Document AI Model and System Characteristics
Create detailed documents about AI models and systems, including their architecture and security risks.
Plain language
This control is about writing down important details about our AI systems, like how they work and the risks they might have. It's important because without this documentation, we could make expensive mistakes or face security issues with our AI models.
Framework
ASD Information Security Manual (ISM)
Control effect
Proactive
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for software developmentOfficial control statement
AI-specific documentation, including AI model cards and AI system cards (or equivalent artefacts), is used to document AI model characteristics, system architectures, use cases and security risks.
Why it matters
Without documenting AI model details and risks, businesses may experience security breaches, financial loss, or reputational damage.
Operational notes
Regularly update AI documentation to reflect system changes and new risks. Ensure all team members can access and understand these documents.
Implementation tips
- System owners should create and maintain AI model cards. To do this, describe the AI model's purpose, how it operates, what data it uses, and potential risks, making sure everything is clear and easy to understand.
- The IT team should document the system architecture. Write down details about how the AI system is set up, including hardware, software, and network components, so everyone knows how the system functions.
- Managers need to review AI system cards with their teams. Schedule regular meetings to discuss these documents, ensuring all team members understand potential security and privacy risks associated with the AI models.
- HR should organise training for staff on AI security risks. Set up workshops to educate employees on recognising and handling any security threats or ethical issues related to AI.
- Procurement should ensure AI systems selected align with documented use cases and security needs. Collaborate with the IT team to evaluate vendors' AI systems against the documented requirements and risks.
Audit / evidence tips
- Askthe AI model cardsLook athow well they explain the model's purpose, operations, data usage, and risks. Good model cards are detailed, easy to read, and updated regularly
- Request the system architecture documentation. Check it includes all relevant hardware, software, and network components. A complete document will show an accurate reflection of the current system setup.
- Askrecords of team review meetings about AI system cardsLook atmeeting notes or minutes that show thorough discussion and understanding. Good notes capture key points and highlight any action items
- Request training attendance records and materials from HR. Check that employees have been trained on AI risks and that training materials cover these risks adequately. Quality training involves practical examples and scenarios.
- Askprocurement criteria and AI system evaluation reports. Examine if they align with documented use cases and security needs. Good practices show a thorough evaluation process documented and followed
Cross-framework mappings
How ISM-2084 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(1)expand_less | ||
| Annex A 8.27 | ISM-2084 requires AI-specific documentation (e.g | |
handshakeSupports(1)expand_less | ||
| Annex A 8.9 | ISM-2084 requires organisations to document AI model characteristics, system architecture, intended use and security risks in AI-specific... | |
linkRelated(1)expand_less | ||
| Annex A 5.8 | Annex A 5.8 requires information security to be integrated into project management so project delivery considers security risks and controls | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Software development
See all Guidelines for software development controls, or browse the full ASD ISM library.