8
3.4 Management
Risk management includes the core risk controls and practices in the AI lifecycle. This pillar
enables organizations to actively reduce identified risks and adapt strategies to evolving threats
or standards.
For high-risk models, independent validation and oversight are essential to safeguard against
unintended consequences. To support responsible development and deployment, firms are
encouraged to form cross-functional teams and set up ethical review boards early in the
process. Additionally, the use of feedback loops and explainability tools can enhance
transparency and enable effective challenge of AI outputs.
Companies should also develop provisions for talent assessment and development, ensuring
they have the skills needed for effective AI Risk management.
3.5 Integration
AI usage introduces model risk, cyber risk, market and credit risk, operations risk, regulatory
risk, and a host of other risk factors. For this reason, companies should approach AI Risk from
a holistic standpoint, preferably incorporating the program into a broader Enterprise Risk
Management (“ERM”) framework and integrating activities with previously established risk
practices. The controls themselves should scale with the complexity and impact of AI Systems,
ensuring adaptability and resilience.
With respect to cyber risk, AI introduces new security exposures that can affect data,
operations, and decision-making. Threats range from corrupted inputs and manipulated
outputs to unauthorized access, data leakage, and vulnerabilities in the systems that support or
connect to AI. Effective protection requires strong access controls, targeted monitoring, and
incident response processes. In a companion paper, we will outline these and other emerging AI
security risks, including model and data security, data poisoning, API and integration security,
and cloud hosting.
In addition, companies should incorporate organizational readiness, training, and capability
pacing into their AI Risk Management Framework.
Best Practices for AI Risk Management Frameworks
• Defined roles, responsibilities, and decision rights across the AI lifecycle, including core
remits, oversight duties, and accountabilities
• Formal risk framework with elements related to governance, recognition, measurement,
management, and integration with other risk areas
• Defined incident response plans for AI-related failures
• Intentional collaboration across the industry to share best practices and align on standards
• Flexible, principles-based frameworks that remain relevant over time, rather than use-case-
based rules that can grow stale as technology progresses
• Explicit consideration of systemic risks, including the dangers of “AI checking AI,”
adversarial exploitation, market amplification, and lessons from past market incidents
informing policy
3.4 Management
Risk management includes the core risk controls and practices in the AI lifecycle. This pillar
enables organizations to actively reduce identified risks and adapt strategies to evolving threats
or standards.
For high-risk models, independent validation and oversight are essential to safeguard against
unintended consequences. To support responsible development and deployment, firms are
encouraged to form cross-functional teams and set up ethical review boards early in the
process. Additionally, the use of feedback loops and explainability tools can enhance
transparency and enable effective challenge of AI outputs.
Companies should also develop provisions for talent assessment and development, ensuring
they have the skills needed for effective AI Risk management.
3.5 Integration
AI usage introduces model risk, cyber risk, market and credit risk, operations risk, regulatory
risk, and a host of other risk factors. For this reason, companies should approach AI Risk from
a holistic standpoint, preferably incorporating the program into a broader Enterprise Risk
Management (“ERM”) framework and integrating activities with previously established risk
practices. The controls themselves should scale with the complexity and impact of AI Systems,
ensuring adaptability and resilience.
With respect to cyber risk, AI introduces new security exposures that can affect data,
operations, and decision-making. Threats range from corrupted inputs and manipulated
outputs to unauthorized access, data leakage, and vulnerabilities in the systems that support or
connect to AI. Effective protection requires strong access controls, targeted monitoring, and
incident response processes. In a companion paper, we will outline these and other emerging AI
security risks, including model and data security, data poisoning, API and integration security,
and cloud hosting.
In addition, companies should incorporate organizational readiness, training, and capability
pacing into their AI Risk Management Framework.
Best Practices for AI Risk Management Frameworks
• Defined roles, responsibilities, and decision rights across the AI lifecycle, including core
remits, oversight duties, and accountabilities
• Formal risk framework with elements related to governance, recognition, measurement,
management, and integration with other risk areas
• Defined incident response plans for AI-related failures
• Intentional collaboration across the industry to share best practices and align on standards
• Flexible, principles-based frameworks that remain relevant over time, rather than use-case-
based rules that can grow stale as technology progresses
• Explicit consideration of systemic risks, including the dangers of “AI checking AI,”
adversarial exploitation, market amplification, and lessons from past market incidents
informing policy

















