OECD Due Diligence Guidance for Responsible AI (2026)
Step 2: Identify and assess actual and potential adverse impacts – OECD Due Diligence Guidance for Responsible AI (2026)

OECD Due Diligence Guidance for Responsible AI (2026) 2.2.G2-own: 2.2.G2-own In-depth assessment of significant risks in own operations: enterprises in the lifecycle

Starting with the most significant areas, assess prioritised risks iteratively and in depth: catalogue applicable legal requirements and standards including labour standards; review test, evaluation, verification and validation information (data availability, accuracy, representativeness, suitability, construct validity) and make sure the measurement tools are themselves tested; review human-subject evaluations where relevant and how outputs are used and overseen by humans; consult domain experts, users and teams outside the developers; consult stakeholders, workers, unions, affected communities and civil society before and during projects, possibly letting some review tests; consider pre-deployment and development risks such as model theft and internal misuse; identify robustness and security risks through testing; identify privacy and data governance risks at data and model level (Box 2.3); and identify risks of the system facilitating harm to human rights, society and the public interest.

Maintained by Gerard Blokdyk

Other controls in Step 2: Identify and assess actual and potential adverse impacts – OECD Due Diligence Guidance for Responsible AI (2026)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.