Phased Implementation Plan

Phase I 0 – 90 days

Main Tasks

  • Approve the standard.
  • Appoint the CAISO.
  • Create the AI register.
  • Define criteria for sensitive / critical AI systems.
  • Enable exception management.
  • Begin the AI literacy programme.
Outcome: Governance core
Phase II 3 – 6 months

Main Tasks

  • Establish risk assessment, DPIA / AI ISA, and pre-deployment gate processes.
  • Integrate AI logs into SOC / SIEM.
  • Create a supplier due-diligence questionnaire.
  • Separate dev / test / prod AI environments.
Outcome: Process control
Phase III 6 – 12 months

Main Tasks

  • Implement AI red teaming.
  • Establish RAG source control.
  • Enforce model versioning discipline.
  • Conduct periodic conformity review.
  • Launch management KPI/KRI reporting.
  • Perform internal audit.
Outcome: Mature compliance and evidence

This standard should be implemented in stages so that governance foundations are established quickly, followed by technical controls, evidence collection, and mature assurance.