Quaintitative

MindForge Toolkit

The organisation-wide risk framework

This area is about folding AI into the enterprise risk framework a firm already runs, rather than managing it off to the side. It is one of the seventeen areas in the MindForge AI Risk Management Toolkit: MindForge is the practices, the AIRG is the expectations and standards. This guide sets out the practice, the AIRG expectation it meets, and the evidence it produces. I wrote the AIRG.

What the AIRG expects

The AIRG expects existing risk frameworks and functions to identify, assess and address the risks AI brings, with clear roles, indicators and escalation across the firm. AI risk is not a new silo: it should sit inside model, operational, technology, third-party and reputational risk, with material AI risk written into the risk appetite. See the AIRG explained and the AIRG in practice.

What MindForge says to do

Capture AI risk in the taxonomy

AI touches reputational, legal and regulatory risk on top of technology and security risk, so the enterprise risk taxonomy has to capture it. The Toolkit sets out three approaches, which can be combined: a distributed one (update each existing risk category for AI), a concentrated one (expand model or technology risk to hold AI-specific risks), or an AI-specific one (a new enterprise risk category for AI). What matters is clear accountability and no gaps between risk types or parts of the firm. The risk appetite is updated to reflect AI.

Uplift controls, set KRIs, monitor and escalate

Existing controls such as access management, data protection and incident management still apply, with AI-specific enhancement where they fall short. The firm sets key risk indicators for AI, owned by people with the competence to read them - for example the proportion of use cases not in the inventory, the number of production systems without approval, drift and data-quality metrics, and aggregate exposure. AI incidents are tracked by severity, with attention to issue ageing because AI incidents can take longer to resolve. Monitoring and escalation run against thresholds set in proportion to the firm's risk appetite.

In practice

What good looks like. AI risk captured in the enterprise taxonomy with clear accountability and no coverage gaps, existing controls uplifted rather than duplicated, a small set of AI KRIs someone owns and acts on, and AI incidents tracked by severity with escalation keyed to risk appetite. AI risk sits inside the framework the board already sees.

Evidence to hold:

  • The updated risk taxonomy and appetite showing where AI risk sits, with owners named.
  • The AI KRIs, their owners and thresholds, and evidence a breach has triggered action.
  • The AI incident log by severity, with issue ageing tracked and escalation records.

How banks do it

The MindForge Implementation Examples show firms integrating AI risk into existing enterprise risk management and their risk functions - updating the taxonomy and controls they already ran - rather than standing up a standalone AI risk programme disconnected from the rest.

My take

AI is not just a model. Park it only on the model-risk desk and you will miss the system, and the use around it.

Folding AI into enterprise risk is right, but do not let that mean dumping it on one desk. The risk lives in the whole system and the way people use it, which is why the KRIs and escalation have to reach across the firm. (From my book, AI Risk Management for Directors.)

Work with me

I train and advise financial institutions on the AIRG and on folding AI into enterprise risk management. See the courses and workshops, read more on AI risk management, or get in touch.