Governance

Risk management: what AI regulations require

Risk tolerance, register, treatment and residual risk.

28 requirements · 12 regulations · 14 checks

Requirements by regulation

USNIST AI RMF11

BRPL 23383

BR-01
BR-16
Value-chain cooperation Arts. 18 §3, 32

Checks in this theme

Most shared first

CodeCheckUsed by
VER-003-01Documented and up-to-date risk register
CHK-POL-RISKAn AI risk-management policy and process are established through transparent, documented controls
VER-032-G-02Systemic risks assessed and mitigation measures documented
VER-003-02Residual risks communicated to deployers
CHK-RISK-RESPONSERisk treatment is prioritized and high-priority responses are planned and documented
VER-003-03Residual risks read and understood by the deployer
VER-003-04Complementary mitigation measures in place
CHK-BR-PRELIMPreliminary assessment carried out and kept on record
CHK-RISK-TOLERANCERisk tolerances are defined and AI systems are assigned to risk levels
CHK-MEASURE-PLANMeasurement approaches and metrics are selected and connected to context; unmeasured risks documented
CHK-ALTRequired resources and viable non-AI alternatives are considered
NEW-ISO42001-02Annex A Statement of Applicability kept up to date
NEW-US-CA-SB53-01Frontier AI framework published and reviewed yearly
NEW-CN-02CAC security assessment completed

Related themes

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo