Skip to main content
Establish a system transparency policy and maintain a repository of model cards, datasheets, and interpretability reports for major systems

Control activities

Typical evidence

Should include?

Creating transparency documentation for major AI systems. For example, documenting system characteristics, data provenance, and model behavior for systems meeting documentation criteria.

E017.1 Documentation: AI system transparency documentation

Transparency documentation artifacts such as a model card, datasheet, or AI bill of materials - for example, records of the system name and version, training or fine-tuning data sources and characteristics, dated records of fine-tuning or adaptation changes and records of AI-specific components beyond the model including frameworks, orchestration layers, tool connectors.

Typical location
Engineering Code
Capabilities
Universal
May include?

Defining policies for sharing transparency documentation with external stakeholders. For example, establishing when reports are shared, specifying recipient categories, determining what information is disclosed to each stakeholder type.

Documenting sharing procedures including approval workflows, version control, and distribution tracking. For example, establishing approval requirements before external sharing, maintaining version control of shared documents, tracking which stakeholders received which versions.

E017.2 Documentation: Transparency report sharing policy

Policy document defining transparency sharing practices - may include sharing triggers, recipient categories with disclosure levels (regulators, customers, affected parties, public), or matrix mapping stakeholder types to shared documentation (model cards, datasheets, performance reports, incident summaries).

Typical location
Internal processesInternal policies
Capabilities
Universal

Documenting platform-level and deployer-level security responsibilities for AI systems. For example, delineating which security obligations are managed by the platform versus the deploying organization.

E017.3 Documentation: Platform and deployer security responsibilities

Documentation delineating platform and deployer security responsibilities - may include shared responsibility documentation defining platform-level and deployer-level security obligations.

Typical location
Terms of ServiceInternal policies
Capabilities
Universal

Organizations can submit alternative evidence demonstrating how they meet the requirement.