Risk Control

A risk control is a measure intended to reduce a risk's likelihood or consequences. It can be technical, procedural, or organizational. A control needs a particular failure path to address and evidence that it operates as intended.

Connect the measure to the failure

In a refund assistant, removing obsolete policy documents addresses outdated retrieval. Restricting payment permissions limits what the assistant can do. A monitoring alert may detect bad advice, but cannot undo advice already received by a customer.

These controls have different effects. Merely counting them does not show how much risk remains.

Verify operation under realistic conditions

Test an obsolete document, an unauthorized payment request, or a missed alert using safe examples. Define who maintains the control and what happens when it fails. A proposed control has not yet reduced operational risk, and a passing test supports only the behavior and conditions actually checked.

Reference: NIST AI RMF Core.


Discover more from Insightful Data Lab

Subscribe to get the latest posts sent to your email.

Similar Posts

Questions, corrections, or additional insights?

This site uses Akismet to reduce spam. Learn how your comment data is processed.