AI risk management: a cycle that holds up
AI risk management is the cycle of identifying, assessing, treating and reviewing the risks of each AI use, with criteria defined in advance, controls proportional to impact, named owners and dated evidence. The cycle matters more than the form: risks that are assessed once and never revisited stop reflecting the use.
A simple cycle
The cycle matters more than the template.
- Identify risks from the concrete use and the people affected.
- Assess impact and likelihood with criteria defined before the urgent case.
- Decide treatment: accept, reduce, transfer or do not allow the use.
- Name an owner and a deadline for each control.
- Record evidence and the decision that closed the cycle.
- Reassess on a schedule and whenever something relevant changes.
Risks that are not only technical
Beyond model failure, the scope includes improper purpose, inadequate data handling, missing transparency, vendor dependency and impact on people. Technical and bias evaluations deepen that reading and depend on the data and access available.
Criteria before the rush
Defining decision criteria in advance is what prevents improvised calls when a new use needs to go live quickly.
Frequently asked questions
How do we assess the risk of an AI use?
Through purpose, data involved, people affected, degree of automation in the decision and reversibility of an error, with impact and likelihood criteria defined beforehand.
Who owns the risk?
The area that answers for the use, supported by governance, legal, security and technology. Every control needs a named owner and a review date.