> ## Documentation Index
> Fetch the complete documentation index at: https://standard.aiuc-1.com/llms.txt
> Use this file to discover all available pages before exploring further.

# E008: Review internal processes

export const InlineClock = ({city, timeZone}) => {
  const [time, setTime] = useState('--:--:--');
  useEffect(() => {
    const update = () => setTime(new Intl.DateTimeFormat('en-US', {
      hour: '2-digit',
      minute: '2-digit',
      second: '2-digit',
      hour12: false,
      timeZone
    }).format(new Date()));
    update();
    const id = setInterval(update, 1000);
    return () => clearInterval(id);
  }, [timeZone]);
  return <div className="aiuc-footer-clock">
      <span className="aiuc-footer-clock-city">{city}</span>
      <span className="aiuc-footer-clock-time">{time}</span>
    </div>;
};

Establish regular internal reviews of key processes and document review records and approvals

<div className="aiuc-requirement-overview">
  <section className="aiuc-requirement-overview-section aiuc-requirement-overview-taxonomy">
    <div className="aiuc-requirement-overview-group">
      <div className="aiuc-requirement-overview-label">Keywords</div>

      <div className="aiuc-requirement-overview-pill-list">
        <span className="aiuc-requirement-overview-pill">Internal Reviews</span>
        <span className="aiuc-requirement-overview-pill">Documentation</span>
      </div>
    </div>
  </section>

  <section className="aiuc-requirement-overview-section aiuc-requirement-overview-details">
    <div className="aiuc-requirement-overview-detail">
      <div className="aiuc-requirement-overview-label">Application</div>
      <span className="aiuc-requirement-overview-pill">Mandatory</span>
    </div>

    <div className="aiuc-requirement-overview-detail">
      <div className="aiuc-requirement-overview-label">Frequency</div>
      <span className="aiuc-requirement-overview-pill">Every 12 months</span>
    </div>

    <div className="aiuc-requirement-overview-detail">
      <div className="aiuc-requirement-overview-label">Type</div>
      <span className="aiuc-requirement-overview-pill">Preventative</span>
    </div>

    <div className="aiuc-requirement-overview-detail">
      <div className="aiuc-requirement-overview-label">Capabilities</div>

      <div className="aiuc-requirement-overview-pill-list">
        <span className="aiuc-requirement-overview-pill">Universal</span>
      </div>
    </div>
  </section>

  <section className="aiuc-requirement-overview-section aiuc-requirement-overview-crosswalks">
    <div className="aiuc-requirement-overview-label">Crosswalks</div>

    <div className="aiuc-requirement-crosswalk-grid">
      <div className="aiuc-requirement-crosswalk-group">
        <div className="aiuc-requirement-crosswalk-heading">
          <span className="aiuc-requirement-crosswalk-title">EU AI Act</span> <span className="aiuc-help-marker aiuc-crosswalk-help-marker" data-tooltip="EU regulation classifies AI systems by risk levels (minimal, limited, high, unacceptable) with corresponding compliance obligations" tabIndex="0">?</span>
        </div>

        <div className="aiuc-requirement-crosswalk-rule" aria-hidden="true" />

        <div className="aiuc-requirement-crosswalk-items">
          <a href="/crosswalks/eu-ai-act" title="This article discusses the process of assessing whether high-risk AI systems meet certain standards. If a provider has used certain standards in creating their…">Article 43: Conformity Assessment</a>
        </div>
      </div>

      <div className="aiuc-requirement-crosswalk-group">
        <div className="aiuc-requirement-crosswalk-heading">
          <span className="aiuc-requirement-crosswalk-title">ISO 42001</span> <span className="aiuc-help-marker aiuc-crosswalk-help-marker" data-tooltip="International standard for AI management systems (AIMS) covering responsible AI development and deployment" tabIndex="0">?</span>
        </div>

        <div className="aiuc-requirement-crosswalk-rule" aria-hidden="true" />

        <div className="aiuc-requirement-crosswalk-items">
          <a href="/crosswalks/iso-42001" title="The organization shall define and put in place a process to report concerns about the organization's role with respect to an AI system throughout its life cycl…">A.3.3: Reporting of concerns</a>
          <a href="/crosswalks/iso-42001" title="The organization shall determine where other policies can be affected by or apply to the organization's objectives with respect to AI systems.">A.2.3: Alignment with other organizational policies</a>
          <a href="/crosswalks/iso-42001" title="The AI policy shall be reviewed at planned intervals or additionally as needed to ensure its continuing suitability, adequacy and effectiveness.">A.2.4: Review of the AI policy</a>
          <a href="/crosswalks/iso-42001" title="The organization shall plan and control changes to the AI management system in a planned manner.">6.3: Planning of changes</a>
          <a href="/crosswalks/iso-42001" title="The organization shall ensure documented information is properly created, updated, and controlled for suitability and adequacy.">7.5.2: Creating and updating documented information</a>
          <a href="/crosswalks/iso-42001" title="The organization shall conduct internal audits at planned intervals to provide information on the AI management system.">9.2.1: Internal audit - General</a>
          <a href="/crosswalks/iso-42001" title="Top management shall review the AI management system at planned intervals for continuing suitability, adequacy, and effectiveness.">9.2.2: Internal audit programme</a>
          <a href="/crosswalks/iso-42001" title="The organization shall review the AI management system at planned intervals to ensure its suitability, adequacy, and effectiveness.">9.3.1: Management review - General</a>
          <a href="/crosswalks/iso-42001" title="Management review inputs shall include audits, performance trends, nonconformities, feedback, risks, changes, and resources.">9.3.2: Management review inputs</a>
          <a href="/crosswalks/iso-42001" title="Management review results shall include decisions on improvements, policy/objectives, resources, and follow-up actions.">9.3.3: Management review results</a>
        </div>
      </div>

      <div className="aiuc-requirement-crosswalk-group">
        <div className="aiuc-requirement-crosswalk-heading">
          <span className="aiuc-requirement-crosswalk-title">NIST AI RMF</span> <span className="aiuc-help-marker aiuc-crosswalk-help-marker" data-tooltip="US government framework for managing AI risks throughout the AI lifecycle with four core functions: Govern, Map, Measure, Manage" tabIndex="0">?</span>
        </div>

        <div className="aiuc-requirement-crosswalk-rule" aria-hidden="true" />

        <div className="aiuc-requirement-crosswalk-items">
          <a href="/crosswalks/nist-ai-rmf" title="Processes and procedures are in place for decommissioning and phasing out of AI systems safely and in a manner that does not increase risks or decrease the org…">GOVERN 1.7: AI system decommissioning</a>
          <a href="/crosswalks/nist-ai-rmf" title="Mechanisms are established to enable AI actors to regularly incorporate adjudicated feedback from relevant AI actors into system design and implementation.">GOVERN 5.2: Feedback integration</a>
          <a href="/crosswalks/nist-ai-rmf" title="Organizational policies and practices are in place to collect, consider, prioritize, and integrate feedback from those external to the team that developed or d…">GOVERN 5.1: External feedback</a>
          <a href="/crosswalks/nist-ai-rmf" title="Measurable activities for continual improvements are integrated into AI system updates and include regular engagement with interested parties, including releva…">MANAGE 4.2: Continual improvement</a>
          <a href="/crosswalks/nist-ai-rmf" title="Appropriateness of AI metrics and effectiveness of existing controls is regularly assessed and updated including reports of errors and impacts on affected comm…">MEASURE 1.2: Metric appropriateness</a>
          <a href="/crosswalks/nist-ai-rmf" title="Effectiveness of the employed TEVV metrics and processes in the MEASURE function are evaluated and documented.">MEASURE 2.13: TEVV effectiveness</a>
        </div>
      </div>

      <div className="aiuc-requirement-crosswalk-group">
        <div className="aiuc-requirement-crosswalk-heading">
          <span className="aiuc-requirement-crosswalk-title">CSA AICM</span> <span className="aiuc-help-marker aiuc-crosswalk-help-marker" data-tooltip="Cloud Security Alliance’s AI Controls Matrix provides security controls framework specifically designed for AI/ML systems" tabIndex="0">?</span>
        </div>

        <div className="aiuc-requirement-crosswalk-rule" aria-hidden="true" />

        <div className="aiuc-requirement-crosswalk-items">
          <a href="/crosswalks/csa-aicm" title="Conduct independent audit and assurance assessments according to relevant standards at least annually.">A\&A-02: Independent Assessments</a>
          <a href="/crosswalks/csa-aicm" title="Perform independent audit and assurance assessments in response to signifianct changes or emerging risks and according to risk-based plans and policies.">A\&A-03: Risk Based Planning Assessment</a>
          <a href="/crosswalks/csa-aicm" title="Define and implement an Audit Management process aligned with global audting standards, to support audit planning, risk analysis, security control assessment,…">A\&A-05: Audit Management Process</a>
          <a href="/crosswalks/csa-aicm" title="Establish, document, approve, communicate, apply, evaluate and maintain a risk-based corrective action plan to remediate audit findings, regularly review and r…">A\&A-06: Remediation</a>
          <a href="/crosswalks/csa-aicm" title="Establish, document, approve, communicate, apply, evaluate and maintain business continuity management and operational resilience policies and procedures.Revie…">BCR-01: Business Continuity Management Policy and Procedures</a>
          <a href="/crosswalks/csa-aicm" title="Audit encryption and key management systems, policies, and processeswith a frequency that is proportional to the risk exposure of the system withaudit occurrin…">CEK-09: Encryption and Key Management Audit</a>
          <a href="/crosswalks/csa-aicm" title="Conduct a Data Protection Impact Assessment (DPIA) to evaluate the origin, nature, particularity and severity of the risks upon the processing of personal data…">DSP-09: Data Protection Impact Assessment</a>
          <a href="/crosswalks/csa-aicm" title="Review all relevant organizational policies and associated proceduresat least annually or when a substantial change occurs within the organization.">GRC-03: Organizational Policy Reviews</a>
          <a href="/crosswalks/csa-aicm" title="Manage, store, and regularly review the inventory of identities, and monitor their level of access.">IAM-03: Identity Inventory</a>
          <a href="/crosswalks/csa-aicm" title="Review and revalidate user access for least privilege and separationof duties with a frequency that is commensurated with organizational risk tolerance and at…">IAM-08: User Access Review</a>
          <a href="/crosswalks/csa-aicm" title="Establish, document and implement which information meta/data system events should be logged. Review and update the scope at least annually or whenever there i…">LOG-07: Logging Scope</a>
          <a href="/crosswalks/csa-aicm" title="Establish, document, approve, communicate, apply, evaluate and maintain audit and assurance policies and procedures and standards. Review and update the polici…">A\&A-01: Audit and Assurance Policy and Procedures</a>
          <a href="/crosswalks/csa-aicm" title="Establish, document and maintain baseline requirements for securing applications.">AIS-02: Application Security Baseline Requirements</a>
          <a href="/crosswalks/csa-aicm" title="Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for application security. Review and update the policies and pr…">AIS-01: Application and Interface Security Policy and Procedures</a>
          <a href="/crosswalks/csa-aicm" title="Define and implement a process to proactively roll back changes to a previous known good state in case of errors or security concerns.">CCC-09: Change Restoration</a>
        </div>
      </div>

      <div className="aiuc-requirement-crosswalk-group">
        <div className="aiuc-requirement-crosswalk-heading">
          <span className="aiuc-requirement-crosswalk-title">IBM AI Risk Atlas</span> <span className="aiuc-help-marker aiuc-crosswalk-help-marker" data-tooltip="Comprehensive taxonomy of risks associated with ML models, GenAI, and AI Agents from IBM Research" tabIndex="0">?</span>
        </div>

        <div className="aiuc-requirement-crosswalk-rule" aria-hidden="true" />

        <div className="aiuc-requirement-crosswalk-items">
          <a href="/crosswalks/ibm-ai-risk-atlas" title="A metric selected to measure or track a risk is incorrectly selected, incompletely measuring the risk, or measuring the wrong risk for the given context.">IBM 85: Non-Technical - Incorrect risk testing</a>
        </div>
      </div>

      <div className="aiuc-requirement-crosswalk-group">
        <div className="aiuc-requirement-crosswalk-heading">
          <span className="aiuc-requirement-crosswalk-title">CA SB 53</span> <span className="aiuc-help-marker aiuc-crosswalk-help-marker" data-tooltip="California Senate Bill 53 establishes safety requirements for frontier AI models including shutdown capabilities and safety testing" tabIndex="0">?</span>
        </div>

        <div className="aiuc-requirement-crosswalk-rule" aria-hidden="true" />

        <div className="aiuc-requirement-crosswalk-items">
          <a href="/crosswalks/ca-sb-53" title="Requires large frontier developers to publish a Frontier AI Framework and transparency reports, and to submit quarterly catastrophic risk assessments to OES.">22757.12: Transparency & Reporting Obligations</a>
        </div>
      </div>
    </div>
  </section>
</div>

<section className="aiuc-requirement-control-evidence">
  <div className="aiuc-requirement-control-evidence-headings">
    <h2>Control activities</h2>
    <h2>Typical evidence</h2>
  </div>

  <div className="aiuc-requirement-control-evidence-group">
    <div className="aiuc-requirement-control-evidence-label">
      <span>Should include</span> <span className="aiuc-help-marker" data-tooltip="Organizations must demonstrate core controls to meet the requirement. Auditors may accept alternative implementations that achieve equivalent outcomes." tabIndex="0">?</span>
    </div>

    <div className="aiuc-requirement-control-evidence-row">
      <div className="aiuc-requirement-card aiuc-requirement-control-card">
        <div className="aiuc-requirement-control-item">
          <span className="aiuc-requirement-control-bullet" aria-hidden="true" />

          <p><strong>Reviewing decision processes every quarter including AI system changes, foundational model selection, security assessment.</strong></p>
        </div>

        <div className="aiuc-requirement-control-item">
          <span className="aiuc-requirement-control-bullet" aria-hidden="true" />

          <p><strong>Maintaining a centralized repository of decision records and internal review of these record.</strong> For example, supporting evidence reviewed, remediation plans.</p>
        </div>

        <div className="aiuc-requirement-control-item">
          <span className="aiuc-requirement-control-bullet" aria-hidden="true" />

          <p><strong>Documenting and tracking remediation of any risks identified.</strong></p>
        </div>
      </div>

      <div className="aiuc-requirement-card aiuc-requirement-evidence-card">
        <div className="aiuc-requirement-evidence-title">E008.1 Documentation: Internal review</div>
        <p>Centralized repository, policy, or tickets showing quarterly internal reviews - e.g. review meeting notes or calendars, decision logs in Jira/Notion/Confluence, risk registers with remediation status, threat modelling outcomes, or audit trails of review activities.</p>

        <div className="aiuc-requirement-evidence-meta">
          <div className="aiuc-requirement-evidence-meta-group">
            <div className="aiuc-requirement-evidence-meta-label">Category</div>
            <a href="/evidence/operational-practices">Operational Practices</a>
          </div>

          <div className="aiuc-requirement-evidence-meta-group">
            <div className="aiuc-requirement-evidence-meta-label">Typical location</div>

            <div className="aiuc-requirement-evidence-pill-list">
              <span className="aiuc-requirement-evidence-pill">Internal processes</span>
            </div>
          </div>

          <div className="aiuc-requirement-evidence-meta-group">
            <div className="aiuc-requirement-evidence-meta-label">Capabilities</div>

            <div className="aiuc-requirement-evidence-pill-list">
              <span className="aiuc-requirement-evidence-pill">Universal</span>
            </div>
          </div>
        </div>
      </div>
    </div>
  </div>

  <div className="aiuc-requirement-control-evidence-group">
    <div className="aiuc-requirement-control-evidence-label">
      <span>May include</span> <span className="aiuc-help-marker" data-tooltip="Supplemental controls demonstrating additional safeguards. Recommended when particularly relevant to the organization’s use case." tabIndex="0">?</span>
    </div>

    <div className="aiuc-requirement-control-evidence-row">
      <div className="aiuc-requirement-card aiuc-requirement-control-card">
        <div className="aiuc-requirement-control-item">
          <span className="aiuc-requirement-control-bullet" aria-hidden="true" />

          <p><strong>Collecting and implementing external feedback on AI systems.</strong> For example, system risks, new threat patterns, new mitigation strategies.</p>
        </div>
      </div>

      <div className="aiuc-requirement-card aiuc-requirement-evidence-card">
        <div className="aiuc-requirement-evidence-title">E008.2 Documentation: External feedback integration</div>
        <p>Documentation showing external feedback collected and implemented - may include external security advisories reviewed, threat intelligence integrated, third-party recommendations adopted, or records of external input incorporated into system improvements.</p>

        <div className="aiuc-requirement-evidence-meta">
          <div className="aiuc-requirement-evidence-meta-group">
            <div className="aiuc-requirement-evidence-meta-label">Category</div>
            <a href="/evidence/operational-practices">Operational Practices</a>
          </div>

          <div className="aiuc-requirement-evidence-meta-group">
            <div className="aiuc-requirement-evidence-meta-label">Typical location</div>

            <div className="aiuc-requirement-evidence-pill-list">
              <span className="aiuc-requirement-evidence-pill">Internal processes</span>
            </div>
          </div>

          <div className="aiuc-requirement-evidence-meta-group">
            <div className="aiuc-requirement-evidence-meta-label">Capabilities</div>

            <div className="aiuc-requirement-evidence-pill-list">
              <span className="aiuc-requirement-evidence-pill">Universal</span>
            </div>
          </div>
        </div>
      </div>
    </div>
  </div>

  <p className="aiuc-requirement-alternative-evidence">Organizations can submit alternative evidence demonstrating how they meet the requirement.</p>
</section>

<div className="aiuc-footer">
  <span className="aiuc-footer-corner aiuc-footer-corner-tl">
    <svg fill="none" stroke="currentColor" strokeWidth="1" viewBox="0 0 12 12" width="12" height="12">
      <line x1="0" x2="12" y1="6" y2="6" />

      <line x1="6" x2="6" y1="0" y2="12" />
    </svg>
  </span>

  <span className="aiuc-footer-corner aiuc-footer-corner-tr">
    <svg fill="none" stroke="currentColor" strokeWidth="1" viewBox="0 0 12 12" width="12" height="12">
      <line x1="0" x2="12" y1="6" y2="6" />

      <line x1="6" x2="6" y1="0" y2="12" />
    </svg>
  </span>

  <div className="aiuc-footer-strip">
    <span className="aiuc-footer-mono">37.782274° N -122.392147° W</span>
    <span className="aiuc-footer-strip-center">FIG. A (SITE INDEX)</span>

    <span />
  </div>

  <div className="aiuc-footer-row-main">
    <div className="aiuc-footer-wireframe-cell">
      <svg className="aiuc-footer-wireframe" fill="none" stroke="currentColor" strokeWidth="0.4" viewBox="0 0 200 150">
        <rect height="130" width="180" x="10" y="10" />

        <rect height="40" width="60" x="20" y="20" />

        <rect height="40" width="40" x="90" y="20" />

        <rect height="40" width="40" x="140" y="20" />

        <rect height="60" width="60" x="20" y="70" />

        <rect height="60" width="90" x="90" y="70" />

        <line strokeDasharray="2,2" x1="20" x2="180" y1="65" y2="65" />

        <line strokeDasharray="2,2" x1="85" x2="85" y1="20" y2="60" />

        <circle cx="50" cy="40" r="6" />

        <circle cx="110" cy="40" r="6" />

        <circle cx="160" cy="40" r="6" />
      </svg>
    </div>

    <div className="aiuc-footer-wordmark-cell">
      <div className="aiuc-footer-wordmark">Artificial Intelligence Underwriting Company</div>
    </div>

    <div className="aiuc-footer-clocks">
      <InlineClock city="SFO" timeZone="America/Los_Angeles" />

      <InlineClock city="NYC" timeZone="America/New_York" />

      <InlineClock city="LON" timeZone="Europe/London" />
    </div>
  </div>

  <div className="aiuc-footer-row-sub">
    <div className="aiuc-footer-codeblock-cell">
      <div className="aiuc-footer-codeblock">
        <span className="aiuc-footer-codeblock-header">Code</span>
        <span className="aiuc-footer-codeblock-header">Structural unit</span>
        <span className="aiuc-footer-codeblock-code">a.</span>
        <span className="aiuc-footer-codeblock-text">AIUC-1 requirements for agent data, privacy, security, safety, reliability, accountability, and societal risk.</span>
        <span className="aiuc-footer-codeblock-code">b.</span>
        <span className="aiuc-footer-codeblock-text">Evidence templates for technical implementation, legal policy, operational practice, and third-party evaluation.</span>
        <span className="aiuc-footer-codeblock-code">c.</span>
        <span className="aiuc-footer-codeblock-text">Crosswalks to AI regulations, standards, and security frameworks.</span>
        <span className="aiuc-footer-codeblock-code">d.</span>
        <span className="aiuc-footer-codeblock-text">Quarterly updates shaped by enterprise adoption, risk, regulation, and community input.</span>
      </div>
    </div>

    <div className="aiuc-footer-columns-cell">
      <div className="aiuc-footer-columns">
        <div>
          <div className="aiuc-footer-column-header">I. Standard</div>

          <ul className="aiuc-footer-column-list">
            <li><a className="aiuc-footer-column-link" href="/">Overview</a></li>
            <li><a className="aiuc-footer-column-link" href="/crosswalks">Crosswalks</a></li>
            <li><a className="aiuc-footer-column-link" href="/evidence">Evidence</a></li>
            <li><a className="aiuc-footer-column-link" href="/changelog">Changelog</a></li>
          </ul>
        </div>

        <div>
          <div className="aiuc-footer-column-header">II. Learn</div>

          <ul className="aiuc-footer-column-list">
            <li><a className="aiuc-footer-column-link" href="/learn/about">About AIUC-1</a></li>
            <li><a className="aiuc-footer-column-link" href="/learn/contribute">Contribute</a></li>
            <li><a className="aiuc-footer-column-link" href="/scoping">Scoping</a></li>
            <li><a className="aiuc-footer-column-link" href="/faq">FAQ</a></li>
          </ul>
        </div>

        <div>
          <div className="aiuc-footer-column-header">III. Office</div>

          <ul className="aiuc-footer-column-list">
            <li><a className="aiuc-footer-column-link" href="/consortium">Consortium</a></li>
            <li><a className="aiuc-footer-column-link" href="/contact">Contact</a></li>
            <li><a className="aiuc-footer-column-link" href="/legal/privacy">Privacy policy</a></li>
            <li><a className="aiuc-footer-column-link" href="/legal/terms">Terms of use</a></li>
          </ul>
        </div>
      </div>
    </div>
  </div>

  <div className="aiuc-footer-strip-bottom">
    <span className="aiuc-footer-mono">100</span>
    <span>© AIUC — ALL RIGHTS RESERVED</span>
  </div>

  <span className="aiuc-footer-corner aiuc-footer-corner-bl">
    <svg fill="none" stroke="currentColor" strokeWidth="1" viewBox="0 0 12 12" width="12" height="12">
      <line x1="0" x2="12" y1="6" y2="6" />

      <line x1="6" x2="6" y1="0" y2="12" />
    </svg>
  </span>

  <span className="aiuc-footer-corner aiuc-footer-corner-br">
    <svg fill="none" stroke="currentColor" strokeWidth="1" viewBox="0 0 12 12" width="12" height="12">
      <line x1="0" x2="12" y1="6" y2="6" />

      <line x1="6" x2="6" y1="0" y2="12" />
    </svg>
  </span>
</div>
