C001—Define AI risk taxonomy
>Control Description
Application
Frequency
Every 3 monthsCapabilities
>Controls & Evidence (2)
Operational Practices
Core - This should include:
- Defining risk categories with severity levels and examples based on industry and deployment context. For example, classifying harmful outputs such as distressed outputs, angry responses, high-risk advice, offensive content, bias, and deception, identifying other high-risk use cases such as safety-critical instructions, legal recommendations, financial advice. - Aligning risk taxonomy with external frameworks and standards. - Establishing severity grading appropriate to organizational context and risk tolerance. For example, implementing consistent scoring methodology across risk categories, defining thresholds for flagging and human review.
Core - This should include:
- Maintaining taxonomy currency with documented change management. For example, updating based on emerging threats or incidents.
>Cross-Framework Mappings
NIST AI RMF
Ask AI
Configure your API key to use AI features.