AI Risk and Compliance Management involves a strategic framework designed to identify, assess, and mitigate the inherent risks associated with the development and deployment of AI technologies. As organizations increasingly rely on AI systems, it becomes essential to navigate the complexities of compliance with global regulations such as the GDPR and the EU’s AI Act. This framework includes a comprehensive risk assessment process to evaluate potential challenges such as, algorithmic bias, data privacy, and transparency. It ensures that AI systems are developed and used in an ethical and responsible manner. Engaging diverse stakeholders, including ethicists and legal experts, enhances the organization's ability to address the social and ethical implications of AI technologies while fostering a culture of accountability.
- AI System Intake Form to request AI use case, AI model, and Datasets.
- AI Risk and Compliance workspace to manage and monitor the risk and compliance posture of AI systems.
- Perform impact assessments (using Smart Assessments) to identify how AI systems, models, and datasets affect fundamental rights.
- New Roles & Access Controls to handle AI Risk and Compliance Management.
- Identify the AI systems from the CMDB by enhancing or leveraging the Entity filter capability.
- Advance Risk Assessment (ARA) integration to identify individual and specific risks associated with AI assets, such as AI systems, models, and datasets. Perform risk assessments on each identified risk separately.
- Bulk risk assessment feature enables product owners to assess the regulatory and operational risks of multiple AI use cases in a unified workflow.
- Auto-creation or resolving entity
- Based on the existence of the CMDB AI System record, an Entity can be auto-created or resolved to an existing record.
- 360-Relationship View:
- Explore the relationships between critical AI assets that impact your business, including controls, risks, and issues.
- Entity based access control
- Implemented Entity based access control feature which facilitates object access via entities. You can map entities to specific users or user groups, enabling you with a granular level of access control.
- Bulk AI Risk Assessments, secure AI Risks and Controls using Entity-based Access Control, Unified Content Management, Email-driven AI Misuse or Inquiry reporting.
- New
- Product Owner Persona (Risk-based Tasks)
AI product owners can now access and act on risk and compliance lifecycle tasks, such as impact assessments and control attestations, from the Task Inbox and Activity Center in AI Control Tower. The Activity Center surfaces AI asset tasks, issues, policy exceptions, and AI cases for this persona. On the asset record page, the Risk and Compliance tab now shows only the Governance widget for product owners; risk assessments and regulatory risk assessments are hidden from the Assessments section, matching the scope of tasks this persona is responsible for. - Continuous Controls Monitoring
Continuous Controls Monitoring helps automate control verification and provide real-time visibility into control health, thereby reducing manual testing. Configure indicators that run on a schedule to evaluate whether a control is compliant or non-compliant. When an indicator fails, an issue is created so that the product owner of the affected asset can remediate it.
- Product Owner Persona (Risk-based Tasks)
- Changed
- As part of MRA Security Enhancements, Strengthened authorization validation within Multiple Record Association (MRA) workflows to improve security and ensure access checks are consistently enforced during record association operations
Permissions and roles:
- Role required to install the app: System Admin (admin)