ISO 42001 GOVERNANCE

Human oversight of AI systems

Part of: Annex A.2: Policies Related to AI

Description

Policy establishing requirements for meaningful human oversight, intervention mechanisms, and escalation procedures for AI system outputs.

Implementation Guidance

Oversight Levels

Define tiered oversight requirements based on AI system risk classification: human-in-the-loop (human approves every decision), human-on-the-loop (human monitors and can intervene), human-in-command (human sets objectives and constraints). Map each deployed AI system to the appropriate level.

Intervention Mechanisms

Implement technical controls enabling human override: kill switches for autonomous systems, confidence threshold alerts, manual review queues for edge cases, and rollback procedures when AI outputs cause harm.

Escalation Procedures

Document clear escalation paths: who to notify when AI outputs are unexpected, how to escalate ethical concerns, and mandatory reporting triggers (bias detected, safety incident, regulatory inquiry).

Evidence Requirements

  • Human oversight policy with risk-tiered requirements
  • AI system risk classification register
  • Intervention mechanism documentation per system
  • Escalation procedure records and incident logs

Related Controls

AI Acceptable Use Policy