Kriter
ISO 42001
AI Security & Governance
ChatGPT Business
Ana hedef
Making the AI management system auditable and ready for certification.
Ensuring safe, controlled and policy-compliant use of all AI tools.
To establish, disseminate and create value for ChatGPT Business within the institution.
Typical trigger
Certification goal, customer expectation, audit or corporate governance need.
Shadow AI, sensitive data risk, uncontrolled employee driving.
The need to initiate the use of OpenAI/ChatGPT with secure workspace and training.
Who is involved?
Management, compliance, risk, legal, information security and process owners.
Information security, IT, law/KVKK, HR and business units.
IT, information security, business units, HR and ChatGPT pilot teams.
Output type
AIMS documentation, risk and impact analyses, control evidence.
AI policy, data matrix, security control architecture, training plan.
Workspace plan, admin control suggestions, use-case backlog, prompt playbook.