Safeguarding AI Deployments: Exploring the Power of an Effective Risk Management Framework
The National Institute of Standards and Technology (NIST) has published an Artificial Intelligence Risk Management Framework to provide resources that will help manage AI risks and promote trustworthy and responsible development and use of AI systems.
Artificial Intelligence Risk Management Framework
Among the current standards and best practices, organizations have different approaches to identify and mitigate risks for information systems. However, these methodologies while effective for existing software and infrastructure, do not fully address the risks particular to AI systems. Artificial intelligence faces unique risks that can impact system functionality, security and trustworthiness. The negative impact that can result from this risk exposure has even a farther reach, affecting people and society. The conditions surrounding AI risks are still hard to understand. The complexity of AI systems entails challenges to detect and respond to potential threats and deficiencies. Additionally, the socio-technical aspect of AI is influenced by the mechanics of society and human conduct. Lack of adequate security controls in AI systems can yield unwanted or inaccurate results and cause undesirable conditions for humans. Implementing adequate security controls, aligned with the specific context and industry best practices, can help detect, manage and mitigate the consequences of potential risks occurrence.
In the artificial intelligence landscape, risk can be defined as a measure of an event’s probability (likelihood) of occurring and the magnitude (degree) of its consequences. The impact on AI systems can be positive, (resulting in opportunities for improvement); negative (producing threats), or both. It is critical to include risk management in the development and use of AI systems, if possible, as early as the design phase. Understanding and integrating the potential risks that AI systems could face aligns the system with its proposed purpose. The teams responsible for AI design, development, and deployment need to analyze and integrate in the context of AI impact, which could either affect positively or negatively. This approach to AI risk management can help to increase transparency and trustworthiness.
The National Institute of Standards and Technology (NIST) in collaboration with private and public sectors has developed an Artificial Intelligence Risk Management Framework driven by the National AI Initiative Act of 2020, the National Security Commission on Artificial Intelligence recommendations, and the Plan for Federal Engagement in Developing Technical Standards and Related Tools. The result of this collaboration is the Artificial Intelligence Risk Management Framework (AI RMF) v. 1.0, that contains the AI research, development and evaluation conducted by NIST and the AI community. Released in January 2023 to address the risks and opportunities associated with generative AI , the NIST AI RMF is a roadmap to provide direction to AI actors throughout the AI lifecycle, while identifying and mitigating AI risks. The Frameworks also support trustworthiness and ethical awareness in the use of artificial intelligence.
NIST is not a regulatory agency, but the technical contribution of this Framework can help set the foundation for a globally accepted framework and provide tangible evidence for policymaking. The Framework aims to provide technical specifications and standards that can be integrated as part of future AI regulations. Employing the approach of the Framework can increase trustworthiness in AI systems, and helps promote responsible AI design, development, deployment, and use for organizations and individuals. The adoption of the Framework is voluntary and does not apply to a specific sector use-case or AI context. Diverse types of organizations, irrelevant of size or industry sector, can reap the benefits of following the principles outlined in the AI RMF.
The AI RMF consists of two parts. Part 1 outlines AI risks framing activities and AI Actors roles. The Organization for Economic Co-operation and Development (OECD) define AI Actors as “those who play an active role in the AI system lifecycle, including organizations and individuals that deploy or operate AI” [OECD (2019) Artificial Intelligence in Society - OECD iLibrary]. It also states in this Part that AI risks need to be analyzed and outlines the characteristics of trustworthy AI systems, such as valid, consistent, secure, resilient, accountable, transparent, explainable, interpretable, privacy enhanced, ethically aware and fair in their harmful biases management. Part 2 comprises the core of the AI RMF. The core of the Framework consists of four individual functions to address AI risks. These functions can be summarized as: Govern, Map, Measure, And Manage, which are segmented into categories and subcategories, with their corresponding activities. The Govern function is present throughout the AI risk management process; while the Map, Measure, and Manage functions can be applied depending on the context of the AI system and the stage of the AI lifecycle.
As AI technology progresses, the AI RMF will be updated, expanded, and improved. The global standards landscape, the AI community insight and the lessons learned will also continue to be considered as part of the context of this Framework. NIST will continue to align the AI RMF with applicable international standards, guidelines, and best practices.
The complete Artificial Intelligence Risk Management Framework (AI RMF) v. 1.0 published by NIST in collaboration with the U.S. Department of Commerce and the AI scientific and development community can be accessed here.
If your organization needs to establish a risk management framework to comply with applicable laws and regulations, become more resilient and manage risks in a responsible and trustworthy manner, you can download the free template AI Risk Management Framework to guide your organization in an efficient implementation of a AI risk management program. This document has been created by an IT Auditor, specializing in security and privacy with more that 20 years of experience. This guide is based on the Artificial Intelligence NIST Risk Management Framework (AI RMF) v. 1.0, ISO/IEC 27001:2022 and ISO/IEC 27018:2019.
_______________
References
AI Risk Management Framework. NIST. (2023a, March 30). https://www.nist.gov/itl/ai-risk-management-framework
OECD. (2022, February 22). OECD framework for the classification of AI Systems. OECD iLibrary. https://www.oecd-ilibrary.org/science-and-technology/oecd-framework-for-the-classification-of-ai-systems_cb6d9eca-en
BSA (2021), Confronting Bias: BSA’s Framework to Build Trust in AI, The Software Alliance, Washington, DC, https://ai.bsa.org/wp-content/uploads/2021/06/2021bsaaibias.pdf. [19]
CISA (2019), National Critical Functions Set, Cybersecurity & Infrastructure Security Agency, Washington, DC, https://www.cisa.gov/national-critical-functions-set. [11]
CoE (2020), The Feasibility Study on AI Legal Framework Adopted by the CAHAI, Council of Europe, Strasbourg, https://rm.coe.int/cahai-2020-23-final-eng-feasibility-study- /1680a0c6da.
ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection - Information security management systems - Requirements
ISO/IEC 27018:2019 Information technology - Security techniques - Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors
NIST, 1.0 Artificial Intelligence Risk Management Framework (AI RMF 1.0) (2023).
Disclaimer: The views and opinions expressed in this blog post are solely those of the author and do not necessarily reflect the official policy or position of NIST (National Institute of Standards and Technology), ISO (International Organization for Standardization), or the Department of Commerce. The author is not affiliated with, nor is representing the opinions or point of view of these organizations. The information provided in this blog post is for informational purposes only and should not be considered as professional advice. Readers are encouraged to conduct further research and consult with relevant experts or authorities for specific guidance and recommendations.