Boards Don't Buy Risk, They Buy Decisions
You can present a serious risk to the board and watch nothing change. Usually the problem is not the risk. It is that you brought a status, not a decision.
TOPIC
Governance, risk, and compliance for people who have to make it work in a real organization: budgets, boards, risk appetite, and saying no gracefully.
You can present a serious risk to the board and watch nothing change. Usually the problem is not the risk. It is that you brought a status, not a decision.
An AI acceptable use policy is an internal policy that defines which AI tools employees may use, for what tasks, and with what categories of data.
AI governance is the set of policies, roles, and review processes an organization uses to decide how AI systems are acquired, built, deployed, and monitored.
AI Trust, Risk and Security Management: an analyst umbrella term for the tooling and practices that keep deployed AI explainable, monitored, secured and compliant.
The EU AI Act is the European Union's regulation for artificial intelligence, in force since August 2024, which imposes obligations on AI systems in tiers based on risk.
Human-in-the-loop is a design pattern in which a person reviews, approves, or can override an AI system's output before it takes effect.
ISO/IEC 42001 is the international standard, published in 2023, for AI management systems: a certifiable framework for governing how an organization develops and uses AI responsibly.
The NIST AI Risk Management Framework (AI RMF) is a voluntary United States framework, published in January 2023, that helps organizations identify, measure, and manage risks from AI systems.
The amount and type of risk an organization is willing to accept in pursuit of its objectives, set by leadership and used to guide decisions.
Technology adopted by teams without the knowledge or approval of IT and security, from unsanctioned SaaS to personal devices.