Managing 1000+ AI Records in AICT – Need Recommendations

smoulimonish
Tera Contributor

We have nearly 1000+ AI systems, models, and prompts in ServiceNow. Following the latest ServiceNow update, all AI-related assets will be managed within AICT.

 

Currently, all records are under review, and usage is restricted until they are approved by an AI Steward. Managing and reviewing over 1000 records is a significant effort.

 

We would appreciate any recommendations or best practices to streamline this process.

1 REPLY 1

rpriyadarshy
Kilo Sage

I Assume AI Council/AI CoE is there and Process is Set and Configured in AICT.

 

Since AICT has persona based roles and Responsibilities and if each one is doing then i do not think there will be much Backlog.

 

AI steward•Responsible for all the execution of AI Control Tower initiatives.
[sn_ai_governance.ai_steward]•Understand the AI assets and AI Control Tower policies.
 •Collaboration of cross-functional teams within the organization to confirm that the organization policies are adhered.
 •Configure Multi-instance Management for AI Control Tower. 
AI Control Tower Workspace user•Users who own and manage AI assets.
[sn_ai_governance.workspace_user]•Access the AI Portfolio on the AI Control Tower home page.
AI asset ownerIncludes the Assessment admin platform role.  Administrator for the SAE application.
[sn_ai_asset_mgmt.ai_asset_owner]•Manages AI assets like systems, models, datasets, and prompts through their asset lifecycle from intake to retirement.
 •AI asset owner is automatically assigned a task in the Deploy phase of the AI asset lifecycle to mark the task as complete.  If the AI asset has been deployed, then the state of the task by itself doesn’t change anything in the asset table or the asset governance details record.
AI Risk and Compliance AdminAI Risk and Compliance Admins can perform the following tasks:
[sn_grc_ai_gov.ai_risk_and_compliance_admin]•Set up risk and impact assessment frameworks.  Configure risk assessment methodologies, risk contribution factors, and impact assessment templates.
 •Define automation rules for impact assessments to determine applicable risks and controls based on assessment responses.
 •Set up and profile AI case types.
 •Delete AI systems.
AI Risk and Compliance ManagerThe AI Risk and Compliance Manager can access all AI systems on the system and perform the following tasks:
[sn_grc_ai_gov.ai_risk_and_compliance_manager]•Initiate impact assessments.
 •Manage the lifecycle of an AI system.
 •Initiate risk assessments.
 •Initiate control attestations.
AI Risk and Compliance AnalystThe AI Risk and Compliance Analyst can access all AI systems on the system and perform the following tasks only on the assigned records:
[sn_grc_ai_gov.ai_risk_and_compliance_analyst]•Initiate impact assessments.
 •Manage the lifecycle of an AI system.
 •Initiate risk assessments.
 •Initiate control attestations.
AI Risk and Compliance User•Create AI case on the Employee Center.
[sn_grc_ai_gov.ai_risk_and_compliance_business_user]•Work on the assigned tasks.
 •Perform control attestations
AI Risk and Compliance ReaderRead access to the AI systems and AI impact assessments.
[sn_grc_ai_gov.ai_risk_and_compliance_reader]
AI System ReaderRead access to the AI systems on AI Control Tower workspace and AI Risk and Compliance workspace.
[sn_grc_ai_gov.ai_risk_and_compliance_ai_system_reader]
AI Case Business UserCreate AI case and AI inquiry on the Employee Center.
[sn_ai_case_mgmt.ai_case_business_user]
  

 

Few More Points

 

Define auto-approval guardrails for assets that meet safe criteria
Apply risk-based triage Categorize assets into High / Medium / Low risk and Cover High Risk Assets First.
Use AICT Approval Controls And Playbooks to reduce manual effrorts
 

Regards

RP