GRN 1.2 - Trustworthy AI Characteristics

NIST AI RMF (in the playbook companion) states:

GOVERN 1.2

The characteristics of trustworthy AI are integrated into organizational policies, processes, and procedures.

About

Policies, processes, and procedures are a central component of effective AI risk management and fundamental to individual and organizational accountability.

Organizational policies and procedures will vary based on available resources and risk profiles, but can help systematize AI actor roles and responsibilities throughout the AI model lifecycle. Without such policies, risk management can be subjective across the organization, and exacerbate rather than minimize risks over time.

Individuals and organizations cannot be held accountable to unwritten, unknown or unrecognized policies. Lack of clear information about responsibilities and chains of command will limit the effectiveness of risk management.

Actions

Establish and maintain formal AI risk management policies that address AI system trustworthy characteristics throughout the system’s lifecycle. Organizational policies should:

  • Define key terms and concepts related to AI systems and the scope of their intended use.

  • Address the use of sensitive or otherwise risky data.

  • Detail standards for experimental design, data quality, and model training.

  • Outline and document risk mapping and measurement processes and standards.

  • Detail model testing and validation processes.

  • Detail review processes for legal and risk functions.

  • Establish the frequency of and detail for monitoring, auditing and review processes.

  • Outline change management requirements.

  • Outline processes for internal and external stakeholder engagement.

  • Establish whistleblower policies to facilitate reporting of serious AI system concerns.

  • Detail and test incident response plans.

  • Verify that formal AI risk management policies align to existing legal standards, and industry best practices and norms.

  • Establish AI risk management policies that broadly align to AI system trustworthy characteristics.

  • Verify that formal AI risk management policies include currently deployed and third-party AI systems.

Transparency and Documentation

Organizations can document the following:

  • To what extent do these policies foster public trust and confidence in the use of the AI system?

  • What policies has the entity developed to ensure the use of the AI system is consistent with its stated values and principles?

  • To what extent are the model outputs consistent with the entity’s values and principles to foster public trust and equity?

Last updated