
Documentation
Policies
16SOPs
41Templates
7Registers
9Runbooks
6Governance
ISMS Core
Risk Management
Internal Audit
Mgmt Review
Compliance
ISO 27001:2022
SOC 2 Type II
AI Governance
Evidence
Evidence Collection
Incidents
Technical
Architecture
System
Audit Log
Settings
Cognium Inc.
ISMS Portal v2.0
ISO 42001 aligned AI/ML controls and risk management
Management System
3/3
Risk Management
0/3
Development
3/3
Deployment
3/3
Monitoring
1/4
Explainability
2/3
Human Oversight
2/2
21 controls
| Control ID | Category | Control Name | Risk | Status | Owner |
|---|---|---|---|---|---|
AI-4.1 | Management | AI System Context | medium | Implemented | Gurmat Dusanjh |
AI-4.2 | Management | Stakeholder Requirements | medium | Implemented | Harvey Toor |
AI-5.1 | Management | AI Leadership Commitment | low | Implemented | Harvey Toor |
AI-6.1 | Risk | AI Risk Assessment | high | In Progress | Pio Greeff |
AI-6.2 | Risk | AI Threat Modeling | high | In Progress | Vibin Thomas |
AI-6.3 | Risk | Bias and Fairness Assessment | high | In Progress | Vibin Thomas |
AI-7.1 | Development | Training Data Management | high | Implemented | Vibin Thomas |
AI-7.2 | Development | Model Development Standards | medium | Implemented | Vibin Thomas |
AI-7.3 | Development | Model Validation and Testing | high | Implemented | Vibin Thomas |
AI-8.1 | Deployment | Deployment Authorization | high | Implemented | Abishek Malani |
AI-8.2 | Deployment | Model Version Control | medium | Implemented | Vibin Thomas |
AI-8.3 | Deployment | Model Rollback Capability | high | Implemented | Abishek Malani |
AI-9.1 | Monitoring | Model Performance Monitoring | high | Implemented | Vibin Thomas |
AI-9.2 | Monitoring | Data Drift Detection | high | In Progress | Vibin Thomas |
AI-9.3 | Monitoring | Model Drift Monitoring | high | In Progress | Vibin Thomas |
AI-9.4 | Monitoring | AI Incident Response | high | In Progress | Pio Greeff |
AI-10.1 | Transparency | Model Explainability | medium | Planned | Vibin Thomas |
AI-10.2 | Transparency | AI System Documentation | medium | Implemented | Gurmat Dusanjh |
AI-10.3 | Transparency | User Disclosure | low | Implemented | Harvey Toor |
AI-11.1 | Human | Human-in-the-Loop Controls | high | Implemented | Gurmat Dusanjh |
AI-11.2 | Human | Override Capability | high | Implemented | Abishek Malani |