Glossary Governance and evidence
TOMs: technical and organisational measures
Technical and organisational safeguards under Art. 32 GDPR, appropriate to the risk.
What is TOMs: technical and organisational measures?
TOMs are the safeguards with which controllers ensure the security of processing (Art. 32 GDPR): from encryption, access control and logging to training, role concepts and approval processes. They must be appropriate to the risk of the processing.
AI systems add AI-specific measures, such as filter chains against prompt attacks, controls against data leakage through output, and monitoring of model and data changes. A risk analysis assigns every measure to a concrete threat and makes maturity measurable.
Related terms
More terms from the subject area Governance and evidence.
From the term into the substance
The link leads to the place on the website where the term becomes practical; the overview shows every term in the glossary by subject area.
Cite this term
For reports, policies or internal documents; the link leads directly to this term page.
“TOMs: technical and organisational measures”. Versatile AI Risk Assessment, glossary of AI risk analysis, as of September 2026. https://www.versatile-ai-risk-assessment.com/en/wissensbasis/glossary/toms/