Manage controls using AI Risk and Compliance
You can add, remove, and delete controls for an AI asset using the AI Risk and Compliance.
Control management in AI Risk and Compliance enables organizations to define, maintain, and validate the controls applied to AI assets throughout their life cycle.
The following topics describe the control management tasks you can perform:
- Add controls from control objective
- Remove controls from an AI asset
- Delete controls from an AI asset
Add controls from control objective
Add controls manually from published control objectives to an AI asset in AI Risk and Compliance. Use this task when controls were not automatically generated by a post-assessment action, or when you need to apply additional controls beyond those mapped through the impact assessment.- Remove controls from an AI asset
Remove associated controls from an AI asset to keep the inventory accurate and up to date. This step is essential to retire outdated or irrelevant controls without deleting their records. - Delete controls from an AI asset
Delete controls from an AI asset to remove them permanently from the control table. This task confirms outdated or unnecessary controls are deleted. - Create control attestations for an AI asset
Create control attestations for AI assets to document the existence, implementation, and effectiveness of controls that govern behavior, data usage, performance, and risk posture. Attestations serve as formal evidence that the AI asset meets regulatory, ethical, security, and operational standards.
Parent Topic:Using AI Risk and Compliance