ISO 42001 AI Data Quality Management
Enforce data quality requirements for AI training and inference per ISO 42001 Annex A.7.
About This Policy Template
Policy enforcing ISO/IEC 42001:2023 Annex A.7 data quality controls for AI systems. AI model quality depends entirely on data quality — this policy detects training data without provenance documentation, datasets lacking bias assessments, use of unvalidated data sources for AI decisions, data preparation steps without documentation, and data lineage gaps. Covers A.7.2 (data management), A.7.3 (data quality), A.7.4 (data provenance), and A.7.5 (data preparation). Critical for organizations where AI model integrity and auditability are requirements.
Policy Rules(6)
High Severity
(3)Dataset Without Bias Assessment
Flag datasets used for AI training without documented bias assessment (A.7.3)
Missing Data Provenance Documentation
Detect AI data used without provenance records including source, lineage, and transformations (A.7.4)
Undocumented AI Training Data Source
Detect AI training using data without documented data management procedures (A.7.2)
Medium Severity
(3)Data Lineage Gap in AI Pipeline
Detect data pipeline content that lacks lineage tracking for AI data flows (A.7.4)
Dataset Without Quality Metrics
Flag datasets used for AI without documented quality metrics (A.7.3)
Undocumented Data Preparation Steps
Detect data preparation for AI systems without documented transformation steps (A.7.5)
Enforcement by Integration
What happens when a violation is detected, based on the enforcement mode and integration type.
| Integration | Block | Approval | Warn | Monitor |
|---|---|---|---|---|
Version Control GitHub, GitLab, Bitbucket | Fail check run / merge request status | Pending check run — held for review | Neutral check run / comment on PR | Pass check run (silent) |
Email — Gmail Gmail | Quarantine label; + violation label (outbound) | Quarantine label — held for review | Add warning label | Log only |
Email — Outlook Outlook | Move to quarantine folder; + flag (outbound) | Move to quarantine — held for review | Flag + categorize | Log only |
Messaging Slack, Teams | Post violation warning in channel | Post 'held for review' warning | Post warning in channel | Log only |
Storage Google Drive, Dropbox, OneDrive | Move file to quarantine folder | Quarantine file — held for review | Log only | Log only |
AI Proxy OpenAI, Anthropic, Gemini, MCP, Agent | Block request (return 403) | Hold request — return review ID | Allow request + audit trail | Log only |
API REST API | Return BLOCK outcome (client decides) | Return APPROVAL_REQUIRED + poll URL | Return WARN outcome | Log only |
Version History
1 version published
Initial release
ISO 42001 questionnaire?
Answer ISO 42001 AIMS questions with controls Aguardic enforces
Ready to Install ISO 42001 AI Data Quality Management?
Get started with pre-built governance policies in minutes.