Policy
What is a policy?
A policy represents an internal or external framework, standard, regulation, or testing criteria. Policies are made up of control bundles (categories) that each contain individual controls (questions or test criteria).
Policies can represent:
- External regulations (e.g. EU AI Act, NIST AI RMF)
- Internal governance frameworks
- Testing or assurance criteria
Policy assignment to AI systems
When an AI system is created, an Operational Risk Assessment policy is automatically assigned. This policy:
- Collects the system’s description, sector, jurisdiction, intended use case, and methodology
- Identifies the system’s current lifecycle stage
- Produces policy recommendations based on the completed answers
After the Operational Risk Assessment is complete, additional relevant policies can be added to the AI system from the Policy Library.
Who can add, create, or edit a policy?
- Any project member can add a policy from the Policy Library to an existing AI system.
- Org Admins can create or edit policies, control bundles, and controls within the organization’s library.
- New policies can be created by Org Admins. Contact support@asenion.ai for this advanced feature.
Who can access a policy?
Any member of the AI system’s team can view and answer the controls within any policy assigned to that system.
How to add a policy
See the “Add Policy to Project” section in the Quick Start Guide.