Who uses it
It suits organisations that build or use AI, including banks, insurers, health providers and public services.
How it is applied
- AI systems in use or planned are listed.
- Risks such as bias, errors and misuse are assessed for each system.
- Controls, human oversight and monitoring are put in place.
- Results are reviewed as systems and uses change.
Cost drivers
The number of AI systems and their impact on people drive the cost.
Timeline
A first programme usually runs over several months. The work then continues as systems and threats change.
Certification
No certificate is issued for this area alone. Organisations usually seek ISO/IEC 42001 certification, which includes AI risk assessment.


