Aligning AI Tools With Risk Management Objectives

Strategic AI Risk Management Resources Available for Download

AI Pulse Survey Vol 3. - From Automation to Autonomy

Explore AI insights and trends in automation and their impact on workforce and operations.

Digital Strategy Oversight Model

Strengthen governance and accelerate decision making with a strategic approach to digital strategy that balances innovation, risk and growth.

Generative AI Questionnaire

Assess your organization’s readiness, strategy and risk management for deploying generative AI with our questionnaire designed to guide effective implementation.

AI Strategies for Risk Management

With the accelerated adoption of AI across all industries, both risk management and internal audit leaders are adopting continuous governance models that are built on pillars such as the NIST AI Risk Management Framework, but are also practical enough to provide value to those organizations rapidly deploying AI models and tools.

While risk management and internal audit leaders have accepted the necessity of deploying new AI models and tools to deliver organizational benefits, many are also drawing attention to AI as a potential source of operational, legal and reputational risk. This sentiment clearly shows in a recent KnowledgeLeader Digital Strategy Oversight Model, where one of the key risks in AI and digital adoption is emotional investment in traditional business models can cause leaders to underestimate the urgency for change.

To ensure that your organization is leveraging AI for efficiency and growth while confronting risks, consider developing a robust AI strategy as a central anchor.

AI Strategy for Risk Management Procedures

Whether you are building an AI risk management strategy for the first time or are revising it to help achieve current organizational goals, leverage a framework that is already in place to build upon, such as the NIST AI RMF and ISO 42001. Consider the following steps to build the AI strategy:

Establish both the mandate and governance

Before drafting any documentation, get executive-level commitment that includes ownership and decision making. Consider forming a steering committee that includes representatives from the business, legal, IT and ERM leadership. This committee will define organizational risk appetite, focus areas, oversight and the approval process for people resources, technology and funds so that risks can be remediated promptly.

Assess the current state

At this stage, the organization will provide an honest assessment of how AI is being used and what is documented about sanctioned tools and models vs. AI tools and models that are either being trialed or have yet to be approved by IT. Create an inventory of AI models, vendors, data sources and their owners from within the organization. Include all tools that are not yet sanctioned to give a complete picture to the steering committee.

Select a framework to structure governance

Most organizations choose a governance framework such as NIST AI RMF, ISO 42001 or a combination of these to create a governance structure. These frameworks are not only well established, but they also will allow your organization to set practices and procedures that auditors and regulators expect. While aspects of these frameworks can remain out of scope and tailored, explaining how adaptations are made will help to explain business-specific controls.

Assess readiness and risk

Determine whether the organization has the foundations to responsibly use AI at the scale required to meet business objectives. Check the quality and availability of data, the maturity of controls and clarity of accountability, especially as it relates to the design, development and operation of AI models throughout their lifecycle. Identify, with the help of the steering committee, where the highest risks sit within the organization so gap analysis and prioritization exercises can take place.

Prioritize use cases to deploy

Select a set of small but high-value pilots that can help the steering committee to understand the feasibility of further deployments. Consider ranking use cases by expected impact, regulatory exposure, operational complexity or how easy it will be to measure results. Make sure that each deployment has clear success criteria, review checkpoints and defined business outcomes that are met before broadening the use of AI to higher-risk use cases.

Once these steps take place, a regular cadence of review, approval and communication out to the organization will follow as new projects and process changes are deployed.

AI Strategy for Risk Management Regulations

While there are several voluntary frameworks, laws and regulations of which to be aware, such as the EU AI Act, GDPR and several U.S. state and sector privacy laws, they are for the most part centered around risk-based governance. There are several themes to consider:

Risk-based classification: Regulators are increasingly grouping AI technology into tiers, such as prohibited, high-risk and limited risk, seeking to apply controls for safety or critical decisions.

Documentation and traceability: Higher-risk AI technology typically requires risk assessments, technical documentation and a clear sense of the purpose of the system, so regulators and auditors can review how the technology works.

Human oversight: Most regulators expect human review for consequential decisions, especially in finance, health and public-sector use cases. According to a recent Protiviti AI Pulse Survey, a semi-autonomous deployment is a practical way forward, as it balances value creation with control.

Security: AI controls are increasingly overlapping with cybersecurity requirements, focusing on incident response and monitoring.

Key regulations and laws

EU AI Act: The first comprehensive legal framework, the EU AI Act, pertains to those organizations that develop, deploy, import or distribute AI in the EU. This act also applies to non-EU companies if their AI systems affect users in the EU. The act centers on a risk-based classification system that splits AI into four regulatory tiers to ensure safety and transparency. The EU AI Act has enforceable controls, where penalties are material.

GDPR: While not new, the General Data Protection Regulation regulates personal data that is used in AI systems. GDPR has global jurisdiction, applying to any organization that processes personal data of people located in the European Economic Area. To abide by GDPR, AI strategy for risk management should address lawful processing, minimizing the use of personal data and maintaining individual rights.

U.S. state/sector rules: While regulations coming out of U.S. states are continuously changing, most organizations should review the California ADMT, which governs how businesses use algorithms and AI to process personal data and to replace human decision making, as well as New York City Local Law 144, which requires bias audits and notices for automated employment decision tools.

AI Strategy for Risk Management Standards

AI-specific risk management standards will help your organization gain proper oversight, accountability, and transparency of the AI systems you have already deployed or are planning to deploy in the future. A common strategy is to tailor common standards and to layer in aspects of others to best suit your organizational risk management needs. As part of this process, consider incorporating our Generative AI Questionnaire that assesses your organization's readiness and strategy for deploying generative AI. This questionnaire can guide effective implementation by identifying potential risks and areas for improvement. There are three standards with which regulators and auditors are most familiar:

NIST AI Risk Management Framework: This voluntary framework is designed to help organizations manage risks associated with AI systems, while also seeking to align outcomes with business objectives. It does this by organizing risk management into four core functions of govern, map, measure and manage, which support risk identification, risk management and risk remediation. This framework is particularly powerful because it can apply across all sectors and industries.

ISO/IEC 23894: This practical risk management standard guides embedding risk management into AI activities, such as development, production, deployment or everyday use. This guidance is often embedded into existing risk management frameworks to define AI risk profiles, including likelihood and impact, mitigation strategies and to manage ongoing AI-related risks.

ISO/IEC 42001: The first international standard to focus specifically on AI, this framework provides a structured way to provide oversight and continuous improvement, so organizations are encouraged to define written policies, assign owners and those responsible and assess risks vs. opportunities from a business perspective. Similar to ISO/IEC 23894, ISO/IEC 42001 is often embedded into existing risk management programs.

AI Strategy for Risk Management Tools

Internal audit and risk management professionals now have access to tools that can be aligned to business use cases, making them very effective. In addition to aligning to business objectives, from a risk management perspective, tools should also be aligned across the risk lifecycle of identification, assessment, response, monitoring and review.

Below are a few tool categories to consider implementing:

  • Enterprise workflow platforms, which centralize risk registers, controls, incidents and compliance tracking
  • Continuous risk monitoring and detection tools, which scan transactions, operations and system activities for unusual aspects or behavior
  • AI governance and risk modeling tools, which can assess model behavior, policy compliance and regulatory exposure
  • Audit and evidence automation tools, which collect proof, map controls to requirements and speed up testing and reporting

AI Strategy Risk Management Practices

When drafting or updating the AI strategy for your organization, there are several best practices to consider.

Establish governance early-on: Executive-level commitment with named owners is essential. Establish a steering committee that leverages current approval processes and escalation paths to enable faster review and approvals for both projects and high-priority items.

AI strategy risk management templates: Use AI strategy templates for regulatory and compliance-driven assessments, and for establishing well-used risk practice functions such as risk registers, RACI matrices and heat maps, to build a more credible structure.

Standardize communication: Use standard risk language and familiar reporting formats so stakeholders can focus on the issues at hand rather than deciphering messaging that may be unclear.

0 Comments