Assess and manage each AI use case on its own merits, so that high-risk settings get safe and responsible handling while lower-risk settings carry minimal burden, using self-assessment models where helpful. Manage risk across the whole AI system lifecycle (design, data and models; verification and validation; deployment; operation and monitoring), with reviews at each phase transition and re-evaluation after significant change. During development prioritise traceability of datasets, processes and decisions according to potential harm; set up monitoring and feedback loops for emerging risks, unintended consequences and performance issues; plan for obsolete and legacy AI systems; and consider oversight mechanisms for high-risk settings, such as internal or external review bodies, advisory bodies or AI risk committees.
This control maps to 5 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 5 it maps to, and the evidence behind each claim, over MCP and REST.