MN-1.4 Negative residual risks, defined as the sum of all unmitigated risks, to both downstream acquirers of AI systems and end users are documented
Negative residual risks (defined as the sum of all unmitigated risks) to both downstream acquirers of AI systems and end users are documented. What remains unmitigated is totalled and documented, and communicated to down
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- Evidence residual risk was communicated to those parties · Document repository
governing documentDocuments that govern the control
- The documented residual risk position after treatment · Document repository
- Identification of downstream acquirers and end users who bear residual risk · Document repository
- The authority that accepted the residual position · Document repository
First move
Common gaps auditors find
- Residual risk computed internally and never disclosed downstream
- Individual residual risks listed with no aggregate position
- Residual position stale because treatments changed after it was recorded
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetMN-1.3 Responses to the AI risks deemed high priority as identified by the MAP function are developed, planned, and documented, and risk response options can include mitigating, transferring, avoiding, or accepting · MN-2.1 Resources required to manage AI risks are taken into account, along with viable non-AI alternative systems, approaches, or methods, to reduce the magnitude or likelihood of potential impacts