This is stage 3 of the implementation roadmap. It establishes a channel to respond to external AI SBOM compliance inquiries (3.7) and assigns responsibility, personnel, and funding to the program (3.8).
This is the multi-page printable view of this section. Click here to print.
Operations
1 - 3.7 Access
This clause is established during Phase 3 — Operations. View the full implementation roadmap
1. Clause Overview
Organizations that exchange AI systems in the supply chain need to verify each other’s compliance. That requires a publicly available channel for external inquiries, and readiness on the organization’s side to respond to them. Access secures both directions.
3.7 requires two things: publicly identifying a means by which a third party can make an AI SBOM compliance inquiry, and maintaining an internal procedure to respond effectively to that inquiry. In AI, AI-specific information — model and dataset licenses, training data provenance, model cards — is added to the subject matter of such inquiries.
2. Required Activities
- Publicly identify a means (e.g., a public email address) by which a third party can make an AI SBOM compliance inquiry.
- Post the public means somewhere externally discoverable, such as a product notice or website.
- Document the internal procedure for receiving, classifying, and responding to external inquiries.
- Define the responsible party and the response deadline.
- Record the history of inquiries and responses.
3. Requirements and Verification Material
| Clause | Requirement (EN) | Verification Material |
|---|---|---|
| 3.7 | Maintain a process to effectively respond to external AI SBOM Compliance inquiries. Publicly identify a means by which a third party can make an AI SBOM Compliance inquiry. | 3.7.1 Publicly visible method that allows any interested parties to make an AI SBOM Compliance inquiry (e.g., via a published contact email address) 3.7.2 An internal documented procedure for responding to third-party AI SBOM Compliance inquiries |
View original English text
3.7 Access Maintain a process to effectively respond to external AI SBOM Compliance inquiries. Publicly identify a means by which a third party can make an AI SBOM Compliance inquiry.
Verification material(s):
- Publicly visible method that allows any interested parties to make an AI SBOM Compliance inquiry (e.g., via a published contact email address).
- An internal documented procedure for responding to third-party AI SBOM Compliance inquiries.
4. Compliance Methods and Samples by Verification Material
3.7.1 Publicly identified means of external inquiry
Compliance Method
Identify a public contact means that anyone can find. A role-based email address (a job function address, not an individual) is stable. Post it in locations such as the product notice, the open source/AI policy page on the company website, or the contact field of the model card. Stating a response deadline alongside it builds trust.
Sample
AI Compliance Inquiries: ai-compliance@company.com
We accept inquiries regarding the components of the AI systems we provide, model and
dataset licenses, and AI SBOMs. We send an initial reply within 14 business days of
receipt.
(Posted at: product notice, company website AI policy page, model card contact field)
3.7.2 Internal inquiry response procedure
Compliance Method
Document the internal procedure from receiving an external inquiry to answering it. Define the stages of intake, classification, assignment, review, reply, and recording, with a deadline for each stage. Because AI SBOM inquiries need to reference model cards or license review records, the AI SBOM verification lead and the license review lead respond together.
The figure below shows the external inquiry response flow.

Figure 1. External AI SBOM compliance inquiry response flow
Considerations
- Set deadlines: Define both an initial reply deadline (e.g., 14 days) and a final answer deadline (e.g., 60 days).
- Protect AI-specific information: Set a standard for how far to disclose sensitive information such as model weights or training data when answering inquiries. Define the boundary between trade secrets and transparency obligations (3.6). ([Recommendation of this guide])
- Retain history: Record the inquiry content, the reply, and the processing time as verification material.
Sample (Response Procedure Outline)
## AI SBOM Compliance Inquiry Response Procedure
1. Intake: Register inquiries received at ai-compliance@.
2. Classification: Classify as AI SBOM request / license inquiry / transparency
obligation inquiry.
3. Assignment: Assign to the AI SBOM verification lead or the license review lead based
on classification.
4. Review and Reply: Reply after checking the relevant AI SBOM and model card. Follow the
disclosure standard for sensitive information. Involve legal review if needed.
5. Record: Retain the inquiry, reply, and processing time.
Deadlines: 14 days for the initial reply, 60 days for the final answer.
5. See Also
- Role and resources of the response lead: 3.8 Effective Resource Allocation
- AI SBOM used in replies: 3.9 AI SBOM
- Disclosure scope and transparency obligations: 3.6 Transparency Obligations
- ISO/IEC 5230 external inquiry example: ISO/IEC 5230 Compliance Guide — 3.2.1 Responding to External Inquiries
2 - 3.8 Effectively Resourced
This clause is built during Phase 3 — Operational Structure. View the full implementation roadmap
1. Clause Overview
If competence (3.2) defines who should be able to do what, effective resourcing is what actually attaches people, time, and budget to those roles so the program runs. When policy and procedures exist only on paper and no resources back them, compliance is a name only.
3.8 requires assigning accountability for program tasks and allocating adequate resources. There are five verification materials, covering the naming of role holders, the provision of staffing and funding, access to legal expertise, an internal responsibility-assignment procedure, and a non-conformance remediation procedure. The specification references the resource-related sections of ISO/IEC 42001 Annex B (B.4.2, B.4.6) and the human oversight determination section (B.9.3).
2. Activities to Perform
- Assign accountability for the successful execution of program tasks.
- Allocate sufficient time and funding to the tasks.
- Make legal expertise on AI SBOM compliance accessible to those who need it.
- Have a procedure for reviewing and updating the policy and its supporting tasks.
- Have a procedure for reviewing and remediating non-conformances.
3. Requirement and Verification Material
| Clause | Requirement | Verification Material |
|---|---|---|
| 3.8 | The organization shall assign accountability for program tasks, allocate sufficient time and funding, and have access to legal expertise and a non-conformance remediation procedure. | 3.8.1 A document identifying the persons, groups, or functions holding program roles 3.8.2 Evidence that identified roles have been staffed and adequately funded 3.8.3 Identification of expertise (internal or external) available to handle AI SBOM compliance matters 3.8.4 A documented procedure for assigning internal responsibility for AI SBOM compliance 3.8.5 A documented procedure for handling the review and remediation of non-conformances |
View original English text
3.8 Effectively resourced Identify and Resource Program Task(s): assign accountability to ensure the successful execution of program tasks; program tasks are sufficiently resourced (time and adequate funding allocated); a process exists for reviewing and updating the policy and supporting tasks; legal expertise pertaining to AI SBOM Compliance is accessible to those who may need such guidance; and a process exists for the resolution of AI SBOM Compliance issues.
Verification material(s):
- Document with name of persons, group or function in program role(s) identified.
- The identified program roles have been properly staffed and adequate funding provided.
- Identification of expertise available to address AI SBOM Compliance matters which could be internal or external.
- A documented procedure that assigns internal responsibilities for AI SBOM Compliance.
- A documented procedure for handling the review and remediation of non-compliant cases.
See, e.g., Sections B.4.2 and B.4.6 of Annex B of ISO/IEC 42001. Section B.9.3 also provides guidance to determine if human resources for human oversight should be incorporated.
4. How to Comply with Each Verification Material, with Samples
3.8.1 Document Identifying Role Holders
How to Comply
Document, by name, the people, groups, or functions holding program roles. Including the job title alongside the name is more stable against personnel changes. The AI SBOM program needs, in addition to the usual open source roles, an AI governance lead, an AI SBOM verification owner, and a model/dataset license review owner.
Sample
| Role | Holder (Job Title) | Contact |
|------|-------------|--------|
| AI Governance Lead | Kim, OO (AI Ethics & Governance Lead) | ai-gov@company.com |
| AI SBOM Verification Owner | Lee, OO (Platform Engineer) | sbom@company.com |
| License Review Owner | Park, OO (Open Source Legal) | oss-legal@company.com |
| Security Owner | Choi, OO (Product Security) | psirt@company.com |
3.8.2 Staffing and Funding
How to Comply
Show that identified roles are actually staffed and that budget has been allocated. Record the time allocation (e.g., 30%) and the basis for the annual budget. AI SBOM compliance takes time for model/dataset review and tool operation, so estimate the per-role time allocation realistically.
Considerations
- State the time allocation: For a shared role, record the percentage of time allocated to AI SBOM work.
- Tool budget: Include the cost of AI SBOM generation/management tools and legal counsel in the budget.
Sample
| Role | Holder | Time Allocation | Annual Budget Basis | Approver / Approval Date |
|------|--------|----------|---------------|--------------|
| AI Governance Lead | Kim, OO | 30% | Personnel cost + regulatory counsel | CTO / 2026-01-15 |
| AI SBOM Verification Owner | Lee, OO | 50% | Personnel cost + tool operation | CTO / 2026-01-15 |
3.8.3 Access to Legal Expertise
How to Comply
Make legal expertise on AI SBOM compliance accessible to those who need it. Because interpreting non-standard licenses and determining regulatory obligations is legal’s job, specify the access path — internal legal counsel or an outside firm. Also define escalation criteria (which matters get escalated to legal).
Sample
- Internal: Open Source Legal Owner (Park, OO) — first-pass license review
- External: XX Law Firm, AI/IP team — non-standard license disputes, regulatory interpretation
- Escalation criteria: a license not on the policy's prohibited/conditional lists, determining
downstream disclosure obligations, matters where new regulation newly applies
3.8.4 Internal Responsibility Assignment Procedure
How to Comply
Document the procedure for assigning internal responsibility for AI SBOM compliance. Vague responsibility leads to gaps, so a RACI matrix distinguishing Responsible (R), Accountable (A), Consulted (C), and Informed (I) per task is effective.
Sample (RACI Matrix)
| Task | AI Governance Lead | AI SBOM Verification Owner | License Review Owner | Security Owner |
|---|---|---|---|---|
| AI SBOM generation | I | R | C | I |
| License obligation review | A | C | R | I |
| Transparency obligation review | A | C | R | I |
| Vulnerability monitoring | I | C | I | R |
| Periodic framework review | R/A | C | C | C |
R Responsible, A Accountable, C Consulted, I Informed
3.8.5 Non-Conformance Review and Remediation Procedure
How to Comply
Have a procedure for reviewing and remediating non-conformances (e.g., a prohibited-license model brought in, a missing AI SBOM, a failure to meet transparency obligations). Vary the handling deadline by severity. In AI, a licensing problem sometimes surfaces after a model has already been deployed, so prepare a remediation path that includes recall or replacement.
Sample (Remediation Procedure and Severity Criteria)
Remediation procedure: identify/report → assess severity → root-cause analysis → corrective
action → recurrence prevention → record
| Severity | Example | Handling Deadline |
|--------|------|----------|
| High | A prohibited-license model is included in a product shipped externally | Immediate response (contain/replace review within 48 hours) |
| Medium | An inbound model is missing from the AI SBOM | Backfill within 7 days |
| Low | Some model card metadata is missing | Handle at the next periodic review |
5. References
- Competence definitions per role: 3.2 Competence
- Governance review linked to non-conformance remediation: 3.10 Governance
- ISO/IEC 5230 resourcing model: ISO/IEC 5230 Compliance Guide — 3.2.2 Effectively Resourced