Strengthen AI Risk Management Practices
Artificial Intelligence and Risk Management Resources Available for Download:
Cybersecurity Governance and Organizational Resilience: A Framework for Sustainable Risk Management
Learn how to effectively integrate cybersecurity governance with organizational resilience to drive sustainable risk management.
Explore the transformative role of artificial intelligence (AI) in enhancing financial risk management practices within the public sector.
Examine the gap between existing information security risk management tools and the actual needs of practitioners within the air traffic management domain.
AI and Risk Management
AI technology is moving the risk management practice to take advantage of increasing speed, scale and consistency in making risk management decisions. In the not-so-distant past, the use of AI and risk management focused on piloting specific use cases, where today, as broader adoption and use have grown, practical uses and implications are increasingly front and center.
AI is increasingly being used to identify, assess, mitigate, monitor and report on risks in real-time. Compliance automation is growing, especially for mapping controls to regulatory requirements and creating audit-ready evidence.
The downside is that if not properly governed and observed, AI technology can introduce failures such as exposure to private information, bias, gaps in explainability and model drift, which can lead to false positives/negatives and inaccurate predictions.
This is leading many organizations to pair the increased use of AI technology with appropriate governance and controls that are designed to be dynamic and automated as opposed to static and point-in-time. Additionally, standards and regulatory frameworks are being continuously updated to ensure that AI systems are safe, secure and trustworthy.
AI and Risk Management Procedures
Today’s AI risk management procedures are typically designed to act as a framework within the organization that contains several core procedures designed to address the challenges in using AI technologies. These core components make up the foundational aspects of your AI risk management strategy.
A practical approach to organizing and documenting these core procedures is to leverage established resources, like the core iterative activities of governance, mapping, measuring, and managing risks, outlined in our article, Cybersecurity Governance and Organizational Resilience: A Framework for Sustainable Risk Management.
Governance
Governance establishes the policies, roles, escalation paths and accountability needed to manage AI risks across the organization. In practice, this means choosing an owner for each AI or predictive model, defining the approval workflow for all use cases, establishing a procedure for reviewing exceptions, and specifying the required steps for vetting the use of third-party AI tools.
Strong governance means driving a risk-averse culture within the organization by providing training, setting documentation standards, and enabling communication at all levels within the organization to encourage early reporting without consequences.
Mapping
Mapping allows you to understand the AI system in context and to understand why and how data is being used within a specific situation. More specifically, to understand what the system or model does, what data it uses, who or what systems interact with it, and who could be harmed if it fails.
Achieving this level of awareness typically involves taking an inventory of your AI models and systems to identify capabilities, use cases, the lineage of all data vendor dependencies, as well as mapping stakeholders, which involves identifying AI actors who can be developers, deployers and end users, as well as identifying potentially impacted individuals and/or communities.
Measuring
Measurement is when you test the AI system and quantify its behavior against expectations. This involves using tools and techniques to check for aspects such as accuracy, false positives and negatives, fairness, explainability and resilience to adversarial inputs, which measures the AI system's ability to maintain its intended function and performance when deceptive inputs are added.
Measuring extends beyond system and model quality and into the control environment around it. This will mean testing access control, version control and whether override actions are tracked. Additionally, measurements should be repeated after significant data, prompt or model changes.
Managing
When managing risks, you are prioritizing the risks that were found and putting remediation steps or controls in place to reduce the risk and level of exposure. It is at this stage that the team or person who is managing risks for the organization decides whether a use case or process that is run by an AI system or model can proceed, requires a redesign, or needs to be paused to allow for further investigation.
This is typically done by prioritizing and determining a response, even if it is preliminary. Use the risk response planning method to either mitigate, transfer, accept or avoid all risks based on priority and severity.
A strong management process includes not just preventative measures, but the process for recovery and communication needed to restore the model to safe operation.
AI and Risk Management Tools
Consideration of and purchasing tools should be based on solving problems. Ask questions such as:
- Can we approve and govern AI safely?
- Can we prove ongoing control?
- Can this model be attacked or misused?
This will lead you to decide which capabilities are needed. The following are some of the standard capabilities of AI and risk management tools:
Governance and Oversight: These tools provide governance and oversight that enable the organization to decide what is allowed, who the approvers are and how tracking takes place. These tools allow you to register AI use cases, assign owners, record approvals, and generally capture items that can produce an audit trail.
Risk Assessment and Control Mapping: These tools enable the organization to evaluate each AI system against a risk framework. Look for tools that map risks to internal controls as well as regulatory or compliance requirements.
Model Inventory and Lifecycle Management: To keep track of and account for every AI model and version that is currently used by the organization, these tools are a must-have. Look for features such as a model registry, training data lineage, deployment status and change approvals.
Security and Abuse Prevention: These tools enable automated monitoring of threats such as data leakage, prompt injection and unauthorized access. Features to make note of include policy enforcement, runtime guardrails, and personal identifiable information detection.
Compliance and Reporting: To generate AI activity into evidence for auditors and regulators, these tools can provide much-needed assistance. Look for tools that can generate reports, maintain evidence, and show alignment with standard frameworks such as the NIST AI RMF and ISO 42001.
AI and Risk Management Standards
Most organizations leverage recognized AI risk management standards to apply practical controls and strengthen governance. As these standards are adopted, it is important to understand how the frameworks your organization uses align with existing and emerging AI and risk management regulations. These articles, Leveraging Artificial Intelligence (AI) in Public Sector Financial Risk Management: Innovations, Challenges and Future Directions and Information Security Risk Management Tools in the Air Traffic Management Domain: What Are Practitioners’ Needs?, provide additional context on how AI and risk management considerations are evolving across different sectors. Below are several key takeaways to consider:
- Practitioners encounter significant hurdles in implementing ISRM due to limitations of current tools.
- Automation enhances efficiency but should be paired with user support.
- Structured documentation and standardized terminology are vital for clear communication.
AI and Risk Management Practices
AI can strengthen your organization’s risk management program by spotting patterns faster, monitoring continuously, and helping teams to prioritize threats before they grow.
It can also automate repetitive tasks such as collecting evidence, performing control checks and evaluating incoming alerts. Below are several AI and risk management best practices:
- Leverage a formal framework. This gives your risk management program a shared structure for governance, risk identification, measurement and continuous improvement.
- Define risk categories. Common categories include security, operational, compliance and data-related risks.
- Keep humans in the loop for important decisions. AI should assist with screening and prioritization, but important decisions need formal review and escalation.
- Leverage AI governance templates. Use templates that can help you to document important subjects and policies, such as a Responsible AI Policy, an Ethical Usage Policy and templates that can clarify governance roles and responsibilities.
- Make models explainable. Transparent models are easier to defend and explain to auditors, regulators and business leaders.