Domain I · Competency I.C

Establish policies and procedures to apply throughout the AI life cycle

Building the policy layer of an AI governance program — lifecycle policies for oversight and accountability, updating existing policies (privacy, security, data governance, IP) for AI, and managing third-party and procurement risk with assessments, contracts and acceptable-use rules.

Exam weight: 6–8 questions

Quick check not attempted yet — take it below to track your score.

Performance indicators

Key terms

Policy
A high-level statement of intent and rules that sets the organization’s expectations (the "what" and "why"). Procedures and standards operationalize it (the "how").
AI life cycle
The stages an AI system passes through — use-case assessment, design, data acquisition, model/system development, training and testing, deployment, monitoring, and retirement. Policies must give oversight at every stage.
Ethics by design
Embedding ethical and responsible-AI considerations into the system from the outset of design rather than bolting them on afterward (cf. privacy by design).
Use-case assessment
An early gate that evaluates whether a proposed AI use is appropriate, lawful, valuable and within risk tolerance before resources are committed.
Incident management
Policies and procedures to detect, escalate, respond to, document and learn from AI failures, harms and near-misses.
Data governance
The framework of policies and controls governing how data is acquired, quality-checked, used, retained and protected — a frequent existing policy that AI forces organizations to extend.
Acceptable use policy (AUP)
Rules defining permitted and prohibited uses of AI tools by employees (e.g., what data may be entered into public generative-AI tools), a core control against shadow AI.
Shadow AI
Unsanctioned use of AI tools by employees outside governance — a primary risk an acceptable-use policy is designed to address.
Third-party / vendor risk
Risk introduced by external AI models, components, data or services. Managed through due-diligence assessments, contractual terms and ongoing oversight.
Procurement
The buying process for AI systems and components; a key control point for embedding governance requirements (assessments, contract clauses) before adoption.
Intellectual property (IP) risk
Risk around rights to training data, ownership/authorship of AI outputs, and confidentiality — an existing-policy area AI reshapes.

At a glance

Competency I.B set up the people; I.C sets up the rules they enforce. This competency is about the policy and procedure layer of an AI governance program across three moves: (1) create lifecycle policies that ensure oversight and accountability at every stage of the AI life cycle, (2) evaluate and update existing policies (privacy, security, data governance, IP) so they actually cover AI, and (3) manage third-party risk through assessments, contracts and acceptable-use policies.

A useful framing: a policy states the organization’s expectations and rules (the what/why); procedures, standards and controls make them operational (the how). Grounded in the NIST AI RMF Govern function (“policies, processes, procedures and practices are in place”) and ISO/IEC 42001’s documented-policy requirements, the exam tests the most widely accepted policy areas at the apply/analyze level.

I.C.1 — Lifecycle policies for oversight and accountability

The core requirement is policies that ensure oversight and accountability across all AI life cycle stages. The BOK enumerates the stages your policies must cover — learn the list, because exam questions test whether a control sits at the right stage:

Life cycle stageWhat the policy ensures
Use-case assessmentA gate to decide whether an AI use is appropriate, lawful and within risk tolerance before building.
Risk managementIdentify, assess, mitigate and monitor risks throughout (ties to NIST Map/Measure/Manage).
Ethics by designEmbed responsible-AI/ethical considerations from the start of design, not after.
Data acquisition and useLawful rights to data; quality, provenance, minimization, bias checks.
Model & system developmentStandards for how systems are built and reviewed.
Training and testingValidation, performance, security, bias and interpretability testing before release.
Deployment and monitoringApproval gates, human oversight, continuous monitoring for drift/degradation.
Documentation and reportingRecords (model cards, technical docs) to evidence compliance and enable review.
Incident managementDetect, escalate, respond to, document and learn from AI failures and harms.

Two ideas the exam stresses:

I.C.2 — Evaluate and update existing policies for AI

Most organizations already have policies — for data privacy, security, data governance and intellectual property. The BOK’s requirement is to evaluate and update them for AI rather than write everything from scratch. AI stresses these existing policies in new ways:

Existing policyWhy AI forces an update
Data privacyTraining on personal data raises lawful-basis, purpose-limitation, minimization, transparency and automated-decision (GDPR Art. 22) issues; DPIAs may be required.
SecurityNew attack surfaces — data poisoning, model inversion/extraction, adversarial examples, prompt injection — that traditional security policy never contemplated.
Data governanceProvenance, lineage, quality, bias and retention of training data; rights to use data for AI specifically.
Intellectual propertyRights to use third-party data for training; ownership/authorship of AI-generated outputs (the U.S. human-authorship requirement); leakage of confidential/IP data into external models.

The takeaway the exam rewards: start by reviewing and extending what you have. Governance is partly new AI-specific policy (I.C.1) and partly adapting existing policy. Don’t assume current privacy/security/IP policies already cover AI — they usually do not address training-data rights, model-specific attacks, or generative-output ownership.

I.C.3 — Manage third-party risk

Most organizations consume AI they did not build — foundation models, APIs, vendor tools, components and data. The BOK requires policies, assessments and contracts to manage third-party risk across procurement, supply chain, human resources and acceptable use.

The control points:

How this shows up later

Sources

Flashcards

1 / 9

Quick check

Quick check1 / 10 · score 0

What does "ethics by design" require of an AI governance policy?

  • AReviewing ethics only after deployment, during incident management.
  • BEmbedding ethical and responsible-AI considerations from the start of the design process.
  • CLimiting ethical review to the legal team’s final sign-off.
  • DTreating ethics as optional for internal tools.