The organization should establish and maintain a comprehensive process for identifying, assessing, and treating risks and opportunities related to its AI management system and the AI systems it develops or uses. This process should take into account the organization's context, the needs and expectations of relevant interested parties, and the specific domain, application environment, and intended use of AI systems.
The organization should define clear criteria for evaluating AI risks, including acceptable and unacceptable levels, and use these criteria to guide AI risk assessments and treatment decisions. Actions planned to address these identified risks and opportunities should be integrated into the organization's AI management system processes, and their effectiveness should be regularly assessed.
All measures undertaken to identify, assess, and manage AI-related risks and opportunities should be properly documented.