AI Governance Frameworks
NIST AI RMF, ISO/IEC 42001, internal review boards, and turning principles into gates that actually block.
5concepts
54flashcards
35minutes of reading
- 01 ISO/IEC 42001 and Certifiable Management Systems What a management system standard certifies, why certification is about process consistency rather than model quality, and where it fits alongside a risk framework.
- 02 Risk Tiering and Impact Assessment How to classify AI systems by consequence rather than by technology, what an impact assessment should establish before a system is built, and why the affected-population question is the one that changes designs.
- 03 The NIST AI Risk Management Framework What the four functions of the AI RMF actually ask an organisation to do, why Govern is the one that determines whether the rest happens, and what a voluntary framework can and cannot deliver.
- 04 Incident Response for AI Systems Why an AI incident often has no error to page on, what detection has to rely on instead, and the response steps that differ from a conventional outage.
- 05 Turning Principles into Gates That Block Why AI principles documents change nothing on their own, the properties a gate needs to have force, and the design that keeps a review board from becoming either a bottleneck or a formality.