<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>AIMS Handbook on Rygen Technologies AI Management System Handbook</title><link>https://ai.rygen.com/</link><description>Recent content in AIMS Handbook on Rygen Technologies AI Management System Handbook</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 20 Jan 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://ai.rygen.com/index.xml" rel="self" type="application/rss+xml"/><item><title>AI Policy</title><link>https://ai.rygen.com/policies/ai-001-ai-policy/</link><pubDate>Wed, 27 Aug 2025 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/policies/ai-001-ai-policy/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;This AI Policy establishes Rygen Technologies&amp;rsquo; commitment to building innovative AI systems responsibly. As a logistics technology leader, we recognize AI&amp;rsquo;s transformative potential to revolutionize supply chain efficiency, decision-making, and customer experience. This policy guides our approach to developing, deploying, and governing AI systems while maintaining the highest standards of trust and accountability.&lt;/p&gt;
&lt;h2 id="scope"&gt;Scope&lt;/h2&gt;
&lt;p&gt;Any AI system used or developed by Rygen, and all members of the Rygen team that affect AI systems, are subject to this policy, including:&lt;/p&gt;</description></item><item><title>Charter</title><link>https://ai.rygen.com/leadership/ai-004-ai-management-system-charter/</link><pubDate>Wed, 27 Aug 2025 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/leadership/ai-004-ai-management-system-charter/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;This document formally establishes Rygen Technologies&amp;rsquo; Artificial Intelligence Management System (AIMS) in accordance with ISO/IEC 42001:2023. The AIMS serves as the governance and operational framework to ensure responsible, transparent, and effective development, deployment, and use of AI systems across Rygen&amp;rsquo;s platforms and internal operations.&lt;/p&gt;
&lt;h2 id="scope"&gt;Scope&lt;/h2&gt;
&lt;p&gt;The scope of the AIMS is defined in the &amp;ldquo;Scope of the AIMS&amp;rdquo; document and includes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;All AI-powered features in the TMS and IPaaS&lt;/li&gt;
&lt;li&gt;AI-driven internal tools&lt;/li&gt;
&lt;li&gt;Models and logic built in-house, integrated via third-party APIs, or managed open-source components&lt;/li&gt;
&lt;li&gt;All teams contributing to AI development, deployment, governance, or monitoring&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="objectives-of-the-aims"&gt;Objectives of the AIMS&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ensure AI is developed and used in a trustworthy, safe, and compliant manner&lt;/li&gt;
&lt;li&gt;Align AI practices with business strategy and risk tolerance&lt;/li&gt;
&lt;li&gt;Enable consistent application of policies, risk assessments, and reviews across AI projects&lt;/li&gt;
&lt;li&gt;Support continual improvement through feedback, monitoring, and governance&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="structure-of-the-aims"&gt;Structure of the AIMS&lt;/h2&gt;
&lt;p&gt;The AIMS consists of:&lt;/p&gt;</description></item><item><title>Statement of Applicability</title><link>https://ai.rygen.com/references/ai-022-statement-of-applicability/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/references/ai-022-statement-of-applicability/</guid><description>&lt;h2 id="1-purpose"&gt;1. Purpose&lt;/h2&gt;
&lt;p&gt;This Statement of Applicability (SOA) defines which ISO 42001:2023 Annex A controls are applicable to Rygen&amp;rsquo;s AI Management System (AIMS). It provides:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A complete listing of all Annex A controls&lt;/li&gt;
&lt;li&gt;The applicability determination for each control (Included/Excluded)&lt;/li&gt;
&lt;li&gt;Implementation status for included controls&lt;/li&gt;
&lt;li&gt;Justification for any excluded controls&lt;/li&gt;
&lt;li&gt;Evidence references demonstrating control implementation&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This document fulfils the requirements of ISO 42001:2023 clause 6.1.3f and serves as the formal controlled record for audit purposes.&lt;/p&gt;</description></item><item><title>Scope</title><link>https://ai.rygen.com/leadership/ai-003-aims-scope/</link><pubDate>Fri, 16 Jan 2026 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/leadership/ai-003-aims-scope/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;This document defines the boundaries and applicability of Rygen&amp;rsquo;s AI Management System (AIMS) and specifies which parts of the organization, products, and operations are governed by it.&lt;/p&gt;
&lt;h2 id="scope-statement"&gt;Scope Statement&lt;/h2&gt;
&lt;p&gt;Rygen&amp;rsquo;s AI Management System (AIMS) applies to the AI systems for Logistics SaaS services which Rygen provides.&lt;/p&gt;
&lt;h2 id="scope-exclusions"&gt;Scope Exclusions&lt;/h2&gt;
&lt;p&gt;The following are &lt;strong&gt;out of scope&lt;/strong&gt; for the current AIMS implementation:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Non-AI software modules with no AI dependencies.&lt;/li&gt;
&lt;li&gt;Third-party SaaS services integrated via API but not developed or hosted by Rygen.&lt;/li&gt;
&lt;li&gt;Marketing or experimental prototypes not deployed to production.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;AI systems previously excluded enter the AIMS scope when any of the following occur:&lt;/p&gt;</description></item><item><title>Security Policy</title><link>https://ai.rygen.com/policies/ai-010-security-policy/</link><pubDate>Wed, 27 Aug 2025 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/policies/ai-010-security-policy/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;This policy establishes our systematic approach to securing AI systems and protecting sensitive information throughout the AI lifecycle. It defines security guidelines for AI systems at Rygen Technologies to protect sensitive data, ensure secure AI deployment, and support our compliance requirements.&lt;/p&gt;
&lt;h2 id="scope"&gt;Scope&lt;/h2&gt;
&lt;p&gt;This policy applies to all AI systems and tools used at Rygen:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;X1 Platform AI features&lt;/li&gt;
&lt;li&gt;Corsair TMS AI capabilities&lt;/li&gt;
&lt;li&gt;Internal AI tools and third-party AI services&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="security-framework"&gt;Security Framework&lt;/h2&gt;
&lt;p&gt;We apply defense-in-depth principles to AI systems, ensuring security at every layer from data handling through model deployment and output validation. This multi-layered approach protects both our organization and our clients&amp;rsquo; sensitive information.&lt;/p&gt;</description></item><item><title>Objectives</title><link>https://ai.rygen.com/leadership/ai-002-aims-objectives/</link><pubDate>Wed, 08 Oct 2025 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/leadership/ai-002-aims-objectives/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;This document establishes the measurable objectives for Rygen Technologies&amp;rsquo; AI Management System (AIMS) in accordance with ISO/IEC 42001:2023. These objectives support the &lt;a href="../policies/AI-001-ai-policy.md"&gt;AI Policy&lt;/a&gt; and demonstrate our commitment to responsible, effective, and trustworthy AI deployment.&lt;/p&gt;
&lt;h2 id="scope"&gt;Scope&lt;/h2&gt;
&lt;p&gt;These objectives apply to all AI systems within the AIMS scope, including the X1 Integration Platform, Corsair TMS, and internal AI tools.&lt;/p&gt;
&lt;h2 id="aims-objectives"&gt;AIMS Objectives&lt;/h2&gt;
&lt;h3 id="trustworthy-delivery"&gt;Trustworthy Delivery&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Objective:&lt;/strong&gt; AI systems shall be evaluated for trustworthiness requirements prior to deployment, with explainability and human oversight controls implemented based on risk and impact assessment outcomes for mission-critical systems or decision-support applications.&lt;/p&gt;</description></item><item><title>Communication Policy</title><link>https://ai.rygen.com/policies/ai-007-communication-policy/</link><pubDate>Wed, 27 Aug 2025 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/policies/ai-007-communication-policy/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;This policy establishes how Rygen Technologies communicates about AI systems and the AI Management System (AIMS) with internal and external stakeholders.&lt;/p&gt;
&lt;h2 id="scope"&gt;Scope&lt;/h2&gt;
&lt;p&gt;This policy applies to all AI-related communications including new features, incidents, compliance requirements, and stakeholder feedback across all Rygen platforms and internal operations.&lt;/p&gt;
&lt;h2 id="communication-framework"&gt;Communication Framework&lt;/h2&gt;
&lt;p&gt;We take a measured and responsible approach to communicating our stance toward AI, AI initiatives, AI capabilities, and any issues with the AI systems we deploy. This impacts both internal and external stakeholders, and involves establishing what members of our team communicate, whom they communicate with, when they communicate it, and how the information is communicated.&lt;/p&gt;</description></item><item><title>Roles and Responsibilities</title><link>https://ai.rygen.com/people/ai-005-aims-roles-responsibilities-authorities/</link><pubDate>Wed, 27 Aug 2025 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/people/ai-005-aims-roles-responsibilities-authorities/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;This document defines and communicates the roles, responsibilities, and authorities for the effective implementation, maintenance, and continual improvement of the AI Management System (AIMS) in alignment with ISO/IEC 42001:2023.&lt;/p&gt;
&lt;h2 id="scope"&gt;Scope&lt;/h2&gt;
&lt;p&gt;This responsibility structure applies across all departments involved in the development, deployment, governance, and operation of AI systems at Rygen, including AI capabilities embedded in the Transportation Management System (TMS), the Integration Platform (IPaaS), and internal support tools.&lt;/p&gt;
&lt;h2 id="top-level-responsibility-and-oversight"&gt;Top-Level Responsibility and Oversight&lt;/h2&gt;
&lt;h3 id="principal-ai-engineer--owner-of-the-aims"&gt;Principal AI Engineer – Owner of the AIMS&lt;/h3&gt;
&lt;p&gt;The Principal AI Engineer is accountable for the establishment, implementation, maintenance, and continual improvement of the AIMS. This role is responsible for ensuring that AI systems at Rygen are developed and deployed in accordance with the principles of ethical, transparent, and trustworthy AI as outlined in ISO 42001. Responsibilities include:&lt;/p&gt;</description></item><item><title>Governance Committee</title><link>https://ai.rygen.com/people/ai-019-governance-committee-roles/</link><pubDate>Wed, 27 Aug 2025 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/people/ai-019-governance-committee-roles/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;This document identifies the assigned roles, responsibilities, and authorities of the AI Governance Committee at Rygen Technologies in accordance with ISO/IEC 42001:2023 Clause 5.3. It ensures that responsibilities are clearly allocated and communicated to support the implementation and maintenance of the AI Management System (AIMS).&lt;/p&gt;
&lt;h2 id="scope"&gt;Scope&lt;/h2&gt;
&lt;p&gt;This document applies to all members of the AI Governance Committee involved in the oversight of Rygen&amp;rsquo;s AI Management System and AI-related governance processes.&lt;/p&gt;</description></item><item><title>Acceptable Usage Policy</title><link>https://ai.rygen.com/policies/ai-016-ai-acceptable-usage-policy/</link><pubDate>Wed, 27 Aug 2025 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/policies/ai-016-ai-acceptable-usage-policy/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;This policy establishes guidelines and requirements for the use of artificial intelligence (AI) tools and services within the organization to protect company data, ensure compliance, and maintain security standards.&lt;/p&gt;
&lt;h2 id="scope"&gt;Scope&lt;/h2&gt;
&lt;p&gt;This policy applies to all employees, contractors, and temporary workers who use or wish to use AI tools in connection with their work duties.&lt;/p&gt;
&lt;h2 id="policy-statement"&gt;Policy Statement&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;All AI tools and services not created by Rygen must receive explicit approval before use in any work-related context.&lt;/li&gt;
&lt;li&gt;Only those tools found in the Approved AI Tools list may be used at Rygen, and those tools must be used according to their safe usage constraints.&lt;/li&gt;
&lt;li&gt;AI tools that cannot provide opt-out options for using data for training purposes are prohibited.&lt;/li&gt;
&lt;li&gt;Employees must verify and enable data privacy settings before using any approved AI tool.&lt;/li&gt;
&lt;li&gt;Sensitive company information, such as contact information and payment data, is prohibited from use with any AI tools.&lt;/li&gt;
&lt;li&gt;Company confidential information and proprietary data may only be input into AI tools that have been specifically approved for handling such data and must be used in accordance with any additional security requirements or restrictions specified during the approval process.&lt;/li&gt;
&lt;li&gt;Employees must not connect unauthorized third party AI systems directly to company databases, file systems, or any other information system owned by Rygen.&lt;/li&gt;
&lt;li&gt;Employees must report any potential data breaches or security concerns related to AI tool usage immediately.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="requirements-for-ai-tool-approval"&gt;Requirements for AI Tool Approval&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;The tool must provide clear documentation of its data handling practices.&lt;/li&gt;
&lt;li&gt;The tool must offer the ability to opt out of data collection for training purposes.&lt;/li&gt;
&lt;li&gt;The tool must have enterprise-grade security features.&lt;/li&gt;
&lt;li&gt;The tool must comply with relevant industry regulations and standards.&lt;/li&gt;
&lt;li&gt;The vendor must provide clear terms of service and data processing agreements.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="prohibited-uses"&gt;Prohibited Uses&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Using unapproved AI tools for any work-related purpose.&lt;/li&gt;
&lt;li&gt;Bypassing security settings or data privacy controls.&lt;/li&gt;
&lt;li&gt;Sharing access credentials for AI tools.&lt;/li&gt;
&lt;li&gt;Using unauthorized personal AI accounts for work purposes.&lt;/li&gt;
&lt;li&gt;Uploading sensitive company data to AI tools without explicit authorization.&lt;/li&gt;
&lt;li&gt;Connecting unapproved AI tools directly to company file systems or databases.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="compliance-and-enforcement"&gt;Compliance and Enforcement&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;IT Security will maintain a list of approved AI tools.&lt;/li&gt;
&lt;li&gt;Regular audits will be conducted to ensure compliance.&lt;/li&gt;
&lt;li&gt;Violations may result in disciplinary action.&lt;/li&gt;
&lt;li&gt;All incidents involving unauthorized AI usage must be reported.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="approval-procedure"&gt;Approval Procedure&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Employee submits AI Tool Request Form to IT Security.&lt;/li&gt;
&lt;li&gt;IT Security reviews request and evaluates tool against security requirements.&lt;/li&gt;
&lt;li&gt;Legal reviews terms of service and data processing agreements.&lt;/li&gt;
&lt;li&gt;If approved, IT Security documents configuration requirements.&lt;/li&gt;
&lt;li&gt;Employee receives training on proper tool usage.&lt;/li&gt;
&lt;li&gt;IT Security enables and configures tool access.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;See the AI Tool Approval Procedure for detailed approval steps.&lt;/p&gt;</description></item><item><title>Document Control</title><link>https://ai.rygen.com/processes/ai-006-document-control-procedure/</link><pubDate>Tue, 20 Jan 2026 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/processes/ai-006-document-control-procedure/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;This procedure establishes requirements for the control of documents within the the Rygen AI Management System.&lt;/p&gt;
&lt;h2 id="scope"&gt;Scope&lt;/h2&gt;
&lt;p&gt;This procedure applies to all AIMS documents including policies, procedures, records, and forms. The specific identification and formatting rules in Section 3.1 apply to core governance documents classified as the AIMS Handbook (e.g., policies, procedures, processes). Other records (e.g., risk assessments, meeting minutes) must be identifiable and controlled, but may follow tooling-specific formats.&lt;/p&gt;</description></item><item><title>Risk Management</title><link>https://ai.rygen.com/processes/ai-008-ai-risk-management-framework/</link><pubDate>Tue, 28 Oct 2025 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/processes/ai-008-ai-risk-management-framework/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;This document establishes the framework for identifying, assessing, evaluating, and treating risks within Rygen Technologies&amp;rsquo; AI Management System (AIMS), in accordance with ISO 42001, which ensures that AI risks are addressed systematically, ensuring responsible AI delivery that our stakeholders can depend on.&lt;/p&gt;
&lt;h2 id="scope"&gt;Scope&lt;/h2&gt;
&lt;p&gt;This framework applies to all AI systems within the AIMS scope, personnel involved in the AI system development lifecycle, and all risk assessments (initial, periodic, or trigger-based).&lt;/p&gt;</description></item><item><title>Impact Assessment</title><link>https://ai.rygen.com/processes/ai-009-ai-system-impact-assessment-process/</link><pubDate>Tue, 13 Jan 2026 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/processes/ai-009-ai-system-impact-assessment-process/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;This process ensures we systematically evaluate how AI systems affect the people and organizations that interact with them, enabling informed decision-making and responsible AI deployment. It defines the process for assessing potential positive and negative impacts to ensure that affected parties are considered and appropriate actions can be taken to capitalize on positive impacts while mitigating negative ones.&lt;/p&gt;
&lt;h2 id="scope"&gt;Scope&lt;/h2&gt;
&lt;p&gt;This process to all AI systems built or used by Rygen, including:&lt;/p&gt;</description></item><item><title>Data Management</title><link>https://ai.rygen.com/processes/ai-011-ai-data-management-procedure/</link><pubDate>Wed, 27 Aug 2025 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/processes/ai-011-ai-data-management-procedure/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;This document establishes Rygen Technologies&amp;rsquo; AI Data Management Process in accordance with ISO/IEC 42001:2023 Section B.7. It ensures that data used in AI systems is properly acquired, validated, documented, and maintained throughout the AI system lifecycle.&lt;/p&gt;
&lt;h2 id="scope"&gt;Scope&lt;/h2&gt;
&lt;p&gt;This process applies to all data used within the AIMS scope:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Training data for custom ML models&lt;/li&gt;
&lt;li&gt;Validation and test data&lt;/li&gt;
&lt;li&gt;Production/operational data&lt;/li&gt;
&lt;li&gt;Data transmitted to/from third-party AI APIs&lt;/li&gt;
&lt;li&gt;Internal data used with internal AI tools&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="applicability-by-system-type"&gt;Applicability by System Type&lt;/h2&gt;
&lt;p&gt;This procedure applies to all AI systems within the AIMS scope, but deliverable requirements differ based on system architecture:&lt;/p&gt;</description></item><item><title>Development Lifecycle</title><link>https://ai.rygen.com/processes/ai-013-ai-system-development-lifecycle/</link><pubDate>Wed, 08 Oct 2025 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/processes/ai-013-ai-system-development-lifecycle/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;This document defines Rygen Technologies&amp;rsquo; AI system development lifecycle, ensuring all AI systems are developed in accordance with ISO/IEC 42001:2023 requirements. It is intended to guide and inform the AI development process from end to end, ensuring that AI systems developed by Rygen are responsible and governed.&lt;/p&gt;
&lt;h2 id="scope"&gt;Scope&lt;/h2&gt;
&lt;p&gt;This lifecycle applies to all AI systems developed or substantially configured by Rygen:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;AI-powered features developed for X1 Platform (IPaaS)&lt;/li&gt;
&lt;li&gt;AI features developed for Corsair (TMS)&lt;/li&gt;
&lt;li&gt;Internal AI tools and automations developed by Rygen&lt;/li&gt;
&lt;li&gt;AI implementations requiring configuration, training, or customization&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="ai-system-development-lifecycle"&gt;AI System Development Lifecycle&lt;/h2&gt;
&lt;pre class="mermaid"&gt;flowchart TD
 A[Problem Definition] --&amp;gt; B{Go / No Go?}
 B --&amp;gt;|No| C[Don&amp;#39;t Implement]
 B --&amp;gt;|Yes| D[Data Collection and Preparation]
 D --&amp;gt; E[Training and Development]
 E --&amp;gt; F[Evaluation]
 F --&amp;gt; G{Acceptable?}
 G --&amp;gt;|No| D
 G --&amp;gt;|Yes| H[Deployment]
 H --&amp;gt; I[Monitoring]
 I --&amp;gt; J[Refinement]
 J --&amp;gt; D&lt;/pre&gt;
&lt;h2 id="development-lifecycle-phases"&gt;Development Lifecycle Phases&lt;/h2&gt;
&lt;h3 id="phase-1-problem-definition"&gt;Phase 1: Problem Definition&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Purpose:&lt;/strong&gt; Define the problem; assess impact and risk; evaluate feasibility; and document system design&lt;/p&gt;</description></item><item><title>Nonconformance</title><link>https://ai.rygen.com/processes/ai-014-nonconformity-corrective-action-procedure/</link><pubDate>Wed, 14 Jan 2026 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/processes/ai-014-nonconformity-corrective-action-procedure/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;This procedure establishes the process for identifying, documenting, investigating, and addressing nonconformities within Rygen&amp;rsquo;s AI Management System (AIMS) to ensure that we systematically identify, analyze, and resolve issues within our AI systems.&lt;/p&gt;
&lt;h2 id="scope"&gt;Scope&lt;/h2&gt;
&lt;p&gt;This procedure applies to all nonconformities related to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;AI systems within AIMS scope (X1, Corsair, internal AI tools)&lt;/li&gt;
&lt;li&gt;AIMS processes and procedures&lt;/li&gt;
&lt;li&gt;AI governance and compliance requirements&lt;/li&gt;
&lt;li&gt;AI system performance, security, or ethical issues&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="definitions"&gt;Definitions&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Nonconformity&lt;/strong&gt;: Failure to fulfill a requirement of the AIMS, including:&lt;/p&gt;</description></item><item><title>Internal Audits</title><link>https://ai.rygen.com/processes/ai-015-internal-audit-procedure/</link><pubDate>Mon, 13 Jan 2025 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/processes/ai-015-internal-audit-procedure/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;This procedure establishes Rygen Technologies&amp;rsquo; internal audit program for the AI Management System (AIMS) in accordance with ISO/IEC 42001:2023 Section 9.2, to provide information on whether the AIMS conforms to organizational requirements and the requirements of the standard, and is effectively implemented and maintained.&lt;/p&gt;
&lt;h2 id="scope"&gt;Scope&lt;/h2&gt;
&lt;p&gt;This procedure applies to all internal audits of the AIMS, covering all processes, activities, and areas within the defined AIMS scope including:&lt;/p&gt;
&lt;p&gt;• AI systems (X1 Platform, Corsair, internal AI tools)
• AIMS processes and procedures
• AI governance activities
• Risk management processes
• All organizational units involved in AI activities&lt;/p&gt;</description></item><item><title>Performance Monitoring</title><link>https://ai.rygen.com/processes/ai-017-performance-monitoring-plan/</link><pubDate>Wed, 08 Oct 2025 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/processes/ai-017-performance-monitoring-plan/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;This plan defines what aspects of the AI Management System (AIMS) are monitored and measured, the methods used, and the frequency of evaluation to ensure continuing suitability, adequacy, and effectiveness per ISO/IEC 42001:2023 Section 9.1.&lt;/p&gt;
&lt;h2 id="scope"&gt;Scope&lt;/h2&gt;
&lt;p&gt;This monitoring plan applies to all components of Rygen&amp;rsquo;s AIMS including:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;AIMS objectives performance&lt;/li&gt;
&lt;li&gt;AI system performance and effectiveness&lt;/li&gt;
&lt;li&gt;Risk management effectiveness&lt;/li&gt;
&lt;li&gt;Process conformity and effectiveness&lt;/li&gt;
&lt;li&gt;Stakeholder satisfaction&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="monitoring-and-measurement-framework"&gt;Monitoring and Measurement Framework&lt;/h2&gt;
&lt;h3 id="aims-objectives-monitoring"&gt;AIMS Objectives Monitoring&lt;/h3&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Objective&lt;/th&gt;
 &lt;th&gt;Metric&lt;/th&gt;
 &lt;th&gt;Target&lt;/th&gt;
 &lt;th&gt;Method&lt;/th&gt;
 &lt;th&gt;Frequency&lt;/th&gt;
 &lt;th&gt;Responsible&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Trustworthy Delivery&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;% AI features with explainability or human oversight controls&lt;/td&gt;
 &lt;td&gt;100%&lt;/td&gt;
 &lt;td&gt;Review system documentation &amp;amp; implementation&lt;/td&gt;
 &lt;td&gt;Quarterly&lt;/td&gt;
 &lt;td&gt;Principal AI Engineer&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Performance Excellence&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;% AI systems meeting performance targets&lt;/td&gt;
 &lt;td&gt;90%&lt;/td&gt;
 &lt;td&gt;Evaluation reports &amp;amp; benchmarking&lt;/td&gt;
 &lt;td&gt;Monthly&lt;/td&gt;
 &lt;td&gt;AI/ML Team&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Responsible AI Governance&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;% completed assessments before deployment&lt;/td&gt;
 &lt;td&gt;100%&lt;/td&gt;
 &lt;td&gt;Risk &amp;amp; impact assessment tracking&lt;/td&gt;
 &lt;td&gt;Per deployment&lt;/td&gt;
 &lt;td&gt;Principal AI Engineer&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Client Value Through Innovation&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;New AI features deployed per year&lt;/td&gt;
 &lt;td&gt;2+&lt;/td&gt;
 &lt;td&gt;Feature deployment tracking&lt;/td&gt;
 &lt;td&gt;Semi-annually&lt;/td&gt;
 &lt;td&gt;Product Manager&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Operational Resilience&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;AI service availability&lt;/td&gt;
 &lt;td&gt;99%&lt;/td&gt;
 &lt;td&gt;System monitoring &amp;amp; incident logs&lt;/td&gt;
 &lt;td&gt;Monthly&lt;/td&gt;
 &lt;td&gt;DevOps Team&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Compliance&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;% compliance with requirements&lt;/td&gt;
 &lt;td&gt;100%&lt;/td&gt;
 &lt;td&gt;Audit results &amp;amp; certification status&lt;/td&gt;
 &lt;td&gt;Quarterly&lt;/td&gt;
 &lt;td&gt;Principal AI Engineer&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="ai-system-performance-monitoring"&gt;AI System Performance Monitoring&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;What is Monitored:&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Management Review</title><link>https://ai.rygen.com/processes/ai-012-management-review-procedure/</link><pubDate>Wed, 27 Aug 2025 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/processes/ai-012-management-review-procedure/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;This procedure ensures systematic, regular evaluation of our AI Management System to maintain its effectiveness and continuous improvement. It establishes the quarterly management review process for Rygen Technologies&amp;rsquo; AI Management System (AIMS) in accordance with ISO/IEC 42001:2023 Section 9.3.&lt;/p&gt;
&lt;h2 id="scope"&gt;Scope&lt;/h2&gt;
&lt;p&gt;This procedure applies to the systematic review of AIMS performance, suitability, adequacy, and effectiveness by top management.&lt;/p&gt;
&lt;h2 id="management-review-framework"&gt;Management Review Framework&lt;/h2&gt;
&lt;p&gt;Regular management reviews ensure our AIMS remains aligned with business objectives, addresses emerging risks, and continuously improves based on performance data and stakeholder feedback. This systematic approach demonstrates our commitment to maintaining effective AI governance at the executive level.&lt;/p&gt;</description></item><item><title>Incident Response</title><link>https://ai.rygen.com/processes/ai-023-ai-incident-response-procedure/</link><pubDate>Tue, 14 Jan 2025 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/processes/ai-023-ai-incident-response-procedure/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;This procedure establishes the framework for responding to incidents involving AI systems within Rygen&amp;rsquo;s AI Management System (AIMS) in accordance with ISO/IEC 42001:2023 Section 8.1 and Annex A.8.4. It ensures AI incidents are properly identified, managed, communicated, and used to improve the AIMS.&lt;/p&gt;
&lt;h2 id="scope"&gt;Scope&lt;/h2&gt;
&lt;p&gt;This procedure applies to all incidents involving AI systems within the AIMS scope:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;X1 Platform AI features&lt;/li&gt;
&lt;li&gt;Corsair TMS AI capabilities&lt;/li&gt;
&lt;li&gt;Internal AI tools and third-party AI services&lt;/li&gt;
&lt;li&gt;AI development and deployment processes&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="ai-incident-types"&gt;AI Incident Types&lt;/h2&gt;
&lt;p&gt;An AI incident is any unplanned event or situation that affects or has the potential to affect:&lt;/p&gt;</description></item><item><title>Approved Tools</title><link>https://ai.rygen.com/references/ai-020-tool-approval-procedure/</link><pubDate>Wed, 27 Aug 2025 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/references/ai-020-tool-approval-procedure/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;This procedure is intended to provide guidance on the process for requesting approval to use AI tools within Rygen.&lt;/p&gt;
&lt;h2 id="scope"&gt;Scope&lt;/h2&gt;
&lt;p&gt;This procedure applies to all the employees at Rygen who use or have access to Rygen&amp;rsquo;s information assets.&lt;/p&gt;
&lt;p&gt;This procedure applies to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Standalone AI tools and platforms&lt;/li&gt;
&lt;li&gt;MCP (Model Context Protocol) connectors used within approved AI tools (e.g., Claude Desktop, ChatGPT)&lt;/li&gt;
&lt;li&gt;AI tool extensions and plugins that process company data&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This procedure does not apply to standard integrations used by approved AI tools (e.g., GitHub, Google Drive, Slack integrations within AI platforms) that are pre-configured by the vendor. These integrations fall under Rygen&amp;rsquo;s general Security Policy and Acceptable Use Policy.&lt;/p&gt;</description></item><item><title>Approved AI Tools List</title><link>https://ai.rygen.com/references/ai-020.1-approved-ai-tools/</link><pubDate>Fri, 21 Feb 2025 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/references/ai-020.1-approved-ai-tools/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;This document lists the AI tools that are approved for use within Rygen, along with constraints for using them safely with company data.&lt;/p&gt;
&lt;h2 id="scope"&gt;Scope&lt;/h2&gt;
&lt;p&gt;These tools can be used safely by any member of the Rygen team, provided they follow the safe usage constraints specified for each tool.&lt;/p&gt;
&lt;h2 id="approved-tools"&gt;Approved Tools&lt;/h2&gt;
&lt;p&gt;The following AI tools have been approved for use within their safe usage constraints.&lt;/p&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Tool&lt;/th&gt;
 &lt;th&gt;Approved By&lt;/th&gt;
 &lt;th&gt;Approved Date&lt;/th&gt;
 &lt;th&gt;Safe Usage Constraints&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;ChatGPT (Plus, Pro, or Teams)&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Chris Broom&lt;/td&gt;
 &lt;td&gt;2025-02-21&lt;/td&gt;
 &lt;td&gt;• Only Plus, Pro, or Teams versions can be used&lt;br&gt;• Free version can be used when following usage policies&lt;br&gt;• Improving the model must be turned off in Data Controls&lt;br&gt;• Do not submit any conversations for review&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Claude (Pro, Max, Teams)&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Chris Broom&lt;/td&gt;
 &lt;td&gt;2025-02-21&lt;/td&gt;
 &lt;td&gt;• Only Pro or Teams versions can be used&lt;br&gt;• Do not submit any conversations for review&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Github Copilot&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Chris Broom&lt;/td&gt;
 &lt;td&gt;2025-02-21&lt;/td&gt;
 &lt;td&gt;• Must use Rygen&amp;rsquo;s organizational account&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Cursor&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Chris Broom&lt;/td&gt;
 &lt;td&gt;2025-02-21&lt;/td&gt;
 &lt;td&gt;• Privacy mode must be enabled&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Cline&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Chris Broom&lt;/td&gt;
 &lt;td&gt;2025-02-21&lt;/td&gt;
 &lt;td&gt;• Must use Rygen-provided API key&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Circleback.ai&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Chris Broom&lt;/td&gt;
 &lt;td&gt;2025-02-21&lt;/td&gt;
 &lt;td&gt;• Be careful of conversations and documents shared&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Google Gemini&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Field Bradley&lt;/td&gt;
 &lt;td&gt;2025-04-01&lt;/td&gt;
 &lt;td&gt;• Only Pro version or built in GCP version can be used, or follow usage policies for free version&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Leapsome&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Field Bradley&lt;/td&gt;
 &lt;td&gt;2025-04-01&lt;/td&gt;
 &lt;td&gt;• Usage following the Leapsome terms and conditions&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Aider&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Field Bradley&lt;/td&gt;
 &lt;td&gt;2025-05-12&lt;/td&gt;
 &lt;td&gt;• Opt out of usage data sharing&lt;br&gt;• Only use approved LLMs&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;n8n&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Field Bradley&lt;/td&gt;
 &lt;td&gt;2025-08-15&lt;/td&gt;
 &lt;td&gt;• Utilize only with approved LLMs&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;Greptile&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Field Bradley&lt;/td&gt;
 &lt;td&gt;2025-11-13&lt;/td&gt;
 &lt;td&gt;• Usage following the Greptile terms and conditions&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="approved-mcp-connectors"&gt;Approved MCP Connectors&lt;/h2&gt;
&lt;p&gt;The following MCP (Model Context Protocol) connectors have been approved for use with Claude Desktop and other compatible AI tools.&lt;/p&gt;</description></item><item><title>Competency Matrix</title><link>https://ai.rygen.com/references/ai-018-competency-matrix/</link><pubDate>Wed, 27 Aug 2025 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/references/ai-018-competency-matrix/</guid><description>&lt;h2 id="purpose"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;This matrix defines the competencies required for roles critical to the AI Management System (AIMS) and identifies how competence is evidenced and maintained.&lt;/p&gt;
&lt;h2 id="competency-requirements"&gt;Competency Requirements&lt;/h2&gt;
&lt;h3 id="principal-ai-engineer"&gt;Principal AI Engineer&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Required Competencies:&lt;/strong&gt;
• ISO 42001 knowledge
• AI/ML expertise
• AI risk management
• AI ethics and governance
• Leadership and communication&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Minimum Evidence:&lt;/strong&gt;
• Advanced degree or equivalent experience
• 5+ years AI/ML experience
• ISO 42001 training certificate
• Current role performance&lt;/p&gt;</description></item><item><title/><link>https://ai.rygen.com/references/ai_tool_request_form/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/references/ai_tool_request_form/</guid><description>&lt;h1 id="ai-tool-request-form"&gt;AI Tool Request Form&lt;/h1&gt;
&lt;h2 id="requestor-information"&gt;Requestor Information&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Name:&lt;/strong&gt;&lt;br&gt;
&lt;strong&gt;Department:&lt;/strong&gt;&lt;br&gt;
&lt;strong&gt;Role:&lt;/strong&gt;&lt;br&gt;
&lt;strong&gt;Manager:&lt;/strong&gt;&lt;br&gt;
&lt;strong&gt;Date:&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id="tool-information"&gt;Tool Information&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Tool Name:&lt;/strong&gt;&lt;br&gt;
&lt;strong&gt;Vendor:&lt;/strong&gt;&lt;br&gt;
&lt;strong&gt;Website:&lt;/strong&gt;&lt;br&gt;
&lt;strong&gt;Pricing Model:&lt;/strong&gt;&lt;br&gt;
&lt;strong&gt;Number of Required Licenses:&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id="business-justification"&gt;Business Justification&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Primary Purpose:&lt;/strong&gt;&lt;br&gt;
&lt;strong&gt;Expected Benefits:&lt;/strong&gt;&lt;br&gt;
&lt;strong&gt;Alternative Solutions Considered:&lt;/strong&gt;&lt;br&gt;
&lt;strong&gt;Impact if Not Approved:&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id="technical-details"&gt;Technical Details&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Does the tool offer opt-out from data training?&lt;/strong&gt; (Yes/No):&lt;br&gt;
&lt;strong&gt;Data security features:&lt;/strong&gt;&lt;br&gt;
&lt;strong&gt;Required integrations:&lt;/strong&gt;&lt;br&gt;
&lt;strong&gt;Type of data to be processed:&lt;/strong&gt;&lt;br&gt;
&lt;strong&gt;Browser/system requirements:&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id="usage-details"&gt;Usage Details&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Who will use this tool?&lt;/strong&gt;&lt;br&gt;
&lt;strong&gt;What type of data will be processed?&lt;/strong&gt;&lt;br&gt;
&lt;strong&gt;How frequently will it be used?&lt;/strong&gt;&lt;br&gt;
&lt;strong&gt;Required access level:&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Competence and Training</title><link>https://ai.rygen.com/processes/ai-021-aims-training-and-competence-procedure/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://ai.rygen.com/processes/ai-021-aims-training-and-competence-procedure/</guid><description>&lt;h2 id="1-purpose"&gt;1. Purpose&lt;/h2&gt;
&lt;p&gt;This procedure defines the process for ensuring that all personnel with responsibilities within the AI Management System (AIMS) possess the necessary competence to fulfill their roles. It establishes the framework for identifying training needs, delivering training, and maintaining records of competence in accordance with ISO/IEC 42001:2023 Clause 7.2.&lt;/p&gt;
&lt;h2 id="2-scope"&gt;2. Scope&lt;/h2&gt;
&lt;p&gt;This procedure applies to all Rygen employees and contractors whose roles and responsibilities are defined within the AIMS. It covers general AIMS awareness training for all staff and role-specific competence training for personnel with direct involvement in AI system development, oversight, or governance.&lt;/p&gt;</description></item></channel></rss>