ISO 42001 APPLICATION

AI system development

Part of: Annex A.5: AI System Life Cycle

Description

Disciplined development practices including version control, peer review, documentation, and responsible AI principle adherence.

Implementation Guidance

Development Standards

Establish AI development standards covering: code version control (all training code, feature engineering, configs), mandatory peer review before model promotion, documentation requirements (model cards, data sheets), and coding standards for ML pipelines.

Reproducibility

Ensure all AI experiments are reproducible: pin library versions, log random seeds, version training data, record hyperparameters, and maintain experiment tracking (MLflow, Weights & Biases). Any production model must be fully reproducible from source.

Responsible Development Practices

Integrate responsible AI checks into the development workflow: bias assessments during feature selection, fairness metric evaluation during training, security review of data pipelines, and privacy impact assessment for new data sources.

Evidence Requirements

  • Development standards documentation
  • Version control history and peer review records
  • Model cards and data sheets
  • Experiment tracking logs showing reproducibility

Related Controls

AI Asset Inventory