AI risk management¶
Risk management is continuous and covers harm to people, mission, rights, security, privacy, finances, operations, environment, and institutional trust.
Risk factors¶
Assess consequence severity, likelihood, scale, affected populations, vulnerability, autonomy, data sensitivity, model opacity, novelty, reversibility, external exposure, dependency concentration, and ability to detect failure.
Illustrative tiers¶
| Tier | Characteristics | Minimum governance |
|---|---|---|
| 1: Limited | Internal, assistive, reversible, non-sensitive | Owner, inventory, basic testing, monitoring |
| 2: Moderate | Material workflow influence or protected data | Impact assessment, formal controls, review gate |
| 3: High | Consequential outcomes, vulnerable groups, high autonomy | Independent assurance, executive acceptance, intensive monitoring |
| 4: Prohibited | Unlawful, policy-prohibited, or intolerable harm | Prohibit development, procurement, deployment, and use |
Risk treatment¶
Use AI only where needed, and reduce risk through architecture before relying on warnings or user behavior. Record inherent risk, controls, evidence, residual risk, owner, approver, review date, and reassessment triggers.
Triggers include model or supplier change, new data or purpose, performance degradation, incident, regulatory change, population shift, expanded autonomy, and changed deployment environment.