What is NIST AI RMF? The AI Risk Management Framework explained
NIST AI RMF is a voluntary framework from the US National Institute of Standards and Technology that helps organisations manage AI risks across the lifecycle. It is the most widely adopted foundation for AI governance programmes.
Why ChatGPT is not enough for AI governance
Generative AI can draft policies, controls, risk-assessment questions and remediation tasks. It cannot, on its own, run an AI governance programme.
What is AI vendor due diligence?
AI vendor due diligence is the assessment of an AI-enabled supplier against your AI governance standards – covering use case, data flows, model provenance, oversight and incident reporting.
What is an AI use-case register?
An AI use-case register is the live inventory of where AI is used inside an organisation – what it does, who owns it, what data it uses, what oversight applies.
AI governance software vs. AI chatbots
AI chatbots can generate compliance content. AI governance software runs the programme around that content. They solve different problems.
Why AI is not enough for compliance management
AI accelerates the production of compliance content. It does not, by itself, produce a defensible compliance programme. The work that survives audit is structural, not generative.
What is Third-Party Risk Management (TPRM)?
Third-Party Risk Management is the process of identifying, assessing and monitoring risks created by suppliers, processors, service providers, contractors and other external parties.
What is third-party due diligence?
Third-party due diligence is the evaluation of an external party – supplier, processor, vendor or service provider – before and during the relationship.
What is third-party privacy risk?
Third-party privacy risk is the risk that an external party processing personal data on your behalf fails to meet your obligations under privacy law.
What is AI third-party risk?
AI third-party risk is the risk arising from external AI capabilities – model providers, AI-enabled SaaS, AI consultants and AI service providers. Distinct from standard vendor risk because of the AI-specific dimensions involved.