GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

AIG-005 AI Risk Management Process

Tier 2+AIProviderDeployerGPAI Model ProviderManaged Service Provider

Description

A documented process for identifying, analysing, evaluating and treating AI risks is established and applied throughout the lifecycle of each AI system. The process identifies risks to health, safety, fundamental rights and business operations. Risk assessments are performed before deployment and at defined intervals, at minimum annually and after any substantial modification. Residual risks are documented and accepted by an accountable owner. Measurable AI risk objectives derived from the risk appetite in AIG-001 are recorded, tracked and reviewed at defined intervals and inform the resources allocated to AI risk management.

Rationale

A lifecycle risk management process is the engine of AI governance; policy and roles are insufficient without an operational assessment mechanism. Systemic risk from a designated general-purpose model, assessed at Union level with capability-tier acceptance criteria, is AIG-050; this control continues to govern the systems built on the model.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredrisk class duty

Art.9(1) makes the process a risk management system established, implemented, documented and maintained across the entire lifecycle, which is a standing system rather than an assessment repeated on a cycle. It is the artefact Art.11 and Annex IV expose to an authority. Art.9(2) fixes what it identifies, known and reasonably foreseeable risks to health, safety and fundamental rights under intended use and under reasonably foreseeable misuse, with post-market monitoring data as a named input. Art.9(3) bounds it to risks that design, development or adequate technical information can reasonably mitigate, so a risk parked as the deployer's problem needs that information supplied under Art.13. Art.9(5) requires each hazard's residual risk and the overall residual risk to be judged acceptable, with design-level elimination taken before mitigation and before informational controls, which is stronger than an accountable owner's acceptance. The Art.9(9) vulnerable-groups consideration sits on AIG-006.

Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (43)

GRC-02Risk Management Programfull
GRC-10AI Impact Assessmentinformative
EU-AI-Art.55.2Systemic Risk Obligations — Systemic Risk Assessment and Mitigationinformative
EU-AI-Art.9.1AI Risk Management System — Establishment and Maintenancefull
EU-AI-Art.9.2AI Risk Management System — Risk Identification and Analysisfull
EU-AI-Art.9.3AI Risk Management System — Scope of Risks to Mitigateinformative
EU-AI-Art.9.4AI Risk Management System — Residual Risk Acceptabilityfull
COP-S-1Safety and Security Frameworkinformative
COP-S-1.2Implementing the Frameworkinformative
COP-S-1.3Updating the Frameworkinformative
COP-S-2Systemic risk identificationinformative
COP-S-2.1Systemic risk identification processinformative
COP-S-3Systemic risk analysisinformative
COP-S-4Systemic risk acceptance determinationinformative
COP-S-8.2Allocation of appropriate resourcesinformative
A.6.1.2Objectives for responsible development of AI systempartial
A.6.1.3Processes for responsible AI system design and developmentfull
GV-1.3-001Risk Management Activity Level Determination | GV-1.3-001full
GV-1.3-005Risk Management Activity Level Determination | GV-1.3-005partial
GV-1.3-006Risk Management Activity Level Determination | GV-1.3-006informative
GV-4.1-001Safety-First Organisational Culture | GV-4.1-001partial
GV-4.2-002Organisational AI Risk Communication | GV-4.2-002partial
MG-1.3-001High-Priority Risk Response Planning | MG-1.3-001partial
MG-3.1-003Third-Party AI Risk Monitoring and Controls | MG-3.1-003informative
MG-4.1-001Post-Deployment AI System Monitoring | MG-4.1-001informative
MP-1.1-003AI System Purpose and Deployment Context | MP-1.1-003partial
MP-4.1-008AI Technology and Legal Risk Mapping | MP-4.1-008full
MS-1.1-005AI Risk Measurement Approach Selection | MS-1.1-005partial
MS-1.1-008AI Risk Measurement Approach Selection | MS-1.1-008informative
MS-1.1-009AI Risk Measurement Approach Selection | MS-1.1-009partial
MS-2.5-006AI System Validity and Reliability | MS-2.5-006informative
MS-2.6-003AI System Safety Risk Evaluation | MS-2.6-003partial
MS-3.2-001Risk Tracking for Measurement Gaps | MS-3.2-001partial
GOVERN 1.3Risk Management Activity Level Determinationfull
GOVERN 1.5Risk Management Monitoring and Reviewfull
GOVERN 4.2Organisational AI Risk Communicationpartial
MANAGE 1.1AI System Purpose and Deployment Determinationfull
MANAGE 1.2AI Risk Treatment Prioritizationfull
MANAGE 1.3High-Priority Risk Response Planningfull
MANAGE 1.4Residual Risk Documentationfull
MANAGE 2.1AI Risk Resource Planning and Non-AI Alternativespartial
MEASURE 1.1AI Risk Measurement Approach Selectioninformative
MEASURE 3.2Risk Tracking for Measurement Gapspartial

Evidence (3)

recorddocumentmanual

AI governance objectives and associated metrics, demonstrating that risk tolerance has been translated into measurable, time-bound objectives that inform resource allocation.

Example: AI Governance OKRs 2025–2026 (Notion), including measurable objectives such as 'bias testing coverage 100% of Tier 2+ systems by Q3 2025' and 'all AI systems mapped to risk tier by Q1 2026'

Test: Request AI governance objectives documentation. Verify: (1) objectives are derived from stated risk tolerance dimensions, (2) each objective has a measurable target and due date, (3) progress against objectives is tracked, (4) objectives were reviewed within the last 12 months.

recorddocumentmanual

Completed AI risk assessments for each production AI system, covering the risk identification, analysis, evaluation, and treatment steps, with residual risk sign-off by the named system owner.

Example: AI Risk Assessment · Customer Churn Model v3 (Confluence), completed 2025-08-12 prior to deployment, with treatment plan and residual risk accepted by Head of Data

Test: Request risk assessments for a sample of production AI systems (minimum 3 or all Tier 2+ systems). Verify each assessment: (1) was completed before deployment or within the last 12 months, (2) covers health, safety, fundamental rights, and business operations dimensions, (3) includes a documented treatment plan for identified risks, (4) has residual risk formally accepted by the named system owner, (5) was triggered again after any substantial modification.

policydocumentmanual

Documented AI risk management process defining how risks are identified, analysed, evaluated, treated, and accepted throughout the AI system lifecycle, including the trigger criteria for reassessment.

Example: AI Risk Management Procedure v2.0 (Confluence), defining risk assessment methodology, lifecycle trigger points, risk register format, and residual risk acceptance thresholds

Test: Request the AI risk management process document. Verify: (1) all four ISO 31000 phases (identify, analyse, evaluate, treat) are described with method guidance, (2) lifecycle triggers for reassessment are defined (including 'substantial modification'), (3) the process specifies who conducts and who approves assessments, (4) retention period for completed assessments is stated.

Questions (3)

boolean

Does your organisation apply a documented risk management process to AI systems throughout their lifecycle?

The process should cover risk identification, analysis, evaluation, treatment, and residual risk acceptance. It should be triggered before deployment and after any substantial modification, not only at initial development.

multi

At which points in the AI system lifecycle is a formal risk assessment conducted?

Before initial deploymentAnnually for all production AI systemsAfter any substantial modification to the systemWhen the system's deployment context or user population changes materiallyWhen new regulatory obligations come into effectNone of the above

Assessments conducted only at initial deployment miss risk accumulation from model drift, changed use contexts, and regulatory evolution. A mature process triggers reassessment at all five points.

select

How are your AI risk tolerance statements expressed?

Qualitative principles only (e.g. 'we prioritise safety')Qualitative with some measurable targets for selected dimensionsMeasurable thresholds defined for all major risk dimensionsMeasurable thresholds linked to specific AI governance objectives with tracked progress

Enterprise buyers should expect at minimum quantified thresholds for the risk dimensions relevant to your AI use cases. Qualitative-only statements cannot be verified or used to drive consistent risk treatment decisions.