What is AI third-party risk?

AI third-party risk is the risk arising from external AI capabilities – model providers, AI-enabled SaaS, AI consultants and AI service providers. Distinct from standard vendor risk because of the AI-specific dimensions involved.

What is GRC and operational risk?

GRC stands for Governance, Risk and Compliance – the discipline of running an organisation in a controlled, evidenced way. Operational risk is the sub-domain concerned with risks from internal processes, people, systems and external events.

What is a risk register?

A risk register is the structured list of identified risks an organisation is tracking – with severity, likelihood, owner, treatment and review date.

What are controls and criteria?

In a risk framework, controls are the things you do to mitigate a risk. Criteria are the conditions a control must satisfy to be considered effective.