Section 10 of 15
Manage
National Institute of Standards and Technology · about 3 minutes
5.4 Manage
¶The MANAGE function entails allocating risk resources to mapped and measured risks on a regular basis and as defined by the GOVERN function. Risk treatment comprises plans to respond to, recover from, and communicate about incidents or events.
¶Contextual information gleaned from expert consultation and input from relevant AI actors – established in GOVERN and carried out in MAP – is utilized in this function to decrease the likelihood of system failures and negative impacts. Systematic documentation practices established in GOVERN and utilized in MAP and MEASURE bolster AI risk management efforts and increase transparency and accountability. Processes for assessing emergent risks are in place, along with mechanisms for continual improvement.
¶After completing the MANAGE function, plans for prioritizing risk and regular monitoring and improvement will be in place. Framework users will have enhanced capacity to manage the risks of deployed AI systems and to allocate risk management resources based on assessed and prioritized risks. It is incumbent on Framework users to continue to apply the MANAGE function to deployed AI systems as methods, contexts, risks, and needs or expectations from relevant AI actors evolve over time.
¶Practices related to managing AI risks are described in the NIST AI RMF Playbook. Table 4 lists the MANAGE function’s categories and subcategories.
¶Table 4: Categories and subcategories for the MANAGE function.
¶Categories Subcategories MANAGE 1: AI MANAGE 1.1: A determination is made as to whether the AI risks based on system achieves its intended purposes and stated objectives and assessments and whether its development or deployment should proceed.
¶other analytical 1.2: Treatment of documented AI risks is prioritized MANAGE output from the based on impact, likelihood, and available resources or methods.
¶MAP and MEASURE MANAGE 1.3: Responses to the AI risks deemed high priority, as functions are identified by the MAP function, are developed, planned, and docprioritized, umented. Risk response options can include mitigating, transferresponded to, and ring, avoiding, or accepting.
¶managed.
¶MANAGE 1.4: Negative residual risks (defined as the sum of all unmitigated risks) to both downstream acquirers of AI systems and end users are documented.
¶MANAGE 2: MANAGE 2.1: Resources required to manage AI risks are taken Strategies to into account – along with viable non-AI alternative systems, apmaximize AI proaches, or methods – to reduce the magnitude or likelihood of benefits and potential impacts.
¶minimize negative 2.2: Mechanisms are in place and applied to sustain MANAGE impacts are planned, the value of deployed AI systems.
¶prepared, MANAGE 2.3: Procedures are followed to respond to and recover implemented, from a previously unknown risk when it is identified.
¶documented, and informed by input MANAGE 2.4: Mechanisms are in place and applied, and responfrom relevant AI sibilities are assigned and understood, to supersede, disengage, or actors. deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use.
¶MANAGE 3: AI MANAGE 3.1: AI risks and benefits from third-party resources risks and benefits are regularly monitored, and risk controls are applied and from third-party documented.
¶entities are 3.2: Pre-trained models which are used for develop- MANAGE managed. ment are monitored as part of AI system regular monitoring and maintenance.
¶Continued on next page Table 4: Categories and subcategories for the MANAGE function. (Continued) Categories Subcategories MANAGE 4: Risk MANAGE 4.1: Post-deployment AI system monitoring plans treatments, are implemented, including mechanisms for capturing and evalincluding response uating input from users and other relevant AI actors, appeal and recovery, and and override, decommissioning, incident response, recovery, and communication change management.
¶plans for the 4.2: Measurable activities for continual improvements MANAGE identified and are integrated into AI system updates and include regular engagemeasured AI risks ment with interested parties, including relevant AI actors. are documented and MANAGE 4.3: Incidents and errors are communicated to relevant monitored regularly.
¶AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented.