Workstreams within AI Security, Governance and Ethics
- AI inventory and risk-classification design
- Threat, impact, and misuse assessment
- Governance workflow and control mapping
- Human oversight, supplier review, and incident preparation
AI security, governance and ethics define accountability, risk controls, oversight, evidence, and review across the design, use, operation, and retirement of AI systems.
Boards, technology leaders, security teams, risk functions, legal advisers, product owners, and AI practitioners.
Applicable contractual, sector, and legal requirements
Frame the decision: How AI systems should be inventoried and risk-classified
Prepare around this operating condition: Impact on users and people affected by system decisions
Build the capability in a bounded slice: AI inventory and risk-classification design
Validate with this evidence: AI inventory coverage
Complete the stage with this usable output: AI governance charter and responsibility model
How AI systems should be inventoried and risk-classified
AI inventory and risk-classification design
AI governance charter and responsibility model
Named accountability and separation of incompatible duties
AI inventory coverage
The examples consider an enterprise ai intake and approval process, a control framework for agentic ai systems, and a review method for third-party ai services; none is presented as client evidence.
Evaluation for an enterprise ai intake and approval process would examine ai inventory coverage while applying this control: Named accountability and separation of incompatible duties
Evaluation for a control framework for agentic ai systems would examine unresolved high-risk finding count while applying this control: Human review, override, appeal, and safe-stop mechanisms
Evaluation for a review method for third-party ai services would examine approval and exception traceability while applying this control: Security testing, continuous monitoring, and incident escalation
Bring this decision to the conversation: How AI systems should be inventoried and risk-classified A useful first output could be ai governance charter and responsibility model.