OECD AI Principles
Audit, Impact Assessments, Metrics

OECD AI Principles OECDAI-7: Third-Party AI Audit, Impact Assessments, and Metrics for Trustworthy AI

Operate third-party AI audit + impact assessments + metrics per OECD AI Principles + emerging assurance standards. Third-party AI audit must (a) engage independent assessors for high-risk AI systems per applicable regulation + voluntary assurance scheme (EU AI Act conformity assessment + ISO/IEC 42001 certification + NIST AI RMF profile assessment + sector-specific), (b) maintain auditability of AI systems including documentation + access to model + data + logs + decision history + (c) implement findings remediation tracking through closure. Impact Assessments Aligned to OECD Principles must (a) conduct AI impact assessments per use case covering OECD Principles + applicable regulation (AI Conformity Assessment per EU AI Act + Algorithmic Impact Assessment per Canadian Directive + DPIA per GDPR + EHRIA + similar), (b) involve diverse stakeholders + affected communities + subject matter experts + (c) document the assessment + findings + mitigations + acceptance + reassessment triggers. Metrics and indicators for trustworthy AI must (a) define operational metrics per OECD Principle (inclusive growth + human-centred + transparency + robustness + accountability), (b) measure operationally across the AI portfolio + report to governance bodies + (c) benchmark against peer organisations + industry indices + (d) integrate with broader enterprise risk and ESG metrics where applicable.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 4 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

Brazil AI Framework · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.