AI Risk Management
What is AI Risk Management?
The process of identifying, assessing, and mitigating risks associated with AI systems. The NIST AI Risk Management Framework provides a structured approach organised around four functions: Govern, Map, Measure, and Manage.
Terms that appear alongside ai risk management
Each of these is named in at least one of the same controls as ai risk management. The number is how many controls name both.
- governance 11 shared controls
- nist 8 shared controls
- ai risk management framework 8 shared controls
- risk management framework 8 shared controls
- ai governance 6 shared controls
- governance framework 6 shared controls
- eu ai act 5 shared controls
- nist ai risk management framework 5 shared controls
Frameworks that govern ai risk management
What the standards actually require on ai risk management
Requirements naming ai risk management across 6 standards, quoted from the control text.
Establish documented AI risk policy stating objectives, scope, roles, criteria, and review cadence.
23894-5.4.2 · AI Risk Management Policy →The organization’s personnel and partners receive AI risk management training to enable them to perform their duties and responsibilities consistent with related policies, procedures, and agreements.
AIRMF-GV-2.2 · The organization's personnel and partners receive AI risk management training to enable them to perform their duties and responsibilities consistent with related policies, procedures, and agreements →A developer/deployer has an affirmative defense if it discovers and cures a violation through internal testing/red-teaming and is otherwise in compliance with the latest NIST AI Risk Management Framework, ISO/IEC 42001, or another nationally/internationally re...
CO-AIA-1705 · Affirmative Defense and Recognised Frameworks →Clauses 8 + 8.1 + 8.2 establish ethical risk management and Clause 10 establishes validation of ethical outcomes. Per public IEEE 7000-2021 abstract + Wikipedia + academic literature (full IEEE text NOT reproduced): ethical risk identification covering: harm t...
IEEE7000-EthicalRisk-Identification-Analysis-Treatment-ValidationOutcomes · IEEE 7000 Clauses 8 + 8.1 + 8.2 - Ethical Risk Identification + Analysis + Treatment + Validation of Ethical Outcomes + AI Safety + Robustness + Adversarial Protection →FTC Safeguards Rule emerging areas in 2024-2025. AI USE IN FINANCIAL INSTITUTIONS: FTC AI guidance + 2024 OMB M-22-09 ZTA + 2024 OMB M-24-08 AI Risk Management + Section 5 FTC Act unfair-and-deceptive enforcement against discriminatory AI + opaque scoring + bi...
FTC-Safeguards-AI-SBOM-Pipeline · AI Use, SBOM, Supply Chain and 2024-2025 Emerging Areas →Florida FDBR crosswalk to comprehensive security + privacy frameworks. NIST CSF 2.0 mapping: GOVERN (FDBR controller responsibilities + DPAs + privacy notice) + IDENTIFY (sensitive data inventory + minors data + voice/facial recognition data) + PROTECT (opt-in...
FDBR-Compliance-Crosswalk-NIST-ISO-SOC · FDBR Crosswalk to NIST CSF, ISO 27001, SOC 2 and Federal/Sectoral Frameworks →Questions people ask about ai risk management
What is AI Risk Management?
Why is AI Risk Management important for compliance?
Which compliance frameworks address AI Risk Management?
Where can I learn more about AI Risk Management?
See how AI Risk Management applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.