Skip to content
GV.4GovernBaseline

AI risks are registered and reviewed at least annually as part of the organization's risk management process.

Baseline

Applies to every organization that uses AI, regardless of size or sector.

Why

AI systems present unique risks, such as hallucinated or incorrect output that is presented as fact, third-party AI systems training on organizational data, and insufficient access control. In order to effectively manage such risk, it must first be identified and documented.

How

AI risks should be added to existing risk registers and reviewed as part of the organization's existing risk management process. Organizations should review these risks every year at the least.

Sources

  • NIST AI RMF GOVERN 1.3
  • NIST AI RMF GOVERN 1.4
  • NIST AI RMF MAP 1.5
  • NIST AI RMF MANAGE 1.2
  • NIST AI RMF MANAGE 1.3
  • NIST AI RMF MANAGE 2.3
  • NIST AI RMF MEASURE 1.1