Thumbnail for How I’m Thinking About AI Risk Frameworks
Photo by Unsplash - Nathália Rosa
field notes / writings

How I’m Thinking About AI Risk Frameworks

I went digging into AI risk frameworks expecting to find the “right” one. Instead, I found a better way to think about how they fit.

For the last several years, I’ve been harping on AI governance very consistently.

As I see more companies introducing AI and LM applications into their environments, I’m noticing that they don’t have a clear picture of what those systems are doing. But it wasn’t until recently that I took a moment to actually try to figure out:

  • What does AI governance even mean?
  • What is governance?
  • What are frameworks you should follow?

And if somebody asked what advice I would give them on accomplishing this task, where would I point them to?

Tactics Win Battles, Strategies Win Wars

I’ve found this statement to be a useful model for me. And the distinction matters because some of these frameworks operate closer to strategy, while others are more useful as a tactical layer. So the answer to, “what does AI governance look like?”, might not have a clear “do these 3 things and you’re set”. But this is where it is helpful to look to a framework to use to make intelligent decisions - OK, but which one?

I looked at 4 of them:

  • AI Risk Management Framework (RMF)
  • ISO 42001
  • Cloud Security Alliance (CSA) AI Controls Matrix (AICM)
  • And the OWASP GenAI project

There are others, but these were what I focused on.

I initially started from a typical security person mindset where I find the best for each situation and recommend that. But as I dug more into them, the more I realized I was asking the wrong question. Frameworks, at least the AI frameworks, don’t work like that. Or at least I discovered that treating them like competing options was the wrong way to go.

What I found was that these different frameworks weren’t competing with each other, but acted more complementary as they focused on different things:

  • NIST AI RMF -> Explains the What and Why, it gives you a vocabulary for risk
  • ISO 42001 and CSA AICM -> Gives you how to implement those controls on an enterprise level
  • OWASP GenAI -> Acts as the battlefield tactics in-hand to train your developers and engineers

These are each helpful in their own right. Even in my research for AI threat modeling (more in another article), I’m realizing that identifying traditional “security properties” is no longer viable. Now we need to move towards “decision pipelines” - as-in how AI systems and agents make decisions (context, intent, RAG, agentic AI, tools, memory, etc.); which is a much different, and more complicated conversation. Cybersecurity is messy, AI is even messier.

Now, what do we make of this? Well, here’s how this deep dive has reshaped the way I think about these security frameworks.

What do Frameworks Actually do for Us?

I think frameworks are interesting because most people in cybersecurity know the big names. People know NIST, people know OWASP, people know ISO 27001. They may not know all the details about them, but if a manager or executive comes into the room and asks how we’re securing the company you can at least point to these.

Note Side note: I’m even having trouble moving from saying that we’re securing a system to securing an entire company. That’s the kind of mental shift it takes to think about this.

I think the purpose of a framework is to give us a common vocabulary and common understanding. Something we can all point to and collectively agree upon. They also save us from having to rediscover the same problems individually. The frameworks themselves are a byproduct of a rigorous exercise in understanding and communicating risks from a collection of some really smart people who’ve already spent time arguing about what matters, what should be measured, and how to talk about it. All told, they allow us to come to a deeper understanding of a complex set of problems we ALL face.

OK Cool, but How Do You Use the Damn Things?

Here’s my recommendation. I mentioned it a bit earlier, but I’ll reiterate it here:

NIST AI RMF

Use NIST AI RMF as a map to build understanding and a vocabulary for thinking about risks around AI systems. These can include home-built systems, purchased systems, SaaS partners, etc. And that’s an important note: if your marketing SaaS vendor introduced a cool, new AI feature into itself then how are you accounting for that in your risk profile? You may not have built it, but it could open up a new risk to your environment.

ISO 42001

Use ISO 42001 as a detailed guide on building a management system around AI in your enterprise. Think of a SOC 2 certification. The process is a lot, and ultimately you will need to show that proper policies and procedures are in place. And most importantly, EVIDENCE that you’re doing these things (auditors love evidence).

CSA AICM

CSA AICM gives you a more concrete control catalog and mapping layer. CSA also has the AI-CAIQ that shows how all the different frameworks map to each other, for more cross-framework context.

OWASP GenAI Project

Use the OWASP GenAI project for training your developers and engineers. As I said earlier, these are the battlefield tactics that will educate your boots-on-the-ground teams to build their own standards and risk mitigation mechanisms.


Anyways, this is at least what I’ve been struggling through and how I’ve developed my own mental model for AI governance moving forward. Ultimately, I’ve stopped looking for the one framework that answers everything. I think the most useful approach is understanding what each framework is trying to help you do. Then, use what is most applicable to your own situation and move on from there. For me, this feels a lot more in-line with what AI governance actually looks like.