3. Technical Controls

Strengthen risk management processes (with models, data, technology) to identify, monitor and mitigate risks in alignment with regulations and organisational risk appetite

3.1 Data management

Ensure the use of quality, trustworthy data that underpins decision-making​ (e.g., minimise malicious use and security threats through consideration of sensitive variables within the data such as race or ethnicity)

foundational

evolving

performing

advanced

none

    3.2 Model risk management

    Establish model risk management practices to address risk issues (e.g., for inaccurate output, model drift, algorithmic bias)​

    foundational

    evolving

    performing

    advanced

    none

      3.3 Control environment (incl. technical guardrails)

      Develop a control environment with technical guardrails and controls to ensure compliance with applicable regulations (e.g., EU AI Act)

      foundational

      evolving

      performing

      advanced

      none

        3.4 Monitoring and incident response

        Monitoring of KRIs (in real-time, as required) for oversight and improvement of AI systems once deployed, along with incident response plans to manage and respond to failures in AI systems

        foundational

        evolving

        performing

        advanced

        none
          Please complete this dimension to continue