What is AI risk management?

By Identra · Updated

AI risk management is the ongoing process of identifying, assessing and addressing potential harm from developing or using AI. It connects each use case to an accountable owner, tested controls and a documented decision about the risk that remains.

How does AI risk management work?

Pick a use. Work out what could go wrong and whether the benefit is worth it. Put controls in, test them, and look again when something changes. An approval should name the use, the data, the users and the actions. A line in a register saying Microsoft 365 Copilot is approved approves far too much.

An AI risk assessment is a snapshot of one use at one point in time. Risk management carries that through rollout, monitoring, incidents and eventually retirement. A vendor's SOC 2 report tells you about the vendor. It says nothing about your data, your permissions or what your team does with the output.

AI governance decides who can approve uses and accept risk. Risk management hands those people evidence. Security, privacy and legal advise, and the business owner stays accountable for the outcome.

Which AI risks should you assess?

Attacks and plain failure, both. An assistant can leak confidential records because someone manipulated it. It can also leak them because it was given a whole SharePoint site when it needed one folder. And a confident wrong answer can do damage with no attacker anywhere.

Weigh who gets hurt, how badly and whether it can be undone. Drafting a meeting agenda and deciding who qualifies for a service are different problems. Write down what you don't know. A medium rating with no reasoning behind it hides that.

Include whatever shadow AI discovery turns up. Browser chat apps, desktop apps, Cursor and Claude Code on developer laptops, agents wired into business systems.

  • Security: data disclosure, stolen credentials, unauthorized actions, manipulation through documents, emails and web pages.
  • Reliability: made-up answers, missed edge cases, behavior that changes when the inputs do.
  • Privacy and fairness: personal data used where it shouldn't be, biased decisions about people, consequential calls nobody really reviews.
  • Dependency: outages, a vendor changing terms or models, runaway API spend, no clean way to switch it off.

How do NIST AI RMF, ISO/IEC 42001 and the EU AI Act differ?

They do different jobs. NIST describes the AI RMF as voluntary guidance and organizes it around four functions: Govern, Map, Measure and Manage. ISO/IEC 42001 sets requirements for an AI management system that an organization can be certified against. The EU AI Act is law, and whether it applies depends on the system, the use and your role. The official overviews are from NIST, ISO and the European Commission.

One inventory and one evidence process can feed all three. Assess each requirement on its own, though. A 42001 certificate doesn't establish compliance with the AI Act, and neither proves that a given output was safe.

  • NIST AI RMF

    What it is
    Voluntary risk management framework
    What you use it for
    Structuring how risks are found, measured and treated
  • ISO/IEC 42001

    What it is
    AI management system standard
    What you use it for
    Setting up and improving the processes around AI
  • EU AI Act

    What it is
    Law
    What you use it for
    Working out and meeting legal obligations that apply to you

What does it look like on a real proposal?

Say the support team wants an assistant that reads Salesforce cases and drafts replies. The request also gives it permission to issue refunds. That bundles three separate risks: customer records leaking, bad advice going out and money moving without proper authority.

The owner approves a smaller pilot. The assistant sees only cases assigned to whoever is using it. No refunds. Staff check each draft against the case before sending. Testing covers poisoned attachments, requests for another customer's data and questions it can't answer well.

Failed tests and fixes get written down. If someone wants refunds added later, that's a new review. Same vendor, same model, very different risk.

How do you turn risks into controls?

Each risk becomes a control with an owner and a result you can test. Use AI responsibly is a slogan. It doesn't tell anyone which files they can upload or which actions need approval.

Apply least privilege to whatever identity and tools the AI uses. Treat instructions inside retrieved documents and emails as untrusted. Content filtering on its own shouldn't be the only thing between an agent and an unauthorized action.

  • Inventory each use with its owner, approved account, data sources, connected tools and where it runs.
  • Write the data rules and prohibited uses, then back them with access restrictions and upload controls.
  • Scope retrieval and tool permissions to the task. Require real human approval before consequential actions.
  • Test misuse and failure before launch. Check authorization separately from whatever the model says.
  • Record the remaining risk, who accepted it and what triggers another look.
  • Have a shutdown plan. Someone needs to know how to cut access quickly.

How do you know it's working?

Evidence should connect the approved use to what actually happens. An AI audit trail helps investigations. Logs won't tell you whether outputs were accurate or fair, so pair them with evaluation results and written reviews. Those records can hold prompts and customer data, which means they need access limits and a retention period of their own.

Reassess when data sources, permissions, models, vendors or users change, and after any serious failure. Make exceptions expire. Remove integrations and credentials nobody uses. An abandoned AI connector still holds its access.

How Identra thinks about it

Identra shows which AI apps, accounts and agents are in use across the browser, endpoints and connected identity, SaaS and cloud providers. Policy controls cover supported AI activity. Every AI agent run on an endpoint is recorded with its outcome, and response actions record their results, which gives a risk review something concrete to check against.

Go deeper: AI security, built on identity

Frequently asked questions

Who should own AI risk management?

A program owner runs the process with security, privacy, legal and the business. Each AI use also needs a business owner for its purpose and someone authorized to accept what risk remains.

Do we need AI risk management if we only buy AI tools?

Yes. You still decide what data a tool gets, what it can access and how people use its output. The vendor's assurances don't make those decisions for you.

How is AI risk management different from cybersecurity?

Cybersecurity covers compromise, data theft and unauthorized actions. AI risk management covers those plus unreliable output, bias, privacy impact and people leaning too hard on automated decisions.

Should every AI use go through the same review?

Same intake, different depth. Sensitive data, decisions about people and the ability to change business systems get a closer look.

Can human review make an AI system safe?

Only when reviewers have the expertise, the source material, the time and the authority to say no. A routine approve click adds very little.

Related terms

Keep exploring · AI standards and frameworks