AIT-RAI-01
AI risk framing
Maps the system, context, stakeholders, impacts, evidence, and risk tolerance for an AI use.
Loading your workspace…
AI & TECHNOLOGY · COMPLETE DRAFT · READY FOR REVIEW
A cross-sector course for translating responsible-AI principles into inventories, risk decisions, controls, monitoring, and accountable human authority.
GOVERNANCE GATE
This version exposes the proposed sources, competencies, instruction, evidence requirements, and rubric for accountable review. It cannot be enrolled in, completed, or used to issue a credential until an authorized reviewer approves a final immutable version and the program is separately published.
Status: Complete draft awaiting accountable instructional review
Draft version: 1.0.0-draft.1
Estimated learning time: 180 minutes
Program level: Course
Evidence activities: 3
Credential pathway: Proposed Certificate of Completion after review, publication, learner evidence approval, and separate administrator issuance.
LEARN → APPLY → DEMONSTRATE → REVIEW → VERIFY
AIT-RAI-01
Maps the system, context, stakeholders, impacts, evidence, and risk tolerance for an AI use.
AIT-RAI-02
Selects proportionate technical, procedural, and human controls tied to identified risks.
AIT-RAI-03
Defines ownership, transparency, contestability, monitoring, incident response, and withdrawal across the lifecycle.
CONTINUING PROFESSIONAL CASE
An organization proposes AI recommendations for training, projects, and promotion pipelines. Historical data reflect uneven access to high-visibility work, and employees cannot see or challenge the recommendations.
Constraint: Leadership wants a six-month pilot but has not assigned risk ownership or defined what evidence would stop it.
Learner task: Create a responsible-AI impact and governance plan covering context, measurement, controls, transparency, appeal, monitoring, and withdrawal.
FIVE SOURCE-GROUNDED LESSONS
LESSON 1
Purpose: Map the system, decision, actors, and impacts.
Responsible practice begins with the specific use, people, institutional history, data, decision authority, and severity of error. General principles acquire meaning only in context.
Professional example: A recommendation for optional training differs from a recommendation that silently determines promotion eligibility.
Evidence connection: NIST's MAP function centers context, intended use, impacts, and affected parties.
Map the opportunity system's decisions, actors, affected groups, data, and potential benefits and harms.
Why is context necessary?
Expected: Risk and appropriate controls depend on use, stakes, actors, and impacts. — Principles need a concrete decision context.
LESSON 2
Purpose: Assign authority before consequential use.
Governance defines who owns the system, who may approve or stop it, what risks are unacceptable, how conflicts are handled, and what evidence reaches leadership.
Professional example: HR owns the decision, an independent review group audits impact, and no recommendation can exclude an employee automatically.
Evidence connection: NIST's GOVERN function integrates policy, roles, accountability, culture, and risk tolerance.
Create a responsibility and escalation map for the pilot.
What demonstrates accountable governance?
Expected: Named owners have evidence, authority, escalation duties, and stopping power. — Accountability requires assigned authority and duties.
LESSON 3
Purpose: Select evidence tied to the real decision.
Measurement should test whether the system supports the intended purpose, how error and opportunity distribute, whether explanations are usable, and where uncertainty remains.
Professional example: The pilot compares recommendation access, acceptance, false exclusions, and later opportunity outcomes across relevant groups.
Evidence connection: NIST's MEASURE function addresses testing, metrics, uncertainty, fairness, privacy, safety, and interpretation.
Define validity, distributional, contestability, and outcome measures for the opportunity pilot.
Which evidence is most complete?
Expected: Decision validity, error distribution, affected-user experience, and downstream outcomes. — Responsible measurement connects technical and human impact evidence.
LESSON 4
Purpose: Reduce risk through layered safeguards and recourse.
Controls may limit data, scope, automation, access, or consequences; require human review; provide alternatives; and give affected people understandable notice, explanation, and appeal.
Professional example: Recommendations remain advisory, employees can view relevant factors, and a human panel reviews challenged exclusions.
Evidence connection: UNESCO and NIST emphasize human oversight, transparency, privacy, fairness, and contestability as operational responsibilities.
Layer technical, process, human, and affected-user controls around the pilot.
What makes an appeal meaningful?
Expected: An authorized person reviews preserved evidence and can correct the outcome. — Recourse requires evidence and corrective authority.
LESSON 5
Purpose: Govern the system after launch.
AI systems, populations, data, and uses change. Monitoring should detect performance and impact drift, preserve incidents and corrections, and trigger predefined review, suspension, or withdrawal.
Professional example: The pilot pauses if unexplained opportunity gaps exceed the approved threshold or appeals reveal systematic exclusions.
Evidence connection: NIST's MANAGE function prioritizes, responds to, communicates, and monitors risk across the lifecycle.
Write the pilot's dashboard, incident workflow, review cadence, and withdrawal rules.
What should be defined before launch?
Expected: Monitoring, incident ownership, correction, suspension, and withdrawal criteria. — Lifecycle governance includes correction and exit.
ASSESSED APPLICATION
PROPOSED REVIEW RUBRIC
Problem framing and operational boundary is explicit, workable, and supported by relevant evidence.
Competency: AIT-RAI-01
Technical design and implementation rationale is explicit, workable, and supported by relevant evidence.
Competency: AIT-RAI-02
Evaluation design and preserved evidence is explicit, workable, and supported by relevant evidence.
Competency: AIT-RAI-03
Risk controls and accountable governance is explicit, workable, and supported by relevant evidence.
Competency: AIT-RAI-03
Failure analysis, revision, and professional judgment is explicit, workable, and supported by relevant evidence.
Competency: AIT-RAI-03
PRIMARY SOURCE BASE
National Institute of Standards and Technology · NIST AI 100-1 · 2023
Provides the govern-map-measure-manage structure for contextual and lifecycle AI risk management.
National Institute of Standards and Technology · NIST AI 600-1 · 2024
Provides a cross-sector framework for identifying, measuring, and managing generative-AI risks across the lifecycle.
UNESCO · UNESCO · 2021
Provides a global human-rights, dignity, fairness, transparency, oversight, sustainability, and accountability framework.