Same shape as GOVERN in CSF 2.0, purpose-built for AI systems. For any organization deploying, building on, or assessing AI in production.
| Code | Category | Subcats |
|---|---|---|
| Govern | ||
| GOVERN 1 | Policies, processes, and practices for mapping, measuring, and managing AI risk are in place and effective | 7 |
| GOVERN 2 | Accountability structures — teams and individuals empowered and trained for AI risk work | 3 |
| GOVERN 3 | Workforce diversity, equity, inclusion, and accessibility in AI risk work | 2 |
| GOVERN 4 | Organizational culture that considers and communicates AI risk | 3 |
| GOVERN 5 | Robust engagement with relevant AI Actors | 2 |
| GOVERN 6 | Policies for third-party software, data, and supply chain AI risk | 2 |
| Map | ||
| MAP 1 | Context is established and understood | 6 |
| MAP 2 | Categorization of the AI system is performed | 3 |
| MAP 3 | AI capabilities, usage, goals, and expected costs/benefits are understood | 5 |
| MAP 4 | Risks and benefits mapped for all components, including third-party software and data | 2 |
| MAP 5 | Impacts to individuals, groups, communities, and society are characterized | 2 |
| Measure | ||
| MEASURE 1 | Appropriate methods and metrics identified and applied | 3 |
| MEASURE 2 | AI systems evaluated for the seven trustworthy characteristics | 13 |
| MEASURE 3 | Mechanisms for tracking identified risks over time are in place | 3 |
| MEASURE 4 | Feedback on measurement efficacy is gathered and assessed | 3 |
| Manage | ||
| MANAGE 1 | Risk from MAP and MEASURE is prioritized, responded to, and managed | 4 |
| MANAGE 2 | Strategies to maximize benefit and minimize harm are planned and documented | 4 |
| MANAGE 3 | Third-party AI risks and benefits are managed | 2 |
| MANAGE 4 | Risk treatment, response, recovery, and communication plans are documented and monitored | 3 |