MS-1.2 Appropriateness of AI metrics and effectiveness of existing controls is regularly assessed and updated, including reports of errors and impacts on affected communities
Appropriateness of AI metrics and effectiveness of existing controls is regularly assessed and updated including reports of errors and impacts on affected communities. The metrics themselves are re-examined on a cycle fo
system holds itEvidence a system already holds
- Changes made to metrics or controls as a result · Policy repository / GRC workspace
periodic reviewEvidence produced at each review
- Records of periodic assessment of metric appropriateness and control effectiveness · Policy repository / GRC workspace
- Error reports and community impact reports considered in that assessment · Document repository
- The trigger conditions, such as drift or changed operating setting, that force a re-assessment · Document repository
governing documentDocuments that govern the control
none for this control
First move
Common gaps auditors find
- Metrics fixed at launch and carried unchanged through model updates
- Assessment considers internal error rates only, not reported impacts
- Re-assessment scheduled but no completed record for the current period
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetMS-1.1 Approaches and metrics for measurement of AI risks enumerated during the MAP function are selected for implementation starting with the most significant AI risks, and the risks or trustworthiness characteristics that will not or cannot be measured are properly documented · MS-1.3 Internal experts who did not serve as front-line developers for the system and independent assessors are involved in regular assessments and updates, and domain experts, users, AI actors external to the team, and affected communities are consulted in support of assessments as necessary per organizational risk tolerance