When implementing risk management measures for AI systems, the organisation must identify the risks that require treatment and define treatment plans for them. The organisation has defined how regularly the treatment plans defined as a whole for AI risk management are evaluated as well as their proportionality to the risk assessment (risk severity and probability).
Different controls and compliance requirements, such as data quality, transparency, and human oversight, interact with each other should be considered in this process. The combined measures should ensure risks are effectively minimised and balanced.