The risk management process and its outcomes are established through transparent policies, procedures, and other controls based on organizational risk priorities.
Summary
The risk management process and its outcomes are established through transparent policies, procedures, and other controls based on organizational risk priorities.
Read the full official text: https://airc.nist.gov/airmf-resources/playbook/
โ Subcategory 1.3
Internal experts who did not serve as front-line developers for the system and/or independent assessors are involved in regular assessments and updates. Domain experts, users, AI actors external to the team that developed or deployed the AI system, and affected communities are consulted in support of assessments as necessary per organizational risk tolerance.
Subcategory 1.4 โ
Negative residual risks (defined as the sum of all unmitigated risks) to both downstream acquirers of AI systems and end users are documented.
Track NIST AI RMF subcategory 1.4 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial