Skip to content
arrow_back
ISM-2084policyASD Information Security Manual (ISM)

Document AI Model and System Characteristics

Create detailed documents about AI models and systems, including their architecture and security risks.

record_voice_over

Plain language

This control is about writing down important details about our AI systems, like how they work and the risks they might have. It's important because without this documentation, we could make expensive mistakes or face security issues with our AI models.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

AI-specific documentation, including AI model cards and AI system cards (or equivalent artefacts), is used to document AI model characteristics, system architectures, use cases and security risks.
policyASD Information Security Manual (ISM)ISM-2084
priority_high

Why it matters

Without documenting AI model details and risks, businesses may experience security breaches, financial loss, or reputational damage.

settings

Operational notes

Regularly update AI documentation to reflect system changes and new risks. Ensure all team members can access and understand these documents.

build

Implementation tips

  • System owners should create and maintain AI model cards. To do this, describe the AI model's purpose, how it operates, what data it uses, and potential risks, making sure everything is clear and easy to understand.
  • The IT team should document the system architecture. Write down details about how the AI system is set up, including hardware, software, and network components, so everyone knows how the system functions.
  • Managers need to review AI system cards with their teams. Schedule regular meetings to discuss these documents, ensuring all team members understand potential security and privacy risks associated with the AI models.
  • HR should organise training for staff on AI security risks. Set up workshops to educate employees on recognising and handling any security threats or ethical issues related to AI.
  • Procurement should ensure AI systems selected align with documented use cases and security needs. Collaborate with the IT team to evaluate vendors' AI systems against the documented requirements and risks.
fact_check

Audit / evidence tips

  • Askthe AI model cardsLook athow well they explain the model's purpose, operations, data usage, and risks. Good model cards are detailed, easy to read, and updated regularly
  • Request the system architecture documentation. Check it includes all relevant hardware, software, and network components. A complete document will show an accurate reflection of the current system setup.
  • Askrecords of team review meetings about AI system cardsLook atmeeting notes or minutes that show thorough discussion and understanding. Good notes capture key points and highlight any action items
  • Request training attendance records and materials from HR. Check that employees have been trained on AI risks and that training materials cover these risks adequately. Quality training involves practical examples and scenarios.
  • Askprocurement criteria and AI system evaluation reports. Examine if they align with documented use cases and security needs. Good practices show a thorough evaluation process documented and followed
link

Cross-framework mappings

How ISM-2084 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
sync_altPartially overlaps(1)expand_less
Annex A 8.27ISM-2084 requires AI-specific documentation (e.g
handshakeSupports(1)expand_less
Annex A 8.9ISM-2084 requires organisations to document AI model characteristics, system architecture, intended use and security risks in AI-specific...
linkRelated(1)expand_less
Annex A 5.8Annex A 5.8 requires information security to be integrated into project management so project delivery considers security risks and controls

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for software development controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls