Roles installed with AI Risk and Compliance
The AI Risk and Compliance installs the essential roles to perform respective day-to-day operational tasks for managing AI assets across the enterprise.
| Role title \[name\] | Description | Contains roles |
|---|---|---|
| AI Risk and Compliance Admin \[sn\_grc\_ai\_gov.ai\_risk\_and\_compliance\_admin\] | The AI Risk and Compliance Admin can perform the following tasks:- Set up risk and impact assessment frameworks. Configure risk assessment methodologies, risk contribution factors, and impact assessment templates. - Define automation rules for impact assessments to determine applicable risks and controls based on the assessment responses. - Set up and profile AI case types. - Delete AI systems. - Enable or disable Entity-Based Access for record types associated with entity properties, and configure the Entity-Based Access settings as needed. Note: GRC: Entity Based Access application must be installed to use this feature. |
Note: GRC: Entity Based Access application must be installed for this role to be available. |
| AI Risk and Compliance Manager \[sn\_grc\_ai\_gov.ai\_risk\_and\_compliance\_manager\] | The AI Risk and Compliance Manager can access all AI systems on the system and perform the following tasks:- Initiate impact assessments. - Manage the life cycle of an AI system. - Initiate risk assessments. - Initiate control attestations. - Write and update access to the bulk access update configuration. Note: GRC: Entity Based Access application must be installed to use this feature. |
Note: GRC: Entity Based Access application must be installed for this role to be available. |
| AI Risk and Compliance Analyst \[sn\_grc\_ai\_gov.ai\_risk\_and\_compliance\_analyst\] | The AI Risk and Compliance Analyst can access all AI systems assigned to them in the system and perform the following tasks only on the assigned records:- Initiate impact assessments. - Manage the life cycle of an AI system. - Initiate risk assessments. - Initiate control attestations. | - sn\_ai\_case\_mgmt.ai\_case\_analyst - sn\_smart\_asmt.assessment\_reader - sn\_smart\_asmt.template\_reader - sn\_grc\_ai\_gov.ai\_risk\_and\_compliance\_business\_user - sn\_grc\_ai\_gov.ai\_risk\_and\_compliance\_reader - sn\_grc\_workspace.user - sn\_grc\_workspace.state\_model\_reader - sn\_risk\_advanced.ara\_creator - sn\_risk\_advanced.ara\_assessor - sn\_risk\_advanced.ara\_approver - sn\_risk\_advanced.risk\_asmt\_project\_user |
| AI Risk and Compliance Business User \[sn\_grc\_ai\_gov.ai\_risk\_and\_compliance\_business\_user\] | The AI Risk and Compliance User can perform the following tasks:- Create AI case on the Employee Center. - Work on the assigned tasks. - Perform control attestations. | - sn_grc_workspace.assessment_template_configuration_reader - sn_smart_asmt.actor - sn_grc_workspace.user - sn_smart_asmt.assessment_reader - sn_risk_advanced.risk_asmt_project_reader Note: For more information on AI Control Tower roles, see AI Control Tower roles. |
| AI Risk and Compliance Reader \[sn\_grc\_ai\_gov.ai\_risk\_and\_compliance\_reader\] | The AI Risk and Compliance Reader can have read access to the AI systems and AI impact assessments. | - sn\_grc\_workspace.user - sn\_grc\_workspace.state\_model\_reader |
| AI System Reader \[sn\_grc\_ai\_gov.ai\_risk\_and\_compliance\_ai\_system\_reader\] | The AI System Reader can have read access to the AI systems on AI Control Tower workspace and AI Risk and Compliance workspace. | NA |
| AI Case Business User \[sn\_ai\_case\_mgmt.ai\_case\_business\_user\] | The AI Case Business User can create AI case and AI inquiry on the Employee Center. | sn\_grc\_case\_mgmt.grc\_case\_business\_user |
| AI Case Analyst \[sn\_ai\_case\_mgmt.ai\_case\_analyst\] | The AI Case Analyst can review the AI cases and AI inquiries assigned to them in the system and perform the following tasks only on the assigned records:- Identify and manage impacted and related areas such as policies, regulations, and enterprise-wide compliance risks. - Identify and manage issues related to impacted areas to eliminate the root causes. | - sn\_grc\_case\_mgmt.grc\_case\_analyst - sn\_ai\_case\_mgmt.ai\_case\_business\_user |
| AI Case Manager \[sn\_ai\_case\_mgmt.ai\_case\_manager\] | The AI Case Manager can review all the AI cases, AI inquiries, and its associated information. | - sn\_ai\_case\_mgmt.ai\_case\_analyst - sn\_grc\_case\_mgmt.grc\_case\_manager |
| AI Case Admin \[sn\_ai\_case\_mgmt.ai\_case\_admin\] | The AI Case Admin can manage type profiles to segregate AI cases. They can set up assignment rules and delete AI cases. | - sn\_grc\_case\_mgmt.grc\_case\_admin - sn\_ai\_case\_mgmt.ai\_case\_manager |
Parent Topic:AI Risk and Compliance reference