7
3.1 Governance
The framework should start with clear policies, ethical principles, and integration with legal
and compliance structures. It should emphasize human oversight and accountability for all AI-
related development and usage.
The CCRO advocates a framework-first approach, emphasizing the need for governance
maturity before widespread AI deployment.
3.2 Recognition
Firms should formalize AI Risk recognition by establishing a tiered classification system
reflecting the risk and materiality of each AI System or Tool. They should also identify and
document potential risks at every stage of the AI lifecycle, mapping context, intended use,
stakeholders, and potential impacts. An AI Risk register should be maintained to ensure
visibility into exposures and promote accountability.
3.3 Measurement
Risk measurement provides the evidence needed for informed decision-making and for
prioritizing risk mitigation efforts. Firms should analyze and quantify risks based on system
behavior, fairness, security, and data quality. Firms should include both their inherent risk and
broader system risks (e.g. flash crashes, common data sets, etc.) in this analysis.
Previous Page Next Page