This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

Operations

The stage of establishing a channel to respond to external compliance inquiries and assigning responsibility and resources to the program.

This is stage 3 of the implementation roadmap. It establishes a channel to respond to external AI SBOM compliance inquiries (3.7) and assigns responsibility, personnel, and funding to the program (3.8).

1 - 3.7 Access

Explains how to publicly identify a means for third parties to make AI SBOM compliance inquiries and the internal procedure for responding to them.

1. Clause Overview

Organizations that exchange AI systems in the supply chain need to verify each other’s compliance. That requires a publicly available channel for external inquiries, and readiness on the organization’s side to respond to them. Access secures both directions.

3.7 requires two things: publicly identifying a means by which a third party can make an AI SBOM compliance inquiry, and maintaining an internal procedure to respond effectively to that inquiry. In AI, AI-specific information — model and dataset licenses, training data provenance, model cards — is added to the subject matter of such inquiries.

2. Required Activities

  • Publicly identify a means (e.g., a public email address) by which a third party can make an AI SBOM compliance inquiry.
  • Post the public means somewhere externally discoverable, such as a product notice or website.
  • Document the internal procedure for receiving, classifying, and responding to external inquiries.
  • Define the responsible party and the response deadline.
  • Record the history of inquiries and responses.

3. Requirements and Verification Material

ClauseRequirement (EN)Verification Material
3.7Maintain a process to effectively respond to external AI SBOM Compliance inquiries. Publicly identify a means by which a third party can make an AI SBOM Compliance inquiry.3.7.1 Publicly visible method that allows any interested parties to make an AI SBOM Compliance inquiry (e.g., via a published contact email address)
3.7.2 An internal documented procedure for responding to third-party AI SBOM Compliance inquiries
View original English text

3.7 Access Maintain a process to effectively respond to external AI SBOM Compliance inquiries. Publicly identify a means by which a third party can make an AI SBOM Compliance inquiry.

Verification material(s):

  • Publicly visible method that allows any interested parties to make an AI SBOM Compliance inquiry (e.g., via a published contact email address).
  • An internal documented procedure for responding to third-party AI SBOM Compliance inquiries.

4. Compliance Methods and Samples by Verification Material

3.7.1 Publicly identified means of external inquiry

Compliance Method

Identify a public contact means that anyone can find. A role-based email address (a job function address, not an individual) is stable. Post it in locations such as the product notice, the open source/AI policy page on the company website, or the contact field of the model card. Stating a response deadline alongside it builds trust.

Sample

AI Compliance Inquiries: ai-compliance@company.com

We accept inquiries regarding the components of the AI systems we provide, model and
dataset licenses, and AI SBOMs. We send an initial reply within 14 business days of
receipt.

(Posted at: product notice, company website AI policy page, model card contact field)

3.7.2 Internal inquiry response procedure

Compliance Method

Document the internal procedure from receiving an external inquiry to answering it. Define the stages of intake, classification, assignment, review, reply, and recording, with a deadline for each stage. Because AI SBOM inquiries need to reference model cards or license review records, the AI SBOM verification lead and the license review lead respond together.

The figure below shows the external inquiry response flow.

A flow that receives an external inquiry, classifies and assigns it, reviews it, determines whether legal review is needed, and replies

Figure 1. External AI SBOM compliance inquiry response flow

Considerations

  • Set deadlines: Define both an initial reply deadline (e.g., 14 days) and a final answer deadline (e.g., 60 days).
  • Protect AI-specific information: Set a standard for how far to disclose sensitive information such as model weights or training data when answering inquiries. Define the boundary between trade secrets and transparency obligations (3.6). ([Recommendation of this guide])
  • Retain history: Record the inquiry content, the reply, and the processing time as verification material.

Sample (Response Procedure Outline)

## AI SBOM Compliance Inquiry Response Procedure

1. Intake: Register inquiries received at ai-compliance@.
2. Classification: Classify as AI SBOM request / license inquiry / transparency
   obligation inquiry.
3. Assignment: Assign to the AI SBOM verification lead or the license review lead based
   on classification.
4. Review and Reply: Reply after checking the relevant AI SBOM and model card. Follow the
   disclosure standard for sensitive information. Involve legal review if needed.
5. Record: Retain the inquiry, reply, and processing time.

Deadlines: 14 days for the initial reply, 60 days for the final answer.

5. See Also

2 - 3.8 Effectively Resourced

Explains how to assign responsibility, staffing, funding, and legal expertise to an AI SBOM compliance program, and how to remediate non-conformances.

1. Clause Overview

If competence (3.2) defines who should be able to do what, effective resourcing is what actually attaches people, time, and budget to those roles so the program runs. When policy and procedures exist only on paper and no resources back them, compliance is a name only.

3.8 requires assigning accountability for program tasks and allocating adequate resources. There are five verification materials, covering the naming of role holders, the provision of staffing and funding, access to legal expertise, an internal responsibility-assignment procedure, and a non-conformance remediation procedure. The specification references the resource-related sections of ISO/IEC 42001 Annex B (B.4.2, B.4.6) and the human oversight determination section (B.9.3).

2. Activities to Perform

  • Assign accountability for the successful execution of program tasks.
  • Allocate sufficient time and funding to the tasks.
  • Make legal expertise on AI SBOM compliance accessible to those who need it.
  • Have a procedure for reviewing and updating the policy and its supporting tasks.
  • Have a procedure for reviewing and remediating non-conformances.

3. Requirement and Verification Material

ClauseRequirementVerification Material
3.8The organization shall assign accountability for program tasks, allocate sufficient time and funding, and have access to legal expertise and a non-conformance remediation procedure.3.8.1 A document identifying the persons, groups, or functions holding program roles
3.8.2 Evidence that identified roles have been staffed and adequately funded
3.8.3 Identification of expertise (internal or external) available to handle AI SBOM compliance matters
3.8.4 A documented procedure for assigning internal responsibility for AI SBOM compliance
3.8.5 A documented procedure for handling the review and remediation of non-conformances
View original English text

3.8 Effectively resourced Identify and Resource Program Task(s): assign accountability to ensure the successful execution of program tasks; program tasks are sufficiently resourced (time and adequate funding allocated); a process exists for reviewing and updating the policy and supporting tasks; legal expertise pertaining to AI SBOM Compliance is accessible to those who may need such guidance; and a process exists for the resolution of AI SBOM Compliance issues.

Verification material(s):

  • Document with name of persons, group or function in program role(s) identified.
  • The identified program roles have been properly staffed and adequate funding provided.
  • Identification of expertise available to address AI SBOM Compliance matters which could be internal or external.
  • A documented procedure that assigns internal responsibilities for AI SBOM Compliance.
  • A documented procedure for handling the review and remediation of non-compliant cases.

See, e.g., Sections B.4.2 and B.4.6 of Annex B of ISO/IEC 42001. Section B.9.3 also provides guidance to determine if human resources for human oversight should be incorporated.

4. How to Comply with Each Verification Material, with Samples

3.8.1 Document Identifying Role Holders

How to Comply

Document, by name, the people, groups, or functions holding program roles. Including the job title alongside the name is more stable against personnel changes. The AI SBOM program needs, in addition to the usual open source roles, an AI governance lead, an AI SBOM verification owner, and a model/dataset license review owner.

Sample

| Role | Holder (Job Title) | Contact |
|------|-------------|--------|
| AI Governance Lead | Kim, OO (AI Ethics & Governance Lead) | ai-gov@company.com |
| AI SBOM Verification Owner | Lee, OO (Platform Engineer) | sbom@company.com |
| License Review Owner | Park, OO (Open Source Legal) | oss-legal@company.com |
| Security Owner | Choi, OO (Product Security) | psirt@company.com |

3.8.2 Staffing and Funding

How to Comply

Show that identified roles are actually staffed and that budget has been allocated. Record the time allocation (e.g., 30%) and the basis for the annual budget. AI SBOM compliance takes time for model/dataset review and tool operation, so estimate the per-role time allocation realistically.

Considerations

  • State the time allocation: For a shared role, record the percentage of time allocated to AI SBOM work.
  • Tool budget: Include the cost of AI SBOM generation/management tools and legal counsel in the budget.

Sample

| Role | Holder | Time Allocation | Annual Budget Basis | Approver / Approval Date |
|------|--------|----------|---------------|--------------|
| AI Governance Lead | Kim, OO | 30% | Personnel cost + regulatory counsel | CTO / 2026-01-15 |
| AI SBOM Verification Owner | Lee, OO | 50% | Personnel cost + tool operation | CTO / 2026-01-15 |

How to Comply

Make legal expertise on AI SBOM compliance accessible to those who need it. Because interpreting non-standard licenses and determining regulatory obligations is legal’s job, specify the access path — internal legal counsel or an outside firm. Also define escalation criteria (which matters get escalated to legal).

Sample

- Internal: Open Source Legal Owner (Park, OO) — first-pass license review
- External: XX Law Firm, AI/IP team — non-standard license disputes, regulatory interpretation
- Escalation criteria: a license not on the policy's prohibited/conditional lists, determining
  downstream disclosure obligations, matters where new regulation newly applies

3.8.4 Internal Responsibility Assignment Procedure

How to Comply

Document the procedure for assigning internal responsibility for AI SBOM compliance. Vague responsibility leads to gaps, so a RACI matrix distinguishing Responsible (R), Accountable (A), Consulted (C), and Informed (I) per task is effective.

Sample (RACI Matrix)

TaskAI Governance LeadAI SBOM Verification OwnerLicense Review OwnerSecurity Owner
AI SBOM generationIRCI
License obligation reviewACRI
Transparency obligation reviewACRI
Vulnerability monitoringICIR
Periodic framework reviewR/ACCC

R Responsible, A Accountable, C Consulted, I Informed


3.8.5 Non-Conformance Review and Remediation Procedure

How to Comply

Have a procedure for reviewing and remediating non-conformances (e.g., a prohibited-license model brought in, a missing AI SBOM, a failure to meet transparency obligations). Vary the handling deadline by severity. In AI, a licensing problem sometimes surfaces after a model has already been deployed, so prepare a remediation path that includes recall or replacement.

Sample (Remediation Procedure and Severity Criteria)

Remediation procedure: identify/report → assess severity → root-cause analysis → corrective
action → recurrence prevention → record

| Severity | Example | Handling Deadline |
|--------|------|----------|
| High | A prohibited-license model is included in a product shipped externally | Immediate response (contain/replace review within 48 hours) |
| Medium | An inbound model is missing from the AI SBOM | Backfill within 7 days |
| Low | Some model card metadata is missing | Handle at the next periodic review |

5. References