GASP: AICF

Search controls

Search by control ID, name or domain

AIG-025 AI Fairness and Bias Controls

Tier 3+AI

Description

AI systems subject to bias risk (systems that score, rank, recommend, or classify individuals) have documented fairness objectives with measurable definitions (e.g. demographic parity, equalised odds) relative to the system's purpose. Bias testing is conducted prior to deployment and periodically in production, disaggregated by relevant protected characteristics. Where bias is detected above defined thresholds, a remediation action is required before continued deployment. Bias testing methodology and results are retained.

Rationale

Bias is an AI-specific harm that cannot be detected from system logs or security tests alone; it requires dedicated measurement against defined fairness criteria.

Framework Mappings (5)

EU-AI-Art.10.2Data Governance — Data Preparation and Bias Managementfull
EU-AI-Art.15.1Accuracy, Robustness and Cybersecurity — Performance Standardspartial
GDPR-Art.5.1aLawfulness, Fairness and Transparency of Processingpartial
GOVERN 3.1Diverse Team Decision-Makingpartial
MEASURE 2.11AI Fairness and Bias Evaluationfull

Evidence (1)

reportmanual

Bias evaluation report produced before deployment and periodically in production, disaggregated by relevant protected characteristics, with results compared to documented fairness thresholds.

Example: Bias Evaluation Report — Loan Scoring Model v4.1 (Weights & Biases artefact, 2026-Q1), showing demographic parity difference ≤ 0.05 for gender and ethnicity, equalised odds gap ≤ 0.03, comparison to thresholds defined in AI fairness objectives, result: PASS

Test: Request bias evaluation reports for a sample of AI systems subject to bias risk, covering pre-deployment and at least one in-production evaluation. Verify: (1) evaluation is disaggregated by relevant protected characteristics for the system's context, (2) fairness metric definitions match those documented in the AI fairness objectives, (3) results are compared to documented pass/fail thresholds, (4) threshold failures have a documented remediation action and re-evaluation result, (5) production evaluation frequency matches the defined schedule.

Questions (2)

boolean

Do AI systems that score, rank, recommend, or classify individuals have documented fairness objectives with measurable definitions?

Bias cannot be detected without predefined, measurable fairness criteria. Objectives should specify the fairness metric (e.g. demographic parity, equalised odds) and the pass/fail threshold, relative to the system's purpose and affected population.

multi

How is bias testing conducted for AI systems subject to bias risk in your organisation?

Before initial deployment, disaggregated by relevant protected characteristicsPeriodically in production on a defined scheduleUsing pre-specified fairness metrics and pass/fail thresholdsResults are retained and traceable to the deployed model versionThreshold failures require a documented remediation action before continued deployment

All five practices are expected. Bias testing conducted only at deployment without production monitoring misses in-production bias accumulation from feedback loops and data drift.