{"schema_version":"ICEQC_NEWS_ARTICLE_V1","id":"iceqc-news-1865193635944418","slug":"2024-10-24-institutional-controls-under-risk-based-artificial-intelligence-regulation-defining-responsibilities-and-exc","language":"en","publication_status":"READY_FOR_IMPORT","publication_date":"2024-10-24","last_modified_date":"2024-10-24","title":"Institutional controls under risk-based artificial intelligence regulation","summary":"Sets out the scope, decision criteria and evidential basis relevant to institutional controls under risk-based artificial intelligence regulation.","category":{"code":"STANDARDS_INTERPRETATION","label":"Standards Interpretation"},"article_type":"Standards interpretation","publisher":"International Council for Education Quality Certification (ICEQC)","jurisdictional_scope":"International","historical_reference_basis":"Artificial Intelligence Act entered into force in August 2024","reference_authority":"European Union institutions and relevant national authorities","sections":[{"heading":null,"paragraphs":["The policy and evidence context for institutional controls under risk-based artificial intelligence regulation has been materially shaped by the artificial Intelligence Act entered into force in August 2024. Oversight of institutional controls under risk-based artificial intelligence regulation should reflect the principle that interpretation should begin with the intended outcome, then identify the controls and evidence needed to show that the outcome is achieved across the declared scope. Proportionality requires controls sufficient to protect learners without imposing measures unrelated to the identified risk.","The applicability described by the artificial Intelligence Act entered into force in August 2024 changes the implementation context for the assurance question. Entry into force or applicability establishes an operative reference point, but the resulting duties must still be traced to the persons, services and jurisdictions covered. Authorities should distinguish immediate duties from staged provisions, and providers should retain the legal and operational basis for any conclusion about application.","The quality significance of the assurance question follows from a basic distinction between availability and effective provision. A decision concerning the relevant requirement should recognise that technology may support teaching, administration and access, but consequential educational decisions must remain accountable, explainable and open to effective review."]},{"heading":"Scope and application","paragraphs":["The European Union Artificial Intelligence Act entered into force on 1 August 2024. It applies a risk-based framework and includes provisions relevant to certain education and vocational-training uses, particularly systems capable of influencing access, evaluation or progression. Requirements apply according to the Act’s staged timetable. Providers should classify intended uses, identify their role in the supply chain and preserve human oversight, data governance and incident controls.","A focused examination of institutional controls under risk-based artificial intelligence regulation requires a clear analytical discipline. A decision concerning the control should recognise that scope should identify the people, decisions, services, locations and periods to which the arrangement applies. Exclusions require an objective reason and should not be inferred from organisational custom or the absence of an earlier complaint. In relation to institutional controls under risk-based artificial intelligence regulation, an imprecise scope or measure may produce a credible-looking record that does not answer the relevant decision question.","Responsibility for the relevant requirement should be visible at the point where consequential decisions are made. In reviewing the assurance question, the assessment question is whether the control operates across the relevant sites, programmes, delivery modes and learner groups, including material exceptions. Escalation should follow whenever the available record cannot support a safe conclusion for the affected learners."]},{"heading":"Evidence required","paragraphs":["Risk assessment of institutional controls under risk-based artificial intelligence regulation should give particular attention to loss of meaningful human review, unclear responsibility between providers and suppliers, and unverified outputs entering teaching or assessment. A provider should also consider unequal performance across learner groups and automation bias in consequential decisions. Stronger controls are required where learners may not detect an error or where later correction cannot restore the lost opportunity.","Relevant evidence for institutional controls under risk-based artificial intelligence regulation will normally include data provenance and access controls, records of human review and overrides, pre-deployment and periodic performance testing, supplier change and incident records, and documented authority for each consequential use. Evidence outside the relevant period or scope should be identified and given no more weight than its limitations permit. An unresolved contradiction is a limitation on the conclusion and should be reported as such.","Implementation of the stated expectation can be tested without imposing unnecessary reporting. In reviewing the control, responsible bodies should begin with the intended public or educational outcome, map every activity capable of affecting that outcome, and record where responsibility passes between functions or organisations. Test boundary cases before confirming the scope. In relation to institutional controls under risk-based artificial intelligence regulation, the assurance record may draw on existing sources, provided their limitations and fitness for the current purpose are examined."]},{"heading":"Decision criteria and exceptions","paragraphs":["The final record on institutional controls under risk-based artificial intelligence regulation should identify the applicable expectation, the relevant scope, the evidence examined, the sampling basis, material exceptions and the reason for the conclusion. Departure from an illustrative method may be justified where equivalent outcome and evidence are established. No complete conclusion should be recorded while a material evidential limitation remains.","The analysis of the assurance question proceeds on the basis that the volume of documentation is not a measure of conformity. Relevance, integrity and coverage are more important than the number of records produced. Oversight of the stated expectation should reflect the principle that a technical capability is not evidence that a use is educationally justified. Accuracy measured in one setting may not transfer to another population, language, curriculum or decision context. If uncertainty could change a consequential decision, additional evidence or a narrower conclusion is required.","Decisions concerning the relevant requirement should remain traceable to the information available for the stated reference period. The reason for revision should be explicit, including whether it arises from new evidence, a methodological change or a different interpretation.","Public reporting on the stated expectation should distinguish established fact, analytical judgement and planned action. If definitions, coverage or evidence alter an earlier conclusion, the reason should be stated so that revision is not mistaken for changed performance.","The appropriate response to the control is therefore one of controlled implementation and review. Assurance should be withheld for the affected scope until the limitation is resolved."]}],"word_count":882,"content_hash":"sha256-03bec664a52621f8a9a77ab27c5d2f03fcf4d77040ea6608ff484b84766d4388","seo_keywords":["institutional controls under risk-based artificial intelligence regulation","education quality standards","education quality","ICEQC"],"schema_type":"TechArticle"}
