AI risks are registered and reviewed at least annually as part of the organization's risk management process.
Baseline
Applies to every organization that uses AI, regardless of size or sector.
Why
AI systems present unique risks, such as hallucinated or incorrect output that is presented as fact, third-party AI systems training on organizational data, and insufficient access control. In order to effectively manage such risk, it must first be identified and documented.
How
AI risks should be added to existing risk registers and reviewed as part of the organization's existing risk management process. Organizations should review these risks every year at the least.
Sources
- NIST AI RMF GOVERN 1.3
- NIST AI RMF GOVERN 1.4
- NIST AI RMF MAP 1.5
- NIST AI RMF MANAGE 1.2
- NIST AI RMF MANAGE 1.3
- NIST AI RMF MANAGE 2.3
- NIST AI RMF MEASURE 1.1