AI RISK ENGINEERING

Govern risk as part of the system.

A practical operating model inspired by the NIST AI Risk Management Framework: Govern, Map, Measure, and Manage.

PRODUCTION READINESS

Can this AI system safely move beyond pilot?

Score the operating evidence—not the quality of the demo.

8/ 24

ASSESSMENT

Pilot only

Controls and evidence are not yet sufficient for consequential production use.

    Scale: 0 absent · 1 informal · 2 documented · 3 tested with evidence. This is an educational review aid, not a certification.

    GOVERN

    Ownership and policy

    Define accountable owners, acceptable use, escalation, review cadence, documentation, and decision rights.

    • System owner and business owner
    • Risk tolerance and prohibited uses
    • Change control and incident response
    MAP

    Context and impact

    Describe users, data, decisions, dependencies, affected people, and the consequences of failure.

    • Use-case boundaries
    • Data and stakeholder map
    • Impact and dependency analysis
    MEASURE

    Evidence and testing

    Measure validity, reliability, security, privacy, fairness, explainability, and human oversight.

    • Task and safety evaluations
    • Red-team and abuse testing
    • Production monitoring thresholds
    MANAGE

    Controls and response

    Prioritize risks, deploy controls, monitor residual risk, and change or stop the system when evidence requires it.

    • Guardrails and approvals
    • Rollback and containment
    • Continuous review and remediation

    TRUSTWORTHINESS CHECK

    Eight questions for every AI system.

    Validity

    Does it perform the intended task under realistic conditions?

    Safety

    Can failures cause physical, financial, operational, or social harm?

    Security

    Can users, data, tools, or instructions be manipulated?

    Privacy

    Is data collection, use, retention, and deletion appropriate?

    Accountability

    Who owns outcomes, approvals, incidents, and changes?

    Transparency

    Can users understand when AI is involved and what it did?

    Fairness

    Are performance and impacts evaluated across relevant groups?

    Human oversight

    Can people review, interrupt, correct, and appeal outcomes?

    Framework reference: NIST AI RMF resources ↗