AI Risk and Compliance Management involves a strategic framework designed to identify, assess, and mitigate the inherent risks associated with the development and deployment of AI technologies. As organizations increasingly rely on AI systems, it becomes essential to navigate the complexities of compliance with global regulations such as the GDPR and the EU’s AI Act. This framework includes a comprehensive risk assessment process to evaluate potential challenges such as, algorithmic bias, data privacy, and transparency. It ensures that AI systems are developed and used in an ethical and responsible manner. Engaging diverse stakeholders, including ethicists and legal experts, enhances the organization's ability to address the social and ethical implications of AI technologies while fostering a culture of accountability.
- AI System Intake Form to request AI use cases, AI models, and Datasets.
- AI Risk and Compliance Workspace to manage and monitor the risk and compliance posture of AI systems.
- Perform impact assessments (using Smart Assessments) to identify how AI systems, models, and datasets affect fundamental rights.
- New roles and access controls to handle AI Risk and Compliance Management.
- Identify the AI systems from the CMDB by enhancing or leveraging the Entity Filter capability.
- Advanced Risk Assessment (ARA) integration to identify individual and specific risks associated with AI assets, such as AI systems, models, and datasets. Perform separate risk assessments on each identified risk.
- Bulk risk assessment feature enables product owners to assess the regulatory and operational risks of multiple AI use cases in a unified workflow.
- Automatic entity creation and resolution
- Based on the existence of the CMDB AI System record, an entity can be auto-created or resolved to an existing record.
- 360-Relationship View:
- Explore the relationships between critical AI assets that impact your business, including controls, risks, and issues.
- Entity-based access control
- Entity-based access control feature facilitates object access via entities, enabling entity-based access administrators to map entities to specific users or user groups for a granular level of access control.
- Unified content management for AI Risk and Compliance provides a centralized repository of frameworks, citations, risk statements, and control objectives to accelerate adoption of AI Risk and Compliance frameworks.
- Email-driven AI Misuse or Inquiry reporting lets anyone submit AI-related cases and inquiries by email instead of a portal or form, automatically creating trackable records ready for review.
- New
- Implemented EA integration with AI Asset intake process. Business application can be mapped to Asset record.
- Fixed
- Bulk risk assessment creation issue.
- Entity owner default user issue.
- Implemented changes to enable improved security.
Permissions and roles:
- Role required to install the app: System Admin (admin)