AIG-005 AI Risk Management Process
Description
A documented process for identifying, analysing, evaluating and treating AI risks is established and applied throughout the lifecycle of each AI system. The process identifies risks to health, safety, fundamental rights and business operations. Risk assessments are performed before deployment and at defined intervals, at minimum annually and after any substantial modification. Residual risks are documented and accepted by an accountable owner. Measurable AI risk objectives derived from the risk appetite in AIG-001 are recorded, tracked and reviewed at defined intervals and inform the resources allocated to AI risk management.
Rationale
A lifecycle risk management process is the engine of AI governance; policy and roles are insufficient without an operational assessment mechanism. Systemic risk from a designated general-purpose model, assessed at Union level with capability-tier acceptance criteria, is AIG-050; this control continues to govern the systems built on the model.
Applicability (9 profiles)
Art.9(1) makes the process a risk management system established, implemented, documented and maintained across the entire lifecycle, which is a standing system rather than an assessment repeated on a cycle. It is the artefact Art.11 and Annex IV expose to an authority. Art.9(2) fixes what it identifies, known and reasonably foreseeable risks to health, safety and fundamental rights under intended use and under reasonably foreseeable misuse, with post-market monitoring data as a named input. Art.9(3) bounds it to risks that design, development or adequate technical information can reasonably mitigate, so a risk parked as the deployer's problem needs that information supplied under Art.13. Art.9(5) requires each hazard's residual risk and the overall residual risk to be judged acceptable, with design-level elimination taken before mitigation and before informational controls, which is stronger than an accountable owner's acceptance. The Art.9(9) vulnerable-groups consideration sits on AIG-006.
Framework Mappings (43)
| GRC-02 | Risk Management Program | full |
| GRC-10 | AI Impact Assessment | informative |
| EU-AI-Art.55.2 | Systemic Risk Obligations — Systemic Risk Assessment and Mitigation | informative |
| EU-AI-Art.9.1 | AI Risk Management System — Establishment and Maintenance | full |
| EU-AI-Art.9.2 | AI Risk Management System — Risk Identification and Analysis | full |
| EU-AI-Art.9.3 | AI Risk Management System — Scope of Risks to Mitigate | informative |
| EU-AI-Art.9.4 | AI Risk Management System — Residual Risk Acceptability | full |
| COP-S-1 | Safety and Security Framework | informative |
| COP-S-1.2 | Implementing the Framework | informative |
| COP-S-1.3 | Updating the Framework | informative |
| COP-S-2 | Systemic risk identification | informative |
| COP-S-2.1 | Systemic risk identification process | informative |
| COP-S-3 | Systemic risk analysis | informative |
| COP-S-4 | Systemic risk acceptance determination | informative |
| COP-S-8.2 | Allocation of appropriate resources | informative |
| A.6.1.2 | Objectives for responsible development of AI system | partial |
| A.6.1.3 | Processes for responsible AI system design and development | full |
| GV-1.3-001 | Risk Management Activity Level Determination | GV-1.3-001 | full |
| GV-1.3-005 | Risk Management Activity Level Determination | GV-1.3-005 | partial |
| GV-1.3-006 | Risk Management Activity Level Determination | GV-1.3-006 | informative |
| GV-4.1-001 | Safety-First Organisational Culture | GV-4.1-001 | partial |
| GV-4.2-002 | Organisational AI Risk Communication | GV-4.2-002 | partial |
| MG-1.3-001 | High-Priority Risk Response Planning | MG-1.3-001 | partial |
| MG-3.1-003 | Third-Party AI Risk Monitoring and Controls | MG-3.1-003 | informative |
| MG-4.1-001 | Post-Deployment AI System Monitoring | MG-4.1-001 | informative |
| MP-1.1-003 | AI System Purpose and Deployment Context | MP-1.1-003 | partial |
| MP-4.1-008 | AI Technology and Legal Risk Mapping | MP-4.1-008 | full |
| MS-1.1-005 | AI Risk Measurement Approach Selection | MS-1.1-005 | partial |
| MS-1.1-008 | AI Risk Measurement Approach Selection | MS-1.1-008 | informative |
| MS-1.1-009 | AI Risk Measurement Approach Selection | MS-1.1-009 | partial |
| MS-2.5-006 | AI System Validity and Reliability | MS-2.5-006 | informative |
| MS-2.6-003 | AI System Safety Risk Evaluation | MS-2.6-003 | partial |
| MS-3.2-001 | Risk Tracking for Measurement Gaps | MS-3.2-001 | partial |
| GOVERN 1.3 | Risk Management Activity Level Determination | full |
| GOVERN 1.5 | Risk Management Monitoring and Review | full |
| GOVERN 4.2 | Organisational AI Risk Communication | partial |
| MANAGE 1.1 | AI System Purpose and Deployment Determination | full |
| MANAGE 1.2 | AI Risk Treatment Prioritization | full |
| MANAGE 1.3 | High-Priority Risk Response Planning | full |
| MANAGE 1.4 | Residual Risk Documentation | full |
| MANAGE 2.1 | AI Risk Resource Planning and Non-AI Alternatives | partial |
| MEASURE 1.1 | AI Risk Measurement Approach Selection | informative |
| MEASURE 3.2 | Risk Tracking for Measurement Gaps | partial |
Evidence (3)
AI governance objectives and associated metrics, demonstrating that risk tolerance has been translated into measurable, time-bound objectives that inform resource allocation.
Example: AI Governance OKRs 2025–2026 (Notion), including measurable objectives such as 'bias testing coverage 100% of Tier 2+ systems by Q3 2025' and 'all AI systems mapped to risk tier by Q1 2026'
Test: Request AI governance objectives documentation. Verify: (1) objectives are derived from stated risk tolerance dimensions, (2) each objective has a measurable target and due date, (3) progress against objectives is tracked, (4) objectives were reviewed within the last 12 months.
Completed AI risk assessments for each production AI system, covering the risk identification, analysis, evaluation, and treatment steps, with residual risk sign-off by the named system owner.
Example: AI Risk Assessment · Customer Churn Model v3 (Confluence), completed 2025-08-12 prior to deployment, with treatment plan and residual risk accepted by Head of Data
Test: Request risk assessments for a sample of production AI systems (minimum 3 or all Tier 2+ systems). Verify each assessment: (1) was completed before deployment or within the last 12 months, (2) covers health, safety, fundamental rights, and business operations dimensions, (3) includes a documented treatment plan for identified risks, (4) has residual risk formally accepted by the named system owner, (5) was triggered again after any substantial modification.
Documented AI risk management process defining how risks are identified, analysed, evaluated, treated, and accepted throughout the AI system lifecycle, including the trigger criteria for reassessment.
Example: AI Risk Management Procedure v2.0 (Confluence), defining risk assessment methodology, lifecycle trigger points, risk register format, and residual risk acceptance thresholds
Test: Request the AI risk management process document. Verify: (1) all four ISO 31000 phases (identify, analyse, evaluate, treat) are described with method guidance, (2) lifecycle triggers for reassessment are defined (including 'substantial modification'), (3) the process specifies who conducts and who approves assessments, (4) retention period for completed assessments is stated.
Questions (3)
Does your organisation apply a documented risk management process to AI systems throughout their lifecycle?
The process should cover risk identification, analysis, evaluation, treatment, and residual risk acceptance. It should be triggered before deployment and after any substantial modification, not only at initial development.
At which points in the AI system lifecycle is a formal risk assessment conducted?
Assessments conducted only at initial deployment miss risk accumulation from model drift, changed use contexts, and regulatory evolution. A mature process triggers reassessment at all five points.
How are your AI risk tolerance statements expressed?
Enterprise buyers should expect at minimum quantified thresholds for the risk dimensions relevant to your AI use cases. Qualitative-only statements cannot be verified or used to drive consistent risk treatment decisions.