Operate third-party AI audit + impact assessments + metrics per OECD AI Principles + emerging assurance standards. Third-party AI audit must (a) engage independent assessors for high-risk AI systems per applicable regulation + voluntary assurance scheme (EU AI Act conformity assessment + ISO/IEC 42001 certification + NIST AI RMF profile assessment + sector-specific), (b) maintain auditability of AI systems including documentation + access to model + data + logs + decision history + (c) implement findings remediation tracking through closure. Impact Assessments Aligned to OECD Principles must (a) conduct AI impact assessments per use case covering OECD Principles + applicable regulation (AI Conformity Assessment per EU AI Act + Algorithmic Impact Assessment per Canadian Directive + DPIA per GDPR + EHRIA + similar), (b) involve diverse stakeholders + affected communities + subject matter experts + (c) document the assessment + findings + mitigations + acceptance + reassessment triggers. Metrics and indicators for trustworthy AI must (a) define operational metrics per OECD Principle (inclusive growth + human-centred + transparency + robustness + accountability), (b) measure operationally across the AI portfolio + report to governance bodies + (c) benchmark against peer organisations + industry indices + (d) integrate with broader enterprise risk and ESG metrics where applicable.
This control maps to 4 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.