// Level 3 · Controls

Govern

Cultivate a culture of AI risk management.

GOVERN-1.1High

Legal and Regulatory Requirements

Legal and regulatory requirements involving AI are understood, managed, and documented.

GOVERN-1.2High

Trustworthy AI Characteristics

The characteristics of trustworthy AI are integrated into organizational policies, processes, and procedures.

GOVERN-1.3High

Risk Tolerance

Processes are in place to determine the needed level of risk management activities based on organization's risk tolerance.

GOVERN-1.4High

Risk Management Processes

The risk management process and its outcomes are established through transparent policies, procedures, and other controls.

GOVERN-1.5Medium

Ongoing Monitoring & Review

Ongoing monitoring and periodic review of the risk management process and its outcomes are planned.

GOVERN-1.6Medium

Inventory

Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities.

GOVERN-1.7Medium

Decommissioning

Processes and procedures are in place for decommissioning and phasing out AI systems safely.

GOVERN-2.1High

Roles, Responsibilities, Authorities

Roles, responsibilities, and lines of communication related to mapping, measuring, and managing AI risks are documented.

GOVERN-2.2Medium

AI Risk Training

The organization's personnel and partners receive AI risk management training.

GOVERN-2.3High

Executive Leadership

Executive leadership of the organization takes responsibility for decisions about risks associated with AI development and deployment.

GOVERN-3.1Medium

Diversity, Equity, Inclusion

Decision-making related to mapping, measuring, and managing AI risks throughout the lifecycle is informed by a diverse team.

GOVERN-3.2High

Human-AI Configurations

Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight.

GOVERN-4.1Medium

Risk-Aware Culture

Organizational policies and practices are in place to foster a critical thinking and safety-first mindset.

GOVERN-4.2Medium

Documentation Practices

Organizational teams document the risks and potential impacts of the AI technology they design, develop, deploy, evaluate, and use.

GOVERN-4.3Medium

Testing Disclosure

Organizational practices are in place to enable AI testing, identification of incidents, and information sharing.

GOVERN-5.1Medium

External Stakeholder Engagement

Organizational policies and practices are in place to collect, consider, prioritize, and integrate feedback from external parties.

GOVERN-5.2Medium

Communication of AI Decisions

Mechanisms are established to enable AI actors to regularly incorporate adjudicated feedback from relevant stakeholders.

GOVERN-6.1High

Third-Party Risks

Policies and procedures are in place to address AI risks and benefits arising from third-party software and data.

GOVERN-6.2High

Contingency Processes

Contingency processes are in place to handle failures or incidents in third-party data or AI systems.