workflow
AI Governance & Risk/Impact Assessment
Assess a single AI system end to end under ISO/IEC 42001 (AIMS) and the NIST AI RMF: govern and register the system, map context and risks, measure risks and impacts, manage treatment, produce transparency artifacts, and authorize deployment with monitoring. The instance attaches to an Audit item created for this assessment cycle (audit_type compliance, or advisory for a pre-deployment review); because Studio has no native AI System type, the system under assessment is named in that Audit's scope and its lifecycle/EU-AI-Act detail lives in the scoping memo and step documents. In scope: one named AI system or use case and its lifecycle risk posture. Out of scope: enterprise-wide AI policy authoring and detailed EU AI Act legal obligation mapping, which are consumed as an input handoff package from the EU AI Act Obligation Impact Analysis workflow. The named deliverable is the approved AI assessment package (executive summary plus recommended governance decision), backed by the AI risk register (Risk items, category ai_governance), the model/system card and AI impact-assessment record, and a deployment authorization with live drift/fairness monitoring; approved outputs hand off to Quarterly Board & Audit-Committee GRC Reporting.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- grc
- department
- ai-governance
- lineOfDefense
- monitor
Details
- teams
- ai-governance
- domains
- grc
- standards
- nist-ai-tevv-athlon
- iso-42001
- nist-800-53
- aiuc-1
- sourceTemplateId
- workflow-library:grc-ai-governance-aims-assessment
- releaseId
- sha256:f13547ad64a1e7ed0822c6ec471aea724ebac5e7e5bcc6629ee6c8c40aca16dc
- canonicalUrl
- https://workflow-library.com/all/?w=grc-ai-governance-aims-assessment
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- monitor
- controls
- UC-AI-01
- UC-AI-03
- UC-AI-04
- UC-AI-07
- UC-AI-08
- UC-AI-10
- UC-AI-02
- UC-AI-05
- UC-AI-06
- UC-AI-09
- UC-AI-11
- UC-AI-12
- UC-AI-14
- UC-AI-15
- UC-AI-16
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:f13547ad64a1e7ed0822c6ec471aea724ebac5e7e5bcc6629ee6c8c40aca16dc
Connections
- AI Governance & Risk/Impact Assessment oversees UC-AI-16 — Ensure human oversight of AI decisions
- AI Governance & Risk/Impact Assessment oversees UC-AI-15 — Fulfill general-purpose AI model provider obligations
- AI Governance & Risk/Impact Assessment oversees UC-AI-11 — Operate AI concern, incident, and external reporting channels
- AI Governance & Risk/Impact Assessment oversees UC-AI-08 — Log and monitor AI system behavior in operation
- AI Governance & Risk/Impact Assessment oversees UC-AI-10 — Meet transparency obligations for AI systems
- AI Governance & Risk/Impact Assessment oversees UC-AI-14 — Manage responsible AI with suppliers and customers
- AI Governance & Risk/Impact Assessment oversees UC-AI-02 — Define AI roles, responsibilities, and competencies
- AI Governance & Risk/Impact Assessment oversees UC-AI-03 — Document AI system resources and dependencies
- AI Governance & Risk/Impact Assessment oversees UC-AI-12 — Enforce responsible and lawful use of AI systems
- AI Governance & Risk/Impact Assessment oversees UC-AI-09 — Govern AI data quality, provenance, and preparation
- AI Governance & Risk/Impact Assessment oversees UC-AI-07 — Verify, validate, and control AI deployment and changes
- AI Governance & Risk/Impact Assessment oversees UC-AI-01 — Maintain and periodically review the AI policy
- AI Governance & Risk/Impact Assessment oversees UC-AI-05 — Set responsible AI development objectives and requirements
- AI Governance & Risk/Impact Assessment oversees UC-AI-04 — Assess impacts and classify AI systems before deployment
- AI Governance & Risk/Impact Assessment oversees UC-AI-06 — Maintain AI system technical documentation