For Risk & Compliance
The AI risk management build grid
This is an AI risk management checklist for the second line: the book condensed into the controls you must have in place and the evidence you must be able to produce for the board above you and the supervisor outside, area by area, mapped to the AIRG. I wrote the AIRG and led the thematic review of how banks actually manage AI model risk, so the areas and paragraph references are the MAS'; the "have in place" and the "evidence to hold" are my interpretations, not regulatory guidance, and are deliberately compressed. Use it to build and self-check your programme, not as a tick-box. The order follows the AIRG's architecture: oversight, the risk-management system, the lifecycle controls, and capability.
Oversight
1. Board responsibilities (AIRG 2.5). Have in place: material AI risk written into the board-approved appetite with limits that can actually be breached, and board reporting, drawn from the inventory, that invites challenge rather than noting. Evidence to hold: board papers and minutes showing AI proposals questioned or stopped, and the appetite limits with their breach history.
2. Senior management (AIRG 2.6). Have in place: the board framework turned into working policies, the function resourced against the size of the estate, and an escalation path that moves breaches up in time. Evidence to hold: the org chart, headcount against system count, and escalation records showing issues surfaced, not absorbed.
3. Cross-functional committee (AIRG 2.4). Have in place: where overall AI risk is material, a committee with real decision authority across the three lines. Evidence to hold: minutes showing decisions that bit - systems sent back, deployments made conditional, action items closed.
4. Org-wide integration (AIRG 2.3). Have in place: AI folded into your existing model, operational, technology, and third-party risk policies, not a parallel AI silo, with a controlled waiver process. Evidence to hold: the updated risk policies and the waiver log with rationale.
5. Risk culture (AIRG 2.2). Have in place: responsible-use principles turned into practical red lines, AI literacy across staff levels, and a real channel to raise concerns. Evidence to hold: the policy, training completion records, and a case of a concern raised and acted on.
The risk-management system
6. Identification (AIRG 3.2). Have in place: a firm-wide definition of AI that you arbitrate, with identification wired into procurement, vendor onboarding, change, and periodic attestation to catch shadow and embedded AI. Evidence to hold: the definition, borderline-case decisions with rationale, and a log of AI caught that was not self-reported.
7. Inventory (AIRG 3.4). Have in place: one reconciled inventory with mandatory metadata, linkages to upstream data and downstream systems, an update cadence matched to deployment, and a decommissioning log. Evidence to hold: the inventory export, and its reconciliation against the model, vendor, and IT registers.
8. Materiality (AIRG 3.8). Have in place: a materiality methodology you own, rating on impact, complexity, and reliance rather than audience, with rubrics that keep a "high" consistent and defined re-rate triggers. Evidence to hold: the methodology, a sample of completed ratings across tiers, the estate distribution, and a record of a self-rating you overruled.
Lifecycle controls
9. Data management (AIRG 4.5). Have in place: representativeness and quality checks, lineage to source, and due diligence on external data. Evidence to hold: data quality and representativeness reports, lineage documentation, and external-data due diligence.
10. Transparency and explainability (AIRG 4.6). Have in place: explanations matched to materiality that a customer can act on and a reviewer can challenge. Evidence to hold: sample customer disclosures and individual explanations, and the transparency policy keyed to risk.
11. Fairness (AIRG 4.8). Have in place: a chosen fairness definition suited to each use, proxy-variable testing, pre-deployment sub-group testing, and documented accuracy trade-offs. Evidence to hold: the fairness methodology, bias-test reports with sub-group results, and the trade-off sign-off.
12. Human oversight (AIRG 4.10). Have in place: effective oversight with real override authority, override logging and pattern analysis, sustainable reviewer workloads, and active automation-bias controls. Evidence to hold: override logs and their analysis, and reviewer competency and workload data.
13. Third-party AI (AIRG 4.11). Have in place: bought AI on the inventory and held to your internal standard, compensatory testing on your own data, supply-chain mapping, and a usable exit. Evidence to hold: vendor due diligence, your own test results on vendor models, contracts with audit and termination rights, and a concentration analysis.
14. Model selection (AIRG 4.12). Have in place: a requirement that developers build and beat a simple baseline and justify any added complexity. Evidence to hold: the model-selection report with baseline-versus-challenger results and the complexity justification.
15. Evaluation and testing (AIRG 4.14). Have in place: a stated "good enough" threshold per task, no train-test leakage, and edge-case and adversarial testing proportionate to materiality. Evidence to hold: test plans and results including the failures, red-team logs where relevant, and the threshold sign-off.
16. Technology and cyber (AIRG 4.16). Have in place: the AI system secured against ordinary technology risks plus AI-specific ones like data poisoning, reviewed before go-live. Evidence to hold: the security assessment and its pre-deployment conclusion.
17. Reproducibility and auditability (AIRG 4.17). Have in place: development documented well enough for an independent reviewer to rebuild it, with versioned data, code, and configuration. Evidence to hold: version-control and experiment-tracking records, and archived model artefacts tied to production versions.
18. Pre-deployment validation (AIRG 4.18). Have in place: genuinely independent validation for material systems, performed by people outside the build and with authority to send a system back. Evidence to hold: validation reports and sign-offs, and a record of systems returned or made conditional, with the conditions closed.
19. Monitoring (AIRG 4.23). Have in place: tiered thresholds that trigger action, segmented so a failing sub-group is not hidden in a healthy average, with incident and periodic-review processes. Evidence to hold: monitoring dashboards, the alert history with actions taken, and periodic revalidation reports.
20. Change management (AIRG 4.25). Have in place: a clear material-versus-minor line, retrains routed back through review, and controlled emergency and unauthorised changes. Evidence to hold: the change log, retraining approvals, and post-change validation.
21. Pilots and PoCs (AIRG 4.3, fn 14). Have in place: time-boxed pilots with end dates and user limits, and controlled use of production data. Evidence to hold: the active-pilot list with end dates and data-handling records.
22. Auto-updating AI (AIRG 4.25c). Have in place: enhanced controls with strict limits on what can change automatically, and a rollback that has been tested. Evidence to hold: the dynamic-update policy, the guardrail configuration, and rollback test results.
Capability
23. Competence and capacity (AIRG, capability). Have in place: skill across all three lines, validators who can actually challenge a model, and headcount sized to the estate. Evidence to hold: competency frameworks, validator qualifications, and a resourcing analysis against the inventory with a plan for the gaps you already know about.
Two closing reminders
The grid lists areas in order, but risk does not arrive in order. Two cross-cutting moves matter more than any single row. First, point your own scrutiny where risk hides - the low rating, the inventory gap, the committee that has never said no - not where the first line wants to show you its best work. Second, hold everything to proportionality: your controls must track your ratings, and your ratings must survive your own audit of the first line. Get those two right and the twenty-three rows above become a programme you can actually run, rather than a binder you file.
Work with me
I train risk and compliance teams on turning AI risk management into a working system. See the courses and workshops, read more on AI risk management, or get in touch.