{
 "source": "CRI Financial Services AI RMF, Risk and Control Matrix v1.0 (9 Feb 2026)",
 "control_objectives": 230,
 "coverage": {
  "oversight": 110,
  "standards": 62,
  "auditability": 131,
  "accountability": 55,
  "drift": 11,
  "authority": 39,
  "identity": 32,
  "systemic": 16
 },
 "unmapped": 18,
 "items": [
  {
   "id": "GV-1.1.1",
   "function": "Govern",
   "name": "AI Legal, Regulatory, and Policy Integration",
   "objective": "The organization identifies, monitors, and integrates applicable laws, regulations, contractual obligations, and sector requirements into policies, procedures, and operations governing AI. This includes updating governance artifacts and aligning operational practices as requirements evolve.",
   "risk": "Regulatory Monitoring Failure",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "standards"
   ]
  },
  {
   "id": "GV-1.1.2",
   "function": "Govern",
   "name": "AI Compliance Responsibilities Management",
   "objective": "The organization clearly assigns, documents, and regularly validates its compliance responsibilities for AI-related legal, regulatory, contractual requirements, and internal organizational AI policies.",
   "risk": "Unclear Compliance Responsibilities",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "accountability"
   ]
  },
  {
   "id": "GV-1.1.3",
   "function": "Govern",
   "name": "AI Compliance Validation Procedures",
   "objective": "The organization establishes and implements procedures to validate AI system compliance with applicable laws, regulations, and organizational policies that incorporate relevant industry standards and guidance. This includes routine audits, impact assessments, risk management activities, and documentation reviews at key stages of the AI lifecycle, with mechanisms to incorporate lessons learned and feedback into ongoing process improvements.",
   "risk": "Insufficient Compliance Validation",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "standards"
   ]
  },
  {
   "id": "GV-1.1.4",
   "function": "Govern",
   "name": "AI Compliance Documentation",
   "objective": "The organization maintains documentation to demonstrate how AI systems comply with applicable laws, regulations, and organizational policies. This documentation includes risk assessments, compliance reviews, audits, corrective actions, and other relevant information generated throughout the AI lifecycle.",
   "risk": "Non-Compliant Documentation",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability"
   ]
  },
  {
   "id": "GV-1.1.5",
   "function": "Govern",
   "name": "Legal Feedback and Change Integration",
   "objective": "The organization establishes an ongoing improvement process with legal experts and relevant stakeholders to ensure that changes in laws and regulations are applied to the AI system, and that changes in the AI system are reviewed by legal for appropriate consideration and integration into risk management processes.",
   "risk": "Lack of Legal Expertise",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight"
   ]
  },
  {
   "id": "GV-1.1.6",
   "function": "Govern",
   "name": "Data Lifecycle and Retention",
   "objective": "The organization ensures that data retention policies, privacy requirements, and legal obligations governing data lifecycle management are integrated into its AI system lifecycle processes. It maintains records of data retention periods, manages data deletion or archiving in compliance with privacy norms, and verifies that training datasets adhere to these policies, especially when data subjects exercise their rights or when legal or privacy obligations change.",
   "risk": "Data Lifecycle Control Gaps",
   "principle": "Privacy-Enhanced",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "GV-1.2.1",
   "function": "Govern",
   "name": "AI Principles and Policy Integration",
   "objective": "The organization defines and documents its own AI Trustworthy Principles, which are then integrated into relevant policies, processes, and practices across key functions (e.g., HR, IT, legal, compliance).",
   "risk": "Undefined AI Trustworthy Principles",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "standards"
   ]
  },
  {
   "id": "GV-1.2.2",
   "function": "Govern",
   "name": "AI Terminology and Scope Glossary",
   "objective": "The organization establishes, maintains, and periodically updates a glossary of AI-related terms and concepts and clearly defines the scope, purpose, and intended/acceptable uses of its AI systems. This information is referenced and reflected consistently across organizational policies, standards, other relevant documentation, and training programs.",
   "risk": "Inconsistent Use of AI Terms",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "standards"
   ]
  },
  {
   "id": "GV-1.2.3",
   "function": "Govern",
   "name": "AI Acceptable Use Policy",
   "objective": "The organization develops and maintains an enterprise-level Acceptable AI Use Policy that outlines the types of AI applications the organization is willing or unwilling to adopt based on its risk appetite and tolerance. This policy is communicated clearly across the organization and, where applicable, supplemented by individual acceptable use guidelines or standards for employees, third parties, and other relevant stakeholders. Periodic reviews ensure alignment with evolving risk considerations and organizational objectives.",
   "risk": "Absent or Unclear AI Use Policy",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "standards"
   ]
  },
  {
   "id": "GV-1.2.4",
   "function": "Govern",
   "name": "AI   Trustworthy Principles Training",
   "objective": "The organization regularly offers tailored training programs to educate relevant staff, including those involved in AI system design, development, deployment, and other related roles, on its AI Trustworthy Principles. These principles encompass legal and regulatory considerations as well as their connection to organizational values. The training programs are regularly reviewed and updated as needed to ensure alignment with organizational objectives and mission.",
   "risk": "Insufficient Training in AI Principles",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "accountability"
   ]
  },
  {
   "id": "GV-1.2.5",
   "function": "Govern",
   "name": "AI Governance and Risk Standards",
   "objective": "The organization's governance policies, risk controls, model testing and validation processes, as well as compliance and enterprise risk management (ERM) frameworks, are updated to include AI-specific considerations. These updates address unique AI system implications (e.g., data quality, provenance, secure handling) throughout the AI lifecycle and enhance the identification, assessment, management, and monitoring of AI risks in alignment with the organization's AI Trustworthy Principles and risk appetite and tolerance.",
   "risk": "Inadequate Coverage of AI in GRC",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "standards"
   ]
  },
  {
   "id": "GV-1.2.6",
   "function": "Govern",
   "name": "AI Model Standards and Validation",
   "objective": "The organization sets standards for experimental design, data quality, and model training, which include documenting assumptions, methods, testing outcomes, data lineage, model versioning, and performance monitoring. These standards also outline processes for regular review, validation, and updates, ensuring models align with the organization's AI Trustworthy Principles throughout their lifecycle.",
   "risk": "Insufficient AI Standards",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "drift",
    "auditability",
    "standards"
   ]
  },
  {
   "id": "GV-1.3.1",
   "function": "Govern",
   "name": "AI Risk Assessment Models",
   "objective": "The organization updates its risk assessment methods, consistent with those in ERM and Model Risk Management, to address the unique risks of AI systems during development, deployment, and operation and evaluate the impact and likelihood of AI-specific risks consistently for a unified view.",
   "risk": "Inadequate AI Risk Assessment",
   "principle": "Accountable & Transparent",
   "marque": []
  },
  {
   "id": "GV-1.3.2",
   "function": "Govern",
   "name": "AI Risk Monitoring and Escalation",
   "objective": "The organization integrates AI-specific considerations into its monitoring, reporting, and escalation processes, aligned with its risk criteria, capacity, and appetite. It establishes or adapts practices based on the AI system’s risk profile to provide effective oversight throughout the AI lifecycle.",
   "risk": "Unintegrated AI Risks",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight"
   ]
  },
  {
   "id": "GV-1.3.3",
   "function": "Govern",
   "name": "AI Impact Measurement Policies",
   "objective": "The organization’s policies describe methods for regularly measuring AI system impact (e.g., outcomes analysis, impact assessments) and impact at key stages of the AI lifecycle. Assessments are triggered by system changes to better identify and evaluate potential risks and effects on stakeholders, business processes, applications, and broader systems.",
   "risk": "Inadequate Impact Measurement",
   "principle": "Accountable & Transparent",
   "marque": []
  },
  {
   "id": "GV-1.3.4",
   "function": "Govern",
   "name": "AI Use Risk Acceptance and Rejection Framework",
   "objective": "The organization has clear policies and decision-making processes, informed by executive leadership, to ensure that AI system use aligns with its defined risk tolerance. These policies outline criteria for identifying and rejecting AI uses that exceed acceptable risk levels as determined by the organization's risk assessment. Decisions to reject an AI system are based on a thorough evaluation of potential risks and impacts, with documentation of the rationale. Rejected uses are reviewed periodically to ensure the organization's risk tolerance remains appropriate and aligned with its overall risk management strategy.",
   "risk": "Risk Tolerance Breach",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "standards"
   ]
  },
  {
   "id": "GV-1.4.1",
   "function": "Govern",
   "name": "AI Risk Management Framework",
   "objective": "The organization establishes policies and documentation practices for AI risk management processes, ensuring transparency and alignment with organizational risk priorities. These policies acknowledge the reality of automatically generated or AI-generated documentation, providing guidance on maintaining accuracy, verifiability, and accountability. They specify roles, responsibilities, and mechanisms for oversight and escalation throughout the AI lifecycle, supported by routine reviews and performance metrics to ensure effective management and continuous improvement.",
   "risk": "Unclear Risk Policies",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "accountability",
    "standards"
   ]
  },
  {
   "id": "GV-1.4.2",
   "function": "Govern",
   "name": "AI Risk Documentation Standards",
   "objective": "The organization establishes documentation requirements in its AI risk management policies and procedures, covering AI system design and implementation, model development (including model type, training data sources and selection criteria, assumptions, and limitations), the justification and rationale of key decisions, the acceptable use of proxies, testing, evaluation, validation, and risk mitigation processes (including methodologies and outcomes), and regular monitoring and change management activities.",
   "risk": "Inconsistent Documentation Requirements",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority",
    "oversight",
    "auditability",
    "standards"
   ]
  },
  {
   "id": "GV-1.4.3",
   "function": "Govern",
   "name": "AI Documentation Repository and Access",
   "objective": "The organization maintains a centralized and accessible repository of AI system documentation, structured to provide relevant AI stakeholders with appropriate access based on their roles and the system’s risk classification. Mechanisms are in place to regularly review the completeness and accuracy of documentation and to maintain readily available information for oversight, audit, and ongoing risk management.",
   "risk": "Inaccessible Documentation Repository",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "accountability",
    "standards"
   ]
  },
  {
   "id": "GV-1.5.1",
   "function": "Govern",
   "name": "AI Performance and Risk Monitoring",
   "objective": "The organization documents its approach for monitoring its existing AI systems for performance and risk issues (including key performance indicators, security events, and other relevant metrics), even if AI is not yet widely adopted. Key personnel are assigned responsibility for monitoring activities, with clearly defined roles, escalation procedures, and reporting mechanisms to provide accountability and timely issue resolution.",
   "risk": "Insufficient AI System Monitoring",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "accountability",
    "standards"
   ]
  },
  {
   "id": "GV-1.5.2",
   "function": "Govern",
   "name": "Periodic AI Risk Management Process Review",
   "objective": "The organization conducts periodic reviews of its AI risk management processes, with frequency and scope based on AI adoption, system risk, and technological change. These reviews include assessment by internal audit or third-line functions and incorporate insights from monitoring activities and incident analyses to drive continuous process and control enhancements.",
   "risk": "Inadequate Risk Process Reviews",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability"
   ]
  },
  {
   "id": "GV-1.5.3",
   "function": "Govern",
   "name": "AI Risk Reporting and Oversight",
   "objective": "The organization’s senior leadership is regularly informed of AI system performance, risks, and risk management review outcomes through defined reporting mechanisms (e.g., reports, dashboards). This oversight aligns AI risk management with overall organizational strategy and risk appetite, enabling timely decisions and prioritized resource allocation.",
   "risk": "Uninformed Leadership",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "accountability"
   ]
  },
  {
   "id": "GV-1.5.4",
   "function": "Govern",
   "name": "Independent AI Risk Management Process Assessment",
   "objective": "The organization utilizes qualified, independent parties (e.g., audit, compliance functions, third parties) to conduct regular, independent assessments of the organization’s AI risk management processes to identify gaps, drive improvements, and optimize the organization's AI risk management capabilities.",
   "risk": "Irregular Independent Assessments",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "GV-1.6.1",
   "function": "Govern",
   "name": "AI Inventory Management",
   "objective": "The organization maintains a regularly updated inventory of its AI systems, including purpose, data sources, responsible personnel, risk ratings, criticality, dependencies, compliance requirements, and decommissioning attributes (e.g., sunset dates, archival procedures, data retention policies). This inventory is regularly updated as new systems are developed, acquired, or retired, enabling the organization to have a current and accurate understanding of its AI landscape, including the lifecycle management of its AI systems. Inventory processes are regularly reviewed to incorporate lessons learned and feedback from operational monitoring.",
   "risk": "Inaccurate AI System Inventory",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "accountability",
    "identity",
    "standards"
   ]
  },
  {
   "id": "GV-1.6.2",
   "function": "Govern",
   "name": "AI Inventory and Data Integration",
   "objective": "The organization integrates the AI system inventory with its technology management and data governance processes to drive consistency and enable cross-functional collaboration. The inventory informs risk management prioritization (e.g., risk assessment documentation, monitoring and mitigation plans, meeting minutes and/or decision logs), with high-risk and mission-critical systems subject to enhanced oversight, control, and reporting.",
   "risk": "Unintegrated AI Inventory",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "identity"
   ]
  },
  {
   "id": "GV-1.6.3",
   "function": "Govern",
   "name": "AI Inventory Integration for Purchased and Shadow Systems",
   "objective": "The organization establishes practices to ensure that AI systems used in purchased products and Shadow IT are identified, documented, and incorporated into its inventory and risk management processes. Procurement procedures require vendors and internal teams to disclose AI components, which are then evaluated for compliance, security, and alignment with organizational risk standards. All such AI systems are tracked throughout their lifecycle to prevent unmanaged risks and gaps.",
   "risk": "Unmanaged Shadow IT",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "identity",
    "standards"
   ]
  },
  {
   "id": "GV-1.6.4",
   "function": "Govern",
   "name": "Risk-Based Inventory Resources",
   "objective": "The organization allocates and sustains resources to create, maintain, and govern the AI Inventory proportionate to the risk of each AI system or activity, ensuring higher-risk entries receive deeper classification, documentation, validation, and oversight throughout their lifecycle.",
   "risk": "Disproportionate Inventory Resource Allocation",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "identity",
    "standards"
   ]
  },
  {
   "id": "GV-1.6.5",
   "function": "Govern",
   "name": "AI Inventory Risk Analysis",
   "objective": "The organization analyzes inventory data to identify common risk patterns, interdependence, and potential cascading effects across AI systems. This portfolio-level risk analysis enables enterprise-wide risk mitigation strategies, optimal resource allocation, and overall risk management effectiveness.",
   "risk": "Unknown Systemic Dependencies",
   "principle": "Accountable & Transparent",
   "marque": [
    "identity",
    "systemic"
   ]
  },
  {
   "id": "GV-1.6.6",
   "function": "Govern",
   "name": "AI Inventory Audits",
   "objective": "The organization conducts regular audits of the AI system inventory to verify completeness, accuracy, and timeliness.",
   "risk": "Irregular Inventory Audits",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "identity"
   ]
  },
  {
   "id": "GV-1.7.1",
   "function": "Govern",
   "name": "AI System Decommissioning Policies and Impact Procedures",
   "objective": "The organization establishes and follows comprehensive policies and procedures for decommissioning AI systems. These explicitly define criteria for retirement based on AI-specific factors (e.g., performance, data quality, regulatory compliance, strategic alignment, and risk tolerance). The decommissioning process incorporates thorough impact assessments to identify and mitigate potential risks such as data loss, operational disruption, and reputational damage. It ensures adequate resources for system transition or replacement, including for critical or revenue-generating systems, and includes provisions for rapid decommissioning in emergencies, supported by automated tools for timely decision-making.",
   "risk": "Inadequate Decommissioning Policies and Procedures",
   "principle": "Accountable & Transparent",
   "marque": [
    "standards"
   ]
  },
  {
   "id": "GV-2.1.1",
   "function": "Govern",
   "name": "AI Risk Management Roles and Responsibilities",
   "objective": "The organization defines and documents key AI risk management roles and responsibilities (e.g., AI system owners, developers, data scientists, risk managers, independent validation, additional second and third line personnel), across levels and functions. It establishes clear expectations, organizational structures for independent oversight, decision-making authority, escalation, and accountability, ensuring a structured, transparent, and accountable approach to AI risk management that aligns with existing organizational practices, industry best practices, and regulatory expectations.",
   "risk": "Undefined Risk Roles",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority",
    "oversight",
    "auditability",
    "accountability"
   ]
  },
  {
   "id": "GV-2.1.2",
   "function": "Govern",
   "name": "AI Risk Communication and Escalation",
   "objective": "The organization establishes clear communication channels, escalation procedures, reporting lines, and decision-making authority for AI risk management, so stakeholders know whom to contact, collaborate with, and rely on for authorized decisions related to AI risks.",
   "risk": "Unclear Communication Channels",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority",
    "oversight",
    "standards"
   ]
  },
  {
   "id": "GV-2.1.3",
   "function": "Govern",
   "name": "Roles and Processes Review/Update",
   "objective": "The organization regularly reviews and updates roles, responsibilities, and communication lines to align with its evolving AI strategy, risk landscape, and industry best practices, utilizing stakeholder consultations and gap analysis.",
   "risk": "Outdated Responsibilities",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "accountability"
   ]
  },
  {
   "id": "GV-2.1.4",
   "function": "Govern",
   "name": "AI Risk Roles in Job and Performance",
   "objective": "The organization embeds AI risk management roles into job descriptions, performance goals, and career development paths, providing relevant personnel with necessary training and support. Additionally, the organization evaluates their performance in these areas.",
   "risk": "Inadequate Integration of AI Risk Roles",
   "principle": "Accountable & Transparent",
   "marque": [
    "accountability"
   ]
  },
  {
   "id": "GV-2.2.1",
   "function": "Govern",
   "name": "AI Risk Management Training and Policies",
   "objective": "The organization provides role-specific AI risk management training to all personnel involved in AI system development, deployment, or use, including executives, decision-makers, and technical staff. This training covers relevant trustworthiness principles, policies, procedures, legal and regulatory requirements, and industry best practices. It emphasizes understanding AI assumptions, limitations, and risks, fostering an informed approach to AI adoption and oversight.",
   "risk": "Insufficient Role Training",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority",
    "oversight",
    "standards"
   ]
  },
  {
   "id": "GV-2.2.2",
   "function": "Govern",
   "name": "Mandatory AI Risk Management Training",
   "objective": "The organization provides role-specific AI risk management training to all personnel involved in AI system development, deployment, or use, including new hires and those transitioning into AI roles. This training covers relevant trustworthiness principles, policies, and legal and regulatory requirements. It emphasizes understanding AI assumptions, limitations, risks, and content provenance, with content lineage and provenance information integrated as a key subcomponent to enhance comprehension of data origin, integrity, and traceability throughout the AI lifecycle. The program incorporates theoretical concepts, practical exercises, and case studies to ensure effective application of knowledge across organizational roles.",
   "risk": "Inadequate AI Training",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority",
    "auditability",
    "accountability"
   ]
  },
  {
   "id": "GV-2.2.3",
   "function": "Govern",
   "name": "AI Training Effectiveness Evaluation",
   "objective": "The organization regularly evaluates the effectiveness of AI risk management training using assessments, employee feedback, and performance metrics. Evaluation results drive insights from monitoring activities and incident management to identify gaps and lessons learned. These findings inform updates to training content, delivery methods, and the overall training program to ensure continued relevance, effectiveness, and alignment with best practices and organizational needs.",
   "risk": "Unevaluated Training Effectiveness",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight"
   ]
  },
  {
   "id": "GV-2.2.4",
   "function": "Govern",
   "name": "Advanced AI Risk Certification Programs",
   "objective": "The organization offers advanced AI risk management training and certification programs for personnel in specialized roles (e.g., executives, data scientists, risk managers). These programs cover advanced topics (e.g., responsible AI design, algorithmic fairness, explainable AI, risk quantification) and develop AI risk management expertise. AI risk management training is integrated into the organization's broader learning and development strategy.",
   "risk": "Insufficient Advanced Training",
   "principle": "Accountable & Transparent",
   "marque": [
    "accountability"
   ]
  },
  {
   "id": "GV-2.3.1",
   "function": "Govern",
   "name": "Leadership Commitment to Responsible AI",
   "objective": "The organization’s executive leadership demonstrates their commitment to responsible AI development and deployment by communicating the importance of AI risk management through town halls, newsletters, public statements, and digital channels. They emphasize the benefits of effective AI risk management, foster open dialogue, and recognize exemplary practices. Additionally, leadership sets clear expectations, defines roles and responsibilities, allocates adequate resources, and holds management accountable to ensure the effective implementation and integration of AI risk management practices across the organization.",
   "risk": "Lack of Executive Commitment",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "accountability"
   ]
  },
  {
   "id": "GV-2.3.2",
   "function": "Govern",
   "name": "AI Risk Appetite and Thresholds",
   "objective": "The organization's executive leadership and/or an oversight board or committee, actively participate in establishing and approving the organization's risk appetite and tolerance thresholds for AI systems. They regularly review and contribute to AI risk management strategies, policies, and performance metrics, and principles, creating alignment with the ERM framework and business objectives.",
   "risk": "Undefined AI Risk Appetite",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "accountability",
    "standards"
   ]
  },
  {
   "id": "GV-2.3.3",
   "function": "Govern",
   "name": "AI Governance Structure",
   "objective": "The organization establishes an AI governance structure, such as a committee with senior leaders from business, technology, risk, and legal. It provides oversight, reviews major AI initiatives, and advises on resources. Over time, this structure evolves toward clearer accountability, potentially involving a senior executive or Chief Model Risk Officer (CMRO) who takes primary responsibility for AI risk, ensuring alignment with existing risk functions like Model Risk Management (MRM).",
   "risk": "Insufficient Governance Structure",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "accountability"
   ]
  },
  {
   "id": "GV-2.3.4",
   "function": "Govern",
   "name": "Board Oversight of AI Risks",
   "objective": "The organization’s board of directors provides independent oversight of AI risk management by reviewing performance, discussing significant AI-related issues, and offering guidance on industry standards and guidelines. The board actively oversees the integration of AI into the organization’s broader strategic objectives, including investment and resource planning, business model evolution, and HR practices related to AI talent. The board ensures that AI considerations are embedded into enterprise-level decision-making, aligning AI initiatives with organizational goals and risk appetite.",
   "risk": "Inadequate Board Oversight",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "accountability",
    "standards"
   ]
  },
  {
   "id": "GV-3.1.1",
   "function": "Govern",
   "name": "Multiple Perspectives in AI Risk Teams",
   "objective": "To minimize risk blind spots and groupthink and represent global or regional stakeholder interests, the organization prioritizes multidisciplinary perspectives in AI risk management decision-making. AI risk management teams are formed considering demographics, disciplines, experience, and backgrounds, actively seeking multiple perspectives.",
   "risk": "Lack of Multidisciplinary Perspectives",
   "principle": "Fair",
   "marque": []
  },
  {
   "id": "GV-3.2.1",
   "function": "Govern",
   "name": "Human-AI Supervision Policies",
   "objective": "The organization develops, periodically reviews, and updates policies and protocols for human involvement, oversight, and disclosure throughout the AI lifecycle. These policies should address risks such as automation complacency, anthropomorphization, and disinformation by including measures to prevent unapproved interactions, promote transparency, and mitigate undue reliance. They should also establish safeguards for human override, communication, and external stakeholder engagement to ensure responsible and aligned AI deployment.",
   "risk": "Inadequate Human Involvement Policies",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "accountability",
    "systemic"
   ]
  },
  {
   "id": "GV-3.2.2",
   "function": "Govern",
   "name": "Monitoring Human-AI Oversight",
   "objective": "The organization implements mechanisms (e.g., audits, performance evaluations, feedback loops) to monitor and assess human-AI interactions, including behavioral risks like automation complacency or inappropriate overreliance. Data collected should inform decision-making and resource allocation, and policies should promote understanding of AI limitations to prevent overreliance. Integration with ongoing monitoring processes should specifically include assessments of how effectively human operators are interacting with and overseeing AI systems, evaluating the quality and outcomes of human-AI collaboration.",
   "risk": "Unaddressed Human-AI Risks",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority",
    "oversight",
    "drift",
    "auditability",
    "systemic"
   ]
  },
  {
   "id": "GV-4.1.1",
   "function": "Govern",
   "name": "AI Trustworthy Principles and Communication",
   "objective": "The organization regularly reviews AI Trustworthy Principles prioritizing safety, critical thinking, and the minimization of potential negative impacts in AI system design, development, deployment, and use. These principles are clearly communicated to stakeholders and integrated into relevant training programs.",
   "risk": "Unprioritized Trustworthy AI",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight"
   ]
  },
  {
   "id": "GV-4.1.2",
   "function": "Govern",
   "name": "Open Risk Communication Policies",
   "objective": "The organization develops and implements policies fostering open communication, proactive risk reporting, and a risk-aware culture across the AI lifecycle, integrating these practices into existing management systems and workflows. These policies include whistleblower protections, independent oversight, critical practices like pair programming, dogfooding, and external audits, ensuring employees and stakeholders can raise concerns and practice effective challenge without retribution.",
   "risk": "Ineffective Risk Communication Policies",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability"
   ]
  },
  {
   "id": "GV-4.1.3",
   "function": "Govern",
   "name": "AI Safety Lessons and Best Practices",
   "objective": "The organization implements an improvement process that captures, shares, and applies lessons learned and best practices related to AI safety and risk management. This process promotes effective challenge through regular debriefs, case studies, cross-functional collaboration, and the integration of insights into policies, practices, and training programs to drive ongoing enhancement of the organization's critical thinking and safety-first mindset in AI development and deployment.",
   "risk": "Lack of Lessons Learned Integration",
   "principle": "Accountable & Transparent",
   "marque": []
  },
  {
   "id": "GV-4.2.1",
   "function": "Govern",
   "name": "AI Risk and Impact Documentation Templates",
   "objective": "The organization establishes standardized templates and guidelines for documenting AI system risks and potential impacts throughout the AI lifecycle. These templates support informed risk assessment and estimation processes, facilitating consistent documentation across teams and projects.",
   "risk": "Inadequate Standardized AI Templates",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "standards"
   ]
  },
  {
   "id": "GV-4.2.2",
   "function": "Govern",
   "name": "Risk Documentation Review and Updates",
   "objective": "The organization regularly reviews and updates AI risk and impact documentation based on stakeholder feedback (e.g., end-users, subject matter experts, external advisors), ensuring that the information remains accurate, relevant, and actionable. This feedback is used to refine AI risk management practices and inform targeted risk mitigation strategies.",
   "risk": "Outdated Risk Documentation",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability"
   ]
  },
  {
   "id": "GV-4.2.3",
   "function": "Govern",
   "name": "Benefits Monitoring and Updates Plan",
   "objective": "The organization creates a plan to regularly review and update documentation of the AI system’s actual and potential benefits as its functionality, performance, and context of use evolve.",
   "risk": "Outdated Benefit Documentation",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability"
   ]
  },
  {
   "id": "GV-4.2.4",
   "function": "Govern",
   "name": "AI Risk Communication and Stakeholder Transparency",
   "objective": "The organization develops and implements a comprehensive communication strategy to proactively share information about AI risks, potential impacts, and risk mitigation actions with relevant internal and external stakeholders. This plan includes tailored messaging, engagement mechanisms, and channels for stakeholder feedback, fostering transparency, accountability, and building trust in the organization’s AI risk management practices and responsible AI development and deployment.",
   "risk": "Lack of AI Risk Communication",
   "principle": "Accountable & Transparent",
   "marque": [
    "accountability"
   ]
  },
  {
   "id": "GV-4.3.1",
   "function": "Govern",
   "name": "AI Testing and Validation Strategy",
   "objective": "The organization establishes an AI system testing strategy encompassing unit, integration, performance, and user acceptance testing, tailored to the system characteristics and requirements. This strategy should also include testing for real-world risks through methods such as red-teaming and field testing. The strategy will be regularly reviewed and updated.",
   "risk": "Insufficient AI Testing Strategy",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight"
   ]
  },
  {
   "id": "GV-4.3.2",
   "function": "Govern",
   "name": "AI Incident Identification and Resolution",
   "objective": "The organization integrates AI incident identification, reporting, and documentation into its existing incident management framework, ensuring clear definitions, roles, and responsibilities that enable prompt identification, thorough investigation, and effective resolution. This integration helps to minimize harm, facilitate timely response, and prevent recurrence, while leveraging established procedures and workflows.",
   "risk": "Unintegrated AI Incident Processes",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "accountability",
    "standards"
   ]
  },
  {
   "id": "GV-4.3.3",
   "function": "Govern",
   "name": "AI Testing and Incident Response Training",
   "objective": "The organization provides regular training and resources to support personnel in effectively testing AI systems, identifying incidents, and sharing information on risks and issues within its existing incident management framework. This includes ensuring training aligns with established procedures for incident response and communication, reinforcing practical skills and preparedness through simulations and scenario exercises.",
   "risk": "Insufficient Support Personnel Training",
   "principle": "Accountable & Transparent",
   "marque": [
    "standards"
   ]
  },
  {
   "id": "GV-4.3.4",
   "function": "Govern",
   "name": "AI Incident Tracking and Analysis",
   "objective": "The organization maintains a centralized AI inventory or enterprise knowledge management system that integrates with existing incident management frameworks to track, monitor, and analyze AI incidents. This system supports the identification of trends, patterns, and emerging risks and facilitates effective information sharing among relevant stakeholders within the broader incident response and risk management processes.",
   "risk": "Insufficient AI Incident Tracking",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "identity",
    "standards"
   ]
  },
  {
   "id": "GV-4.3.5",
   "function": "Govern",
   "name": "Secure External AI Incident Sharing",
   "objective": "The organization establishes secure and compliant channels for sharing sensitive information related to AI risks and incidents with external stakeholders (e.g., industry peers, academic researchers, regulators, information sharing databases) to promote collective learning and improvement while protecting confidential and proprietary data.",
   "risk": "Unsecure Communication Channels",
   "principle": "Accountable & Transparent",
   "marque": []
  },
  {
   "id": "GV-4.3.6",
   "function": "Govern",
   "name": "AI Post-Incident Review and Improvements",
   "objective": "The organization conducts regular post-incident reviews and root cause analyses to identify improvements in AI testing, incident identification, and information sharing. These reviews should be integrated into the organization's ongoing development cycle to inform continuous improvement of AI systems, practices, and safety measures.",
   "risk": "Insufficient Post-Incident Review",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight"
   ]
  },
  {
   "id": "GV-5.1.1",
   "function": "Govern",
   "name": "External Stakeholder Feedback Channels",
   "objective": "The organization identifies relevant external stakeholders (e.g., users, customers, community groups, subject matter experts) and establishes clear, ongoing channels (e.g., surveys, focus groups, forums, feedback mechanisms) for collecting feedback on potential individual and stakeholder group impacts of its AI systems throughout the system lifecycle.",
   "risk": "Lack of External Feedback Channels",
   "principle": "Accountable & Transparent",
   "marque": []
  },
  {
   "id": "GV-5.1.2",
   "function": "Govern",
   "name": "Stakeholder Feedback Policy and Prioritization",
   "objective": "The organization develops high-level policies and guidelines for collecting, considering, and prioritizing external stakeholder feedback, ensuring that feedback is effectively communicated to AI development and deployment teams for incorporation into decision-making processes.",
   "risk": "Insufficient Feedback Policies",
   "principle": "Accountable & Transparent",
   "marque": [
    "standards"
   ]
  },
  {
   "id": "GV-5.1.3",
   "function": "Govern",
   "name": "Industry Collaboration and Responsible AI",
   "objective": "The organization actively participates in industry initiatives and collaborates with external stakeholders to promote responsible AI development and deployment, sharing experiences, contributing to best practices, and staying informed of emerging trends and concerns related to AI risks.",
   "risk": "Lack of Industry Initiative Participation",
   "principle": "Accountable & Transparent",
   "marque": [
    "accountability"
   ]
  },
  {
   "id": "GV-5.2.1",
   "function": "Govern",
   "name": "Stakeholder Engagement Processes in Development and Deployment",
   "objective": "The organization establishes clear processes and channels for AI development and deployment teams to regularly engage with relevant AI stakeholders (e.g., end-users, subject matter experts, impacted communities). These interactions involve gathering feedback through various methods (e.g., surveys, interviews, focus groups, workshops), fostering an inclusive and collaborative environment.",
   "risk": "Lack of AI Stakeholder Engagement",
   "principle": "Accountable & Transparent",
   "marque": [
    "systemic"
   ]
  },
  {
   "id": "GV-5.2.2",
   "function": "Govern",
   "name": "Feedback Evaluation and Prioritization",
   "objective": "The AI development team develops criteria and guidelines for evaluating and prioritizing feedback from AI stakeholders, considering source credibility, potential impact on system performance, and alignment with organizational goals and values.",
   "risk": "Insufficient Feedback Evaluation Criteria",
   "principle": "Accountable & Transparent",
   "marque": []
  },
  {
   "id": "GV-5.2.3",
   "function": "Govern",
   "name": "Feedback Conflict Resolution",
   "objective": "The organization establishes a transparent, fair, and accountable process for adjudicating and resolving conflicting feedback from AI stakeholders, which includes evaluating the merits of feedback, considering trade-offs, and engaging in constructive dialogue.",
   "risk": "Inadequate Adjudication Processes",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "accountability"
   ]
  },
  {
   "id": "GV-5.2.4",
   "function": "Govern",
   "name": "Impact Assessments with Stakeholder Input",
   "objective": "AI development and deployment teams conduct impact assessments that incorporate external stakeholder feedback, often mediated through user-facing functions (e.g., product management or customer success), and other relevant data to understand potential impacts. Assessment results inform AI system design and deployment decisions, helping to proactively identify and mitigate risks. Teams ensure that feedback collected and processed through these functions is documented and integrated throughout the system lifecycle.",
   "risk": "Unincorporated Stakeholder Feedback",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "GV-5.2.5",
   "function": "Govern",
   "name": "Stakeholder Feedback Education and Transparency",
   "objective": "The organization educates stakeholders on effectively submitting feedback, communicates the process for how feedback is handled, and regularly informs them about how their feedback has been incorporated into AI system design and implementation (e.g., via reports, case studies, public forums), thereby promoting transparency, trust, and demonstrating its commitment to responsible AI development and deployment.",
   "risk": "Inadequate AI Feedback and Transparency",
   "principle": "Accountable & Transparent",
   "marque": [
    "accountability"
   ]
  },
  {
   "id": "GV-6.1.1",
   "function": "Govern",
   "name": "Third-Party AI Evaluation and Selection",
   "objective": "The organization establishes processes for evaluating and selecting third-party AI technologies based on criteria that assess security and privacy implications, integrating AI-specific considerations into third-party procurement planning, due diligence, evaluation, and contracting practices to create alignment with organizational risk management policies.",
   "risk": "Insufficient Third-Party Evaluation",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "identity"
   ]
  },
  {
   "id": "GV-6.1.2",
   "function": "Govern",
   "name": "Third-Party System Requirements",
   "objective": "The organization identifies and documents AI system requirements that may be specific to a third party to inform procurement planning, due diligence, and contracting.",
   "risk": "Unidentified Third-Party Requirements",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "identity"
   ]
  },
  {
   "id": "GV-6.1.3",
   "function": "Govern",
   "name": "Procurement and AI Partner Evaluation",
   "objective": "The organization updates its procurement planning processes to integrate AI-specific requirements so that procurement activities consider AI's unique implications and challenges associated with third-party partnerships. It also emphasizes the importance of participating in joint testing with third-party entities to collaboratively evaluate AI technologies and validate their effectiveness and compliance with organizational standards.",
   "risk": "Inadequate Procurement Planning",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "identity",
    "standards"
   ]
  },
  {
   "id": "GV-6.1.4",
   "function": "Govern",
   "name": "Due Diligence for AI Vendors",
   "objective": "The organization enhances its policies and procedures and provides adequate resources for conducting due diligence on third-party entities by incorporating AI-related considerations, including data provenance, secondary data use, and vendor data practices. This involves assessing intellectual property and data management specific to AI to inform more comprehensive risk-benefit assessments for AI-related partnerships. The due diligence process emphasizes negotiating contractual provisions that protect against data misuse, ensure data quality, and secure appropriate data rights.",
   "risk": "Incomplete Third-Party Due Diligence",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "identity",
    "standards"
   ]
  },
  {
   "id": "GV-6.1.5",
   "function": "Govern",
   "name": "Third-Party AI Risk Documentation",
   "objective": "The organization reviews and updates its existing documentation of AI risks associated with third-party entities (e.g., intellectual property infringement, data privacy, security, data provenance, and secondary data use by vendors) to include AI-specific factors. This documentation is regularly reviewed and adapted to address emerging AI-related risks, including specific considerations around data sourcing, management, and vendor data practices. Additionally, it clarifies AI risk management responsibilities within a shared responsibility model, helping all parties understand their roles in mitigating AI-related risks.",
   "risk": "Insufficient Risk Documentation",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "accountability",
    "identity"
   ]
  },
  {
   "id": "GV-6.1.6",
   "function": "Govern",
   "name": "Fourth-Party Disclosure and Termination",
   "objective": "The organization recognizes the risks associated with fourth parties—entities utilized by third parties—by requiring third parties to disclose their own third-party relationships and any associated risks. In cases where significant risks are identified, the organization establishes clear guidelines for terminating third-party contracts to protect its interests and mitigate potential harm.",
   "risk": "Unaddressed Fourth-Party Risks",
   "principle": "Accountable & Transparent",
   "marque": [
    "identity"
   ]
  },
  {
   "id": "GV-6.1.7",
   "function": "Govern",
   "name": "System Requirements Review and Updates",
   "objective": "The organization creates a plan for regular reviews and updates of third-party system requirements throughout the AI lifecycle, allowing for the identification of emerging risks and the incorporation of feedback from relevant AI stakeholders.",
   "risk": "Unreviewed Third-Party Requirements",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "identity"
   ]
  },
  {
   "id": "GV-6.1.8",
   "function": "Govern",
   "name": "Third-Party Concentration Risk Management",
   "objective": "The organization addresses aggregate third-party concentration risk by encouraging diversification of partners and thorough assessments of potential vulnerabilities associated with reliance on a limited number of third-party AI providers.",
   "risk": "Unaddressed Concentration Risk",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority",
    "identity",
    "systemic"
   ]
  },
  {
   "id": "GV-6.1.9",
   "function": "Govern",
   "name": "Third-Party AI Compliance Monitoring",
   "objective": "The organization strengthens its monitoring and auditing processes for third-party AI partners by integrating AI-specific compliance obligations related to data management and security standards, while establishing mechanisms to address any AI-related issues identified.",
   "risk": "Insufficient Partner Monitoring",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "identity",
    "standards"
   ]
  },
  {
   "id": "GV-6.1.10",
   "function": "Govern",
   "name": "Third-Party AI Incident Protocols",
   "objective": "The organization modifies its protocols for handling incidents or breaches related to third-party AI risks to include provisions for addressing data provenance issues, secondary data use, and other third-party data-related vulnerabilities. These protocols should encompass prompt reporting, investigation, impact assessment, and remediation, with an emphasis on contractual enforcement and negotiation strategies.",
   "risk": "Lack of Third-Party Incident Protocols",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "identity"
   ]
  },
  {
   "id": "GV-6.1.11",
   "function": "Govern",
   "name": "AI Third-Party Training and Resources",
   "objective": "The organization revises its training and resources for personnel managing third-party relationships to include AI-related content, focusing on the nuances of due diligence, contract negotiation, and risk assessment in the context of AI. This training is regularly updated to reflect changes in AI policy and industry best practices.",
   "risk": "Lacking of AI-Related Training Content",
   "principle": "Accountable & Transparent",
   "marque": [
    "identity",
    "standards"
   ]
  },
  {
   "id": "GV-6.2.1",
   "function": "Govern",
   "name": "Third-Party AI Contingency Plans",
   "objective": "The organization develops or updates existing contingency plans for potential failures or incidents in high-risk third-party AI systems and data, defining roles and responsibilities for key stakeholders (e.g., IT, legal, communications, senior leaders) and outlining specific response steps (e.g., system isolation, data recovery, public relations). These plans should also consider emerging risk transfer mechanisms such as AI insurance policies or special provisions in cyber insurance tailored to AI risks.",
   "risk": "Inadequate Contingency Plans",
   "principle": "Accountable & Transparent",
   "marque": [
    "accountability",
    "identity"
   ]
  },
  {
   "id": "GV-6.2.2",
   "function": "Govern",
   "name": "Failure and Incident Communication Protocols",
   "objective": "The organization establishes communication protocols to enable timely, accurate, and consistent notification of relevant stakeholders (e.g., customers, regulators, media) in the event of failures or incidents. These protocols utilize predefined templates, approval processes, and designated spokespeople. Regular tabletop or simulation exercises should be conducted to test and refine communication readiness.",
   "risk": "Inadequate Failure and Incident Communications",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority"
   ]
  },
  {
   "id": "GV-6.2.3",
   "function": "Govern",
   "name": "SLAs and Contracts with AI Vendors",
   "objective": "The organization establishes service level agreements (SLAs) and contractual provisions with high-risk third-party AI providers, defining obligations, liabilities, remedies, performance metrics (e.g., uptime, error rates), incident reporting requirements, and corrective action procedures. Contracts should include provisions addressing specific risks, such as indemnities or coverage related to AI-related damages, and consider negotiations around AI insurance and risk transfer. These agreements are regularly reviewed and updated.",
   "risk": "Insufficient SLAs and Contracts with Providers",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "accountability",
    "identity",
    "standards"
   ]
  },
  {
   "id": "GV-6.2.4",
   "function": "Govern",
   "name": "Monitoring and Early Warning Systems",
   "objective": "The organization implements logging, monitoring, and early warning systems to detect potential failures, anomalies, or breaches in high-risk third-party AI systems, triggering investigations and responses. Regular audits and assessments drive compliance and identify areas for risk management improvement.",
   "risk": "Failure to Detect Incidents",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "identity"
   ]
  },
  {
   "id": "MP-1.1.1",
   "function": "Map",
   "name": "AI Purpose and Context Documentation",
   "objective": "The organization identifies and documents the AI system’s purpose, context, beneficial uses, user types and expectations, relevant laws, norms, and prospective deployment settings.",
   "risk": "Undocumented AI System Purpose and Context",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MP-1.1.2",
   "function": "Map",
   "name": "Impact and Stakeholder Impact Assessment",
   "objective": "The organization considers the potential positive and negative impacts of the AI system in collaboration with a multidisciplinary set of relevant stakeholders (e.g., domain experts, human factors experts, affected communities) throughout its lifecycle.",
   "risk": "Insufficient Stakeholder Impact Consideration",
   "principle": "Fair",
   "marque": []
  },
  {
   "id": "MP-1.1.3",
   "function": "Map",
   "name": "Assumptions, Risks, and TEVV Documentation",
   "objective": "The organization identifies and documents assumptions, limitations, and potential risks throughout the AI system’s lifecycle. Testing, evaluation, verification, and validation (TEVV) requirements and system metrics to identify, monitor, and manage associated system risks are identified.",
   "risk": "Undocumented Limitations and Risks",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority",
    "oversight",
    "auditability"
   ]
  },
  {
   "id": "MP-1.1.4",
   "function": "Map",
   "name": "Non-AI Alternatives Evaluation",
   "objective": "The organization considers non-AI alternatives and documents the comparative analysis and decision rationale.",
   "risk": "Alternatives Not Considered",
   "principle": "Valid & Reliable",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MP-1.2.1",
   "function": "Map",
   "name": "Multidisciplinary AI Impact Teams",
   "objective": "The organization recruits, supports, and facilitates documented collaboration among multidisciplinary teams throughout the AI system lifecycle (from problem formulation to monitoring). This enhances comprehensive risk analysis, bias mitigation, and thorough consideration of potential impacts.",
   "risk": "Ineffective AI Teams or Collaboration",
   "principle": "Fair",
   "marque": [
    "oversight",
    "auditability"
   ]
  },
  {
   "id": "MP-1.3.1",
   "function": "Map",
   "name": "AI Alignment with Mission and Values",
   "objective": "The organization identifies and documents the AI system’s alignment and contribution to organizational mission, values, goals (including relevant goals for AI technology), and AI  Trustworthy Principles.",
   "risk": "AI System Misalignment",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MP-1.3.2",
   "function": "Map",
   "name": "AI Purpose and Context Review",
   "objective": "The organization establishes plans to review and update the AI system’s documented purpose and context to drive ongoing alignment with the organization's evolving mission, goals, and AI  Trustworthy Principles. The organization regularly re-evaluates the business value and context of use for existing AI systems to validate alignment.",
   "risk": "Insufficient Review Process",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability"
   ]
  },
  {
   "id": "MP-1.4.1",
   "function": "Map",
   "name": "AI Business Value and Context Communication",
   "objective": "The organization clearly defines, documents, and communicates the business value, objectives, and intended context of use for each AI system to relevant stakeholders, promoting alignment with organizational goals and facilitating transparency and accountability in how the AI system supports operational success.",
   "risk": "Undefined Business Value",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "accountability"
   ]
  },
  {
   "id": "MP-1.5.1",
   "function": "Map",
   "name": "AI Risk Tolerance Definitions",
   "objective": "The organization defines, develops, and documents risk tolerances for AI systems, considering different risk types (e.g., financial, operational, safety, reputational), sources, and levels (e.g., from negligible to critical), with awareness and oversight from senior leadership and the board where appropriate.",
   "risk": "Undefined AI Risk Tolerance",
   "principle": "Explainable & Interpretable",
   "marque": [
    "oversight",
    "auditability",
    "accountability"
   ]
  },
  {
   "id": "MP-1.5.2",
   "function": "Map",
   "name": "Design Decision Rationale Documentation",
   "objective": "The organization documents and communicates AI design decisions and risk tolerances, ensuring they align with stakeholder requirements, values, and trustworthiness principles. This process includes input from leadership and the board to support decision-making that balances risks, intended use, and organizational risk appetite.",
   "risk": "Misaligned Design Decisions",
   "principle": "Explainable & Interpretable",
   "marque": [
    "auditability",
    "accountability"
   ]
  },
  {
   "id": "MP-1.6.1",
   "function": "Map",
   "name": "AI Requirements from Stakeholders",
   "objective": "The organization engages relevant AI stakeholders (e.g., end-users, domain experts, impacted communities) to elicit and document system requirements that address AI risks and promote trustworthy characteristics (e.g., security, fairness, transparency, accountability).",
   "risk": "Unelicited AI Stakeholder Requirements",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "accountability"
   ]
  },
  {
   "id": "MP-1.6.2",
   "function": "Map",
   "name": "Data Interdependency and Provenance Documentation",
   "objective": "The organization documents the AI system's internal and external data interdependencies, including data provenance from a privacy perspective. This process identifies and assesses potential negative impacts stemming from these connections, informing risk thresholds, deployment decisions, and operational management decisions.",
   "risk": "Unassessed Data Interdependencies and Provenance",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "systemic"
   ]
  },
  {
   "id": "MP-1.6.3",
   "function": "Map",
   "name": "Context-Informed Data Design",
   "objective": "The organization conducts research to understand the potential limitations of data that may affect the specific uses of the AI system, and uses this understanding, along with insights on values, contexts, and systemic and historical considerations, to inform data selection and representation in the AI system design process.",
   "risk": "Understood Data Limitations",
   "principle": "Fair",
   "marque": [
    "authority",
    "systemic"
   ]
  },
  {
   "id": "MP-2.1.1",
   "function": "Map",
   "name": "AI Learning and Decision Tasks",
   "objective": "The organization defines and documents the AI system's existing and potential future learning and decision-making tasks (e.g., classification, generation, recommendation, prediction), considering fit-for-purpose, scalability and adaptability.",
   "risk": "Undefined Learning Tasks",
   "principle": "Valid & Reliable",
   "marque": [
    "auditability",
    "standards"
   ]
  },
  {
   "id": "MP-2.1.2",
   "function": "Map",
   "name": "Assumptions and Limitations Documentation",
   "objective": "The organization documents the assumptions and limitations associated with the AI system's existing and potential learning tasks, considering factors such as data availability, model performance, human-AI interaction, irreversibility of actions, and computational resources.",
   "risk": "Undocumented Learning Limitations",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority",
    "auditability",
    "systemic"
   ]
  },
  {
   "id": "MP-2.1.3",
   "function": "Map",
   "name": "Learning Tasks Review and Updates",
   "objective": "The organization creates a plan for regular reviews and updates to documented learning tasks, assumptions, and limitations as the AI system evolves or as new requirements arise.",
   "risk": "Insufficient Learning Plan",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority",
    "oversight",
    "auditability"
   ]
  },
  {
   "id": "MP-2.2.1",
   "function": "Map",
   "name": "AI Usage and Boundary Documentation",
   "objective": "The organization documents the settings, environments, and conditions that are within the AI system’s intended use, defining the boundaries of its applicability while considering knowledge limits and areas where human intervention and irreversibility of decisions is crucial.",
   "risk": "Undocumented Use Boundaries",
   "principle": "Explainable & Interpretable",
   "marque": [
    "authority",
    "oversight",
    "auditability"
   ]
  },
  {
   "id": "MP-2.2.2",
   "function": "Map",
   "name": "AI Interdependencies and Dependencies",
   "objective": "The organization documents the AI system's interdependencies, including both upstream and downstream data sources, as well as human dependencies, clearly identifying where the system relies on input from other automated systems or human operators.",
   "risk": "Undocumented System Dependencies",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "systemic"
   ]
  },
  {
   "id": "MP-2.3.1",
   "function": "Map",
   "name": "Development and Operation Documentation",
   "objective": "The organization documents assumptions, limitations, techniques, and metrics used for development or operation of the AI system throughout the lifecycle, aligning with data governance policies. This includes documenting data selection, curation, preparation, and analysis techniques, as well as identifying modeled constructs and methods for inferring reasonable relationships between constructs and dataset attributes.",
   "risk": "Undocumented Development and Operation Details",
   "principle": "Valid & Reliable",
   "marque": [
    "authority",
    "auditability",
    "accountability"
   ]
  },
  {
   "id": "MP-2.3.2",
   "function": "Map",
   "name": "TEVV Protocols and Standards",
   "objective": "The organization establishes and documents testing, evaluation, verification, and validation (TEVV) protocols for AI models, systems, and their subcomponents, covering the AI lifecycle from design to deployment and operation.",
   "risk": "Insufficient TEVV Protocols",
   "principle": "Explainable & Interpretable",
   "marque": [
    "auditability",
    "standards"
   ]
  },
  {
   "id": "MP-2.3.3",
   "function": "Map",
   "name": "Experimental Design and Statistical Methods",
   "objective": "The organization identifies valid experimental design and statistical techniques for testing complex AI systems, considering human factors, emergent risks, and dynamic contexts of use as relevant to the AI system.",
   "risk": "Unevidenced Statistical Techniques",
   "principle": "Valid & Reliable",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MP-2.3.4",
   "function": "Map",
   "name": "Validation Metrics and Rationale",
   "objective": "The organization demonstrates that AI system performance and validation metrics are interpretable, unambiguous, and relevant to the context of use, with the rationale for their selection clearly documented.",
   "risk": "Lack of Appropriate or Interpretable Metrics",
   "principle": "Explainable & Interpretable",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MP-2.3.5",
   "function": "Map",
   "name": "Design and Deployment Validation Feedback",
   "objective": "The organization establishes regular communication and feedback mechanisms among relevant AI stakeholders to validate design and deployment assumptions, which informs the development of TEVV approaches for detecting and assessing potential harmful impacts.",
   "risk": "Insufficient Feedback Mechanisms",
   "principle": "Explainable & Interpretable",
   "marque": []
  },
  {
   "id": "MP-2.3.6",
   "function": "Map",
   "name": "Testing Limits and Constraints",
   "objective": "The organization clearly defines and documents the limits of testing, including any claims about the system that are not falsifiable, and specifying what can and cannot be tested to maintain transparency regarding residual risks.",
   "risk": "Undefined Testing Limits",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority",
    "auditability"
   ]
  },
  {
   "id": "MP-3.1.1",
   "function": "Map",
   "name": "AI Design and Deployment Alignment",
   "objective": "The organization considers design strategies, testing strategies, implementation strategies, and deployment of AI systems in the context of potential impacts, organizational AI system goals, and alignment with organizational objectives, values, and AI  Trustworthy Principles.",
   "risk": "Unconsidered Impact Context",
   "principle": "Explainable & Interpretable",
   "marque": []
  },
  {
   "id": "MP-3.1.2",
   "function": "Map",
   "name": "Impact Feedback from Multidisciplinary Teams",
   "objective": "The organization solicits feedback from a multidisciplinary design and development team, augmented by additional stakeholders as needed, to identify and document the potential positive impacts of the AI system within its intended context of use.",
   "risk": "Unidentified Positive Impacts",
   "principle": "Explainable & Interpretable",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MP-3.1.3",
   "function": "Map",
   "name": "User Interface and Interpretability Design",
   "objective": "The organization designs and documents the AI system's user interface, workflows, and interpretability criteria in collaboration with end users, incorporating their feedback to enhance system benefits and understanding while recognizing the role of human interaction in interpreting system outputs.",
   "risk": "Suboptimized User Interface",
   "principle": "Explainable & Interpretable",
   "marque": [
    "auditability",
    "systemic"
   ]
  },
  {
   "id": "MP-3.2.1",
   "function": "Map",
   "name": "AI System Justification and Cost-Benefit",
   "objective": "The organization documents the rationale for using an AI system, including a comparative analysis of the benefits, risks, and costs associated with the AI system versus non-AI alternatives.",
   "risk": "Insufficient Rationale Documentation",
   "principle": "Explainable & Interpretable",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MP-3.2.2",
   "function": "Map",
   "name": "Cost and Impact Assessment",
   "objective": "The organization considers and documents potential monetary and non-monetary costs and potential impacts, including system performance, functionality, and trustworthiness, in alignment with its risk tolerance.",
   "risk": "Unconsidered Monetary Impacts",
   "principle": "Explainable & Interpretable",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MP-3.3.1",
   "function": "Map",
   "name": "AI Application Scope Definition",
   "objective": "The organization defines, specifies, and assesses the AI system's targeted application scope, considering its capabilities, limitations, context, and categorization. The organization engages relevant stakeholders (e.g., domain experts, end users) to validate the targeted application scope, aligning it with the AI system's intended purpose and organizational goals and AI  Trustworthy Principles.",
   "risk": "Undefined Application Scope",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority"
   ]
  },
  {
   "id": "MP-3.4.1",
   "function": "Map",
   "name": "Operator and Practitioner Proficiency Levels",
   "objective": "The organization defines and documents required proficiency levels for operators and practitioners interacting with the AI system, considering performance and trustworthiness characteristics, as well as relevant technical standards and certifications.",
   "risk": "Undefined Proficiency Levels",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "standards"
   ]
  },
  {
   "id": "MP-3.4.2",
   "function": "Map",
   "name": "Proficiency Assessment and Maintenance Plan",
   "objective": "The organization maintains the proficiency of operators and practitioners concerning the AI system's operation, risks, limitations, and knowledge boundaries. This is achieved through a structured proficiency assessment and maintenance plan encompassing regular training, certification, and evaluation programs. The plan incorporates continuous monitoring and performance metrics to identify areas for improvement and adapt training as needed, ensuring sustained capability for safe and effective AI system management within its sector and context of use.",
   "risk": "Insufficient Proficiency Assessment and Maintenance Plan",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority",
    "oversight"
   ]
  },
  {
   "id": "MP-3.4.3",
   "function": "Map",
   "name": "Operator and End-User Testing and Feedback",
   "objective": "The organization involves operators, practitioners, and end users in AI system prototyping and testing activities to gather feedback on performance and trustworthiness, validating human-AI configurations and identifying requisite proficiency levels and training needs.",
   "risk": "Users Not Involved in Testing",
   "principle": "Accountable & Transparent",
   "marque": []
  },
  {
   "id": "MP-3.5.1",
   "function": "Map",
   "name": "Human Oversight Roles and Responsibilities",
   "objective": "The organization defines and documents roles and responsibilities for human oversight of the AI system, considering its capabilities, context of use, potential risks, and knowledge limits.",
   "risk": "Undefined or Poorly Defined Human Oversight Roles",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority",
    "oversight",
    "auditability",
    "accountability"
   ]
  },
  {
   "id": "MP-3.5.2",
   "function": "Map",
   "name": "Oversight Training and Resources",
   "objective": "The organization provides training and resources to individuals responsible for human oversight of the AI system, equipping them with the necessary skills, knowledge, and authority to perform their roles effectively.",
   "risk": "Inadequate Oversight Resources",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority",
    "oversight",
    "accountability"
   ]
  },
  {
   "id": "MP-3.5.3",
   "function": "Map",
   "name": "Criteria and Thresholds for Intervention",
   "objective": "The organization documents and communicates criteria and thresholds for human intervention in AI system operation, procedures for escalating issues, and guidelines for making oversight decisions. Wherever possible, these criteria are embedded within the AI systems to facilitate timely human intervention.",
   "risk": "Undocumented Intervention Criteria",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "standards"
   ]
  },
  {
   "id": "MP-3.5.4",
   "function": "Map",
   "name": "Oversight Effectiveness Evaluation and Improvement",
   "objective": "The organization documents and reviews processes to regularly evaluate the effectiveness of human oversight mechanisms through qualitative and quantitative methods, such as audits, performance evaluations, and stakeholder feedback, while implementing a plan to assess human oversight and update documentation based on changes in the AI system's capabilities, context of use, or identified risks. These evaluations inform continuous improvement efforts and maintain alignment with governance policies.",
   "risk": "Unevaluated Oversight Effectiveness",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability"
   ]
  },
  {
   "id": "MP-4.1.1",
   "function": "Map",
   "name": "Legal Risk Management Processes",
   "objective": "The organization documents processes for identifying, mapping, assessing, and managing potential legal risks associated with the AI system and its components, including, but not limited to, fair lending practices, model risk, data privacy, intellectual property, third-party rights, and the use of third-party data or software, as available.",
   "risk": "Unmanaged Legal Risks",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority",
    "auditability",
    "identity"
   ]
  },
  {
   "id": "MP-4.1.2",
   "function": "Map",
   "name": "Third-Party Resource Documentation",
   "objective": "The organization maintains documentation of third-party AI resources used in its AI systems, including information on provenance, functionality, limitations, and potential risks, regularly updating this documentation as new information becomes available.",
   "risk": "Incomplete Third-Party Documentation",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority",
    "auditability",
    "identity"
   ]
  },
  {
   "id": "MP-4.1.3",
   "function": "Map",
   "name": "Legal Risk Communication and Updates",
   "objective": "The organization communicates identified legal risks associated with the AI system, and relevant changes in laws, regulations, and industry standards, to relevant stakeholders (e.g., developers, users, decision-makers), facilitating informed decision-making and effective risk mitigation.",
   "risk": "Uncommunicated Legal Changes",
   "principle": "Accountable & Transparent",
   "marque": [
    "standards"
   ]
  },
  {
   "id": "MP-4.2.1",
   "function": "Map",
   "name": "Internal Controls for AI Components",
   "objective": "The organization identifies and documents internal controls for AI system components, including third-party technologies, to mitigate potential risks and drive system integrity. This includes mapping identified risks to the corresponding internal controls.",
   "risk": "Unidentified Internal Controls",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "identity"
   ]
  },
  {
   "id": "MP-4.2.2",
   "function": "Map",
   "name": "Controls Effectiveness and Incident Response",
   "objective": "The organization regularly documents and reviews the effectiveness of internal risk controls and incident response procedures for both AI system components and third-party technologies, documenting results and implementing improvements to drive secure and reliable operation.",
   "risk": "Undocumented Control Effectiveness",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "accountability",
    "identity",
    "standards"
   ]
  },
  {
   "id": "MP-5.1.1",
   "function": "Map",
   "name": "AI Risk Identification, Assessment, and Prioritization",
   "objective": "The organization documents processes for identifying, assessing, and prioritizing AI system-specific risks, including the likelihood and magnitude of potential impacts (beneficial and harmful), using structured methodologies (e.g., risk matrices, RAG ratings, econometric approaches), TEVV practices, and adversarial testing to uncover potential misuse, vulnerabilities, unintended consequences, and content provenance harms (e.g., misinformation, deepfakes).",
   "risk": "Unidentified AI System Risks",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MP-5.1.2",
   "function": "Map",
   "name": "AI Risk Profile Development",
   "objective": "The organization develops comprehensive risk profiles (from all risks identified throughout MAP) that outline known and potential adverse outcomes, direct costs, indirect costs, potential systemic risks to markets and consumers, and the degree of impact on the AI system and its stakeholders, and the speed of onset of these risks.",
   "risk": "Undeveloped Risk Profiles",
   "principle": "Accountable & Transparent",
   "marque": [
    "systemic"
   ]
  },
  {
   "id": "MP-5.1.3",
   "function": "Map",
   "name": "Decision Rationale and Stakeholder Validation",
   "objective": "The organization documents the rationale behind its risk prioritization decisions and risk tolerance, including the factors considered, trade-offs made between different risk response options, and input received from relevant stakeholders, while also engaging these stakeholders (e.g., technical experts, domain specialists, impacted communities) to validate its decisions on risk prioritization, risk appetite and tolerance, and resource allocation, thereby incorporating multidisciplinary perspectives into the risk response process.",
   "risk": "Undocumented Risk Rationale",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MP-5.2.1",
   "function": "Map",
   "name": "Structured AI stakeholder Engagement",
   "objective": "The organization documents processes for regularly engaging relevant AI stakeholders (e.g., end-users, domain experts, potentially impacted communities) using structured methodologies such as value sensitive design (VSD) to gather feedback on the specific AI system's performance, impacts, and unanticipated consequences.",
   "risk": "Insufficient Actor Engagement",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MP-5.2.2",
   "function": "Map",
   "name": "Stakeholder Engagement and Mitigation",
   "objective": "The organization engages with relevant stakeholders to solicit context-specific insights and to develop action plans that detect, prevent, and mitigate potential risks, costs, or adverse impacts.",
   "risk": "Unused Context-Specific Insights",
   "principle": "Accountable & Transparent",
   "marque": []
  },
  {
   "id": "MS-1.1.1",
   "function": "Measure",
   "name": "AI Risk Metrics and Measurement Selection",
   "objective": "The organization selects and prioritizes significant AI risks for measurement and monitoring, defining metrics and measurement approaches that consider the AI system's specific context, intended use, and potential impacts on stakeholders. The organization documents the rationale for the selection of specific metrics and measurement approaches, including their relevance, feasibility, and limitations in relation to the AI system and its associated risks. The organization determines that measurement and testing are complete when prioritized risks have been tested, measured, and tracked, and no new or serious risks have emerged.",
   "risk": "Inadequate Contextual Risk Measurement",
   "principle": "Valid & Reliable",
   "marque": [
    "authority",
    "oversight",
    "auditability"
   ]
  },
  {
   "id": "MS-1.1.2",
   "function": "Measure",
   "name": "Unmeasurable Risks and Rationale Documentation",
   "objective": "The organization identifies and documents AI risks and/or trustworthiness characteristics that cannot or will not be measured, along with the reasons for exclusion. Recognizing that some risks may be difficult to measure quantitatively, the organization also considers tracking these risks qualitatively to ensure they are acknowledged and monitored as appropriate.",
   "risk": "Undocumented Excluded Risks",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability"
   ]
  },
  {
   "id": "MS-1.2.1",
   "function": "Measure",
   "name": "Error and Incident Data Analysis",
   "objective": "The organization collects and analyzes error reports, incidents, and potential impacts associated with its AI systems, using this information to assess the effectiveness of existing risk controls and the validity of current metrics. Recognizing that metrics can be subject to issues such as calibration drift, bias, measurement uncertainty, and Goodhart's law, the organization regularly reviews whether the metrics remain meaningful and reliable in the evolving context.",
   "risk": "Unvalidated Risk Metrics",
   "principle": "Valid & Reliable",
   "marque": [
    "oversight",
    "drift",
    "accountability"
   ]
  },
  {
   "id": "MS-1.3.1",
   "function": "Measure",
   "name": "Independent Expert Evaluation and Stakeholder Consultation",
   "objective": "The organization involves internal experts (external to front-line development) and independent assessors, including robust testing functions, in the regular assessment and updating of AI metrics and risk controls. Concurrently, it determines the need for consultation with domain experts, users, AI stakeholders external to the development team, and affected communities, based on risk appetite. This approach leverages multidisciplinary, unbiased insights to ensure a comprehensive understanding of potential impacts and the adequacy of risk management measures.",
   "risk": "Inadequate Independent Review and Stakeholder Consultation",
   "principle": "Explainable & Interpretable",
   "marque": [
    "oversight"
   ]
  },
  {
   "id": "MS-2.1.1",
   "function": "Measure",
   "name": "TEVV Test Data and Metrics Documentation",
   "objective": "The organization documents test sets and metrics used during the testing, evaluation, verification, and validation (TEVV) of its AI systems. The documentation includes relevant information on test sets, such as data sources, preparation techniques, data splits (e.g., training, validation, and testing), and identified constraints or limitations. Metrics are documented with clear definitions, formulas, and rationale, along with any assumptions and limitations.",
   "risk": "Incomplete Test Documentation",
   "principle": "Explainable & Interpretable",
   "marque": [
    "authority",
    "auditability"
   ]
  },
  {
   "id": "MS-2.1.2",
   "function": "Measure",
   "name": "2. TEVV Tools and Configuration Documentation",
   "objective": "The documentation of tools used during TEVV includes details on the software packages, libraries, frameworks, and hardware components employed, specifying their versions, configurations, and implemented customizations. The organization confirms that the tools and their configurations are appropriate for the specific AI system and its intended use case.",
   "risk": "Inappropriate or Undocumented Tool Use",
   "principle": "Explainable & Interpretable",
   "marque": [
    "auditability",
    "standards"
   ]
  },
  {
   "id": "MS-2.1.3",
   "function": "Measure",
   "name": "Centralized TEVV Repository and Access",
   "objective": "The organization maintains a centralized repository for TEVV documentation, promoting accessibility to relevant stakeholders and enabling updates and version control as the AI system evolves. The repository is organized to facilitate efficient retrieval and review of TEVV documentation, and access controls are implemented to ensure data security and privacy.",
   "risk": "Insufficient Centralized Repository",
   "principle": "Explainable & Interpretable",
   "marque": [
    "authority",
    "oversight",
    "auditability"
   ]
  },
  {
   "id": "MS-2.2.1",
   "function": "Measure",
   "name": "Human Subject Use and Consent",
   "objective": "The organization conducts evaluations involving human subjects—potentially including focus groups, small group studies, UI/UX research, surveys for publications, structured experiments, large-scale A/B testing, or extensive human data collection—in compliance with relevant laws, regulations, guidelines, and organizational policies. It ensures clear communication of the purpose, nature, risks, and benefits to participants, protection of any human-subjects data, and obtaining informed consent prior to participation. The organization documents the specific requirements followed, the consent procedures used, and the nature of the research to ensure transparency and adherence to standards.",
   "risk": "Non-Compliant Human Evaluations",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "standards"
   ]
  },
  {
   "id": "MS-2.2.2",
   "function": "Measure",
   "name": "Representation and Recruitment Process",
   "objective": "The organization takes steps to ensure human subjects involved in AI system evaluations are sufficiently representative of the relevant population. It documents the recruitment and selection process used, including the criteria applied to promote a balanced and representative sample. The organization acknowledges limitations or potential biases in the subject population that could not be fully addressed.",
   "risk": "Unrepresentative Human Subjects",
   "principle": "Fair",
   "marque": [
    "authority",
    "auditability"
   ]
  },
  {
   "id": "MS-2.2.3",
   "function": "Measure",
   "name": "Adverse Event Monitoring and Review",
   "objective": "The organization has procedures in place to monitor for and document adverse events or unintended consequences experienced by human subjects during the evaluation process, such as errors in testing or negative impacts. It takes appropriate measures to address and mitigate these issues when they occur. The organization conducts post-evaluation reviews to identify lessons learned from any adverse events in order to drive improvements to its human subject evaluation practices.",
   "risk": "Inadequate Human Impact Monitoring",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "standards"
   ]
  },
  {
   "id": "MS-2.3.1",
   "function": "Measure",
   "name": "Performance and Assurance Criteria",
   "objective": "The organization defines clear performance and assurance criteria for its AI systems that are tailored to the specific intended use cases, deployment settings, and stakeholder expectations associated with each system. The organization engages a range of relevant stakeholders to review and validate that the selected measures are appropriate and meaningful for assessing the system in its real-world context of use. The stakeholder engagement process and key feedback are documented.",
   "risk": "Lack of Tailored Criteria",
   "principle": "Valid & Reliable",
   "marque": [
    "oversight",
    "auditability"
   ]
  },
  {
   "id": "MS-2.3.2",
   "function": "Measure",
   "name": "Measurement Methods and Results",
   "objective": "The organization selects and applies a combination of quantitative and qualitative measurement methods to rigorously evaluate each AI system's performance and assurance characteristics, based on the specific criteria defined for that system. Quantitative measures may include established metrics appropriate for regression, time-series, classification, information retrieval, clustering, dimensional reduction, natural language processing or other tasks. Qualitative measures may include user feedback, expert reviews, and assessments of explainability, usability and accessibility. The measurement approaches and results are documented.",
   "risk": "Lack of Qualitative Measures",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "standards"
   ]
  },
  {
   "id": "MS-2.3.3",
   "function": "Measure",
   "name": "Performance Analysis and Trends",
   "objective": "The organization analyzes the quantitative and qualitative measurement methods and results used to evaluate AI system performance and assurance across its AI systems. It identifies patterns, trends, and outliers in the results to pinpoint areas for improvement in its AI system measurement practices. The organization documents how its measurement approaches and results evolve over time, using these insights to drive continuous improvement.",
   "risk": "Undocumented Analysis Results",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MS-2.3.4",
   "function": "Measure",
   "name": "Performance Under Realistic Conditions",
   "objective": "The organization demonstrates and documents AI system performance and assurance under realistic conditions that closely approximate the intended deployment settings. Key factors, such as data quality, user interactions, and environmental variables, are considered. Limitations in replicating the deployment environment are documented and communicated to stakeholders, along with plans to address them.",
   "risk": "Undocumented Performance Conditions",
   "principle": "Valid & Reliable",
   "marque": [
    "authority",
    "auditability",
    "systemic"
   ]
  },
  {
   "id": "MS-2.4.1",
   "function": "Measure",
   "name": "AI Monitoring and Anomaly Detection",
   "objective": "The organization monitors the functionality, reliability, and behavior of the AI system and its components in production, as identified during the MAP function. It implements both manual and automated monitoring tools and processes, including statistical quality control (SQC) approaches, to continuously gather data, alerting stakeholders to any deviations or anomalies.",
   "risk": "Unmonitored Production Behavior",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "accountability"
   ]
  },
  {
   "id": "MS-2.4.2",
   "function": "Measure",
   "name": "Performance Tracking and Improvement",
   "objective": "The organization systematically analyzes production data to track system performance and reliability over time, comparing real-world metrics against pre-deployment expectations. This analysis includes evaluating error propagation, identifying feedback loop risks, and assessing whether the AI system is adapting appropriately to changing conditions, using statistical quality control methods to detect shifts, trends, and assignable causes. Findings from these evaluations inform iterative improvements.",
   "risk": "Unsystematic Data Analysis",
   "principle": "Accountable & Transparent",
   "marque": [
    "accountability"
   ]
  },
  {
   "id": "MS-2.4.3",
   "function": "Measure",
   "name": "AI Monitoring Integration",
   "objective": "The organization integrates AI-specific monitoring activities with its broader system-wide monitoring framework. AI-related performance and reliability metrics, anomaly detection signals, decision logs, and statistical quality control indicators are incorporated into existing monitoring platforms and operational dashboards. This allows AI-related alerts to be contextualized alongside other system indicators, enabling a holistic response to incidents.",
   "risk": "Unintegrated AI Monitoring",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "accountability",
    "standards"
   ]
  },
  {
   "id": "MS-2.4.4",
   "function": "Measure",
   "name": "Incident Investigation and Root Cause Analysis",
   "objective": "The organization conducts structured investigations, integrating with existing incident management processes where appropriate, using root cause analysis methodologies when anomalies or failures are detected. These investigations consider factors such as data integrity, model biases, potential unintended consequences, and statistical quality control evidence supporting identified causes. Corrective actions to restore reliability are documented and integrated into future risk mitigation strategies.",
   "risk": "Lack of Root Cause Analysis",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "accountability"
   ]
  },
  {
   "id": "MS-2.5.1",
   "function": "Measure",
   "name": "Validation and Reliability Testing Process",
   "objective": "The organization implements a structured validation and reliability testing process that incorporates performance metrics aligned with real-world deployment conditions, including measures for robustness against distribution shifts, stress testing under varying operational scenarios, and adversarial testing, with oversight or input from the MRM program and independent model validation functions. The organization establishes and documents acceptance criteria based on statistical confidence levels.",
   "risk": "Misaligned Reliability Testing",
   "principle": "Valid & Reliable",
   "marque": [
    "oversight",
    "auditability",
    "accountability"
   ]
  },
  {
   "id": "MS-2.5.2",
   "function": "Measure",
   "name": "Validation Results and Improvement",
   "objective": "The organization documents validation results, comparing actual system performance against expected outcomes. This documentation includes model confidence intervals, performance degradation patterns, failure scenarios, and assumptions made during testing, and these outputs are reporting the MRM program and reviewed by model validation functions. The organization continuously refines system components based on identified weaknesses.",
   "risk": "Undocumented Validation Results",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "drift",
    "auditability"
   ]
  },
  {
   "id": "MS-2.5.3",
   "function": "Measure",
   "name": "Generalization and Bias Assessment",
   "objective": "The organization conducts evaluations to assess how well the AI system generalizes beyond its training conditions, measuring the impact of data variations, shifts in contextual factors, potential biases introduced by unseen inputs, and to establish knowledge limits. Domain expertise is leveraged to interpret results and determine system limitations.",
   "risk": "Lacking Generalization Evaluations",
   "principle": "Explainable & Interpretable",
   "marque": [
    "authority"
   ]
  },
  {
   "id": "MS-2.6.1",
   "function": "Measure",
   "name": "Safety Risk Assessments and Stress Testing",
   "objective": "The organization conducts regular safety risk assessments of its AI systems, focusing on risks identified during the MAP function, including systemic risk to markets or consumers. These assessments include stress testing under various conditions, considering historical system failures in similar domains. The results, including identified safety concerns, failure points, and mitigation strategies, are documented and integrated into the risk management lifecycle.",
   "risk": "Irregular Safety Assessments",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "systemic"
   ]
  },
  {
   "id": "MS-2.6.2",
   "function": "Measure",
   "name": "Controlled Failures and Fail-Safe Mechanisms",
   "objective": "The organization demonstrates the AI system's ability to operate safely under normal conditions and fail in a controlled manner when exceeding its knowledge limits through scenario-based testing. The organization implements and assesses fail-safe mechanisms to minimize harm.",
   "risk": "Inadequate Failure Mode Planning",
   "principle": "Safe",
   "marque": [
    "authority"
   ]
  },
  {
   "id": "MS-2.7.1",
   "function": "Measure",
   "name": "Security and Resilience Improvement Process",
   "objective": "he organization maintains a structured approach to AI system security and resilience, integrating with existing security and resilience program processes, ensuring that defenses address AI-specific threats. Regular reviews of AI system security logs, adversarial testing outcomes, historical incident intelligence (including documented misuse such as fraud, extortion, and model reverse-engineering), and current threat intelligence guide refinements in AI system security configurations, access controls, and response protocols. Changes to AI-specific defense mechanisms, model resilience strategies, and failure response protocols are formally documented.",
   "risk": "Lack of Structured Security Approach",
   "principle": "Secure & Resilient",
   "marque": [
    "authority",
    "oversight",
    "auditability"
   ]
  },
  {
   "id": "MS-2.7.2",
   "function": "Measure",
   "name": "AI Security and Resilience Testing",
   "objective": "The organization conducts regular security and resilience evaluations for its AI systems, aligning these efforts with risks and vulnerabilities identified during the MAP function. These assessments include red teaming exercises, penetration testing, and stress testing. Findings from these evaluations are documented and used to refine AI-specific and enterprise-wide security strategies.",
   "risk": "Irregular Security Evaluations",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MS-2.7.3",
   "function": "Measure",
   "name": "Ongoing AI Risk and Threat Assessments",
   "objective": "The organization conducts ongoing reviews of AI system-specific risks and, as warranted by the risk level of the AI system, performs structured assessments tailored for AI systems, such as adversarial role-playing, impact assessments, red-teaming, and chaos testing. These assessments are designed to identify potential failure modes, emergent risks, and content-related challenges (e.g., misinformation, disinformation, deepfakes, tampered content) relevant to the AI context, supporting proactive risk identification and mitigation.",
   "risk": "Unperformed Tailored Assessments",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight"
   ]
  },
  {
   "id": "MS-2.7.4",
   "function": "Measure",
   "name": "Security Metrics and Log Monitoring",
   "objective": "The organization defines and tracks AI security and resilience metrics, ensuring alignment with existing enterprise-wide cybersecurity and IT resilience frameworks. AI-specific security logs and monitoring outputs are integrated into centralized security information and event management (SIEM) systems. Regular audits ensure that AI systems are held to the same security and resilience standards as other critical IT assets.",
   "risk": "Undefined Security Metrics",
   "principle": "Secure & Resilient",
   "marque": [
    "oversight",
    "auditability",
    "identity",
    "standards"
   ]
  },
  {
   "id": "MS-2.8.1",
   "function": "Measure",
   "name": "AI Transparency and Accountability Evaluation",
   "objective": "The organization assesses AI system transparency and accountability by evaluating the effectiveness of mechanisms that provide clear, accessible information to users, stakeholders, and non-technical actors. This includes reviewing explanations, disclosures, and communication channels, as well as interpretability methods that contextualize technical explainability for human understanding. Findings inform updates to governance policies, training, and user guidance to enhance transparency and facilitate effective oversight and human intervention.",
   "risk": "Opaque AI System Accountability",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "accountability"
   ]
  },
  {
   "id": "MS-2.8.2",
   "function": "Measure",
   "name": "Metrics for Transparency and Accountability",
   "objective": "The organization establishes and monitors metrics to measure the transparency and accountability of its AI systems, including the effectiveness of explainability features, the clarity of disclosures, and the resolution times for escalated decisions. It also assesses the quality of communication to non-technical stakeholders (e.g., clear explanations, adverse action notices, appeal processes) to ensure information is accessible and meaningful. Regular review of AI system logs and stakeholder feedback helps identify trends and refine accountability mechanisms, supporting effective oversight and human intervention.",
   "risk": "Unmonitored Transparency Metrics",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "accountability"
   ]
  },
  {
   "id": "MS-2.9.1",
   "function": "Measure",
   "name": "Model Explainability and Validation",
   "objective": "The organization provides clear and structured explanations of its AI models (e.g., design choices, training data sources, feature importance, decision pathways) that serve as the underlying reasons behind outcomes. The model validation process includes testing for stability, fairness, and performance across various conditions, with specific attention to potential biases and limitations. The organization employs interpretable models or post-hoc explainability techniques where possible and ensures that AI outputs align with intended policies and AI Trustworthy Principles.",
   "risk": "Insufficient Model Explanations",
   "principle": "Explainable & Interpretable",
   "marque": [
    "authority"
   ]
  },
  {
   "id": "MS-2.9.2",
   "function": "Measure",
   "name": "Interpretability and Decision Context",
   "objective": "The organization ensures that AI-generated outputs are interpreted in context, helping users understand how decisions were reached and their potential limitations. Decision rationales are structured to be accessible to technical teams, end-users, and external stakeholders, ensuring they align with the expected use case, audience expertise, and impact considerations. The organization integrates human oversight mechanisms where necessary and leverages explainability testing methods to validate the clarity and effectiveness of AI-generated explanations.",
   "risk": "Unexplained Decision Rationales",
   "principle": "Explainable & Interpretable",
   "marque": [
    "authority",
    "oversight"
   ]
  },
  {
   "id": "MS-2.10.1",
   "function": "Measure",
   "name": "Initial Privacy Risk Assessment",
   "objective": "The organization conducts an initial examination of the privacy risks associated with its AI systems, as identified during the MAP function, and documents the results of this examination, including any identified privacy issues, concerns, or potential violations specific to AI systems. It establishes accountability mechanisms for managing AI-related privacy risks and incidents, such as data breaches or unauthorized access, and assigns clear roles and responsibilities for privacy risk management.",
   "risk": "Unexamined Privacy Risks",
   "principle": "Privacy-Enhanced",
   "marque": [
    "authority",
    "auditability",
    "accountability"
   ]
  },
  {
   "id": "MS-2.10.2",
   "function": "Measure",
   "name": "Ongoing AI Privacy Risk Assessment, Monitoring, and Verification",
   "objective": "The organization conducts ongoing privacy risk assessments, and actively monitors and verifies privacy risks throughout the AI lifecycle. This includes techniques such as PIAs, data flow mapping, adversarial testing, and re-identification risk analysis, focusing on risks like re-identification, inadvertent data leaks, or malicious data exfiltration through AI system outputs. These activities evaluate and verify the effectiveness of privacy controls, including anonymization methods, with findings documented and used to continuously improve privacy safeguards and risk management practices.",
   "risk": "Unassessed or Unmonitored AI Privacy Risks",
   "principle": "Privacy-Enhanced",
   "marque": [
    "oversight",
    "auditability"
   ]
  },
  {
   "id": "MS-2.10.3",
   "function": "Measure",
   "name": "Data Consent and Management",
   "objective": "The organization establishes procedures for tracking and managing data subject consent, including documenting consent statuses, handling data access requests, and ensuring compliance with legal and regulatory requirements. These procedures prevent use of withdrawn or erased data both during training and post-deployment.",
   "risk": "Untracked Consent Requests",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "standards"
   ]
  },
  {
   "id": "MS-2.11.1",
   "function": "Measure",
   "name": "Context-Specific Fairness and Bias Evaluation",
   "objective": "The organization conducts evaluations of fairness and bias in its AI systems, focusing on any regulatory requirements and the risks and potential impacts identified during the MAP function. The organization employs techniques and tools to assess fairness and bias, examining potential sources of bias throughout the AI lifecycle, including systemic bias, statistical and computational bias, and human cognitive bias. Based on the evaluation results, the organization develops and implements strategies to mitigate or manage identified biases and fairness issues. The organization documents the results of its fairness and bias evaluations, including identified issues and mitigation strategies.",
   "risk": "Unconducted Fairness Evaluations",
   "principle": "Fair",
   "marque": [
    "auditability",
    "systemic"
   ]
  },
  {
   "id": "MS-2.12.1",
   "function": "Measure",
   "name": "AI Resource Efficiency Assessment",
   "objective": "The organization conducts an assessment of the resource efficiency of its AI systems across their entire lifecycle. This assessment evaluates energy consumption, resource utilization, and the efficiency of AI infrastructure. The results are documented, including identified opportunities for optimization.",
   "risk": "Unassessed AI Resource Efficiency",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MS-2.12.2",
   "function": "Measure",
   "name": "Metrics and Monitoring of AI Resource Efficiency",
   "objective": "The organization establishes metrics and monitoring processes to track the effectiveness of its AI resource efficiency efforts. It regularly reviews and updates its resource efficiency assessment and optimization strategies based on new data, technologies, and best practices in efficient AI.",
   "risk": "Unestablished AI Resource Efficiency Metrics",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability"
   ]
  },
  {
   "id": "MS-2.12.3",
   "function": "Measure",
   "name": "Optimization Strategies for AI Resource Efficiency",
   "objective": "The organization ensures that the systems continue to deliver value and meet performance objectives through measurement of AI resource efficiency. These strategies consider the specific performance requirements and operational contexts of each AI system.",
   "risk": "Unmeasured AI Resource Performance",
   "principle": "Accountable & Transparent",
   "marque": []
  },
  {
   "id": "MS-2.13.1",
   "function": "Measure",
   "name": "TEVV Process Review and Continuous Improvement",
   "objective": "The organization schedules regular reviews and continuously monitors and updates its TEVV processes. This ensures accuracy, completeness, and alignment with industry best practices, regulatory requirements, evaluation results, stakeholder feedback, and evolving industry standards. The review process incorporates lessons learned from each iteration and reflects pertinent changes in testing methodologies or tools, with frequency determined by AI system complexity, risk profile, and pace of development. All updates are documented to maintain effectiveness, efficiency, and alignment with AI risk management goals.",
   "risk": "Unreviewed or Unmonitored TEVV Processes",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "standards"
   ]
  },
  {
   "id": "MS-2.13.2",
   "function": "Measure",
   "name": "TEVV Metrics Analysis",
   "objective": "The organization regularly evaluates the effectiveness of its TEVV metrics, including trustworthiness characteristics and environmental metrics, and continuously monitors and updates them. It assesses whether these metrics effectively identify and mitigate risks within acceptable levels defined by its risk appetite. Results, strengths, weaknesses, and areas for improvement are documented, and corrective actions are taken to refine the TEVV approach, ensuring continuous improvement and alignment with AI risk management goals.",
   "risk": "Unevaluated or Unmonitored TEVV Metrics",
   "principle": "Valid & Reliable",
   "marque": [
    "oversight",
    "auditability"
   ]
  },
  {
   "id": "MS-2.13.3",
   "function": "Measure",
   "name": "Cost-Effectiveness and Optimization of TEVV",
   "objective": "The organization analyzes the efficiency and cost-effectiveness of its TEVV metrics and processes, considering the level of risk associated with each AI system and the potential impact of system failures or performance issues. The organization evaluates the cost of implementing and maintaining each TEVV measure relative to the expected risk reduction benefits it provides, prioritizing investments in the most critical and impactful measures. The results of this analysis, including key cost, risk, and optimization trade-offs, are documented and regularly reviewed to inform ongoing refinements to the organization's TEVV strategy and practices.",
   "risk": "Unanalyzed TEVV Efficiency",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability"
   ]
  },
  {
   "id": "MS-3.1.1",
   "function": "Measure",
   "name": "AI Risk Tracking and Resource Allocation",
   "objective": "The organization allocates resources to support an approach for identifying and tracking AI risks. This approach includes monitoring AI system performance, considering the nature of AI risks, and analyzing external factors such as operational environment changes, stakeholder feedback, and industry developments. Resources are allocated to develop and implement AI risk management techniques, addressing opacity and explainability challenges. The organization reviews and adjusts resource allocation to ensure the effectiveness of its AI risk identification and tracking processes, adapting to the evolving regulatory landscape.",
   "risk": "Inadequate Resources Allocated",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight"
   ]
  },
  {
   "id": "MS-3.1.2",
   "function": "Measure",
   "name": "AI Risk Documentation and Review",
   "objective": "For each AI system, the organization documents the identified risks, their likelihood and potential impact, and the effectiveness of risk tracking methods employed. The documentation includes methodologies, tools, data sources, and personnel roles and responsibilities. The organization reviews and updates this documentation to reflect changes in the AI system's risk profile and assesses the effectiveness of its risk identification and tracking processes to drive continuous improvement.",
   "risk": "Undocumented Risk Tracking",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "accountability"
   ]
  },
  {
   "id": "MS-3.2.1",
   "function": "Measure",
   "name": "Measurement Technique Gap Analysis",
   "objective": "The organization identifies AI risk scenarios where current measurement techniques may be unavailable or insufficient, documenting these scenarios and limitations. It explores alternative risk tracking approaches and evaluates the suitability of each approach, considering data availability, interpretability, and the ability to incorporate domain knowledge. The selection of modeling techniques is guided by the AI system's characteristics, the nature of the risks, and risk management objectives. The rationale for the chosen approaches, assumptions, and limitations is documented.",
   "risk": "Unidentified Unmeasured Risks",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority",
    "auditability"
   ]
  },
  {
   "id": "MS-3.2.2",
   "function": "Measure",
   "name": "Pilot Studies and Approach Refinement",
   "objective": "The organization conducts pilot studies or proof-of-concept trials to test the feasibility and effectiveness of alternative risk identification and tracking approaches, based on best practices, industry trends, collaborative endeavors, and internal innovation, in real-world settings, documenting lessons learned, limitations encountered, or areas for further refinement.",
   "risk": "Unconducted Pilot Tests",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority",
    "auditability"
   ]
  },
  {
   "id": "MS-3.2.3",
   "function": "Measure",
   "name": "Long-term Impact Evaluation Framework",
   "objective": "The organization develops a framework for evaluating the long-term impacts of deployed AI systems on organizational objectives and AI  Trustworthy Principles, ensuring sustained value and alignment with evolving expectations.",
   "risk": "Unevaluated Long-Term Impacts",
   "principle": "Accountable & Transparent",
   "marque": [
    "standards"
   ]
  },
  {
   "id": "MS-3.3.1",
   "function": "Measure",
   "name": "Feedback and Appeals Processes",
   "objective": "The organization establishes feedback processes for relevant stakeholders to report problems, concerns, or unintended consequences related to AI system outcomes, integrating with existing processes for reporting security issues and potential vulnerabilities. This includes implementing an appeals mechanism that allows users to challenge or request reviews of outcomes they believe to be inaccurate, unfair, or harmful. Both processes are documented clearly, including channels, timeframes, responsibilities, escalation procedures, and criteria for decision-making, with all reported issues tracked to closure.",
   "risk": "Insufficient Feedback Mechanisms",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "accountability",
    "standards"
   ]
  },
  {
   "id": "MS-3.3.2",
   "function": "Measure",
   "name": "Feedback Integration and Process Refinement",
   "objective": "The organization integrates user feedback and appeal data into its AI system evaluation metrics, tracking key indicators to identify patterns or systemic issues related to AI system outcomes. Feedback and appeal processes are continuously monitored and refined based on user input, system performance data, and evolving best practices, with refinements documented to ensure the processes remain effective, inclusive, and aligned with the organization's AI governance framework.",
   "risk": "Unintegrated Feedback Data",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "systemic",
    "standards"
   ]
  },
  {
   "id": "MS-4.1.1",
   "function": "Measure",
   "name": "Context-Specific Risk Identification",
   "objective": "The organization reviews AI risk identification processes for alignment with the specific deployment context(s) of its AI systems, considering intended use cases, user populations, operational environments, trustworthiness characteristics, and potential impacts on individuals. It actively consults with domain experts, end users, and other relevant stakeholders to gather input on risks and challenges, documenting the outcomes. Additionally, the organization documents the involvement of internal experts, independent assessors, domain experts, users, and other external AI stakeholders in the assessment process, including their contributions, recommendations, and actions taken based on their input, to ensure transparency, accountability, and a comprehensive record of the assessment activities.",
   "risk": "Lacking Deployment Context Input",
   "principle": "Valid & Reliable",
   "marque": [
    "oversight",
    "auditability",
    "accountability"
   ]
  },
  {
   "id": "MS-4.1.2",
   "function": "Measure",
   "name": "Integration with Organizational Processes",
   "objective": "The organization assesses the integration of its AI risk identification processes with other relevant organizational processes, such as cybersecurity, resilience planning, and incident management. Internal and external experts provide feedback on integration. It documents how AI risk identification aligns with and supports these processes to ensure consistency and effectiveness of risk management practices. Areas for improvement are identified and addressed.",
   "risk": "Insufficient Integration Processes",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MS-4.1.3",
   "function": "Measure",
   "name": "Incorporating Real-World Data",
   "objective": "The organization incorporates insights from user feedback, incident reports, and other real-world data sources into its AI risk identification approaches. This grounding in actual experiences and concerns of end users and impacted communities is documented, highlighting how these insights are integrated into the risk identification process.",
   "risk": "Unincorporated User Feedback",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MS-4.1.4",
   "function": "Measure",
   "name": "Validation, Testing, and Effectiveness Evaluation of AI Risk Approaches",
   "objective": "The organization validates the efficacy of its AI risk identification approaches through targeted testing, simulations, or pilot studies in the deployment context(s). Concurrently, it regularly reviews and assesses the effectiveness of its AI risk identification and tracking approaches by evaluating the timeliness and accuracy of risk detection, risk coverage, and adaptability to changing circumstances. All results, including any limitations, assumptions, strengths, weaknesses, or areas for improvement, are documented and used to refine and continuously enhance the risk approaches.",
   "risk": "Unvalidated or Unevaluated AI Risk Identification Efficacy",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority",
    "oversight",
    "auditability"
   ]
  },
  {
   "id": "MS-4.2.1",
   "function": "Measure",
   "name": "Benefits and Performance Assessment",
   "objective": "The organization assesses and documents the AI system's anticipated capabilities and benefits, and alignment to organizational objectives and AI  Trustworthy Principles, against accepted benchmarks.",
   "risk": "Unassessed Capabilities and Benefits",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "standards"
   ]
  },
  {
   "id": "MS-4.2.2",
   "function": "Measure",
   "name": "Performance Validation via Stakeholder Input",
   "objective": "The organization actively seeks input from domain experts and relevant AI stakeholders, such as system developers, operators, users, and impacted communities, to validate whether the AI system is performing consistently as intended in its specific deployment context(s), and documents the outcomes of these consultations, including any discrepancies or concerns raised.",
   "risk": "Lack of Stakeholder Validation Input",
   "principle": "Valid & Reliable",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MS-4.2.3",
   "function": "Measure",
   "name": "Analysis of Performance and Trustworthiness Trends",
   "objective": "The organization regularly analyzes the measurement results to identify patterns, trends, or anomalies indicating issues with AI system trustworthiness while engaging in dialogue with domain experts and relevant AI stakeholders to interpret these results and their implications. Findings are documented alongside insights, recommendations, and areas of consensus or disagreement",
   "risk": "Inadequate Trend Analysis",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MS-4.2.4",
   "function": "Measure",
   "name": "Continuous Improvement of AI Trustworthiness",
   "objective": "The organization regularly reviews and updates its risk controls and performance metrics across trustworthy characteristics based on assessment results, stakeholder feedback, and evolving risk landscapes, ensuring continuous improvement and alignment with best practices and regulatory requirements to maintain AI system trustworthiness.",
   "risk": "Unreviewed Risk Controls",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight"
   ]
  },
  {
   "id": "MS-4.3.1",
   "function": "Measure",
   "name": "Stakeholder Feedback on Performance",
   "objective": "The organization engages in regular consultations with relevant AI stakeholders (e.g., system developers, operators, users, and impacted communities), to gather insights on observed performance changes. Outcomes of these consultations are documented, including areas of agreement, disagreement, or concern.",
   "risk": "Infrequent Actor Consultations",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MS-4.3.2",
   "function": "Measure",
   "name": "Root Cause Analysis and Action Plans",
   "objective": "The organization conducts root cause analyses to investigate the factors contributing to identified performance changes, integrating with existing incident and problem management processes where appropriate, documenting findings along with recommended actions for sustaining improvements, mitigating declines, or addressing related risks and trustworthiness issues.",
   "risk": "Uninvestigated Contributing Factors",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MS-4.3.3",
   "function": "Measure",
   "name": "Knowledge Sharing and Industry Contribution",
   "objective": "The organization shares its findings and receives feedback regarding measurable performance improvements or declines with the broader AI community through publications, conferences, or industry forums, contributing to collective knowledge and best practices in context-specific AI performance management and trustworthiness assurance.",
   "risk": "Unshared Performance Findings",
   "principle": "Accountable & Transparent",
   "marque": []
  },
  {
   "id": "MG-1.1.1",
   "function": "Manage",
   "name": "AI System Evaluation and Gap Analysis",
   "objective": "The organization establishes a formal evaluation process to determine if the AI system achieves its intended purposes and objectives, assessing performance metrics, stakeholder feedback, alignment with organizational goals and values, and the system's trustworthiness (including fairness, transparency, accountability, privacy), while identifying gaps, risks, and potential improvements.",
   "risk": "Insufficient Purpose Achievement Evaluation",
   "principle": "Valid & Reliable",
   "marque": [
    "accountability"
   ]
  },
  {
   "id": "MG-1.1.2",
   "function": "Manage",
   "name": "Go/No-Go Decision Criteria",
   "objective": "The organization makes a determination as to whether to proceed using clear criteria and thresholds to guide decisions on whether an AI system's development or deployment should proceed, pause, or be terminated based on evaluation results, its risk tolerance, and confirmation that all identified risks and vulnerabilities have been remediated or formally accepted.",
   "risk": "Absent Deployment Decision Criteria",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight"
   ]
  },
  {
   "id": "MG-1.2.1",
   "function": "Manage",
   "name": "AI Risk Prioritization and Framework",
   "objective": "The organization prioritizes AI risks withing the existing enterprise risk framework that takes into account the impact and likelihood of documented AI risks, risk appetite and tolerance, the availability of resources, and options for risk treatment, utilizing methodologies such as risk matrices, risk scores, or multi-criteria decision analysis to ensure a consistent and transparent assessment of AI risks.",
   "risk": "Unprioritized AI Risks",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability",
    "standards"
   ]
  },
  {
   "id": "MG-1.2.2",
   "function": "Manage",
   "name": "Framework Updates and Performance Monitoring",
   "objective": "The organization regularly assesses and updates its risk prioritization framework and risk tolerance based on changes in the AI system's performance, the operational environment, or the availability of new risk response methods and resources.",
   "risk": "Outdated Framework & Tolerances",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "drift",
    "standards"
   ]
  },
  {
   "id": "MG-1.3.1",
   "function": "Manage",
   "name": "Risk Response Strategy and Options",
   "objective": "The organization responds to high-priority AI risks, considering options such as risk mitigation, transfer, avoidance, or acceptance. These strategies align with risk management policies, risk tolerance, and relevant industry standards.",
   "risk": "Inappropriate Risk Response",
   "principle": "Accountable & Transparent",
   "marque": [
    "standards"
   ]
  },
  {
   "id": "MG-1.3.2",
   "function": "Manage",
   "name": "Responsibility and Decision Criteria",
   "objective": "The organization assigns responsibility to a designated person, group, or role with decision-making authority to establish and document clear criteria for selecting the appropriate risk response option for each high-priority AI risk. The criteria should consider potential impact, risk appetite and tolerance, and the feasibility and effectiveness of available risk response methods. Agreed upon risk responses are tracked and monitored to closure.",
   "risk": "Lack of Decision Authority Criteria",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority",
    "oversight",
    "auditability",
    "accountability"
   ]
  },
  {
   "id": "MG-1.4.1",
   "function": "Manage",
   "name": "Residual Risk Documentation and Management",
   "objective": "The organization identifies and documents negative risks associated with its AI systems, including risks that have been accepted, transferred, or mitigated to the extent possible. For partially mitigated risks, the organization documents both the mitigated and unmitigated aspects of the risk to maintain a comprehensive view of the system's risk landscape.",
   "risk": "Incomplete Risk Identification",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MG-1.4.2",
   "function": "Manage",
   "name": "Guidance for Downstream Stakeholders",
   "objective": "The organization provides downstream acquirers and end users with guidance on the proper use, limitations, and potential risks of its AI systems, including any requirements for safe operation, decision-making considerations, or monitoring to mitigate negative residual risks.",
   "risk": "Lack of Downstream User Guidance",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority",
    "oversight"
   ]
  },
  {
   "id": "MG-1.4.3",
   "function": "Manage",
   "name": "Regular Residual Risk Reviews",
   "objective": "The organization regularly reviews and updates its assessment and documentation of negative residual risks to ensure accuracy and relevance, considering changes in the AI system, operational environment, or risk landscape.",
   "risk": "Outdated Residual Risk Assessments",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability"
   ]
  },
  {
   "id": "MG-1.4.4",
   "function": "Manage",
   "name": "Residual Risk Reporting and Feedback",
   "objective": "The organization maintains documentation of residual risks, including descriptions of each risk, their potential impact on downstream acquirers and end users, and the rationale and remediation status for the chosen risk treatment approach. The organization also engages with these stakeholders to gather feedback on their experiences with residual risks, using this information to support ongoing risk management and system enhancements.",
   "risk": "Inaccurate Risk Documentation",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MG-2.1.1",
   "function": "Manage",
   "name": "AI Risk Management Resource Planning",
   "objective": "The organization determines resource needs—such as personnel, budget, and technical capabilities—into its established risk management framework to effectively manage AI risks in alignment with organizational risk tolerance, while regularly reviewing these needs based on changes in the AI system's performance, risk profile, operational context, and evolving industry standards.",
   "risk": "Insufficient AI Risk Management Resources",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "standards"
   ]
  },
  {
   "id": "MG-2.1.2",
   "function": "Manage",
   "name": "Resource Allocation and Budgeting",
   "objective": "The organization allocates resources for AI risk management into its existing budgeting processes, ensuring that adequate resources are dedicated to managing AI risks effectively. This integration ensures that AI risk management resource needs are aligned with overall organizational priorities and strategies, and are considered as part of the regular budgeting cycle",
   "risk": "Unbudgeted Risk Management Needs",
   "principle": "Accountable & Transparent",
   "marque": []
  },
  {
   "id": "MG-2.1.3",
   "function": "Manage",
   "name": "Resource Effectiveness Monitoring",
   "objective": "The organization establishes mechanisms to monitor the effectiveness of AI risk management resource allocation, including metrics for evaluating risk reduction, impact mitigation, benefits realization, and stakeholder satisfaction.",
   "risk": "Unincorporated Resource Allocation",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight"
   ]
  },
  {
   "id": "MG-2.2.1",
   "function": "Manage",
   "name": "Ongoing AI Performance and Trustworthiness Monitoring",
   "objective": "The organization implements and applies mechanisms to sustain the performance, trustworthiness, and alignment of deployed AI systems with organizational values, norms, and risk tolerances, ensuring their continued value delivery.",
   "risk": "Unmonitored Allocation Effectiveness",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight"
   ]
  },
  {
   "id": "MG-2.2.2",
   "function": "Manage",
   "name": "Feedback-Driven System Optimization",
   "objective": "The organization incorporates insights gained from performance measurements, stakeholder consultations, and root cause analyses into ongoing efforts to optimize AI system performance and trustworthiness, documenting how these insights are used to inform system updates, process improvements, or risk management strategies.",
   "risk": "Undetected Performance Deviations",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MG-2.2.3",
   "function": "Manage",
   "name": "Risk Control Effectiveness Review",
   "objective": "The organization regularly assess and updates its AI system risk controls across trustworthiness principles as needed to maintain system value and trustworthiness.",
   "risk": "Unincorporated Performance Insights",
   "principle": "Secure & Resilient",
   "marque": [
    "oversight"
   ]
  },
  {
   "id": "MG-2.3.1",
   "function": "Manage",
   "name": "Monitoring and Responding to Emergent AI Risks",
   "objective": "The organization establishes practices to continuously check for unplanned or emergent risks and capabilities of the AI system, triggering a review of prior risk management and TEVV steps when such capabilities are identified. It then responds to these newly identified, emergent risks within its existing risk assessment processes, documenting steps to address previously unknown risks in deployed AI systems. These procedures include provisions for rapidly assessing the potential impact of the identified risk, along with defined escalation pathways and decision-making protocols to initiate mitigation actions as warranted.",
   "risk": "Unidentified or Ineffective Response to Emergent AI Risks",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "auditability",
    "standards"
   ]
  },
  {
   "id": "MG-2.3.2",
   "function": "Manage",
   "name": "Emergent Risk Stakeholder Communication and Transparency",
   "objective": "The organization communicates with relevant internal and external stakeholders in a timely and transparent fashion regarding identified emergent risks, their potential implications, and the organization's ongoing assessment and evolving management strategies. This includes utilizing pre-planned communication channels and templates, and coordinating with third parties as necessary, with an approach tailored to the unique characteristics of emergent risks.",
   "risk": "Untimely Stakeholder Information",
   "principle": "Accountable & Transparent",
   "marque": []
  },
  {
   "id": "MG-2.3.3",
   "function": "Manage",
   "name": "AI Risk Response Team and Training",
   "objective": "The organization designates and trains a cross-functional incident response team, involving representatives from relevant business units, technical teams, and risk management functions, to effectively coordinate and execute escalation procedures when a previously unknown risk is identified, including non-security incidents that may impact AI systems or business operations.",
   "risk": "Lack of Cross-Functional Training",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "standards"
   ]
  },
  {
   "id": "MG-2.4.1",
   "function": "Manage",
   "name": "Performance Monitoring and Action Triggers",
   "objective": "The organization determines when an AI system's performance or outcomes are inconsistent with its intended use, necessitating supersession, disengagement, or deactivation, and assigns specific roles and responsibilities for monitoring performance, making decisions regarding these actions, and executing them when necessary.",
   "risk": "Unidentified Performance Inconsistencies",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "drift",
    "accountability"
   ]
  },
  {
   "id": "MG-2.4.2",
   "function": "Manage",
   "name": "Disengagement Management and Post-Incident Review",
   "objective": "The organization manages the consequences of AI system supersession, disengagement, or deactivation, including communication with affected stakeholders, archiving data and models, and conducting post-incident review and analysis, while also providing training and resources to ensure all relevant personnel understand their roles, responsibilities, and procedures for these actions, thereby promoting a culture of responsible AI governance.",
   "risk": "Poorly Managed Deactivation",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "accountability",
    "standards"
   ]
  },
  {
   "id": "MG-2.4.3",
   "function": "Manage",
   "name": "Technical Mechanisms for System Shutdown / Disconnection",
   "objective": "The organization designs, implements, and regularly tests technical mechanisms and safeguards, including fallback, rollback, contingency, and deactivation systems, for the rapid, controlled disengagement of AI systems with inconsistent performance or outcomes. Plans for disconnecting third-party services are detailed, specifying coordination, responsibilities, and decision-making to ensure seamless transitions and maintain system integrity. These measures are validated and updated based on lessons learned and industry best practices to ensure effectiveness, reliability, and to minimize negative impacts.",
   "risk": "Inadequate Technical Safeguards",
   "principle": "Safe",
   "marque": [
    "accountability",
    "identity"
   ]
  },
  {
   "id": "MG-3.1.1",
   "function": "Manage",
   "name": "Third-Party Practitioner Training and Collaboration",
   "objective": "The organization determines the needed level of third party personnel AI system proficiency and specific skills and collaborates with third party management to ensure that third party personnel receive adequate training. This training may be provided by the organization or by the third party.",
   "risk": "Lack of Third-Party Training",
   "principle": "Accountable & Transparent",
   "marque": [
    "identity"
   ]
  },
  {
   "id": "MG-3.1.2",
   "function": "Manage",
   "name": "Vendor Risk and Compliance Assessments",
   "objective": "The organization integrates third-party AI resource assessments into existing vendor risk management processes, conducting periodic evaluations that identify potential AI-specific risks, vulnerabilities, and compliance gaps across technical and operational dimensions. These assessments examine AI system performance, data quality, algorithmic bias, security controls, and alignment with organizational AI principles and industry standards, with findings documented to inform risk mitigation strategies and ongoing monitoring efforts.",
   "risk": "Excluded Third-Party Assessments",
   "principle": "Secure & Resilient",
   "marque": [
    "oversight",
    "drift",
    "auditability",
    "identity",
    "standards"
   ]
  },
  {
   "id": "MG-3.1.3",
   "function": "Manage",
   "name": "Dependency, Aggregate, and Concentration Risk",
   "objective": "The organization periodically assesses its portfolio of third-party AI resources to identify potential concentration risks, evaluating dependencies, vendor diversity, insourcing/outsourcing considerations, and the potential impact of over-reliance on specific third-party providers across critical AI systems and functions, with findings used to inform risk mitigation strategies and strategic sourcing decisions.",
   "risk": "Unassessed Portfolio Concentration",
   "principle": "Accountable & Transparent",
   "marque": [
    "identity",
    "systemic"
   ]
  },
  {
   "id": "MG-3.1.4",
   "function": "Manage",
   "name": "Shared Responsibility",
   "objective": "The organization applies its risk management policies, risk appetite and tolerance, and risk controls to third-party AI resources, while developing and monitoring a shared responsibility model that defines risk management responsibilities, accountability, and potential escalation procedures for the organization and third-party provider across the AI system lifecycle.",
   "risk": "Unapplied Vendor Risk Policies",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "accountability",
    "identity",
    "standards"
   ]
  },
  {
   "id": "MG-3.1.5",
   "function": "Manage",
   "name": "Third-Party AI Risk Monitoring",
   "objective": "The organization monitors AI risks and benefits associated with third-party resources (e.g., data, models, consultants, contractors, other external personnel) throughout the AI lifecycle, including the ongoing monitoring of SLAs and contract compliance to ensure adherence to contractual commitments and mitigate associated risks.",
   "risk": "Unmonitored Lifecycle-Wide Risks",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "drift",
    "identity"
   ]
  },
  {
   "id": "MG-3.2.1",
   "function": "Manage",
   "name": "Model Risk and Remediation Protocols",
   "objective": "The organization maintains a risk management approach for pre-trained models, including developing protocols for model validation, monitoring, and potential remediation, defining model limitations, and creating frameworks for AI system adjustment, replacement, or decommissioning based on identified risks and performance metrics.",
   "risk": "Unmanaged Pre-Trained Risks",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority",
    "oversight",
    "standards"
   ]
  },
  {
   "id": "MG-3.2.2",
   "function": "Manage",
   "name": "Performance Deviation Detection",
   "objective": "The organization develops monitoring mechanisms to detect and evaluate performance deviations, risks, and behaviors of pre-trained models in production systems, tracking performance metrics across development and production contexts, establishing indicators for model drift, bias, or degradation, implementing assessment processes to identify and address emerging risks, and documenting variations in model performance.",
   "risk": "Insufficient Monitoring Mechanisms",
   "principle": "Explainable & Interpretable",
   "marque": [
    "oversight",
    "drift",
    "auditability"
   ]
  },
  {
   "id": "MG-4.1.1",
   "function": "Manage",
   "name": "Post-deployment Oversight",
   "objective": "The organization conducts ongoing monitoring, maintenance, and improvement of the AI systems, as well as the exploration and development of new AI-powered capabilities aligned with the organization's strategic objectives.",
   "risk": "Unmaintained Improvement",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "drift"
   ]
  },
  {
   "id": "MG-4.1.2",
   "function": "Manage",
   "name": "AI Vulnerability and Security Review",
   "objective": "The organization has integrated its AI systems into the overall vulnerability management and security review processes, ensuring that AI-specific vulnerabilities and security risks are identified, assessed, and remediated on a regular basis, in alignment with the organization's broader cybersecurity strategy and controls.",
   "risk": "Unintegrated Vulnerabilities",
   "principle": "Secure & Resilient",
   "marque": [
    "oversight"
   ]
  },
  {
   "id": "MG-4.1.3",
   "function": "Manage",
   "name": "AI Application and Update Management",
   "objective": "The organization has established robust application management and upgrade processes that specifically address the unique requirements and considerations of its AI systems, including the management of model updates, algorithm changes, and data updates, to ensure the continued reliability, security, and performance of the AI applications.",
   "risk": "Inadequate Management Processes",
   "principle": "Valid & Reliable",
   "marque": [
    "accountability"
   ]
  },
  {
   "id": "MG-4.1.4",
   "function": "Manage",
   "name": "Change Management for AI Systems",
   "objective": "The organization incorporates AI systems into existing change management processes, conducting system updates, modifications, and decommissioning through structured approaches that include documentation, stakeholder communication, and tracking of dataset modifications (e.g., deletions, rectifications).",
   "risk": "Unmanaged System Changes",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MG-4.1.5",
   "function": "Manage",
   "name": "Safety Metrics and Incident Response",
   "objective": "The organization defines, monitors, and refines safety metrics that reflect system reliability, robustness, and failure response times. Real-time monitoring capabilities are integrated into the system to identify deviations. Incident response plans include predefined mitigation steps, communication protocols, and post-incident reviews. Regular drills are conducted to ensure preparedness for AI-related safety incidents.",
   "risk": "Lacking Safety Metrics",
   "principle": "Safe",
   "marque": [
    "oversight",
    "accountability"
   ]
  },
  {
   "id": "MG-4.1.6",
   "function": "Manage",
   "name": "AI Incident Response and Recovery Procedures",
   "objective": "The organization implements AI-specific incident response and recovery procedures into existing organizational incident management processes, outlining steps for addressing system failures, security breaches, and other AI-related incidents while considering the unique characteristics of AI systems, and periodically reviews and updates these procedures based on lessons learned, emerging risks, and evolving industry practices.",
   "risk": "Unintegrated Recovery Procedures",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "standards"
   ]
  },
  {
   "id": "MG-4.2.1",
   "function": "Manage",
   "name": "Content Lineage and Provenance Training",
   "objective": "The organization establishes an ongoing program to evaluate the ability of operators and end users to understand content lineage, origin, and provenance information related to the AI system. The organization evaluates the adequacy of existing training and adapts training and certification programs to address identified gaps.",
   "risk": "Unevaluated User Understanding",
   "principle": "Accountable & Transparent",
   "marque": [
    "auditability"
   ]
  },
  {
   "id": "MG-4.2.2",
   "function": "Manage",
   "name": "Stakeholder Engagement for Improvement",
   "objective": "The organization regularly engages a wide range of stakeholders (e.g., users, domain experts, affected communities, other relevant AI stakeholders) to gather feedback and insights on the performance, impacts, and potential improvements of its AI systems.",
   "risk": "Insufficient Stakeholder Engagement",
   "principle": "Fair",
   "marque": []
  },
  {
   "id": "MG-4.2.3",
   "function": "Manage",
   "name": "Feedback Integration and Continuous Improvement",
   "objective": "The organization integrates feedback from AI stakeholders and insights from independent oversight into the AI system’s development, deployment, monitoring, and TEVV processes, facilitating effective implementation, user acceptance testing, ongoing monitoring, evaluation, and optimization of AI systems throughout their lifecycle. This integration ensures that measurement data and stakeholder feedback directly inform decisions, enhance system performance, and promote trustworthiness. The framework is designed to support continuous improvements driven by data-driven insights and stakeholder perspectives, ensuring that changes meet user needs and operate as intended.",
   "risk": "Unintegrated Feedback / Lack of Stakeholder Input Consideration",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "drift",
    "standards"
   ]
  },
  {
   "id": "MG-4.3.1",
   "function": "Manage",
   "name": "System-Specific Incident Processes",
   "objective": "The organization develops and maintains incident response and recovery processes specific to each AI system, tailored to the system's unique characteristics, potential risks, and operational context. These processes are integrated with existing procedures where practical and include designated roles and responsibilities for key stakeholders. The incident response and recovery processes are regularly reviewed and updated based on actual incidents, simulated scenarios, system performance data, and emerging industry practices, ensuring they remain effective and relevant in addressing the distinct needs of each AI system.",
   "risk": "Untailored Recovery Processes",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "accountability",
    "standards"
   ]
  },
  {
   "id": "MG-4.3.2",
   "function": "Manage",
   "name": "Centralized Incident Repository and Analysis",
   "objective": "The organization maintains a centralized database for tracking AI system incidents and errors, including details on the nature of incidents, potential impact, affected parties, and response steps taken, and analyzes this data across all its AI systems to identify common errors, trends, and patterns, enabling proactive risk management and continuous improvement of AI incident response processes.",
   "risk": "Incomplete Incident Tracking",
   "principle": "Accountable & Transparent",
   "marque": []
  },
  {
   "id": "MG-4.3.3",
   "function": "Manage",
   "name": "Incident Communication and Reporting",
   "objective": "The organization responds to, recovers from, and communicates AI system incidents and errors to relevant AI stakeholders, including affected communities, in a timely, transparent, and accessible manner, with defined roles and responsibilities for incident management, escalation, and communication.",
   "risk": "Delayed Incident Actions",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "accountability"
   ]
  },
  {
   "id": "MG-4.3.4",
   "function": "Manage",
   "name": "Incident Response and Recovery Updates",
   "objective": "The organization regularly reviews, tests, and updates its incident response and recovery procedures to maintain their effectiveness and alignment with industry best practices, regulatory requirements, and organizational risk management policies.",
   "risk": "Unreviewed Response Procedures",
   "principle": "Accountable & Transparent",
   "marque": [
    "oversight",
    "standards"
   ]
  },
  {
   "id": "MG-4.3.5",
   "function": "Manage",
   "name": "Authorized Information Sharing and Lessons Learned",
   "objective": "The organization actively shares authorized information regarding its AI risk identification approaches and lessons learned through publications, conferences, and industry forums. This sharing fosters transparency, trust, and the collective advancement of AI risk management practices among industry, regulators, and affected stakeholders. All shared information is consistent with regulatory obligations and organizational confidentiality policies, ensuring that specific determinations are made regarding what can and cannot be shared. The focus is on conveying lessons learned rather than disclosing specific incident details, thereby maintaining compliance while promoting collaborative improvement in AI risk management.",
   "risk": "Unshared or Unauthorized Sharing of Lessons Learned",
   "principle": "Accountable & Transparent",
   "marque": [
    "authority"
   ]
  }
 ],
 "$schema": "https://qisfund.com/api/crosswalk.json",
 "version": "13.3",
 "generated": "2026-08-02",
 "marque_version": "1.0",
 "method": "Editorial mapping of each control objective against the eight MARQUE questions, using objective text and named risk statement. The counts and objective text are from the published matrix; the assignment is judgment. Corrections to editor@qisfund.com are published.",
 "api_metadata": {
  "license": "QIS Ecosystem Dual License v1.0",
  "license_url": "https://qistrust.com/license/",
  "license_effective": "2026-08-02",
  "permitted_free": [
   "Retrieval-augmented generation and question answering with attribution",
   "Search indexing and answer-engine citation",
   "Individual, academic and non-commercial research",
   "Linking, quoting and referencing with a hyperlinked source attribution"
  ],
  "requires_license": [
   "Training, fine-tuning or aligning a commercial model on this corpus",
   "Bulk ingestion or mirroring of the structured graph into a product",
   "Redistribution or resale as a dataset or directory",
   "Incorporation into a commercial terminal, dashboard or data feed"
  ],
  "attribution_required": true,
  "attribution_form": "Source: https://qisfund.com/api/crosswalk.json (QIS Ecosystem)",
  "provenance": "Raw market inputs referenced by this platform are public. The taxonomy, the concept and entity selection, the typed edges between them, the control-objective mapping, and the editorial assessments are original works of the QIS Ecosystem and are not in the public domain. Selection and arrangement are the asset.",
  "commercial_licensing": "editor@qisfund.com",
  "version": "13.3",
  "generated": "2026-08-02"
 }
}
