0% found this document useful (0 votes)
17 views13 pages

AI Governance and Risk Framework

The document outlines a framework for building AI systems with a focus on governance, risk assessment, and compliance. It highlights the importance of identifying genuine AI applications, understanding regulatory impacts, and ensuring data privacy and security. Additionally, it emphasizes the need for a unified internal AI policy and adherence to international standards to protect global business interests.

Uploaded by

VishankhDutta
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
17 views13 pages

AI Governance and Risk Framework

The document outlines a framework for building AI systems with a focus on governance, risk assessment, and compliance. It highlights the importance of identifying genuine AI applications, understanding regulatory impacts, and ensuring data privacy and security. Additionally, it emphasizes the need for a unified internal AI policy and adherence to international standards to protect global business interests.

Uploaded by

VishankhDutta
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Building AI System

Repository &
Governance Framework
Responsible AI Summit 2025
Table of Contents

01 AI-Enabled Applications
04 Inventory Ready

02 AI Scan Report 05 AI Risk Assessment

Finding AI Applications in
03 AI facts & Stats
06 Your Asset Inventory

Global Business –
07 How to Protect It?
What % of Large Enterprises

Applications are 42% report active use of AI in some


business processes.

AI-enabled or
marketed as AI? AI Washing
Many vendors label products with “AI”
without substantive use.

Reality Check

Actual AI/ML usage across all apps is often


far lower than marketing claims. Audit Approach
Measure by inventory- search for true
AI libraries or documented models, not
just keyword.
How many apps in your IT
landscape do you think
have genuine AI
Components?
AI Scan Report
Sector Website Detected AI Technologies Type of AI Notes

Personalized product recommendations; customer


Amazon India AWS Personalize, Amazon Lex Recommendation engine, Chatbot
support chatbot.

E-commerce

AJIO Recommendation ML Recommendation engine Personalized style recommendations.

Dynamic pricing, dispatch Forecasts demand; implements surge pricing and


Ola Demand prediction ML
optimization dispatch.
Cab Service

Uber India ETA prediction, surge pricing ML Route & pricing optimization Machine learned ETA and dynamic pricing models.

Netflix India Netflix recommendation engine Recommendation engine Proprietary ML models for personalized suggestions.

Entertainment
Amazon Prime
AWS Personalize Recommendation engine Uses AWS ML for content suggestions.
Video

Image recognition, Menu item recognition; personalized restaurant


Zomato Computer vision, recommendation
recommendation ML suggestions.
Food

Swiggy Logistics ML, ETA prediction Delivery optimization Route planning and delivery time estimates.
Some eye-opening AI
While AI offers transformative opportunities, it
simultaneously raises profound regulatory, ethical, and

Facts & Stats security challenges.

01 Regulatory
Impact 02 Privacy
Violation 03 Security
Concern
Italy fined OpenAI €15 million Swedish school fined €20k 72% of CISOs fear generative
for GDPR breaches. for using facial-recognition. AI tools could cause security
breaches.

04 Data
Ethics 05 Economic
Opportunity 06 High
Fines
75% of tech professionals AI-related tech is booming: Under the EU AI Act 2024,
rank data privacy as a top WEF projects 170 million new violations can incur up to 7%
ethical concern. jobs by 2030. of global turnover in penalties.
AI Updates around the World
AI is reshaping global policy and job markets, with new regulations, public investments, and infrastructure
initiatives driving both innovation and accountability.

AI Job Global AI IndiaAI Mission &


Market Regulations Portals

The WEF Future of Jobs Report The EU AI Act enforces strict Launched in 2024 with a ₹10,371
2025 projects 170 million new rules on high-risk AI systems, Cr budget, the IndiaAI Mission,
jobs by 2030, with AI/ML while U.S. Executive Orders on AI along with the AIKosha data
specialists and data scientists focus on safety and portal and IndiaAI Compute
among the fastest-growing governance development. Portals.
roles.
Inventory Ready – As AI functionalities expand, it's crucial to catalog their
capabilities, map their context, and document high-risk uses

Identify Functionalities
to ensure effective governance and minimize potential risks.

01 Catalog AI
Functions 02 Context
Mapping
03 Stakeholder
Impact
For each identified AI system, Determine data List who uses it and who is
note what it does. inputs/outputs and affected impacted.
processes.

04 High-risk
Use Cases 05 Documentation

Cross-reference functionalities Document each AI app’s


with known risk categories. purpose, algorithms, and data
classification.
AI Risk Assessment - Scope & Questions
S. No. Key Focus Area Scope and Assessment Questions

High-risk AI (per step 5) needs thorough vetting; low-impact AI may need lighter review. Follow
01 Scale evaluation to risk
frameworks (e.g. NIST AI RMF, ISO 23894).

02 Key risk dimensions Assess Accuracy, Fairness (Bias), Privacy, Security, Transparency, and Safety.

Is data legally obtained and of good quality? Are people’s privacy rights protected (consent,
03 Data & privacy
anonymization)?

04 Bias & ethics Are protected groups over/under-represented? What steps are taken to detect and mitigate bias?

05 Transparency Can outputs be explained? Are end-users informed they’re interacting with AI?

06 Security & robustness Is the model protected from adversarial attacks or theft? Is there a plan for failure or rollback?

07 Accountability Who is responsible if the AI causes harm? Are governance roles (owner, reviewer) clear?

08 Regulatory requirements For high-risk cases, check compliance checklists (e.g. EU AI Act’s seven high-level requirements
Finding AI Applications in Your
Asset Inventory
Method Pros Cons Best Use

Time-consuming -
Uncovers AI hidden inside
Developers might You build your own apps or
Developer Surveys custom apps - Developers
underreport or miss have data science teams.
can flag future AI plans.
embedded libraries.

Very thorough for internal Resource-intensive - Won’t You develop a lot in-house
Code Inspection code - Detects AI even if find AI inside black-box and can afford code
undocumented. SaaS. scanning.

Needs mature network


Can detect real usage of AI
monitoring tools - You want real-time tracking
Log & Network Monitoring APIs - Catches systems not
Privacy/legal concerns if or spot unknown AI use.
officially documented as "AI".
mishandled.
Global Business – How to Protect It?

Multi-Jurisdictional Policy Harmonization


Compliance Establish a unified internal AI policy on ethics,
Ensure compliance with regional laws and stay privacy, and security, to be overseen by an AI
updated on emerging AI frameworks. governance council.

Adopt Highest Standards Monitor Evolving Laws


Use GDPR/AI Act principles globally as a Stay updated on AI safety acts, emerging
baseline. guidelines and national initiatives.

Intellectual Property & Export


Data Governance
Use Standard Contractual Clauses or Binding
Controls
Corporate Rules for cross-border data transfers. Protect your AI models and data under
Implement data localization. international IP laws. Be aware of export control
rules on advanced AI chips or software.
Thank You!
Global Business – How to Protect It

Multi-Jurisdictional Policy Harmonization


Compliance Establish a unified internal AI policy on ethics,
Ensure compliance with regional laws (GDPR, privacy, and security, with local adaptability,
NIST, DPDP, PIPL) and stay updated on emerging and oversee it through a global AI governance
AI frameworks such as EU AI Act. council.

Adopt Highest Standards Monitor Evolving Laws


Use GDPR/AI Act principles globally as a Stay updated on AI safety acts, emerging
baseline. E.g., if it’s compliant with EU, it often guidelines (OECD AI principles, UNESCO), and
exceeds requirements elsewhere. national initiatives.

Intellectual Property & Export


Data Governance
Use Standard Contractual Clauses or Binding
Controls
Corporate Rules for cross-border data transfers. Protect your AI models and data under
Implement data localization where required by international IP laws. Be aware of export control
local regulations. rules on advanced AI chips or software.

You might also like