Complete AI Training
Sign inGet my AI kit

Your job's AI kit

Get your AI kit

Tell us who you are and what you do. We show you your kit right away and email you the link: skills, prompts, AI agents, MCP servers and courses for your job.

500+ jobs ready, and we make a kit for any other job. No payment needed to look.

Share

AI news ·

New AI-specific frameworks emerge to address governance and security risks

New AI risk frameworks published in 2023 help firms manage system failures and meet regulatory demands. Leaders must match these standards to specific operational gaps.

Organizations racing to embed AI into business operations are discovering that traditional risk management frameworks weren't built for the behaviors, failure modes, and ethical complexities AI systems introduce. A new generation of AI-specific frameworks-from ISO, NIST, ENISA, and Google-now gives business leaders structured ways to identify where AI can go wrong, implement controls, and demonstrate responsible use to regulators and investors.

These frameworks are complementary, not competing, because they have different intents and priorities, said Nicole Carignan, CISO at Darktrace. "There is overlap across these frameworks, but that overlap is helpful," she said. "It reinforces the core practices organizations need to get right: governance, data integrity, security, accountability, oversight, testing, and continuous improvement."

Building a governance foundation with ISO/IEC 42001

ISO/IEC 42001:2023 is the first internationally recognized formal standard for AI management. Published in December 2023, it follows a structure similar to ISO 27001 and requires organizations to document how they design, monitor, validate, and control AI systems. The standard mandates AI impact assessments to evaluate legal, ethical, and societal effects, and covers governance structures, third-party oversight, data management, and lifecycle management.

Carignan said ISO 42001 provides the strongest foundation for building an AI risk management program. "It forces organizations to think holistically about ownership, governance, oversight, data integrity, security risk mitigation, accountability, and continuous improvement," she said. The standard is voluntary but certifiable, and a growing number of companies are using it to align with regulations such as the EU AI Act. One downside, Carignan noted, is that implementation is resource-intensive and the full standard is not publicly available.

Operational risk management with NIST AI RMF

The NIST AI Risk Management Framework, released in January 2023, is a voluntary guide that helps organizations identify and manage AI risks across the entire system lifecycle. It describes characteristics of trustworthy AI-validity, safety, security, transparency, and fairness-and organizes its guidance around four functions:

  • Govern - building internal culture, policies, and accountability
  • Map - understanding the context and potential risks of specific AI systems
  • Measure - evaluating and tracking risks with qualitative and quantitative methods
  • Manage - prioritizing risks and deciding on mitigation, transfer, or acceptance

Ram Varadarajan, CEO at Acalvio, recommends NIST AI RMF for organizations starting from zero. "It's built around maturity rather than pass/fail audits," he said. "It forces the three conversations that have to happen first: who owns AI risk, what AI is actually running, and who gets hurt if something goes wrong." Forrester researchers, while calling the framework a step forward, cautioned that it remains "descriptive and not prescriptive" and lacks an explicit role for data governance.

Management teams navigating these choices can find deeper dives into AI governance and strategy at AI for Management.

Cybersecurity and sector-specific frameworks

ENISA's Framework for AI Cybersecurity Practices (FAICP), published in June 2023, gives EU organizations structured cybersecurity guidance aligned with the EU AI Act. It layers foundational IT security practices, AI-specific risks such as adversarial attacks and model tampering, and sector-specific advice for energy, healthcare, and telecommunications. Varadarajan predicted that Europe's AI Act will likely become the global reference point, with NIST AI RMF providing the operational playbook to meet it.

ISO/IEC 23894:2023 offers specific guidance on managing AI risks by adapting the ISO 31000 standard to address algorithmic bias, model drift, and transparency gaps. Unlike ISO 42001, it is a guidance-only standard, not a certifiable management system. Google's Secure AI Framework (SAIF) focuses on weaving security and privacy into every stage of AI development, tackling threats like data poisoning and prompt injection. Technology consultancy Thoughtworks assessed SAIF as a concise, actionable playbook especially valuable for teams building agentic systems.

David Brumley, chief AI and science officer at Bugcrowd, said the question for organizations is not "which AI risk framework is best?" but "which framework helps [the] organization safely build, deploy, and learn from AI in the real world?" He warned that focusing only on preventing bad outcomes could create a shadow AI problem. "AI adoption is not waiting for perfect governance," Brumley said.

Why this matters for management

Selecting an AI risk framework is not a one-size-fits-all exercise. Management teams must match the framework to their most urgent gaps-whether that's a certifiable management system like ISO 42001, a flexible maturity-based approach like NIST AI RMF, or cybersecurity-specific guidance from ENISA or Google SAIF. The frameworks work together, and starting with one doesn't preclude adding others later. The real risk for leaders is delaying action while AI adoption accelerates inside the business without guardrails.

Share