Continuous controls monitoring in the AI Risk and Compliance Workspace
Summarize
Summary of Continuous controls monitoring in the AI Risk and Compliance Workspace
Continuous controls monitoring (CCM) within the AI Risk and Compliance Workspace enables risk and compliance managers to automatically and continuously verify control compliance for AI systems. This approach replaces manual control testing, which can lead to visibility gaps and delayed issue resolution, by providing real-time insights into control effectiveness and supporting prompt remediation of compliance failures.
Show less
Key Features
- Indicators Framework: AI system controls are monitored via indicators that run on a scheduled basis, evaluating compliance status and triggering issues if controls fail.
- Automated Issue Creation: When a control indicator fails, a GRC issue is automatically created for the product owner to address, and the compliance score of the AI system decreases accordingly.
- Integration with AI Evaluation Frameworks: The system can connect to external AI evaluation providers (e.g., Traceloop) to leverage various metrics—such as toxicity, personally identifiable information (PII) detection, prompt injection, and agent goal accuracy—for comprehensive control evaluation.
- Compliance Scoring and Audit Trail: Continuous monitoring supports maintaining an audit trail and compliance scoring aligned to AI-specific control objectives, including internal policies and external regulations.
- Configurable Monitoring Frequency: Controls on AI use cases can be evaluated daily, weekly, or monthly, assessing evaluation framework data against defined thresholds.
Key Outcomes
- Provides a unified system of record for AI governance evidence, enhancing transparency and accountability.
- Enables continuous, automated monitoring of AI model risk, improving operational resilience and reducing compliance violations.
- Facilitates timely detection and remediation of control failures, minimizing potential risks and supporting regulatory compliance.
Indicators in AI Risk and Compliance Workspace continuously monitor control compliance for AI systems.
Risk and compliance managers can continuously monitor the controls attached to AI systems. Connect an external AI evaluation framework to the existing indicators framework in AI Risk and Compliance Workspace.
Indicators for AI systems
In organizations managing Governance, Risk, and Compliance (GRC) workflows for AI systems, teams can be challenged when monitoring control effectiveness in real time. Manual control testing can leave gaps in visibility and increase the risk of undetected control failures. Without continuous insight into control performance, organizations can face delayed issue resolution, costly compliance violations, and reduced operational resilience. Continuous Controls Monitoring (CCM) automates control verification, reducing manual testing burden and providing real-time visibility into control health. AI Risk and Compliance Workspace evaluates whether a control is compliant or non-compliant using indicators that run on a schedule. When an indicator fails, a GRC issue is created so that the product owner of the affected asset can remediate it. The compliance score of the associated record decreases. This same indicator concept is extended to AI systems by using evaluation scores produced by an AI evaluation framework.
Value for AI governance
Applying indicators to AI system entities gives an organization a single system of record for AI governance evidence. This approach enables continuous monitoring of model risk instead of relying on periodic manual reviews. It also provides an audit trail that supports Compliance Scoring for AI-specific control objectives and authorities, such as internal AI policies or external AI regulation.
AI evaluation framework providers
A compliance evaluation configuration can evaluate an AI system using metrics from ServiceNow or from other evaluation framework providers, such as Traceloop. Each provider exposes a different set of base metrics, such as toxicity, PII detection, prompt injection, and agent goal accuracy. The provider selected in a configuration determines which metrics are available.
For more information, see Create a compliance evaluation configuration, Use a compliance evaluation on an AI system record, and AI evaluation base metrics.Monitoring lifecycle
After an AI use case is deployed, it moves into a monitor state. Its controls are evaluated continuously over the lifetime of the AI system, on a daily, weekly, or monthly frequency. Each evaluation checks the trace, session, or span records produced by the evaluation framework against the configured metric thresholds. If a control fails, an issue is raised against the AI system and its compliance score decreases; when the control becomes compliant again, the score increases.