Enterprise AI Risk Management
Learning Objectives
After completing this lecture on Enterprise AI Risk Management for government, you will be able to:
- Apply the NIST AI Risk Management Framework (AI RMF 1.0, January 2023) functions GOVERN, MAP, MEASURE, and MANAGE across a federal agency's portfolio of AI systems.
- Implement OMB Memorandum M-24-10 minimum practices for rights-impacting and safety-impacting AI, including AI Impact Assessments, use case inventories, and waivers.
- Align the AI RMF with FISMA, NIST SP 800-53 Rev. 5, NIST SP 800-37 Risk Management Framework for information systems, Privacy Act of 1974 SORNs, and agency-specific statutes.
- Map controls to ISO/IEC 42001:2023 (AI management systems), ISO/IEC 23894 (AI risk management guidance), and for transatlantic programs, EU AI Act Article 9 risk management requirements.
- Design risk registers, risk appetite statements, and escalation thresholds that survive leadership turnover, using lessons from IRS ID.me, Michigan MIDAS, Dutch childcare benefits (toeslagenaffaire), SyRI, and Houston HISD teacher evaluation.
- Integrate cybersecurity for AI (CISA guidance, adversarial ML threats cataloged in NIST AI 100-2 and MITRE ATLAS) into enterprise risk registers alongside fairness, accuracy, and accountability risks.
- Brief senior leaders, Inspectors General, GAO auditors, and Congressional committees with a defensible, evidence-based narrative on AI risk posture.
Key Topics Covered
Enterprise AI risk management ties together five disciplines inside one governance spine:
- Framework integration: NIST AI RMF 1.0 and NIST AI 600-1 Generative AI Profile combined with OMB M-24-10, ISO/IEC 42001, ISO/IEC 23894, and NIST SP 800-53 Rev. 5 controls.
2. Governance operating model: Chief AI Officer role under M-24-10, AI Governance Board composition, CAIO Council interagency coordination, Inspector General independence, and CIO/CISO/CPO interfaces.
3. Risk identification and classification: Rights-impacting and safety-impacting designation, model cards, data sheets, use-case inventories published under M-24-10, and alignment to EU AI Act risk categories (unacceptable, high, limited, minimal).
4. Risk measurement and treatment: Independent evaluation, red-teaming per EO 14110, disparate impact testing, uncertainty quantification, continuous monitoring under NIST SP 800-137, and waiver or retirement decisions.
5. Accountability and reporting: AI Impact Assessments, public-facing use case inventories, Congressional notifications, GAO audits, OIG reviews, civil-society engagement, and litigation-ready documentation.
Why This Matters for Government
Enterprise AI risk management is the discipline of treating AI systems as components of a federal agency's enterprise risk posture rather than as isolated IT projects. It builds directly on a fifty-year statutory backbone: the Federal Managers' Financial Integrity Act of 1982, OMB Circular A-123 Management's Responsibility for Enterprise Risk Management and Internal Control, the Chief Financial Officers Act of 1990, the Federal Information Security Modernization Act (FISMA), the Privacy Act of 1974 with its System of Records Notice requirements, and the Government Accountability Office's Standards for Internal Control in the Federal Government (the Green Book). AI risk is new; enterprise risk discipline is not. The job of the Chief AI Officer designated under OMB Memorandum M-24-10 is to extend that discipline to AI systems, integrate the NIST AI Risk Management Framework (AI RMF 1.0 published January 2023 and its Generative AI Profile NIST AI 600-1 published July 2024), and make the results legible to Inspectors General, the GAO, the Privacy and Civil Liberties Oversight Board, the relevant appropriations and authorizing committees, and the public through use-case inventories required under EO 13960 and M-24-10.
The case for enterprise-level AI risk management rather than case-by-case review comes from the pattern of documented failures across US and peer governments. The IRS rollout of ID.me facial verification in 2022 was a biometric identity deployment without enterprise AI risk visibility; Senator Wyden's Finance Committee letters, Senators Warren and Menendez's joint statements, and the Treasury Inspector General for Tax Administration (TIGTA) review all noted missing demographic performance analysis and missing non-biometric alternatives required under Section 508 and the Rehabilitation Act. Michigan's MIDAS unemployment fraud detection system ran for years with no enterprise risk register tracking the model's false positive rate; Cahoo v. SAS Analytics and subsequent settlements documented roughly 40,000 false accusations and more than twenty million dollars in settlements before the legislature restricted fully automated adjudication. Houston Independent School District's EVAAS teacher value-added model was found in Houston Federation of Teachers v. Houston ISD (S.D. Tex. 2017) to raise serious due-process concerns because teachers could not meaningfully contest the algorithmic score. SyRI, the Dutch System Risk Indication program, was struck down by The Hague District Court in February 2020 for violating Article 8 of the European Convention on Human Rights; the court found the government had not justified why less intrusive means were insufficient and had not published enough about the model to permit meaningful scrutiny. The Dutch childcare benefits (toeslagenaffaire) scandal forced the resignation of the Rutte III cabinet in January 2021 after revelations that risk indicators disproportionately flagged dual-nationality families. Clearview AI faced enforcement actions in the UK, Italy, France, Australia, and Canada. Compas risk assessment was challenged in State v. Loomis (Wis. 2016). These cases are diverse in domain but identical in root cause: the enterprise did not know what it had, did not track it over time, did not escalate it, and could not answer oversight questions when they arrived.
The unifying lesson is governance, not technology. None of these systems failed primarily because a model was mathematically poor; they failed because enterprises did not know they had the risk, did not track it over time, did not escalate it through a documented chain, and could not defend their decisions under judicial review, legislative oversight, or journalistic scrutiny. Enterprise AI risk management is the set of practices that forces the agency to know what it has, what it is doing, and what could go wrong, at a resolution leadership can act on. That means: (a) a comprehensive AI use-case inventory updated at least annually and published as required by M-24-10 Section 3 and EO 13960; (b) an enterprise risk register that distinguishes rights-impacting, safety-impacting, and operational AI per M-24-10 definitions; (c) AI Impact Assessments scoped to NIST AI RMF GOVERN, MAP, MEASURE, and MANAGE functions; (d) mitigation plans with named owners, resourced timelines, and documented completion criteria; (e) continuous monitoring tied to FISMA continuous monitoring obligations and to NIST SP 800-53 controls plus the draft AI-specific overlay; (f) vendor risk management aligned with FedRAMP, Supply Chain Risk Management under NIST SP 800-161, and EO 14028 software supply chain requirements; (g) clear escalation to the agency head and to the interagency Chief AI Officers Council convened by OMB.
The role of the Chief AI Officer is explicit in M-24-10: serve as the senior agency official for AI, coordinate AI governance, maintain the inventory, oversee risk management for rights-impacting and safety-impacting AI, and report to OMB. For the L5 AI Visionary, enterprise AI risk management is also a communication discipline. The CAIO must translate technical risk into language the CFO, the General Counsel, the Senior Agency Official for Privacy, the CISO, the Inspector General, the appropriations staff, the authorizing committees, and ultimately the agency head can act on. That translation is easier when the underlying data structures exist: a populated inventory, a tiered risk register with residual risk scores, an audit-ready AI Impact Assessment file, documented model cards tied to NIST AI 100-1 and NIST SP 1270, and a vendor register keyed to FedRAMP authorization status and SBOM coverage. The remainder of this seminar walks through the anti-patterns that most commonly block CAIOs from building that infrastructure, then provides exercises that turn theory into a twelve-month implementation plan anchored to the agency's appropriations cycle and the M-24-10 reporting calendar. References: OMB M-24-10; NIST AI RMF 1.0; NIST AI 600-1; EO 14110; GAO-21-519SP AI Accountability Framework; GAO Green Book; OMB Circular A-123; FISMA; Privacy Act of 1974; NIST SP 800-53; NIST SP 800-161; EO 14028; EO 13960; ISO/IEC 42001; ISO/IEC 23894; EU AI Act Annex III.
Overview
Enterprise risk management in federal agencies has a long statutory backbone: the Federal Managers' Financial Integrity Act, OMB Circular A-123, and the GAO Standards for Internal Control in the Federal Government (the Green Book). AI risk is new; enterprise risk discipline is not. The job of the Chief AI Officer under OMB M-24-10 is to extend that discipline to AI systems, integrate the NIST AI RMF, and make the results legible to Inspectors General, GAO, and Congress.
The case for enterprise-level AI risk management, as opposed to case-by-case risk review, comes from the pattern of documented failures. IRS ID.me in 2022 was a biometric identity rollout without enterprise-level AI risk visibility; Senator Wyden's Finance Committee letters and the Treasury IG review noted missing fairness analysis and missing non-biometric alternatives. Michigan MIDAS ran for years with no enterprise register tracking the unemployment fraud model's false positive rate; the state settled claims and reformed statute only after 40,000 families had been damaged. Houston HISD's EVAAS teacher evaluation was ruled to raise due-process concerns in Houston Federation of Teachers v. Houston ISD (S.D. Tex. 2017) because teachers could not meaningfully contest the model. SyRI was struck down in 2020 by The Hague District Court. The Dutch toeslagenaffaire scandal ended Rutte III in January 2021 and prompted the EU AI Act's Annex III focus on benefits determinations.
The unifying lesson is governance, not technology. None of these systems failed primarily because a model was bad; they failed because enterprises did not know they had the risk, did not track it over time, did not escalate it, and could not answer oversight questions. Enterprise AI risk management is the set of practices that forces the agency to know what it has, what it is doing, and what could go wrong, at a resolution leadership can act on.
ANTI-PATTERN 1
Risk: IT team manages AI risks in isolation; not integrated with enterprise risk management
Why: AI risks seem technical; easier to handle within IT
What Goes Wrong: Enterprise leadership unaware of AI risks; oversight bodies discover undocumented risks; organization exposed
How to Avoid: Enterprise risk officer actively involved in AI risk identification and management
ANTI-PATTERN 2
Risk: Identify risks but don't address them; creates false sense of security
Why: Mitigation takes resources; easier to document without acting
What Goes Wrong: Identified risk occurs; organization unprepared; damage to reputation
How to Avoid: Mitigation planning mandatory. Ownership assigned. Progress tracked.
ANTI-PATTERN 3
Risk: Wait for incident, then react; don't proactively manage risks
Why: Proactive management takes ongoing resources
What Goes Wrong: Preventable incidents occur; cause unnecessary damage
How to Avoid: Proactive monitoring for key risks; early intervention prevents crises
PRACTICE PROMPTS
EXERCISE 1
For your AI system, identify material risks across categories:
- Algorithmic risks (fairness, accuracy, explainability)
- Data risks (quality, poisoning, privacy)
- Security risks (theft, adversarial, unauthorized access)
- Operational risks (integration, vendor failure, staff capability)
For each: Description, probability, impact, risk score
EXERCISE 2
For your top 5 risks, develop mitigation strategies:
- What approach (prevention/mitigation/transfer/acceptance)?
- Who's responsible?
- What's the timeline?
- How will you monitor?
EXERCISE 3
Create template for your organization's AI risk register:
- Risk identification section (fields to capture)
- Risk assessment section (probability/impact framework)
- Mitigation section (strategy, owner, timeline)
- Governance section (owner, review cadence, escalation)
EXERCISE 4
Develop plan to integrate AI risks into enterprise risk management:
- How will AI risks be reported to leadership?
- How will they be included in board reporting?
- How will they be confirmed in compliance reporting?
- Insurance implications (coverage, gaps)?
EXERCISE 5
Design quarterly AI risk management report:
- Summary of material risks and status
- Progress on mitigation actions
- New risks identified this quarter
- Escalations or concerns
- Recommendations for executive attention
KEY TAKEAWAYS
- AI SYSTEMS INTRODUCE RISKS BEYOND TRADITIONAL IT RISKS
Fairness, data poisoning, adversarial attacks are AI-specific risks requiring focused attention.
- RISK IDENTIFICATION MUST BE COMPREHENSIVE AND STAKEHOLDER-INFORMED
Work with operations, security, civil rights teams to identify risks you'd miss alone.
- RISK ASSESSMENT SHOULD USE STANDARD FRAMEWORKS
Probability x Impact determines priority; focus mitigation on highest-risk items.
- MITIGATION PLANS MUST HAVE OWNERS AND TIMELINES
Documents without action create false security. Assign ownership; track progress.
- AI RISK REGISTER SHOULD BE MAINTAINED AND REVIEWED REGULARLY
Quarterly minimum. Part of enterprise risk management governance.
- OVERSIGHT BODIES EXPECT DOCUMENTED RISK MANAGEMENT
Be prepared to demonstrate how material AI risks are identified and managed.
GLOSSARY
RISK REGISTER: Documented list of identified risks with assessment, mitigation, and ownership.
MITIGATION STRATEGY: Plan to prevent, reduce, transfer, or accept risk.
RISK SCORE: Probability x Impact (determines priority).
ENTERPRISE RISK MANAGEMENT (ERM): Organizational process for identifying and managing all material risks.
AI risk management is standard risk management applied to AI-specific risks. Use frameworks your organization already has; add AI-specific risk categories.
Integrate AI risks into enterprise processes. This ensures executive attention and oversight body confidence.
For your primary AI system:
- What are the top 5 material risks?
- How would you prioritize them?
- What mitigation strategies would you pursue?
- How would you integrate these into enterprise risk management?
Effective risk management prevents crises. Identify AI risks early, develop mitigation strategies, and maintain executive visibility.
Government AI CLUB Certification Program
Level 3: AI Practitioner | Risk Management and Compliance | Lecture 4.1.1
A GOVT.CLUB initiative.
<- 3.3.10 Managing AI Vendor Performance
3.4.2 AI Red-Teaming Fundamentals ->
Start Your CLUB Certification
This seminar is part of L5: AI Visionary, 160 hours of government AI training aligned to NIST AI RMF, OMB M-24-10, EO 14110, ISO/IEC 42001, and GAO Green Book standards. Completion plus capstone is required for CLUB Level 5 certification. Explore CLUB Certification at skill.re/govt.
Related Lectures
L3
3.4.2 -- AI Red-Teaming Fundamentals
90 min - Lecture + Exercises
L3
3.4.3 -- Bias Detection and Mitigation at Scale
120 min - Workshop + Tools
L3
3.4.4 -- Privacy Engineering for AI
120 min - Lecture + Workshop
Skill.re