← All transcripts

How to Manage Your AI Before It Makes the Wrong Decision Transcript, AI Summary & Key Points

IBM Technology · 25 days ago · Education · 08:50 · EN

📄 Transcript

Searchable transcript of How to Manage Your AI Before It Makes the Wrong Decision — IBM Technology (08:50). Search for a phrase, then click its timestamp to jump straight to that moment in the video.

Captions sourced from the original video on YouTube, published by IBM Technology. The video, its captions and all related intellectual property remain the property of their respective owners; AINotes claims no ownership. Provided for research, accessibility and search — see the Transcript Notice and Copyright Policy.

00:00 A bank denies a loan. No explanation, no appeal, just an AI decision. Now ask yourself, who validated that model? Who monitored it after deployment? Who's responsible when it's wrong? Most companies don't know the answer to that, and that's the gap. What's needed is an AI management system to govern all of this. And the good news is, we have one. If you're a cybersecurity person like me, you've probably at least heard of the International Standards Organization, and in particular, one of their standards, 27001, which

00:37 is the international standard for information security management systems. So, 27001 specifies how an organization establishes, implements, maintains, and continuously improves an information security system. Well, they came out with a new standard called 42001. It basically does what 27001 did for security, it does for AI. So it's an AI management system.

01:08 Now 42001 is not some checklist of controls. It's a system for managing AI risk continuously. It's auditable, it's certifiable, it's built around continual improvement across the entire life cycle. It's governance. Not model architecture. Now, like other ISO standards, 42001 follows the plan, do, check, act model. In this case, we plan by defining AI policies, scope and risk criteria.

01:39 Then we move into the do phase where we develop and deploy AI systems with appropriate controls. Then we check on the results, monitor performance, look for bias drift and unintended consequences. And then ultimately we act on what we find, continuously improve based on those findings and the whole thing becomes a continuous improvement cycle. Everything in ISO 42001 hinges on a risk-based approach and not all risk is equal because not all systems are equal.

02:12 So we need to put in the appropriate level of controls for our perceived level of risk. It explicitly considers risk across multiple layers. So one area of risk could be data risk, where we've got bias or quality issues in the data itself that will affect the results. We've got model risks that can happen here also, where the accuracy of the information or the explainability of the results that come out are in question.

02:41 We have system level risks where we have integrations between components, we have security aspects, those need to be considered here also. And then usage risks, where we have to consider what misuse and unintended consequences might introduce into the system. ISO 42001 uses the standard ISO high level structure. So let's take a look at some of the major sections that are in that.

03:07 So the first one we're going to take a looks at is context. With context, we're trying to define the scope of the AI systems. We're going identify the stakeholders. We're gonna determine whatever regulatory obligations we may have, and depending on what industry you're in or what country you're, those could vary. The next thing that it discusses is leadership.

03:30 So we're gonna assign AI accountability. Who's responsible for this? If no one is, then it doesn't get done. We define AI policy and we establish some sort of governance structure in this section. Then the next one deals with planning. And in the planning step is where we're gonna do AI risk assessments. We're gonna look at a methodology to determine what kind of risk are we facing?

03:56 What appetite do we have for risk? What tolerance do we for risk that you can look at those different ways? What is the risk treatment plan? What kinds of actions are we gonna take? Because we don't eliminate all risks. In some cases, we may decide to accept certain risks. And then measurable AI objectives will all be included in this step. Then we're going to move to the support component.

04:18 Here we're going to provide documentation, awareness training, and overall communication of how we want to operate the system. Then to an operation section, here we're going to define the life cycle governance. A change management, the system will not stay the same always so we need to plan for change because change is the only constant. Supplier, AI, oversight, all of that needs to be covered in this section.

04:46 Then we're gonna do evaluation. In the evaluation component, we're monitoring, we're doing internal audits, we're looking at management reviews, all of this. And then ultimately, an improvement stage where we've taken all of these things, we're going to do incident handling, we're go take corrective actions, and we're do that continuous improvement.

05:08 So we've been talking about this ISO 42001 standard. And I expect a lot of people are gonna be using it as an AI management system and a standard to certify against. But there are other things out there as well. And you may have heard of some of these and wonder how do they compare and contrast? Well, for instance, the U.S. National Institute of Standards and Technology has an AI risk management framework.

05:36 That also sounds at least somewhat similar to what I've been talking about with the ISO 42001. And then the European Union, the EU has their AI Act, which also has some similarities and some overlaps here. So let's take a look at the the compare and contrast amongst these three. So we'll start off with this one, the NIST risk management framework. So first of all, this one is voluntary.

06:04 So you can do this one or you cannot. It's up to you. It's flexible. So, there's a good deal of left to the user to decide how you want to do some of these things, think of it more as guidance, where it's basically telling you as a design guide, here are the things that you should be doing. So, take a look at it this way. It's telling you what good looks like.

06:30 That's the goal of this one. Now, for the ISO 42001, as I mentioned previously, it's certifiable. You can actually get a document that says, We've had someone come in and audit us. And issue a certificate against this standard. So then you can prove that you're in compliance with it. You wouldn't be able to do that with this one. This one is also very prescriptive in nature.

06:55 It prescribes a structure and it tells you basically how to manage your AI infrastructure and how to basically meet the obligations that you may have and do it in a consistent way. Then we've got the EU AI Act. Now this one's different still. This one has a lot of teeth in it. This one is law. This one's definitely not voluntary if you're in the EU.

07:22 It's based on risks and it has a tiered risk structure where you've got unacceptable, high, limited, and minimal are all spelled out. And this one is enforced. So there are penalties if you don't follow this and it's gonna define what you have to do. So this is the one that is basically telling you. How you comply. So think of it this way. The NIST AI Risk Management Framework is for risk modeling and best practices.

07:53 ISO 42001 is for governance, audibility, and certification. And the EU AI Act is the legal constraint you have to satisfy. They're not competing, they're complementary layers that can give you a stronger AI system. Organizations that treat AI governance as a checkbox are going to struggle. Organizations that don't govern their AI will struggle even more.

08:19 But those that build it into the management system will scale faster and safer. ISO 42001 is the first international standard to formalize this into a complete system. Govern your AI well, and you can harness it to do amazing things. If you don't, you're gonna feel like it locked you in the trunk and went for a joy ride. Thank you.

💡 Answer

Use ISO 42001 to continuously govern AI risks across its lifecycle, with NIST guidance for risk management and the EU AI Act for legal compliance.

🧠 AI Summary

AI should be managed through a continuous, risk-based governance system rather than treated as a one-time checklist. ISO 42001 provides an auditable and certifiable AI management system covering policies, accountability, risk assessment, lifecycle governance, monitoring, audits, incident handling, and continual improvement. NIST's AI Risk Management Framework provides voluntary guidance and best practices, while the EU AI Act establishes enforceable legal requirements. These approaches are complementary layers for scaling AI more safely.

🔑 Key Points

  • ISO 42001 applies the management-system approach of ISO 27001 to artificial intelligence.
  • ISO 42001 uses a Plan, Do, Check, Act cycle for continuous AI risk management.
  • AI risk should be assessed across data, model, system, security, usage, misuse, and unintended-consequence layers.
  • AI governance requires defined scope, stakeholders, regulatory obligations, accountability, policies, risk treatment, documentation, training, and communication.
  • Lifecycle governance includes change management and supplier AI oversight.
  • Evaluation includes performance monitoring, internal audits, and management reviews; improvement includes incident handling and corrective actions.
  • NIST's AI Risk Management Framework is voluntary and guidance-oriented, ISO 42001 is certifiable and prescriptive, and the EU AI Act is enforceable law.
  • NIST, ISO 42001, and the EU AI Act are complementary rather than competing approaches.

✅ Actionable items

  • Define the scope of the organization's AI systems, identify stakeholders, and determine applicable regulatory obligations.
  • Assign clear accountability for AI and establish an AI governance structure and policy.
  • Conduct AI risk assessments, define risk appetite and tolerance, and create risk treatment plans.
  • Set measurable AI objectives and provide documentation, awareness training, and operational communication.
  • Establish lifecycle governance, change management, and supplier AI oversight.
  • Monitor AI performance, conduct internal audits and management reviews, and address bias drift and unintended consequences.
  • Handle incidents, take corrective actions, and continuously improve the AI management system.

🧭 Frameworks

ISO 4200101:18
  1. Plan by defining AI policies, scope, and risk criteria.
  2. Do by developing and deploying AI systems with appropriate controls.
  3. Check results by monitoring performance, bias drift, and unintended consequences.
  4. Act by implementing findings and continuously improving.
NIST AI Risk Management Framework05:57
  1. Use voluntary, flexible guidance for AI risk modeling and best practices.
EU AI Act07:07
  1. Apply legally enforced, risk-based obligations with unacceptable, high, limited, and minimal risk tiers.

⚖️ Advantages, risks & lessons

Advantages

  • ISO 42001 is auditable and certifiable.
  • ISO 42001 supports continual improvement across the entire AI lifecycle.
  • A management-system approach can help organizations scale AI faster and safer.

Risks

  • Biased or poor-quality data can affect AI results.
  • Model accuracy and explainability can be uncertain.
  • System integrations and security create additional risks.
  • Misuse and unintended consequences can introduce usage risks.
  • AI systems change over time, requiring change management.
  • Organizations that treat AI governance as a checkbox or fail to govern AI face greater difficulty.

Lessons

  • AI governance requires continuous management rather than a one-time set of controls.
  • Controls should match the perceived risk because not all AI systems have equal risk.
  • Some risks may be accepted rather than eliminated, but they should be addressed through an explicit risk treatment plan.
  • Clear accountability is necessary for AI governance activities to be completed.

💬 Quotes

It's governance. Not model architecture.

It distinguishes ISO 42001's purpose from the design of AI models.01:23

They're not competing, they're complementary layers that can give you a stronger AI system.