risk Management
  • ISMSP-PI-01 Personal Information Collection
  • ISMSP-PI-04 Cross-Border Transfer
  • ISMSP-SYS-02 Encryption Implementation

South Korea PIPA · 4 controls

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021
  • PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37
  • PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2

APPI · 3 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • AL-DPA-12 International Data Transfers
  • AL-DPA-14 Direct Marketing
  • AL-DPA-7 Right of Access
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • IS.D.OR.210 Information Security Risk Treatment
  • IS.I.OR.210 Information Security Risk Treatment
  • IS.I.OR.220 Information Security Risk Management
  • FFIEC-03 Risk appetite and tolerance for IT risk
  • FFIEC-18 Ongoing monitoring and assessment
  • FFIEC-20 Exit strategy and transition planning
  • 60601-1.4.1 General requirements
  • 60601-1.4.2 Risk management process
  • 60601-1.5.1 General requirements for testing
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning
  • IEC62304-7.4 Risk Management of Software Changes

ISO 27799:2025 · 3 controls

  • ISO27799-03 Minimum necessary standard enforcement
  • ISO27799-04 Patient data de-identification procedures
  • ISO27799-05 Audit trail for ePHI access
  • ISO-25012-5.1 Establishing data quality requirements
  • ISO-25012-5.2 Defining data quality measures
  • ISO-25012-5.3 Planning and performing data quality evaluations

ISO/IEC 27011:2024 · 3 controls

  • 27011-5.2 Information Security Roles in Telecoms
  • 27011-6.3 Awareness and Training
  • 27011-8.6 Data protection and backup

ISO/IEC 29100:2024 · 3 controls

  • 29100-6.10 Information security
  • 29100-6.5 Use, retention and disclosure limitation
  • 29100-6.9 Accountability

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders

NIST SP 800-190 · 3 controls

NIST SP 800-53 Rev 5 · 3 controls

  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • IM8-DAT.2 Data Protection
  • IM8-DAT.4 Data Retention and Disposal
  • IM8-TPM.4 Supply Chain Risk Management

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • AIGE-OM-4 Data provenance, minimisation and protection
  • AIGE-P5 Privacy and Data Governance
  • MLE.1 Machine Learning Requirements Analysis
  • MLE.2 Machine Learning Architecture
  • BS65000-RM-01 Resilience Journey
  • BS65000-RM-02 Integrated Approach
  • DIQ-2 Data Quality Management
  • DIQ-3 Metadata Management
  • CAT-D1-2 Risk management
  • CAT-ML-2 Evolving
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • ICP-16 Enterprise Risk Management for Solvency Purposes
  • ICP-8 Risk Management and Internal Controls

ISO/IEC 27003:2017 · 2 controls

  • ISO27003-6.1 Actions to address risks and opportunities
  • ISO27003-8.3 Information security risk treatment
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data

Turkey KVKK · 2 controls

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • TURKEYKVKK-3 Special Categories and Sensitive Data
  • D.1 Incident Response Planning
  • UKDEFSTD-1 Cyber Defence Cyber Risk Profile (CRP)
  • USMCADIGITAL-1 Cross-Border Data Flows and Localisation
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • VIETNAMCYBER-4 Incident Reporting and Cooperation
  • AMLCTF-82 Part A Compliance

API 1164 · 1 control

  • API1164-21 TSA Pipeline Security Directive Alignment
  • AS9100D-8.1 Operational Planning and Control
  • ASD37-27 Outbound data loss prevention (Very Good)
  • ACQS-8-4 Risk Management
  • AUAIE-4 Privacy protection and security
  • DS-2 Ensure software supply chain security

Brazil AI Framework · 1 control

  • BRAI-A42 Text and data mining / copyright
  • CA-10 Selects and Develops Control Activities
  • CO-AIA-1702-2 Developer Documentation and Disclosures to Deployers
  • CTDPA-1 Definitions
  • CJIS-19 Supply Chain Risk Management
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)

IEC 62443 · 1 control

  • IEC62443-21 Supply chain risk management for critical components
  • ISO-20400-4.5 Key considerations for sustainable procurement

ISO 22320:2018 · 1 control

  • ISO-22320-4.3 Risk-based approach

ISO 26000:2010 · 1 control

  • ISO-26000-6.7 Consumer issues
  • ISO28001-SA-04 Security Risk Treatment Planning

ISO/IEC 27019:2024 · 1 control

  • ISO27019-21 Supply chain risk management for critical components

NIST SP 1800-32 · 1 control

  • ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)
  • OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence
  • PSPF24-1 Security Culture, Governance, Risk Management
  • EHDS-HOLD-3 Dataset Descriptions and Catalogues
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • CRM-3 Risk Management Framework
  • OB-CX.2 Granular Consent Management
  • CPSC-CS.3 Data Protection for Safety Systems

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 298 it maps to, and the evidence behind each claim, over MCP and REST.