Ownership and policy
Define accountable owners, acceptable use, escalation, review cadence, documentation, and decision rights.
- System owner and business owner
- Risk tolerance and prohibited uses
- Change control and incident response
AI RISK ENGINEERING
A practical operating model inspired by the NIST AI Risk Management Framework: Govern, Map, Measure, and Manage.
PRODUCTION READINESS
Score the operating evidence—not the quality of the demo.
Scale: 0 absent · 1 informal · 2 documented · 3 tested with evidence. This is an educational review aid, not a certification.
Define accountable owners, acceptable use, escalation, review cadence, documentation, and decision rights.
Describe users, data, decisions, dependencies, affected people, and the consequences of failure.
Measure validity, reliability, security, privacy, fairness, explainability, and human oversight.
Prioritize risks, deploy controls, monitor residual risk, and change or stop the system when evidence requires it.
TRUSTWORTHINESS CHECK
Does it perform the intended task under realistic conditions?
Can failures cause physical, financial, operational, or social harm?
Can users, data, tools, or instructions be manipulated?
Is data collection, use, retention, and deletion appropriate?
Who owns outcomes, approvals, incidents, and changes?
Can users understand when AI is involved and what it did?
Are performance and impacts evaluated across relevant groups?
Can people review, interrupt, correct, and appeal outcomes?
Framework reference: NIST AI RMF resources ↗