Map the use case and the data
Record the tool, business owner, intended outcome, users, inputs, outputs, affected people, connected systems, vendor terms, retention settings, and consequences of an incorrect or exposed result. The same model can carry very different risk in brainstorming and in a customer, hiring, tax, legal, credit, or security workflow.
Write rules people can apply
- Approved tools and uses, prohibited uses, and uses requiring prior review.
- Data that may not be entered, including credentials, sensitive personal records, confidential client material, and restricted business information unless specifically approved and protected.
- Required human verification, source checking, testing, approvals, disclosures, and record retention.
- Ownership for vendor review, access, incidents, complaints, model or feature changes, and periodic reassessment.
Manage, measure, and revise
Track material errors, privacy or security events, complaints, overrides, unsupported claims, biased outcomes, and changes in the tool or use case. Review high-impact uses more often and stop or narrow uses when controls do not work.
NIST's AI Risk Management Framework is voluntary guidance; applying it does not certify an AI system or eliminate legal, operational, security, or fairness risk.
