▲ 8 r/AI_Governance
What should an enterprise AI risk management program include?
Building an AI risk program from scratch and trying not to reinvent things that already exist elsewhere in the org (overlap with data governance, third-party risk, etc.).
At minimum I'm thinking: an inventory of AI tools in use (sanctioned and shadow), risk tiering based on data sensitivity, usage policies with actual enforcement mechanisms, and incident response procedures specific to AI-related data exposure. What am I missing? How have others scoped this, standalone program or folded into existing GRC structures
u/Plus-Maintenance-434 — 3 days ago