S0056RS1-T01-S0056-Z · Full risk code

Absence of Model Validation

模型驗證機制缺失

Verification & Validation
Risk Description

When an organization's model is validated by the development team itself before deployment, with no independent review; due to unmitigated control gaps, when the authority requests an independent validation report during inspection, the organization cannot produce one, and a retrospective review reveals that several AI-specific risks were never assessed, triggering compliance exposure and operational reputational costs.

Framework Mappings

EU AI ActArt.9、Art.43
NIST AI RMFMEASURE 1.1
NIST AI 600-1
ISO/IEC TR 24027
ISO/IEC 5338驗證與確效
MIT AI Risk RepositoryDomain 7

Risk Treatment & Implementation Guidance

Establish a model-validation framework covering AI-specific risks—bias, robustness, explainability—assessed and documented item by item; Institute review independent of the development team with independently signed validation reports; Retain validation evidence for regulatory examination