35% of ASEAN Guide on AI Governance and Ethics you already have
ISO 27018 already covers about 35% of ASEAN Guide on AI Governance and Ethics, leaving
24 of 37 controls as genuinely new work.
Already covered 2
Likely covered 11
New work 24
What is genuinely new work
Nothing in ISO 27018 reaches these. This is the list to scope.
AIGE-HI-1Establish AI objectives and assess against principles and risks
AIGE-HI-3Determine the level of human involvement
AIGE-HI-5Mitigate automation bias and protect affected groups
AIGE-IG-2Define roles and responsibilities for AI oversight
AIGE-IG-4Training, awareness and capability building
AIGE-IG-5Periodic review of the governance model
AIGE-IG-6Apply risk-based proportionality
AIGE-OM-1Project governance and problem statement definition
AIGE-OM-10Third-party and vendor AI governance
AIGE-OM-2Data quality and representativeness
AIGE-OM-3Bias identification and mitigation
AIGE-OM-5Model explainability
AIGE-OM-6Repeatability and reproducibility
AIGE-OM-7Robustness and security testing
AIGE-OM-8Traceability and auditability
AIGE-OM-9Deployment, monitoring and review
AIGE-P1Transparency and Explainability
AIGE-P2Fairness and Equity
AIGE-P6Accountability and Integrity
AIGE-SI-1Stakeholder communication policy and AI-use disclosure
AIGE-SI-2Feedback channels
AIGE-SI-3Decision review and recourse channels
AIGE-SI-4Acceptable use policies
Show the 13 you already have
AIGE-HI-2Assess probability and severity of harm
AIGE-IG-3AI ethics policies, standards and code of conduct
AIGE-HI-4Document risk impact assessments
AIGE-IG-1Establish internal AI governance structures and oversight body
AIGE-NR-1Nurture AI talent and upskill the workforce
AIGE-NR-2Invest in AI research and development
AIGE-NR-3Support the AI innovation ecosystem and investment
AIGE-OM-4Data provenance, minimisation and protection
AIGE-P3Security and Safety
AIGE-P5Privacy and Data Governance
AIGE-P7Robustness and Reliability
AIGE-RR-1Establish an ASEAN Working Group on AI Governance
AIGE-RR-2Foster regional alignment, cooperation and interoperability
How this is calculated
Already covered means a mapping runs from a control in ISO 27018 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition