MS-1.1 Approaches and metrics for measurement of AI risks enumerated during the MAP function are selected for implementation starting with the most significant AI risks, and the risks or trustworthiness characteristics that will not or cannot be measured are properly documented
Approaches and metrics for measurement of AI risks enumerated during the Map function are selected for implementation starting with the most significant AI risks. The risks or trustworthiness characteristics that will no
system holds itEvidence a system already holds
- The selected measurement approaches and metrics, traced to mapped risks · Policy repository / GRC workspace
periodic reviewEvidence produced at each review
- An explicit record of risks and characteristics that will not or cannot be measured, with reasons · Document repository
- Evidence the selection was implemented rather than only planned · Document repository
governing documentDocuments that govern the control
- The prioritisation showing the most significant risks addressed first · Document repository
First move
Common gaps auditors find
- Metrics chosen from what the tooling already emits rather than from the mapped risks
- Unmeasured characteristics simply absent, so their absence reads as a pass
- Selection documented with no evidence of implementation
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetMP-5.2 Practices and personnel for supporting regular engagement with relevant AI actors and integrating feedback about positive, negative, and unanticipated impacts are in place and documented · MS-1.2 Appropriateness of AI metrics and effectiveness of existing controls is regularly assessed and updated, including reports of errors and impacts on affected communities