// Level 3 · Controls

Map

Establish context to frame AI risks.

MAP-1.1High

Context Established

Intended purposes, potentially beneficial uses, context-specific laws, norms and expectations, and prospective settings in which the AI system will be deployed are understood.

MAP-1.2Medium

Interdisciplinary AI Actors

Interdisciplinary AI actors, competencies, skills, and capacities for establishing context reflect demographic diversity and broad domain and user experience expertise.

MAP-1.3Medium

Mission and Goals

The organization's mission and relevant goals for AI technology are understood and documented.

MAP-1.4Medium

Business Value

The business value or context of business use has been clearly defined.

MAP-1.5Medium

Risk Tolerance

Organizational risk tolerances are determined and documented.

MAP-1.6High

System Requirements

System requirements (e.g., 'the system shall respect the privacy of its users') are elicited from and understood by relevant AI actors.

MAP-2.1Medium

Tasks and AI System Categorization

The specific tasks and methods used to implement them (e.g., classifiers, generative models) are defined.

MAP-2.2High

Knowledge Limits

Information about the AI system's knowledge limits and how system output may be utilized and overseen by humans is documented.

MAP-2.3Medium

Scientific Integrity

Scientific integrity and TEVV considerations are identified and documented.

MAP-3.1Low

Benefits Examination

Potential benefits of intended AI system functionality and performance are examined and documented.

MAP-3.2High

Costs Examined

Potential costs, including non-monetary costs, of AI system errors are examined and documented.

MAP-3.3Medium

Targeted Application Scope

Targeted application scope is specified and documented based on the system's capability.

MAP-3.4Medium

Operator and Practitioner Proficiency

Processes for operator and practitioner proficiency with AI system performance and trustworthiness are defined and documented.

MAP-3.5High

Human Oversight

Processes for human oversight are defined, assessed, and documented in accordance with organizational policies.

MAP-4.1High

Third-Party Mapping

Approaches for mapping AI technology and legal risks of its components — including third-party software and data — are in place.

MAP-4.2High

Internal Risk Controls

Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented.

MAP-5.1High

Likelihood and Magnitude

Likelihood and magnitude of each identified impact (both potentially beneficial and harmful) are identified and documented.

MAP-5.2Medium

Risk Tracking

Practices and personnel for supporting regular engagement with relevant AI actors and integrating feedback are in place and documented.