S0009RS1-T02-S0009-Z · Full risk code

Absence of AI Governance Structure

缺乏 AI 治理組織架構

Inception
Risk Description

When individual departments adopt AI tools and services independently for efficiency, without unified review; due to unmitigated control gaps, when a data leak or output dispute occurs, the organization discovers multiple unmanaged AI applications in use, with no inventory, no risk assessment, and no one able to explain data flows or supplier terms, triggering external stakeholder impacts and causing incident response and accountability both break down.

Framework Mappings

ISO/IEC 42001§4.4、§5.3、Annex A.2.2、A.3.2
NIST AI RMFGOVERN 1.6、GOVERN 2.1
ISO/IEC 23894§5
ISO/IEC 5338啟動
MIT AI Risk RepositoryDomain 6

Risk Treatment & Implementation Guidance

Establish an organization-wide AI governance structure with a policy requiring unified review before any AI adoption; Implement an AI management system maintaining an inventory across all departments, recording purpose, data flows and supplier terms; Sweep and onboard unmanaged existing applications, with a duty to register any newly discovered use