What is AI third-party risk?
AI third-party risk is the risk arising from external AI capabilities – model providers, AI-enabled SaaS, AI consultants and AI service providers. Distinct from standard vendor risk because of the AI-specific dimensions involved.
What is GRC and operational risk?
GRC stands for Governance, Risk and Compliance – the discipline of running an organisation in a controlled, evidenced way. Operational risk is the sub-domain concerned with risks from internal processes, people, systems and external events.
What is a risk register?
A risk register is the structured list of identified risks an organisation is tracking – with severity, likelihood, owner, treatment and review date.
What are controls and criteria?
In a risk framework, controls are the things you do to mitigate a risk. Criteria are the conditions a control must satisfy to be considered effective.