Define the mandatory control catalog per consequence class
Draft
Define the mandatory control catalog per consequence class
Layer 4. Control POLPolicy and framework
Allocation
| L4-POL-03 | |
|---|---|
| Decides | AI Governance Board |
| Consulted | CISO, DPO and Head of Internal Audit |
| Executes | CISO |
| Evidence | Control catalog mapped to source instruments, stating the consequence class scheme in use and its derivation from the section 5B factors |
In plain terms
Decide which controls are compulsory for which class of system. This is where borrowed controls become required ones, and it is what turns policy into something Layer 3 can act on.
What is being judged
Not which controls exist, which ISO and NIST already answer, but which are mandatory here and for which class. Three properties make a catalog usable. Every entry maps to a source instrument, so the organization can say where the requirement came from. Every entry is testable, so Layer 4 can verify it operated. Every entry is assigned to a class, so lighter systems are not carrying controls sized for heavier ones.
A catalog that lists everything is a wish list. The judgment is subtraction.
What this decision does not cover
It does not decide how a control is built; that is L3-07. It does not decide whether a system may proceed without one; that is the exception path at L4-POL-04 and L4-POL-05.
When it fires
On event. On regulatory change affecting an obligation in the register. On revision of the consequence class scheme. On an incident where a control that should have been mandatory was not.
On cycle. Semi-annually.
What you need before deciding
The consequence class scheme. The regulatory obligation register. The crosswalk, to source each entry. Current Layer 3 practice, so the catalog reflects what can actually be operated.
How this goes wrong
Policy without a catalog, the Layer 4 anti-pattern: policy states systems must be secure and fair, nothing translates that into required controls, and two teams give different answers. The unsourced control: an entry nobody can trace to an instrument or an obligation, which survives because removing it looks like weakening. One class for everything: a single catalog applied to all systems, which over-controls the light and under-controls the heavy.
Side effect worth knowing. The catalog defines the Layer 2 architecture exception band. An exception routes to the Head of Risk where it weakens a control the catalog marks required. Editing the catalog therefore moves a Layer 2 threshold, which is intended and easy to do accidentally.
Related decisions
Upstream L4-POL-01 policy, L4-CLS-02 materiality, §5B classification.
Downstream L3-07 control implementation, L2-06 and L2-07 exceptions, L4-ASR-01 audit scope.
Instrument references
ISO/IEC 27001 Annex A and ISO/IEC 42001 Annex A both supply control sets. COBIT supplies control objectives. None states which are mandatory for which class of AI system. That determination is the organization’s, and this decision is where it is made.
Correction
The maintainer answers corrections. There is no service level. Responses are best-effort and opportunistic within a reasonable time: a correction raised on a Monday is answered that week or sooner.