# Cloud and AI Approval Procedure | Document information | Value | |-----------------------|------| | Document type | Procedure instruction (VA-11) | | Scope | {{ISMS_SCOPE}} | | Organisation | {{ORG_NAME}} | | Process owner | {{ROLE_ISB}} | | Approved by | {{ROLE_ISB}} | | Version | {{DOC_VERSION}} | | Date | {{DOC_DATE}} | | Status | {{DOC_STATUS}} | ## 1. Purpose This procedure governs the assessment and approval of cloud and AI/GenAI services as well as their permissible use. It operationalises the associated policy ({{LINK:R12}}). ## 2. Scope Applies within the ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}). ## 3. Trigger Request to use a cloud or AI service. ## 4. Inputs - Service description & provider information - Protection need/data classes - Contract/DPA documents ## 5. Process 1. Record the request in {{TOOL_TICKET}} (service, purpose, data classes). 2. Assessment: protection need, data location/EU, tenant separation, exit; for AI, exclusion of training/passing on. 3. Review contract/DPA (for AI: opt-out/enterprise contract, EU AI Act). 4. Approval & inclusion in the approval list ({{TOOL_NAME}}); define permissible data classes. 5. Use & control: human in the loop for AI, periodic review ({{REVIEW_CYCLE}}). ## 6. RACI | # | Step | R (Execution) | A (Accountable) | C (Consulted) | I (Informed) | |---|---------|------------------|------------------|-----------------|----------------| | 1 | Record the request in {{TOOL_TICKET}} (service) | Requester/business unit | {{ROLE_ISB}} | - | - | | 2 | Assessment | {{ROLE_ISB}} | {{ROLE_ISB}} | {{ROLE_IT_LEAD}} | {{ROLE_DPO}} | | 3 | Review contract/DPA (for AI) | {{ROLE_ISB}} | {{ROLE_MANAGEMENT}} | {{ROLE_DPO}} | - | | 4 | Approval & inclusion in the approval list | {{ROLE_ISB}} | {{ROLE_ISB}} | - | Business unit | | 5 | Use & control | Business unit | {{ROLE_ISB}} | - | - | ## 7. Result & evidence Approval decision and approval list in the ISMS tool ({{TOOL_NAME}}); documented permissible data classes. Evidence is referenced in the central evidence register ({{LINK:NACHWEISREGISTER}}). ## 8. Key performance indicators (KPI) - Share of approved vs. used services - Shadow IT findings - Overdue service reviews ## 9. Related documents - Associated policy: {{LINK:R12}} - {{LINK:VA-10}} - Technical security baseline: {{LINK:BASELINE}} - ISA mapping matrix: {{LINK:ISA_MAPPING}}